2416299_en-US

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

2416299_en-US

2416299_en-US

Correct snvs_cfg values for TAMPER_OUT0/TAMPER_IN4 active tamper loop on i.MX8DXL EVK (J20)

Hi,

I'm validating the external active-tamper loop on the i.MX8DXL EVK (MCIMX8DXL-WEVK) via U-Boot.

From the board schematic, I've confirmed J20 (TAMPER header, 1x3) is wired as:
- Pin 1 = TAMPER_IN4 (net SNVS.TAMPER_IN4, ball AJ13)
- Pin 2 = GND
- Pin 3 = TAMPER_OUT0 (net SNVS.TAMPER_OUT0, ball AP22)

These are dedicated SNVS pins, not shared with SAI2/SAI3 like TAMPER_OUT1-4/IN0-3.

Available U-Boot commands: tamper_pin_cfg, snvs_cfg (with sub-registers hp.lock, hp.secvio_intcfg, hp.secvio_ctl, lp.lock, lp.secvio_ctl, lp.tamper_filt_cfg, lp.tamper_det_cfg, lp.tamper_det_cfg2, lp.tamper_filt1_cfg, lp.tamper_filt2_cfg, lp.act_tamper1_cfg through lp.act_tamper5_cfg, lp.act_tamper_ctl, lp.act_tamper_clk_ctl, lp.act_tamper_routing_ctl1, lp.act_tamper_routing_ctl2), snvs_sec_status, snvs_clear_status.

Since TAMPER_OUT0/TAMPER_IN4 form an active tamper pair, my questions:

1. Which lp.act_tamperN_cfg channel (1-5) corresponds to TAMPER_OUT0?
2. What values for lp.act_tamper_routing_ctl1/routing_ctl2 route TAMPER_OUT0's pattern to be checked against TAMPER_IN4?
3. What value for lp.act_tamper_clk_ctl enables the pattern clock for this channel?
4. What value for lp.act_tamper_ctl globally enables active tamper detection for this channel?

Goal: closing a jumper across J20 pins 1-3 should read as secure in snvs_sec_status, and opening it should trigger a violation.

I've attempted several values on hardware (routing 4, 5, 10; various clock/detector settings) — all were either rejected by the SECO firmware (error res:9 / SC_ERR_PARM) or accepted with no observable change in snvs_sec_status's SNVS a4(1) (LPTDSR) register when physically toggling the loop.

Is there a reference test procedure or app note for external active tamper validation on i.MX8DXL?

Thanks!

Re: Correct snvs_cfg values for TAMPER_OUT0/TAMPER_IN4 active tamper loop on i.MX8DXL EVK (J20)

Hello,

1. lp.act_tamper1_cfg drives TAMPER_OUT0.

2. The i.MX8DXL SNVS has 5 Active Tamper (AT) output sources and up to 8 External Tamper (ET) input detectors.

Please use this configuration:

lp.act_tamper_routing_ctl1 = 0x00010000 # ET5 (TAMPER_IN4) to AT1 (TAMPER_OUT0)
lp.act_tamper_routing_ctl2 = 0x00000000 # ET6-ET8 not used

3. That value changes the clock divider, use 0x00 for maximum frequency configuration.

lp.act_tamper_clk_ctl = 0x00000000

4. Use lp.act_tamper_ctl = 0x00010001:

Bit 0: AT1EN enable AT1 LFSR pattern generator

Bit 16: AT1_OUT_EN drive TAMPER_OUT0 pad with AT1 pattern

There is no application note available for this processor but you can use this from an i.MX7 that can be used as reference:

/* Config ET5 (pin in et4) <-> (pin out et5) AT 1 *
/* reset */
write32(0, &svregs->lp.act_tamper_clk_ctl);
write32(0, &svregs->lp.act_tamper_ctl);
write32(0, &svregs->lp.tamper_det_cfg);
write32(0, &svregs->lp.tamper_det_cfg2)
/* Deault value for LFSR */
write32(0x84000000 | 0x00001111, &svregs->lp.act_tamper1_cfg)
/* Set the clock at max freq */
write32(0x00000000, &svregs->lp.act_tamper_clk_ctl);
/* ET5 (pin et4) takes ref from AT1 (pin et5) */
write32(0x00010000, &svregs->lp.act_tamper_routing_ctl1);
write32(0x0, &svregs->lp.act_tamper_routing_ctl2)
/* activate out pad of AT1 and enable it, AT1 output on pin et5 */
write32(0x00010000 | 0x00000001, &svregs->lp.act_tamper_ctl)
/* Configuring IRQs and secviols */
write32(0x8000003f, &svregs->hp.secvio_intcfg);
write32(0x4000003f, &svregs->hp.secvio_ctl);
write32(0x0000003f, &svregs->lp.secvio_ctl)
/* Activating detector for ET5 */
write32(0x00000000, &svregs->lp.tamper_det_cfg);
write32(0x00000004, &svregs->lp.tamper_det_cfg2);

Best regards.

Re: Correct snvs_cfg values for TAMPER_OUT0/TAMPER_IN4 active tamper loop on i.MX8DXL EVK (J20)

Thank you for the configuration. I applied it exactly on a fresh power cycle:

snvs_dgo_cfg 0 0 20000000 0 80000000 0
snvs_cfg 0 8000003f 4000003f 0 3f 0 0 4 0 0 84001111 0 0 0 0 10001 0 10000 0

Readback matches your values: SNVS e8(2) = 00010000 00000000, SNVS 48(2) = 00000000 00000004, SNVS e0 = 00010001, DGO 20 = 20000000, DGO 40 = 80000000.

Result: LPTDSR (SNVS a4) = 00000004 (ET5D set). It reads 00000004 both with no jumper and with an insulated jumper connected between J20 pin 1 (TAMPER_IN4) and pin 3 (TAMPER_OUT0). It also stays 00000004 after snvs_clear_status 107ff ff. So detection asserts with the loop open, but I never get a clean 00000000 state with the loop closed.

Questions:
1. Does the TAMPER_OUT0 / TAMPER_IN4 loop on this EVK need a pad or pull setting (for example DGO tamper_pull_ctl), or a different act_tamper_clk_ctl value, for a wired-jumper loop?
2. Is snvs_clear_status expected to clear LPTDSR while the tamper condition is still present?
3. Is any other setting needed for the loop to be seen as closed?

Thanks again.

Tags (1)
No ratings
Version history
Last update:
18 hours ago
Updated by: