DPPI is implemented with split security, meaning it handles both secure and non-secure accesses. In a system implementing the TrustZone® for Cortex®-M technology, DPPI channels can be defined as secure or non-secure using the SPU.
A peripheral configured as non-secure will only be able to subscribe to or publish on non-secure DPPI channels. A peripheral configured as secure will be able to access all DPPI channels. DPPI handles both secure and non-secure accesses, but behaves differently depending on the access type:
- A non-secure peripheral access can only configure and control the DPPI channels defined as non-secure in the SPU.DPPI.PERM[] register(s)
- A secure peripheral access can control all the DPPI channels, independently of the SPU.DPPI.PERM[] register(s)
A group of channels can be created, making it possible to simultaneously enable or disable all channels within the group. The security attribute of a group of channels (secure or non-secure) is defined as follows:
- If all channels (enabled or not) within a group are non-secure, then the group is considered non-secure
- If at least one of the channels (enabled or not) within the group is secure, then the group is considered secure
A non-secure access to a DPPI register, or a bit field, controlling a channel marked as secure in SPU.DPPI[].PERM register(s) will be ignored. Write accesses will have no effect, and read accesses will always return a zero value.
No exceptions are triggered when non-secure accesses target a register or a bit field
controlling a secure channel. For example, if the bit i is set in the
SPU.DPPI[0].PERM register (declaring DPPI channel i as secure), then:
- Non-secure write accesses to registers CHEN, CHENSET, and CHENCLR cannot write bit
iof these registers - Non-secure write accesses to TASK_CHG[j].EN and TASK_CHG[j].DIS registers are
ignored if the channel group
jcontains at least one channel defined as secure (it can be the channel i itself or any channel declared as secure) - Non-secure read accesses to registers CHEN, CHENSET, and CHENCLR always read 0 for
the bit at position
i
For the channel configuration registers (CHG[]), access from non-secure code is only
possible if the included channels are all non-secure, whether the channels are enabled
or not. If a CHG[g] register included one or more secure channel(s), then the group
g is considered as secure, and only secure transfers can read to or
write from CHG[g]. A non-secure write access is ignored, and a non-secure read access
returns 0.
The DPPI can subscribe to secure and non-secure channels through the SUBSCRIBE_CHG[] registers, in order to trigger the task for enabling or disabling groups of channels. An event from a secure channel will be ignored if the group subscribing to this channel is non-secure. A secure group can subscribe to a non-secure channel or a secure channel.