Encryption

nRF5340 Product Specification

The contents of an external flash memory can be protected using stream cipher encryption. Encryption can be configured and enabled independently for XIP and EasyDMA, with separate keys and nonce.

Once configured and enabled, the stream cipher operates between the AHB bus and the external flash, encrypting and decrypting data passing through.

The following figure shows the stream cipher block with the three configuration registers. The stream cipher uses an AES 128 encryption operation to form the keystream from key, nonce, and external memory address. The keystream then combines each 32-bit plaintext digit one at a time with the corresponding digit of the keystream.
Figure 3. Stream cipher
Page-1 Sheet.241 ADDR[31:4] ADDR[31:4] Sheet.242 ENC.KEY[127:0] ENC.KEY[127:0] Sheet.244 AES 128 AES 128 Sheet.245 Sheet.246 Sheet.249 DATA IN[31:0] DATA IN[31:0] Sheet.250 Sheet.251 DATA OUT[31:0] DATA OUT[31:0] Sheet.252 NONCE[95:0] NONCE[95:0] Sheet.253 ADDRESS IN[31:0] ADDRESS IN[31:0] Sheet.257 Sheet.260 Sheet.263 ENC.ENABLE ENC.ENABLE Sheet.264 AES[63:32] AES[63:32] Sheet.265 AES[31:0] AES[31:0] Sheet.266 AES[127:96] AES[127:96] Sheet.267 AES[95:64] AES[95:64] Sheet.268 Sheet.269 Sheet.274 Sheet.276 ADDR[3:2] ADDR[3:2] Sheet.277 ZEROS[3:0] ZEROS[3:0] Sheet.278 ENC.NONCE[95:0] ENC.NONCE[95:0] Sheet.279 Dynamic connector Dynamic connector.282 Sheet.284 Dynamic connector.286 Dynamic connector.288 Dynamic connector.290 Dynamic connector.291 Dynamic connector.292 Dynamic connector.293 Dynamic connector.294 Dynamic connector.289 Sheet.295 Sheet.247 Sheet.285 Sheet.255 Sheet.256

The same nonce and key must be used for both encryption and decryption of the same memory address.

The memory address used for encryption is the external flash memory address and thus independent of XIPOFFSET. This means a second firmware image can be encrypted and written using EasyDMA, then XIPOFFSET set to point to the new firmware image before executing from it.

Stream ciphers are symmetric. They do not differentiate between encrypting or decrypting, reading or writing. Thus, if the contents of a plain text external flash is read when stream cipher is enabled, the data provided to the MCU is encrypted.

Execute in place (XIP)

Enable the stream cipher for QSPI XIP by doing the following steps.
  1. Configure keys using XIP_ENC.KEY0 through XIP_ENC.KEY3.
  2. Configure nonce using XIP_ENC.NONCE0 through XIP_ENC.NONCE2.
  3. Set XIP_ENC.ENABLE.
Any instructions or data read from the XIP interface will now pass through the stream cipher.

EasyDMA

Enable the stream cipher for QSPI EasyDMA by doing the following steps.
  1. Configure keys using DMA_ENC.KEY0 through DMA_ENC.KEY3.
  2. Configure nonce using DMA_ENC.NONCE0 through DMA_ENC.NONCE2.
  3. Set DMA_ENC.ENABLE.
Any data read from or written to the external flash over the EasyDMA interface will now pass through the stream cipher.