All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Trusted Platform Module ST33KTPM2XSPI / ST33KTPM2XI2C

Certificate#4702StandardFIPS 140-3Level1TypeHardwareEmbodimentSingle ChipStatusActiveVendorSTMicroelectronics
High review priority  ·  exposes HSM/SE firmware trust anchor  ·  last validated 25 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeHardware
EmbodimentSingle Chip
StatusActive
Sunset date6/3/2029
CaveatWhen operated in approved mode
VendorSTMicroelectronics

Approved Algorithms (11)

AlgorithmACVP Cert
KTS-IFCA2554
RSA Decryption PrimitiveA2554
SHA-1A2548
SHA-1A2549
SHA2-256A2548
SHA2-256A2549
SHA2-384A2548
SHA2-384A2548
SHA2-384A2549
SHA3-256A2548
SHA3-384A2548

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Trusted Platform Module ST33KTPM2XSPI / ST33KTPM2XI2C
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>recovery<br/>upgrade<br/>firmware load</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>status output</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C6 clue;
  class I2,I3,I6 infer;
  class R2,R3,R6 risk;
  class E2,E3,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Trusted Platform Module ST33KTPM2XSPI / ST33KTPM2XI2C
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>recovery<br/>upgrade<br/>firmware load</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>status output</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C6 clueLow;

Security Policy, page by page

Page 1

STMICROELECTRONICS Trusted Platform Module ST33KTPM2XSPI / ST33KTPM2XI2C Level 1 Date: 2024-03-06 Document Version: 01-02 NON-PROPRIETARY DOCUMENT FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 2
Table of Contents
#SectionPage
Page 3
ISO/IEC 24759 Section 6. [Number Below]FIPS 140-3 Section TitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical security1
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacksN/A
Overall level1
1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy for the STMicroelectronics Trusted Platform Module ST33KTPM2XSPI / ST33KTPM2XI2C. It details how the module meets the requirements specified in [FIPS 140-3] for a Security Level1 module.

1.2 Security levels

Next table indicates the security levels reached by the security module. Table 1 - Security Levels FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 4
ModelHardware [Part Number and Version]Firmware VersionDistinguishing Features
ST33KTPM2XSPIST33K1M5T revC9.256 (dec.) 0x00.09.01.00 (hex.)SPI
ST33KTPM2XI2CSPI or I2C1
2CRYPTOGRAPHIC MODULE SPECIFICATION ST33KTPM2XSPI / ST33KTPM2XI2C is a fully integrated security module implementing the revision 1.59 of the Trusted Computing Group (TCG) specification for Trusted Platform Modules (TPM) version 2.0. It is designed to be integrated into personal computers and any other embedded electronic systems. TPM is primarily used for cryptographic keys generation, keys storage, keys management and secure storage for digital certificates. The security module is a single chip cryptographic HW module as defined in [FIPS 140-3]. The single silicon chip is encapsulated in a hard, opaque, production grade integrated circuit (IC) package. The cryptographic boundary is defined as the perimeter of the IC package. The security module supports both SPI and I2C interfaces, compliant with the PC Client specification [PTP 1.05]. The HW and FW cryptographic boundaries are indicated in Figure 2 and Figure 4 of the current document.
2.1Operating Environments
2.1.1Module identification parameters The operating environments covered by the FIPS 140-3 evaluation are summarized in the table below: Table 2 - Cryptographic Module Tested Configuration FW version can be read in the response to the command TPM2_GetCapability with property set to TPM_PT_FIRMWARE_VERSION_1. The product is manufactured in one single package: • UFQFPN32 ▪ Ultra-thin pitch Quad Flat No-lead 32-pin ▪ 5 x 5 mm Figure 1 - UFQFPN32 package
2.1.2Configurations The security module is available in the configurations listed hereafter.
2.1.2.1KE2 The current FIPS 140-3 level 1 security policy always applies (no mode lock requested) to this security module configuration.
1 The interface is dynamically selected

FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 5
Module configuration
Module name / HW P/NST33KTPM2XSPI
PackageUFQFPN32
InterfaceSPI
MarkingKE2
FW version00.09.01.00 (9.256)
TPM2.0 revision1.59
Libraries version07.01.00.00 (HWINTF library) 05.01.00.00 (TPM2.0 library)
Module configuration
Module name / HW P/NST33KTPM2XI2C
PackageUFQFPN 32
InterfaceSPI / I2C
MarkingKE3
FW version00.09.01.00 (9.256)
TPM2.0 revision1.59
Libraries version07.01.00.00 (HWINTF library) 05.01.00.00 (TPM2.0 library)
CAVP CertAlgorithm and StandardMode / MethodDescription / Key Size(s) / Key Strength(s)Use / Function
A2553AES [SP 800-38A]ECB, CFB128, OFB, CBC, CTR128, 192, 256Data encryption/decryption
A2547DRBG [SP 800-90A]HASH_based SHA2-256Deterministic random bit generation
A2555ECDSA [FIPS 186-4]SHA2-256, SHA2-384, SHA3- 256, SHA3-384P-256, P-384Digital signature generation
SHA-1, SHA2-256, SHA2-384, SHA3-256, SHA3-384P-256, P-384Digital signature verification
ECDSA KeyVer (FIPS 186-4)P-256, P-384Key verification
Appendix B.4.1P-256, P-384Key generation

The current FIPS 140-3 level 1 security policy always applies (no mode lock requested) to this security module configuration. SPI or I2C mode selection is done during the boot of the security

2.2 Security functions

The security module supports the following cryptographic algorithms (both approved and nonapproved). Algorithm certificate numbers for each approved algorithm are listed below. All algorithms, keys size or curve lengths listed below are part of services offered by the module. FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 6
CAVP Cert -Algorithm and Standard ENT (P) [SP800-90B]Mode / MethodDescription / Key Size(s) / Key Strength(s)Use / Function Entropy source1
A2551 A2552HMAC [FIPS 198-1]SHA-1, SHA2-256, SHA2-384, SHA3-256, SHA3-384160, 256, 384Message authentication
A2555KAS [SP 800-56A Rev3]2 [SP 800-56C Rev1]ECC (Full unified and One pass DH)P-256, P-384Key agreement scheme
A2550KBKDF [SP 800-108]CTRKey derivation (based on HMAC)
A2554KTS-IFC [SP800-56B Rev 2]KTS-OAEP-basic2048, 3072, 4096Key generation and key transport
RSADP Component (IG 2.4.B)2048Decryption primitive
A2554RSA [FIPS 186-4]SHA2-256, SHA2-384, RSASSA-PKCS-v1.5, RSASSA-PSS2048, 3072, 4096Digital signature generation
SHA-13, SHA2-256, SHA2-384, RSASSA-PKCS-v1.5, RSASSA-PSS10244, 2048, 3072, 4096Digital signature verification
Appendix C3.12048, 3072, 4096Key generation
A2548SHA3-256, SHA3- 384 [FIPS 202]SHA3-256, SHA3-384Message digest
A2548 A2549SHS [FIPS 180-4]SHA-1, SHA2-256, SHA2-384Message digest. SHA2- 256 is also used as SP800-90B vetted conditioner
AlgorithmCaveatUse / Function
CKG [IG D.H]Direct Generation of Symmetric Keys (Section 4 of [SP800-133 Rev2]).Key generation5
RSA [FIPS 186-4]Use of SHA3-256 or SHA3-384 hashing algorithms.Digital signature generation Digital signature verification

Table 5 - Approved Algorithms Table 6 - Vendor Affirmed Approved Algorithms

1 Seed or reseed SP800-90A approved DRBG with a minimum of 414 bits of entropy. Generate random

numbers not dedicated to being used as cryptographic material.

2 Per [IG] D.F Scenario 2 path (2), [56Ar3] compliant key agreement scheme where testing is performed end-to-end

for the shared secret computation and a KDF compliant with oneStepKdf [56Cr1] without key confirmation.

3 Legacy use only
4 Legacy use only

5 Symmetric keys and seeds used for generating the asymmetric keys are either generated by using

KBKDF or DRBG methods. Methods are detailed per SSPs in Table 19 and Table 20. FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 7
AlgorithmCaveatUse/Function
AES CFBThe AES CFB algorithm itself is Approved and awarded CAVP Cert. #A2553, but this usage employs a key that is non-compliant. The usage of AES CFB in this manner is entirely internal to the module and inaccessible to the operator. No security claimed per IG 2.4.A, Example Scenario #1.Obfuscation of internally stored data
XORNo security claimed per IG 2.4.A, Example Scenario #1.Obfuscation of input or output data
Algorithm/FunctionUse/Function
ECC BN P-256Key generation, digital signature generation based on BN P-256 elliptic curve
ECC derived keysSecret exchange or digital signature generation/verification
ECDAAKey generation, digital signature generation
ECSchnorrKey generation, digital signature generation and verification
HMACKey length < 112 bits for message authentication
RSA1024-bit RSA digital signature generation
RSA with no padding mode (null scheme)Key transport
RSAES-PKCS1-v1_5Key transport
SHA-1Digital signature generation
NameTypeDescriptionSF Properties [O]AlgorithmsAlgorithm Properties
KASKASKey establishmentSP 800-56A, Rev 3 Key length 128 bits IG D.FKAS-ECC (Initiator, Responder), KPG, Full (Cert. #A2555)P-256, P-384 fullUnified, onePassDH oneStepKDF
KTSKTSKey TransportSP 800-38F IG D.G SSP establishment methodology provides 128 or 256 bits of encryption strengthKTS (AES Cert. #A2553 + HMAC Cert. #2551)AES CFB Key size 128 or 256 bits.
KTS- RSAKTSKey TransportSP 800-56B Rev 2 IG D.G KTS-OAEP-basic SSP establishment methodology provides between 112 and 150 bits of encryption strengthKTS-IFC (Cert. #A2554)Key size 2048, 3072, or 4096

