CTRL-AP — Control access port

The control access port (CTRL-AP) is a custom access port that enables control of the device when other access ports (AP) have been disabled by the access port protection.

For an overview of the other debug access ports, see DAP.

Figure 1. Control access port details

Control access port details

Access port protection (APPROTECT) blocks the debugger from accessing the AHB-AP and prevents read and write access to all CPU registers and memory-mapped addresses.

Erase protection (ERASEPROTECT) protects the entire non-volatile memory, and UICR from being erased. Erase protection is enabled through UICR and disabled through cooperation between the firmware and debugger. For more information about disabling erase protection, see Erase protection.

CTRL-AP has the following features:
The CTRL-AP peripheral has the following types of registers:

Reset request

The debugger can request the device to perform a reset.

The register RESET is used to request the reset. Once the reset is performed, the reset reason is accessible through the RESETREAS register. For more information about reset, see RESET — Reset control.

Erase all

The erase all function lets the debugger trigger an erase of non-volatile memory, user information configuration registers (UICR), RAM, all peripheral settings, and also temporarily removes the access port protection.

To trigger an erase all function, follow the sequence in the following flowchart. After the sequence has completed, the access port protection is removed until the next pin reset, power-on reset, brownout reset, or watchdog timer reset.

Figure 2. Erase all states
Erase all states

Erase all protection

It is possible to prevent the debugger from performing an erase all operation by using either the TAMPC TAMPC.PROTECT.ERASEPROTECT register, or the UICR.ERASEPROTECT register followed by a device reset.

Once this has been configured, the CTRL-AP ERASEALL operation is disabled.

The register ERASEPROTECT.STATUS holds the status for erase protection.

Erase protection

Erase protection can be used to prevent a device from being erased.

A device ERASEALL operation can be initiated either by the non-volatile memory controller, or through the control access port. The following table describes the protection of the CTRL-AP ERASEALL operation. For more information, see Access port protection

Table 1. Erase all protection
Access port protection stateERASEALL operation
UICR.­ERASEPROTECTTAMPC.­PROTECT.­ERASEPROTECTERASEALL
UnprotectedUnprotectedAllowed
Protected-Disabled
-ProtectedDisabled

The debugger can read the erase protection status in the register ERASEPROTECT.STATUS.

When erase protection is enabled, both the debugger and on-board firmware are required to disable it. The same non-zero 32-bit KEY value must be written to the debugger register ERASEPROTECT.DISABLE and CPU register ERASEPROTECT.DISABLE to disable erase protection. When both registers have been written with the same non-zero 32-bit KEY value, the device is automatically erased as described in Erase all. The access ports will be re-enabled on the next reset once the secure erase sequence has completed.

Write to the write-once register ERASEPROTECT.LOCK as early as possible in the start-up sequence, preferably as soon as the on-chip firmware has determined it does not need to communicate with a debugger over the CTRL-AP mailbox interface. Once written, it will not be possible to remove the erase protection until the next pin reset, power-on reset, brownout reset, or watchdog timer reset, and therefore ERASEPROTECT.DISABLE is also disabled.

Mailbox interface

CTRL-AP implements a mailbox interface which enables the CPU to communicate with a debugger over the SWD interface.

The mailbox interface consists of a transmit register MAILBOX.TXDATA with its corresponding status register MAILBOX.TXSTATUS, and a receive register MAILBOX.RXDATA with its corresponding status register MAILBOX.RXSTATUS. Status bits in registers TXSTATUS/RXSTATUS will be set and cleared automatically when registers TXDATA/RXDATA are written to and read from, independently of the direction.
Figure 3. Mailbox register interface

Mailbox transfer sequence

  1. Sender writes TXDATA
  2. CTRL-AP sets sender's TXSTATUS to DataPending
  3. CTRL-AP sets receiver's RXSTATUS to DataPending
  4. Receiver reads RXDATA
  5. CTRL-AP sets receiver's RXSTATUS to NoDataPending
  6. CTRL-AP sets sender's TXSTATUS to NoDataPending

Events

EVENTS_RXREADY is generated when MAILBOX.RXSTATUS changes to DataPending. This indicates that a debugger has written new data to MAILBOX.RXDATA.

EVENTS_TXDONE is generated when the MAILBOX.TXSTATUSchanges to to NoDataPending. This indicates that a debugger has read the data from MAILBOX.TXDATA.

Device information

Device information, such as part number and hardware revision, can be read using CTRL-AP.

CTRL-AP provides the following information about the device:The information is available even for protected devices.

Debugger registers

CTRL-AP has a set of registers that can only be accessed from the debugger through the SWD interface. These are not accessible from the CPU.

Debug side registers

Register overview
RegisterOffsetDescription
RESET0x000

System reset request and status

ERASEALL0x004

Perform a secure erase of the device, where flash, SRAM, and UICR will be erased in sequence. The device will be returned to factory default settings upon next reset.

ERASEALLSTATUS0x008

This is the status register for the ERASEALL operation.

ERASEPROTECT.STATUS0x00C

Erase protection status.

ERASEPROTECT.DISABLE0x010

This register disables ERASEPROTECT and performs Erase all.

APPROTECT.STATUS0x014

This is the status register for the access port protection.

MAILBOX.TXDATA0x020

Data sent from the debugger to the device.

MAILBOX.TXSTATUS0x024

Status to indicate if data sent from the debugger to the device has been read.

MAILBOX.RXDATA0x028

Data sent from the device to the debugger.

MAILBOX.RXSTATUS0x02C

Status to indicate if data sent from the device to the debugger has been read.

INFO.PARTNO0x030

Part number of the device

INFO.HWREVISION0x034

Hardware Revision of the device

IDR0x0FC

CTRL-AP Identification Register, IDR

RESET

Address offset: 0x000

System reset request and status

Only the enumerated values are supported, writing other values has unpredictable effect.

The Erase all operation cannot be interrupted by this reset request. Once the Erase all operation has started, CTRL-AP reset requests are ignored.

Bit number313029282726252423222120191817161514131211109876543210
IDAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

W

RESET

Reset request

NoReset

0

Release the RESET register value.

SoftReset

1

Trigger soft reset of the device. Use NoReset after the device has been reset.

HardReset

2

Trigger hard reset of the device - as part of the ERASEALL sequence. Use NoReset after the device has been reset.

PinReset

4

Trigger pin reset of the device. Use NoReset after the device has been reset.

ERASEALL

Address offset: 0x004

Perform a secure erase of the device, where flash, SRAM, and UICR will be erased in sequence. The device will be returned to factory default settings upon next reset.

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

W

ERASEALL

Return device to factory default settings

NoOperation

0

No operation

Erase

1

Erase flash, SRAM, and UICR in sequence

ERASEALLSTATUS

Address offset: 0x008

This is the status register for the ERASEALL operation.

Bit number313029282726252423222120191817161514131211109876543210
IDAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

R

ERASEALLSTATUS

Status bits for the ERASEALL operation

Ready

0

ERASEALL is ready

ReadyToReset

1

Device is ready to be reset

Busy

2

ERASEALL is busy (on-going)

Error

3

Error during ERASEALL

ERASEPROTECT.STATUS

Address offset: 0x00C

Erase protection status.

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

R

PALL

Erase protection status.

Enabled

1

Erase protection is enabled.

Disabled

0

Erase protection is not enabled and ERASEALL can be performed.

ERASEPROTECT.DISABLE

Address offset: 0x010

This register disables ERASEPROTECT and performs Erase all.

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

KEY

The Erase all sequence will be initiated if value of the KEY fields are non-zero and the KEY fields match on both the CPU and debugger sides.

APPROTECT.STATUS

Address offset: 0x014

This is the status register for the access port protection.

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

R

APPROTECT

Status bit for access port protection.

Enabled

1

APPROTECT is enabled

Disabled

0

APPROTECT is disabled

MAILBOX.TXDATA

Address offset: 0x020

Data sent from the debugger to the device.

