MPC — Memory Privilege Controller

The MPC peripheral is an address decoder with built-in security functions.

MPC enforces security for system memory access. It is used to divide the address space into smaller regions and assign permissions to these regions.

The main features of MPC are the following:

Override configuration

The MPC overrides are used to divide the address space into smaller regions and assign permissions to these regions.

When the device is reset, the memory in RAM and the non-volatile memory (NVM) is secure. Only secure CPUs and peripherals can read, write, or execute from secure memory.

To configure permission settings in a memory region, perform the following steps.

  1. Define the memory region by configuring STARTADDR and ENDADDR. The values must be multiples of the override region granularity, which is 4096.
  2. Use PERMMASK to define which of the access permissions in PERM to apply.
  3. Enable and lock the override using the CONFIG register.

To prevent unintended reconfiguration of MPC, all overrides should be safeguarded by using the LOCK bit in the CONFIG register.

Note: For overlapping regions, MPC will perform a logical OR between the permission bits. The logical OR applies to both PERMMASK and PERM registers. Because of this, it is not possible to retract the READ, WRITE or EXECUTE permissions. For PERM.SECURE, the OR operation between Secure (1) and NonSecure (0) will result in a Secure overlap region.

Access blocking

Dedicated override regions can be used to block access to a memory region. See the MPC configuration table for which overrides are capable of access blocking.

To configure an override to block access, perform the following steps.
  1. Define the memory region by configuring STARTADDR and ENDADDR. The values must be multiples of the override region granularity, which is 4096.
  2. Enable and lock the override using the CONFIG register.
After applying the configuration, the memory region is blocked from access. The CPU will receive a bus fault when trying to access the region.

MPC error reporting

MPC reports an error when an access violation is detected.

MPC generates an EVENTS_MEMACCERR event when an erroneous transaction is detected. The following errors can be detected.
  • The address cannot be decoded or the bus Manager does not have permissions to access the Subordinate. When this happens, the MEMACCERR.ADDRESS will capture the failing address issued by the bus Manager port and MEMACCERR.INFO will capture additional access information for the attempted transaction.
  • If a transaction is routed to a Subordinate, but the Subordinate responds with an error.
The MEMACCERR registers will not be updated when EVENTS_MEMACCERR is set.

Registers

Instances

InstanceDomainBase addressTrustZoneSplit accessDescription
MapAttDMA
MPC00GLOBAL0x50041000HFSNANo

Memory privilege controller MPC00

Configuration

InstanceDomainConfiguration
MPC00GLOBAL

The override region granularity is 4096 bytes

Overrides 0 through 6 are available for override configuration. Override 7 can be configured for access blocking. Overrides 8 through 11 are reserved by the system and cannot be configured.

Register overview

RegisterOffsetTZDescription
EVENTS_MEMACCERR0x100

Memory Access Error event

INTEN0x300

Enable or disable interrupt

INTENSET0x304

Enable interrupt

INTENCLR0x308

Disable interrupt

MEMACCERR.ADDRESS0x400

Target Address of Memory Access Error. Register content will not be changed as long as MEMACCERR event is active.

MEMACCERR.INFO0x404

Access information for the transaction that triggered a memory access error. Register content will not be changed as long as MEMACCERR event is active.

OVERRIDE[n].CONFIG0x800

Override region n Configuration register

OVERRIDE[n].STARTADDR0x804

Override region n Start Address

OVERRIDE[n].ENDADDR0x808

Override region n End Address

OVERRIDE[n].PERM0x810

Permission settings for override region n

OVERRIDE[n].PERMMASK0x814

Masks permission setting fields from register OVERRIDE.PERM

EVENTS_MEMACCERR

Address offset: 0x100

Memory Access Error event

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

EVENTS_MEMACCERR

Memory Access Error event

NotGenerated

0

Event not generated

Generated

1

Event generated

INTEN

Address offset: 0x300

Enable or disable interrupt

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

MEMACCERR

Enable or disable interrupt for event MEMACCERR

Disabled

0

Disable

Enabled

1

Enable

INTENSET

Address offset: 0x304

Enable interrupt

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW
W1S

MEMACCERR

Write '1' to enable interrupt for event MEMACCERR

Set

1

Enable

Disabled

0

Read: Disabled

Enabled

1

Read: Enabled

INTENCLR

Address offset: 0x308

Disable interrupt

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW
W1C

MEMACCERR

Write '1' to disable interrupt for event MEMACCERR

Clear

1

Disable

Disabled

0

Read: Disabled

Enabled

1

Read: Enabled

MEMACCERR

Memory Access Error status registers

MEMACCERR.ADDRESS

Address offset: 0x400

Target Address of Memory Access Error. Register content will not be changed as long as MEMACCERR event is active.

