Access port protection

nRF5340 Product Specification

The control access ports are always accessible from the debugger, while access to the system resources through each core's individual access ports (AHB-AP) can be protected in different ways.

The following tables give an overview of the access port protection methods.

Table 2. Application core access port protection overview
Registers Description
UICR.APPROTECT and CTRL-AP.APPROTECT.DISABLE These registers control the generation of the application core AHB-AP DBGEN signal, which controls all non-secure access through the application core AHB-AP. This can be used to provide readback protection of the flash contents. See also Application core access port protection for non-secure debug access. For more information about the DBGEN signal, see the Arm CoreSight SoC-400 Technical Reference Manual, Revision r3p2.
UICR.SECUREAPPROTECT and CTRL-AP.SECUREAPPROTECT.DISABLE These registers control the generation of the application core AHB-AP SPIDEN signal, which blocks all secure access through the application core AHB-AP. This means that only the non-secure code can be debugged and accessed.

To enable access to the secure access port, APPROTECT must be unprotected. See also Application core access port protection for secure debug access.

For more information about the SPIDEN signal, see the Arm CoreSight SoC-400 Technical Reference Manual, Revision r3p2.

UICR.ERASEPROTECT and CTRL-AP.ERASEPROTECT.DISABLE Disables the application core CTRL-AP.ERASEALL and NVMC ERASEALL functionality. This can be used together with APPROTECT to provide read-back and re-purposing protection.
Table 3. Network core access port protection overview
Registers Description
UICR.APPROTECT and CTRL-AP.APPROTECT.DISABLE These registers control the generation of the network core AHB-AP DBGEN signal, which blocks all access through the network core AHB-AP. See also Network core access port protection for debug access.

For the network core that does not feature TrustZone®, only DBGEN can be controlled and SPIDEN is not used.

UICR.ERASEPROTECT Disables the network core CTRL-AP.ERASEALL and NVMC ERASEALL functionality. This can be used together with APPROTECT to provide read-back and re-purposing protection.
For both cores, UICR and CTRL-AP are combined to enable or disable the access port protection. The access port is normally protected, and is opened when the following conditions are met:
  1. UICR.APPROTECT must be Unprotected.
  2. CTRL-AP.APPROTECT.DISABLE on both CPU and debugger side must match. However, after reset the debugger side register value is known and CPU can open the port by writing Unprotected to the register.

The following tables lists the available APPROTECT combinations.

Table 4. Application core access port protection for non-secure debug access
Application core UICR.APPROTECT CPU and debugger side CTRL-AP.APPROTECT.DISABLE registers are equal DBGEN Debug access to application core AHB-AP
Protected No 0 Not permitted
Protected Yes 0 Not permitted
Unprotected No 0 Not permitted
Unprotected Yes 1 Permitted
Table 5. Application core access port protection for secure debug access
Application core UICR.SECURE­APPROTECT CPU and debugger side CTRL-AP.SECURE­AP­PROTECT.DISABLE registers are equal SPIDEN Secure debug access to application core AHB-AP
Protected No 0 Not permitted
Protected Yes 0 Not permitted
Unprotected No 0 Not permitted
Unprotected Yes 1 Permitted
Table 6. Network core access port protection for debug access
Network core UICR.AP­PROTECT CPU and debugger side CTRL-AP.AP­PROTECT registers are equal DBGEN Debug access to AHB-AP
Protected No 0 Not permitted
Protected Yes 0 Not permitted
Unprotected No 0 Not permitted
Unprotected Yes 1 Permitted
The access port is also open after the completion of the CTRL-AP.ERASEALL operation. After completing the erase operation, CTRL-AP will temporarily unprotect AHB-AP. AHB-AP will be protected when one of the following conditions are met:
  • Power-on reset
  • Brown-out reset
  • Watchdog timer reset
  • Pin reset

The following figure is an example on how nRF5340 with access port protection enabled can be erased, programmed, and configured to allow debugging. Operations sent from debugger as well as registers written by firmware will affect the access port state. The operation named Reset* is one of the conditions listed above.

Figure 2. Access port unlocking
Access port unlocking

The debugger can read the access port protection status in the core's AHB-AP, using the Arm AHB-AP Control/Status Word register (CSW), defined in the Arm CoreSight SoC-400 Technical Reference Manual, Revision r3p2. The DbgStatus field indicates that the AHB-AP can perform AHB transfers, while the SPIStatus field indicates if secure AHB transfers are permitted. For a list of all debug access ports, see DAP — Debug access port.

For more details on CTRLAP.ERASEALL, CTRLAP.SECUREAPPROTECT, and CTRLAP.APPROTECT, see CTRL-AP - Control access port.

Note: Using SPU — System protection unit, the application core can be configured to grant the network core access to its resources. This grant also applies to the network core AHB-AP.