Table 9 - Security Function Implementations FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 8

RSA/ECC HW accelerator RAM RAM S bus

CPU core MPU

CPU core MPU C-AHB bus

SPI / I2C interface

2.3 Cryptographic boundary

A block diagram of the security module with its associated cryptographic boundary is provided in Figure 2. memory Read RAM RAM ST ROM cache APB/AHB Cryptographic bridge boundary f APB Security Administrator EDES+ HW Clock generator Reset manager ENT (P) Timers GPIOs module Power mngt GPIO GND VC C LEGEND Instructions Input/output data/commands External control Internal data Cryptographic Internal control boundary Figure 2 - HW block diagram Module is composed of:

1 I2C block is not used by the ST33KTPM2XSPI module configuration

FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 9
2.4 Overall security design
  1. The Module provides one operator role: the Cryptographic Officer.
  2. The Module, evaluated at FIPS 140-3 Level 1, does not claim to provide authentication.
  3. The Module allows the operator to initiate power-up self-tests by power cycling or resetting the Module.
  4. Power up self-tests do not require any operator action.
  5. Data output is inhibited during key generation, self-tests, zeroization, firmware loading, and error states.
  6. Status information does not contain CSPs or sensitive data that if misused could lead to a compromise of the Module.
  7. The Module does not support concurrent operators.
  8. The Module does not support a maintenance interface or role.
  9. The Module does not support manual key entry method.
  10. The Module does not have any proprietary external input/output devices used for entry/output of data.
  11. The Module does not output intermediate key values.
  12. The Module does not provide bypass services or ports/interfaces. FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT
Page 10
SignalTypeDescription
VCCInputPower supply. This pin must be connected to 1.8V or 3.3V DC power rail supplied by the motherboard.
GNDInputGND has to be connected to the main motherboard ground.
RESETInputReset used to re-initialize the device
I2C SCL / GPIO5Input or Input/OutputI²C serial clock (Open drain with no weak pull-up resistor) or GPIO if SPI interface is selected
I2C SDA / GPIO6Input/OutputI²C serial data (Open drain with no weak pull-up resistor) or GPIO if SPI interface is selected
PIRQOutputIRQ used by TPM to generate an interrupt
SPI CLK / GPIO1Input or Input/OutputSPI serial clock (output from master) or GPIO if I2C interface is selected
SPI NSS / GPIO2Input or Input/OutputSPI slave select (active low; output from master) or GPIO if I2C interface is selected
SPI MISO / GPIO0Output or Input/OutputSPI Master Input, Slave Output (output from slave) or GPIO if I2C interface is selected
SPI MOSI / GPIO3Input or Input/OutputSPI Master Output, Slave Input (output from master) or GPIO if I2C interface is selected
GPI8InputGPI default to low. The level of this pin on the rising edge of the RESET signal is used to determine the physical interface to use (high level corresponds to SPI configuration and low-level to I2C)
PPInputPhysical presence, active high, internal pull-down. Used to indicate Physical Presence to the TPM.
NC-Not Connected: connected to the die but not usable. May be left unconnected. Internal pull-down.
3CRYPTOGRAPHIC MODULE INTERFACES
3.1Pinout description The pin layouts for the ST33KTPM2XSPI / ST33KTPM2XI2C with the UFQFPN32 package in Figure 3. The security module supports both SPI and I2C physical interfaces but only one interface is configured during TPM boot. The interface configured remains active until the next module reset.
3.1.1UFQFPN32 configuration Figure 3 - UFQFPN32 Pinout Diagram Next table gives a description of the products pins. Table 10 - UFQFPN32 pins definition

FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 11
Physical portLogical interfaceData that passes over the port/interface
SPI_NSS / SPI_CLK / SPI_MOSI / RESET / PP I2C_SCL / I2C_SDA / RESET / PPControl input interfaceControl parts of the TPM commands provided to the security module. It concerns all bytes of a command except plaintext data, ciphertext data and SSPs (entered with the data input interface).
SPI_NSS / SPI_CLK / SPI_MISO / PIRQ I2C_SCL / I2C_SDA / PIRQControl output interfaceControl parts of the TPM responses output by the security module. It concerns all bytes of a response except plaintext data, ciphertext data and SSPs (output with the data output interface) and except the responseCode of a response (output with the status output interface)
SPI_NSS / SPI_CLK / SPI_MISO / PIRQ I2C_SCL / I2C_SDAStatus output interfaceStatus output by the security module (responseCode parameter of a response)
SPI_NSS / SPI_CLK / SPI_MOSI I2C_SCL / I2C_SDAData input interfaceData (plaintext data, ciphertext data and SSPs) provided to the security module as part of an input processing command.
SPI_NSS / SPI_CLK / SPI_MISO I2C_SCL / I2C_SDAData output interfaceData (plaintext data, ciphertext data and SSPs) output by the security module as part of the response to a processing command.
VCC / GNDPower interfacePower interface of the security module
3.2 Ports and interfaces

their mapping to physical ports of the module are described below: Table 11 - Ports and Interfaces Here are some details concerning the ports and interfaces of TPM: distinguished by properly parsing input TPM command parameters according to input structures description, indicated for each command in [TPM2.0 Part3]1. and control are distinguished by properly setting output TPM response parameters according to output structures description, indicated for each command in [TPM2.0 Part3].

  1. The logical state machine and the command structure parsing of the module prevent from using input data externally from the “data input path” and prevent from outputting data externally from
  2. While performing key generation or key zeroization (no manual key entry on TPM), the output data path is logically disconnected while the output status path remains connected to report any possible failure during command processing. Generally, the output data path is only connected when TPM outputs response containing data.
  3. To prevent the inadvertent output of CSPs in plaintext form on TPM2_Duplicate, the two following independent internal actions are performed: a. Verification of the encryptedDuplication attribute of the key to be duplicated b. Verification of the handle of the new parent of the key to be duplicated encryptedDuplication attribute must be set to 0 and new handle must be set to the null handle to authorize outputting the private part of the key in plaintext form.
  4. The logical state machine and command structure of the module guarantees the inhibition of all data output via the data output interface whenever an error state exists and while doing selftests. The status output interface remains active during the error state to output the status of the security module with the service TPM2_GetCapability and TPM2_GetTestResult. FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT
Page 12
RoleServiceInputOutput
Crypto officer (CO)This role performs the cryptographic initialization of the security module and executes the management functions. This role also covers the use of the general security services provided by the cryptographic module.Any valid inputs and outputs for commands are usable (refer to [TPM2.0 Part3]).
Mandatory service requested from [ISO/IEC 19790]Corresponding services from the security module
Show module’s versioning informationTPM2_GetCapability
Show statusTPM2_GetTestResult
Perform self-testsTPM2_SelfTest TPM2_IncrementalSelfTest
Perform approved security functionsSee approved services listed in Table 14
Perform zeroizationTPM2_Clear, TPM2_ChangePPS, TPM2_ChangeEPS, TPM2_FlushContext, TPM2_EvictControl
4ROLES, SERVICES AND AUTHENTICATION This chapter gives details about the roles managed by TPM.
4.1Roles Services proposed by TPM are accessible under the roles defined in the table below. The list The security module does not provide a maintenance role or maintenance interface and does not support concurrent operators. The CO role is implicitly selected by the TPM operator on service execution.
4.2Authentication In the context of this FIPS 140-3 Level 1 evaluation, there is no authentication mechanism claimed to control access of the security module. The authorization mechanisms (password, HMAC and policy) provided by the TPM2.0 standard are available and protected as sensitive parameters but are not employed to satisfy FIPS 140-3 requirements. Crypto officer role is implicitly assumed by the operator when using services corresponding to that role. All services are accessible under the roles defined in Table 12and no specific access rights are considered to operate with keys and SSPs. Full services inputs and outputs are defined in Table 13 - Mapping between services The security module does not implement any bypass capability, nor self-initiated cryptographic output capability. Next table lists all approved services supported by the TPM. The indicator is accessible with the TPM2_GetCapability (capability = TPM_CAP_VENDOR_PROPERTIES) command by using the sub-capability TPM_SUBCAP_VENDOR_TPMA_MODES = 0x7.

FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 13
ServiceDescriptionApproved Security FunctionsKeys and/or SSPsRolesAccess rights to Keys and/or SSPs1Indicator2
TPM2_StartupSet-up the TPM after a power cycle.NoneppSeed, epSeed, spSeed, phProof, ehProof, shProof, drbgStateCOGApproved
nullSeed, nullProof, contextKey, drbgSeedG, Z
TPM2_Shutdown (I)Prepare the TPM for a power cycle.NoneNoneCON/ANon-security relevant
TPM2_SelfTest (I)Self-tests executionSHS, SHA3, ENT, HMAC, AES, DRBG, KBKDF, KAS, RSA (signature generation, verification) ECC (signature generation, verification)NoneCON/AApproved
TPM2_IncrementalSelfTest (I)Incremental self-tests executionSHS, SHA3, ENT, HMAC, AES, DRBG, KBKDF, KAS, RSA (signature generation, verification), ECC (signature generation, verification)NoneCON/AApproved
TPM2_GetTestResult (I)Get self-tests resultNoneNoneCON/ANon-security relevant
TPM2_StartAuthSession (I/E/D)Session commandSHS, SHA3, HMAC, AES, DRBG, KBKDF, KTS-RSA, KAS, KDA, CKGsesHmacKey, sesSymKeyCOG, WApproved
sesSaltE, Z
objSens, objAuth, nvAuth, platformAuth, endorsementAuth, ownerAuth, lockoutAuth, seqAuthE
TPM2_PolicyRestart (I)Policy session restartNoneNoneCON/ANon-security relevant
TPM2_Create (I/E/D)Object creationobjSeed, objSens, objPubCOG, R, EApproved
1 G = generate, R = read, W = write, E = execute, Z = zeroize

FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 14
SHS, SHA3, HMAC, AES, DRBG, KBKDF, CKG, RSA (signature generation, verification, key generation), ECC (signature generation, verification, key generation)objSymKey, objHmacKey drbgState objAuth nullProof, phProof, ehProof, shProofG, E W, E W E
TPM2_Load (I/E/D)Object loadingSHS, SHA3, HMAC, AES, KBKDFobjSens, objSeedCOW, EApproved
objPub, objAuthW
objSymKey, objHmacKeyG, W, E
TPM2_LoadExternal (I/E/D)External object loadingNoneobjPub, objSens, objAuthCOWApproved
TPM2_ReadPublic (I)Read public part of a loaded objectNoneobjPubCORApproved
TPM2_ActivateCredential (I/E/D)Enables the association of a credential with an objectSHS, SHA3, HMAC, AES, KBKDF, KTS-RSA, KAS, CKGobjSensCOEApproved
creSeedE, Z
creSymKey, creHmacKeyG, E, Z
TPM2_MakeCredential (I/E/D)Allows the TPM to perform the actions required of a Certificate AuthoritySHS, SHA3, HMAC, AES, KBKDF, KTS-RSA, KAS, CKGobjPubCOEApproved
creSeedG, R, E, Z
creSymKey, creHmacKeyG, E, Z
TPM2_Unseal (I/E/D)Returns the data in a loaded Sealed Data ObjectNoneobjSensCORApproved
TPM2_ObjectChangeAuth (I/E/D)Changes the authorization secret for a TPM-resident objectSHS, SHA3, HMAC, AES, KBKDF, CKGdrbgState, objAuthCOWApproved
objSeedR, E
objSymKey, objHmacKeyE
objSensR
TPM2_CreateLoaded (I/E/D)Creates an object and loads it in the TPMSHS, SHA3, HMAC, AES, DRBG, KBKDF, CKG, RSA (signature generation, verification, key generation), ECC (signature generation, verification, key generation)objPubCOR, EApproved
nullSeed, ppSeed, epSeed, spSeed, nullProof, phProof, ehProof, shProof, ekRsa, ekEcc, shProofForReseedE
objSeed, objSymKey, objHmacKey, tdrbgStateG, E

FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 15
objSensG, R, E
drbgStateW, E
TPM2_Duplicate (I/E/D)Duplicates a loaded object so that it may be used in a different hierarchySHS, SHA3, HMAC, AES, DRBG, KBKDF, KTS-RSA, KAS, CKGdupSeed, dupInSymKey, dupOutSymKey, dupOutHmacKeyCOG, E, ZApproved
objSens, objAuthR
drbgStateW, E
objPubE
TPM2_Rewrap (I/E/D)Rewraps a duplicated object with a new parent keySHS, SHA3, HMAC, AES, KBKDF, KTS-RSA, KAS, CKGobjSensCOW, EApproved
dupOutSymKey, dupOutHmacKeyG, E, Z
dupInpSymKeyW, Z
drbgState, objPubE
dupSeedW, E, Z
TPM2_Import (I/E/D)Allows an object to be encrypted using the symmetric encryption values of a Storage KeySHS, SHA3, HMAC, AES, KBKDF, KTS-RSA, KAS, CKGdrbgStateCOEApproved
objSens, objPubW, E
objAuthW
dupSeed, dupInSymKeyE, Z
dupOutSymKey, dupOutHmacKeyW, E, Z
TPM2_RSA_Encrypt (I/E/D)Performs RSA encryptionKTS-RSAobjPubCOEApproved
TPM2_RSA_Decrypt (I/E/D)Performs RSA decryptionKTS-RSAobjSensCOEApproved
TPM2_ECDH_KeyGen (I/E/D)Shared secret value computation using KASKASdrbgStateCOW, EApproved
ephSensEccKeyG, E, Z
ephPubEccKeyG, R, Z
objPubE
TPM2_ECDH_ZGen (I/E/D)Shared secret value recovery using KASKASobjSensCOEApproved
ephPubEccKeyW, E, Z

FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 16
TPM2_ECC_Parameters (I)Returns the parameters of an ECC curve identified by its TCG-assigned curveIDNoneNoneCON/ANon-security relevant
TPM2_EncryptDecrypt (I/E)Symmetric encryption or decryptionAESobjSensCOEApproved
TPM2_EncryptDecrypt2 (I/E/D)Symmetric encryption or decryptionAESobjSensCOEApproved
TPM2_Hash (I/E/D)Performs a hash operation on dataSHS, SHA3nullProof, phProof, ehProof, shProofCOEApproved
TPM2_HMAC (I/E/D)Performs a HMAC operation on dataHMACobjSensCOEApproved
TPM2_GetRandom (I/E)Outputs random bytes from a DRBGDRBGdrbgStateCOW, EApproved
TPM2_StirRandom (I/D)Reseed the state of a DRBGENT(P), DRBGdrbgSeedCOW, E, ZApproved
drbgStateW, E
TPM2_HMAC_Start (I/D)Starts an HMAC sequenceHMACseqAuthCOWApproved
objSensE
TPM2_HashSequenceStart (I/D)Starts a hash or an event sequenceSHS, SHA3seqAuthCOWApproved
TPM2_SequenceUpdate (I/D)Adds data to a hash or HMAC sequenceSHS, SHA3, HMACobjSensCOEApproved
TPM2_SequenceComplete (I/E/D)Adds last part of data to a hash or HMAC sequence and returns the resultSHS, SHA3, HMACnullProof, phProof, ehProof, shProof, objSensCOEApproved
seqAuthZ
TPM2_EventSequenceComplete (I/D)Adds last part of data to a hash or HMAC sequence and returns the result in a digest listSHS, SHA3, HMACobjSensCOEApproved
seqAuthZ
TPM2_Certify (I/E/D)Proves that an object with a specific Name is loaded in the TPMSHS, SHA3, HMAC, DRBG, KBKDF, CKG, RSA (signature generation), ECC (signature generation)drbgStateCOW, EApproved
objSens, shProofE
TPM2_CertifyCreation (I/E/D)Proves the association between an object and its creation dataSHS, SHA3, HMAC, DRBG, KBKDF, CKG, RSA (signature generation), ECC (signature generation)drbgStateCOW, EApproved
objSens, nullProof, phProof, ehProof, shProofE
TPM2_Quote (I/E/D)Quotes PCR valuesSHS, SHA3, HMAC,drbgStateCOW, EApproved

FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 17
DRBG, KBKDF, CKG, RSA (signature generation), ECC (signature generation)objSens, shProofE
TPM2_GetSessionAuditDigest (I/E/D)Returns a digital signature of the audit session digestSHS, SHA3, HMAC, DRBG, KBKDF, CKG, RSA (signature generation), ECC (signature generation)drbgStateCOW, EApproved
objSens, shProofE
TPM2_GetCommandAuditDigest (I/E/D)Returns the current value of the command audit digest, a digest of the commands being audited, and the audit hash algorithmSHS, SHA3, HMAC, DRBG, KBKDF, CKG, RSA (signature generation), ECC (signature generation)drbgStateCOW, EApproved
objSens, shProofE
TPM2_GetTime (I/E/D)Returns the current values of Time and ClockSHS, SHA3, HMAC, DRBG, KBKDF, CKG, RSA (signature generation), ECC (signature generation)drbgStateCOW, EApproved
objSens, shProofE
TPM2_CertifyX509 (I/E/D)X.509 certificate generationSHS, SHA3, RSA (signature generation), ECC (signature generationdrbgStateCOW, EApproved
objSensE
TPM2_VerifySignature (I/D)Validates a signature on a message with the message digest passed to the TPMHMAC, RSA (signature generation), ECC (signature generation)objPub, nullProof, phProof, ehProof, shProofCOEApproved
TPM2_Sign (I/D)Signs an externally provided hash with the specified symmetric or asymmetric signing keySHS, SHA3, HMAC, DRBG, RSA (signature generation), ECC (signature generation)objSens, nullProof, phProof, ehProof, shProofCOEApproved
TPM2_SetCommandCodeAuditStatus (I)Changes the audit status of a command or to set the hash algorithm used for the audit digestNoneNoneCON/ANon-security relevant
TPM2_PCR_Extend (I)Updates the indicated PCRSHS, SHA3NoneCON/AApproved
TPM2_PCR_Event (I/D)Updates the indicated PCR and reports list of digestsSHS, SHA3NoneCON/AApproved
TPM2_PCR_Read (I)Returns the values of all PCR specified in pcrSelectionInNoneNoneCON/ANon-security relevant

FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 18
TPM2_PCR_Allocate (I)Sets the desired PCR allocation of PCR and algorithmsNoneNoneCON/ANon-security relevant
TPM2_PCR_Reset (I)Sets the PCR in all banks to zeroNoneNoneCON/ANon-security relevant
_TPM_Hash_StartIndicates to the TPM interface the start of an H-CRTM measurement sequenceSHS, SHA3NoneCON/AApproved
_TPM_Hash_DataIndicates to the TPM interface data to be included in the H-CRTM measurement sequenceSHS, SHA3NoneCON/AApproved
_TPM_Hash_EndIndicates to the TPM interface the end of the H-CRTM measurement sequenceSHS, SHA3NoneCON/AApproved
TPM2_PolicySigned (I/E/D)Includes a signed authorization in a policySHS, SHA3, HMAC, RSA (signature verification), ECC (signature verification)objPub, nullProof, phProof, ehProof, shProofCOEApproved
TPM2_PolicySecret (I/E/D)Includes a secret-based authorization to a policySHS, SHA3, HMACnullProof, phProof, ehProof, shProofCOEApproved
TPM2_PolicyTicket (I/D)Includes a ticket in a policySHS, SHA3, HMACnullProof, phProof, ehProof, shProofCOEApproved
TPM2_PolicyOR (I)Allows options in authorizations without requiring that the TPM evaluate all the optionsSHS, SHA3NoneCON/AApproved
TPM2_PolicyPCR (I/D)Causes conditional gating of a policy based on PCRSHS, SHA3NoneCON/AApproved
TPM2_PolicyLocality (I)Indicates that the policy will be limited to a specific localitySHS, SHA3NoneCON/AApproved
TPM2_PolicyNV (I/D)Causes conditional gating of a policy based on the contents of an NV IndexSHS, SHA3NoneCON/AApproved
TPM2_PolicyCounterTimer (I/D)Causes conditional gating of a policy based on the contents of the TPMS_TIME_INFO structureSHS, SHA3NoneCON/AApproved
TPM2_PolicyCommandCode (I)Limits policy to a specific command codeSHS, SHA3NoneCON/AApproved

FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 19
TPM2_PolicyPhysicalPresence (I)Physical presence will need to be asserted at the time the authorization is performedSHS, SHA3NoneCON/AApproved
TPM2_PolicyCpHash (I/D)Allows a policy to be bound to a specific command and command parametersSHS, SHA3NoneCON/AApproved
TPM2_PolicyNameHash (I/D)Allows a policy to be bound to a specific set of TPM entities without being bound to the parameters of the commandSHS, SHA3NoneCON/AApproved
TPM2_PolicyDuplicationSelect (I/D)Allows qualification of duplication to allow duplication to a selected new parentSHS, SHA3NoneCON/AApproved
TPM2_PolicyAuthorize (I/D)Let a policy authority sign a new policy so that it may be used in an existing policySHS, SHA3, HMACnullProof, phProof, ehProof, shProofCOEApproved
TPM2_PolicyAuthValue (I)Allows a policy to be bound to the authorization value of the authorized entitySHS, SHA3NoneCON/AApproved
TPM2_PolicyPassword (I)Allows a policy to be bound to the authorization value of the authorized objectSHS, SHA3NoneCON/AApproved
TPM2_PolicyGetDigest (I/E)Returns the current policyDigest of a policy sessionNoneNoneCON/ANon-security relevant
TPM2_PolicyNvWritten (I)Allows a policy to be bound to the TPMA_NV_WRITTEN attributesSHS, SHA3NoneCON/AApproved
TPM2_PolicyTemplate (I/D)Allows a policy to be bound to a specific creation templateSHS, SHA3NoneCON/AApproved
TPM2_PolicyAuthorizeNV (I)Provides a capability that is the equivalent of a revocable policySHS, SHA3NoneCON/AApproved
TPM2_CreatePrimary (I/E/D)Creates a Primary Object under one of the Primary Seeds or a Temporary Object under TPM_RH_NULLSHS, SHA3, HMAC, AES, DRBG, KBKDF, CKG, RSA (signature generation, verification, key generation), ECC (signature generation, verification, key generation)objPubCOR, EApproved
nullSeed, ppSeed, epSeed, spSeed, nullProof, phProof, ehProof, shProof, ekRsa, ekEcc, shProofForReseedE
objSeed, objSymKey, objHmacKey, tdrbgStateG, E

FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 20
objSensG, R, E
drbgStateW, E
TPM2_HierarchyControl (I)Enables and disables use of a hierarchy and its associated NV storageNoneNoneCON/ANon-security relevant
TPM2_SetPrimaryPolicy (I/D)Sets the authorization policy for a hierarchyNoneNoneCON/ANon-security relevant
TPM2_ChangePPS (I)Replaces the current platform primary seed (PPS) with a value from the DRBG and sets platformPolicy to the default initialization valueNonedrbgStateCOW, EApproved
ppSeed, phProof, objSeed, objSens, objPubZ
TPM2_ChangeEPS (I)Replaces the current endorsement primary seed (EPS) with a value from the DRBG and sets endorsementPolicy to the default initialization valueNonedrbgStateCOW, EApproved
epSeed, ehProof, objSeed, objSens, objPub, ekRsa, ekEccZ
TPM2_Clear (I)Removes all TPM context associated with a specific OwnerNonedrbgStateCOW, EApproved
spSeed, ehProof, shProof, shProofForReseed, objSeed, objSens, objPub, objAuthZ
TPM2_ClearControl (I)Disables and enables the execution of TPM2_Clear()NoneNoneCON/ANon-security relevant
TPM2_HierarchyChangeAuth (I/D)Changes the authValue of hierarchiesNoneNoneCON/ANon-security relevant
TPM2_DictionaryAttackLockReset (I)Cancels the effect of a TPM lockout due to several successive authorization failuresNoneNoneCON/ANon-security relevant
TPM2_DictionaryAttackParameters (I)Changes the lockout parametersNoneNoneCON/ANon-security relevant
TPM2_VendorCmdFieldUpgradeStart (I)Initiates a field upgrade sessionSHS, SHA3, KBKDF, CKG, ECC (signature verification)fuSigKeyCOEApproved
TPM2_VendorCmdFieldUpgradeData (I)Conveys firmware in a field upgrade sessionSHSNoneCON/AApproved
TPM2_ContextSaveKBKDF, HMAC, AES, CKGcontextEncKeyCOG, E, ZApproved

FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 21
Saves a session context, object context, or sequence object context outside the TPMobjSeed, objSens, objPub, objAuth nullProof, phProof, ehProof, shProof, contextEncKey, contextKeyR E
TPM2_ContextLoadReloads a context that has been saved by TPM2_ContextSave()KBKDF, HMAC, AES, CKGcontextEncKeyCOG, E, ZApproved
objSeed, objSens, objPub, objAuthR
nullProof, phProof, ehProof, shProof, contextEncKey, contextKeyE
TPM2_FlushContextCauses all context associated with a loaded object, sequence object, or session to be removed from TPM memoryNoneobjSeed, objSens, objPub, sesHmacKey, sesSymKeyCOZApproved
TPM2_EvictControl (I)Allows certain Transient Objects to be made persistent or a persistent object to be evictedNoneobjSeed, objSens, objPub, objAuthCOR, W, ZApproved
sesHmacKey, sesSymKeyR, W
TPM2_ReadClock (I)Reads the current TPMS_TIME_INFO structureNoneNoneCON/ANon-security relevant
TPM2_ClockSet (I)Advances the value of the TPM’s clockNoneNoneCON/ANon-security relevant
TPM2_ClockRateAdjust (I)Adjusts the rate of advance of Clock and TimeNoneNoneCON/ANon-security relevant
TPM2_GetCapability (I)Returns various information regarding the TPM and its current stateNoneNoneCON/ANon-security relevant
TPM2_TestParms (I)Checks if specific combinations of algorithm parameters are supportedNoneNoneCON/ANon-security relevant
TPM2_NV_DefineSpace (I/D)Defines the attributes of an NV Index and causes the TPM to reserve space to hold the data associated with the NV IndexNonenvAuthCOWApproved
TPM2_NV_UndefineSpace (I)Removes an Index from the TPMNonenvAuthCOZApproved

FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 22
TPM2_NV_UndefineSpaceSpecial (I)Removal of a platform-created NV Index that has TPMA_NV_POLICY_DELETE SETNonenvAuthCOZApproved
TPM2_NV_ReadPublic (I/E)Reads the public area and Name of an NV IndexSHS, SHA3NoneCON/AApproved
TPM2_NV_Write (I/D)Writes a value to an area in NV memory that was previously defined by TPM2_NV_DefineSpace()NoneNoneCON/ANon-security relevant
TPM2_NV_Increment (I)Increments the value in an NV Index that has the TPM_NT_COUNTER attributeNoneNoneCON/ANon-security relevant
TPM2_NV_Extend (I/D)Extends a value to an area in NV memory that was previously defined by TPM2_NV_DefineSpace()SHS, SHA3NoneCON/AApproved
TPM2_NV_SetBits (I)Sets bits in an NV Index that was created as a bit fieldNoneNoneCON/ANon-security relevant
TPM2_NV_WriteLock (I)Inhibits further writes of the NV Index if the TPMA_NV_WRITEDEFINE or TPMA_NV_WRITE_STCLEAR attributes of an NV location are SETNoneNoneCON/ANon-security relevant
TPM2_NV_GlobalWriteLock (I)Sets TPMA_NV_WRITELOCKED for all indexes that have their TPMA_NV_GLOBALLOCK attribute SETNoneNoneCON/ANon-security relevant
TPM2_NV_Read (I/E)Reads a value from an area in NV memory previously defined by TPM2_NV_DefineSpace()NoneNoneCON/ANon-security relevant
TPM2_NV_ReadLock (I)Prevents further reads of the NV Index until the next TPM2_Startup (TPM_SU_CLEAR) if TPMA_NV_READ_STCLEAR is SETNoneNoneCON/ANon-security relevant
TPM2_NV_ChangeAuth (I/D)Allows the authValue of an NV Index to be changedNonenvAuthCOWApproved
TPM2_NV_Certify (I/E/D)Certifies the contents of an NV Index or portion of an NV IndexSHS, SHA3, HMAC, ECC (signature generation), RSA (signature generation)objSensCOEApproved
TPM2_VendorCmdSetMode (I)Sets the low power modeNoneNoneCON/ANon-security relevant

FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 23
TPM2_VendorCmdSetCommandSet (I)Activates and locks commandsNoneNoneCON/ANon-security relevant
TPM2_VendorCmdSetCommandSetLock (I)Prevents locking commandsNoneNoneCON/ANon-security relevant
TPM2_VendorCmdGetRandom2 (I/E)Get random value from DRBGDRBGdrbgStateCOW, EApproved
TPM2_VendorCmdGPIOConfig (I)Configures GPIONoneNoneCON/ANon-security relevant
TPM2_VendorCmdGetRandom800_90B (I/E)Get random value from ENT (P)ENTNoneCON/AApproved
TPM2_VendorCmdChangeObjectDeletionAuth (I)Modifies deletion authorization for an objectNoneNoneCON/ANon-security relevant
TPM2_VendorCmdRestoreEK (I)Restore EK RSA or EK ECC in case of deletion by TPM2_ChangeEPSNoneekRsa, ekEccCOWApproved
TPM2_VendorCmdZeroizeEK (I)Zeroize EK RSA and EK ECCNoneekRsa, ekEccCOZApproved
TPM2_PP_CommandsDetermines which commands require assertion of Physical PresenceNoneNoneCON/ANon-security relevant
Integrity mechanism provided by sessions1This service is not callable from TPM interface but is only used internally by any command and response with an authorization area. It consists in computing the integrity of the received command or transmitted response.SHS, SHA3, DRBG, KBKDF, HMAC, CKGsesHmacKeyCOE, ZApproved
Encryption mechanism provided by sessions2This service is not callable from TPM interface but is only used internally by any command and response with an encryption or decryption session. It consists in decrypting the first parameter of a received command or encrypting the first parameter of a transmitted response.SHS, SHA3, DRBG, KBKDF, CKG, AES, XORsesSymKeyCOG, E, ZApproved

1 The internal security function is not directly callable from the security module external interfaces. Function is used (or might be used) by the services listed in this table. When a service

is usable with a session, (I) is added next to the service name. When a service can additionally use the encryption mechanism of a session, (I/E) is added next to the service name. FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 24
NameDescriptionAlgorithms AccessedRoleIndicator
TPM2_Create TPM2_CreateLoaded TPM2_Load TPM2_LoadExternalCreation or loading of an ECC key with a non-approved elliptic curve: • ECC key with curve BN P-256ECC BN P-256CONot approved
Creation or loading of an ECC signing key with an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL)-
Creation or loading of an RSA decryption key with an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL)-
Creation or loading of a 1024-bit RSA keyRSA
TPM2_CreateLoadedDerivation of an ECC key from a derivation parent keyKBKDF ECC derived keys
TPM2_Load TPM2_LoadExternalLoading of an ECC or RSA key (sensitive and public parts) in the NULL hierarchy-
TPM2_Duplicate TPM2_Rewrap TPM2_ImportKey transport with a 1024-bit RSA key Key agreement scheme with a non-approved ECC curve: • BN P-256RSA ECC BN P-256CONot approved
TPM2_RSA_Encrypt TPM2_RSA_DecryptKey transport with a non-approved scheme: • RSAES-PKCS1-v1_5 • RSA with no padding mode (null scheme) Key transport with an RSA decryption key: • Generated with an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL) • Loaded in the NULL hierarchyRSAES-PKCS1-v1_5 RSA with no padding scheme KTS-RSACONot approved
TPM2_ECDH_KeyGenUse of a non-approved elliptic curve: • ECC key with curve BN P-256ECC BN P-256
TPM2_ECDH_ZGenUse of an ECC key: • Generated on curve BN P-256 • Derived from a derivation parent key • Loaded in the NULL hierarchyECC BN P-256 KBKDF
TPM2_ZGen_2PhaseThis command is only usable jointly with TPM2_EC_Ephemeral service that is non approved as using key derivation to generate ECC keys-
TPM2_HMACHMAC generation with a key length < 112 bitsHMACCONot approved

FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 25
TPM2_HMAC_Start TPM2_SequenceUpdate TPM2_SequenceCompleteHMAC generation with a key length < 112 bitsHMACCONot approved
TPM2_Certify TPM2_CertifyCreation TPM2_Quote TPM2_GetSessionAuditDigest TPM2_GetCommandAuditDigest TPM2_GetTime TPM2_CertifyX509Digital signature with a non-approved signature scheme: • ECC signature with ECDAA signature scheme • ECC signature with ECSchnorr signature scheme • RSA signature with key length of 1024 bits • ECC or RSA signature key using SHA-1 as digest method • ECC signature with curve BN P-256ECDAA, ECSchnorr, RSA, SHA-1, ECC BN P-256CONot approved
Digital signature with an ECC signing key generated with an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL)ECDSA
Digital signature with an ECC signing derived from a derivation parent keyECDSA
Digital signature with an ECC or RSA key loaded in the NULL hierarchyRSA, ECDSA
TPM2_CommitGeneration of an ECC key through key derivation methodKBKDFCONot approved
TPM2_EC_EphemeralGeneration of an ECC key through key derivation methodKBKDF
TPM2_VerifySignatureDigital signature verification with a non-approved signature scheme or a non- approved curve: • ECDAA signature scheme • ECSchnorr signature scheme • ECC signature with curve BN P-256ECDAA, ECSchnorr, ECC BN P-256CONot approved
TPM2_SignDigital signature generation with a non-approved signature scheme: • ECC signature with ECDAA signature scheme • ECC signature with ECSchnorr signature scheme • RSA signature with key length of 1024 bits • ECC or RSA signature key using SHA-1 as digest method • ECC signature with curve BN P-256ECDAA, ECSchnorr, RSA, SHA-1, ECC BN P-256
Digital signature with an ECC signing key generated with an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL)ECDSA
Digital signature with an ECC signing derived from a derivation parent keyECDSA

FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 26
Digital signature with an ECC or RSA key loaded in the NULL hierarchyRSA, ECDSA
TPM2_PolicySignedDigital signature verification with a non-approved signature scheme or a non- approved curve: • ECDAA signature scheme • ECSchnorr signature scheme • ECC signature with curve BN P-256ECDAA, ECSchnorr, ECC BN P-256CONot approved
TPM2_CreatePrimaryCreation and loading of an ECC key with a non-approved elliptic curve: • ECC key with curve BN P-256ECC BN P-256CONot approved
Creation and loading of an ECC signing key with an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL)-
Creation and loading of an RSA decryption key with an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL)-
TPM2_NV_CertifyDigital signature with a non-approved signature scheme: • ECC signature with ECDAA signature scheme • ECC signature with ECSchnorr signature scheme • RSA signature with key length of 1024 bits • ECC or RSA signature key using SHA-1 as digest method • ECC signature with curve BN P-256ECDAA, ECSchnorr, ECC BN P-256 RSA, SHA-1CONot approved
Digital signature with an ECC signing key generated with an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL)ECDSA
Digital signature with an ECC signing derived from a derivation parent keyECDSA
Digital signature with an ECC or RSA key loaded in the NULL hierarchyRSA, ECDSA

Table 15 - Non-Approved Services FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 27
5 SOFTWARE/FIRMWARE SECURITY

A block diagram of the FW is provided in Figure 4. Core Memory Loader Sequencer Sequencer HWINTF HWINTF library TPM2.0 commands library TPM2.0 commands TPM2.0 core TPM2.0 core Memory Memory management and management and low-level services low-level services Cryptographic Cryptographic library library TPM instance #1 TPM instance #2 Figure 4 - FW block diagram FW integrity is verified by computing an EDC (CRC-16 ISO 13239) over the active FW and comparing it to a reference value. FW integrity is verified during boot sequence before execution of one of the code blocks (CML and TPM) and can be triggered on demand by the operator with the execution of the service TPM2_SelfTest (full parameter must be set to YES) or TPM2_IncrementalSelfTest. If failure is detected during boot sequence, TPM enters an infinite reset loop that can be exit only by a power-off/power-on sequence. If failure is detected during self-tests, the security module enters failure mode. FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 28
6 OPERATIONAL ENVIRONMENT

Module operational environment is “limited” because it allows loading authenticated firmware that meets all applicable requirements of [FIPS 140-3] standard. Loading of FW on the security module can be achieved by using two services:

Page 29
7 PHYSICAL SECURITY

The security module meets the Physical Security protection requirements for single-chip module at FIPS 140-3 Level 1. The module is production grade.

