8.5.5 Permanent Regions
Multiple parties can create permanent OTP and/or IRT Flash regions in a device. If either the UCB erase-protect and/or UCB write-protect Configuration Words are programmed, OTP and IRT region descriptors cannot be modified even with a chip erase.
OTP regions can be used to prevent firmware tampering for devices that do not require firmware updates. This eliminates the need for secure boot in these devices.
Execute-only OTP regions can be used for firmware IP protection. These regions are configured to not allow data reads but allow execution and CRC access for integrity checking without exposing the protected code.
IRT protection regions designate the root of trust partition within the user program space. IRT regions can be used for IRT firmware, data and cryptographic keys. OTP regions can also be used for IRT firmware.