Device Security
282
SLAU356I – March 2015 – Revised June 2019
Copyright © 2015–2019, Texas Instruments Incorporated
System Controller (SYSCTL)
Table 4-1. Boot Override Flash Mailbox (continued)
Mailbox
Offset
Group
Description
Value
0x60
SEC_ZONE0_PARAMS
SEC_ZONE0_SECEN
Disable = 0xFFFFFFFF (default state)
Enable = 0x00000000 (any value other than 0xFFFFFFFF)
0x64
SEC_ZONE0_START_ADDR
Start address of IP protected secure zone 0. Should be in Bank
0 and aligned to 4KB boundary in main flash region.
0x68
SEC_ZONE0_LENGTH
Length of IP protected secure zone 0 in bytes. Should be
multiples of 4KB flash sector size.
0x6C-0x78
SEC_ZONE0_AESINIT_VECT[0-3]
IP protected secure zone 0 AES initialization vector for AES-
CBC to be used for encrypted updates.
0x7C-0x98
SEC_ZONE0_SECKEYS[0-7]
AES-CBC security keys. This should be the key that is used to
generate the ENCPAYLOAD when the user intends to do an
upgrade.
0xFFFFFFFF when IP protected secure zone 0 security
disabled.
0x9C-0xA8
SEC_ZONE0_UNENC_PWD[0-3]
Unencrypted password for upgrade.
0xFFFFFFFF when IP protected secure zone 0 security
disabled.
0xAC
SEC_ZONE0_ENCUPDATE_EN
Disable = 0xFFFFFFFF(default state)
Enable = 0x0000000 (any value other than 0xFFFFFFFF)
0xB0
SEC_ZONE0_DATA_EN
Disable = 0xFFFFFFFF(default state)
Enable = 0x00000000 (any value other than 0xFFFFFFFF)
0xB4
ACK
Acknowledgment for this command
0xB8-BC
RESERVED
0xFFFFFFFF
0xC0
SEC_ZONE1_PARAMS
SEC_ZONE1_SECEN
Disable = 0xFFFFFFFF(default state)
Enable = 0x00000000 (any value other than 0xFFFFFFFF)
0xC4
SEC_ZONE1_START_ADDR
Start address of IP protected secure zone 1. Should be in Bank
0 and aligned to 4KB boundary in main flash region.
0xC8
SEC_ZONE1_LENGTH
Length of IP protected secure zone 1 in bytes. Should be
multiples of 4KB flash sector size.
0xCC-0xD8
SEC_ZONE1_AESINIT_VECT[0-3]
IP protected secure zone 1 AES initialization vector for AES-
CBC to be used for Encrypted Updates.
0xDC-0xF8
SEC_ZONE1_SECKEYS[0-7]
AES-CBC security keys. This should be the key that is used to
generate the ENCPAYLOAD when the user intends to do an
upgrade.
0xFFFFFFFF when IP protected secure zone 1 security
disabled.
0xFC-0x108
SEC_ZONE1_UNENC_PWD[0-3]
Unencrypted password for upgrade.
0xFFFFFFFF when IP protected secure zone 1 security
disabled.
0x10C
SEC_ZONE1_ENCUPDATE_EN
Disable = 0xFFFFFFFF(default state)
Enable = 0x0000000 (any value other than 0xFFFFFFFF)
0x110
SEC_ZONE1_DATA_EN
Disable = 0xFFFFFFFF(default state)
Enable = 0x00000000 (any value other than 0xFFFFFFFF)
0x114
ACK
Acknowledgment for this command
0x118-
0x11C
RESERVED
0xFFFFFFFF