KMU — Key management unit
The key management unit (KMU) provides secure key storage functions by storing data in a dedicated region of RRAM.
The secure information configuration region, SICR, is the RRAM region that holds keys seeds, and metadata. Access to KMU and the key slots in SICR is only allowed from secure mode. KMU has exclusive access to SICR, meaning the rest of the system does not have access. The KMU stores data in key slots that hold one 128-bit value together with an access policy and a destination address for the key value. Multiple key slots can be combined to hold key sizes larger than 128 bits. How and when a key value can be used is determined by the access policy. When requested by the CPU, the destination address, which is part of the key slot, determines the memory map location for the key value that is pushed by KMU.
Key slots can be configured to be pushed directly into write-only key registers or RAM of cryptographic accelerators like CRACEN, without revealing the key value to the CPU. This enables the CPU to use the key values stored inside the key slots for cryptographic operations without knowing the key value.
KMU can also store other secrets, like the CRACEN SEED register, using multiple key slots.
A good design practice is to overwrite previously pushed secrets when they are no longer in use. KMU can be used for this, by pushing key slots with previously generated random data to the key RAM.
Key slot
A key slot stores secure assets and up to 32 bits of additional metadata. Assets greater than 128 bits must be divided and distributed over multiple key slot instances.
The following table summarizes what can be stored in a key slot.
| Field | Size [bits] | Description |
|---|---|---|
| METADATA | 32 | A text field that can be used for any purpose. This field can be read by secure code using the READMETADATA task. |
| DEST | 32 | The destination address used for the push, and used by the PUSH operation. |
| VALUE | 128 | The secure asset. This field cannot be read, only pushed to its destination address using the PUSH task. |
| RPOLICY | 2 | The revocation policy for the key slot. See Provisioning for a detailed definition of this field. |
Key slot states
KMU maintains the key slot state.
The following figure shows the key slot states and how they transition through the device life cycle.
Operations
KMU has operations to store, use, and remove assets.
| Operation | Description |
|---|---|
| Provision | Store assets in SICR |
| Push | Retrieve assets from SICR and push to write-only registers or memory for use |
| Read metadata | Read key slot metadata from SICR |
| Revoke | Remove an asset from SICR |
| Block | Block a keyslot from being pushed, provisioned, or revoked until next reset |
| Push block | Block a key slot by preventing a push until next reset |
KMU allows a single operation to run at a time. Once a TASK is triggered to start an operation, KMU ignores any subsequent TASK requests until the initial operation is complete.
Provisioning
Provisioning is the storage of an asset in SICR. During provisioning, KMU copies data and permission policy from RAM to SICR.
Provisioning a key slot is possible when the key slot is in the ERASED state.
- Populate the SRC data struct as an array in RAM.
- Write the SRC register to the address of the SRC data in RAM. See the following table for SRC data details.
- Configure the key slot ID in the KEY SLOT register.
- Using the RRAM controller, enable unbuffered RRAM write using register RRAMC.CONFIG. For more details on RRAMC, see RRAMC — Resistive random access memory controller.
- Trigger the PROVISION task. KMU writes data to SICR.
If copying of data was successful, KMU generates the PROVISIONED event, otherwise KMU generates the ERROR event.
- Disable the RRAM write operation. For details, see RRAMC — Resistive random access memory controller.
If a power failure occurs during provisioning, KMU will not write key slot data to RRAM and the key slot is not provisioned.
For more details on how to detect power failures, see Power-fail comparator.
The following lists the SRC data used for provisioning.
| Field | Byte offset | Size [bytes] | Description |
|---|---|---|---|
| METADATA | 24 | 4 | 32 bits of any cleartext metadata that belongs with the key slot. This metadata can later be read using the READMETADATA task (for details, see Read metadata). |
| DEST | 20 | 4 | 32-bit destination address. Note that DEST cannot point to SICR. DEST must be on a 128-bit boundary. |
| RPOLICY | 16 | 4 | Revocation policy (same definition as the key slot RPOLICY
field). Only two LSB's of the field are used, unused bits shall be
set to zero.
|
| VALUE[3:0] | 0 | 16 | Asset contents/value. This value can later be used by the PUSH task (for details, see Push). |
Push
Retrieving an asset from SICR is called a push. During a push, KMU copies data from SICR to the destination address that was determined during provisioning.
A key slot can be pushed only when it is in the PROVISIONED state and if it is not push-blocked. For more details on push-block, see Push block.
If the push is successful, KMU generates the PUSHED event. If the keyslot is in the REVOKED state, KMU generates the REVOKED event. If unsuccessful, KMU generates the ERROR event.
Read metadata
Each key slot has a 32-bit metadata field that can be read.
The metadata field is the same 32-bit field that is provisioned, see Provisioning.
When reading the metadata, KMU copies the key slot metadata from SICR to the METADATA register.
