MPC — Memory Privilege Controller
The MPC peripheral is an address decoder with built-in security functions.
MPC enforces security for system memory access. It is used to divide the address space into smaller regions and assign permissions to these regions.
The main features of MPC are the following:
- Address decoding
- Configurable access permissions
- Error reporting
Override configuration
The MPC overrides are used to divide the address space into smaller regions and assign permissions to these regions.
When the device is reset, the memory in RAM and the non-volatile memory (NVM) is secure. Only secure CPUs and peripherals can read, write, or execute from secure memory.
To configure permission settings in a memory region, perform the following steps.
- Define the memory region by configuring STARTADDR and ENDADDR. The values must be multiples of the override region granularity, which is 4096.
- Use PERMMASK to define which of the access permissions in PERM to apply.
- Enable and lock the override using the CONFIG register.
To prevent unintended reconfiguration of MPC, all overrides should be safeguarded by using the LOCK bit in the CONFIG register.
Access blocking
Dedicated override regions can be used to block access to a memory region. See the MPC configuration table for which overrides are capable of access blocking.
MPC error reporting
MPC reports an error when an access violation is detected.
- The address cannot be decoded or the bus Manager does not have permissions to access the Subordinate. When this happens, the MEMACCERR.ADDRESS will capture the failing address issued by the bus Manager port and MEMACCERR.INFO will capture additional access information for the attempted transaction.
- If a transaction is routed to a Subordinate, but the Subordinate responds with an error.
Registers
Instances
| Instance | Domain | Base address | TrustZone | Split access | Description | ||
|---|---|---|---|---|---|---|---|
| Map | Att | DMA | |||||
| MPC00 | GLOBAL | 0x50041000 | HF | S | NA | No | Memory privilege controller MPC00 |
Configuration
| Instance | Domain | Configuration |
|---|---|---|
| MPC00 | GLOBAL | The override region granularity is 4096 bytes Overrides 0 through 6 are available for override configuration. Override 7 can be configured for access blocking. Overrides 8 through 11 are reserved by the system and cannot be configured. |
Register overview
| Register | Offset | TZ | Description |
|---|---|---|---|
| EVENTS_MEMACCERR | 0x100 | Memory Access Error event | |
| INTEN | 0x300 | Enable or disable interrupt | |
| INTENSET | 0x304 | Enable interrupt | |
| INTENCLR | 0x308 | Disable interrupt | |
| MEMACCERR.ADDRESS | 0x400 | Target Address of Memory Access Error. Register content will not be changed as long as MEMACCERR event is active. | |
| MEMACCERR.INFO | 0x404 | Access information for the transaction that triggered a memory access error. Register content will not be changed as long as MEMACCERR event is active. | |
| OVERRIDE[n].CONFIG | 0x800 | Override region n Configuration register | |
| OVERRIDE[n].STARTADDR | 0x804 | Override region n Start Address | |
| OVERRIDE[n].ENDADDR | 0x808 | Override region n End Address | |
| OVERRIDE[n].PERM | 0x810 | Permission settings for override region n | |
| OVERRIDE[n].PERMMASK | 0x814 | Masks permission setting fields from register OVERRIDE.PERM |
EVENTS_MEMACCERR
Address offset: 0x100
Memory Access Error event
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | A | ||||||||||||||||||||||||||||||||||
| Reset 0x00000000 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | RW | EVENTS_MEMACCERR | Memory Access Error event | ||||||||||||||||||||||||||||||||
NotGenerated | 0 | Event not generated | |||||||||||||||||||||||||||||||||
Generated | 1 | Event generated | |||||||||||||||||||||||||||||||||
INTEN
Address offset: 0x300
Enable or disable interrupt
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | A | ||||||||||||||||||||||||||||||||||
| Reset 0x00000000 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | RW | MEMACCERR | Enable or disable interrupt for event MEMACCERR | ||||||||||||||||||||||||||||||||
Disabled | 0 | Disable | |||||||||||||||||||||||||||||||||
Enabled | 1 | Enable | |||||||||||||||||||||||||||||||||
INTENSET
Address offset: 0x304
Enable interrupt
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | A | ||||||||||||||||||||||||||||||||||
| Reset 0x00000000 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | RW | MEMACCERR | Write '1' to enable interrupt for event MEMACCERR | ||||||||||||||||||||||||||||||||
Set | 1 | Enable | |||||||||||||||||||||||||||||||||
