1. Today’s topic

Today we examine board resilience to electromagnetic interference and electrical transients:

text
long cable / external connector
→ energy limiting
→ overvoltage protection
→ filtering
→ galvanic isolation or transceiver
→ clean digital-level conditioning
→ ESP32 or STM32 GPIO/ADC
→ software diagnostics

The central idea: protection is built from the connector toward the microcontroller. Disturbance energy must be diverted or limited before reaching GPIO, logic ground, or MCU power.

2. Why this matters in your projects

For traffic-light phase inputs, field wiring may run beside power cables, relays, contactors, 220 V lines, motors, and variable-frequency drives. Interference may look like a false edge, phase conflict, queue overflow, or watchdog reset. RS-485/CAN can face:

text
ESD from a person or connector
EFT from switching an inductive load
surge on an outdoor cable
prolonged connection to 24 V
ground-potential difference

Firmware can count and filter glitches, but cannot reduce current flowing through GPIO.

3. Theory

11.3.1 3.1. Disturbance types

DisturbanceCharacterProtection objective
ESDvery fast dischargedivert the edge at the connector
EFTa series of fast pulsesfiltering, return path, isolation
Surgesustained high energypowerful TVS, current limiting
DC faultprolonged incorrect voltagefuse, PTC, fault-protected input
Common-modeboth lines move relative to groundisolation, CMC, common-mode range
Differential noisevoltage between linesRC/LC, termination, differential receiver

11.3.2 3.2. Protection chain

text
connector
→ primary protection
→ current/energy limiting
→ filter
→ isolation or protected receiver
→ secondary protection/conditioning
→ MCU

Example of a 24 V discrete input:

text
FIELD_IN
  ├─ TVS to field return
  ├─ series resistors
  ├─ RC filter
  └─ optocoupler / comparator
         └─ Schmitt output → MCU GPIO

11.3.3 3.3. TVS placement

Place TVS close to the connector. A short, low-inductance current return path matters. If TVS is near the MCU, the pulse has already traveled through the board.

11.3.4 3.4. Where TVS current flows

Distinguish:

text
PE / chassis
field ground
isolated bus ground
digital ground
analog ground

If pulse current flows through digital GND, all logic may experience a potential jump.

11.3.5 3.5. Choosing TVS

Check:

text
VRWM — working voltage
VBR — breakdown voltage
VCL — clamping voltage at the specified current
IPP / pulse power — pulse energy
capacitance — interface impact

11.3.6 3.6. Series resistor

It limits current, forms an RC filter, and reduces ringing. Check working voltage, pulse overload, power, and creepage.

11.3.7 3.7. RC filter

text
τ = R × C
fc = 1 / (2πRC)

Example:

text
R = 10 kOhm
C = 10 nF
τ = 100 us
fc ≈ 1.59 kHz

Choose the filter based on the shortest useful pulse and interference duration. If those intervals overlap, one RC network is insufficient.

11.3.8 3.8. Schmitt trigger

A Schmitt trigger has two thresholds and eliminates repeated switching on a slow/noisy edge.

text
optocoupler
→ pull-up
→ RC
→ Schmitt buffer
→ GPIO

11.3.9 3.9. Internal MCU clamp diodes

Do not treat them as the main system ESD protection for an external cable. Check absolute maximum voltage, injected current, and total port current.

11.3.10 3.10. Industrial 24 V input

Conceptually:

text
24V_FIELD
→ fuse / fusible resistor
→ reverse polarity protection
→ TVS
→ resistor chain
→ RC
→ optocoupler LED
→ isolated transistor
→ pull-up 3.3 V
→ Schmitt/GPIO

Calculating optocoupler LED resistance:

text
R ≈ (VIN − VF_LED − Vbridge) / ILED

11.3.11 3.11. 220/230 V AC input

For 230 V RMS:

text
VPEAK ≈ 230 × √2 ≈ 325 V

Account for resistor working voltage, surge rating, creepage/clearance, the optocoupler insulation class, fusing, and safety. This is not a circuit for a breadboard.

11.3.12 3.12. RS-485 and CAN

Conceptual chain:

text
connector
→ TVS array
→ optional pulse-proof resistors / PTC
→ optional common-mode choke
→ termination/bias
→ fault-protected transceiver
→ optional isolation
→ MCU

11.3.13 3.13. What firmware can do

Firmware should count residual disturbances:

c
typedef struct {
    uint32_t raw_edge_count;
    uint32_t accepted_edge_count;
    uint32_t rejected_glitch_count;
    uint32_t conflict_count;
    uint32_t impossible_transition_count;
    uint32_t timeout_count;
    uint32_t min_pulse_us;
    uint32_t max_pulse_us;
    uint32_t min_interval_us;
    uint32_t max_interval_us;
    int64_t last_raw_edge_us;
    int64_t last_valid_change_us;
} emc_input_diag_t;

During a glitch storm:

c
input_state = INPUT_DEGRADED_NOISY;
exti_temporarily_mask();
schedule_polled_recovery();
fault_report(FAULT_INPUT_GLITCH_STORM);

4. Common mistakes

text
1. Placing TVS near the MCU.
2. Choosing TVS only by VRWM.
3. Connecting all TVS to sensitive digital GND.
4. Treating ESD, EFT, and surge as the same.
5. Protecting prolonged 24 V connection only with TVS.
6. Using internal GPIO clamps as primary protection.
7. An input capacitor that is too large.
8. Filtering damaging voltage in software.
9. Selecting high GPIO speed everywhere.
10. No idle state when the cable is disconnected.
11. Ignoring RS-485/CAN ground differences.
12. Testing interference only with a software generator.

5. Practical assignment for 30-60 minutes

Create EMC_ESD_POLICY.md:

markdown
# EMC / ESD policy
1. Every external connector has a documented threat model.
2. Protection components are placed close to the connector.
3. Transient current return paths do not cross sensitive logic.
4. GPIO internal clamps are not system-level protection.
5. Every input has a defined idle state.
6. Hardware filtering is calculated from useful pulse timing.
7. Software debounce does not replace overvoltage protection.
8. Field and logic grounds are explicitly documented.
9. Every communication interface has an overrun/recovery policy.
10. EMC tests include both hardware survival and functional behavior.

Create a threat table:

markdown
| Interface | Normal signal | Possible fault | Hardware reaction | Firmware reaction |
|---|---|---|---|---|
| RED input | 220 V AC via opto | EFT/glitch | RC + opto + Schmitt | reject short pulse |
| 24 V input | 0/24 V | reverse/36 V | series R + TVS | mark channel fault |
| RS-485 | differential | ESD/surge/DC fault | TVS/fault transceiver | framing/error counters |
| CAN | differential | common-mode pulse | TVS/CMC/isolation | bus-off recovery |
| EC25 UART | logic | ringing | series R, short traces | UART error counters |

Add an emc diag CLI:

text
emc diag:
RED:
raw=12540
valid=11980
rejected=560
glitch_storms=1
min_pulse=42us
max_pulse=10220us
RS485:
frame_errors=2
crc_errors=4
collisions=0
recovery=1

Low-voltage HIL test:

text
stable level;
1 ms pulses;
1-100 us glitches;
a burst of fast pulses;
bouncing near an edge;
a missing expected pulse.

6. Further reading

  • ST AN1709 on EMC.
  • ST AN4899 on GPIO.
  • ESP32 Hardware Design Guidelines.
  • TI reference designs for RS-485 ESD/EFT/surge.

Brief recap

text
external cable
→ connector protection
→ controlled transient return
→ current limiting
→ filtering
→ isolation/protected transceiver
→ Schmitt/digital receiver
→ MCU input
→ timestamp/filter/diagnostics

Main rules:

text
1. Identify the disturbance type before selecting protection.
2. Place TVS near the connector.
3. The transient current path matters as much as the TVS rating.
4. ESD, EFT, surge, and DC fault require different measures.
5. Internal GPIO clamps are not main external protection.
6. Choose RC from useful-signal and disturbance timing.
7. Schmitt trigger prevents repeated switching on a slow edge.
8. A direct mains input requires insulation and safety design.
9. RS-485/CAN protection includes common-mode and ground strategy.
10. Low GPIO speed and series resistors reduce emissions.
11. Firmware should count glitches and errors, not merely hide them.
12. Real EMC resilience is shown by circuit testing, not debounce alone.

12 Brief index of lessons 31-40

text
31. Time architecture: monotonic, UTC, NTP, PPS, drift.
32. UART/RS-485 and Modbus RTU: DE, t1.5/t3.5, CRC, DMA.
33. Low-level crash debug: STM32 HardFault and ESP32 Guru Meditation.
34. MPU and memory protection: XN RAM, read-only config, stack guards.
35. TrustZone/Secure Boot: key isolation and firmware verification.
36. TLS/PKI: CA, hostname, mTLS, certificates, EC25 vs ESP32 TLS.
37. Secure commands: HMAC, signature, anti-replay, idempotency.
38. Deterministic memory: static allocation, object pools, heap budget.
39. Brownout and power: EC25 peak current, power-good, safe shutdown.
40. EMC/ESD: TVS, RC, Schmitt, industrial inputs, CAN/RS-485 protection.

Exercise

Compare a low-voltage glitch HIL test with an EMC protection test. What does each prove, and why is more software debounce insufficient?

Self-check criteria: Keep the low-voltage-only boundary; do not introduce mains/breadboard experiments or claim hardware immunity from software success.

Show the supplied answer

A controlled low-voltage test verifies timestamps, filtering, counters, conflict handling, and recovery. It does not prove survival of ESD/EFT/surge energy or DC faults. Protection must limit/divert energy at the connector and receive appropriate hardware validation.

Exercise

Trace a connector-side TVS transient return path. What happens if its current crosses sensitive digital ground?

Self-check criteria: Discuss placement and current-loop inductance, not just TVS voltage; distinguish common-mode disturbance from differential filtering.

Show the supplied answer

Identify field/chassis/isolated/digital/analog ground strategy and the shortest appropriate return path. Large transient current crossing digital ground can shift the logic reference and cause false events or resets even when TVS clamps locally.