Writing to this register will automatically set field DataPending in register TXSTATUS.

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

Data

Data sent from debugger

MAILBOX.TXSTATUS

Address offset: 0x024

Status to indicate if data sent from the debugger to the device has been read.

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

R

Status

Status of register DATA

NoDataPending

0

No data pending in register TXDATA

DataPending

1

Data pending in register TXDATA

MAILBOX.RXDATA

Address offset: 0x028

Data sent from the device to the debugger.

Reading from this register will automatically set field NoDataPending in register RXSTATUS.

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

R

Data

Data sent from device

MAILBOX.RXSTATUS

Address offset: 0x02C

Status to indicate if data sent from the device to the debugger has been read.

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

R

Status

Status of register DATA

NoDataPending

0

No data pending in register RXDATA

DataPending

1

Data pending in register RXDATA

INFO.PARTNO

Address offset: 0x030

Part number of the device

This register is retained on system on idle.

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

R

PARTNO

Part number

INFO.HWREVISION

Address offset: 0x034

Hardware Revision of the device

This register is retained on system on idle.

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

R

ID

Part Variant

IDR

Address offset: 0x0FC

CTRL-AP Identification Register, IDR

Bit number313029282726252423222120191817161514131211109876543210
IDEEEEDDDDCCCCCCCBBBBAAAAAAAA
Reset 0x3288000000110010100010000000000000000000
IDR/WFieldValue IDValueDescription
A

R

APID

AP Identification

B

R

CLASS

Access Port (AP) class

NotDefined

0x0

No defined class

MEMAP

0x8

Memory Access Port

C

R

JEP106ID

JEDEC JEP106 identity code

D

R

JEP106CONT

JEDEC JEP106 continuation code

E

R

REVISION

Revision

Peripheral registers

CTRL-AP has a set of registers that can be accessed by the CPU.

CPU side registers

Instances
InstanceDomainBase addressDescription
CTRLAPGLOBAL0x40052000

Control access port CPU side

Register overview
RegisterOffsetDescription
EVENTS_RXREADY0x100

RXSTATUS is changed to DataPending.

EVENTS_TXDONE0x104

TXSTATUS is changed to NoDataPending.

INTEN0x300

Enable or disable interrupt

INTENSET0x304

Enable interrupt

INTENCLR0x308

Disable interrupt

INTPEND0x30C

Pending interrupts

MAILBOX.RXDATA0x400

Data sent from the debugger to the CPU.

MAILBOX.RXSTATUS0x404

Status to indicate if data sent from the debugger to the CPU has been read.

MAILBOX.TXDATA0x480

Data sent from the CPU to the debugger.

MAILBOX.TXSTATUS0x484

Status to indicate if data sent from the CPU to the debugger has been read.

ERASEPROTECT.LOCK0x500

This register locks the ERASEPROTECT.DISABLE register from being written until next reset.

ERASEPROTECT.DISABLE0x504

This register disables the ERASEPROTECT register and performs an ERASEALL operation.

RESET0x520

System reset request.

EVENTS_RXREADY

Address offset: 0x100

RXSTATUS is changed to DataPending.

New data is available in MAILBOX.RXDATA.

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

EVENTS_RXREADY

RXSTATUS is changed to DataPending.

New data is available in MAILBOX.RXDATA.

NotGenerated

0

Event not generated

Generated

1

Event generated

EVENTS_TXDONE

Address offset: 0x104

TXSTATUS is changed to NoDataPending.

MAILBOX.TXDATA has been read.

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

EVENTS_TXDONE

TXSTATUS is changed to NoDataPending.

MAILBOX.TXDATA has been read.

NotGenerated

0

Event not generated

Generated

1

Event generated

INTEN

Address offset: 0x300

Enable or disable interrupt

Bit number313029282726252423222120191817161514131211109876543210
IDBA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

RXREADY

Enable or disable interrupt for event RXREADY

New data is available in MAILBOX.RXDATA.

Disabled

0

Disable

Enabled

1

Enable

B

RW

TXDONE

Enable or disable interrupt for event TXDONE

MAILBOX.TXDATA has been read.

