13. OTP

RP2350 provides 8 kB of one-time programmable storage (OTP), which holds:

For the full listing of predefined OTP contents, see Section 13.10 .

OTP is physically an array of 4096 rows of 24 bits each. You can directly access these 24-bit values, but there is also hardware support for storing 16 bits of data in each row, with 6 bits of Hamming ECC protection and 2 bits of bit polarity reversal protection, yielding an ECC data capacity of 8192 bytes.

On a blank device, the OTP contents is all zeroes, except for some basic device information pre-programmed during manufacturing test. Each bit can be irreversibly programmed from zero to one. To program the OTP contents:

RP2350 enforces page-based permissions on OTP to partition Secure from Non-secure data and to ensure that contents that should not change do not change. The OTP address space is logically partitioned into 64 pages, each 64 rows in size, for a total of 128 bytes of ECC data per page. Pages initially have full read-write permissions, but can be restricted to read-only or inaccessible for each of Secure, Non-secure and bootloader access.

The page permissions themselves are stored in OTP. Locking pages in this way is an irreversible operation, referred to as hard locking . The hardware also supports soft locking , where a page's permissions are further restricted by writing to the relevant register in SW_LOCK0 through SW_LOCK63 ; this restriction remains in effect until the next OTP reset. Resetting the OTP block also resets the processors, so soft locking can be used to restrict the availability of sensitive content like decryption keys to early boot stages.

OTP access keys ( Section 13.5.2 ) provide an additional layer of protection. A fixed challenge is written to a write-only OTP area. Pages registered to that key require the key to be entered to a write-only register in order to open read or write access. This supports configuration data that can be accessed or edited by the board manufacturer, but not by general firmware running on the device.

13.1. OTP address map

The OTP hardware resides in a 128 kB region starting at 0x40120000 (OTP_BASE in the SDK). Bit 16 of the address is used to select either the OTP control registers, in the lower 64 kB, or one of the OTP read data aliases, in the upper 64 kB of this space.

The OTP control registers ( Section 13.9 ) are aliased at 4 kB intervals to implement the usual set, clear, and XOR atomic write aliases described in Section 2.1.3 .

The read data region starting at 0x40130000 divides further into four aliases:

Bit 14 of the address selects ECC (0) vs raw (1). Bit 15 of the address selects unguarded (0) vs guarded (1) access. Guarded reads return the same data as unguarded reads, but perform additional hardware consistency checks and return bus faults on permission failure. For more information, see Section 13.1.1 .

! IMPORTANT

The read data regions starting at 0x40130000 are accessible only when USR.DCTRL is set, otherwise all reads return a bus error response. This bit is clear when the OTP is being programmed via the SBPI bridge.

Writing to the read data aliases is not a valid operation, and will always return a bus fault. The OTP is programmed by the SBPI bridge, which is used internally by the bootrom otp_access API, Section 5.4.8.21 .

13.1.1. Guarded reads

Reads through the guarded aliases differ from unguarded reads in the following ways:

These checks help to make the OTP fail-safe in contexts where deliberate fault injection is a possibility. For example, the RP2350 bootrom uses guarded reads to check boot configuration flags.

The data returned from a successful guarded read is the same as the data returned by a successful read from the corresponding unguarded alias.

! IMPORTANT

Users relying on OTP data in a Secure context should always perform guarded reads, and it is strongly recommended to use ECC. For rows where ECC is not possible, software should take care to ensure the consistency of data across multiple overlapping reads.

13.2. Background: OTP IP details

The RP2350 OTP subsystem uses the Synopsys NVM OTP IP, which comes in 3 parts:

13.3. Background: OTP hardware architecture

This diagram shows the integration of the three Synopsys IP components, and the Raspberry Pi hardware added to make this all function in the context of RP2350's system and security architecture. More specifically:

Figure 142. OTP architecture

Figure 142: OTP architecture diagram. The diagram illustrates the integration of Synopsys IP components (AP, SHF, IPS) and Raspberry Pi hardware (APB interface, APB splitter, ctrl_regs, data bridge, SBPI bridge, lock shim) for OTP hardware architecture. Key components include: APB interface, APB splitter, ctrl_regs, data bridge, SBPI bridge, lock shim, and the SNPS IP block (AP, SHF, IPS). Signals shown include clk_ref, clk_apb, clk_otp, clk_osc, and various control signals like MRR, PGM/PGW, MR, Q, addr, we/sth/oe, sel, sel_ena, rawQ, rawQp, SW locks key, and HW locks keys. The diagram shows the flow of data and control signals between these components, highlighting the integration of the OTP subsystem with the SoC.
Figure 142: OTP architecture diagram. The diagram illustrates the integration of Synopsys IP components (AP, SHF, IPS) and Raspberry Pi hardware (APB interface, APB splitter, ctrl_regs, data bridge, SBPI bridge, lock shim) for OTP hardware architecture. Key components include: APB interface, APB splitter, ctrl_regs, data bridge, SBPI bridge, lock shim, and the SNPS IP block (AP, SHF, IPS). Signals shown include clk_ref, clk_apb, clk_otp, clk_osc, and various control signals like MRR, PGM/PGW, MR, Q, addr, we/sth/oe, sel, sel_ena, rawQ, rawQp, SW locks key, and HW locks keys. The diagram shows the flow of data and control signals between these components, highlighting the integration of the OTP subsystem with the SoC.

The OTP subsystem clock is initially provided by the OTP boot oscillator (Section 13.3.3) during hardware startup, but switches to clk_ref before any software runs on the processors. The frequency of clk_ref must not exceed 25 MHz when accessing the OTP.

13.3.1. Lock shim

The lock shim is inserted between the Synopsys AP block and the SHF block, and is used to enforce read/write page locks, based on:

Because the Synopsys AP performs both reads and writes in the course of programming an OTP row, it is impossible to disable reads to an address without also disabling writes. Three lock states are supported:

The full locking scheme is described in in Section 13.5 , but to summarise:

The full locking scheme is described in in Section 13.5 .

13.3.2. External interfaces

The OTP integration has one upstream APB interface, which splits internally onto two separate interfaces. This guarantees the hardware only serves a single upstream APB access at a time, with a single PPROT security level.

The first APB interface is the data interface (or data bridge) (OTPD). It has the following characteristics:

The second APB interface is the command interface. This provides two main functions:

Hardware configuration data read from OTP during the power-up sequence drives system-level control signals, e.g. disabling CoreSight APs. This is described in more detail in (Section 13.3.4).

A single system-level interrupt output (IRQ) generates interrupts for the following sources:

Any failed access also returns a bus fault ( PSLVERR ). To determine whether an OTP address is accessible, query the lock tables.

Non-secure code cannot access the interrupt status registers.

13.3.3. OTP boot oscillator

The OTP startup sequence (Section 13.3.4) runs from a local ring oscillator, dedicated to the OTP subsystem. This is separate from the system ring oscillator (the ROSC) which provides the system clock to run the processors during boot.

The boot oscillator has a nominal frequency of 12MHz. It provides the clock for reading out hardware configuration from OTP, including the critical flags (Section 13.4) which configure hardware security features such as debug disable and the glitch detectors.

Keeping this oscillator local to the OTP hardware subsystem reduces the power signature of the clock itself, due to the lower switched clock capacitance. Along with the random jitter of the frequency controls, this helps frustrate attempts to recover OTP access keys and debug keys via power signature analysis attacks, or to disable security features by timing fault injection against the OTP clock.

Only the OTP boot oscillator enables the ROSC frequency randomisation feature by default: for later operations using the system ROSC (Section 8.3), you must explicitly enable this feature on that oscillator, by programming the ROSC control registers. The crystal oscillator (XOSC) does not support frequency randomisation.

13.3.4. Power-up state machine

The OTP is the second item in the switched core domain's Power-On State Machine (Section 7.4), after the processor cold reset. OTP does not release its rst_done , or enable any debug interface (including the factory test JTAG described in Section 10.10), until the OTP PSM reads out OTP-resident hardware configuration. The rst_done output to the system

PSM holds the rest of the system in reset until the OTP PSM completes, so that no software runs until the OTP's contents are known.

The OTP boot sequence runs from a local ring oscillator. This oscillator is dedicated to the OTP subsystem, and is separate from the main system ROSC used by the processors at boot. The sequence is:

  1. 1. First, the PSM runs the Synopsys boot instruction. This has the following steps:
    1. a. Wait for the power supply to return a 'good' value.
    2. b. Read consistency check location until hardware sees the correct value for 16 successive reads. Consistency checks use predefined words stored in mask ROM cells with similar analogue properties to OTP cells.
  2. 2. Read critical flags (non-ECC): each critical bit is redundant across 8 OTP rows, with three-of-eight vote for each flag.
  3. 3. Read hardware access keys via ECC read interface.
  4. 4. Read valid bits for hardware access keys, including the debug keys ( Section 3.5.9.2 )
  5. 5. Initialise page lock registers from the lock page via raw read interface.
  6. 6. Assert rst_done signal to the system power-on state machine
  7. 7. The system reset sequence continues, starting with the system ROSC

RP2350 A3 adds correctness checks and robustness to the PSM. For more information about these additions, see RP2350-E16 .

13.4. Critical flags

Critical flags enable hardware security features which are fundamental to RP2350's secure boot implementation. The OTP power-up state machine reads critical flags very early in the system reset sequence, before any code runs on the processors.

Most critical flags are in the main Boot Configuration page, page 1. These are listed under CRIT1 in the OTP data listing. The exceptions are the Arm/RISC-V disable flags, which are in the Chip Info page, page 0. This page is made read-only during factory programming, so users can not write to the CRIT0 flags.

Critical flags define 0 as the unprogrammed value, and 1 as the programmed value. On a blank device, all of the CRIT1 flags are 0 . The reset value specified below is the value assigned to the internal logic net between the OTP reset being applied and the OTP PSM completing. For example, the reset value of 1 for the debug disable flags implies that debug is not accessible whilst the OTP PSM is running, but may be available afterward, depending on the value read from OTP storage.

debug disable flag.

Critical flags are encoded with a three-of-eight vote across eight consecutive OTP rows. Each flag is redundantly programmed to the same bit position in eight consecutive rows. Hardware considers the flag to be set if the bit reads as 1 in at least three of these eight rows. The flag is considered clear if no more than two bits are observed to be set.

i NOTE

As of RP2350 A3 the ARM_DISABLE flag has no effect, removing a potential unlock path for debug on a secured RP2350. Additionally, the combination of RISCV_DISABLE=1 and BOOT_ARCH=1 is decoded to an invalid state and the chip will not boot.

JTAG disable is ignored only if the customer RMA flag ( Section 13.7 ) is set.

For further discussion of the effects of the critical flags, see:

13.5. Page locks

The OTP protection hardware logically segments OTP into 64 pages (0 through 63), each 128 bytes in size, or equivalently 64 OTP rows.

Each page has a set of lock registers which determine read and write access for that page from Secure and Non-secure code. The lock registers are preloaded from OTP at reset, and can then be advanced (i.e. made less permissive) by software. Lock registers themselves are always world-readable.

Pages 61 through 63 are not so neatly described by a single set of lock registers. These pages store lock initialisation metadata. For more details, see Section 13.5.4 . This section describes the more common case of a page protected by a set of page locks.

13.5.1. Lock progression

Due to hardware constraints ( Section 13.3.1 ), read and write restrictions are not orthogonal: it's impossible to disallow reads to an address without also disallowing writes. So, the progression of locking for a given page is:

  1. 0. Read/Write
  2. 1. Read-only
  3. 2. Inaccessible

Lock state only increases . This is enforced in two ways:

Secure and Non-secure use separate lock values, which can advance independently of one another. There is no hardware distinction between Non-secure Read/Write and Non-secure Read-only, since Non-secure can not directly write to the OTP anyway. It is still worth encoding, because Secure software performing a write on Non-secure software's behalf can check and enforce the Non-secure write lock.

You can reprogram bits from any state to any higher state. Locks use a 2-bit thermometer code: the initial all-zeroes state is read-write, and locks are advanced by programming first bit 0, then bit 1.

Lock bits in OTP are triple-redundant with a majority vote. They can't be ECC-protected, because they may be mutated bit-by-bit over multiple programming operations.

The OTP-resident lock bits are write-protected by their own Secure lock level. The lock pages are always world-readable.

The Secure lock registers can be advanced by Secure code, and are world-readable.

The Non-secure lock registers can be advanced by Secure or Non-secure code, and are world-readable.

13.5.2. OTP access keys

Page 61 contains 128-bit keys. Each key has a valid bit : when set, the key becomes completely inaccessible to software. The keys are always read out into hidden registers by hardware during startup so that hardware can perform key comparisons without exposing the keys to software.

Pages can require specific keys for some page permissions. To unlock the page, the user writes their key to a write-only register in the OTP block. The page remains unlocked for as long as the correct key is present in this register. To re-lock the page, erase the active key by writing zeroes to the key register.

The per-page lock config specifies the following:

The no-key state is encoded as follows:

lightbulb icon TIP

Key index 7 does not exist in the configuration. If you specify key index 7, it is guaranteed to never match.

The hardware determines the key lock level by comparing the entered key to the key config of the current page, as follows:

  1. 1. If no keys are registered, the key lock level is 0
  2. 2. Else if keys are registered and no matching key is entered, the key lock level is 2 or 1 depending on the "no-key state" config
  3. 3. Else if a write key is registered and present, the key lock level is 0
  4. 4. Else if a read key is registered and present, the key lock level is 1

Hardware compares the key lock level to the page's lock level for the current security domain (Secure/Non-secure) and takes whichever is higher . For example, if a page has been made Non-secure read-only, there is nothing a key can do to make it Non-secure writable.

There are six 128-bit access keys stored in the OTP. Keys 5 and 6 also function as the Secure debug access key and

Non-secure debug access key, respectively. See Section 3.5.9.2 for information on how the debug keys affect external debug access.

You might use OTP access keys if a bootloader contains OTP configuration that needs to be Secure-writable only to the board owner , not to general Secure software on the device.

13.5.3. Lock encoding in OTP

Page locks are encoded as a 16-bit value. This value is stored as a pair of triple-redundant bytes, each byte occupying a 24-bit OTP row.

The lock halfword is encoded as follows:

BitsPurpose
2:0Write key index, or 0 if no write key
5:3Read key index, or 0 if no read key
6No-key state, 0=Read-only 1=Inaccessible
7Reserved
9:8Secure lock state (thermometer code 0 → 2)
11:10Non-secure lock state (thermometer code 0 → 2)
13:12PicoBoot lock state (thermometer code 0 → 2) or software-defined use if PicoBoot OTP is disabled
15:12Reserved

13.5.4. Special pages

The following pages require special case handling in their lock checks:

Page 0, known as the chip info page , is not a special page. Raspberry Pi sets page 0 to read-only during factory test, after writing chip identification and calibration values.

13.5.5. Permissions of blank devices

Each RP2350 device has some information programmed during manufacturing test. At this time, a small number of hard page lock bits are also programmed:

This minimal set of default permissions on blank devices avoids certain classes of security model violation, like Non-secure code being able to brick the chip by overwriting the boot key fingerprints with invalid data. In this context, the term blank device refers to a device that has gone through manufacturing test programming, but has not had any other OTP bits programmed by the user.

You can add additional soft or hard locks to these default permissions, with the exception of page 0. Page 0 cannot be hard-locked, since the secure read-only permission prevents a user from altering its lock word.

