UICR — User information configuration registers

The user information configuration registers (UICR) are non-volatile memory (NVM) registers that configure user specific settings and values for emulated one-time programmable (OTP).

All UICR registers have a RW1 protection, which means that they can be read multiple times, but written only once when UICR has been erased by the Erase All operation.

For information on writing registers, see RRAMC — Resistive random access memory controller and Memory.

Notice that all access port protection registers are duplicated into PROTECT0/PROTECT1. For optimal security, set both registers set to "random" values different from the Unprotected value. For ERASEPROTECT, set both PROTECT0/PROTECT1 registers to the Protected value.

Registers

Instances

InstanceDomainBase addressTrustZoneSplit accessDescription
MapAttDMA
UICRGLOBAL0x00FFD000HFSNANo

User information configuration

Register overview

RegisterOffsetTZDescription
APPROTECT[n].PROTECT00x000

Access port protection

APPROTECT[n].PROTECT10x01C

Access port protection

SECUREAPPROTECT[n].PROTECT00x020

Access port protection

SECUREAPPROTECT[n].PROTECT10x03C

Access port protection register

AUXAPPROTECT[n].PROTECT00x040

Access port protection

AUXAPPROTECT[n].PROTECT10x05C

Access port protection register

ERASEPROTECT[n].PROTECT00x60

Erase protection

ERASEPROTECT[n].PROTECT10x7C

Erase protection

BOOTCONF0x080

Immutable boot region configuration.

USER.ROT.PUBKEY[n].DIGEST[o]0x200

First 256 bits of SHA2-512 digest over RoT public key generation [n].

USER.ROT.PUBKEY[n].REVOKE[o]0x220

Revocation status for RoT public key generation [n].

USER.ROT.AUTHOPKEY[n].DIGEST[o]0x2B0

First 256 bits of SHA2-512 digest over RoT authenticated operation public key generation [n].

USER.ROT.AUTHOPKEY[n].REVOKE[o]0x2D0

Revocation status for RoT authenticated operation public key generation [n].

OTP[n]0x500

One time programmable memory

APPROTECT[n]

Access Port Protection Registers

APPROTECT[n].PROTECT0

Address offset: 0x000 + (n × 0x20)

Access port protection

Any other value than Unprotected will lock TAMPC PROTECT.DOMAIN signal protectors.

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0xFFFFFFFF11111111111111111111111111111111
IDR/WFieldValue IDValueDescription
A

RW1

PALL

Unprotected

0xFFFFFFFF

Leaves TAMPC PROTECT.DOMAIN DBGEN and NIDEN signal protectors unlocked and under CPU control.

APPROTECT[n].PROTECT1

Address offset: 0x01C + (n × 0x20)

Access port protection

Any other value than Unprotected will lock TAMPC PROTECT.DOMAIN signal protectors.

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0xFFFFFFFF11111111111111111111111111111111
IDR/WFieldValue IDValueDescription
A

RW1

PALL

Unprotected

0xFFFFFFFF

Leaves TAMPC PROTECT.DOMAIN DBGEN and NIDEN signal protectors unlocked and under CPU control.

SECUREAPPROTECT[n]

Access Port Protection Registers

SECUREAPPROTECT[n].PROTECT0

Address offset: 0x020 + (n × 0x20)

Access port protection

Any other value than Unprotected will lock TAMPC PROTECT.DOMAIN signal protectors.

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0xFFFFFFFF11111111111111111111111111111111
IDR/WFieldValue IDValueDescription
A

RW1

PALL

Unprotected

0xFFFFFFFF

Leaves TAMPC PROTECT.DOMAIN SPIDEN and SPNIDEN signal protectors unlocked and under CPU control.

SECUREAPPROTECT[n].PROTECT1

Address offset: 0x03C + (n × 0x20)

Access port protection register

Any other value than Unprotected will lock TAMPC PROTECT.DOMAIN signal protectors.

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0xFFFFFFFF11111111111111111111111111111111
IDR/WFieldValue IDValueDescription
A

RW1

PALL

Unprotected

0xFFFFFFFF

Leaves TAMPC PROTECT.DOMAIN SPIDEN and SPNIDEN signal protectors unlocked and under CPU control.

AUXAPPROTECT[n]

Access Port Protection Registers

AUXAPPROTECT[n].PROTECT0

Address offset: 0x040 + (n × 0x20)

Access port protection

Any other value than Unprotected will lock TAMPC PROTECT.AP signal protectors.

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0xFFFFFFFF11111111111111111111111111111111
IDR/WFieldValue IDValueDescription
A

RW1

PALL

Unprotected

0xFFFFFFFF

Leaves TAMPC PROTECT.AP DBGEN signal protector unlocked and under CPU control.

AUXAPPROTECT[n].PROTECT1

Address offset: 0x05C + (n × 0x20)

Access port protection register

Any other value than Unprotected will lock TAMPC PROTECT.AP signal protectors.

