TrustZone security

The security architecture is based on Arm TrustZone.

The Arm Cortex-M based CPU supports Arm TrustZone for secure, non-secure, and non-secure callable memory regions.

The security attribution unit (SAU) and implementation defined attribution unit (IDAU) define the access permissions based on the security state.

The IDAU configuration divides system memory space into secure (S) and non-secure (NS) regions. The SAU provides configurable regions for the Arm Cortex-M CPU, and is used to define non-secure callable (NSC) regions.

IDAU preset configuration

IDAU configuration is preset in hardware and is not available for user configuration. The security attribution follows the address map, and the peripheral memory space is aliased for the secure and non-secure memory state, as defined in the following table.
Table 4. IDAU configuration
Memory map nameAddress mapIDAU TrustZone security attribute
Private peripheral bus0xE0000000 – 0xFFFFFFFFNot applicable
Device memory0xA0000000 – 0xDFFFFFFFNS
External memory0x60000000 – 0xAFFFFFFFNS
Peripheral (secure)0x50000000 – 0x5FFFFFFFS
Peripheral (non-secure)0x40000000 – 0x4FFFFFFFNS
Data memory0x20000000 – 0x3FFFFFFFNS
Program memory0x00000000 – 0x1FFFFFFFNS

SAU configuration

The Arm Cortex-M33 CPU must configure its SAU regions when the CPU starts. The CPU assumes the memory map is secure before configuring the SAU regions.

SAU configuration registers are documented in the Arm Cortex-M33 Technical Reference Manual.

TrustZone security attributes

Based on IDAU and SAU configuration, the following table shows the TrustZone security attribute results.
Table 5. TrustZone security attributes
IDAU security attributeSAU security attributeSecurity attribute result
SNS, NSC, or SS
NS, NSC, or SSS
NSNSNS
NSNSCNSC

For the memory region that contains the secure gateway instruction branch veneers (entry points), the TrustZone security attribute seen by the Arm Cortex-M must be NSC for the secure functions that are callable from a non-secure program.

Example memory map

The following figure shows an example memory map using SAU regions to provide NS, S, and NSC regions. The figure also includes the required MPC override configuration to ensure correct secure/non-secure system partitioning.
Figure 2. Example memory map security attribution
Combining the security attribution from IDAU and SAU to create a complete memory map

TrustZone security access

The Arm Cortex-M TrustZone security module generates a CPU SecureFault exception when access is not allowed. The following table shows combinations of TrustZone security attributes.
Table 6. TrustZone security access
Arm Cortex-M TrustZone security attributeDestination address security attributeSecure faultAccess allowed
SSNoYes
SNSNoYes
NSNSNoYes
NSSYesNo

The first two columns show the TrustZone security attribute from the TrustZone security attributes table.

The Arm Cortex-M TrustZone security attribute is the TrustZone security attribute seen by the Arm Cortex-M CPU while executing a program. This shows if the Arm Cortex-M CPU program is executed from S, NS, or NSC memory. The NSC for the Arm Cortex-M TrustZone security attribute behaves same as S in the table.

The destination address security attribute is the TrustZone security attribute of the destination address lookup from the SAU and IDAU. It is used by the Arm Cortex-M CPU on the bus transaction.