Lock words 2 through 61, covering all pages with user-defined contents, are left unprogrammed. On a blank device, these pages are fully accessible from all domains. Before launching any Non-secure application, you should apply at least a soft read-only lock to all pages that are not explicitly allocated for Non-secure use. To do this, write to SW_LOCK2 through SW_LOCK61 . For devices that you don't expect to RMA, such as those that have passed board-level manufacturing tests, you should lock secure writes to the RMA flag.

13.6. Error Correction Code (ECC)

ECC-protected rows store data in the following structure, accessible through a raw alias:

RP2350 stores the following error correction data in the 8 MSBs of each 24-bit row:

Writes first encode ECC, then BRP. Reads first decode BRP, then ECC. When reading through an ECC data alias ( Section 13.1 ), hardware performs correction transparently. ECC programming operations (writes) automatically generate ECC bits when you use the bootrom otp_access API ( Section 5.4.8.21 ).

ECC is not suitable for data that mutates one bit at a time, since the ECC value is derived from the entire 16-bit data value. When storing data without ECC, use another form of redundancy, such as 3-way majority vote.

13.6.1. Bit repair by polarity (BRP)

Bit repair by polarity (BRP) compensates for a single bit present at time of programming.

When programming a row, hardware or software first calculates a 24-bit target value consisting of:

Before programming, an OTP row should contain all zeros. However, sometimes OTP rows contain a single bit that is already set to 1 , either due to manufacturing flaws or previous programming. If a bit is already set ( 1 ) in an OTP row

before programming, BRP checks the status of the corresponding bit in the target value. BRP compensates for this single set bit in one of two ways, depending on the corresponding value in the target value:

When you read an OTP value through an ECC alias (Section 13.1), BRP checks for two ones in bits 23:22. When both bits 23 and 22 are set, BRP inverts the entire row before passing it to the modified Hamming code stage.

BRP makes it possible to store any 22-bit value in a row that initially has at most one bit set, preserving the correction margin of the modified Hamming code. During manufacturing test, hardware scans the entire OTP array to ensure no rows contain more than one pre-set bit.

13.6.2. Modified Hamming ECC

ECC generates six parity bits based on the data value stored in bits 15:0 of an OTP row. When programming a row, ECC generates those six parity bits and includes them in the target value as bits 21:16. This code consists of:

When you read an OTP value through an ECC alias (Section 13.1), ECC recalculates the six parity bits based on the value read from the OTP row. Then, ECC XORs the original six parity bits with the newly-calculated parity bits. This generates 6 new bits:

If all 6 bits in this value are zero, ECC did not detect an error. If the MSB is 1, the syndrome should indicate a single-bit error. ECC flips the corresponding data bit to recover from the error. If the MSB is 0, but the syndrome contains a value other than 0, the ECC detected an unrecoverable multi-bit error.

You can calculate 5-bit Hamming codes and parity bits with the following C code (adapted from the RP2350 bootrom source):

uint32_t even_parity(uint32_t input) {
    uint32_t rc = 0;
    while (input) {
        rc ^= input & 1;
        input >>= 1;
    }
    return rc;
}

const uint32_t otp_ecc_parity_table[6] = {
    0b0000001010110101011011,
    0b000000011011001101101,
    0b000001100011110001110,
    0b0000000001111110000,
    0b0000011110000000000,
    0b01111111111111111111
};

uint32_t s_otp_calculate_ecc(uint16_t x) {
    uint32_t p = x;
    for (uint i = 0; i < 6; ++i) {
        p |= even_parity(p & otp_ecc_parity_table[i]) << (16 + i);
    }
    return p;
}

}

13.7. Device decommissioning (RMA)

Decommissioning refers to destroying a device's sensitive contents and restoring some test or debug functionality when a device reaches the end of its security lifecycle. The OTP hardware can't actually destroy user data without circumventing write protection in some way. Instead, decommissioning is implemented with the RMA flag , which modifies devices in the following ways:

The RMA flag doesn't change permissions for page 0 (manufacturing data), pages 1 and 2 (boot configuration), page 61 (OTP access keys), or pages 62 and 63 (locks).

The RMA flag is encoded in a spare bit of the page 63 lock word. This lock word would otherwise be unused, since page 63 is one of the lock pages; consequently, it is not protected by a lock word. Instead, each lock word protects itself.

Like all other lock words, the page 63 lock word is protected by its own locks, which means it can be hard- and soft-locked to prevent the RMA flag being set. Locking the RMA flag makes it impossible to re-enable the factory JTAG interface if any of CRIT1.SECURE_BOOT_ENABLE , CRIT1.DEBUG_DISABLE or CRIT1.SECURE_DEBUG_DISABLE is set. This makes it impossible for Raspberry Pi to re-test such devices if they are returned for fault analysis.

! IMPORTANT

Setting the RMA flag does not destroy OTP contents, it merely renders it inaccessible. The design intent is for this to be irreversible, but hardware is never perfect. This is something the user's threat model must account for when programming the RMA flag on devices with sensitive OTP contents – for example, by personalising per-device OTP secrets to avoid class breaks if an attacker is able to retrieve the keys.

13.8. Imaging Vulnerability

The RP2350 OTP is intended to store boot key fingerprints and boot decryption keys. The ability to protect encrypted contents in external flash storage depends on the ability to protect the OTP contents from unauthorised or external reads. The OTP uses antifuse bit cells, which store data as a charge, similar to a flash bit cell. They do not make use of a physical structural change as used in a traditional fuse cell. This makes them resistant to many imaging techniques, such as optical and scanning electron microscopy. However antifuse cells can be imaged using a novel technique called passive voltage contrast (PVC), using a focused ion beam (FIB) device.

PVC Whitepaper

For more information on passive voltage contrast imaging, read the whitepaper by IOActive:

https://www.ioactive.com/wp-content/uploads/2025/01/IOActive-RP2350HackingChallenge.pdf

This process involves decapsulating the die. Therefore physical access to the device is a strict requirement, and there is a moderate chance of destroying the die without being able to recover its OTP contents.

13.8.1. Best Practices

The following best practices minimise your susceptibility to imaging of OTP contents:

13.8.2. Chaff

OTP bits come in pairs: two bits are stored in the isolated gates of two transistors, with a common bit line between them. This structure is known as a bit cell . In each 64-row OTP page, rows i and \( 32 + i \) share the same bit cells. For example, the ECC halfwords BOOTKEY0_0 and BOOTKEY2_0 are physically colocated.

The particulars of the PVC technique make it difficult to distinguish which of the two bits in a bit cell is set. If one bit in each pair is known to be zero – for example, a key stored at the bottom of an otherwise blank page – then the data can be trivially read from the PVC image. However the presence of unknown data in both bits frustrates these attempts. This fact can be exploited by storing data redundantly in the top and bottom half of each page. Specifically:

The bitwise operations specified here are on the entire 24-bit raw row contents, including the ECC bit pattern.

An alternative technique is to store a random value in row \( 32 + i \) and the XOR of that random value with the desired data value in row i . This is advantageous from a power side channel perspective because it avoids reading the secret value directly from OTP, and the example RP2350 encrypted bootloader uses a similar technique with a 4-way XOR. However the bitwise complement technique described above is recommended for pairwise chaff. This is the same as the XOR technique with a fixed XOR pattern of 0xfffff .

13.9. List of registers

The OTP control registers start at a base address of 0x40120000 (defined as OTP_BASE in the SDK).

Table 1332. List of OTP registers

Offset 0x42fc8 0x42fcc 0x42fd0 0x42fd4 0x42fd8Name DEVID DEVTYPE PIDR4 PIDR5 PIDR6Info Device Configuration register Device Type Identifier register CoreSight Periperal ID4 CoreSight Periperal ID5 CoreSight Periperal ID6
them. This structure is known as abit cell . In each 64-row OTP page, rows i and 32 + i share the same bit cells. For
example, the ECC halfwordsBOOTKEY0_0 and BOOTKEY2_0 are physically colocated.
each pair is known to be zero —for example, a key stored at the bottom of an otherwise blank page — then the data can
•Store arbitrary data in each rowi from 0 to 31.
•Store the 24-bit bitwise complement of those values in each row 32 + i .
An alternative technique is to store a random value in row32 + i and the XOR of that random value with the desired data
value in rowi. This is advantageous from a power side channel perspective because it avoids reading the secret value
13.9. List of registers The OTP control registers start at a base address of0x40120000 (defined as OTP_BASE in the SDK).
Offset OTP registersNameInfo
0x000SW_LOCK0Software lock register for page 0.
0x004SW_LOCK1Software lock register for page 1.
0x008SW_LOCK2Software lock register for page 2.
0x00cSW_LOCK3Software lock register for page 3.
0x010SW_LOCK4Software lock register for page 4.
0x014SW_LOCK5Software lock register for page 5.
0x018SW_LOCK6Software lock register for page 6.
0x01cSW_LOCK7Software lock register for page 7.
0x020SW_LOCK8Software lock register for page 8.
0x024SW_LOCK9Software lock register for page 9.
0x028SW_LOCK10Software lock register for page 10.
0x02cSW_LOCK11Software lock register for page 11.
0x030SW_LOCK12Software lock register for page 12.
0x034SW_LOCK13Software lock register for page 13.
0x038SW_LOCK14Software lock register for page 14.
0x03cSW_LOCK15Software lock register for page 15.
13.9. List of registers 13.9. List of registers1280
OffsetNameInfo
0x040SW_LOCK16Software lock register for page 16.
0x044SW_LOCK17Software lock register for page 17.
0x048SW_LOCK18Software lock register for page 18.
0x04cSW_LOCK19Software lock register for page 19.
0x050SW_LOCK20Software lock register for page 20.
0x054SW_LOCK21Software lock register for page 21.
0x058SW_LOCK22Software lock register for page 22.
0x05cSW_LOCK23Software lock register for page 23.
0x060SW_LOCK24Software lock register for page 24.
0x064SW_LOCK25Software lock register for page 25.
0x068SW_LOCK26Software lock register for page 26.
0x06cSW_LOCK27Software lock register for page 27.
0x070SW_LOCK28Software lock register for page 28.
0x074SW_LOCK29Software lock register for page 29.
0x078SW_LOCK30Software lock register for page 30.
0x07cSW_LOCK31Software lock register for page 31.
0x080SW_LOCK32Software lock register for page 32.
0x084SW_LOCK33Software lock register for page 33.
0x088SW_LOCK34Software lock register for page 34.
0x08cSW_LOCK35Software lock register for page 35.
0x090SW_LOCK36Software lock register for page 36.
0x094SW_LOCK37Software lock register for page 37.
0x098SW_LOCK38Software lock register for page 38.
0x09cSW_LOCK39Software lock register for page 39.
0x0a0SW_LOCK40Software lock register for page 40.
0x0a4SW_LOCK41Software lock register for page 41.
0x0a8SW_LOCK42Software lock register for page 42.
0x0acSW_LOCK43Software lock register for page 43.
0x0b0SW_LOCK44Software lock register for page 44.
0x0b4SW_LOCK45Software lock register for page 45.
0x0b8SW_LOCK46Software lock register for page 46.
0x0bcSW_LOCK47Software lock register for page 47.
0x0c0SW_LOCK48Software lock register for page 48.
0x0c4SW_LOCK49Software lock register for page 49.
0x0c8SW_LOCK50Software lock register for page 50.
0x0ccSW_LOCK51Software lock register for page 51.
OffsetNameInfo
0x0d0SW_LOCK52Software lock register for page 52.
0x0d4SW_LOCK53Software lock register for page 53.
0x0d8SW_LOCK54Software lock register for page 54.
0x0dcSW_LOCK55Software lock register for page 55.
0x0e0SW_LOCK56Software lock register for page 56.
0x0e4SW_LOCK57Software lock register for page 57.
0x0e8SW_LOCK58Software lock register for page 58.
0x0ecSW_LOCK59Software lock register for page 59.
0x0f0SW_LOCK60Software lock register for page 60.
0x0f4SW_LOCK61Software lock register for page 61.
0x0f8SW_LOCK62Software lock register for page 62.
0x0fcSW_LOCK63Software lock register for page 63.
0x100SBPI_INSTRDispatch instructions to the SBPI interface, used for programming the OTP fuses.
0x104SBPI_WDATA_0SBPI write payload bytes 3..0
0x108SBPI_WDATA_1SBPI write payload bytes 7..4
0x10cSBPI_WDATA_2SBPI write payload bytes 11..8
0x110SBPI_WDATA_3SBPI write payload bytes 15..12
0x114SBPI_RDATA_0Read payload bytes 3..0. Once read, the data in the register will automatically clear to 0.
0x118SBPI_RDATA_1Read payload bytes 7..4. Once read, the data in the register will automatically clear to 0.
0x11cSBPI_RDATA_2Read payload bytes 11..8. Once read, the data in the register will automatically clear to 0.
0x120SBPI_RDATA_3Read payload bytes 15..12. Once read, the data in the register will automatically clear to 0.
0x124SBPI_STATUS
0x128USRControls for APB data read interface (USER interface)
0x12cDBGDebug for OTP power-on state machine
0x134BISTDuring BIST, count address locations that have at least one leaky bit
0x138CRT_KEY_W0Word 0 (bits 31..0) of the key. Write only, read returns 0x0
0x13cCRT_KEY_W1Word 1 (bits 63..32) of the key. Write only, read returns 0x0
0x140CRT_KEY_W2Word 2 (bits 95..64) of the key. Write only, read returns 0x0
0x144CRT_KEY_W3Word 3 (bits 127..96) of the key. Write only, read returns 0x0
0x148CRITICALQuickly check values of critical flags read during boot up
0x14cKEY_VALIDWhich keys were valid (enrolled) at boot time
OffsetNameInfo
0x150DEBUGENEnable a debug feature that has been disabled. Debug features are disabled if one of the relevant critical boot flags is set in OTP (DEBUG_DISABLE or SECURE_DEBUG_DISABLE), OR if a debug key is marked valid in OTP, and the matching key value has not been supplied over SWD.
0x154DEBUGEN_LOCKWrite 1s to lock corresponding bits in DEBUGEN. This register is reset by the processor cold reset.
0x158ARCHSELArchitecture select (Arm/RISC-V), applied on next processor reset. The default and allowable values of this register are constrained by the critical boot flags.
0x15cARCHSEL_STATUSGet the current architecture select state of each core. Cores sample the current value of the ARCHSEL register when their warm reset is released, at which point the corresponding bit in this register will also update.
0x160BOOTDISTell the bootrom to ignore scratch register boot vectors (both power manager and watchdog) on the next power up.
0x164INTRRaw Interrupts
0x168INTEInterrupt Enable
0x16cINTFInterrupt Force
0x170INTSInterrupt status after masking & forcing

OTP: SW_LOCK0, SW_LOCK1, ..., SW_LOCK62, SW_LOCK63 Registers

Offsets: 0x000, 0x004, ..., 0x0f8, 0x0fc

Description

Software lock register for page N .

Locks are initialised from the OTP lock pages at reset. This register can be written to further advance the lock state of each page (until next reset), and read to check the current lock state of a page.

Table 1333.
SW_LOCK0,
SW_LOCK1, ...,
SW_LOCK62,
SW_LOCK63 Registers

BitsDescriptionTypeReset
31:4Reserved.--
3:2NSEC: Non-secure lock status. Writes are OR'd with the current value.RW-
Enumerated values:
0x0 → READ_WRITE
0x1 → READ_ONLY
0x3 → INACCESSIBLE
1:0SEC: Secure lock status. Writes are OR'd with the current value. This field is read-only to Non-secure code.RW-
Enumerated values:
0x0 → READ_WRITE
0x1 → READ_ONLY
0x3 → INACCESSIBLE

OTP: SBPI_INSTR Register

Offset: 0x100

Description

Dispatch instructions to the SBPI interface, used for programming the OTP fuses.