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0xFFFFFFFF11111111111111111111111111111111
IDR/WFieldValue IDValueDescription
A

RW1

PALL

Unprotected

0xFFFFFFFF

Leaves TAMPC PROTECT.AP DBGEN signal protector unlocked and under CPU control.

ERASEPROTECT[n]

Erase Protection Registers

ERASEPROTECT[n].PROTECT0

Address offset: 0x60 + (n × 0x20)

Erase protection

Any other value than Protected will leave the TAMPC PROTECT.ERASEPROTECT signal protector unlocked, so that CPU can control its value.

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0xFFFFFFFF11111111111111111111111111111111
IDR/WFieldValue IDValueDescription
A

RW1

PALL

Protected

0x50FA50FA

Erase protection is enabled and the signal protector is locked.

ERASEPROTECT[n].PROTECT1

Address offset: 0x7C + (n × 0x20)

Erase protection

Any other value than Protected will leave the TAMPC PROTECT.ERASEPROTECT signal protector unlocked, so that CPU can control its value.

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0xFFFFFFFF11111111111111111111111111111111
IDR/WFieldValue IDValueDescription
A

RW1

PALL

Protected

0x50FA50FA

Erase protection is enabled and the signal protector is locked.

BOOTCONF

Address offset: 0x080

Immutable boot region configuration.

If this register is not equal to 0xFFFFFFFF, RRAMC applies these settings to form the immutable boot region.

Unused bits (unused fields) must be set to zero.

Bit number313029282726252423222120191817161514131211109876543210
IDGGGGGGGFEDCBA
Reset 0xFFFFFFFF11111111111111111111111111111111
IDR/WFieldValue IDValueDescription
A

RW1

READ

Read access. Must be enabled in order for the Arm Cortex CPU to start executing from RRAM.

NotAllowed

0

Reading from the region is not allowed.

Allowed

1

Reading from the region is allowed

B

RW1

WRITE

Write access

NotAllowed

0

Writing to the region is not allowed

Allowed

1

Writing to the region is allowed

C

RW1

EXECUTE

Execute access

NotAllowed

0

Executing code from the region is not allowed

Allowed

1

Executing code from the region is allowed

D

RW1

SECURE

Secure access

NonSecure

0

Both secure and non-secure access to region is allowed

Secure

1

Only secure access to region is allowed

E

RW1

WRITEONCE

Write-once

Disabled

0

Write-once disabled

Enabled

1

Write-once enabled

Writes to a 32-bit word in the BOOTCONF region are is only when the current data is 0xFFFFFFFF, otherwise the writes are ignored

F

RW1

LOCK

Enable lock of configuration register

Disabled

0

Lock is disabled, and the RRAMC region configuration registers for the immutable boot region are writable.

Enabled

1

Lock is enabled, and the RRAMC configuration registers for the immutable boot region are read-only.

G

RW1

SIZE

Immutable boot region size

Configures the region size in kB

USER.ROT

Assets installed to establish initial Root of Trust in the device.

User RoT key materials

USER.ROT.PUBKEY[n].DIGEST[o]

Address offset: 0x200 + (n × 0x2C) + (o × 0x4)

First 256 bits of SHA2-512 digest over RoT public key generation [n].

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0xFFFFFFFF11111111111111111111111111111111
IDR/WFieldValue IDValueDescription
A

RW1

VALUE

Value for word [o] in the key digest [n].

USER.ROT.PUBKEY[n].REVOKE[o]

Address offset: 0x220 + (n × 0x2C) + (o × 0x4)

Revocation status for RoT public key generation [n].

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0xFFFFFFFF11111111111111111111111111111111
IDR/WFieldValue IDValueDescription
A

RW1

STATUS

Revocation status.

NotRevoked

0xFFFFFFFF

Key not revoked.

Any other value says the key is revoked.

USER.ROT.AUTHOPKEY[n].DIGEST[o]

Address offset: 0x2B0 + (n × 0x2C) + (o × 0x4)

First 256 bits of SHA2-512 digest over RoT authenticated operation public key generation [n].

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0xFFFFFFFF11111111111111111111111111111111
IDR/WFieldValue IDValueDescription
A

RW1

VALUE

Value for word [o] in the key digest [n].

USER.ROT.AUTHOPKEY[n].REVOKE[o]

Address offset: 0x2D0 + (n × 0x2C) + (o × 0x4)

Revocation status for RoT authenticated operation public key generation [n].

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0xFFFFFFFF11111111111111111111111111111111
IDR/WFieldValue IDValueDescription
A

RW1

STATUS

Revocation status.

NotRevoked

0xFFFFFFFF

Key not revoked.

Any other value says the key is revoked.

OTP[n]

Address offset: 0x500 + (n × 0x4)

One time programmable memory

Bit number313029282726252423222120191817161514131211109876543210
IDAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Reset 0xFFFFFFFF11111111111111111111111111111111
IDR/WFieldValue IDValueDescription
A

RW1

OTP

OTP word

Can only be written to a non 0xFFFFFFFF value once after Erase All operation.