Revoke

nRF54LM20A | nRF54LM20B Datasheet

A key slot which is revoked can no longer be pushed.

A key slot can be revoked when it is in the PROVISIONED state or when its revocation policy is not LOCKED.

To revoke a key slot, perform the following steps:
  1. Configure the key slot ID in the KEYSLOT register.
  2. Enable RRAM write operation in Normal write mode. For details, see RRAMC — Resistive random access memory controller.
  3. Trigger the REVOKE task.

    KMU erases the asset from SICR. If revoking the key slot is successful, KMU generates the REVOKED event. If unsuccessful, or the key slot is already in the REVOKED state, KMU generates the ERROR event.

  4. Disable RRAM write operation. For details, see RRAMC — Resistive random access memory controller.

Rotating key slots are available after a successful revocation. Non-rotating key slots remain in a REVOKED state and can not be used again until SICR is erased.

SICR can only be erased using the Erase All functions of CTRL-AP — Control access port and RRAMC — Resistive random access memory controller.