Key slot metadata can be read when the key slot is in the PROVISIONED state.
- Configure the key slot ID in the KEYSLOT register.
- Trigger the READMETADATA task.
If the key slot is revoked, KMU generates the REVOKED event and ends the operation.
If the key slot has not been provisioned, KMU generates the ERROR event and ends the operation.
Revoke
A key slot that is revoked it can no longer be pushed.
A key slot can be revoked when it is in the PROVISIONED state or when its revocation policy is not LOCKED.
- Configure the key slot ID in the KEYSLOT register.
- Enable RRAM write operation in Normal write mode. For details, see RRAMC — Resistive random access memory controller.
- Trigger the REVOKE task.
KMU erases the asset from SICR. If revoking the key slot is successful, KMU generates the REVOKED event. If unsuccessful, or the key slot is already in the REVOKED state, KMU generates the ERROR event.
- Disable RRAM write operation. For details, see RRAMC — Resistive random access memory controller.
Push block
Push block prevents a key slot from being pushed until the next device reset.
A key slot must be in the PROVISIONED state for a push block to take effect.
- Configure the key slot ID in the KEYSLOT register.
- Trigger the PUSHBLOCK task.
When the push block has been applied, KMU generates the PUSHBLOCKED event.
Registers
Instances
| Instance | Domain | Base address | TrustZone | Split access | Description | ||
|---|---|---|---|---|---|---|---|
| Map | Att | DMA | |||||
| KMU | GLOBAL | 0x50045000 | HF | S | NSA | No | Key management unit |
Configuration
| Instance | Domain | Configuration |
|---|---|---|
| KMU | GLOBAL | Number of keyslots is 250 Number of bits per keyslot is 128 |
Register overview
| Register | Offset | TZ | Description |
|---|---|---|---|
| TASKS_PROVISION | 0x0000 | Provision key slot | |
| TASKS_PUSH | 0x0004 | Push key slot | |
| TASKS_REVOKE | 0x0008 | Revoke key slot | |
| TASKS_READMETADATA | 0x000C | Read key slot metadata into METADATA register | |
| TASKS_PUSHBLOCK | 0x0010 | Block only the PUSH operation of a key slot, preventing the key slot from being PUSHED until next reset. The task is kept for backwards compatibility. | |
| EVENTS_PROVISIONED | 0x100 | Key slot successfully provisioned | |
| EVENTS_PUSHED | 0x104 | Key slot successfully pushed | |
| EVENTS_REVOKED | 0x108 | Key slot has been revoked and can no longer be used | |
| EVENTS_ERROR | 0x10C | Error generated during PROVISION, PUSH, READMETADATA or REVOKE operations. Triggering the PROVISION, PUSH and REVOKE tasks on a BLOCKED keyslot will also generate this event. | |
| EVENTS_METADATAREAD | 0x110 | Key slot metadata has been read into METADATA register | |
| EVENTS_PUSHBLOCKED | 0x114 | The PUSHBLOCK operation was successful. The event is kept for backwards compatibility. | |
| STATUS | 0x400 | KMU status register | |
| KEYSLOT | 0x500 | Select key slot to operate on | |
| SRC | 0x504 | Source address for provisioning | |
| METADATA | 0x508 | Key slot metadata as read by TASKS_READMETADATA. |
TASKS_PROVISION
Address offset: 0x0000
Provision key slot
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | A | ||||||||||||||||||||||||||||||||||
| Reset 0x00000000 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | W | TASKS_PROVISION | Provision key slot | ||||||||||||||||||||||||||||||||
Trigger | 1 | Trigger task | |||||||||||||||||||||||||||||||||
TASKS_PUSH
Address offset: 0x0004
Push key slot
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | A | ||||||||||||||||||||||||||||||||||
| Reset 0x00000000 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | W | TASKS_PUSH | Push key slot | ||||||||||||||||||||||||||||||||
Trigger | 1 | Trigger task | |||||||||||||||||||||||||||||||||
TASKS_REVOKE
Address offset: 0x0008
Revoke key slot
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | A | ||||||||||||||||||||||||||||||||||
| Reset 0x00000000 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | W | TASKS_REVOKE | Revoke key slot | ||||||||||||||||||||||||||||||||
Trigger | 1 | Trigger task | |||||||||||||||||||||||||||||||||
TASKS_READMETADATA
Address offset: 0x000C
Read key slot metadata into METADATA register
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | A | ||||||||||||||||||||||||||||||||||
| Reset 0x00000000 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | W | TASKS_READMETADATA | Read key slot metadata into METADATA register | ||||||||||||||||||||||||||||||||
Trigger | 1 | Trigger task | |||||||||||||||||||||||||||||||||
TASKS_PUSHBLOCK
Address offset: 0x0010
Block only the PUSH operation of a key slot, preventing the key slot from being PUSHED until next reset. The task is kept for backwards compatibility.