Table 1334.
SBPI_INSTR Register

BitsDescriptionTypeReset
31Reserved.--
30EXEC : Execute instructionSC0x0
29IS_WR : Payload type is writeRW0x0
28HAS_PAYLOAD : Instruction has payload (data to be written or to be read)RW0x0
27:24PAYLOAD_SIZE_M1 : Instruction payload size in bytes minus 1RW0x0
23:16TARGET : Instruction target, it can be PMC (0x3a) or DAP (0x02)RW0x00
15:8CMDRW0x00
7:0SHORT_WDATA : wdata to be used only when payload_size_m1=0RW0x00

OTP: SBPI_WDATA_0 Register

Offset: 0x104

Table 1335.
SBPI_WDATA_0
Register

BitsDescriptionTypeReset
31:0SBPI write payload bytes 3..0RW0x00000000

OTP: SBPI_WDATA_1 Register

Offset: 0x108

Table 1336.
SBPI_WDATA_1
Register

BitsDescriptionTypeReset
31:0SBPI write payload bytes 7..4RW0x00000000

OTP: SBPI_WDATA_2 Register

Offset: 0x10c

Table 1337.
SBPI_WDATA_2
Register

BitsDescriptionTypeReset
31:0SBPI write payload bytes 11..8RW0x00000000

OTP: SBPI_WDATA_3 Register

Offset: 0x110

Table 1338.
SBPI_WDATA_3
Register

BitsDescriptionTypeReset
31:0SBPI write payload bytes 15..12RW0x00000000

OTP: SBPI_RDATA_0 Register

Offset: 0x114

Table 1339.
SBPI_RDATA_0
Register

BitsDescriptionTypeReset
31:0Read payload bytes 3..0. Once read, the data in the register will automatically clear to 0.RO0x00000000

OTP: SBPI_RDATA_1 Register

Offset: 0x118

Table 1340.
SBPI_RDATA_1
Register

BitsDescriptionTypeReset
31:0Read payload bytes 7..4. Once read, the data in the register will automatically clear to 0.RO0x00000000

OTP: SBPI_RDATA_2 Register

Offset: 0x11c

Table 1341.
SBPI_RDATA_2
Register

BitsDescriptionTypeReset
31:0Read payload bytes 11..8. Once read, the data in the register will automatically clear to 0.RO0x00000000

OTP: SBPI_RDATA_3 Register

Offset: 0x120

Table 1342.
SBPI_RDATA_3
Register

BitsDescriptionTypeReset
31:0Read payload bytes 15..12. Once read, the data in the register will automatically clear to 0.RO0x00000000

OTP: SBPI_STATUS Register

Offset: 0x124

Table 1343.
SBPI_STATUS Register

BitsDescriptionTypeReset
31:24Reserved.--
23:16MISO : SBPI MISO (master in - slave out): response from SBPIRO-
15:13Reserved.--
12FLAG : SBPI flagRO-
11:9Reserved.--
8INSTR_MISS : Last instruction missed (dropped), as the previous has not finished runningWC0x0
7:5Reserved.--
4INSTR_DONE : Last instruction doneWC0x0
3:1Reserved.--
0RDATA_VLD : Read command has returned dataWC0x0

OTP: USR Register

Offset: 0x128

Description

Controls for APB data read interface (USER interface)

Table 1344. USR Register

Bits 31:0 Bits 31:0 Bits 31:28column_2Description Description Input value for GPIO0…31. Description QSPI_SD : Input value on QSPI SD0 (MOSI), SD1 (MISO), SD2 and SD3 pinsType RO Type RO Type ROReset - Reset 0x00000000 Reset 0x0
31:5Reserved.--
4PD : Power-down; 1 disables current reference. Must be 0 to read data from theRW0x0
3:1OTP. Reserved.--
0DCTRL: 1 enables USER interface; 0 disables USER interface (enables SBPI).RW0x1
BitsDescriptionTypeReset
31:13Reserved.--
12CUSTOMER_RMA_FLAG: The chip is in RMA modeRO-
11:8Reserved.--
7:4PSM_STATE: Monitor the PSM FSM’s stateRO-
3ROSC_UP: Ring oscillator is up and runningRO-
2ROSC_UP_SEEN: Ring oscillator was seen up and runningWC0x0
1BOOT_DONE: PSM boot done status flagRO-
0PSM_DONE: PSM done status flagRO-
BitsDescriptionTypeReset
31Reserved.--
30CNT_FAIL: Flag if the count of address locations with at least one leaky bitRO-
29CNT_CLRexceeds cnt_max : Clear counter before useSC0x0
28CNT_ENA: Enable the counter before the BIST function is initatedRW0x0
27:16CNT_MAX: The cnt_fail flag will be set if the number of leaky locationsRW0xfff
15:13Reserved.--
OTP: DBG Register Offset : 0x12c Description

Debug for OTP power-on state machine

Table 1345. DBG Register

OTP: BIST Register Offset : 0x134 Description

During BIST, count address locations that have at least one leaky bit

Table 1346. BIST Register

BitsDescriptionTypeReset
12:0CNT : Number of locations that have at least one leaky bit. Note: This count is true only if the BIST was initiated without the fix option.RO-

OTP: CRT_KEY_W0 Register

Offset: 0x138

Table 1347.
CRT_KEY_W0 Register

BitsDescriptionTypeReset
31:0Word 0 (bits 31..0) of the key. Write only, read returns 0x0WO0x00000000

OTP: CRT_KEY_W1 Register

Offset: 0x13c

Table 1348.
CRT_KEY_W1 Register

BitsDescriptionTypeReset
31:0Word 1 (bits 63..32) of the key. Write only, read returns 0x0WO0x00000000

OTP: CRT_KEY_W2 Register

Offset: 0x140

Table 1349.
CRT_KEY_W2 Register

BitsDescriptionTypeReset
31:0Word 2 (bits 95..64) of the key. Write only, read returns 0x0WO0x00000000

OTP: CRT_KEY_W3 Register

Offset: 0x144

Table 1350.
CRT_KEY_W3 Register

BitsDescriptionTypeReset
31:0Word 3 (bits 127..96) of the key. Write only, read returns 0x0WO0x00000000

OTP: CRITICAL Register

Offset: 0x148

Description

Quickly check values of critical flags read during boot up

Table 1351. CRITICAL
Register

BitsDescriptionTypeReset
31:18Reserved.--
17RISCV_DISABLERO0x0
16ARM_DISABLERO0x0
15:7Reserved.--
6:5GLITCH_DETECTOR_SENSRO0x0
4GLITCH_DETECTOR_ENABLERO0x0
3DEFAULT_ARCHSELRO0x0
2DEBUG_DISABLERO0x0
1SECURE_DEBUG_DISABLERO0x0
0SECURE_BOOT_ENABLERO0x0

OTP: KEY_VALID Register

Offset: 0x14c

Table 1352.
KEY_VALID Register

BitsDescriptionTypeReset
31:8Reserved.--
7:0Which keys were valid (enrolled) at boot timeRO0x00

OTP: DEBUGEN Register

Offset: 0x150

Description

Enable a debug feature that has been disabled. Debug features are disabled if one of the relevant critical boot flags is set in OTP (DEBUG_DISABLE or SECURE_DEBUG_DISABLE), OR if a debug key is marked valid in OTP, and the matching key value has not been supplied over SWD.

Specifically:

Table 1353. DEBUGEN Register

BitsDescriptionTypeReset
31:9Reserved.--
8

MISC: Enable other debug components. Specifically, the CTI, and the APB-AP used to access the RISC-V Debug Module.

These components are disabled by default if either of the debug disable critical flags is set, or if at least one debug key has been enrolled and the least secure of these enrolled key values has not been provided over SWD.

RW0x0
7:4Reserved.--
3

PROC1_SECURE: Permit core 1's Mem-AP to generate Secure accesses, assuming it is enabled at all. Also enable secure debug of core 1 (SPIDEN and SPNIDEN).

Secure debug of core 1 is disabled by default if the secure debug disable critical flag is set, or if at least one debug key has been enrolled and the most secure of these enrolled key values not yet provided over SWD.

RW0x0
Bits 31:0 Bits 31:0 Bits 31:28column_2Description Description Input value for GPIO0…31. Description QSPI_SD : Input value on QSPI SD0 (MOSI), SD1 (MISO), SD2 and SD3 pinsType RO Type RO Type ROReset - Reset 0x00000000 Reset 0x0
Register 31:9Reserved.--
8MISC: Write 1 to lock the MISC bit of DEBUGEN. Can’t be cleared once set.RW0x0
7:4Reserved.--
3PROC1_SECURE: Write 1 to lock the PROC1_SECURE bit of DEBUGEN. Can’t be cleared once set.RW0x0
2PROC1: Write 1 to lock the PROC1 bit of DEBUGEN. Can’t be cleared once set.RW0x0
1PROC0_SECURE: Write 1 to lock the PROC0_SECURE bit of DEBUGEN. Can’t be cleared once set.RW0x0
0PROC0: Write 1 to lock the PROC0 bit of DEBUGEN. Can’t be cleared once set.RW0x0

OTP: DEBUGEN_LOCK Register

Offset: 0x154

Description

Write 1s to lock corresponding bits in DEBUGEN. This register is reset by the processor cold reset.

Table 1354.
DEBUGEN_LOCK
Register

OTP: ARCHSEL Register

Offset: 0x158

Description

Architecture select (Arm/RISC-V). The default and allowable values of this register are constrained by the critical boot flags.

This register is reset by the earliest reset in the switched core power domain (before a processor cold reset).

Cores sample their architecture select signal on a warm reset. The source of the warm reset could be the system power-up state machine, the watchdog timer, Arm SYSRESETREQ or from RISC-V hartresetreq.

Note that when an Arm core is deselected, its cold reset domain is also held in reset, since in particular the SYSRESETREQ bit becomes inaccessible once the core is deselected. Note also the RISC-V cores do not have a cold reset domain, since their corresponding controls are located in the Debug Module.

Table 1355. ARCHSEL Register

BitsDescriptionTypeReset
31:2Reserved.--
1CORE1 : Select architecture for core 1.RW0x0
Enumerated values:
0x0 → ARM: Switch core 1 to Arm (Cortex-M33)
0x1 → RISC-V: Switch core 1 to RISC-V (Hazard3)
0CORE0 : Select architecture for core 0.RW0x0
Enumerated values:
0x0 → ARM: Switch core 0 to Arm (Cortex-M33)
0x1 → RISC-V: Switch core 0 to RISC-V (Hazard3)

OTP: ARCHSEL_STATUS Register

Offset: 0x15c

Description

Get the current architecture select state of each core. Cores sample the current value of the ARCHSEL register when their warm reset is released, at which point the corresponding bit in this register will also update.

Table 1356. ARCHSEL_STATUS Register

BitsDescriptionTypeReset
31:2Reserved.--
1CORE1 : Current architecture for core 0. Updated on processor warm reset.RO0x0
Enumerated values:
0x0 → ARM: Core 1 is currently Arm (Cortex-M33)
0x1 → RISC-V: Core 1 is currently RISC-V (Hazard3)
0CORE0 : Current architecture for core 0. Updated on processor warm reset.RO0x0
Enumerated values:
0x0 → ARM: Core 0 is currently Arm (Cortex-M33)
0x1 → RISC-V: Core 0 is currently RISC-V (Hazard3)

OTP: BOOTDIS Register

Offset: 0x160

Description

Tell the bootrom to ignore scratch register boot vectors (both power manager and watchdog) on the next power up.

If an early boot stage has soft-locked some OTP pages in order to protect their contents from later stages, there is a risk that Secure code running at a later stage can unlock the pages by performing a watchdog reset that resets the OTP.

This register can be used to ensure that the bootloader runs as normal on the next power up, preventing Secure code at

a later stage from accessing OTP in its unlocked state.

Should be used in conjunction with the power manager BOOTDIS register.

Table 1357. BOOTDIS Register

Bits Register 31:28 27 26 25 24Description QSPI_SD QSPI_CSN QSPI_SCK USB_DM USB_DPType WO WO WO WO WOReset 0x0 0x0 0x0 0x0 0x0
31:2Reserved.- -
1NEXT not cleared by software.: This flag always ORs writes into its current contents. It can be set butRW 0x0
0to prevent later stages from unlocking it via watchdog reset. NOW OR’d into BOOTDIS_NOW, and BOOTDIS_NEXT is cleared.: When the core is powered down, the current value of BOOTDIS_NEXT isWC 0x0
BitsRaw Interrupts DescriptionTypeReset
31:5Reserved.--
4APB_RD_NSEC_FAILWC0x0
3APB_RD_SEC_FAILWC0x0
2APB_DCTRL_FAILWC0x0
1SBPI_WR_FAILWC0x0
0SBPI_FLAG_NRO0x0
BitsInterrupt Enable DescriptionTypeReset
31:5Reserved.--
4APB_RD_NSEC_FAILRW0x0
3APB_RD_SEC_FAILRW0x0
2APB_DCTRL_FAILRW0x0

OTP: INTR Register

Offset: 0x164

Description

Raw Interrupts

Table 1358. INTR Register

OTP: INTE Register

Offset: 0x168

Description

Interrupt Enable

Table 1359. INTE Register

BitsDescriptionTypeReset
1SBPI_WR_FAILRW0x0
0SBPI_FLAG_NRW0x0

OTP: INTF Register

Offset: 0x16c

Description

Interrupt Force

Table 1360. INTF Register

BitsDescriptionTypeReset
31:5Reserved.--
4APB_RD_NSEC_FAILRW0x0
3APB_RD_SEC_FAILRW0x0
2APB_DCTRL_FAILRW0x0
1SBPI_WR_FAILRW0x0
0SBPI_FLAG_NRW0x0

OTP: INTS Register

Offset: 0x170

Description

Interrupt status after masking & forcing

Table 1361. INTS Register

BitsDescriptionTypeReset
31:5Reserved.--
4APB_RD_NSEC_FAILRO0x0
3APB_RD_SEC_FAILRO0x0
2APB_DCTRL_FAILRO0x0
1SBPI_WR_FAILRO0x0
0SBPI_FLAG_NRO0x0

13.10. Predefined OTP data locations

This section lists OTP locations used by either the hardware (particularly the OTP power-on state machine), the bootrom, or both. This listing is for RP2350 silicon revision A2.

OTP locations are listed by row number, not by address. When read through an ECC alias, OTP rows are spaced two bytes apart in the system address space; when read through a raw alias, OTP rows are four bytes apart. Therefore the row numbers given here should be multiplied by two or four appropriately when reading OTP contents directly from software. The OTP APIs provided by the bootrom use OTP row numbers directly, so this row-to-byte-address conversion is not necessary when accessing OTP through these APIs.

For normal (non-guarded) reads, you can access error-corrected content starting at OTP_DATA_BASE ( 0x40130000 ), and raw content starting at OTP_DATA_RAW_BASE ( 0x40134000 ). The register listings below indicate whether or not a given OTP row contains error-corrected contents. OTP never mixes error-corrected and non-error-corrected content in the same row.

