AES_CONTROL

nRF5340 Product Specification

Address offset: 0x4C0

Control the AES engine behavior.

Bit number 31 30 29 28 27 26 25 24 23 22 21 20 19 18 17 16 15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0
ID P O N M L K J I I H H G F E D D D C C C B A
Reset 0x00000000 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
ID R/W Field Value ID Value Description
A

RW

DEC_KEY0

Set AES encrypt or decrypt mode in non-tunneling operations.

Encrypt

0

Perform AES encryption

Decrypt

1

Perform AES decryption

B

RW

MODE0_IS_CBC_CTS

This field allows to add distinction to the CBC and CTR modes defined in field MODE_KEY0. If MODE_KEY0 is set to CBC in combination with this field, AES mode is CBC-CTS. If MODE_KEY0 is set to CTR in combination with this field, AES mode is GCTR.

Disable

0

Disable CBC-CTS and GCTR mode

Enable

1

Enable CBC-CTS and GCTR mode

C

RW

MODE_KEY0

Set the AES mode in non-tunneling operations, or the AES mode of the first stage in tunneling operations.

ECB

0x0

Electronic codebook mode

CBC

0x1

Cipher block chaining mode

This CBC cipher mode can also be configured to run in several distinct modes:
  • CBC-CTS mode when combined with field MODE0_IS_CBC_CTS set.
  • CBC with ESSIV mode when combined with field CBC_IS_ESSIV set.
  • CBC BITLOCKER mode when combined with field CBC_IS_BITLOCKER set.

CTR

0x2

Counter mode

This CTR cipher mode can also be configured to run GCTR mode when combined with field MODE0_IS_CBC_CTS set.

CBC_MAC

0x3

Cipher Block Chaining Message Authentication Code

XEX_XTS

0x4

Xor-Encrypt-Xor (XEX)-based tweaked-codebook mode with ciphertext stealing (XTS)

XCBC_MAC

0x5

AES in CBC mode with extensions to overcome fixed length limitations

OFB

0x6

AES Output FeedBack mode

CMAC

0x7

Cipher-based Message Authentication Code

D

RW

MODE_KEY1

Set the AES mode of the second stage in tunneling operations

ECB

0x0

Electronic codebook mode

CBC

0x1

Cipher block chaining mode

CTR

0x2

Counter mode

CBC_MAC

0x3

Cipher block chaining message authentication code mode

XEX_XTS

0x4

Xor-Encrypt-Xor (XEX)-based tweaked-codebook mode with ciphertext stealing (XTS)

XCBC_MAC

0x5

AES in CBC mode with extensions to overcome fixed length limitations

OFB

0x6

AES Output FeedBack mode

CMAC

0x7

Cipher-based Message Authentication Code

E

RW

CBC_IS_ESSIV

If MODE_KEY0 is set to CBC, and this field is set, the mode is CBC with ESSIV.

Disable

0

Disable CBC with ESSIV mode

Enable

1

Enable CBC with ESSIV mode

F

RW

AES_TUNNEL

Configure AES engine for standard non-tunneling or tunneling operations.

Disable

0

Standard non-tunneling operations

Enable

1

Enable tunneling operations

G

RW

CBC_IS_BITLOCKER

If MODE_KEY0 is set to CBC, and this field is set, the mode is CBC Bitlocker.

Disable

0

Disable CBC Bitlocker mode

Enable

1

Enable CBC Bitlocker mode

H

RW

NK_KEY0

Set the AES key length in non-tunneling operations, or the AES key length of the first stage in tunneling operations.

128Bits

0x0

128 bits key length

192Bits

0x1

192 bits key length

256Bits

0x2

256 bits key length

I

RW

NK_KEY1

Set the AES key length of the second stage in tunneling operations.

128Bits

0x0

128 bits key length

192Bits

0x1

192 bits key length

256Bits

0x2

256 bits key length

J

RW

AES_TUNNEL1_DECRYPT

Configure if first tunnel stage performs encrypt or decrypt operation.

Encrypt

0

Second tunnel stage performs encrypt operations.

Decrypt

1

Second tunnel stage performs decrypt operations.

K

RW

AES_TUN_B1_USES_PADDED_DATA_IN

For tunneling operations this field determine the data that is fed to the second tunneling stage.

Disable

0

The output of the first block is used directly (standard tunneling operation).

Enable

1

The output of the first block is padded before use.

L

RW

AES_TUNNEL0_ENCRYPT

Configure if first tunnel stage performs encrypt or decrypt operation.

Decrypt

0

First tunnel stage performs decrypt operations.

Encrypt

1

First tunnel stage performs encrypt operations.

M

RW

AES_OUTPUT_MID_TUNNEL_DATA

This fields configure if the AES engine output is the result of the first or second tunneling stage.

SecondStage

0

Output result from the second tunnel stage (standard tunneling).

FirstStage

1

Output result from the first tunnel stage.

N

RW

AES_TUNNEL_B1_PAD_EN

This field configure if the input data to the second tunnel stage is to be padded with zeroes according to how many bytes are remaining.

Disable

0

The data input to the second tunnel stage is not padded with zeros.

Enable

1

The data input to the second tunnel stage is padded with zeros.

O

RW

AES_OUT_MID_TUN_TO_HASH

This field determines for AES-TO-HASH-AND-DOUT tunneling operations, whether the AES outputs to the HASH the result of the first or the second tunneling stage.

SecondStage

0

The AES engine writes to the HASH the result of the second tunnel stage.

FirstStage

1

The AES engine writes to the HASH the result of the first tunnel stage.

P

RW

DIRECT_ACCESS

Using direct access and not the DIN-DOUT DMA interface

Disable

0

Access using the DIN-DOUT DMA interface

Enable

1

Access using direct access