7.4.6 Control Fuses

The control fuse box includes 128 OTP (One-time programming) fuse bits. Only some of them are used to configure software security features (see table below). Reserved bits in the range 0 to 17 must not be modified. Bits from 18 to 128 are not used. The default status of all fuses is not set.

Fuse BitNameDescription
0ENCRNOTPLAINIf it is set, Secure mode is active
1READ_AES_KEYIf it is set, KEY_ENC and KEY_TAG cannot be read
2WRITE_AES_KEYIf it is set, KEY_ENC and KEY_TAG can’t be written
5READ_CONTROLIf it is set, CONTROL_FUSES can’t be read
6WRITE_CONTROLIf it is set, CONTROL_FUSES can’t be written
7READ_RAMIf it is set, memory ram can’t be read
8RESERVEDReserved
9RESERVEDReserved
10FORCE_IVNBINCIf it is set, initialization vector and number of blocks must be used in the calculation of the signature
11RESERVEDReserved
12RESERVEDReserved
13RESERVEDReserved
14RESERVEDReserved
15RESERVEDReserved
16DBG_DISABLEIf it is set, JTAG debug is disabled
17DBG_DISABLE_SEReserved