DS1991 MultiKey iButton
Three password-protected 384-bit subkeys in one button.
One token, three walls. The DS1991 carries three independent 384-bit subkeys, each with its own 64-bit password and its own 64-bit public ID field, so three different systems — or three departments, or a landlord and two tenants — can share one physical key without any of them being able to read the others' data. A 512-bit scratchpad buffers writes, and the whole 1152-bit array is battery-backed NV RAM with over 10 years of retention.
Three isolated key zones in one button
No other iButton partitions itself this way. Where a DS1992 gives you one flat memory that anyone who can touch the key can read, the DS1991 gives three private rooms with separate doors — the classic answer when one credential must serve several independent operators. Be honest about the era, though: its password scheme dates from the early 1990s and a published dictionary attack (CVE-2001-1436) means it should not be specified as the security layer of a new design. Order it to keep an installed base running; for new systems that must resist cloning, use the DS1961S with its SHA-1 challenge–response instead.
Key features
- Three independent, password-protected subkeys in one button — acts as three separate electronic keys.
- 1,152-bit secure NV memory: 3 blocks of 384 bits, each with its own 64-bit password and ID field.
- A read with the wrong password returns random data, not an error — real content stays hidden.
- Scratchpad-verified writes (write → read back → verify → copy) protect data integrity.
- Family code 02h; over 10 years data retention; UL 913 intrinsically-safe rated.
- Single-wire 1-Wire® bus — two conductors carry both power and data, so the host stays simple and the wiring cheap.
- A unique, unalterable 64-bit ROM ID in every part — usable for equipment tracking and provenance checks independently of the three protected zones.
How the password protection behaves
Specifications
| Chip / compatibility | DS1991 · factory model TM1991L-F5 · family code 02h |
|---|---|
| Memory | 1152-bit secure NV RAM = 3 subkeys × 384 bits, each with a 64-bit password and 64-bit ID field, + 512-bit scratchpad |
| Operating temperature | −40 to +70 °C · over 10 years data retention |
| Package | F5 can — stainless-steel shell with a moulded polymer grommet; dust-, damp-, shock- and corrosion-resistant |
| Protocol | 1-Wire® |
| Mounting | Read/write needs a 1-Wire master plus software that implements the subkey commands — an ordinary key-copier cannot write it |
| Options | Legacy support: Analog Devices performed a last-time build of the original DS1991L — we continue to manufacture compatible parts (our part no. TMK-TM1991) for installed systems. Every piece is read/write tested and initialised before shipment. Trial packs from 1 pc; volume tiers at 51 and 501 pcs. Laser marking and pre-programming to order. |
Inside the stainless can
A 0.25 mm solid stainless shell, a UV-stable polypropylene grommet isolating lid from base, and the die bonded inside. Lid = data contact, base = ground return.
Which memory iButton do you need?
The whole memory range side by side, grouped by storage technology — capacities and family codes per the Analog Devices datasheets.
| Model | Family code | Capacity | Memory technology | Pick it for |
|---|---|---|---|---|
| DS1971 | 14h | 256 bit + 64-bit OTP | EEPROM — battery-free | Asset tag: a locked ID beside rewritable data |
| DS1972 | 2Dh | 1 Kbit (128 B) | EEPROM — battery-free | Per-page write-protect or EPROM-emulation modes |
| DS1973 | 23h | 4 Kbit (512 B) | EEPROM — battery-free | Largest battery-free memory; production travellers |
| DS1982 | 09h | 1 Kbit (128 B) | EPROM — add-only, cannot be erased | Tamper-evident checkpoints and certificates |
| DS1985 | 0Bh | 16 Kbit (2 KB) | EPROM — add-only, cannot be erased | Full append-only service history |
| DS1992 / DS1993 | 08h / 06h | 1 Kbit / 4 Kbit | NV RAM — battery-backed, unlimited writes | Data that changes constantly on the key |
| DS1996 | 0Ch | 64 Kbit (8 KB) | NV RAM — battery-backed, unlimited writes | Portable database — the largest capacity here |
| DS1994 | 04h | 4 Kbit + RTC | NV RAM + clock, timer, counter, alarms | Time- or usage-limited access that expires by itself |
| DS1904L | 24h | No user memory | Real-time clock only | Give a microcontroller an accurate timebase |
| DS1991 | 02h | 1152 bit = 3 × 384 bit | Secure NV RAM — three password zones | Legacy multi-tenant systems (not for new secure designs) |
| DS1961S | 33h | 1 Kbit + 64-bit secret | EEPROM + SHA-1 challenge–response | The anti-cloning choice — proves it knows a secret |
Ordering information
| MOQ | 100 pcs |
|---|---|
| Lead time | 3–7 days for stock items, 10–15 days for OEM |
| Packing | Bulk ESD bags (100–200 pcs/bag, 2 bags/carton); blister or header cards for retail on request |
| Samples | Free samples for volume buyers — courier at cost |
| Payment | T/T bank transfer; other terms negotiable for repeat orders |
| Shipping | DHL / FedEx / UPS air express; sea or rail freight for pallet volumes |
| Customization | ROM ranges · housing colours · laser logo · private label |
Typical applications
Frequently asked questions
Is the DS1991 secure enough for a new access-control design?
No — and we would rather say so than sell you the wrong part. Its three-password scheme dates from the early 1990s and a published dictionary attack (CVE-2001-1436) can recover the subkey passwords, after which all protected data is readable. Analog Devices has also run a last-time build of the original DS1991L. Use it to keep an existing installation running, and specify the DS1961S with SHA-1 challenge–response for anything new that must resist cloning.
What is the DS1991 still genuinely good for?
Compartmentalisation, not cryptography. It remains the only iButton that splits itself into three independent 384-bit zones with separate passwords and separate public ID fields, so one physical token can serve three unrelated operators who must not read each other's data. Where that structure is what the installed system expects — and the threat model is casual rather than determined — it still does the job, and we continue to manufacture compatible parts.
Which applications actually order this part today?
Three recurring ones, all of them retrofit rather than greenfield. Smart water and utility meters, where the meter reader's token must carry an operator credential the household cannot read. Authorisation keys for precision instruments and test equipment, where a calibration level or licence tier lives in one zone and the service history in another. And high-value industrial equipment management, where the machine builder, the owner and the maintenance contractor each hold rights to their own zone on the same physical key. In every case the reason is the three-way partition, not the strength of the password.
What equipment do I need to read and write it, and how does it arrive?
You need a 1-Wire master (a USB adapter or your own controller) plus software that implements the DS1991 subkey command set — reading a protected zone means presenting that zone's 64-bit password with the read command. An ordinary door-key duplicator cannot do this: it only handles the 64-bit ROM ID of simple parts and has no notion of subkeys or passwords, which is exactly why this part resists casual copying. Every piece we ship has been read/write tested and initialised at the factory, so it arrives in a known state — you write your own data and set your own passwords on arrival.
Related products
DS1992 / DS1993 Memory iButton
1 Kb and 4 Kb NV RAM tokens for carrying data on the key.
DS1996 64 Kb Memory iButton
The large-memory token — 64 Kb of rewritable NV RAM.
DS1961S SHA-1 Authentication iButton
1 Kb EEPROM with on-chip SHA-1 challenge–response.
DS1971 EEPROM iButton
256-bit EEPROM — non-volatile without a battery.