AAR — Accelerated address resolver

Accelerated address resolver is a cryptographic support function for implementing the Resolvable Private Address Resolution Procedure described in the Bluetooth Core specification.

The main features of AAR are:

The procedure allows two devices that share a secret key to generate and resolve a hash based on their device address. AAR enables real-time address resolution on incoming packets when configured as described in this chapter. This allows real-time packet filtering (whitelisting) using a list of known shared keys (Identity Resolving Keys (IRK) in Bluetooth).

The inputs and outputs of AAR are illustrated in the following figure.

Figure 1. AAR block diagram


Shared resources

AAR shares the same AES module as the ECB and CCM peripherals. ECB will always have the lowest priority. If there is a sharing conflict during encryption, ECB operation will be aborted and an ERRORECB event will be generated by ECB.

Additionally, AAR shares registers and other resources with the peripherals that have the same ID as AAR. See Peripherals with shared ID for more information.

Resolving a resolvable address

As per Bluetooth specification, a private resolvable address is composed of six bytes.

Figure 2. Resolvable address

A private resolvable address composed of 6 bytes.

To resolve an address, IN.PTR must point to a job list describing both the Hash and Prand parts of the private resolvable address (DEVICEADDR) field from the Bluetooth packet, as well as a number of Identity Resolving Keys (IRK). This is illustrated in the examples below. How many IRKs are used is determined by the number of IRKs in the job list. See EasyDMA for an introduction to EasyDMA job lists.

The resolver is started by triggering the START task. A RESOLVED event is generated if AAR manages to resolve the address using one of the Identity Resolving Keys (IRK). AAR will generate a NOTRESOLVED event if it is not able to resolve the address using the specified list of IRKs. If there are no IRKs in the joblist, the NOTRESOLVED event is generated.

Figure 3. Address resolution with 16 IRKs and DEVICEADDR preloaded into RAM

Address resolution with packet preloaded into RAM

Figure 4. Address resolution with packet device address preloaded into multiple RAM locations, and three IRK keys

Address resolution with packet device address preloaded into multiple RAM locations, and three IRK keys

AAR will go through the list of available IRKs in the job list, and for each IRK try to resolve the address according to the Resolvable Private Address Resolution Procedure described in the Bluetooth Specification1. The time it takes to resolve an address may vary depending on where in the list the resolvable address is located. The resolution time will also be affected by RAM accesses performed by other peripherals and the CPU. See the Electrical specifications for more information about resolution time.
Note: Maximum number of IRKs supported in a job list is 4096.

AAR only compares the received address to those programmed in the module without checking the address type.

AAR will stop when it has managed to resolve the maximum number allowed, specified in the MAXRESOLVED register. Each time AAR resolves an IRK, the index of the corresponding IRK is written to memory through the output job list in OUT.PTR. For each IRK found, OUT.AMOUNT is updated accordingly.

The output job list must define a memory region large enough to hold list of resolved IRK indices. This is calculated from the MAXRESOLVED register, where each IRK index occupies two bytes in memory. In the example below, the n indicates the number of bytes (size) in the resolved IRK index array. The value of n must be exactly 2 times the value of MAXRESOLVED.
Figure 5. Resolved IRK index structure at RAM

Resolved IRK index structure at RAM

At the end of the operation, AAR will generate the END event.

Triggering the STOP task will stop AAR. If AAR is stopped before the operation has completed, the END, RESOLVED, and NOTRESOLVED events are not generated. However, if STOP is triggered close to the end of the operation the events can be generated.

1 Bluetooth Specification Version 4.0 [Vol 3] chapter 10.8.2.3.

EasyDMA

This peripheral implements EasyDMA with scatter-gather functionality for reading from memory without CPU involvement.

The scatter-gather functionality allows EasyDMA to collect data from multiple memory regions, instead of one contiguous block. The memory regions are described by a job list, called input job list. The job list consists of one or more job entries that consist of a 32-bit address field, 8-bit attribute field, and 24-bit length field. A job list ends with a zero filled job entry.

The input job list must have separate entries for the following entries:
  1. The three first bytes of the resolvable private address (the 24-bit hash)
  2. The three following bytes of the resolvable private address (the 24-bit prand)
  3. The IRKs
The attribute field of each of these entries identify the input job and must be set according to the following table.
Table 1. Attribute field for input job list
AttributeValue
Hash11
Prand12
Irk13

If the IN.PTR register or the entries in the input job list are not pointing to memory connected to the DMA bus, an EasyDMA transfer may result in a HardFault or memory corruption. See Memory for more information about the different memory regions and DMA connectivity.

The EasyDMA will have finished accessing the RAM when the END, RESOLVED, or NOTRESOLVED events are generated.

