Hardware Interfaces

Parameters

The following table lists the instantiation parameters of the CHERIoT memory subsystem. Theory of Operation.

ParameterDefaultTop EarlgreyDescription
addr_tlogic [top_pkg::TL_AW-1:0]logic [31:0]TL-UL address type.
MainSramBaseAddr0x1000_00000x1000_0000Base address of the main SRAM region, inclusive.
MainSramTopAddr0x1003_00000x1003_0000Top address of the main SRAM region, exclusive.
NvmBaseAddr0x3000_00000x3000_0000Base address of the NVM region, inclusive.
NvmTopAddr0x3020_00000x3020_0000Top address of the NVM region, exclusive.
MetaSramBaseAddr0x1100_00000x1100_0000Base address of the unified meta SRAM.

Signals

Referring to the Comportable guideline for peripheral device functionality, the module cheriot_mem_sys has the following hardware interfaces defined

  • Primary Clock: clk_i
  • Other Clocks: none
  • Bus Device Interfaces (TL-UL): regs_tl_d, revbm_tl_d
  • Bus Host Interfaces (TL-UL): cored_tl_h, tbre_tl_h
  • Peripheral Pins for Chip IO: none

Inter-Module Signals

Port NamePackage::StructTypeActWidthDescription
cheriot_enaprim_mubi_pkg::mubi4unircv1CHERIoT mode enable.
cored_tl_dtlul_pkg::tlreq_rsprsp1Data port from the core.
cored_tag_h2dlogicunircv1CHERIoT capability tag carried with the A-channel of cored_tl_h.
cored_tag_d2hlogicunireq1Capability tag returned on the D-channel of cored_tl_h.
corerevbm_tltlul_pkg::tlreq_rsprsp1TRVK (tag revocation) revocation bitmap port from the core.
meta_sram_tltlul_pkg::tlreq_rspreq1Host TL-UL port to the external meta SRAM controller’s RAM interface.
cored_tl_htlul_pkg::tlreq_rspreq1
tbre_tl_htlul_pkg::tlreq_rspreq1
regs_tl_dtlul_pkg::tlreq_rsprsp1
revbm_tl_dtlul_pkg::tlreq_rsprsp1

Interrupts

Interrupt NameTypeDescription
tbre_doneEventRaised when the revocation engine has resolved every capability of a sweep.

Security Alerts

Alert NameDescription
fatal_faultThis fatal alert is triggered when an integrity fault is detected, when the meta SRAM path returns a device error, when the revocation engine reports a fault, when a capability store to the NVM is partial, or when a request breaks the core’s capability store sequence.

Security Countermeasures

Countermeasure IDDescription
CHERIOT_MEM_SYS.BUS.INTEGRITYEnd-to-end bus integrity between the Ibex lockstep and the storage cells. Relies on LOGIC.SHADOW, which is not implemented yet.
CHERIOT_MEM_SYS.LOGIC.SHADOWThe CHERIoT memory subsystem is instantiated in lockstep. Not implemented yet. This also covers the pointers of the subsystem’s FIFOs, which therefore are not redundantly encoded (CTR.REDUN).
CHERIOT_MEM_SYS.MEM.SW_NOACCESSThe capability tag store is not memory mapped.
CHERIOT_MEM_SYS.INTERSIG.MUBIThe CHERIoT mode enable is multi-bit encoded.