One embodiment relates to a data processing system having a cryptographic
unit. The cryptographic unit includes cryptographic circuitry which
performs a first cryptographic function to provide security for a portion
of the cryptographic unit, and which performs a second cryptographic
function to provide security for a portion of the data processing system
external to the cryptographic unit. The cryptographic unit may therefore
operate in a normal operating mode and in a secure operating mode. During
a first secure operating mode a first key is used to decrypt first
security configuration information which includes a second key. During a
second secure operating mode, the second key is used to decrypt second
security configuration information. The cryptographic unit may include a
secure internal memory such that during the secure operating modes, the
cryptographic unit may only process descriptors provided from this secure
internal memory.