Disabled

0

Disable

Enabled

1

Enable

INTENSET

Address offset: 0x304

Enable interrupt

Bit number313029282726252423222120191817161514131211109876543210
IDBA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW
W1S

RXREADY

Write '1' to enable interrupt for event RXREADY

New data is available in MAILBOX.RXDATA.

Set

1

Enable

Disabled

0

Read: Disabled

Enabled

1

Read: Enabled

B

RW
W1S

TXDONE

Write '1' to enable interrupt for event TXDONE

MAILBOX.TXDATA has been read.

Set

1

Enable

Disabled

0

Read: Disabled

Enabled

1

Read: Enabled

INTENCLR

Address offset: 0x308

Disable interrupt

Bit number313029282726252423222120191817161514131211109876543210
IDBA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW
W1C

RXREADY

Write '1' to disable interrupt for event RXREADY

New data is available in MAILBOX.RXDATA.

Clear

1

Disable

Disabled

0

Read: Disabled

Enabled

1

Read: Enabled

B

RW
W1C

TXDONE

Write '1' to disable interrupt for event TXDONE

MAILBOX.TXDATA has been read.

Clear

1

Disable

Disabled

0

Read: Disabled

Enabled

1

Read: Enabled

INTPEND

Address offset: 0x30C

Pending interrupts

Bit number313029282726252423222120191817161514131211109876543210
IDBA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

R

RXREADY

Read pending status of interrupt for event RXREADY

New data is available in MAILBOX.RXDATA.

NotPending

0

Read: Not pending

Pending

1

Read: Pending

B

R

TXDONE

Read pending status of interrupt for event TXDONE

MAILBOX.TXDATA has been read.

NotPending

0

Read: Not pending

Pending

1

Read: Pending

MAILBOX.RXDATA

Address offset: 0x400

Data sent from the debugger to the CPU.

Reading from this register will automatically set field NoDataPending in register RXSTATUS.

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

R

RXDATA

Data received from debugger.

MAILBOX.RXSTATUS

Address offset: 0x404

Status to indicate if data sent from the debugger to the CPU has been read.

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

R

RXSTATUS

Status of data in register RXDATA.

NoDataPending

0

No data is pending in register RXDATA.

DataPending

1

Data is pending in register RXDATA.

MAILBOX.TXDATA

Address offset: 0x480

Data sent from the CPU to the debugger.

Writing to this register will automatically set field DataPending in register TXSTATUS.

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW

TXDATA

Data sent to debugger.

MAILBOX.TXSTATUS

Address offset: 0x484

Status to indicate if data sent from the CPU to the debugger has been read.

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

R

TXSTATUS

Status of data in register TXDATA.

NoDataPending

0

No data is pending in register TXDATA.

DataPending

1

Data is pending in register TXDATA.

ERASEPROTECT.LOCK

Address offset: 0x500

This register locks the ERASEPROTECT.DISABLE register from being written until next reset.

Bit number313029282726252423222120191817161514131211109876543210
IDA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

RW1

LOCK

Writing any value will lock the ERASEPROTECT.DISABLE register from being written until next reset.

Locked

1

Register ERASEPROTECT.DISABLE is read-only.

ERASEPROTECT.DISABLE

Address offset: 0x504

This register disables the ERASEPROTECT register and performs an ERASEALL operation.

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

W1

KEY

The ERASEALL sequence is initiated if the value of the KEY fields are non-zero and the KEY fields match on both the CPU and debugger sides.

RESET

Address offset: 0x520

System reset request.

Only the enumerated values are supported, writing other values has unpredictable effect.

Bit number313029282726252423222120191817161514131211109876543210
IDAAA
Reset 0x0000000000000000000000000000000000000000
IDR/WFieldValue IDValueDescription
A

W

RESET

Reset request

NoReset

0

No reset is generated

SoftReset

1

Perform a device soft reset

HardReset

2

Perform a device hard reset

PinReset

4

Perform a device pin reset