For instances supporting DMA error detection, the ERRORSTATUS register will report if a bus error has occurred during DMA access. To see if DMA error detection is supported, see the the instance's configuration in Instantiation.

The list of the resolved IRK indices are stored in memory using the output job list, configured by OUT.PTR.
Table 2. Attribute field for output job list
AttributeValue
Resolved Irk index11

Example

The figure below shows an example of a job list with three job entries. Each of the entries point to a memory address, and the length field describes how many bytes of data is stored at that address. There are three blocks of memory in use
  • Hash, an array of length 3
  • Prand, an array of length 3
  • Irk, an array of at least length 16
The data pointed to from the job list is what is fed into the module and processed according to the peripheral's operation. The entries of the job list comprises pointers to the individual arrays, as well as their sizes. Job entries with length greater than one are processed in little endian order.
Figure 6. EasyDMA Scatter-Gather job list example

EasyDMA Scatter-Gather job list example

Use case example for chaining RADIO packet reception with address resolution using AAR

AAR may be started as soon as the 6 bytes required by AAR have been received by RADIO and stored in RAM. The Hash and Prand part of the job list must point to the part of the packet containing the device address.

Figure 7. Address resolution with packet loaded into RAM by RADIO

Address resolution with packet loaded into RAM by RADIO

Registers

Instances

InstanceDomainBase addressTrustZoneSplit accessDescription
MapAttDMA

AAR00 : S
AAR00 : NS

GLOBAL

0x50046000
0x40046000

USSSANo

Accelerated address resolver 00

Configuration

InstanceDomainConfiguration

AAR00 : S
AAR00 : NS

GLOBAL

Register overview

RegisterOffsetTZDescription
TASKS_START0x000

Start resolving addresses based on IRKs specified in the IRK data structure

TASKS_STOP0x004

Stop resolving addresses

SUBSCRIBE_START0x080

Subscribe configuration for task START

SUBSCRIBE_STOP0x084

Subscribe configuration for task STOP

EVENTS_END0x100

Address resolution procedure complete or ended due to an error

EVENTS_RESOLVED0x104

Address resolved

EVENTS_NOTRESOLVED0x108

Address not resolved

EVENTS_ERROR0x10C

Operation aborted because of a STOP task or due to an error

This event does not generate an interrupt

PUBLISH_END0x180

Publish configuration for event END

PUBLISH_RESOLVED0x184

Publish configuration for event RESOLVED

PUBLISH_NOTRESOLVED0x188

Publish configuration for event NOTRESOLVED

PUBLISH_ERROR0x18C

Publish configuration for event ERROR

INTENSET0x304

Enable interrupt

INTENCLR0x308

Disable interrupt

ERRORSTATUS0x404

Error status

ENABLE0x500

Enable AAR

MAXRESOLVED0x508

Maximum number of IRKs to resolve

IN.PTR0x530

Input pointer

OUT.PTR0x538

Output pointer

OUT.AMOUNT0x53C

Number of bytes transferred in the last transaction

TASKS_START

Address offset: 0x000

Start resolving addresses based on IRKs specified in the IRK data structure

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

W

TASKS_START

Start resolving addresses based on IRKs specified in the IRK data structure

Trigger

1

Trigger task

TASKS_STOP

Address offset: 0x004

Stop resolving addresses

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

W

TASKS_STOP

Stop resolving addresses

Trigger

1

Trigger task

SUBSCRIBE_START

Address offset: 0x080

Subscribe configuration for task START

Bit number313029282726252423222120191817161514131211109876543210
IDBAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

CHIDX

[0..255]

DPPI channel that task START will subscribe to

B

RW

EN

Disabled

0

Disable subscription

Enabled

1

Enable subscription

SUBSCRIBE_STOP

Address offset: 0x084

Subscribe configuration for task STOP

Bit number313029282726252423222120191817161514131211109876543210
IDBAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

CHIDX

[0..255]

DPPI channel that task STOP will subscribe to

B

RW

EN

Disabled

0

Disable subscription

Enabled

1

Enable subscription

EVENTS_END

Address offset: 0x100

Address resolution procedure complete or ended due to an error

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

EVENTS_END

Address resolution procedure complete or ended due to an error

NotGenerated

0

Event not generated

Generated

1

Event generated

EVENTS_RESOLVED

Address offset: 0x104

Address resolved

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

EVENTS_RESOLVED

Address resolved

NotGenerated

0

Event not generated

Generated

1

Event generated

EVENTS_NOTRESOLVED

Address offset: 0x108

Address not resolved

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

EVENTS_NOTRESOLVED

Address not resolved

NotGenerated

0

Event not generated

Generated

1

Event generated

EVENTS_ERROR

Address offset: 0x10C

Operation aborted because of a STOP task or due to an error

This event does not generate an interrupt

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

EVENTS_ERROR

Operation aborted because of a STOP task or due to an error

This event does not generate an interrupt

NotGenerated

0

Event not generated

Generated

1

Event generated

PUBLISH_END

Address offset: 0x180

Publish configuration for event END

Bit number313029282726252423222120191817161514131211109876543210
IDBAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

