The RAM memory space is divided into 64 regions of 8 KiB, each with configurable permissions settings.
For each region, the following types of permissions can be configured:
- Read
- Allows data read access to the region. Code fetch from this region is not controlled by the read permission but by the execute permission described below.
- Write
- Allows write access to the region.
- Execute
- Allows code fetch from this region.
- Secure
- Allows only bus accesses with the security attribute set to access the region.
Permissions can be set independently. For example, it is possible to configure a RAM region to be accessible only through secure transfer, being read-only (no write allowed) and non-executable (no code fetch allowed). For each region, permissions can be set and then locked to prevent subsequent modifications by using the RAMREGION[n].PERM.LOCK bit.
The following figure shows the RAM memory space divided into N=64 regions, each of 8 KiB.