7.1 Zeroization

Zeroization, performed for physical security purposes by some services (refer to detailed services in Table 15), occurs in a sufficiently small time-period to prevent the recovery of the sensitive data between the time of detection and the actual zeroization. FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 30
8 NON-INVASIVE SECURITY

The security module does not claim support of non-invasive security attack mitigation techniques referenced in [NIST SP800-140F]. FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 31
NameDescriptionPersistence Type
Dynamic RAMVolatile memory used to store SSPs between two consecutive resets or power-on/power-off sequence of the security module. SSPs doesn’t persist after command execution.Dynamic
Static RAMVolatile memory used to store SSPs between two consecutive resets or power-on/power-off sequence of the security module. SSPs persist after command execution.Static
NVRAMNon-volatile memory (flash-based) used to store SSPs and make them persistent to a reset or a power-off/power-on sequence of the security moduleStatic
NameFromToFormat typeDistribution typeEntry typeSFI or Algorithm [O]
Input plaintext to NVRAMOutside of cryptographic boundaryNVRAMPlaintextManual or AutomatedElectronicNone
Input protected to NVRAMOutside of cryptographic boundaryNVRAMEncryptedManual or AutomatedElectronicKTS (AES cert + HMAC cert) (A2553 + A2551)
Input plaintext to RAMOutside of cryptographic boundaryStatic RAMPlaintextManual or AutomatedElectronicNone
Input protected to RAMOutside of cryptographic boundaryStatic RAMEncryptedManual or AutomatedElectronicKTS (AES cert + HMAC cert) (A2553 + A2551)
Output plaintext from NVRAMNVRAMOutside of cryptographic boundaryPlaintextManual or AutomatedElectronicNone
Output protected from NVRAMNVRAMOutside of cryptographic boundaryEncryptedManual or AutomatedElectronicKTS (AES cert + HMAC cert) (A2553 + A2551)
Output plaintext from RAMStatic RAMOutside of cryptographic boundaryPlaintextManual or AutomatedElectronicNone
Output protected from RAMStatic RAMOutside of cryptographic boundaryEncryptedManual or AutomatedElectronicKTS (AES cert + HMAC cert) (A2553 + A2551)
Input asym. encrypted to RAMOutside of cryptographic boundaryStatic RAMEncryptedManual or AutomatedElectronicKTS-RSA (A2554) KAS (A2555)
Output asym. encrypted to RAMStatic RAMOutside of cryptographic boundaryEncryptedManual or AutomatedElectronicKTS-RSA (A2554) KAS (A2555)
Input during manufacturingOutside of cryptographic boundaryNVRAMObfuscatedAutomatedElectronicNone
MethodDescriptionRationaleOperator Initiation Capability
ResetZeroization of all volatile SSPs-Activation of reset signal
TPM2_ClearZeroization of all contexts associated with an OwnerSSPs linked to an Owner must not persist if the Owner changesSend TPM2_Clear command
TPM2_StartupZeroization of platformAuthZeroize platformAuth before its first use after a resetSend TPM2_Startup command
TPM2_ChangePPSZeroize the platform primary seed and flush all transient and persistent objects in the Platform hierarchyPlatform hierarchy renewalSend TPM2_ChangePPS command
9SENSITIVE SECURITY PARAMETERS MANAGEMENT
9.1Storage Areas Next table lists the SSP storage methods. Table 16 - Storage Areas
9.2SSP Input-Output Methods Next table lists the SSP input and output methods. Table 17 - SSP Input-Output Methods
9.3SSP Zeroization Methods Next table lists the SSP zeroization methods.

FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 32
TPM2_ChangeEPSZeroize the endorsement primary seed and flush all transient and persistent objects in the Endorsement hierarchyEndorsement hierarchy renewalSend TPM2_ChangeEPS command
TPM2_EvictControlZeroize an object from NVRAMMethod required to zeroize a dedicated object in NVRAMSend TPM2_EvictControl command
TPM2_FlushContextZeroize an object from RAMMethod required to zeroize a dedicated object in RAMSend TPM2_FlushContext command
AutomaticZeroize SSPs at the end of a command processingMethod for limited life-cycle SSPsNo, zeroization is automatic.
TPM2_NV_UndefineSpace TPM2_NV_UndefineSpaceSpecialZeroize a NV indexMethod required to flush NV indices from NVRAMSend TPM2_NV_UndefineSpace command. Send TPM2_NV_UndefineSpaceSpecial command
TPM2_VendorCmdZeroizeEKZeroize the endorsement key provisionedMandatory zeroization method for EK SSPsSend TPM2_ZeroizeEK command
TPM2_SequenceComplete TPM2_EventSequenceCompleteZeroize a hash or HMAC sequenceMethod required to flush sequences from RAMSend TPM2_SequenceComplete command. Send TPM2_EventSequenceComplete command
Name1DescriptionSize (bits)StrengthTypeGenerated by2Established byInputs / OutputsStorageZeroizationUsed by3CategoryRelated SSPs
nullProofProof (secret value) of the null hierarchy512256Symmetric keyDRBGInternal-Obfuscated in Static RAMReset• KBKDF CTR to generate context encryption key and IV (cf. [TPM2.0 Part1] §30.3.1) • HMAC SHA2-384 to compute context blob integrity (cf. [TPM2.0 Part1] §30.3.2) • HMAC SHA2-384 to compute/verify ticketsCSPcontextEncKey is derived from nullProof / phProof / ehProof nullProof / phProof / ehProof are derived from drbgState
phProofProof (secret value) of the platform hierarchy512256Symmetric keyDRBGInternal-Obfuscated in NVRAMTPM2_ChangePPSCSP
ehProofProof (secret value) of the endorsement hierarchy512256Symmetric keyDRBGInternal-Obfuscated in NVRAMTPM2_ChangeEPSCSP
shProofProof (secret value) of the storage hierarchy512256Symmetric keyDRBGInternal-Obfuscated in NVRAMTPM2_Clear• KBKDF CTR to generate context encryption key and IV (cf. [TPM2.0 Part1] §30.3.1) • HMAC SHA2-384 to compute context blob integrity (cf. [TPM2.0 Part1] §30.3.2) • HMAC SHA2-384 to compute/verify tickets • KBKDF CTR to generate obfuscation value used in attestation commands (cf. [TPM2.0 Part1] §36.7)CSPcontextEncKey is derived from shProof shProof is derived from drbgState
shProofForReseedRandom value512256Entropy sourceENT (P)Internal-Obfuscated in NVRAMTPM2_ClearDRBG for reseed before generating objSeed PSP in the endorsement hierarchy (cf. [TPM2.0 Part1])CSPdrbgState is reseeded with shProofForReseed
platformAuthAuthentication value for the platform hierarchy512128 to 256 (depending on the underlying hash algorithm used)Authentication value / Symmetric keySet to 0 by default at each reset / -Internal / ExternalInput protected to RAM or Input plaintext to RAM (as parameter of TPM2_HierarchyChangeAuth)Obfuscated in Static RAMTPM2_Startup• HMAC SHS/SHA3 authorization in case of unsalted and unbound session • KBKDF CTR to generate session key used in HMAC authorization in case of bound sessionCSPsesHmacKey can be derived from platformAuth / endorsementAuth / ownerAuth / lockoutAuth

Table 18 - SSP Zeroization Methods Next tables list all the SSPs in the security module.

1 Temporary storage duration column was removed for readability purpose because when temporary storage is indicated, duration corresponds to the duration of a command execution.

