Author Topic: Solartron 7071/7081 ER3400 replacement with FRAM  (Read 313 times)

0 Members and 1 Guest are viewing this topic.

Offline chekhovTopic starter

  • Regular Contributor
  • *
  • Posts: 142
  • Country: by
Solartron 7071/7081 ER3400 replacement with FRAM
« on: August 09, 2026, 11:01:46 pm »
While I still remember something, let's give it a go.

After obtaining Solartron 7071 I started to wonder, how to eliminate the case of suddenly loosing its calibration due to possible ER3400 data corruption, reported in other threads.
One way would be as straightforward as it could - back it up, by just reading CAL constants or reading entire its content and saving it.
Then they could be restored any time into a new IC, and it's still possible to buy them.

However there are all kind of inconveniences with this approach. The only thing that works out of the box is reading CAL constants, if you happen to have the key, or disassembled the meter and unplugged one wire from the lock. Every other action is a pain - still requires opening the meter and taking off AC PCB. And even then, there is no easy available tool to read/program this IC directly.

So, why don't at least somehow simplify this process ? Why don't we attempt to replace this IC with something else, still available and supported by programmers.
Here the saga story begins.

---- What can we use ----
Initially I always thought about using FRAM because sounds like something cool, but first I decided to verify whether we can use EEPROM/Flash.

In order to use any we have to match two sides - what Solartron does while reading/programming and what other chip expects.
And the most important moment is erase-write sequence. Some memory types require erase before write, some not.

I had a few Intel 2816A, and from first glance everything looked fine, timings and sequence - since ER3400 has very long erase cycle it's just should work fine with EEPROM, but there is a glitch - 2816A wants all its inputs to be in HIGH state during erase, and ER3400 doesn't care.

(ER3400 erase mode)
2871580-0

(Intel 2816A erase mode)
2871516-1

Later I verified that 7071 keeps them LOW. In order to solve that I should have something in between data lines and 2816A that will specially hold data lines HIGH (disconnect them from 7071 bus) and for all other READ/WRITE cycles to have them just connected. Maybe that's not a big deal after all, but I decided to not go this route.

Looking at other chips it was obvious that the newer the chip, the more complicated writing procedure becomes (for a reason!).
Thus, I decided to take FRAM a chance, FM16W08 in particular. I initially abandoned full ER3400 erase mode, so not an issue.
Looking at the datasheet, everything looked promising, and the story of using it in 3458A/1281 also inspired me as well.

---- First attempt ----

The first obvious difficulty was to translate working modes from C0 C1 and #WE (which is always 0 in 7071) of ER3400 into #WE and #OE of FM16W08.
After some looking at ER3400 pin functions table and thinking, solution was promising - single IC that contains 4 NOR gates seem to be enough:

(ER3400 operating modes)
2871520-2

(operating mode shifter - erase is not used)
2871524-3

This was a time to wire it in some hardware and test. Since earlier I went through the hell of extracting exact ER3400 contents, I even could initially write proper stuff into FM16W08.
A note about how it looks like - I decided to minimize solder work, so used flex-cable-to-board terminals to connect to original socket. Had to use 2 of them.
Unfortunately I have no idea where to find those adapters that can directly plug into standard IC sockets like used on digital board.
One more restriction - I decided that I have to make solution that only uses exposed pins - no additional soldering to PBC should be required.

(adapter in a meter)
2871528-4

Time to test. Turn ON - OK. Turn OFF, turn ON - OK. Read CAL constants, turn OFF, turn ON - NVM FAIL, WTF ???
From there the most interesting part of this journey begins.

(additional pictures - working with ER3400 while calibrating 0V point, what C0 and C1 values are used)
« Last Edit: August 09, 2026, 11:19:40 pm by chekhov »
 
The following users thanked this post: Mickle T.

Offline chekhovTopic starter

  • Regular Contributor
  • *
  • Posts: 142
  • Country: by
Re: Solartron 7071/7081 ER3400 replacement with FRAM
« Reply #1 on: August 09, 2026, 11:02:22 pm »
---- Data corruption investigation and fix attempts ----

There were basically a few bytes that changed its value, in second half of the address space.
2871576-0

I tried several times refreshing FRAM and cycling the meter, and much more frequently it failed when I was reading CAL constants, however without that it failed too, just with much lower chance.
I hooked logic analyzer, and it was obvious - digital levels were bouncing all around when powering off the meter. And after CAL constants reading memory chip was left with #CE=0, rocketing the chance of failure.
Thus, on power off we were writing data. The speed of FRAM chip and the fact that it works from 2.7V likely made this situation worse that could have been. But verdict is obvious - we cannot use FRAM as is with just converted C0 C1, need something else.

