4.3.2. Reuse of AHB slaves

ARM recommends that separate AHB buses are used to contain the Secure and the Non-secure AHB slaves. This enables use of the single NS-bit control signal provided by the AXI-to-AHB bridge; the bridge will reject any transactions which have invalid security permissions.

In situations where this is not possible, a TrustZone Address Space Controller can be placed before the AXI-to-AHB bridge, enabling address-based checks of the NS-bit to be performed.

