UICR — User information configuration registers
The user information configuration registers (UICR) are non-volatile memory (NVM) registers that configure user specific settings and values for emulated one-time programmable (OTP).
All UICR registers have a RW1 protection, which means that they can be read multiple times, but written only once when UICR has been erased by the Erase All operation.
For information on writing registers, see RRAMC — Resistive random access memory controller and Memory.
Notice that all access port protection registers are duplicated into PROTECT0/PROTECT1. For optimal security, set both registers set to "random" values different from the Unprotected value. For ERASEPROTECT, set both PROTECT0/PROTECT1 registers to the Protected value.
Registers
Instances
| Instance | Domain | Base address | Description |
|---|---|---|---|
| UICR | GLOBAL | 0x00FFD000 | User information configuration |
Register overview
| Register | Offset | Description |
|---|---|---|
| APPROTECT[n].PROTECT0 | 0x000 | Access port protection |
| APPROTECT[n].PROTECT1 | 0x00C | Access port protection |
| ERASEPROTECT[n].PROTECT0 | 0x60 | Erase protection |
| ERASEPROTECT[n].PROTECT1 | 0x6C | Erase protection |
| BOOTCONF | 0x080 | Immutable boot region configuration. |
| USER.ROT.PUBKEY[n].DIGEST[o] | 0x200 | First 256 bits of SHA2-512 digest over RoT public key generation [n]. |
| USER.ROT.PUBKEY[n].REVOKE[o] | 0x220 | Revocation status for RoT public key generation [n]. |
| USER.ROT.AUTHOPKEY[n].DIGEST[o] | 0x2B0 | First 256 bits of SHA2-512 digest over RoT authenticated operation public key generation [n]. |
| USER.ROT.AUTHOPKEY[n].REVOKE[o] | 0x2D0 | Revocation status for RoT authenticated operation public key generation [n]. |
| OTP[n] | 0x500 | One time programmable memory |
APPROTECT[n]
Access Port Protection Registers
APPROTECT[n].PROTECT0
Address offset: 0x000 + (n × 0x10)
Access port protection
Any other value than Unprotected will lock TAMPC PROTECT.DOMAIN signal protectors.
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | |||
| Reset 0xFFFFFFFF | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | RW1 | PALL | |||||||||||||||||||||||||||||||||
Unprotected | 0xFFFFFFFF | Leaves TAMPC PROTECT.DOMAIN DBGEN and NIDEN signal protectors unlocked and under CPU control. | |||||||||||||||||||||||||||||||||
APPROTECT[n].PROTECT1
Address offset: 0x00C + (n × 0x10)
Access port protection
Any other value than Unprotected will lock TAMPC PROTECT.DOMAIN signal protectors.
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | |||
| Reset 0xFFFFFFFF | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | RW1 | PALL | |||||||||||||||||||||||||||||||||
Unprotected | 0xFFFFFFFF | Leaves TAMPC PROTECT.DOMAIN DBGEN and NIDEN signal protectors unlocked and under CPU control. | |||||||||||||||||||||||||||||||||
ERASEPROTECT[n]
Erase Protection Registers
ERASEPROTECT[n].PROTECT0
Address offset: 0x60 + (n × 0x10)
Erase protection
Any other value than Protected will leave the TAMPC PROTECT.ERASEPROTECT signal protector unlocked, so that CPU can control its value.
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | |||
| Reset 0xFFFFFFFF | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | RW1 | PALL | |||||||||||||||||||||||||||||||||
Protected | 0x50FA50FA | Erase protection is enabled and the signal protector is locked. | |||||||||||||||||||||||||||||||||
ERASEPROTECT[n].PROTECT1
Address offset: 0x6C + (n × 0x10)
Erase protection
Any other value than Protected will leave the TAMPC PROTECT.ERASEPROTECT signal protector unlocked, so that CPU can control its value.
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | |||
| Reset 0xFFFFFFFF | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | RW1 | PALL | |||||||||||||||||||||||||||||||||
Protected | 0x50FA50FA | Erase protection is enabled and the signal protector is locked. | |||||||||||||||||||||||||||||||||
BOOTCONF
Address offset: 0x080
Immutable boot region configuration.
If this register is not equal to 0xFFFFFFFF, RRAMC applies these settings to form the immutable boot region.
For an immutable bootloader, recommended value is READ, EXECUTE, WRITEONCE, LOCK, and SIZE. READ permission is needed for the CPU to read constants and instructions.
