8.6.3.1 Crypto Key Storage
The Crypto module accepts keys placed in user Flash/RAM. Additionally, keys can also be stored in a non-executable/non-writable IRT/OTP region. The access to keys stored in IRT region can be revoked upon completion of IRT code execution, thereby securing the keys from being accessed by application firmware code. Any attempt to access keys from restricted space reads zero and logs an error in BMXCRYPT register.
Refer to Security Module for more information.