NuMicro M2351 Series – a TrustZone® empowered microcontroller series focusing on IoT security.

The rise of the internet of things era has increased awareness for the integration of the physical world into digital systems. While the digitization of our everyday lives led to efficiency improvements and economic benefits, it has also placed pressure on systems designers who are now required to come up with innovative IoT products capable of performing secure connection and data exchange while maintaining low power consumption. Since security and power consumption are both key requirements in IoT application, Nuvoton has developed the NuMicro® M2351 Series, which excels in supporting the proliferation of intelligent connected devices.

"Intro-1" 
The Nuvoton NuMicro® M2351 microcontroller series is powered by Arm® Cortex®-M23 core with TrustZone® for Armv8-M architecture, which elevates the traditional firmware security to a new level of robust software security.

 

 


The lo
"Intro-2-1030x477"w-power M2351 series microcontrollers operate at up to 64 MHz frequency, with up to 512 Kbytes embedded Flash memory in dual bank mode, supporting secure OTA (Over-The-Air) firmware update and up to 96 Kbytes embedded SRAM. Furthermore, the M2351 series also provides high-performance connectivity peripheral interfaces such as UART, SPI, I²C, GPIOs, USB and ISO 7816-3 for the smart card reader. Its secure and efficient power management features strengthen the innovation of IoT security.


TrustZone® for Arm®v8-M empowered

The NuMicro® M2351 series is empowered by the Arm® TrustZone® for Armv8-M architecture. Arm® TrustZone® technology is a System on Chip (SoC) and CPU system-wide approach to security. In addition to firmware-level security, the M2351 series offers a more enhanced software-level security for robust security and greater power efficiency.

 

"1-1030x500"

In addition to the Cortex®-M23 core, the TrustZone® components of M2351 series include:

  • Secure Attribution Unit (SAU, inside of Cortex®-M23 CPU)
  • Implementation Defined Attribution Unit (IDAU)
  • Flash Memory Controller (FMC)
  • Security Configuration Unit (SCU, which supports SRAM and peripheral configurations)

As described in the figure, some functionalities are fixed to be secure attribution or secure resources accessible only for better software-level security assurance. Besides, other parts of the functionalities are designed to support TrustZone® implementation with bus master and bus slave IPs integration to realize the security functions.

Nuvoton Security Feature Strengthened

"M2351-Diagram-2"

In addition to the TrustZone® technology, the NuMicro® M2351 series is also equipped with rich functions to improve system security. The Secure Bootloader supports trusted boot feature. The hardware crypto accelerators, including ECC, support encryption and decryption operations to offload the main processor’s computing power. The KPROM is a password protection mechanism to allow Flash memory write and erase. The XOM defines execute-only memory regions to protect critical program codes. The Flash lock bits are designed to disable external Flash read/write and debug interface. Tamper detection pins can detect the state transition on the tamper pins.


Power management technology for IoT Innovation

"Intro-4-1030x429"

Other than security, power consumption is also vital for IoT applications. M2351 Series offers multiple power modes for more efficient power management. Regarding the power consumption of M2351 series, the normal run mode consumes 97 μA/MHz in LDO mode and 45 μA/MHz in DC-DC mode. The current consumption of stand-by power down mode is 2.8 μA and the deep power-down mode without VBAT is less than 2μA.

Arm® PSA  with Nuvoton Secure Microcontroller Platform (NuSMP) Supported

The Platform Security Architecture (PSA) is a holistic set of threat models, security analysis, hardware and firmware architecture specifications, and an open source firmware reference implementation. The PSA is a contribution from Arm® to the entire IoT ecosystem, offering common ground rules and a more economical approach to building more secure devices.

Nuvoton has developed the Nuvoton Secure Microcontroller Platform (NuSMP) to support Arm® PSA. The NuSMP is a range of hardware and software mixture technologies for security requirements of general purpose and secure IoT microcontrollers. With NuSMP, developers can easily achieve the secure services with the M2351 series in coverage of: Trusted Boot (Root of Trust), Secure OTA (Over-The-Air) firmware update (including secure software download), Power Management APIs for non-secure world and PC side crypto related development software tool.

"NuSMP-Architecture-for-landing-page-1"The entire offering suite is constructed in compliance of Chain of Trust (CoT) with several secure booting layers named NuMicro® Boot Loader 1 (NuBL1, hardware level), Boot Loader 2 (NuBL2 first software level including trust boot code and memory partition manager with OTA update feature), Boot Loader 32 (NuBL32, for Secure World), and Boot Loader 33 (NuBL33, for Non-Secure World). With the CoT guarantee, all services and software tool can support most security requirements for MCU applications.

Easy to develop, easy to implement.

Being committed to providing an easy development experience, Nuvoton offers a wealth of resources to work with the M2351 series. For compiler selection, the M2351 series supports the development on Arm® Keil MDK, IAR Embedded Workbench for Arm M2351 series and GCC. Furthermore, the Keil MDK Nuvoton Edition for M2351 series is free to use. For supporting tools, the M2351 series offers considerate tools to aid the project progress. For example, the TrustZone Template Generator could assist the security state planning and the secure firmware building; the CryptoTool could support the cryptographic requirements of M2351 series, including key generation, key exchange, signature, encryption and decryption. For security project developing, Nuvoton offers integrated security technologies, NuSMP (Nuvoton Secure Microcontroller Platform). The application note, sample code and training videos for each technology would be available for developers to access and reference. Lastly, the Arm® Mbed OS for IoT solutions and the Segger emWin for interactive interfaces are both supported in the M2351 series.

"IDE-List-1030x218"

 

Security Features

Targeting Applications

  • Arm® Cortex®-M23 TrustZone® Technology
  • 8 regions MPU_NS (for non-secure world); 8 regions MPU_S (for secure world)
  • 8 regions Security Attribution Units (SAU)
  • Implementation Defined Attribution Unit (IDAU)
  • 2 KB OTP ROM with additional 1KB lock bits
  • Hardware Crypto Accelerators
  • CRC calculation unit
  • Up to 6 tamper detection pins
  • 96-bit Unique ID (UID), 128-bit Unique Customer ID (UCID)
  • Arm® Platform Security Architecture (PSA) and Trusted Base System Architecture-M (TBSA-M) supported
  • IoT Devices with Secure Connection
  • Collaborative Secure Software Development Business Model
  • Trusted Execution Environment (TEE) with Trusted Applications (TAs)
  • Digital Currency Authentication
  • Fingerprint Card, Fingerprint Lock
  • Smart Home Appliance
  • Smart City Facilities
  • Wireless Sensor Node Device (WSND)
  • Auto Meter Reading (AMR)
  • Portable Wireless Data Collector