Next ides is obvious - ER3400 needs -30V for programming, and I verified that it's hooked up only at the moments of actual programming.
Thus, our schematics is getting a little upgrade - a mosfet that protects #WE from going low when -30V is not present.
Maybe not the best solution overall, but I wanted something simple, with parts I can reach. Very likely some very clever power supply monitoring IC should have been used instead, but I haven't tried this path.

(values are semi-random, likely not the ones I tried, I'm sure there are better combinations)
2871548-1


(actual photo, from first further attempt to condition #CE as well)
2871552-2


Wired. Let's test - and it worked ... for some time ... until it didn't fail again.
Similar failure, similar corruption.

Here how it looks like (I took some scope captures, no necessarily at exact corruption time, but something for reference better than nothing).
(Yellow: -30V, green: #WE)
2871556-3

(Yellow: -30V, green: +5V, blue: #CS at 1.5V)
2871560-4

And here we came to maybe the most strange part - implementation of this -30V supply and how it's hooked.
2871564-5

Eventually I spent quite some time looking at power off sequences, and how those glitches look like.
What we see is +28V line goes down, and D804, Collector-Base or TR804 and D805 become just 3 diodes in series, eventually pulling charged capacitor C804 to ground.
This way on power OFF ER3400 is actually supplied with -30V for a short period of time.

NOTE: When I was discussing all this wonderful situation with one person, they came up with awesome statement/idea - what if all this original ER3400 sudden 'death/corruption' was exactly this little chance of getting 'all stars aligned' - C0, C1, #CE, -12V and -30V in a way that initiated chip erase. That will exactly generate a garbage in it. That's insane still very viable theory. :blah:


Ok, so looking at -30V to protect #WE is useless. What else we have - -12V supply. Looking at pictures from the scope it was more or less consistent between how 5V and -12V disappear. -12V rail only has 1uF capacitor, so it goes to 0 much quicker than -30 or +5, so I still had a chance.

2871568-6
And I tried the same 'solution' as with -30V. Just in case of -12V what I didn't like from the very beginning is voltage margins.
What I didn't like is mosfet voltages margins. Vgs is usually -2V, for most of mosfets I have. So we need our gate to sit at least -2V in order to operate properly. With -12V it means I need 5V to disappear, so -12 + 5 = -7V.
But in order to reliably protect my #CE I need Source voltage to remain 3-4V to represent good logic 1. And so gate should be 2-3V to guarantee that. And this 2-3V is -3-2V at -12V line - almost when -12V hits ground, very long time from shutdown start. Still I decided to give it a try.

I did a lot of power switching activity, and even unfortunately broke original switch :(((( |O :palm:, but finally caught a failure - so this still does not work well enough.

Unfortunately at this point I'm not sure, whether it was just bad idea completely or it's all because I picked up (from what I only had) wrong mosfet - it had too high gate capacity.
And I never tried different mosfet - went straight to better version that use 2 mosfets - one protecting #CE and the other applies gate voltage.

2871572-7

So far this seems to work, at least I wasn't able to break it yet. Unfortunately that's the best I can tell, not 1000% guarantee.
« Last Edit: August 09, 2026, 11:22:57 pm by chekhov »
 
The following users thanked this post: Mickle T.

Offline chekhovTopic starter

  • Regular Contributor
  • *
  • Posts: 142
  • Country: by
Re: Solartron 7071/7081 ER3400 replacement with FRAM
« Reply #2 on: August 09, 2026, 11:04:21 pm »
Proper final would be to draw a board, but I haven't reached this point yet. I likely will cost 15-20$ to get this little PCB and 2 months to wait for it, so will likely end up either etching something at home or use 1.27mm board to make it all compact.

Notes about possible physical construction. The main difficulty there is that we have:
 a) non-standard leads spacing - more than steep DIP and less than wide one.
 b) we only have 15mm between lower PCB and electrostatic shield PCB, and ~5 already occupied with on-board DIP socket.
    Because of that FM16W08 with its adaptor and special pins is already go beyound that 10mm limit. So likely my home-etched PCB could only use pins from DIP socket (which is still improper - they are ~0.6mm in diameter, when special pins are ~0.5 mm, and extra thickness damages IC sockets). I don't know where to find proper shorter circular 0.5 mm pins in a row.
« Last Edit: August 09, 2026, 11:13:34 pm by chekhov »
 
The following users thanked this post: Mickle T.


Share me

Digg  Facebook  SlashDot  Delicious  Technorati  Twitter  Google  Yahoo
Smf

 

-->