Unused bits (unused fields) must be set to zero.
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | F | F | F | F | F | F | F | F | F | F | E | D | C | B | A | ||||||||||||||||||||
| Reset 0xFFFFFFFF | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | RW1 | READ | Read access. Must be enabled in order for the Arm Cortex CPU to start executing from RRAM. | ||||||||||||||||||||||||||||||||
NotAllowed | 0 | Reading from the region is not allowed. | |||||||||||||||||||||||||||||||||
Allowed | 1 | Reading from the region is allowed | |||||||||||||||||||||||||||||||||
| B | RW1 | WRITE | Write access | ||||||||||||||||||||||||||||||||
NotAllowed | 0 | Writing to the region is not allowed | |||||||||||||||||||||||||||||||||
Allowed | 1 | Writing to the region is allowed | |||||||||||||||||||||||||||||||||
| C | RW1 | EXECUTE | Execute access | ||||||||||||||||||||||||||||||||
NotAllowed | 0 | Executing code from the region is not allowed | |||||||||||||||||||||||||||||||||
Allowed | 1 | Executing code from the region is allowed | |||||||||||||||||||||||||||||||||
| D | RW1 | WRITEONCE | Write-once | ||||||||||||||||||||||||||||||||
Disabled | 0 | Write-once disabled | |||||||||||||||||||||||||||||||||
Enabled | 1 | Write-once enabled Writes to a 32-bit word in the BOOTCONF region are is only when the current data is 0xFFFFFFFF, otherwise the writes are ignored | |||||||||||||||||||||||||||||||||
| E | RW1 | LOCK | Enable lock of configuration register | ||||||||||||||||||||||||||||||||
Disabled | 0 | Lock is disabled, and the RRAMC region configuration registers for the immutable boot region are writable. | |||||||||||||||||||||||||||||||||
Enabled | 1 | Lock is enabled, and the RRAMC configuration registers for the immutable boot region are read-only. | |||||||||||||||||||||||||||||||||
| F | RW1 | SIZE | Immutable boot region size Configures the region size in kB | ||||||||||||||||||||||||||||||||
USER.ROT
Assets installed to establish initial Root of Trust in the device.
User RoT key materials
USER.ROT.PUBKEY[n].DIGEST[o]
Address offset: 0x200 + (n × 0x2C) + (o × 0x4)
First 256 bits of SHA2-512 digest over RoT public key generation [n].
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | |||
| Reset 0xFFFFFFFF | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | RW1 | VALUE | Value for word [o] in the key digest [n]. | ||||||||||||||||||||||||||||||||
USER.ROT.PUBKEY[n].REVOKE[o]
Address offset: 0x220 + (n × 0x2C) + (o × 0x4)
Revocation status for RoT public key generation [n].
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | |||
| Reset 0xFFFFFFFF | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | RW1 | STATUS | Revocation status. | ||||||||||||||||||||||||||||||||
NotRevoked | 0xFFFFFFFF | Key not revoked. Any other value says the key is revoked. | |||||||||||||||||||||||||||||||||
USER.ROT.AUTHOPKEY[n].DIGEST[o]
Address offset: 0x2B0 + (n × 0x2C) + (o × 0x4)
First 256 bits of SHA2-512 digest over RoT authenticated operation public key generation [n].
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | |||
| Reset 0xFFFFFFFF | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | RW1 | VALUE | Value for word [o] in the key digest [n]. | ||||||||||||||||||||||||||||||||
USER.ROT.AUTHOPKEY[n].REVOKE[o]
Address offset: 0x2D0 + (n × 0x2C) + (o × 0x4)
Revocation status for RoT authenticated operation public key generation [n].
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | |||
| Reset 0xFFFFFFFF | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | RW1 | STATUS | Revocation status. | ||||||||||||||||||||||||||||||||
NotRevoked | 0xFFFFFFFF | Key not revoked. Any other value says the key is revoked. | |||||||||||||||||||||||||||||||||
OTP[n]
Address offset: 0x500 + (n × 0x4)
One time programmable memory
| Bit number | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ID | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | A | |||
| Reset 0xFFFFFFFF | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | 1 | |||
| ID | R/W | Field | Value ID | Value | Description | ||||||||||||||||||||||||||||||
| A | RW1 | OTP | OTP word Can only be written to a non 0xFFFFFFFF value once after Erase All operation. | ||||||||||||||||||||||||||||||||