ECB — AES electronic codebook mode encryption

The AES electronic codebook mode encryption (ECB) can be used for a range of cryptographic functions like hash generation, digital signatures, and keystream generation for data encryption/decryption. The ECB encryption block supports 128 bit AES encryption (encryption only, not decryption).

The main features of ECB are:

The inputs and outputs of the ECB are illustrated below.

Figure 1. ECB block diagram

ECB block diagram

AES ECB uses EasyDMA with scatter-gather to access to memory for in-place operations on cleartext and ciphertext during encryption. ECB uses the same AES core as the CCM and AAR blocks and is an asynchronous operation which may not complete if the AES core is busy.

AES ECB performs a 128 bit AES block encrypt. At the START task, cleartext is loaded into the ECB from memory described by the scatter/gather job list pointed to by INPTR and the ciphertext is written into memory described by the job list pointed to by OUTPTR. When the last cleartext byte has been encrypted and written to OUTPTR, the END event is triggered.

The following figure illustrates how the input and output job lists can be configured. For more details of the joblists, see EasyDMA.

Figure 2. Example job lists for ECB operation

Example job lists for ECB operation

The AES key is set by writing the KEY.VALUE key registers. The same key can be used to encrypt multiple blocks by triggering the START task multiple times.

AES ECB can be stopped by triggering the STOP task.

ECB only supports a single 16-byte block. For different job list sizes the following rules apply:
The 128-bit key in the KEY.VALUE registers is stored in reverse byte order relative to the payload. For example, using the sample calculation from the Bluetooth Core Specification v5.4, Volume 6, Part C, chapter 1.1, with the following data:The KEY.VALUE registers are populated as follows:The IN.PTR points to a job that contains the following 16-byte input data array:

          {0x02, 0x13, 0x24, 0x35, 0x46, 0x57, 0x68, 0x79, 0xAC, 0xBD, 0xCE, 0xDF, 0xE0, 0xF1, 0x02, 0x13}
      
Once the encryption is complete, the output buffer referenced by the output job will be filled with the following 16-byte array:

          {0x99, 0xAD, 0x1B, 0x52, 0x26, 0xA3, 0x7E, 0x3E, 0x05, 0x8E, 0x3B, 0x8E, 0x27, 0xC2, 0xC6, 0x66}
      
Note: The KEY byte order is reversed compared to the NRF52 and NRF53 series devices.

Shared resources

The ECB shares the same AES module as the AAR and CCM peripherals. The ECB will always have lowest priority. If there is a sharing conflict during encryption, the ECB operation will be aborted and an ERROR event will be generated.

EasyDMA

This peripheral implements EasyDMA with scatter-gather functionality for reading from and writing to memory without CPU involvement.

The scatter-gather functionality allows EasyDMA to collect data from multiple memory regions, instead of one contigous block. The memory regions are described by a job list. The job list consists of one or more job entries that consist of a 32-bit address field, 8-bit attribute field, and 24-bit length field. A job list ends with a zero filled job entry. The attribute field must be set to 11.

If INPTR or OUTPTR pointers or the entries in the job lists are not pointing to memory connected to the DMA bus, an EasyDMA transfer may result in a HardFault or memory corruption. See Memory for more information about the different memory regions and DMA connectivity.

The EasyDMA will have finished accessing the RAM when the END or ERROR events are generated.

For instances supporting DMA error detection, the ERRORSTATUS register will report if a bus error has occurred during DMA access. To see if DMA error detection is supported, see the the instance's configuration in Instantiation.

Example

The figure below shows an example of a job list with three job entries. Each of the entries point to a memory address, and the length field describes how many bytes of data is stored at that address. There are three blocks of memory in use
  • FIRSTDATA, an array of length 3
  • SECONDDATA, an array of length 2
  • THIRDDATA, an array of length 11
The data pointed to from the job list is what is fed into the module and processed according to the peripheral's operation. The entries of the job list comprises pointers to the individual arrays, as well as their sizes. Job entries with length greater than one are processed in little endian order.
Figure 3. EasyDMA Scatter-Gather job list example

EasyDMA Scatter-Gather job list example

Registers

Instances

InstanceDomainBase addressTrustZoneSplit accessDescription
MapAttDMA

ECB00 : S
ECB00 : NS

GLOBAL

0x5004B000
0x4004B000

USSSANo

AES ECB mode encryption 00

When configuring this peripheral's DMA security using SPU configuration (DMASEC field of SPU->PERIPH[apb_slave_index]), use apb_slave_index 10 (same as AAR00 and CCM00)

Configuration

InstanceDomainConfiguration

ECB00 : S
ECB00 : NS

GLOBAL

Register overview

RegisterOffsetTZDescription
TASKS_START0x000

Start ECB block encrypt

TASKS_STOP0x004

Abort a possible executing ECB operation

SUBSCRIBE_START0x080

Subscribe configuration for task START

SUBSCRIBE_STOP0x084

Subscribe configuration for task STOP

EVENTS_END0x100

ECB block encrypt complete

EVENTS_ERROR0x104

ECB block encrypt aborted because of a STOP task or due to an error

PUBLISH_END0x180

Publish configuration for event END

PUBLISH_ERROR0x184

Publish configuration for event ERROR

INTENSET0x304

Enable interrupt

INTENCLR0x308

Disable interrupt

ERRORSTATUS0x400

Error status

KEY.VALUE[n]0x510

128-bit AES key

IN.PTR0x530

Input pointer

OUT.PTR0x538

Output pointer

Points to a job list containing encrypted ECB data structure

CSAA.REFLECTOR0x53C

Selected Channel Sounding Access Address used in the CS SYNC from Reflector to Initiator

CSAA.INITIATOR0x540

Selected Channel Sounding Access Address used in the CS SYNC from Initiator to Reflector

CSAA.MODE0x544

Operation modes

TASKS_START

Address offset: 0x000

Start ECB block encrypt

If a crypto operation is already running in the AES core, the START task will not start a new encryption and an ERROR event will be triggered

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

W

TASKS_START

Start ECB block encrypt

If a crypto operation is already running in the AES core, the START task will not start a new encryption and an ERROR event will be triggered

Trigger

1

Trigger task

TASKS_STOP

Address offset: 0x004

Abort a possible executing ECB operation

If a running ECB operation is aborted by STOP, the ERROR event is triggered.