Disabled | 0 | Read: Disabled | |||||||||||||||||||||||||||||||||
Enabled | 1 | Read: Enabled | |||||||||||||||||||||||||||||||||
INTENCLR
Address offset: 0x308
Disable interrupt
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | A | ||||||||||||||||||||||||||||||||||
| Reset 0x00000000 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | RW | MEMACCERR | Write '1' to disable interrupt for event MEMACCERR | ||||||||||||||||||||||||||||||||
Clear | 1 | Disable | |||||||||||||||||||||||||||||||||
Disabled | 0 | Read: Disabled | |||||||||||||||||||||||||||||||||
Enabled | 1 | Read: Enabled | |||||||||||||||||||||||||||||||||
MEMACCERR
Memory Access Error status registers
MEMACCERR.ADDRESS
Address offset: 0x400
Target Address of Memory Access Error. Register content will not be changed as long as MEMACCERR event is active.
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | |||
| Reset 0x00000000 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | R | ADDRESS | Target address for erroneous access | ||||||||||||||||||||||||||||||||
MEMACCERR.INFO
Address offset: 0x404
Access information for the transaction that triggered a memory access error. Register content will not be changed as long as MEMACCERR event is active.
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | E | D | C | B | A | ||||||||||||||||||||||||||||||
| Reset 0x00000000 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | R | READ | Read bit of bus access | ||||||||||||||||||||||||||||||||
Set | 1 | Read access bit was set | |||||||||||||||||||||||||||||||||
NotSet | 0 | Read access bit was not set | |||||||||||||||||||||||||||||||||
| B | R | WRITE | Write bit of bus access | ||||||||||||||||||||||||||||||||
Set | 1 | Write access bit was set | |||||||||||||||||||||||||||||||||
NotSet | 0 | Write access bit was not set | |||||||||||||||||||||||||||||||||
| C | R | EXECUTE | Execute bit of bus access | ||||||||||||||||||||||||||||||||
Set | 1 | Execute access bit was set | |||||||||||||||||||||||||||||||||
NotSet | 0 | Execute access bit was not set | |||||||||||||||||||||||||||||||||
| D | R | SECURE | Secure bit of bus access | ||||||||||||||||||||||||||||||||
Set | 1 | Secure access bit was set | |||||||||||||||||||||||||||||||||
NotSet | 0 | Secure access bit was not set | |||||||||||||||||||||||||||||||||
| E | R | ERRORSOURCE | Source of memory access error | ||||||||||||||||||||||||||||||||
MPC | 1 | Error was triggered by MPC module | |||||||||||||||||||||||||||||||||
Slave | 0 | Error was triggered by a Subordinate | |||||||||||||||||||||||||||||||||
OVERRIDE[n]
Special privilege tables
OVERRIDE[n].CONFIG
Address offset: 0x800 + (n × 0x20)
Override region n Configuration register
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | B | A | |||||||||||||||||||||||||||||||||
| Reset 0x00000000 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | RW1 | LOCK | Lock Override region n | ||||||||||||||||||||||||||||||||
Unlocked | 0 | Override region n settings can be updated | |||||||||||||||||||||||||||||||||
Locked | 1 | Override region n settings can not be updated until next reset | |||||||||||||||||||||||||||||||||
| B | RW | ENABLE | Enable Override region n | ||||||||||||||||||||||||||||||||
Disabled | 0 | Override region n is not used | |||||||||||||||||||||||||||||||||
Enabled | 1 | Override region n is used | |||||||||||||||||||||||||||||||||
OVERRIDE[n].STARTADDR
Address offset: 0x804 + (n × 0x20)
Override region n Start Address
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | |||
| Reset 0x00000000 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | RW | STARTADDR | Start address for override region n Address must be aligned to override region granularity, see the instance configuration table above for the override region granularity. The least significant bits of this register field are ignored based on the override region granularity and read as zero. | ||||||||||||||||||||||||||||||||
OVERRIDE[n].ENDADDR
Address offset: 0x808 + (n × 0x20)
Override region n End Address
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | |||
| Reset 0x00000000 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | RW | ENDADDR | End address for override region n Address must be aligned to override region granularity, see the instance configuration table above for the override region granularity. The least significant bits of this register field are ignored based on the override region granularity and read as zero. | ||||||||||||||||||||||||||||||||
OVERRIDE[n].PERM
Address offset: 0x810 + (n × 0x20)
Permission settings for override region n
See section Validate an access above.