CHIDX

[0..255]

DPPI channel that event END will publish to

B

RW

EN

Disabled

0

Disable publishing

Enabled

1

Enable publishing

PUBLISH_RESOLVED

Address offset: 0x184

Publish configuration for event RESOLVED

Bit number313029282726252423222120191817161514131211109876543210
IDBAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

CHIDX

[0..255]

DPPI channel that event RESOLVED will publish to

B

RW

EN

Disabled

0

Disable publishing

Enabled

1

Enable publishing

PUBLISH_NOTRESOLVED

Address offset: 0x188

Publish configuration for event NOTRESOLVED

Bit number313029282726252423222120191817161514131211109876543210
IDBAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

CHIDX

[0..255]

DPPI channel that event NOTRESOLVED will publish to

B

RW

EN

Disabled

0

Disable publishing

Enabled

1

Enable publishing

PUBLISH_ERROR

Address offset: 0x18C

Publish configuration for event ERROR

Bit number313029282726252423222120191817161514131211109876543210
IDBAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

CHIDX

[0..255]

DPPI channel that event ERROR will publish to

B

RW

EN

Disabled

0

Disable publishing

Enabled

1

Enable publishing

INTENSET

Address offset: 0x304

Enable interrupt

Bit number313029282726252423222120191817161514131211109876543210
IDDCBA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW
W1S

END

Write '1' to enable interrupt for event END

Set

1

Enable

Disabled

0

Read: Disabled

Enabled

1

Read: Enabled

B

RW
W1S

RESOLVED

Write '1' to enable interrupt for event RESOLVED

Set

1

Enable

Disabled

0

Read: Disabled

Enabled

1

Read: Enabled

C

RW
W1S

NOTRESOLVED

Write '1' to enable interrupt for event NOTRESOLVED

Set

1

Enable

Disabled

0

Read: Disabled

Enabled

1

Read: Enabled

D

RW
W1S

ERROR

Write '1' to enable interrupt for event ERROR

Set

1

Enable

Disabled

0

Read: Disabled

Enabled

1

Read: Enabled

INTENCLR

Address offset: 0x308

Disable interrupt

Bit number313029282726252423222120191817161514131211109876543210
IDDCBA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW
W1C

END

Write '1' to disable interrupt for event END

Clear

1

Disable

Disabled

0

Read: Disabled

Enabled

1

Read: Enabled

B

RW
W1C

RESOLVED

Write '1' to disable interrupt for event RESOLVED

Clear

1

Disable

Disabled

0

Read: Disabled

Enabled

1

Read: Enabled

C

RW
W1C

NOTRESOLVED

Write '1' to disable interrupt for event NOTRESOLVED

Clear

1

Disable

Disabled

0

Read: Disabled

Enabled

1

Read: Enabled

D

RW
W1C

ERROR

Write '1' to disable interrupt for event ERROR

Clear

1

Disable

Disabled

0

Read: Disabled

Enabled

1

Read: Enabled

ERRORSTATUS

Address offset: 0x404

Error status

Bit number313029282726252423222120191817161514131211109876543210
IDAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

R

ERRORSTATUS

Error status when the ERROR event is generated

NoError

0

No errors have occurred

PrematureInptrEnd

1

End of INPTR job list before data structure was read.

DmaError

4

Bus error during DMA access.

ENABLE

Address offset: 0x500

Enable AAR

Bit number313029282726252423222120191817161514131211109876543210
IDAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

ENABLE

Enable or disable AAR

Disabled

0

Disable

Enabled

3

Enable

MAXRESOLVED

Address offset: 0x508

Maximum number of IRKs to resolve

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAA
Reset 0x0000000100000000000000000000000000000001
IDR/WFieldValue IDValueDescription
A

RW

MAXRESOLVED

1..4095

The maximum number of IRKs to resolve

After MAXRESOLVED number of IRKs have been resolved, AAR will stop processing and generate the END event

IN

IN EasyDMA channel

IN.PTR

Address offset: 0x530

Input pointer

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

PTR

Points to a job list containing AAR data structure

OUT

OUT EasyDMA channel

OUT.PTR

Address offset: 0x538

Output pointer

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

PTR

Output pointer

OUT.AMOUNT

Address offset: 0x53C

Number of bytes transferred in the last transaction

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

R

AMOUNT

[1..255]

Number of bytes written to memory after triggering the START task.

Each resolved IRK index uses two bytes.