Memory and peripheral access permissions

Access permissions are controlled by TrustZone, MPC, and SPU security peripherals.

The following figure shows the system security control modules for memory, peripherals, GPIO, and PPI.

Figure 1. Modules filtering access permissions

Modules filtering access permissions

The Arm Cortex®-M33 CPU enforces TrustZone security internally, before issuing bus transactions. For security checks internal to the Arm Cortex-M33, see TrustZone security. After the internal CPU security check, the transaction is available on the bus.

Secure and non-secure memory has to be configured in the SAU and MPC.

The security attribution of a bus transaction from the Arm Cortex-M33 is determined by the CPU, SAU, and IDAU settings. See TrustZone security for more information.

For RISC-V and peripherals, the attribution of the bus transaction is determined by the SPU settings.

The destination's security attribute is a combination of MPC and SPU configurations.

Table 1. Abbreviations
AbbreviationDescription
NSNon-secure – TrustZone security attribute is non-secure
SSecure – TrustZone security attribute is secure
NSCNon-secure callable – TrustZone security attribute is non-secure callable
IDAUArm implementation defined attribution unit
SAUArm security attribution unit
SPUNordic system protection unit
MPCNordic memory privilege controller

Memory access overview

The following table lists the security attributes of the bus manager and their access to memory configured as secure and non-secure.
Table 2. Memory access overview
Bus manager security attributeDestination memory security attributeAccess successfulMPC bus fault and error event
SSYesNo
NSSNoYes
SNSYesNo
NSNSYesNo

Peripheral access overview

Peripherals are moved in the memory map based on their security association. Non-secure peripherals can be accessed through addresses starting with 0x4 while secure peripherals are accessible in the memory region starting with 0x5.

The security association of each peripheral is controlled via the SPU. Only peripherals with programmable security association can be moved in the memory map.
Table 3. Peripheral access overview
Bus manager security attributeDestination memory security attributeAddress regionAccess successfulSPU bus fault and error event
SS0x5YesNo
SS0x4NoYes
NSS0x5NoYes
NSS0x4NoYes
SNS0x5NoYes
SNS0x4YesNo
NSNS0x5NoYes
NSNS0x4YesNo
In addition, the following also applies:
  • For split security peripherals, bus faults are not generated for blocked split security bit accesses. Reads as 0, write is ignored.
  • In a split peripheral, access is blocked to secure registers using the non-secure 0x4 memory region because it is through non-secure transactions. Make sure to use the secure memory region to access secure registers.