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | D | C | B | A | |||||||||||||||||||||||||||||||
| Reset 0x00000000 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | RW | READ | Read access | ||||||||||||||||||||||||||||||||
NotAllowed | 0 | Read access to override region n is not allowed | |||||||||||||||||||||||||||||||||
Allowed | 1 | Read access to override region n is allowed | |||||||||||||||||||||||||||||||||
| B | RW | WRITE | Write access | ||||||||||||||||||||||||||||||||
NotAllowed | 0 | Write access to override region n is not allowed | |||||||||||||||||||||||||||||||||
Allowed | 1 | Write access to override region n is allowed | |||||||||||||||||||||||||||||||||
| C | RW | EXECUTE | Software execute | ||||||||||||||||||||||||||||||||
NotAllowed | 0 | Software execution from override region n is not allowed | |||||||||||||||||||||||||||||||||
Allowed | 1 | Software execution from override region n is allowed | |||||||||||||||||||||||||||||||||
| D | RW | SECATTR | Security mapping | ||||||||||||||||||||||||||||||||
Secure | 1 | Override region n is mapped in secure memory address space | |||||||||||||||||||||||||||||||||
NonSecure | 0 | Override region n is mapped in non-secure memory address space | |||||||||||||||||||||||||||||||||
OVERRIDE[n].PERMMASK
Address offset: 0x814 + (n × 0x20)
Masks permission setting fields from register OVERRIDE.PERM
See section Validate an access above.
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | D | C | B | A | |||||||||||||||||||||||||||||||
| Reset 0x00000000 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | RW | READ | Read mask | ||||||||||||||||||||||||||||||||
Masked | 0 | Permission setting READ in OVERRIDE register will not be applied | |||||||||||||||||||||||||||||||||
UnMasked | 1 | Permission setting READ in OVERRIDE register will be applied | |||||||||||||||||||||||||||||||||
| B | RW | WRITE | Write mask | ||||||||||||||||||||||||||||||||
Masked | 0 | Permission setting WRITE in OVERRIDE register will not be applied | |||||||||||||||||||||||||||||||||
UnMasked | 1 | Permission setting WRITE in OVERRIDE register will be applied | |||||||||||||||||||||||||||||||||
| C | RW | EXECUTE | Execute mask | ||||||||||||||||||||||||||||||||
Masked | 0 | Permission setting EXECUTE in OVERRIDE register will not be applied | |||||||||||||||||||||||||||||||||
UnMasked | 1 | Permission setting EXECUTE in OVERRIDE register will be applied | |||||||||||||||||||||||||||||||||
| D | RW | SECATTR | Security mapping mask | ||||||||||||||||||||||||||||||||
Masked | 0 | Permission setting SECATTR in OVERRIDE register will not be applied | |||||||||||||||||||||||||||||||||
UnMasked | 1 | Permission setting SECATTR in OVERRIDE register will be applied | |||||||||||||||||||||||||||||||||