| 数据搜索系统,热门电子元器件搜索 |
|
STM32H533CE 数据表(PDF) 22 Page - STMicroelectronics |
|
|
|||||||||||||||||||||||||||||
STM32H533CE 数据表(HTML) 22 Page - STMicroelectronics |
|
22 / 231 page ![]() Functional overview STM32H533xx 22/231 DS14539 Rev 1 Note: The ECC is supported by SRAM2, and BKPSRAM when enabled with the SRAM2_ECC, and BKPRAM_ECC user option bits. 3.5.1 SRAMs TrustZone security When the TrustZone security is enabled, all SRAMs are secure after reset. The SRAM1, SRAM2, SRAM3, can be programmed as secure or non-secure by blocks, using the MPCBB (block-based memory protection controller). The granularity of SRAM secure block based is a page of 512 bytes. Backup SRAM regions can be programmed as secure or non-secure with watermark, using the TZSC (TrustZone security controller) in the GTZC (global TrustZone controller). 3.5.2 SRAMs privilege protection The SRAM1, SRAM2, SRAM3, can be programmed as privileged or non-privileged by blocks, using the MPCBB. The granularity of SRAM privilege block based is a page of 512 bytes. Backup SRAM regions can be programmed as privileged or non-privileged with watermark, using the TZSC (TrustZone security controller) in the GTZC (global TrustZone controller). 3.6 Security overview The STM32H533xx security enables the possibility to reopen the debug mode even if the product is in secure state. The reopening of the debug mode is controlled with a debug authentication procedure which permits the authentication of the host. The sensible assets such as keys or secret codes must be protected when opening the debug mode. The protection is made via code protection and hardware keys storage solutions where all root of trust can be protected thanks to hardware mechanisms. In cases where sensitive information cannot be protected, a partial or a full regression can be launched in order to allow a debugging. Regressions are enabled by a debug authentication method. The STM32H533xx design also permits the developers to introduce their own root of trust solution (OEM-iROT), including their installation in a non-trusted environment thanks to a secure firmware install (SFI) solution. The STM32H533xx boot stages are isolated via a hardware mechanism called HDPL (temporal isolation level). The HDPL guarantees isolation of the different boot stages: ST assets, iROT (immutable root of trust), uROT (updatable root of trust), secure operating system and non-secure applications. STM32H533xx devices embed a hardware key storage solution with the following characteristics: • Feature a dedicated flash memory area per boot stages with access-control based on HDPL and which can be secure or non-secure. • The keys can be stored encrypted with a derived key related to the current execution context (HDPL, regression counter called EPOCH, secure or non-secure). • One crypto accelerator hardware DPA resistant (SAES), connected via hardware key bus to a non-DPA protected accelerator. |
|
链接网址 |
| ALLDATASHEET是否为您带来帮助? [ DONATE ] |
关于 Alldatasheet | 广告服务 | 联系我们 | 隐私政策 | 数据表链接 | 链接交换 | 制造商名单 All Rights Reserved©Alldatasheet.com |
| Russian : Alldatasheetru.com | Korean : Alldatasheet.co.kr | Spanish : Alldatasheet.es | French : Alldatasheet.fr | Italian : Alldatasheetit.com Portuguese : Alldatasheetpt.com | Polish : Alldatasheet.pl | Vietnamese : Alldatasheet.vn Indian : Alldatasheet.in | Mexican : Alldatasheet.com.mx | British : Alldatasheet.co.uk | New Zealand : Alldatasheet.co.nz |
|
Family Site : ic2ic.com |
icmetro.com |