KMU — Key management unit

The key management unit (KMU) provides secure key storage functions by storing data in a dedicated region of RRAM.

The secure information configuration region, SICR, is the RRAM region that holds keys seeds, and metadata. Access to KMU and the key slots in SICR is only allowed from secure mode. KMU has exclusive access to SICR, meaning the rest of the system does not have access. The KMU stores data in key slots that hold one 128-bit value together with an access policy and a destination address for the key value. Multiple key slots can be combined to hold key sizes larger than 128 bits. How and when a key value can be used is determined by the access policy. When requested by the CPU, the destination address, which is part of the key slot, determines the memory map location for the key value that is pushed by KMU.

Key slots can be configured to be pushed directly into write-only key registers or RAM of cryptographic accelerators like CRACEN, without revealing the key value to the CPU. This enables the CPU to use the key values stored inside the key slots for cryptographic operations without knowing the key value.

KMU can also store other secrets, like the CRACEN SEED register, using multiple key slots.

A good design practice is to overwrite previously pushed secrets when they are no longer in use. KMU can be used for this, by pushing key slots with previously generated random data to the key RAM.

Figure 1. Block diagram

Key slot

A key slot stores secure assets and up to 32 bits of additional metadata. Assets greater than 128 bits must be divided and distributed over multiple key slot instances.

The following table summarizes what can be stored in a key slot.

Table 1. Key slot contents
FieldSize [bits]Description
METADATA32A text field that can be used for any purpose. This field can be read by secure code using the READMETADATA task.
DEST32The destination address used for the push, and used by the PUSH operation.
VALUE128The secure asset. This field cannot be read, only pushed to its destination address using the PUSH task.
RPOLICY2The revocation policy for the key slot. See Provisioning for a detailed definition of this field.

Key slot states

KMU maintains the key slot state.

The following figure shows the key slot states and how they transition through the device life cycle.

Figure 2. Key slot states
State diagram of the key slots, showing the transitions between the Erased, Provisioned, and the Revoked states.

Operations

KMU has operations to store, use, and remove assets.

Table 2. KMU operations
OperationDescription
ProvisionStore assets in SICR
PushRetrieve assets from SICR and push to write-only registers or memory for use
Read metadataRead key slot metadata from SICR
RevokeRemove an asset from SICR
BlockBlock a keyslot from being pushed, provisioned, or revoked until next reset
Push blockBlock a key slot by preventing a push until next reset

KMU allows a single operation to run at a time. Once a TASK is triggered to start an operation, KMU ignores any subsequent TASK requests until the initial operation is complete.

Provisioning

Provisioning is the storage of an asset in SICR. During provisioning, KMU copies data and permission policy from RAM to SICR.

Provisioning a key slot is possible when the key slot is in the ERASED state.

To provision an asset, perform the following steps:
  1. Populate the SRC data struct as an array in RAM.
  2. Write the SRC register to the address of the SRC data in RAM. See the following table for SRC data details.
  3. Configure the key slot ID in the KEY SLOT register.
  4. Using the RRAM controller, enable unbuffered RRAM write using register RRAMC.CONFIG. For more details on RRAMC, see RRAMC — Resistive random access memory controller.
  5. Trigger the PROVISION task. KMU writes data to SICR.

    If copying of data was successful, KMU generates the PROVISIONED event, otherwise KMU generates the ERROR event.

  6. Disable the RRAM write operation. For details, see RRAMC — Resistive random access memory controller.

If a power failure occurs during provisioning, KMU will not write key slot data to RRAM and the key slot is not provisioned.

For more details on how to detect power failures, see Power-fail comparator.

The following lists the SRC data used for provisioning.

Table 3. SRC data
FieldByte offsetSize [bytes]Description
METADATA24432 bits of any cleartext metadata that belongs with the key slot. This metadata can later be read using the READMETADATA task (for details, see Read metadata).
DEST20432-bit destination address. Note that DEST cannot point to SICR. DEST must be on a 128-bit boundary.
RPOLICY164Revocation policy (same definition as the key slot RPOLICY field). Only two LSB's of the field are used, unused bits shall be set to zero.
  • '11' REVOKED: When TASKS_REVOKE is triggered, key slot ends up in the Revoked state "forever" (until Erase all).
  • '01' ROTATING: Key Slot can be reused, and when TASKS_REVOKE is triggered, the key slot ends up in the Erased state and can be reused.
  • '10' LOCKED: Key Slot can not be revoked (until Erase all). When TASKS_REVOKE is triggerd, EVENTS_ERROR is generated.
  • '00' RESERVED: Reserved for future use.
The revocation policy affects how the key slot transitions through it states, see Key slot states.
VALUE[3:0]016Asset contents/value. This value can later be used by the PUSH task (for details, see Push).

