General concepts

nRF5340 Product Specification

SPU provides a register interface to control the various internal logic blocks that monitor access to memory-mapped slave devices (RAM, flash, peripherals, etc) and other resources (device pins, DPPI channels, etc).

For memory-mapped devices like RAM, flash, and peripherals, the internal logic checks the address and attributes (e.g. read, write, execute, secure) of the incoming transfer to block it if necessary. A secure resource can be accessed by a given master based on the following factors:

  • CPU-type master – By the security state of the CPU and the security state reported by SPU, for the address in the bus transfer.
  • Non-CPU master – By the security attribute of the master that initiates the transfer, defined by a SPU register.

The Simplified view of SPU protection shows a simplified view of the SPU registers controlling several internal modules.

Figure 1. Simplified view of SPU protection
Page-1 Sheet.6 Sheet.7 RAM Blocks RAM Blocks Sheet.9 Cortex-M33 TrustZone-M aware CPU Cortex-M33 TrustZone-M aware CPU Sheet.11 Implementation defined attribution unit (IDAU) Implementation defined attribution unit (IDAU) Sheet.12 Sheet.13 Other bus masters Other bus masters Sheet.15 Bus interconnect Bus interconnect Sheet.16 Secure control logic Secure control logic Sheet.17 Peripherals Peripherals Sheet.19 Sheet.20 Sheet.21 Sheet.22 Flash Flash Sheet.23 Sheet.24 Sheet.25 Sheet.26 Sheet.27 Sheet.28 Sheet.29 Sheet.30 SPU configuration registers SPU configuration registers Sheet.31 Sheet.32 Sheet.33 Secure control logic Secure control logic Sheet.34 Sheet.35 Sheet.36 Sheet.37 Sheet.38 Internal system logic Internal system logic Sheet.39 Sheet.8 Sheet.18 RAM blocks RAM blocks
The protection logic implements a read-as-zero/write-ignore (RAZ/WI) policy where the following are true:
  • A blocked read operation will always return a zero value on the bus, preventing information leak.
  • A write operation to a forbidden region or peripheral will be ignored.

An error is reported through dedicated error signals. For security state violations from an M33 master this will be a SecureFault exception, for other violations this will be an SPU event. The SPU event can be configured to generate an interrupt towards the CPU.

Other resources like pins and DPPI channels are protected by comparing the security attributes of the protected resource with the security attribute of the peripheral that wants to access it. SPU is the only place where those security attributes can be configured.