OffsetNameInfo
0x010ROSC_CALIBRing oscillator frequency in kHz, measured during manufacturing (ECC)

This is measured at 1.1 V, at room temperature, with the ROSC configuration registers in their reset state.
0x011LPOSC_CALIBLow-power oscillator frequency in Hz, measured during manufacturing (ECC)

This is measured at 1.1V, at room temperature, with the LPOSC trim register in its reset state.
0x018NUM_GPIOSThe number of main user GPIOs (bank 0). Should read 48 in the QFN80 package, and 30 in the QFN60 package. (ECC)
0x036INFO_CRC0Lower 16 bits of CRC32 of OTP addresses 0x00 through 0x6b (polynomial 0x4c11db7, input reflected, output reflected, seed all-ones, final XOR all-ones) (ECC)
0x037INFO_CRC1Upper 16 bits of CRC32 of OTP addresses 0x00 through 0x6b (ECC)
0x038CRIT0Page 0 critical boot flags (RBIT-8)
0x039CRIT0_R1Redundant copy of CRIT0
0x03aCRIT0_R2Redundant copy of CRIT0
0x03bCRIT0_R3Redundant copy of CRIT0
0x03cCRIT0_R4Redundant copy of CRIT0
0x03dCRIT0_R5Redundant copy of CRIT0
0x03eCRIT0_R6Redundant copy of CRIT0
0x03fCRIT0_R7Redundant copy of CRIT0
0x040CRIT1Page 1 critical boot flags (RBIT-8)
0x041CRIT1_R1Redundant copy of CRIT1
0x042CRIT1_R2Redundant copy of CRIT1
0x043CRIT1_R3Redundant copy of CRIT1
0x044CRIT1_R4Redundant copy of CRIT1
0x045CRIT1_R5Redundant copy of CRIT1
0x046CRIT1_R6Redundant copy of CRIT1
0x047CRIT1_R7Redundant copy of CRIT1
0x048BOOT_FLAGS0Disable/Enable boot paths/features in the RP2350 mask ROM. Disables always supersede enables. Enables are provided where there are other configurations in OTP that must be valid. (RBIT-3)
0x049BOOT_FLAGS0_R1Redundant copy of BOOT_FLAGS0
0x04aBOOT_FLAGS0_R2Redundant copy of BOOT_FLAGS0
0x04bBOOT_FLAGS1Disable/Enable boot paths/features in the RP2350 mask ROM. Disables always supersede enables. Enables are provided where there are other configurations in OTP that must be valid. (RBIT-3)
Offset 0x42fc8 0x42fcc 0x42fd0 0x42fd4 0x42fd8Name DEVID DEVTYPE PIDR4 PIDR5 PIDR6Info Device Configuration register Device Type Identifier register CoreSight Periperal ID4 CoreSight Periperal ID5 CoreSight Periperal ID6
0x04cBOOT_FLAGS1_R1Redundant copy of BOOT_FLAGS1
0x04dBOOT_FLAGS1_R2Redundant copy of BOOT_FLAGS1
0x04eDEFAULT_BOOT_VERSION0Default boot version thermometer counter, bits 23:0 (RBIT-3)
0x04fDEFAULT_BOOT_VERSION0_R1Redundant copy of DEFAULT_BOOT_VERSION0
0x050DEFAULT_BOOT_VERSION0_R2Redundant copy of DEFAULT_BOOT_VERSION0
0x051DEFAULT_BOOT_VERSION1Default boot version thermometer counter, bits 47:24 (RBIT-3)
0x052DEFAULT_BOOT_VERSION1_R1Redundant copy of DEFAULT_BOOT_VERSION1
0x053DEFAULT_BOOT_VERSION1_R2Redundant copy of DEFAULT_BOOT_VERSION1
0x054FLASH_DEVINFOStores information about external flash device(s). (ECC)
0x055FLASH_PARTITION_SLOT_SIZEBOOT_FLAGS0_FLASH_DEVINFO_ENABLE is set. Gap between partition table slot 0 and slot 1 at the start of flash (the default size is 4096 bytes) (ECC) Enabled by the
0x056BOOTSEL_LED_CFGthe size is 4096 * (value + 1) Pin configuration for LED status, used by USB bootloader. (ECC)
0x057BOOTSEL_PLL_CFGMust be valid if BOOT_FLAGS0_ENABLE_BOOTSEL_LED is set. Optional PLL configuration for BOOTSEL mode. (ECC)
0x058BOOTSEL_XOSC_CFGNon-default crystal oscillator configuration for the USB
0x059USB_BOOT_FLAGSbootloader. (ECC) USB boot specific feature flags (RBIT-3)
0x05aUSB_BOOT_FLAGS_R1Redundant copy of USB_BOOT_FLAGS
0x05bUSB_BOOT_FLAGS_R2Redundant copy of USB_BOOT_FLAGS
0x05cUSB_WHITE_LABEL_ADDRRow index of the USB_WHITE_LABEL structure within OTP (ECC)
0x05eOTPBOOT_SRCOTP start row for the OTP boot image. (ECC)
0x05fOTPBOOT_LENLength in rows of the OTP boot image. (ECC)
0x060OTPBOOT_DST0Bits 15:0 of the OTP boot image load destination (and entry point). (ECC)
0x061OTPBOOT_DST1Bits 31:16 of the OTP boot image load destination (and entry point). (ECC)
0x080BOOTKEY0_0Bits 15:0 of SHA-256 hash of boot key 0 (ECC)
0x081BOOTKEY0_1Bits 31:16 of SHA-256 hash of boot key 0 (ECC)
0x082BOOTKEY0_2Bits 47:32 of SHA-256 hash of boot key 0 (ECC)
0x083BOOTKEY0_3Bits 63:48 of SHA-256 hash of boot key 0 (ECC)
0x084BOOTKEY0_4Bits 79:64 of SHA-256 hash of boot key 0 (ECC)
0x085BOOTKEY0_5Bits 95:80 of SHA-256 hash of boot key 0 (ECC)
0x086BOOTKEY0_6Bits 111:96 of SHA-256 hash of boot key 0 (ECC)
0x087BOOTKEY0_7Bits 127:112 of SHA-256 hash of boot key 0 (ECC)
OffsetNameInfo
0x088BOOTKEY0_8Bits 143:128 of SHA-256 hash of boot key 0 (ECC)
0x089BOOTKEY0_9Bits 159:144 of SHA-256 hash of boot key 0 (ECC)
0x08aBOOTKEY0_10Bits 175:160 of SHA-256 hash of boot key 0 (ECC)
0x08bBOOTKEY0_11Bits 191:176 of SHA-256 hash of boot key 0 (ECC)
0x08cBOOTKEY0_12Bits 207:192 of SHA-256 hash of boot key 0 (ECC)
0x08dBOOTKEY0_13Bits 223:208 of SHA-256 hash of boot key 0 (ECC)
0x08eBOOTKEY0_14Bits 239:224 of SHA-256 hash of boot key 0 (ECC)
0x08fBOOTKEY0_15Bits 255:240 of SHA-256 hash of boot key 0 (ECC)
0x090BOOTKEY1_0Bits 15:0 of SHA-256 hash of boot key 1 (ECC)
0x091BOOTKEY1_1Bits 31:16 of SHA-256 hash of boot key 1 (ECC)
0x092BOOTKEY1_2Bits 47:32 of SHA-256 hash of boot key 1 (ECC)
0x093BOOTKEY1_3Bits 63:48 of SHA-256 hash of boot key 1 (ECC)
0x094BOOTKEY1_4Bits 79:64 of SHA-256 hash of boot key 1 (ECC)
0x095BOOTKEY1_5Bits 95:80 of SHA-256 hash of boot key 1 (ECC)
0x096BOOTKEY1_6Bits 111:96 of SHA-256 hash of boot key 1 (ECC)
0x097BOOTKEY1_7Bits 127:112 of SHA-256 hash of boot key 1 (ECC)
0x098BOOTKEY1_8Bits 143:128 of SHA-256 hash of boot key 1 (ECC)
0x099BOOTKEY1_9Bits 159:144 of SHA-256 hash of boot key 1 (ECC)
0x09aBOOTKEY1_10Bits 175:160 of SHA-256 hash of boot key 1 (ECC)
0x09bBOOTKEY1_11Bits 191:176 of SHA-256 hash of boot key 1 (ECC)
0x09cBOOTKEY1_12Bits 207:192 of SHA-256 hash of boot key 1 (ECC)
0x09dBOOTKEY1_13Bits 223:208 of SHA-256 hash of boot key 1 (ECC)
0x09eBOOTKEY1_14Bits 239:224 of SHA-256 hash of boot key 1 (ECC)
0x09fBOOTKEY1_15Bits 255:240 of SHA-256 hash of boot key 1 (ECC)
0x0a0BOOTKEY2_0Bits 15:0 of SHA-256 hash of boot key 2 (ECC)
0x0a1BOOTKEY2_1Bits 31:16 of SHA-256 hash of boot key 2 (ECC)
0x0a2BOOTKEY2_2Bits 47:32 of SHA-256 hash of boot key 2 (ECC)
0x0a3BOOTKEY2_3Bits 63:48 of SHA-256 hash of boot key 2 (ECC)
0x0a4BOOTKEY2_4Bits 79:64 of SHA-256 hash of boot key 2 (ECC)
0x0a5BOOTKEY2_5Bits 95:80 of SHA-256 hash of boot key 2 (ECC)
0x0a6BOOTKEY2_6Bits 111:96 of SHA-256 hash of boot key 2 (ECC)
0x0a7BOOTKEY2_7Bits 127:112 of SHA-256 hash of boot key 2 (ECC)
0x0a8BOOTKEY2_8Bits 143:128 of SHA-256 hash of boot key 2 (ECC)
0x0a9BOOTKEY2_9Bits 159:144 of SHA-256 hash of boot key 2 (ECC)
0x0aaBOOTKEY2_10Bits 175:160 of SHA-256 hash of boot key 2 (ECC)
0x0abBOOTKEY2_11Bits 191:176 of SHA-256 hash of boot key 2 (ECC)
OffsetNameInfo
0x0acBOOTKEY2_12Bits 207:192 of SHA-256 hash of boot key 2 (ECC)
0x0adBOOTKEY2_13Bits 223:208 of SHA-256 hash of boot key 2 (ECC)
0x0aeBOOTKEY2_14Bits 239:224 of SHA-256 hash of boot key 2 (ECC)
0x0afBOOTKEY2_15Bits 255:240 of SHA-256 hash of boot key 2 (ECC)
0x0b0BOOTKEY3_0Bits 15:0 of SHA-256 hash of boot key 3 (ECC)
0x0b1BOOTKEY3_1Bits 31:16 of SHA-256 hash of boot key 3 (ECC)
0x0b2BOOTKEY3_2Bits 47:32 of SHA-256 hash of boot key 3 (ECC)
0x0b3BOOTKEY3_3Bits 63:48 of SHA-256 hash of boot key 3 (ECC)
0x0b4BOOTKEY3_4Bits 79:64 of SHA-256 hash of boot key 3 (ECC)
0x0b5BOOTKEY3_5Bits 95:80 of SHA-256 hash of boot key 3 (ECC)
0x0b6BOOTKEY3_6Bits 111:96 of SHA-256 hash of boot key 3 (ECC)
0x0b7BOOTKEY3_7Bits 127:112 of SHA-256 hash of boot key 3 (ECC)
0x0b8BOOTKEY3_8Bits 143:128 of SHA-256 hash of boot key 3 (ECC)
0x0b9BOOTKEY3_9Bits 159:144 of SHA-256 hash of boot key 3 (ECC)
0x0baBOOTKEY3_10Bits 175:160 of SHA-256 hash of boot key 3 (ECC)
0x0bbBOOTKEY3_11Bits 191:176 of SHA-256 hash of boot key 3 (ECC)
0x0bcBOOTKEY3_12Bits 207:192 of SHA-256 hash of boot key 3 (ECC)
0x0bdBOOTKEY3_13Bits 223:208 of SHA-256 hash of boot key 3 (ECC)
0x0beBOOTKEY3_14Bits 239:224 of SHA-256 hash of boot key 3 (ECC)
0x0bfBOOTKEY3_15Bits 255:240 of SHA-256 hash of boot key 3 (ECC)
0xf48KEY1_0Bits 15:0 of OTP access key 1 (ECC)
0xf49KEY1_1Bits 31:16 of OTP access key 1 (ECC)
0xf4aKEY1_2Bits 47:32 of OTP access key 1 (ECC)
0xf4bKEY1_3Bits 63:48 of OTP access key 1 (ECC)
0xf4cKEY1_4Bits 79:64 of OTP access key 1 (ECC)
0xf4dKEY1_5Bits 95:80 of OTP access key 1 (ECC)
0xf4eKEY1_6Bits 111:96 of OTP access key 1 (ECC)
0xf4fKEY1_7Bits 127:112 of OTP access key 1 (ECC)
0xf50KEY2_0Bits 15:0 of OTP access key 2 (ECC)
0xf51KEY2_1Bits 31:16 of OTP access key 2 (ECC)
0xf52KEY2_2Bits 47:32 of OTP access key 2 (ECC)
0xf53KEY2_3Bits 63:48 of OTP access key 2 (ECC)
0xf54KEY2_4Bits 79:64 of OTP access key 2 (ECC)
0xf55KEY2_5Bits 95:80 of OTP access key 2 (ECC)
0xf56KEY2_6Bits 111:96 of OTP access key 2 (ECC)
0xf57KEY2_7Bits 127:112 of OTP access key 2 (ECC)
OffsetNameInfo
0xf58KEY3_0Bits 15:0 of OTP access key 3 (ECC)
0xf59KEY3_1Bits 31:16 of OTP access key 3 (ECC)
0xf5aKEY3_2Bits 47:32 of OTP access key 3 (ECC)
0xf5bKEY3_3Bits 63:48 of OTP access key 3 (ECC)
0xf5cKEY3_4Bits 79:64 of OTP access key 3 (ECC)
0xf5dKEY3_5Bits 95:80 of OTP access key 3 (ECC)
0xf5eKEY3_6Bits 111:96 of OTP access key 3 (ECC)
0xf5fKEY3_7Bits 127:112 of OTP access key 3 (ECC)
0xf60KEY4_0Bits 15:0 of OTP access key 4 (ECC)
0xf61KEY4_1Bits 31:16 of OTP access key 4 (ECC)
0xf62KEY4_2Bits 47:32 of OTP access key 4 (ECC)
0xf63KEY4_3Bits 63:48 of OTP access key 4 (ECC)
0xf64KEY4_4Bits 79:64 of OTP access key 4 (ECC)
0xf65KEY4_5Bits 95:80 of OTP access key 4 (ECC)
0xf66KEY4_6Bits 111:96 of OTP access key 4 (ECC)
0xf67KEY4_7Bits 127:112 of OTP access key 4 (ECC)
0xf68KEY5_0Bits 15:0 of OTP access key 5 (ECC)
0xf69KEY5_1Bits 31:16 of OTP access key 5 (ECC)
0xf6aKEY5_2Bits 47:32 of OTP access key 5 (ECC)
0xf6bKEY5_3Bits 63:48 of OTP access key 5 (ECC)
0xf6cKEY5_4Bits 79:64 of OTP access key 5 (ECC)
0xf6dKEY5_5Bits 95:80 of OTP access key 5 (ECC)
0xf6eKEY5_6Bits 111:96 of OTP access key 5 (ECC)
0xf6fKEY5_7Bits 127:112 of OTP access key 5 (ECC)
0xf70KEY6_0Bits 15:0 of OTP access key 6 (ECC)
0xf71KEY6_1Bits 31:16 of OTP access key 6 (ECC)
0xf72KEY6_2Bits 47:32 of OTP access key 6 (ECC)
0xf73KEY6_3Bits 63:48 of OTP access key 6 (ECC)
0xf74KEY6_4Bits 79:64 of OTP access key 6 (ECC)