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

R

ADDRESS

Target address for erroneous access

MEMACCERR.INFO

Address offset: 0x404

Access information for the transaction that triggered a memory access error. Register content will not be changed as long as MEMACCERR event is active.

Bit number313029282726252423222120191817161514131211109876543210
IDEDCBA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

R

READ

Read bit of bus access

Set

1

Read access bit was set

NotSet

0

Read access bit was not set

B

R

WRITE

Write bit of bus access

Set

1

Write access bit was set

NotSet

0

Write access bit was not set

C

R

EXECUTE

Execute bit of bus access

Set

1

Execute access bit was set

NotSet

0

Execute access bit was not set

D

R

SECURE

Secure bit of bus access

Set

1

Secure access bit was set

NotSet

0

Secure access bit was not set

E

R

ERRORSOURCE

Source of memory access error

MPC

1

Error was triggered by MPC module

Slave

0

Error was triggered by a Subordinate

OVERRIDE[n]

Special privilege tables

OVERRIDE[n].CONFIG

Address offset: 0x800 + (n × 0x20)

Override region n Configuration register

Bit number313029282726252423222120191817161514131211109876543210
IDBA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW1

LOCK

Lock Override region n

Unlocked

0

Override region n settings can be updated

Locked

1

Override region n settings can not be updated until next reset

B

RW

ENABLE

Enable Override region n

Disabled

0

Override region n is not used

Enabled

1

Override region n is used

OVERRIDE[n].STARTADDR

Address offset: 0x804 + (n × 0x20)

Override region n Start Address

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

STARTADDR

Start address for override region n

Address must be aligned to override region granularity, see the instance configuration table above for the override region granularity. The least significant bits of this register field are ignored based on the override region granularity and read as zero.

OVERRIDE[n].ENDADDR

Address offset: 0x808 + (n × 0x20)

Override region n End Address

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

ENDADDR

End address for override region n

Address must be aligned to override region granularity, see the instance configuration table above for the override region granularity. The least significant bits of this register field are ignored based on the override region granularity and read as zero.

OVERRIDE[n].PERM

Address offset: 0x810 + (n × 0x20)

Permission settings for override region n

See section Validate an access above.

Bit number313029282726252423222120191817161514131211109876543210
IDDCBA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

READ

Read access

NotAllowed

0

Read access to override region n is not allowed

Allowed

1

Read access to override region n is allowed

B

RW

WRITE

Write access

NotAllowed

0

Write access to override region n is not allowed

Allowed

1

Write access to override region n is allowed

C

RW

EXECUTE

Software execute

NotAllowed

0

Software execution from override region n is not allowed

Allowed

1

Software execution from override region n is allowed

D

RW

SECATTR

Security mapping

Secure

1

Override region n is mapped in secure memory address space

NonSecure

0

Override region n is mapped in non-secure memory address space

OVERRIDE[n].PERMMASK

Address offset: 0x814 + (n × 0x20)

Masks permission setting fields from register OVERRIDE.PERM

See section Validate an access above.

Bit number313029282726252423222120191817161514131211109876543210
IDDCBA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

READ

Read mask

Masked

0

Permission setting READ in OVERRIDE register will not be applied

UnMasked

1

Permission setting READ in OVERRIDE register will be applied

B

RW

WRITE

Write mask

Masked

0

Permission setting WRITE in OVERRIDE register will not be applied

UnMasked

1

Permission setting WRITE in OVERRIDE register will be applied

C

RW

EXECUTE

Execute mask

Masked

0

Permission setting EXECUTE in OVERRIDE register will not be applied

UnMasked

1

Permission setting EXECUTE in OVERRIDE register will be applied

D

RW

SECATTR

Security mapping mask

Masked

0

Permission setting SECATTR in OVERRIDE register will not be applied

UnMasked

1

Permission setting SECATTR in OVERRIDE register will be applied