7.6 Configuration lockdown

The MPC provides a configuration lockdown feature that prevents malicious software from changing the security configuration. Writing 0b1 to the security lockdown bit, CTRL.SEC_CFG_LOCK, enables the configuration lockdown feature.

Once the configuration lockdown feature is enabled:


Arm recommends that you write 0b1 to the LUT autoincrement bit, CTRL.INC_BLK_IDX before enabling the configuration lockdown feature. When the lockdown feature is enabled, only LUT reading is available which is simpler when BLK_IDX increments automatically during the read sequence.