0xf75KEY6_5Bits 95:80 of OTP access key 6 (ECC)
0xf76KEY6_6Bits 111:96 of OTP access key 6 (ECC)
0xf77KEY6_7Bits 127:112 of OTP access key 6 (ECC)
0xf79KEY1_VALIDValid flag for key 1.
0xf7aKEY2_VALIDValid flag for key 2.
0xf7bKEY3_VALIDValid flag for key 3.
0xf7cKEY4_VALIDValid flag for key 4.
OffsetNameInfo
0xf7dKEY5_VALIDValid flag for key 5.
0xf7eKEY6_VALIDValid flag for key 6.
0xf80PAGE0_LOCK0Lock configuration LSBs for page 0 (rows 0x0 through 0x3f).
0xf81PAGE0_LOCK1Lock configuration MSBs for page 0 (rows 0x0 through 0x3f).
0xf82PAGE1_LOCK0Lock configuration LSBs for page 1 (rows 0x40 through 0x7f).
0xf83PAGE1_LOCK1Lock configuration MSBs for page 1 (rows 0x40 through 0x7f).
0xf84PAGE2_LOCK0Lock configuration LSBs for page 2 (rows 0x80 through 0xbf).
0xf85PAGE2_LOCK1Lock configuration MSBs for page 2 (rows 0x80 through 0xbf).
0xf86PAGE3_LOCK0Lock configuration LSBs for page 3 (rows 0xc0 through 0xff).
0xf87PAGE3_LOCK1Lock configuration MSBs for page 3 (rows 0xc0 through 0xff).
0xf88PAGE4_LOCK0Lock configuration LSBs for page 4 (rows 0x100 through 0x13f).
0xf89PAGE4_LOCK1Lock configuration MSBs for page 4 (rows 0x100 through 0x13f).
0xf8aPAGE5_LOCK0Lock configuration LSBs for page 5 (rows 0x140 through 0x17f).
0xf8bPAGE5_LOCK1Lock configuration MSBs for page 5 (rows 0x140 through 0x17f).
0xf8cPAGE6_LOCK0Lock configuration LSBs for page 6 (rows 0x180 through 0x1bf).
0xf8dPAGE6_LOCK1Lock configuration MSBs for page 6 (rows 0x180 through 0x1bf).
0xf8ePAGE7_LOCK0Lock configuration LSBs for page 7 (rows 0x1c0 through 0x1ff).
0xf8fPAGE7_LOCK1Lock configuration MSBs for page 7 (rows 0x1c0 through 0x1ff).
0xf90PAGE8_LOCK0Lock configuration LSBs for page 8 (rows 0x200 through 0x23f).
0xf91PAGE8_LOCK1Lock configuration MSBs for page 8 (rows 0x200 through 0x23f).
0xf92PAGE9_LOCK0Lock configuration LSBs for page 9 (rows 0x240 through 0x27f).
0xf93PAGE9_LOCK1Lock configuration MSBs for page 9 (rows 0x240 through 0x27f).
0xf94PAGE10_LOCK0Lock configuration LSBs for page 10 (rows 0x280 through 0x2bf).
0xf95PAGE10_LOCK1Lock configuration MSBs for page 10 (rows 0x280 through 0x2bf).
0xf96PAGE11_LOCK0Lock configuration LSBs for page 11 (rows 0x2c0 through 0x2ff).
0xf97PAGE11_LOCK1Lock configuration MSBs for page 11 (rows 0x2c0 through 0x2ff).
0xf98PAGE12_LOCK0Lock configuration LSBs for page 12 (rows 0x300 through 0x33f).
0xf99PAGE12_LOCK1Lock configuration MSBs for page 12 (rows 0x300 through 0x33f).
0xf9aPAGE13_LOCK0Lock configuration LSBs for page 13 (rows 0x340 through 0x37f).
0xf9bPAGE13_LOCK1Lock configuration MSBs for page 13 (rows 0x340 through 0x37f).
OffsetNameInfo
0xf9cPAGE14_LOCK0Lock configuration LSBs for page 14 (rows 0x380 through 0x3bf).
0xf9dPAGE14_LOCK1Lock configuration MSBs for page 14 (rows 0x380 through 0x3bf).
0xf9ePAGE15_LOCK0Lock configuration LSBs for page 15 (rows 0x3c0 through 0x3ff).
0xf9fPAGE15_LOCK1Lock configuration MSBs for page 15 (rows 0x3c0 through 0x3ff).
0xfa0PAGE16_LOCK0Lock configuration LSBs for page 16 (rows 0x400 through 0x43f).
0xfa1PAGE16_LOCK1Lock configuration MSBs for page 16 (rows 0x400 through 0x43f).
0xfa2PAGE17_LOCK0Lock configuration LSBs for page 17 (rows 0x440 through 0x47f).
0xfa3PAGE17_LOCK1Lock configuration MSBs for page 17 (rows 0x440 through 0x47f).
0xfa4PAGE18_LOCK0Lock configuration LSBs for page 18 (rows 0x480 through 0x4bf).
0xfa5PAGE18_LOCK1Lock configuration MSBs for page 18 (rows 0x480 through 0x4bf).
0xfa6PAGE19_LOCK0Lock configuration LSBs for page 19 (rows 0x4c0 through 0x4ff).
0xfa7PAGE19_LOCK1Lock configuration MSBs for page 19 (rows 0x4c0 through 0x4ff).
0xfa8PAGE20_LOCK0Lock configuration LSBs for page 20 (rows 0x500 through 0x53f).
0xfa9PAGE20_LOCK1Lock configuration MSBs for page 20 (rows 0x500 through 0x53f).
0xfaaPAGE21_LOCK0Lock configuration LSBs for page 21 (rows 0x540 through 0x57f).
0xfabPAGE21_LOCK1Lock configuration MSBs for page 21 (rows 0x540 through 0x57f).
0xfacPAGE22_LOCK0Lock configuration LSBs for page 22 (rows 0x580 through 0x5bf).
0xfadPAGE22_LOCK1Lock configuration MSBs for page 22 (rows 0x580 through 0x5bf).
0xfaePAGE23_LOCK0Lock configuration LSBs for page 23 (rows 0x5c0 through 0x5ff).
0xfafPAGE23_LOCK1Lock configuration MSBs for page 23 (rows 0x5c0 through 0x5ff).
0xfb0PAGE24_LOCK0Lock configuration LSBs for page 24 (rows 0x600 through 0x63f).
0xfb1PAGE24_LOCK1Lock configuration MSBs for page 24 (rows 0x600 through 0x63f).
0xfb2PAGE25_LOCK0Lock configuration LSBs for page 25 (rows 0x640 through 0x67f).
OffsetNameInfo
0xfb3PAGE25_LOCK1Lock configuration MSBs for page 25 (rows 0x640 through 0x67f).
0xfb4PAGE26_LOCK0Lock configuration LSBs for page 26 (rows 0x680 through 0x6bf).
0xfb5PAGE26_LOCK1Lock configuration MSBs for page 26 (rows 0x680 through 0x6bf).
0xfb6PAGE27_LOCK0Lock configuration LSBs for page 27 (rows 0x6c0 through 0x6ff).
0xfb7PAGE27_LOCK1Lock configuration MSBs for page 27 (rows 0x6c0 through 0x6ff).
0xfb8PAGE28_LOCK0Lock configuration LSBs for page 28 (rows 0x700 through 0x73f).
0xfb9PAGE28_LOCK1Lock configuration MSBs for page 28 (rows 0x700 through 0x73f).
0xfbaPAGE29_LOCK0Lock configuration LSBs for page 29 (rows 0x740 through 0x77f).
0xfbbPAGE29_LOCK1Lock configuration MSBs for page 29 (rows 0x740 through 0x77f).
0xfbcPAGE30_LOCK0Lock configuration LSBs for page 30 (rows 0x780 through 0x7bf).
0xfbdPAGE30_LOCK1Lock configuration MSBs for page 30 (rows 0x780 through 0x7bf).
0xfbePAGE31_LOCK0Lock configuration LSBs for page 31 (rows 0x7c0 through 0x7ff).
0xfbefPAGE31_LOCK1Lock configuration MSBs for page 31 (rows 0x7c0 through 0x7ff).
0xfc0PAGE32_LOCK0Lock configuration LSBs for page 32 (rows 0x800 through 0x83f).
0xfc1PAGE32_LOCK1Lock configuration MSBs for page 32 (rows 0x800 through 0x83f).
0xfc2PAGE33_LOCK0Lock configuration LSBs for page 33 (rows 0x840 through 0x87f).
0xfc3PAGE33_LOCK1Lock configuration MSBs for page 33 (rows 0x840 through 0x87f).
0xfc4PAGE34_LOCK0Lock configuration LSBs for page 34 (rows 0x880 through 0x8bf).
0xfc5PAGE34_LOCK1Lock configuration MSBs for page 34 (rows 0x880 through 0x8bf).
0xfc6PAGE35_LOCK0Lock configuration LSBs for page 35 (rows 0x8c0 through 0x8ff).
0xfc7PAGE35_LOCK1Lock configuration MSBs for page 35 (rows 0x8c0 through 0x8ff).
0xfc8PAGE36_LOCK0Lock configuration LSBs for page 36 (rows 0x900 through 0x93f).
0xfc9PAGE36_LOCK1Lock configuration MSBs for page 36 (rows 0x900 through 0x93f).
OffsetNameInfo
0xfcaPAGE37_LOCK0Lock configuration LSBs for page 37 (rows 0x940 through 0x97f).
0xfcbPAGE37_LOCK1Lock configuration MSBs for page 37 (rows 0x940 through 0x97f).
0xfccPAGE38_LOCK0Lock configuration LSBs for page 38 (rows 0x980 through 0x9bf).
0xfcdPAGE38_LOCK1Lock configuration MSBs for page 38 (rows 0x980 through 0x9bf).
0xfcePAGE39_LOCK0Lock configuration LSBs for page 39 (rows 0x9c0 through 0x9ff).
0xfcfPAGE39_LOCK1Lock configuration MSBs for page 39 (rows 0x9c0 through 0x9ff).
0xfd0PAGE40_LOCK0Lock configuration LSBs for page 40 (rows 0xa00 through 0xa3f).
0xfd1PAGE40_LOCK1Lock configuration MSBs for page 40 (rows 0xa00 through 0xa3f).
0xfd2PAGE41_LOCK0Lock configuration LSBs for page 41 (rows 0xa40 through 0xa7f).
0xfd3PAGE41_LOCK1Lock configuration MSBs for page 41 (rows 0xa40 through 0xa7f).
0xfd4PAGE42_LOCK0Lock configuration LSBs for page 42 (rows 0xa80 through 0xabf).
0xfd5PAGE42_LOCK1Lock configuration MSBs for page 42 (rows 0xa80 through 0xabf).
0xfd6PAGE43_LOCK0Lock configuration LSBs for page 43 (rows 0xac0 through 0xaff).
0xfd7PAGE43_LOCK1Lock configuration MSBs for page 43 (rows 0xac0 through 0xaff).
0xfd8PAGE44_LOCK0Lock configuration LSBs for page 44 (rows 0xb00 through 0xb3f).
0xfd9PAGE44_LOCK1Lock configuration MSBs for page 44 (rows 0xb00 through 0xb3f).
0xfdaPAGE45_LOCK0Lock configuration LSBs for page 45 (rows 0xb40 through 0xb7f).
0xfdbPAGE45_LOCK1Lock configuration MSBs for page 45 (rows 0xb40 through 0xb7f).
0xfdcPAGE46_LOCK0Lock configuration LSBs for page 46 (rows 0xb80 through 0xbbf).
0xfddPAGE46_LOCK1Lock configuration MSBs for page 46 (rows 0xb80 through 0xbbf).
0xfdePAGE47_LOCK0Lock configuration LSBs for page 47 (rows 0xbc0 through 0xbff).
0xfdfPAGE47_LOCK1Lock configuration MSBs for page 47 (rows 0xbc0 through 0xbff).
0xfe0PAGE48_LOCK0Lock configuration LSBs for page 48 (rows 0xc00 through 0xc3f).
OffsetNameInfo
0xfe1PAGE48_LOCK1Lock configuration MSBs for page 48 (rows 0xc00 through 0xc3f).
0xfe2PAGE49_LOCK0Lock configuration LSBs for page 49 (rows 0xc40 through 0xc7f).
0xfe3PAGE49_LOCK1Lock configuration MSBs for page 49 (rows 0xc40 through 0xc7f).
0xfe4PAGE50_LOCK0Lock configuration LSBs for page 50 (rows 0xc80 through 0xcbf).
0xfe5PAGE50_LOCK1Lock configuration MSBs for page 50 (rows 0xc80 through 0xcbf).
0xfe6PAGE51_LOCK0Lock configuration LSBs for page 51 (rows 0xcc0 through 0xcff).
0xfe7PAGE51_LOCK1Lock configuration MSBs for page 51 (rows 0xcc0 through 0xcff).
0xfe8PAGE52_LOCK0Lock configuration LSBs for page 52 (rows 0xd00 through 0xd3f).
0xfe9PAGE52_LOCK1Lock configuration MSBs for page 52 (rows 0xd00 through 0xd3f).
0xfeaPAGE53_LOCK0Lock configuration LSBs for page 53 (rows 0xd40 through 0xd7f).
0xfebPAGE53_LOCK1Lock configuration MSBs for page 53 (rows 0xd40 through 0xd7f).
0xfecPAGE54_LOCK0Lock configuration LSBs for page 54 (rows 0xd80 through 0xdbf).
0xfedPAGE54_LOCK1Lock configuration MSBs for page 54 (rows 0xd80 through 0xdbf).
0xfeePAGE55_LOCK0Lock configuration LSBs for page 55 (rows 0xdc0 through 0xdf).
0xfefPAGE55_LOCK1Lock configuration MSBs for page 55 (rows 0xdc0 through 0xdf).
0xff0PAGE56_LOCK0Lock configuration LSBs for page 56 (rows 0xe00 through 0xe3f).
0xff1PAGE56_LOCK1Lock configuration MSBs for page 56 (rows 0xe00 through 0xe3f).
0xff2PAGE57_LOCK0Lock configuration LSBs for page 57 (rows 0xe40 through 0xe7f).
0xff3PAGE57_LOCK1Lock configuration MSBs for page 57 (rows 0xe40 through 0xe7f).
0xff4PAGE58_LOCK0Lock configuration LSBs for page 58 (rows 0xe80 through 0xebf).
0xff5PAGE58_LOCK1Lock configuration MSBs for page 58 (rows 0xe80 through 0xebf).
0xff6PAGE59_LOCK0Lock configuration LSBs for page 59 (rows 0xec0 through 0xeff).
0xff7PAGE59_LOCK1Lock configuration MSBs for page 59 (rows 0xec0 through 0xeff).