Push

Retrieving an asset from SICR is called a push. During a push, KMU copies data from SICR to the destination address that was determined during provisioning.

A key slot can be pushed only when it is in the PROVISIONED state and if it is not push-blocked. For more details on push-block, see Push block.

To push a key slot, perform the following steps:
  1. Configure the key slot ID in the KEYSLOT register.
  2. Trigger the PUSH task.

    KMU copies data from SICR.

If the push is successful, KMU generates the PUSHED event. If the keyslot is in the REVOKED state, KMU generates the REVOKED event. If unsuccessful, KMU generates the ERROR event.

Note: Some push operations generate the PUSHED event when data is not successfully copied to the destination. For example, when the CRACEN SEEDLOCK register is set to enabled, write operations to the CRACEN SEED register are ignored.

Read metadata

Each key slot has a 32-bit metadata field that can be read.

The metadata field is the same 32-bit field that is provisioned, see Provisioning.

When reading the metadata, KMU copies the key slot metadata from SICR to the METADATA register.

Key slot metadata can be read when the key slot is in the PROVISIONED state.

Perform the following steps to read key slot metadata.
  1. Configure the key slot ID in the KEYSLOT register.
  2. Trigger the READMETADATA task.

    If the key slot is revoked, KMU generates the REVOKED event and ends the operation.

    If the key slot has not been provisioned, KMU generates the ERROR event and ends the operation.

KMU copies data from SICR into the METADATA register. If copying of data was successful, KMU generates the METADATAREAD event. If unsuccessful, KMU generates the ERROR event.

Revoke

A key slot that is revoked it can no longer be pushed.

A key slot can be revoked when it is in the PROVISIONED state or when its revocation policy is not LOCKED.

To revoke a key slot, perform the following steps:
  1. Configure the key slot ID in the KEYSLOT register.
  2. Enable RRAM write operation in Normal write mode. For details, see RRAMC — Resistive random access memory controller.
  3. Trigger the REVOKE task.

    KMU erases the asset from SICR. If revoking the key slot is successful, KMU generates the REVOKED event. If unsuccessful, or the key slot is already in the REVOKED state, KMU generates the ERROR event.

  4. Disable RRAM write operation. For details, see RRAMC — Resistive random access memory controller.
Rotating key slots are available after a successful revocation. Non-rotating key slots remain in a REVOKED state and can not be used again until SICR is erased. SICR can only be erased using the Erase All functions of CTRL-AP — Control access port and RRAMC — Resistive random access memory controller.

Push block

Push block prevents a key slot from being pushed until the next device reset.

A key slot must be in the PROVISIONED state for a push block to take effect.

To block a key slot from the push operation, perform the following steps:
  1. Configure the key slot ID in the KEYSLOT register.
  2. Trigger the PUSHBLOCK task.

    When the push block has been applied, KMU generates the PUSHBLOCKED event.

Registers

Instances

InstanceDomainBase addressTrustZoneSplit accessDescription
MapAttDMA
KMUGLOBAL0x50045000HFSNSANo

Key management unit

Configuration

InstanceDomainConfiguration
KMUGLOBAL

Number of keyslots is 250

Number of bits per keyslot is 128

Register overview

RegisterOffsetTZDescription
TASKS_PROVISION0x0000

Provision key slot

TASKS_PUSH0x0004

Push key slot

TASKS_REVOKE0x0008

Revoke key slot

TASKS_READMETADATA0x000C

Read key slot metadata into METADATA register

TASKS_PUSHBLOCK0x0010

Block only the PUSH operation of a key slot, preventing the key slot from being PUSHED until next reset. The task is kept for backwards compatibility.

