The contents of an external flash memory can be protected using stream cipher encryption. Encryption can be configured and enabled independently for XIP and EasyDMA, with separate keys and nonce.
Once configured and enabled, the stream cipher operates between the AHB bus and the external flash, encrypting and decrypting data passing through.
The same nonce and key must be used for both encryption and decryption of the same memory address.
The memory address used for encryption is the external flash memory address and thus independent of XIPOFFSET. This means a second firmware image can be encrypted and written using EasyDMA, then XIPOFFSET set to point to the new firmware image before executing from it.
Stream ciphers are symmetric. They do not differentiate between encrypting or decrypting, reading or writing. Thus, if the contents of a plain text external flash is read when stream cipher is enabled, the data provided to the MCU is encrypted.
Execute in place (XIP)
- Configure keys using XIP_ENC.KEY0 through XIP_ENC.KEY3.
- Configure nonce using XIP_ENC.NONCE0 through XIP_ENC.NONCE2.
- Set XIP_ENC.ENABLE.
EasyDMA
- Configure keys using DMA_ENC.KEY0 through DMA_ENC.KEY3.
- Configure nonce using DMA_ENC.NONCE0 through DMA_ENC.NONCE2.
- Set DMA_ENC.ENABLE.