Table 1365. CHIPID2 Register

BitsDescriptionTypeReset
31:16Reserved.--
15:0Bits 47:32 of public device ID (ECC)RO-
OTP_DATA: CHIPID3 Register

Offset: 0x003

Table 1366. CHIPID3 Register

BitsDescriptionTypeReset
31:16Reserved.--
15:0Bits 63:48 of public device ID (ECC)RO-
OTP_DATA: RANDID0 Register

Offset: 0x004

Table 1367. RANDID0 Register

BitsDescriptionTypeReset
31:16Reserved.--
15:0

Bits 15:0 of private per-device random number (ECC)

The RANDID0..7 rows form a 128-bit random number generated during device test.

This ID is not exposed through the USB PICOBOT GET_INFO command or the ROM get_sys_info() API. However note that the USB PICOBOT OTP access point can read the entirety of page 0, so this value is not meaningfully private unless the USB PICOBOT interface is disabled via the DISABLE_BOOTSEL_USB_PICOBOT_IFC flag in BOOT_FLAGS0 .

RO-
OTP_DATA: RANDID1 Register

Offset: 0x005

Table 1368. RANDID1 Register

BitsDescriptionTypeReset
31:16Reserved.--
15:0Bits 31:16 of private per-device random number (ECC)RO-
OTP_DATA: RANDID2 Register

Offset: 0x006

Table 1369. RANDID2 Register

BitsDescriptionTypeReset
31:16Reserved.--
15:0Bits 47:32 of private per-device random number (ECC)RO-
OTP_DATA: RANDID3 Register

Offset: 0x007

Table 1370. RANDID3 Register

BitsDescriptionTypeReset
31:16Reserved.--
BitsDescriptionTypeReset
15:0Bits 63:48 of private per-device random number (ECC)RO-

OTP_DATA: RANDID4 Register

Offset: 0x008

Table 1371. RANDID4 Register

BitsDescriptionTypeReset
31:16Reserved.--
15:0Bits 79:64 of private per-device random number (ECC)RO-

OTP_DATA: RANDID5 Register

Offset: 0x009

Table 1372. RANDID5 Register

BitsDescriptionTypeReset
31:16Reserved.--
15:0Bits 95:80 of private per-device random number (ECC)RO-

OTP_DATA: RANDID6 Register

Offset: 0x00a

Table 1373. RANDID6 Register

BitsDescriptionTypeReset
31:16Reserved.--
15:0Bits 111:96 of private per-device random number (ECC)RO-

OTP_DATA: RANDID7 Register

Offset: 0x00b

Table 1374. RANDID7 Register

BitsDescriptionTypeReset
31:16Reserved.--
15:0Bits 127:112 of private per-device random number (ECC)RO-

OTP_DATA: ROSC_CALIB Register

Offset: 0x010

Table 1375. ROSC_CALIB Register

BitsDescriptionTypeReset
31:16Reserved.--
15:0Ring oscillator frequency in kHz, measured during manufacturing (ECC)

This is measured at 1.1 V, at room temperature, with the ROSC configuration registers in their reset state.
RO-

OTP_DATA: LPOSC_CALIB Register

Offset: 0x011

Table 1376.
LPOSC_CALIB Register

BitsDescriptionTypeReset
31:16Reserved.--
15:0Low-power oscillator frequency in Hz, measured during manufacturing (ECC)

This is measured at 1.1V, at room temperature, with the LPOSC trim register in its reset state.
RO-

OTP_DATA: NUM_GPIOs Register

Offset: 0x018

Table 1377.
NUM_GPIOs Register

BitsDescriptionTypeReset
31:8Reserved.--
7:0The number of main user GPIOs (bank 0). Should read 48 in the QFN80 package, and 30 in the QFN60 package. (ECC)RO-

OTP_DATA: INFO_CRC0 Register

Offset: 0x036

Table 1378.
INFO_CRC0 Register

BitsDescriptionTypeReset
31:16Reserved.--
15:0Lower 16 bits of CRC32 of OTP addresses 0x00 through 0x6b (polynomial 0x4c11db7, input reflected, output reflected, seed all-ones, final XOR all-ones) (ECC)RO-

OTP_DATA: INFO_CRC1 Register

Offset: 0x037

Table 1379.
INFO_CRC1 Register

BitsDescriptionTypeReset
31:16Reserved.--
15:0Upper 16 bits of CRC32 of OTP addresses 0x00 through 0x6b (ECC)RO-

OTP_DATA: CRIT0 Register

Offset: 0x038

Description

Page 0 critical boot flags (RBIT-8)

Table 1380. CRIT0 Register

BitsDescriptionTypeReset
31:2Reserved.--
1RISCV_DISABLE : Permanently disable RISC-V processors (Hazard3)RO-
0ARM_DISABLE : Permanently disable ARM processors (Cortex-M33)RO-

OTP_DATA: CRIT0_R1, CRIT0_R2, ..., CRIT0_R6, CRIT0_R7 Registers

Offsets: 0x039, 0x03a, ..., 0x03e, 0x03f

Table 1381. CRIT0_R1, CRIT0_R2, ..., CRIT0_R6, CRIT0_R7 Registers

BitsDescriptionTypeReset
31:24Reserved.--
23:0Redundant copy of CRIT0RO-

OTP_DATA: CRIT1 Register

Offset: 0x040

Description

Page 1 critical boot flags (RBIT-8)

Table 1382. CRIT1 Register

BitsDescriptionTypeReset
31:7Reserved.--
6:5GLITCH_DETECTOR_SENS : Increase the sensitivity of the glitch detectors from their default.RO-
4GLITCH_DETECTOR_ENABLE : Arm the glitch detectors to reset the system if an abnormal clock/power event is observed.RO-
3BOOT_ARCH : Set the default boot architecture, 0=ARM 1=RISC-V. Ignored if ARM_DISABLE, RISC_V_DISABLE or SECURE_BOOT_ENABLE is set.RO-
2DEBUG_DISABLE : Disable all debug accessRO-
1SECURE_DEBUG_DISABLE : Disable Secure debug accessRO-
0SECURE_BOOT_ENABLE : Enable boot signature enforcement, and permanently disable the RISC-V cores.RO-

OTP_DATA: CRIT1_R1, CRIT1_R2, ..., CRIT1_R6, CRIT1_R7 Registers

Offsets: 0x041, 0x042, ..., 0x046, 0x047

Table 1383. CRIT1_R1, CRIT1_R2, ..., CRIT1_R6, CRIT1_R7 Registers

BitsDescriptionTypeReset
31:24Reserved.--
23:0Redundant copy of CRIT1RO-

OTP_DATA: BOOT_FLAGS0 Register

Offset: 0x048

Description

Disable/Enable boot paths/features in the RP2350 mask ROM. Disables always supersede enables. Enables are provided where there are other configurations in OTP that must be valid. (RBIT-3)

Table 1384. BOOT_FLAGS0 Register

BitsDescriptionTypeReset
31:22Reserved.--
21DISABLE_SRAM_WINDOW_BOOTRO-
20DISABLE_XIP_ACCESS_ON_SRAM_ENTRY : Disable all access to XIP after entering an SRAM binary.

Note that this will cause bootrom APIs that access XIP to fail, including APIs that interact with the partition table.
RO-
19DISABLE_BOOTSEL_UART_BOOTRO-
BitsDescriptionTypeReset
18DISABLE_BOOTSEL_USB_PICOBOOT_IFCRO-
17DISABLE_BOOTSEL_USB_MSD_IFCRO-
16DISABLE_WATCHDOG_SCRATCHRO-
15DISABLE_POWER_SCRATCHRO-
14

ENABLE_OTP_BOOT : Enable OTP boot. A number of OTP rows specified by OTPBOOT_LEN will be loaded, starting from OTPBOOT_SRC, into the SRAM location specified by OTPBOOT_DST1 and OTPBOOT_DST0.

The loaded program image is stored with ECC, 16 bits per row, and must contain a valid IMAGE_DEF. Do not set this bit without first programming an image into OTP and configuring OTPBOOT_LEN, OTPBOOT_SRC, OTPBOOT_DST0 and OTPBOOT_DST1.

Note that OTPBOOT_LEN and OTPBOOT_SRC must be even numbers of OTP rows. Equivalently, the image must be a multiple of 32 bits in size, and must start at a 32-bit-aligned address in the ECC read data address window.

RO-
13DISABLE_OTP_BOOT : Takes precedence over ENABLE_OTP_BOOT.RO-
12DISABLE_FLASH_BOOTRO-
11ROLLBACK_REQUIRED : Require binaries to have a rollback version. Set automatically the first time a binary with a rollback version is booted.RO-
10HASHED_PARTITION_TABLE : Require a partition table to be hashed (if not signed)RO-
9SECURE_PARTITION_TABLE : Require a partition table to be signedRO-
8DISABLE_AUTO_SWITCH_ARCH : Disable auto-switch of CPU architecture on boot when the (only) binary to be booted is for the other Arm/RISC-V architecture and both architectures are enabledRO-
7SINGLE_FLASH_BINARY : Restrict flash boot path to use of a single binary at the start of flashRO-
6

OVERRIDE_FLASH_PARTITION_SLOT_SIZE : Override the limit for default flash metadata scanning.

The value is specified in FLASH_PARTITION_SLOT_SIZE. Make sure FLASH_PARTITION_SLOT_SIZE is valid before setting this bit

RO-
5FLASH_DEVINFO_ENABLE : Mark FLASH_DEVINFO as containing valid, ECC'd data which describes external flash devices.RO-
4FAST_SIGCHECK_ROSC_DIV : Enable quartering of ROSC divisor during signature check, to reduce secure boot timeRO-
3

FLASH_IO_VOLTAGE_1V8 : If 1, configure the QSPI pads for 1.8 V operation when accessing flash for the first time from the bootrom, using the VOLTAGE_SELECT register for the QSPI pads bank. This slightly improves the input timing of the pads at low voltages, but does not affect their output characteristics.

If 0, leave VOLTAGE_SELECT in its reset state (suitable for operation at and above 2.5 V)

RO-
BitsDescriptionTypeReset
2ENABLE_BOOTSEL_NON_DEFAULT_PLL_XOSC_CFG : Enable loading of the non-default XOSC and PLL configuration before entering BOOTSEL mode.

Ensure that BOOTSEL_XOSC_CFG and BOOTSEL_PLL_CFG are correctly programmed before setting this bit.

If this bit is set, user software may use the contents of BOOTSEL_PLL_CFG to calculate the expected XOSC frequency based on the fixed USB boot frequency of 48 MHz.
RO-
1ENABLE_BOOTSEL_LED : Enable bootloader activity LED. If set, bootsel_led_cfg is assumed to be validRO-
0Reserved.--

OTP_DATA: BOOT_FLAGS0_R1, BOOT_FLAGS0_R2 Registers

Offsets: 0x049, 0x04a

Table 1385.
BOOT_FLAGS0_R1,
BOOT_FLAGS0_R2
Registers

BitsDescriptionTypeReset
31:24Reserved.--
23:0Redundant copy of BOOT_FLAGS0RO-

OTP_DATA: BOOT_FLAGS1 Register

Offset: 0x04b

Description

Disable/Enable boot paths/features in the RP2350 mask ROM. Disables always supersede enables. Enables are provided where there are other configurations in OTP that must be valid. (RBIT-3)

Table 1386.
BOOT_FLAGS1
Register

BitsDescriptionTypeReset
31:20Reserved.--
19DOUBLE_TAP : Enable entering BOOTSEL mode via double-tap of the RUN/RSTn pin. Adds a significant delay to boot time, as configured by DOUBLE_TAP_DELAY.

This functions by waiting at startup (i.e. following a reset) to see if a second reset is applied soon afterward. The second reset is detected by the bootrom with help of the POWMAN_CHIP_RESET_DOUBLE_TAP flag, which is not reset by the external reset pin, and the bootrom enters BOOTSEL mode (NSBOOT) to await further instruction over USB or UART.
RO-
18:16DOUBLE_TAP_DELAY : Adjust how long to wait for a second reset when double tap BOOTSEL mode is enabled via DOUBLE_TAP. The minimum is 50 milliseconds, and each unit of this field adds an additional 50 milliseconds.

For example, settings this field to its maximum value of 7 will cause the chip to wait for 400 milliseconds at boot to check for a second reset which requests entry to BOOTSEL mode.

200 milliseconds (DOUBLE_TAP_DELAY=3) is a good intermediate value.
RO-
15:12Reserved.--
BitsDescriptionTypeReset
11:8

KEY_INVALID: Mark a boot key as invalid, or prevent it from ever becoming valid. The bootrom will ignore any boot key marked as invalid during secure boot signature checks.

Each bit in this field corresponds to one of the four 256-bit boot key hashes that may be stored in page 2 of the OTP.

When provisioning boot keys, it's recommended to mark any boot key slots you don't intend to use as KEY_INVALID, so that spurious keys can not be installed at a later time.

RO-
7:4Reserved.--
3:0

KEY_VALID: Mark each of the possible boot keys as valid. The bootrom will check signatures against all valid boot keys, and ignore invalid boot keys.

Each bit in this field corresponds to one of the four 256-bit boot key hashes that may be stored in page 2 of the OTP.

A KEY_VALID bit is ignored if the corresponding KEY_INVALID bit is set. Boot keys are considered valid only when KEY_VALID is set and KEY_INVALID is clear.

Do not mark a boot key as KEY_VALID if it does not contain a valid SHA-256 hash of your secp256k1 public key. Verify keys after programming, before setting the KEY_VALID bits – a boot key with uncorrectable ECC faults will render your device unbootable if secure boot is enabled.

Do not enable secure boot without first installing a valid key. This will render your device unbootable.

RO-

OTP_DATA: BOOT_FLAGS1_R1, BOOT_FLAGS1_R2 Registers

Offsets: 0x04c, 0x04d

Table 1387.
BOOT_FLAGS1_R1,
BOOT_FLAGS1_R2
Registers

BitsDescriptionTypeReset
31:24Reserved.--
23:0Redundant copy of BOOT_FLAGS1RO-

OTP_DATA: DEFAULT_BOOT_VERSION0 Register

Offset: 0x04e

Table 1388.
DEFAULT_BOOT_VERSION0
Register

BitsDescriptionTypeReset
31:24Reserved.--
23:0Default boot version thermometer counter, bits 23:0 (RBIT-3)RO-

OTP_DATA: DEFAULT_BOOT_VERSION0_R1, DEFAULT_BOOT_VERSION0_R2 Registers

Offsets: 0x04f, 0x050

Table 1389.
DEFAULT_BOOT_VERS
ION0_R1,
DEFAULT_BOOT_VERS
ION0_R2 Registers

BitsDescriptionTypeReset
31:24Reserved.--
23:0Redundant copy of DEFAULT_BOOT_VERSION0RO-

OTP_DATA: DEFAULT_BOOT_VERSION1 Register

Offset: 0x051

Table 1390.
DEFAULT_BOOT_VERS
ION1 Register

BitsDescriptionTypeReset
31:24Reserved.--
23:0Default boot version thermometer counter, bits 47:24 (RBIT-3)RO-

OTP_DATA: DEFAULT_BOOT_VERSION1_R1, DEFAULT_BOOT_VERSION1_R2 Registers

Offsets: 0x052, 0x053

Table 1391.
DEFAULT_BOOT_VERS
ION1_R1,
DEFAULT_BOOT_VERS
ION1_R2 Registers

BitsDescriptionTypeReset
31:24Reserved.--
23:0Redundant copy of DEFAULT_BOOT_VERSION1RO-

OTP_DATA: FLASH_DEVINFO Register

Offset: 0x054

Description

Stores information about external flash device(s). (ECC)

Assumed to be valid if BOOT_FLAGS0_FLASH_DEVINFO_ENABLE is set.