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | A | ||||||||||||||||||||||||||||||||||
| Reset 0x00000000 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | W | TASKS_PUSHBLOCK | Block only the PUSH operation of a key slot, preventing the key slot from being PUSHED until next reset. The task is kept for backwards compatibility. | ||||||||||||||||||||||||||||||||
Trigger | 1 | Trigger task | |||||||||||||||||||||||||||||||||
EVENTS_PROVISIONED
Address offset: 0x100
Key slot successfully provisioned
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | A | ||||||||||||||||||||||||||||||||||
| Reset 0x00000000 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | RW | EVENTS_PROVISIONED | Key slot successfully provisioned | ||||||||||||||||||||||||||||||||
NotGenerated | 0 | Event not generated | |||||||||||||||||||||||||||||||||
Generated | 1 | Event generated | |||||||||||||||||||||||||||||||||
EVENTS_PUSHED
Address offset: 0x104
Key slot successfully pushed
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | A | ||||||||||||||||||||||||||||||||||
| Reset 0x00000000 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | RW | EVENTS_PUSHED | Key slot successfully pushed | ||||||||||||||||||||||||||||||||
NotGenerated | 0 | Event not generated | |||||||||||||||||||||||||||||||||
Generated | 1 | Event generated | |||||||||||||||||||||||||||||||||
EVENTS_REVOKED
Address offset: 0x108
Key slot has been revoked and can no longer be used
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | A | ||||||||||||||||||||||||||||||||||
| Reset 0x00000000 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | RW | EVENTS_REVOKED | Key slot has been revoked and can no longer be used | ||||||||||||||||||||||||||||||||
NotGenerated | 0 | Event not generated | |||||||||||||||||||||||||||||||||
Generated | 1 | Event generated | |||||||||||||||||||||||||||||||||
EVENTS_ERROR
Address offset: 0x10C
Error generated during PROVISION, PUSH, READMETADATA or REVOKE operations. Triggering the PROVISION, PUSH and REVOKE tasks on a BLOCKED keyslot will also generate this event.
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | A | ||||||||||||||||||||||||||||||||||
| Reset 0x00000000 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | RW | EVENTS_ERROR | Error generated during PROVISION, PUSH, READMETADATA or REVOKE operations. Triggering the PROVISION, PUSH and REVOKE tasks on a BLOCKED keyslot will also generate this event. | ||||||||||||||||||||||||||||||||
NotGenerated | 0 | Event not generated | |||||||||||||||||||||||||||||||||
Generated | 1 | Event generated | |||||||||||||||||||||||||||||||||
EVENTS_METADATAREAD
Address offset: 0x110
Key slot metadata has been read into METADATA register
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | A | ||||||||||||||||||||||||||||||||||
| Reset 0x00000000 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | RW | EVENTS_METADATAREAD | Key slot metadata has been read into METADATA register | ||||||||||||||||||||||||||||||||
NotGenerated | 0 | Event not generated | |||||||||||||||||||||||||||||||||
Generated | 1 | Event generated | |||||||||||||||||||||||||||||||||
EVENTS_PUSHBLOCKED
Address offset: 0x114
The PUSHBLOCK operation was successful. The event is kept for backwards compatibility.
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | A | ||||||||||||||||||||||||||||||||||
| Reset 0x00000000 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | RW | EVENTS_PUSHBLOCKED | The PUSHBLOCK operation was successful. The event is kept for backwards compatibility. | ||||||||||||||||||||||||||||||||
NotGenerated | 0 | Event not generated | |||||||||||||||||||||||||||||||||
Generated | 1 | Event generated | |||||||||||||||||||||||||||||||||
STATUS
Address offset: 0x400
KMU status register
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | A | ||||||||||||||||||||||||||||||||||
| Reset 0x00000000 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | R | STATUS | KMU status | ||||||||||||||||||||||||||||||||
Ready | 0 | KMU is ready for new operation | |||||||||||||||||||||||||||||||||
Busy | 1 | KMU is busy, an operation is in progress | |||||||||||||||||||||||||||||||||
KEYSLOT
Address offset: 0x500
Select key slot to operate on
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | A | A | A | A | A | A | A | A | |||||||||||||||||||||||||||
| Reset 0x00000000 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | RW | ID | 0..249 | Select key slot ID to provision, push, read METADATA, revoke or block when the corresponding task is triggered. | |||||||||||||||||||||||||||||||
SRC
Address offset: 0x504
Source address for provisioning
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | |||
| Reset 0x00000000 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | RW | SRC | Source address for TASKS_PROVISION. | ||||||||||||||||||||||||||||||||
METADATA
Address offset: 0x508
Key slot metadata as read by TASKS_READMETADATA.
When EVENTS_METADATA has been generated, this register holds the key slot metadata.
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | |||
| Reset 0x00000000 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | RW | METADATA | Read metadata. | ||||||||||||||||||||||||||||||||