EVENTS_PROVISIONED0x100

Key slot successfully provisioned

EVENTS_PUSHED0x104

Key slot successfully pushed

EVENTS_REVOKED0x108

Key slot has been revoked and can no longer be used

EVENTS_ERROR0x10C

Error generated during PROVISION, PUSH, READMETADATA or REVOKE operations. Triggering the PROVISION, PUSH and REVOKE tasks on a BLOCKED keyslot will also generate this event.

EVENTS_METADATAREAD0x110

Key slot metadata has been read into METADATA register

EVENTS_PUSHBLOCKED0x114

The PUSHBLOCK operation was successful. The event is kept for backwards compatibility.

STATUS0x400

KMU status register

KEYSLOT0x500

Select key slot to operate on

SRC0x504

Source address for provisioning

METADATA0x508

Key slot metadata as read by TASKS_READMETADATA.

TASKS_PROVISION

Address offset: 0x0000

Provision key slot

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

W

TASKS_PROVISION

Provision key slot

Trigger

1

Trigger task

TASKS_PUSH

Address offset: 0x0004

Push key slot

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

W

TASKS_PUSH

Push key slot

Trigger

1

Trigger task

TASKS_REVOKE

Address offset: 0x0008

Revoke key slot

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

W

TASKS_REVOKE

Revoke key slot

Trigger

1

Trigger task

TASKS_READMETADATA

Address offset: 0x000C

Read key slot metadata into METADATA register

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

W

TASKS_READMETADATA

Read key slot metadata into METADATA register

Trigger

1

Trigger task

TASKS_PUSHBLOCK

Address offset: 0x0010

Block only the PUSH operation of a key slot, preventing the key slot from being PUSHED until next reset. The task is kept for backwards compatibility.

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

W

TASKS_PUSHBLOCK

Block only the PUSH operation of a key slot, preventing the key slot from being PUSHED until next reset. The task is kept for backwards compatibility.

Trigger

1

Trigger task

EVENTS_PROVISIONED

Address offset: 0x100

Key slot successfully provisioned

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

EVENTS_PROVISIONED

Key slot successfully provisioned

NotGenerated

0

Event not generated

Generated

1

Event generated

EVENTS_PUSHED

Address offset: 0x104

Key slot successfully pushed

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

EVENTS_PUSHED

Key slot successfully pushed

NotGenerated

0

Event not generated

Generated

1

Event generated

EVENTS_REVOKED

Address offset: 0x108

Key slot has been revoked and can no longer be used

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

EVENTS_REVOKED

Key slot has been revoked and can no longer be used

NotGenerated

0

Event not generated

Generated

1

Event generated

EVENTS_ERROR

Address offset: 0x10C

Error generated during PROVISION, PUSH, READMETADATA or REVOKE operations. Triggering the PROVISION, PUSH and REVOKE tasks on a BLOCKED keyslot will also generate this event.

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

EVENTS_ERROR

Error generated during PROVISION, PUSH, READMETADATA or REVOKE operations. Triggering the PROVISION, PUSH and REVOKE tasks on a BLOCKED keyslot will also generate this event.

NotGenerated

0

Event not generated

Generated

1

Event generated

EVENTS_METADATAREAD

Address offset: 0x110

Key slot metadata has been read into METADATA register

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

EVENTS_METADATAREAD

Key slot metadata has been read into METADATA register

NotGenerated

0

Event not generated

Generated

1

Event generated

EVENTS_PUSHBLOCKED

Address offset: 0x114

The PUSHBLOCK operation was successful. The event is kept for backwards compatibility.

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

EVENTS_PUSHBLOCKED

The PUSHBLOCK operation was successful. The event is kept for backwards compatibility.

NotGenerated

0

Event not generated

Generated

1

Event generated

STATUS

Address offset: 0x400

KMU status register

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

R

STATUS

KMU status

Ready

0

KMU is ready for new operation

Busy

1

KMU is busy, an operation is in progress

KEYSLOT

Address offset: 0x500

Select key slot to operate on

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

ID

0..249

Select key slot ID to provision, push, read METADATA, revoke or block when the corresponding task is triggered.

SRC

Address offset: 0x504

Source address for provisioning

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

SRC

Source address for TASKS_PROVISION.

METADATA

Address offset: 0x508

Key slot metadata as read by TASKS_READMETADATA.

When EVENTS_METADATA has been generated, this register holds the key slot metadata.

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

METADATA

Read metadata.