Table 1392.
FLASH_DEVINFO
Register

BitsDescriptionTypeReset
31:16Reserved.--
15:12

CS1_SIZE: The size of the flash/PSRAM device on chip select 1 (addressable at 0x11000000 through 0x11ffffff).

A value of zero is decoded as a size of zero (no device). Nonzero values are decoded as 4kiB << CS1_SIZE. For example, four megabytes is encoded with a CS1_SIZE value of 10, and 16 megabytes is encoded with a CS1_SIZE value of 12.

When BOOT_FLAGS0_FLASH_DEVINFO_ENABLE is not set, a default of zero is used.

RO-
Enumerated values:
0x0 → NONE
0x1 → 8K
0x2 → 16K
0x3 → 32K
0x4 → 64K
0x5 → 128K
BitsDescriptionTypeReset
0x6 → 256K
0x7 → 512K
0x8 → 1M
0x9 → 2M
0xa → 4M
0xb → 8M
0xc → 16M
11:8

CS0_SIZE: The size of the flash/PSRAM device on chip select 0 (addressable at 0x10000000 through 0x10ffffff).

A value of zero is decoded as a size of zero (no device). Nonzero values are decoded as 4kiB << CS0_SIZE. For example, four megabytes is encoded with a CS0_SIZE value of 10, and 16 megabytes is encoded with a CS0_SIZE value of 12.

When BOOT_FLAGS0_FLASH_DEVINFO_ENABLE is not set, a default of 12 (16 MiB) is used.

RO-
Enumerated values:
0x0 → NONE
0x1 → 8K
0x2 → 16K
0x3 → 32K
0x4 → 64K
0x5 → 128K
0x6 → 256K
0x7 → 512K
0x8 → 1M
0x9 → 2M
0xa → 4M
0xb → 8M
0xc → 16M
7

D8H_ERASE_SUPPORTED: If true, all attached devices are assumed to support (or ignore, in the case of PSRAM) a block erase command with a command prefix of D8h, an erase size of 64 kiB, and a 24-bit address. Almost all 25-series flash devices support this command.

If set, the bootrom will use the D8h erase command where it is able, to accelerate bulk erase operations. This makes flash programming faster.

When BOOT_FLAGS0_FLASH_DEVINFO_ENABLE is not set, this field defaults to false.

RO-
6Reserved.--
BitsDescriptionTypeReset
5:0

CS1_GPIO: Indicate a GPIO number to be used for the secondary flash chip select (CS1), which selects the external QSPI device mapped at system addresses 0x11000000 through 0x11ffffff. There is no such configuration for CS0, as the primary chip select has a dedicated pin.

On RP2350 the permissible GPIO numbers are 0, 8, 19 and 47.

Ignored if CS1_size is zero. If CS1_SIZE is nonzero, the bootrom will automatically configure this GPIO as a second chip select upon entering the flash boot path, or entering any other path that may use the QSPI flash interface, such as BOOTSEL mode (nsboot).

RO-

OTP_DATA: FLASH_PARTITION_SLOT_SIZE Register

Offset: 0x055

Table 1393.
FLASH_PARTITION_SLOT_SIZE Register

BitsDescriptionTypeReset
31:16Reserved.--
15:0Gap between partition table slot 0 and slot 1 at the start of flash (the default size is 4096 bytes) (ECC) Enabled by the OVERRIDE_FLASH_PARTITION_SLOT_SIZE bit in BOOT_FLAGS, the size is 4096 * (value + 1)RO-

OTP_DATA: BOOTSEL_LED_CFG Register

Offset: 0x056

Description

Pin configuration for LED status, used by USB bootloader. (ECC)
Must be valid if BOOT_FLAGS0_ENABLE_BOOTSEL_LED is set.

Table 1394.
BOOTSEL_LED_CFG Register

BitsDescriptionTypeReset
31:9Reserved.--
8ACTIVELOW: LED is active-low. (Default: active-high.)RO-
7:6Reserved.--
5:0PIN: GPIO index to use for bootloader activity LED.RO-

OTP_DATA: BOOTSEL_PLL_CFG Register

Offset: 0x057

Description

Optional PLL configuration for BOOTSEL mode. (ECC)

This should be configured to produce an exact 48 MHz based on the crystal oscillator frequency. User mode software may also use this value to calculate the expected crystal frequency based on an assumed 48 MHz PLL output.

If no configuration is given, the crystal is assumed to be 12 MHz.

The PLL frequency can be calculated as:

\[ \text{PLL out} = (\text{XOSC frequency} / (\text{REFDIV} + 1)) \times \text{FBDIV} / (\text{POSTDIV1} \times \text{POSTDIV2}) \]

Conversely the crystal frequency can be calculated as:

\[ \text{XOSC frequency} = 48 \text{ MHz} \times (\text{REFDIV} + 1) \times (\text{POSTDIV1} \times \text{POSTDIV2}) / \text{FBDIV} \]

(Note the +1 on REFDIV is because the value stored in this OTP location is the actual divisor value minus one.)

Used if and only if ENABLE_BOOTSEL_NON_DEFAULT_PLL_XOSC_CFG is set in BOOT_FLAGS0. That bit should be set only after this row and BOOTSEL_XOSC_CFG are both correctly programmed.

Table 1395.
BOOTSEL_PLL_CFG
Register

Bits 31:0 Bits 31:0 Bits 31:28column_2Description Description Input value for GPIO0…31. Description QSPI_SD : Input value on QSPI SD0 (MOSI), SD1 (MISO), SD2 and SD3 pinsType RO Type RO Type ROReset - Reset 0x00000000 Reset 0x0
Register 31:16Reserved.--
15REFDIV: PLL reference divisor, minus one. Programming a value of 0 means a reference divisor of 1. Programming aRO-
14:12POSTDIV2value of 1 means a reference divisor of 2 (for exceptionally fast XIN inputs) : PLL post-divide 2 divisor, in the range 1..7 inclusive.RO-
11:9POSTDIV1: PLL post-divide 1 divisor, in the range 1..7 inclusive.RO-
8:0FBDIV: PLL feedback divisor, in the range 16..320 inclusive.RO-
Table 1396. BitsDescriptionTypeReset
BOOTSEL_XOSC_CFG Register 31:16Reserved.--
15:14RANGE: Value of the XOSC_CTRL_FREQ_RANGE register. Enumerated values:RO-
13:0STARTUP0x3 → 40_100MHZ : Value of the XOSC_STARTUP registerRO-
Table 1397. BitsDescriptionTypeReset
USB_BOOT_FLAGS Register 31:24Reserved.--
23DP_DM_SWAP: Swap DM/DP during USB boot, to support board layouts with mirrored USB routing (deliberate or accidental).RO-

OTP_DATA: BOOTSEL_XOSC_CFG Register

Offset: 0x058

Description

Non-default crystal oscillator configuration for the USB bootloader. (ECC)

These values may also be used by user code configuring the crystal oscillator.

Used if and only if ENABLE_BOOTSEL_NON_DEFAULT_PLL_XOSC_CFG is set in BOOT_FLAGS0. That bit should be set only after this row and BOOTSEL_PLL_CFG are both correctly programmed.

Table 1396.
BOOTSEL_XOSC_CFG
Register

OTP_DATA: USB_BOOT_FLAGS Register

Offset: 0x059

Description

USB boot specific feature flags (RBIT-3)

Table 1397.
USB_BOOT_FLAGS
Register

BitsDescriptionTypeReset
22WHITE_LABEL_ADDR_VALID : valid flag for INFO_UF2_TXT_BOARD_ID_STRDEF entry of the USB_WHITE_LABEL struct (index 15)RO-
21:16Reserved.--
15WL_INFO_UF2_TXT_BOARD_ID_STRDEF_VALID : valid flag for the USB_WHITE_LABEL_ADDR fieldRO-
14WL_INFO_UF2_TXT_MODEL_STRDEF_VALID : valid flag for INFO_UF2_TXT_MODEL_STRDEF entry of the USB_WHITE_LABEL struct (index 14)RO-
13WL_INDEX_HTM_REDIRECT_NAME_STRDEF_VALID : valid flag for INDEX_HTM_REDIRECT_NAME_STRDEF entry of the USB_WHITE_LABEL struct (index 13)RO-
12WL_INDEX_HTM_REDIRECT_URL_STRDEF_VALID : valid flag for INDEX_HTM_REDIRECT_URL_STRDEF entry of the USB_WHITE_LABEL struct (index 12)RO-
11WL_SCSI_INQUIRY_VERSION_STRDEF_VALID : valid flag for SCSI_INQUIRY_VERSION_STRDEF entry of the USB_WHITE_LABEL struct (index 11)RO-
10WL_SCSI_INQUIRY_PRODUCT_STRDEF_VALID : valid flag for SCSI_INQUIRY_PRODUCT_STRDEF entry of the USB_WHITE_LABEL struct (index 10)RO-
9WL_SCSI_INQUIRY_VENDOR_STRDEF_VALID : valid flag for SCSI_INQUIRY_VENDOR_STRDEF entry of the USB_WHITE_LABEL struct (index 9)RO-
8WL_VOLUME_LABEL_STRDEF_VALID : valid flag for VOLUME_LABEL_STRDEF entry of the USB_WHITE_LABEL struct (index 8)RO-
7WL_USB_CONFIG_ATTRIBUTES_MAX_POWER_VALUES_VALID : valid flag for USB_CONFIG_ATTRIBUTES_MAX_POWER_VALUES entry of the USB_WHITE_LABEL struct (index 7)RO-
6WL_USB_DEVICE_SERIAL_NUMBER_STRDEF_VALID : valid flag for USB_DEVICE_SERIAL_NUMBER_STRDEF entry of the USB_WHITE_LABEL struct (index 6)RO-
5WL_USB_DEVICE_PRODUCT_STRDEF_VALID : valid flag for USB_DEVICE_PRODUCT_STRDEF entry of the USB_WHITE_LABEL struct (index 5)RO-
4WL_USB_DEVICE_MANUFACTURER_STRDEF_VALID : valid flag for USB_DEVICE_MANUFACTURER_STRDEF entry of the USB_WHITE_LABEL struct (index 4)RO-
3WL_USB_DEVICE_LANG_ID_VALUE_VALID : valid flag for USB_DEVICE_LANG_ID_VALUE entry of the USB_WHITE_LABEL struct (index 3)RO-
2WL_USB_DEVICE_SERIAL_NUMBER_VALUE_VALID : valid flag for USB_DEVICE_BCD_DEVICEVALUE entry of the USB_WHITE_LABEL struct (index 2)RO-
1WL_USB_DEVICE_PID_VALUE_VALID : valid flag for USB_DEVICE_PID_VALUE entry of the USB_WHITE_LABEL struct (index 1)RO-
BitsDescriptionTypeReset
0WL_USB_DEVICE_VID_VALUE_VALID : valid flag for USB_DEVICE_VID_VALUE entry of the USB_WHITE_LABEL struct (index 0)RO-

OTP_DATA: USB_BOOT_FLAGS_R1, USB_BOOT_FLAGS_R2 Registers

Offsets: 0x05a, 0x05b

Table 1398.
USB_BOOT_FLAGS_R1,
USB_BOOT_FLAGS_R2
Registers

BitsDescriptionTypeReset
31:24Reserved.--
23:0Redundant copy of USB_BOOT_FLAGSRO-

OTP_DATA: USB_WHITE_LABEL_ADDR Register

Offset: 0x05c

Table 1399.
USB_WHITE_LABEL_A
DDR Register

BitsDescriptionTypeReset
31:16Reserved.--
15:0

Row index of the USB_WHITE_LABEL structure within OTP (ECC)

The table has 16 rows, each of which are also ECC and marked valid by the corresponding valid bit in USB_BOOT_FLAGS (ECC).

The entries are either _VALUES where the 16 bit value is used as is, or _STRDEFs which acts as a pointers to a string value.

The value stored in a _STRDEF is two separate bytes: The low seven bits of the first (LSB) byte indicates the number of characters in the string, and the top bit of the first (LSB) byte if set to indicate that each character in the string is two bytes (Unicode) versus one byte if unset. The second (MSB) byte represents the location of the string data, and is encoded as the number of rows from this USB_WHITE_LABEL_ADDR; i.e. the row of the start of the string is USB_WHITE_LABEL_ADDR value + msb_byte.

In each case, the corresponding valid bit enables replacing the default value for the corresponding item provided by the boot rom.

Note that Unicode _STRDEFs are only supported for USB_DEVICE_PRODUCT_STRDEF, USB_DEVICE_SERIAL_NUMBER_STRDEF and USB_DEVICE_MANUFACTURER_STRDEF. Unicode values will be ignored if specified for other fields, and non-unicode values for these three items will be converted to Unicode characters by setting the upper 8 bits to zero.

Note that if the USB_WHITE_LABEL structure or the corresponding strings are not readable by BOOTSEL mode based on OTP permissions, or if alignment requirements are not met, then the corresponding default values are used.

The index values indicate where each field is located (row USB_WHITE_LABEL_ADDR value + index):

RO-
Enumerated values:
0x0000 → INDEX_USB_DEVICE_VID_VALUE
0x0001 → INDEX_USB_DEVICE_PID_VALUE
BitsDescriptionTypeReset
0x0002 → INDEX_USB_DEVICE_BCD_DEVICE_VALUE
0x0003 → INDEX_USB_DEVICE_LANG_ID_VALUE
0x0004 → INDEX_USB_DEVICE_MANUFACTURER_STRDEF
0x0005 → INDEX_USB_DEVICE_PRODUCT_STRDEF
0x0006 → INDEX_USB_DEVICE_SERIAL_NUMBER_STRDEF
0x0007 → INDEX_USB_CONFIG_ATTRIBUTES_MAX_POWER_VALUES
0x0008 → INDEX_VOLUME_LABEL_STRDEF
0x0009 → INDEX_SCSI_INQUIRY_VENDOR_STRDEF
0x000a → INDEX_SCSI_INQUIRY_PRODUCT_STRDEF
0x000b → INDEX_SCSI_INQUIRY_VERSION_STRDEF
0x000c → INDEX_INDEX_HTM_REDIRECT_URL_STRDEF
0x000d → INDEX_INDEX_HTM_REDIRECT_NAME_STRDEF
0x000e → INDEX_INFO_UF2_TXT_MODEL_STRDEF
0x000f → INDEX_INFO_UF2_TXT_BOARD_ID_STRDEF

OTP_DATA: OTPBOOT_SRC Register

Offset: 0x05e

Table 1400.
OTPBOOT_SRC
Register

BitsDescriptionTypeReset
31:16Reserved.--
15:0

OTP start row for the OTP boot image. (ECC)

If OTP boot is enabled, the bootrom will load from this location into SRAM and then directly enter the loaded image. Note that the image must be signed if SECURE_BOOT_ENABLE is set. The image itself is assumed to be ECC-protected.

This must be an even number. Equivalently, the OTP boot image must start at a word-aligned location in the ECC read data address window.

RO-

OTP_DATA: OTPBOOT_LEN Register

Offset: 0x05f

Table 1401.
OTPBOOT_LEN
Register

BitsDescriptionTypeReset
31:16Reserved.--
15:0

Length in rows of the OTP boot image. (ECC)

OTPBOOT_LEN must be even. The total image size must be a multiple of 4 bytes (32 bits).

RO-

OTP_DATA: OTPBOOT_DST0 Register

Offset: 0x060

Table 1402.
OTPBOOT_DST0
Register

BitsDescriptionTypeReset
31:16Reserved.--
15:0Bits 15:0 of the OTP boot image load destination (and entry point). (ECC)

This must be a location in main SRAM (main SRAM is addresses 0x20000000 through 0x20082000) and must be word-aligned.
RO-

OTP_DATA: OTPBOOT_DST1 Register

Offset: 0x061

Table 1403.
OTPBOOT_DST1
Register

BitsDescriptionTypeReset
31:16Reserved.--
15:0Bits 31:16 of the OTP boot image load destination (and entry point). (ECC)

This must be a location in main SRAM (main SRAM is addresses 0x20000000 through 0x20082000) and must be word-aligned.
RO-

OTP_DATA: BOOTKEY0_0, BOOTKEY0_1, ..., BOOTKEY3_14, BOOTKEY3_15 Registers

Offsets: 0x080, 0x081, ..., 0x0be, 0x0bf

Table 1404.
BOOTKEY0_0,
BOOTKEY0_1, ...,
BOOTKEY3_14,
BOOTKEY3_15
Registers

BitsDescriptionTypeReset
31:16Reserved.--
15:0Bits \( N + 15 : N \) of SHA-256 hash of boot key \( K \) (ECC)RO-

OTP_DATA: KEY1_0, KEY2_0, ..., KEY5_0, KEY6_0 Registers

Offsets: 0xf48, 0xf50, ..., 0xf68, 0xf70

Table 1405. KEY1_0,
KEY2_0, ..., KEY5_0,
KEY6_0 Registers

BitsDescriptionTypeReset
31:16Reserved.--
15:0Bits 15:0 of OTP access key \( n \) (ECC)RO-

OTP_DATA: KEY1_1, KEY2_1, ..., KEY5_1, KEY6_1 Registers

Offsets: 0xf49, 0xf51, ..., 0xf69, 0xf71

Table 1406. KEY1_1,
KEY2_1, ..., KEY5_1,
KEY6_1 Registers

BitsDescriptionTypeReset
31:16Reserved.--
15:0Bits 31:16 of OTP access key \( n \) (ECC)RO-

OTP_DATA: KEY1_2, KEY2_2, ..., KEY5_2, KEY6_2 Registers

Offsets: 0xf4a, 0xf52, ..., 0xf6a, 0xf72

Table 1407. KEY1_2, KEY2_2, ..., KEY5_2, KEY6_2 Registers

BitsDescriptionTypeReset
31:16Reserved.--
15:0Bits 47:32 of OTP access key \( n \) (ECC)RO-
OTP_DATA: KEY1_3, KEY2_3, ..., KEY5_3, KEY6_3 Registers Offsets: 0xf4b, 0xf53, ..., 0xf6b, 0xf73

Table 1408. KEY1_3, KEY2_3, ..., KEY5_3, KEY6_3 Registers

BitsDescriptionTypeReset
31:16Reserved.--
15:0Bits 63:48 of OTP access key \( n \) (ECC)RO-
OTP_DATA: KEY1_4, KEY2_4, ..., KEY5_4, KEY6_4 Registers Offsets: 0xf4c, 0xf54, ..., 0xf6c, 0xf74

Table 1409. KEY1_4, KEY2_4, ..., KEY5_4, KEY6_4 Registers

BitsDescriptionTypeReset
31:16Reserved.--
15:0Bits 79:64 of OTP access key \( n \) (ECC)RO-
OTP_DATA: KEY1_5, KEY2_5, ..., KEY5_5, KEY6_5 Registers Offsets: 0xf4d, 0xf55, ..., 0xf6d, 0xf75

Table 1410. KEY1_5, KEY2_5, ..., KEY5_5, KEY6_5 Registers

BitsDescriptionTypeReset
31:16Reserved.--
15:0Bits 95:80 of OTP access key \( n \) (ECC)RO-
OTP_DATA: KEY1_6, KEY2_6, ..., KEY5_6, KEY6_6 Registers Offsets: 0xf4e, 0xf56, ..., 0xf6e, 0xf76

Table 1411. KEY1_6, KEY2_6, ..., KEY5_6, KEY6_6 Registers

BitsDescriptionTypeReset
31:16Reserved.--
15:0Bits 111:96 of OTP access key \( n \) (ECC)RO-
OTP_DATA: KEY1_7, KEY2_7, ..., KEY5_7, KEY6_7 Registers Offsets: 0xf4f, 0xf57, ..., 0xf6f, 0xf77

Table 1412. KEY1_7, KEY2_7, ..., KEY5_7, KEY6_7 Registers

BitsDescriptionTypeReset
31:16Reserved.--
15:0Bits 127:112 of OTP access key \( n \) (ECC)RO-
OTP_DATA: KEY1_VALID Register Offset: 0xf79 Description

Valid flag for key 1. Once the valid flag is set, the key can no longer be read or written, and becomes a valid fixed key for protecting OTP pages.

Table 1413.
KEY1_VALID Register

BitsDescriptionTypeReset
31:17Reserved.--
16VALID_R2 : Redundant copy of VALID, with 3-way majority voteRO-
15:9Reserved.--
8VALID_R1 : Redundant copy of VALID, with 3-way majority voteRO-
7:1Reserved.--
0VALIDRO-

OTP_DATA: KEY2_VALID Register

Offset: 0xf7a

Description

Valid flag for key 2. Once the valid flag is set, the key can no longer be read or written, and becomes a valid fixed key for protecting OTP pages.

Table 1414.
KEY2_VALID Register

BitsDescriptionTypeReset
31:17Reserved.--
16VALID_R2 : Redundant copy of VALID, with 3-way majority voteRO-
15:9Reserved.--
8VALID_R1 : Redundant copy of VALID, with 3-way majority voteRO-
7:1Reserved.--
0VALIDRO-

OTP_DATA: KEY3_VALID Register

Offset: 0xf7b

Description

Valid flag for key 3. Once the valid flag is set, the key can no longer be read or written, and becomes a valid fixed key for protecting OTP pages.

Table 1415.
KEY3_VALID Register

BitsDescriptionTypeReset
31:17Reserved.--
16VALID_R2 : Redundant copy of VALID, with 3-way majority voteRO-
15:9Reserved.--
8VALID_R1 : Redundant copy of VALID, with 3-way majority voteRO-
7:1Reserved.--
0VALIDRO-

OTP_DATA: KEY4_VALID Register

Offset: 0xf7c

Description

Valid flag for key 4. Once the valid flag is set, the key can no longer be read or written, and becomes a valid fixed key for protecting OTP pages.

Table 1416.
KEY4_VALID Register

BitsDescriptionTypeReset
31:17Reserved.--
16VALID_R2 : Redundant copy of VALID, with 3-way majority voteRO-
15:9Reserved.--
8VALID_R1 : Redundant copy of VALID, with 3-way majority voteRO-
7:1Reserved.--
0VALIDRO-

OTP_DATA: KEY5_VALID Register

Offset: 0xf7d

Description

Valid flag for key 5. Once the valid flag is set, the key can no longer be read or written, and becomes a valid fixed key for protecting OTP pages.

Table 1417.
KEY5_VALID Register

BitsDescriptionTypeReset
31:17Reserved.--
16VALID_R2 : Redundant copy of VALID, with 3-way majority voteRO-
15:9Reserved.--
8VALID_R1 : Redundant copy of VALID, with 3-way majority voteRO-
7:1Reserved.--
0VALIDRO-

OTP_DATA: KEY6_VALID Register

Offset: 0xf7e

Description

Valid flag for key 6. Once the valid flag is set, the key can no longer be read or written, and becomes a valid fixed key for protecting OTP pages.

Table 1418.
KEY6_VALID Register

BitsDescriptionTypeReset
31:17Reserved.--
16VALID_R2 : Redundant copy of VALID, with 3-way majority voteRO-
15:9Reserved.--
8VALID_R1 : Redundant copy of VALID, with 3-way majority voteRO-
7:1Reserved.--
0VALIDRO-

OTP_DATA: PAGE0_LOCK0, PAGE1_LOCK0, ..., PAGE61_LOCK0, PAGE62_LOCK0 Registers

Offsets: 0xf80, 0xf82, ..., 0xffa, 0xffc

Description

Lock configuration LSBs for page \( N \) (rows \( 0x40 * N \) through \( 0x40 * N + 0x3f \) ). Locks are stored with 3-way majority vote encoding, so that bits can be set independently.

This OTP location is always readable, and is write-protected by its own permissions.

Table 1419.
PAGE0_LOCK0,
PAGE1_LOCK0, ...,
PAGE61_LOCK0,
PAGE62_LOCK0
Registers

BitsDescriptionTypeReset
31:24Reserved.--
23:16R2 : Redundant copy of bits 7:0RO-
15:8R1 : Redundant copy of bits 7:0RO-
7Reserved.--
6NO_KEY_STATE : State when at least one key is registered for this page and no matching key has been entered.RO-
Enumerated values:
0x0 → READ_ONLY
0x1 → INACCESSIBLE
5:3KEY_R : Index 1-6 of a hardware key which must be entered to grant read access, or 0 if no such key is required.RO-
2:0KEY_W : Index 1-6 of a hardware key which must be entered to grant write access, or 0 if no such key is required.RO-

OTP_DATA: PAGE0_LOCK1, PAGE1_LOCK1, ..., PAGE61_LOCK1, PAGE62_LOCK1 Registers

Offsets: 0xf81, 0xf83, ..., 0xffb, 0xffd

Description

Lock configuration MSBs for page \( N \) (rows \( 0x40 * N \) through \( 0x40 * N + 0x3f \) ). Locks are stored with 3-way majority vote encoding, so that bits can be set independently.

This OTP location is always readable, and is write-protected by its own permissions.

Table 1420.
PAGE0_LOCK1,
PAGE1_LOCK1, ...,
PAGE61_LOCK1,
PAGE62_LOCK1
Registers

BitsDescriptionTypeReset
31:24Reserved.--
23:16R2 : Redundant copy of bits 7:0RO-
15:8R1 : Redundant copy of bits 7:0RO-
7:6Reserved.--
5:4LOCK_BL : Dummy lock bits reserved for bootloaders (including the RP2350 USB bootloader) to store their own OTP access permissions. No hardware effect, and no corresponding SW_LOCKx registers.RO-
Enumerated values:
0x0 → READ_WRITE: Bootloader permits user reads and writes to this page
0x1 → READ_ONLY: Bootloader permits user reads of this page
0x2 → RESERVED: Do not use. Behaves the same as INACCESSIBLE
0x3 → INACCESSIBLE: Bootloader does not permit user access to this page
BitsDescriptionTypeReset
3:2LOCK_NS: Lock state for Non-secure accesses to this page. Thermometer-coded, so lock state can be advanced permanently from any state to any less-permissive state by programming OTP. Software can also advance the lock state temporarily (until next OTP reset) using the SW_LOCKx registers.

Note that READ_WRITE and READ_ONLY are equivalent in hardware, as the SBPI programming interface is not accessible to Non-secure software. However, Secure software may check these bits to apply write permissions to a Non-secure OTP programming API.
RO-
Enumerated values:
0x0 → READ_WRITE: Page can be read by Non-secure software, and Secure software may permit Non-secure writes.
0x1 → READ_ONLY: Page can be read by Non-secure software
0x2 → RESERVED: Do not use. Behaves the same as INACCESSIBLE.
0x3 → INACCESSIBLE: Page can not be accessed by Non-secure software.
1:0LOCK_S: Lock state for Secure accesses to this page. Thermometer-coded, so lock state can be advanced permanently from any state to any less-permissive state by programming OTP. Software can also advance the lock state temporarily (until next OTP reset) using the SW_LOCKx registers.RO-
Enumerated values:
0x0 → READ_WRITE: Page is fully accessible by Secure software.
0x1 → READ_ONLY: Page can be read by Secure software, but can not be written.
0x2 → RESERVED: Do not use. Behaves the same as INACCESSIBLE.
0x3 → INACCESSIBLE: Page can not be accessed by Secure software.

OTP_DATA: PAGE63_LOCK0 Register

Offset: 0xffe

Description

Lock configuration LSBs for page 63 (rows 0xfc0 through 0xfff). Locks are stored with 3-way majority vote encoding, so that bits can be set independently.

This OTP location is always readable, and is write-protected by its own permissions.

Table 1421.
PAGE63_LOCK0
Register

BitsDescriptionTypeReset
31:24Reserved.--
23:16R2: Redundant copy of bits 7:0RO-
15:8R1: Redundant copy of bits 7:0RO-
7RMA: Decommission for RMA of a suspected faulty device. This re-enables the factory test JTAG interface, and makes pages 3 through 61 of the OTP permanently inaccessible.RO-
6NO_KEY_STATE: State when at least one key is registered for this page and no matching key has been entered.RO-
Enumerated values:
BitsDescriptionTypeReset
0x0 → READ_ONLY
0x1 → INACCESSIBLE
5:3KEY_R : Index 1-6 of a hardware key which must be entered to grant read access, or 0 if no such key is required.RO-
2:0KEY_W : Index 1-6 of a hardware key which must be entered to grant write access, or 0 if no such key is required.RO-

OTP_DATA: PAGE63_LOCK1 Register

Offset: 0xfff

Description

Lock configuration MSBs for page 63 (rows 0xfc0 through 0xfff). Locks are stored with 3-way majority vote encoding, so that bits can be set independently.

This OTP location is always readable, and is write-protected by its own permissions.

Table 1422.
PAGE63_LOCK1
Register

BitsDescriptionTypeReset
31:24Reserved.--
23:16R2 : Redundant copy of bits 7:0RO-
15:8R1 : Redundant copy of bits 7:0RO-
7:6Reserved.--
5:4LOCK_BL : Dummy lock bits reserved for bootloaders (including the RP2350 USB bootloader) to store their own OTP access permissions. No hardware effect, and no corresponding SW_LOCKx registers.RO-
Enumerated values:
0x0 → READ_WRITE: Bootloader permits user reads and writes to this page
0x1 → READ_ONLY: Bootloader permits user reads of this page
0x2 → RESERVED: Do not use. Behaves the same as INACCESSIBLE
0x3 → INACCESSIBLE: Bootloader does not permit user access to this page
3:2LOCK_NS : Lock state for Non-secure accesses to this page. Thermometer-coded, so lock state can be advanced permanently from any state to any less-permissive state by programming OTP. Software can also advance the lock state temporarily (until next OTP reset) using the SW_LOCKx registers.

Note that READ_WRITE and READ_ONLY are equivalent in hardware, as the SBPI programming interface is not accessible to Non-secure software. However, Secure software may check these bits to apply write permissions to a Non-secure OTP programming API.
RO-
Enumerated values:
0x0 → READ_WRITE: Page can be read by Non-secure software, and Secure software may permit Non-secure writes.
0x1 → READ_ONLY: Page can be read by Non-secure software
0x2 → RESERVED: Do not use. Behaves the same as INACCESSIBLE.
0x3 → INACCESSIBLE: Page can not be accessed by Non-secure software.
BitsDescriptionTypeReset
1:0LOCK_S : Lock state for Secure accesses to this page. Thermometer-coded, so lock state can be advanced permanently from any state to any less-permissive state by programming OTP. Software can also advance the lock state temporarily (until next OTP reset) using the SW_LOCKx registers.RO-
Enumerated values:
0x0 → READ_WRITE: Page is fully accessible by Secure software.
0x1 → READ_ONLY: Page can be read by Secure software, but can not be written.
0x2 → RESERVED: Do not use. Behaves the same as INACCESSIBLE.
0x3 → INACCESSIBLE: Page can not be accessed by Secure software.