Last edited 2 weeks ago

Tamper configuration

Applicable for STM32MP13x lines, STM32MP15x lines, STM32MP21x lines, STM32MP23x lines, STM32MP25x lines

1. Overview[edit | edit source]

The STM32 MPUs embed a tamper detection management system.

The tamper management and configuration functions have been added to the OP-TEE secure OS to protect against external attacks when the system is running. The tamper management is also present in the TF-A BL2 because tamper events can occur when the SoC is in low-power or power-off modes.

When a tamper event occurs, the platform's secrets are erased or blocked. The automatic erase mode of all secrets can be configured for some tampers. It is enabled by default but can be turned off (see TAMP device tree configuration) if the user application needs to control erase operations. The platform secrets access is blocked when erase is on-going.

Except for STM32MP15x lines , the tampers can be configured in two modes:

  • Confirmed mode: immediate erase of secrets on tamper detection, including backup registers erase
  • Potential mode: some of the secrets are instead locked following a tamper detection until a software action.

On STM32MP15x lines , the secrets will be erased.

To learn more about which secrets are erased or blocked in which modes, refer to the TAMP interconnection table (tamp_confirmed and tamp_potential signals) in the TAMP chapter of the SoC reference manual. Note that the erased/blocked secret list is device dependent: for instance HASH1/HASH2, RNG1/2 and OTFDEC1/2 keys on STM32MP21x lines , HASH and OTFDEC on STM32MP23x lines  and STM32MP25x lines .

Information
Because STMicroelectronics cannot provide generic sequences on how to handle tampers, someone wishing to use tampers is expected to customize the tampers interrupt handler sequence. The default behavior when a tamper event occurs is a system reset when running. When the tamper is in confirmed mode, the appropriate secret erase sequence is also performed by the hardware. Whereas in potential mode, the secrets are blocked but not erased until the handler sequence is performed. The files to custom are TF-A BL2 platform setup for the STM32MP1 series and TF-A BL2 platform setup for the STM32MP2 series (when a tamper event happens when the SoC is in retention mode), and OP-TEE tamper driver for runtime management

1.1. Internal tampers[edit | edit source]

The table below represents the list of the supported internal tampers. Hovering a check mark gives the corresponding internal tamper index (ITAMPx) used in the TAMP registers and in the st,tamp-internal-tampers device tree property.

STM32MP13x lines  STM32MP15x lines  STM32MP21x lines  STM32MP23x lines  STM32MP25x lines 
Backup voltage domain monitoring [1] ✓ ✓ ✓ ✓ ✓
Temperature monitoring [1] ✓ ✓ ✓ ✓ ✓
LSE monitoring [2] ✓ ✓ ✓ ✓ ✓
HSE monitoring [3] ✓ ✓ ✓ ✓ ✓
RTC calendar overflow ✓ ✓ ✓ ✓ ✓
Monotonic counter 1 overflow ✓ ✓ ✓ ✓ ✓
JTAG/SWD access ✓ ✓ ✓ ✓
Cryptographic peripherals fault ✓ ✓
SAES or CRYP or PKA or RNG1/2
✓
SAES or PKA or TRNG
✓
SAES or PKA or TRNG
Monotonic counter 2 overflow ✓ ✓ ✓ ✓
IWDG reset when tamper flag is set ✓
IWDG1
✓
IWDG1, IWDG3
✓
IWDG1, IWDG3, IWDG5
✓
IWDG1, IWDG3, IWDG5
ADC2 analog watchdog monitoring 1 ✓ ✓
ADC2 analog watchdog monitoring 2 ✓ ✓
ADC2 analog watchdog monitoring 3 ✓ ✓
VDDCORE monitoring under/over voltage [4] ✓ ✓
VDDCPU (Cortex®-A35) monitoring under/over voltage [5] ✓ ✓
LPSRAM1 CRC fail (same signal as IWDG5 reset) [6] ✓ ✓
RIFSC or BSEC or DBGMCU fault ✓
Boot ROM fault ✓
Information
The internal tamper indexes are not aligned across the STM32 MPU series: for instance ITAMP7 is the ADC2 analog watchdog monitoring 1 on STM32MP13x lines  and STM32MP21x lines , but the VDDCORE monitoring on STM32MP23x lines  and STM32MP25x lines . Always use the INT_TAMPER_xxx macros of the device tree binding header matching your device (see TAMP device tree configuration).

1.2. External tampers[edit | edit source]

External tampers can be defined on all MPUs:

  • 3 on STM32MP15x lines 
  • 8 on STM32MP13x lines 
  • 7 on STM32MP21x lines 
  • 7 on STM32MP23x lines 
  • 8 on STM32MP25x lines 

The external tampers can be configured as passive (they detect a level or an edge on one pin) or as active (two pins have to be linked together, and the TAMP hardware regularly sends a random level on the OUT pin, then reads IN pins and raises the tamper flag if the values mismatch). Note that the number of mismatches raised before a tamper event can be configured.

A given TAMP_INx input may be routed to several pins; the routing is selected through the TAMP option register and is handled by the OP-TEE tamper driver. On STM32MP21x lines , only TAMP_IN1 is remappable (PI8 or PC4). On STM32MP23x lines  and STM32MP25x lines , TAMP_IN1 (PI8 or PC4), TAMP_IN3 (PC3 or PZ2) and TAMP_IN5 (PF6 or PZ4) are remappable.

2. Software configuration[edit | edit source]

2.1. Default internal tampers configuration[edit | edit source]

Be aware that some of the internal tampers require other feature to be functional (LSE/HSE monitoring, voltage monitoring). Refer to the TAMP chapter of the SoC reference manual to learn more on this subject.

Warning
Because it monitors the LSE oscillator used for the retention domain, a LSE monitoring internal tamper event must be followed by either a reset of the backup domain or a custom sequence. For the latter, please modify the code in TF-A BL2 platform setup / TF-A BL2 platform setup and OP-TEE tamper driver .

On all the STM32 MPU series (STM32MP13x lines , STM32MP15x lines , STM32MP21x lines , STM32MP23x lines  and STM32MP25x lines ), no internal tamper is enabled by default. To enable one or more of them, refer to the TAMP common property list.

2.2. Default external tampers configuration[edit | edit source]

On STMicroelectronics boards, the TAMP button is enabled by default in the board device tree file to generate tamper events, except on STM32MP15x lines  and STM32MP21x lines  platforms:

Board Tamper button Tamper input Mode
STM32MP135x-DK Enabled TAMP_IN2 (PA6) Confirmed
STM32MP215x-DK Not enabled: no tamper button declared in the board device tree
STM32MP235x-DK Enabled TAMP_IN3 (PZ2) Confirmed
STM32MP257x-DK Enabled TAMP_IN3 (PZ2) Confirmed
STM32MP257x-EV1 Enabled TAMP_IN1 (PI8) Confirmed

This is done in the board device tree file. See: Board device tree configuration.

3. References[edit | edit source]

  1. ↑ 1.0 1.1 This monitoring must be enabled by setting MONEN in the PWR control register 2 (PWR_CR2).
  2. ↑ This monitoring must be enabled by setting LSECSSON in the RCC backup domain control register (RCC_BDCR).
  3. ↑ HSE monitoring is an OR between the HSECSS output and the LPTIM1 output (lptim_ch1) when it is configured for HSE over-frequency detection. HSECSS must be enabled by the HSECSSON bit in the RCC oscillator clock enable set register (RCC_OCENSETR). See How to activate HSE monitoring.
  4. ↑ This monitoring must be enabled by setting VCOREMONEN in the PWR control register 5 (PWR_CR5).
  5. ↑ This monitoring must be enabled by setting VCPUMONEN in the PWR control register 6 (PWR_CR6).
  6. ↑ The CRC computation and signature check must be enabled on LPSRAM1 to allow the CPU3 boot when a D3 domain wake-up is triggered by a tamper event (ePOS mode). If the CRC check fails, CPU3 is not allowed to boot and a tamper event is generated.