S32K148 GPIO output privileged access

キャンセル
次の結果を表示 
表示  限定  | 次の代わりに検索 
もしかして: 

S32K148 GPIO output privileged access

ソリューションへジャンプ
3,622件の閲覧回数
jeremie_chirat
Contributor II

We use the S32K148 in an automotive application with some ASIL B functionality.

Safety block diagram (p.107 of S32K-RM.pdf rev 13)

jeremie_chirat_0-1639479039923.png

 

 

 

 

We want to prevent non safe code (unprivileged code) from changing the GPIO outputs.

Safe code (Highest ASIL level of the application) must still be able to change GPIO Outputs at all times (not only at startup but also at runtime)

 

We cannot seem to protect the GPIO controller using MPU: p.281 of S32K-RM.pdf rev 13

 

jeremie_chirat_1-1639479039960.png

 

 

 

We know that the mux configuration of the GPIOs can be protected:

S32K1xx_Memory_Map.xlsx :

 

 

jeremie_chirat_2-1639479039988.png

 

However the S32K148 doesn’t seem to allow to configure the access rights of the GPIO controller.

We do know it is available for S32K118, and have studied the aips_demo_s32k118 form the S32K knowledge base: https://community.nxp.com/t5/S32K-Knowledge-Base/aips-demo-s32k118-zip/ta-p/1124234

 

 

jeremie_chirat_3-1639479040005.png

 

 

The aliased peripheral of does not have any registers allowing privilege control.

jeremie_chirat_4-1639479040024.png

 

 

 

 

jeremie_chirat_5-1639479040164.png

 

 

I thought we could use the clock gating of the SIM module (which himself can be protected from unprivileged access),

but on p.169 of S32K-RM.pdf rev 13, it says that clock gating is not available for our MCU S32K148, only for S32K11x variants.

 

jeremie_chirat_6-1639479040182.png

 

Is there any way to protect the access to the GPIOs outputs for S32K148 ?

 

Thank you for your help.

0 件の賞賛
返信
1 解決策
3,557件の閲覧回数
danielmartynek
NXP TechSupport
NXP TechSupport

Hi @jeremie_chirat,

The SafeAssure team has just replied to the thread discussing some SW solutions.

 

Regards,

Daniel

元の投稿で解決策を見る

0 件の賞賛
返信
3 返答(返信)
3,578件の閲覧回数
jeremie_chirat
Contributor II

Hello Daniel @danielmartynek ,

 

My colleague Mattia Secchiaroli has posted on the NDA SafeAssure Community Group almost a month ago, but we did not get any answer,

that is why I tried here on the normal S32K board.

 

Here is the link to the original post on the NDA group:

https://community.nxp.com/t5/SafeAssure-NDA-group/GPIO-ASIL-protection/m-p/1374873

We know as I wrote that it cannot be protected by MPU, but we would like to know if there is any way to protect it with another mechanism (using privilege access to some registers or something else entirely).

Can you or another NXP colleague answer us on the SafeAssure post?

 

Thank you,

Jérémie Chirat

0 件の賞賛
返信
3,558件の閲覧回数
danielmartynek
NXP TechSupport
NXP TechSupport

Hi @jeremie_chirat,

The SafeAssure team has just replied to the thread discussing some SW solutions.

 

Regards,

Daniel

0 件の賞賛
返信
3,589件の閲覧回数
danielmartynek
NXP TechSupport
NXP TechSupport

Hello @jeremie_chirat,

I'm afraid you are right, the access can't be restricted.

The GPIO module is not on the Peripheral Bridge (AIPS-Lite) and the S2 port of the Crossbar switch is not protected by the MPU.

Since this is a question on the S32K Functional Safety,

please use the SafeAssure Community Group.

https://community.nxp.com/groups/safeassure-nda

https://community.nxp.com/docs/DOC-335524

 


Thank you,

BR, Daniel

0 件の賞賛
返信