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

W

TASKS_STOP

Abort a possible executing ECB operation

If a running ECB operation is aborted by STOP, the ERROR event is triggered.

Trigger

1

Trigger task

SUBSCRIBE_START

Address offset: 0x080

Subscribe configuration for task START

If a crypto operation is already running in the AES core, the START task will not start a new encryption and an ERROR event will be triggered

Bit number313029282726252423222120191817161514131211109876543210
IDBAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

CHIDX

[0..255]

DPPI channel that task START will subscribe to

B

RW

EN

Disabled

0

Disable subscription

Enabled

1

Enable subscription

SUBSCRIBE_STOP

Address offset: 0x084

Subscribe configuration for task STOP

If a running ECB operation is aborted by STOP, the ERROR event is triggered.

Bit number313029282726252423222120191817161514131211109876543210
IDBAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

CHIDX

[0..255]

DPPI channel that task STOP will subscribe to

B

RW

EN

Disabled

0

Disable subscription

Enabled

1

Enable subscription

EVENTS_END

Address offset: 0x100

ECB block encrypt complete

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

EVENTS_END

ECB block encrypt complete

NotGenerated

0

Event not generated

Generated

1

Event generated

EVENTS_ERROR

Address offset: 0x104

ECB block encrypt aborted because of a STOP task or due to an error

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

EVENTS_ERROR

ECB block encrypt aborted because of a STOP task or due to an error

NotGenerated

0

Event not generated

Generated

1

Event generated

PUBLISH_END

Address offset: 0x180

Publish configuration for event END

Bit number313029282726252423222120191817161514131211109876543210
IDBAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

CHIDX

[0..255]

DPPI channel that event END will publish to

B

RW

EN

Disabled

0

Disable publishing

Enabled

1

Enable publishing

PUBLISH_ERROR

Address offset: 0x184

Publish configuration for event ERROR

Bit number313029282726252423222120191817161514131211109876543210
IDBAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

CHIDX

[0..255]

DPPI channel that event ERROR will publish to

B

RW

EN

Disabled

0

Disable publishing

Enabled

1

Enable publishing

INTENSET

Address offset: 0x304

Enable interrupt

Bit number313029282726252423222120191817161514131211109876543210
IDBA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW
W1S

END

Write '1' to enable interrupt for event END

Set

1

Enable

Disabled

0

Read: Disabled

Enabled

1

Read: Enabled

B

RW
W1S

ERROR

Write '1' to enable interrupt for event ERROR

Set

1

Enable

Disabled

0

Read: Disabled

Enabled

1

Read: Enabled

INTENCLR

Address offset: 0x308

Disable interrupt

Bit number313029282726252423222120191817161514131211109876543210
IDBA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW
W1C

END

Write '1' to disable interrupt for event END

Clear

1

Disable

Disabled

0

Read: Disabled

Enabled

1

Read: Enabled

B

RW
W1C

ERROR

Write '1' to disable interrupt for event ERROR

Clear

1

Disable

Disabled

0

Read: Disabled

Enabled

1

Read: Enabled

ERRORSTATUS

Address offset: 0x400

Error status

Bit number313029282726252423222120191817161514131211109876543210
IDAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

R

ERRORSTATUS

Error status when the ERROR event is generated

NoError

0

No errors have occurred

PrematureInptrEnd

1

End of INPTR job list before data structure was read.

PrematureOutptrEnd

2

End of OUTPTR job list before data structure was read.

EncryptionTooSlow

3

Encryption aborted due to higher priority peripheral requesting or using the AES module.

This enumerator is deprecated.

Aborted

3

Encryption aborted due to higher priority peripheral requesting or using the AES module.

DmaError

4

Bus error during DMA access.

KEY.VALUE[n]

Address offset: 0x510 + (n × 0x4)

128-bit AES key

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

W

VALUE

AES 128-bit key value, bits (32*(n+1))-1 : (32*n)

IN

IN EasyDMA channel

IN.PTR

Address offset: 0x530

Input pointer

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

PTR

Points to a job list containing unencrypted ECB data structure

OUT

OUT EasyDMA channel

OUT.PTR

Address offset: 0x538

Output pointer

Points to a job list containing encrypted ECB data structure

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

PTR

Output pointer

CSAA

Channel sounding access address scoring algorithm

CSAA.REFLECTOR

Address offset: 0x53C

Selected Channel Sounding Access Address used in the CS SYNC from Reflector to Initiator

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

R

PN

CSAA.INITIATOR

Address offset: 0x540

Selected Channel Sounding Access Address used in the CS SYNC from Initiator to Reflector

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

R

PN

CSAA.MODE

Address offset: 0x544

Operation modes

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

BITREVERSE

Reverse the endianness on bit level for the ECB output, INITIATOR, and REFLECTOR registers

Enable bit reversal on each byte.

Default

0

Default endianness

Reversed

1

Reversed endianness