Revoke

nRF54L15 | nRF54L10 | nRF54L05 Datasheet

A key slot that is revoked it can no longer be pushed.

A key slot can be revoked when it is in the PROVISIONED state or when its revocation policy is not LOCKED.

To revoke a key slot, perform the following steps:
  1. Configure the key slot ID in the KEYSLOT register.
  2. Enable RRAM write operation in Normal write mode. For details, see RRAMC — Resistive random access memory controller.
  3. Trigger the REVOKE task.

    KMU erases the asset from SICR. If revoking the key slot is successful, KMU generates the REVOKED event. If unsuccessful, or the key slot is already in the REVOKED state, KMU generates the ERROR event.

  4. Disable RRAM write operation. For details, see RRAMC — Resistive random access memory controller.
Rotating key slots are available after a successful revocation. Non-rotating key slots remain in a REVOKED state and can not be used again until SICR is erased. SICR can only be erased using the Erase All functions of CTRL-AP — Control access port and RRAMC — Resistive random access memory controller.