SDAA472 August   2026 MSPM33C321A

 

  1.   1
  2.   Abstract
  3.   Trademarks
  4. 1Introduction
    1. 1.1 Key Concepts
  5. 2Customer Secure Code Overview
    1. 2.1 Boot and Startup Sequence
    2. 2.2 CSC Flow
    3. 2.3 FLASH Memory Map
    4. 2.4 Bank Swap
    5. 2.5 CSC Feature
      1. 2.5.1 Asymmetric Verification
        1. 2.5.1.1 SHA-256
        2. 2.5.1.2 ECDSA
        3. 2.5.1.3 MLDSA
      2. 2.5.2 Keystore
    6. 2.6 Protection on CSC
      1. 2.6.1 Write Erase Protection
      2. 2.6.2 FLASH Hide Protection
      3. 2.6.3 Data Integrity Verification
      4. 2.6.4 Secure & Privilege Protection
    7. 2.7 CSC Performance
  6. 3Evaluate CSC-based Secure Boot
    1. 3.1 Environment Setup
    2. 3.2 Program CSC
      1. 3.2.1 General
      2. 3.2.2 Step 1 - Building
      3. 3.2.3 Step 2 - Programming
    3. 3.3 Program Application
      1. 3.3.1 General
      2. 3.3.2 Step 1 - Application Image Generation – Image 1 (version 1.0.0, Located at Bank 0 – 0x10000)
      3. 3.3.3 Step 2 - Application Image Generation – Image 2 (version 2.0.0, Located at 0x20000)
      4. 3.3.4 Step 3 - Programming
    4. 3.4 Running the CSC Application
  7. 4Q&A
    1. 4.1 How to Modify the Application Image Version
      1. 4.1.1 Application Image
    2. 4.2 How to Modify the Application Image Address
      1. 4.2.1 Application Image
      2. 4.2.2 Application Image Sign Command
      3. 4.2.3 CSC Example Code
    3. 4.3 How to Modify the Slot Size
      1. 4.3.1 Application Image
      2. 4.3.2 CSC Example Code
    4. 4.4 How to Modify the Application Image Size
      1. 4.4.1 Application Image
      2. 4.4.2 Modification on Slot Size
    5. 4.5 Doing More Customization on Application Image or CSC
  8. 5References
  9. 6Revision History

Boot and Startup Sequence

Figure 2-1 shows the CSC boot and startup sequence. At BOOTRST, TI ROM boot-code execution commences. After successful boot, boot code issues BOOTDONE. At this point, SYSCTL issues a SYSRST to the device to trigger execution from MAIN flash memory. For HSFS state device, a MAIN flash program always starts after boot code finishes from physical address 0x0004 vector (Reset Handler). Depending on the CSCEXISTS configuration in NONMAIN flash BCR, there are two execution flow after BOOTDONE:

  • CSCEXISTS set: CSC boot sequence is enabled and MAIN flash program starts with INITDONE in clear state. Users need to place the CSC firmware into MAIN flash 0x0000 address in this case. Users can set static write protection policy in the NONMAIN BCR configuration to protect the CSC firmware.
  • CSCEXISTS clear: CSC boot sequence is not allowed and MAIN flash program starts with INITDONE in set state. Any security related policy is not configurable and users need to place the application firmware into MAIN flash 0x0000 address in this case.
Note: Bank swap policy resets during BOOTRST, so the MAIN flash program always starts without bank swap after BOOTDONE. Bank swap only takes effects after INITDONE when both CSCEXISTS and FLASHBANKSWAPPOLICY enabled in NONMAIN configuration.

For the CSC existing case, CSC is responsible for determining execution bank, secure key initialization into the KEYSTORE, take application program integrity and authenticity verification, and others. The device is working in a privileged state with permission configuring those security policies. The INITDONE is issued (by writing to SYSCTL.SECCFG.INITDONE, see the device-specific technical reference manual for the register definition) at the end of CSC, then SYSCTL issues a second SYSRST and all the security policies listed below take effect during INITDONE and cannot be modified until the next BOOTRST:

  • Bank swap policy
  • Keystore protection

During CSC, the global security controller (GSC) can be configured for security policies. The vector table offset register (VTOR) from GSC also updates for the vector table address of the main application.

After INITDONE, a SYSRST is triggered, and the device starts execution from address in VTOR and directly jumps to the main application.

For more details on boot and startup sequence, plrese refer to the SECURITY chapter of the MSPM33 C3-Series 160MHz Microcontrollers technical reference manual.

  Boot and Startup Sequence Figure 2-1 Boot and Startup Sequence