2 The algorithms indicated in this column correspond to the certified algorithms listed in Table 5.

3 The algorithms indicated in this column correspond to the certified algorithms listed in Table 5.

FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 33
endorsementAuth ownerAuth lockoutAuthAuthentication value for the endorsement hierarchy Authentication value for the storage hierarchy Authentication value for the lockout hierarchy512 512 512Authentication value / Symmetric key Authentication value / Symmetric key Authentication value / Symmetric keySet to 0 by default / - Set to 0 by default / - Set to 0 by default / -Internal / External Internal / External Internal / ExternalObfuscated in NVRAM Obfuscated in NVRAM Obfuscated in NVRAMTPM2_Clear TPM2_ChangeEPS TPM2_Clear TPM2_Clear• HMAC SHA-2/SHA3 authorization in case of salted or bound session (key is concatenation of sessionKey and authValue) • KBKDF CTR to generate session key used in HMAC authorization in case of salted and bound session (key is concatenation of authValue and salt)CSP CSP CSPNew input platformAuth / endorsementAuth / ownerAuth / lockoutAuth values can be wrapped by sesSymKey and integrity protected by sesHmacKey
objSeedSeed value for object generation384128 to 256Data, Symmetric keyDRBG or KBKDFInternal-Obfuscated in Static RAM or NVRAMTPM2_Clear TPM2_ChangePPS TPM2_ChangeEPS• Data in SHS/SHA3 (all modes) computation to generate object’s unique value (HMAC and symmetric key creation) • Key in KBKDF CTR to generate a symmetric encryption key used in TPM2B_PRIVATE structure encryption/decryption. • Key in KBKDF CTR to generate HMAC key used in TPM2B_PRIVATE integrity protection generation or verificationCSPobjSymKey and objHmacKey are derived from objSeed objSeed can be derived from tdrbgState for primary objects, from drbgState for ordinary objects, from parents seed for derived objects
objAuthObject’s authorization value1 to 3841 to 256Authentication value / Symmetric keyUserExternalInput protected to RAM or Input plaintext to RAM on keys creation commands. Changed with command TPM2_ObjectChangeAuth.Obfuscated in Static RAM or NVRAMTPM2_Clear TPM2_ChangePPS TPM2_ChangeEPSHMAC SHS/SHA3 and/or KBKDF CTR keys or part of keys in session based on HMAC or password (usage is the same than for endorsementAuth, ownerAuth, platformAuth and lockoutAuth)CSPsesHmacKey and sesSymKey can be derived from objAuth objAuth can be protected by sesHmacKey and sesSymKey
objSymKeyEncryption key of object private part256256Symmetric keyKBKDFInternal-Obfuscated in Dynamic RAM or NVRAMAutomaticSymmetric encryption / decryption key with AES CFB128 of TPM2B_PRIVATE structureCSPobjSens is wrapped by objSymKey objSymKey can wrap platformAuth / endorsementAuth / ownerAuth / lockoutAuth / objAuth
objHmacKeyIntegrity key of object private part160, 256, 384128 to 256Symmetric keyKBKDFInternal-Obfuscated in Dynamic RAM or NVRAMAutomaticIntegrity protection generation or verification with HMAC SHS/SHA3 of TPM2B_PRIVATE structureCSPobjSens is integrity protected by objHmacKey objHmacKey can protect platformAuth / endorsementAuth / ownerAuth / lockoutAuth / objAuth
objSensObject private part2048, 3072, 4096 (RSA) 128, 192, 256 (AES) 256, 384 (ECC) 1 to 1024 (HMAC)1 to 256Symmetric or asymmetric private keyDRBG or KBKDF / -Internal / ExternalOutput protected from RAM Input protected to RAM Input plaintext to RAMObfuscated in Static RAM or NVRAMTPM2_Clear TPM2_ChangePPS TPM2_ChangeEPSDepending on object’s type, sensitive is used as private key for: • Symmetric encryption/decryption (AES all modes) • Obfuscation/De-obfuscation (XOR) • Asymmetric encryption/decryption (RSA all modes) • Signature generation (RSA, ECDSA, HMAC all modes) • Secret value exchange (KAS all modes) • Key for derivation of derived objects (KBKDF CTR) Key type and length are selected by user thanks to the keys creation commands.CSPobjSymKey wraps objSens objHmacKey can integrity protect objSens objSens can be generated from tdrbgState for primary objects, from drbgState for ordinary objects and derived from parents seed for derived objects
objPubObject public part2048, 3072, 4096 (RSA) 512,768 (ECC)112 to 192Asymmetric public keyECDSA key generation, RSA key generation / -Internal / ExternalOutput plaintext from RAM Input plaintext to RAMObfuscated in Static RAM or NVRAMTPM2_Clear TPM2_ChangePPS TPM2_ChangeEPS• Encrypt data or verify signature (RSA SHA-1, SHA2-256, SHA2- 384, RSASSA-PKCS-v1.5, RSASSA-PSS) • Secret key exchange (KAS ECC One pass DH) or signature verification (ECDSA SHA-1,PSPobjPub is computed from objSens

FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 34
SHA2-256, SHA2-384, SHA3- 256, SHA3-384)
nvAuthAuthorization of NV index1 to 3841 to 256Authentication value / Symmetric keyUserExternalInput protected to RAM Input plaintext to RAM Changed with command TPM2_NV_ChangeAuth.Obfuscated in NVRAMTPM2_NV_UndefineSpace TPM2_NV_UndefineSpaceSpecialHMAC SHS/SHA3 and/or KBKDF CTR keys or part of keys in session based on HMAC or password (usage is the same than for endorsementAuth, ownerAuth, platformAuth and lockoutAuth)CSPsesHmacKey can be derived from nvAuth New input nvAuth value can be wrapped by sesSymKey and integrity protected by sesHmacKey
sesSaltSalt for keys diversification160, 256, 384128 to 256Symmetric keyUserExternalInput protected to RAMObfuscated in Dynamic RAMAutomaticPart of KBKDF CTR key to generate the sesHmacKey CSP (cf. [TPM2.0 Part1CSPsesHmacKey is derived from sesSalt
sesHmacKeyHMAC session key160, 256, 384128 to 256Symmetric keyKBKDFInternal / ExternalInput protected to RAMObfuscated in Dynamic RAMAutomatic• HMAC SHS/SHA3 key used to generate and verify command authorization • Part of KBKDF CTR key used to generate encryption key and IV of encryption-based sessionCSPsesHmacKey can protect all inputs CSPs contextKey and contextEncKey keys can wrap sesHmacKey
sesSymKeyEncrypted session key128, 192, 256128 to 256Symmetric keyKBKDFInternal / ExternalInput protected to RAMObfuscated in Dynamic RAMAutomatic• Key and IV for symmetric encryption / decryption of first parameter of command / response if parameter structure is of type TPM2B_CSPsesSymKey is derived from sesHmacKey and platformAuth / endorsementAuth / ownerAuth / lockoutAuth / objAuth / seqAuth
contextKeyDerivation key for context protection128128Symmetric keyDRBGInternal-Obfuscated in RAMResetFirst part of key used in KBKDF CTR to generate a symmetric encryption key and IV used in context blob encryption / decryptionCSPcontextKey is generated from drbgState contextEncKey is derived from contextKey
contextEncKeyWrapping key for context protection256256Symmetric keyKBKDFInternal-Obfuscated in Dynamic RAMAutomaticAES CFB128 encryption / decryption of context blobCSPcontextEncKey is derived from contextKey and nullProof / phProof / ehProof / shProof
dupInSymKeyWrapping key for duplicated object128, 192, 256128 to 256Symmetric keyDRBGInternal / ExternalInput plaintext to RAM Input protected to RAM Output plaintext from RAM Output protected from RAMObfuscated in Dynamic RAMAutomaticAES CFB128 symmetric encryption / decryption key to protect TPM2B_PRIVATE output structureCSPdupInSymKey can be wrapped by sesSymKey and protected by sesHmacKey
dupSeedSeed for protection keys derivation160 to 384128 to 256Symmetric keyDRBG, KASInternal / ExternalInput asym. encrypted to RAM Output asym. encrypted from RAMObfuscated in Dynamic RAMAutomatic• KBKDF CTR to generate a symmetric encryption / decryption key for outer protection • KBKDF CTR to generate a HMAC key for outer integrity protectionCSPdupSeed is encrypted by objPub key (RSA or KAS)
dupOutSymKeyHMAC key for duplicated objects128, 192, 256128 to 256Symmetric keyKBKDFInternal-Obfuscated in RAMAutomaticAES CFB128 symmetric encryption / decryption key to protect TPM2B_PRIVATE output structureCSPdupOutSymKey is derived from dupSeed dupOutSymKey wraps objSens
dupOutHmacKeyEncryption key for duplicated objects160, 256, 384128 to 256Symmetric keyKBKDFInternal-Obfuscated in Dynamic RAMAutomaticHMAC SHS/SHA3 key for outer protection of TPM2B_PRIVATE output structureCSPdupOutHmacKey is derived from dupSeed dupOutHmacKey protects objSens
creSeedSeed for credential keys derivation160 to 384128 to 256Symmetric keyUserExternalInput asym. encrypted to RAMObfuscated in Dynamic RAMAutomatic• KBKDF CTR to generate a symmetric encryption / decryption key for outer protection • KBKDF CTR to generate a HMAC key for outer integrity protectionCSP
creSymKeyHMAC key for credentials128, 192, 256128 to 256Symmetric keyKBKDFInternal-Obfuscated in Dynamic RAMAutomaticAES CFB128 symmetric encryption / decryption key for outer protection of credentialBlobCSPcreSymKey is derived from creSeed
creHmacKeyEncryption key for credentials160, 256, 384128 to 256Symmetric keyKBKDFInternal-Obfuscated in Dynamic RAMAutomaticHMAC SHS/SHA3 integrity key for outer protection of credentialBlobCSPcreHmacKey is derived from creSeed
ephSensEccKeyECC ephemeral private key256, 384128 to 192ECC private keyDRBGInternal-Obfuscated in Dynamic RAMAutomaticPart of KAS ECC one pass DH serviceCSPephSensEccKey is derived from drbgState
ephPubEccKeyECC ephemeral public key512, 768128 to 192ECC public keyECDSA key generationInternal-Obfuscated in Dynamic RAMAutomaticPart of KAS ECC one pass DH servicePSPephSensEccKey is generated from ephSensEccKey

FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 35
ekRsaProvisioned RSA endorsement key2048112RSA private keyRSA key generationExternalInput during manufacturingObfuscated in NVRAMTPM2_ZeroizeEKKTS-RSA KTS-OAEP basicCSPekRsa is copied in objSens
ekEccProvisioned ECC endorsement key256, 384128 to 192ECC private keyECDSA key generationExternalInput during manufacturingObfuscated in NVRAMTPM2_ZeroizeEKKAS ECC one pass DH serviceCSPekEcc is copied in objSens
fuSigKeyField upgrade signature verification key384192ECC public keyECDSA key generationExternalInput during manufacturingObfuscated in NVRAM-ECDSA SHA2-384 signature verification on a FW upgrade start commandPSP-
seqAuthAuthorization value for hash or HMAC sequence1 to 3841 to 256Authentication value / Symmetric keyUserExternalInput plaintext to RAM Input protected to RAM on TPM2_HashSequenceStart or TPM2_HMAC_Start commandsObfuscated in NVRAMTPM2_SequenceComplete TPM2_EventSequenceCompleteHMAC SHS/SHA3 and/or KBKDF CTR keys or part of keys in session based on HMAC or password for TPM2_SequenceUpdate, TPM2_SequenceComplete or TPM2_EventSequenceComplete commands authorizationsCSPsesSymKey and sesHmacKey are derived from seqAuth
Name1DescriptionSize (bits)StrengthTypeGenerated by2Established byInputs / OutputsStorageZeroizationUsed by3CategoryRelated SSPs
nullSeedSeed of the null hierarchy512256SeedENT(P)Internal-Obfuscated in Static RAMResetDRBG HASH_based SHA2-256 to generate random used for sensitive part creation of primary keys (prime numbers for RSA and private key for ECC / KEYEDHASH / SYMCIPHER objects) and objSeed CSP creation for all types of primary keys.CSPtdrbgState is instantiated by nullSeed / phSeed / ehSeed / shSeed
phSeedSeed of the platform hierarchy512256SeedENT(P)Internal-Obfuscated in NVRAMTPM2_ChangePPSCSP
ehSeedSeed of the endorsement hierarchy512256SeedENT(P)Internal-Obfuscated in NVRAMTPM2_ChangeEPSCSP
shSeedSeed of the storage hierarchy512256SeedENT(P)Internal-Obfuscated in NVRAMTPM2_ClearCSP
drbgStateInternal state (V and C secret values) of the DRBG (based on SHA256)256256StateDRBGInternal-Obfuscated in Static RAMTPM2_ClearRandom numbers and seedsCSPdrbgState is seeded by drbgSeed
drbgSeedSeed value for the DRBG512256SeedENT(P)Internal-Obfuscated in Dynamic RAMAutomaticdrbgStateCSPdrbgSeed seeds drbgState
tdrbgStateInternal state (V and C secret values) of the transient DRBG (based on SHA256) used to generate prime numbers for primary RSA keys.256256StateDRBGInternal-Obfuscated in Dynamic RAMAutomaticPrime numbers generation for primary RSA keysCSPtdrbgState is instantiated by nullSeed / phSeed / ehSeed / shSeed
AlgorithmUnderlying algorithmKey size (bits)Security strength (bits)
KBKDFSHA-1size ≥ 128128
size < 128Key size
SHA2-256size ≥ 192192
size < 192Key size
SHA2-384size ≥ 256256
size < 256Key size
HMACSHA-1size ≥ 128128
size < 128Key size
SHA2-256size ≥ 192192

Table 19 - SSPs (list of keys) Table 20 - SSPs (not used as keys)

1 Temporary storage duration column was removed for readability purpose because when temporary storage is indicated, duration corresponds to the duration of a command execution.

2 The algorithms indicated in this column correspond to the certified algorithms listed in Table 5.

3 The algorithms indicated in this column correspond to the certified algorithms listed in Table 5.

FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 36
size < 192Key size
SHA2-384size ≥ 256256
size < 256Key size
DRBGSHA2-256-256
AES-128128
-192192
-256256
RSA-2048112
-3072128
-4096142
ECC-256128
-384192

Table 21 - Security strength of a key depending on the underlying algorithm used and its size FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 37
Entropy SourceMinimum number of bits of entropyDetails
ENT (P)Min-entropy of 0.814324 per 1- bit sampleThis ENT (P) has been evaluated according to the non-IID evaluation path of the [SP800-90B] standard. It is used to generate random numbers not dedicated to being used as cryptographic material or to seed or reseed the Hash- DRBG (indicated as drbgSeed in Table 20.) listed above with a minimum of 414 bits of entropy.
9.5 List of RBGs

The security module implements:

Page 38
AlgorithmImplementationTest propertiesTest MethodTypeIndicatorDetails
Firmware integrityFirmware integrityNACRC-16EDCIntegrity TestProcessing of TPM2_Startup command indicates tests have been runFW integrity is verified by computing an EDC (CRC-16 ISO 13239) and comparing it to reference values.
HW integrityHW integrityNAHW registers verificationCritical FunctionHW integrity is guaranteed via check of HW sensors. If failure is detected during boot sequence, status is set to FAIL, and error is returned.
ENT(P)ENT(P)NARCT and APTSP 800- 90B Health- TestsCritical FunctionTPM performs AIS31 and SP800-90B (RCT and APT) start-up health tests on ENT(P) output sequence. If test fails, test status is set to FAIL, and an error is returned.
AlgorithmImplementationTest propertiesTest MethodTypeIndicator1DetailsCondition
Firmware integrityNACRC-16EDCIntegrity TestBit #1 clearFW integrity is verified by computing an EDC (CRC-16 ISO 13239) and comparing it to reference values.TPM2_SelfTest (full = YES)
HW integrityNANAFlags verificationCritical FunctionHW integrity is guaranteed via check of HW sensors. If failure is detected during boot sequence, status is set to FAIL, and error is returned.
10 SELF-TESTS

Self-tests run by the cryptographic module are split into two categories:

10.1 Self-tests error states

In case of self-test failure, the security module outputs the return code TPM_RC_FAILURE as defined in [TPM2.0 Part2] via the status interface and the module enters the failure state. In failure state, the module does not perform any cryptographic functions and all data output via the data output interface are inhibited. The only usable services in failure state are TPM2_GetTestResult and TPM2_GetCapability to get a status on the functionality whose selftest failed. Failure can be exit by resetting the security module. If pre-operational self-tests passed successfully, no success status is indicated but commands that require self-tests to be completed can be successfully executed.

10.2 Pre-operational tests

The module performs the following pre-operational self-tests: Table 23 - Pre-Operational Self-Tests

10.3 Conditional self-tests

The Module performs the following conditional self-tests:

1 Bit index indicated corresponds to the index in the algo_status field in the TPM2_GetTestResult

response FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 39
ENT(P)NARCT and APTSP 800- 90B Health- TestsCritical FunctionAIS31 and SP800-90B (RCT and APT) start-up health tests on ENT(P) output sequence. If test fails, test status is set to FAIL, and error is returned.
Hash-DRBGNASeed (64 bytes)KATCASTInstantiate then Reseed are seeded with a known seed value. Random is then generated with Generate API to output a 32-bytes value compared to a reference value (single test sequence done in accordance with §11.3 of [SP800-90A]).
SHA1Certs #A2548 and #A2549 implementationsKnown data (16 bytes)Bit #1 clearHash of known data and comparison of output to an expected digest (20 bytes).
SHA256Bit #2 clearHash of known data and comparison of output to an expected digest (32 bytes).
SHA384Bit #3 clearHash of known data and comparison of output to an expected digest (48 bytes).
SHA3_256NABit #4 clearHash of known data and comparison of output to an expected digest (32 bytes).
HMAC SHA1Certs #A2551 and #A2552 implementationsknown data (16 bytes) known key (16 bytesBit #5 clearHMAC on known data and known key. Comparison of output to an expected MAC value (20 bytes).TPM2_SelfTest (full = YES) or TPM2_SelfTest (full = NO) or TPM2_Increme ntalSelfTest or Execution of command requiring algorithm or Automatic execution
KDF SP800- 108NAknown data (16 bytes) known label (“TEST”)Bit #6 clearKDF on known data and known label. Comparison of output to an expected derivation value (32 bytes).
AESNAknown data (32 bytes) known key (16 bytes) known IV (16 bytes).known data (32 bytes) known key (16 bytes) known IV (16 bytes).Bit #7 clearAES CBC 128 encryption of known data compared to a reference value. AES CBC 128 decryption of encrypted data and comparison to the initial plaintext data.
KASNAknown private key d (32 bytes) known point P (2*32 bytes) NIST P-256 curveBit #8 clearPrimitive “Z” Computation and key derivation are implemented: a known private key d is used with a known point P of NIST P-256 curve to compute Q = dP. Key derivation of Q performed with SHA-1 underlying algorithm to output a key of 20 bytes that is compared to a refence value.
ECDSANAKnown key (256 bits) known data (20 bytes) fixed k (20 bytes) NIST P-256 curveBit #9 clearECDSA signature generation on known data with known key and k. Output of signature is compared to a reference signature. Signature verification performed on the generated signature.

FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 40
RSANAKnown key (2048 bits) known data (20 bytes) RSASSA- PKCS1-v1_5Bit #10 clearRSA signature generation on known data with a known key. Output of signature is compared to a reference signature. Signature verification performed on the generated signature (covers also KTS- RSA functionality).
FW loadNAECDSA NIST P-384) SHA384Firmware loadBit #1 clearVerification of chained digest and signature (ECDSA NIST P- 384) to ensure authentication of the FW
RSA key generationNAknown data (16 bytes)PCTKey creation failureDepending on the key purpose (signing or encrypting) indicated in sign attribute of the key, en/decryption or signing/verification is done on known data.RSA key generation
ECC key generationNAfixed k (20 bytes) NIST P-256 or NIST P-384PCTKey creation failureDepending on the key purpose (signing or key establishment) an ECDSA signature is generated (k fixed and the message varies) and verified with pairwise consistency test as defined by SP800-56Ar3.ECC key generation

Table 24 - Conditional Self-Tests Successful completion of self-tests can be verified through use of TPM2_GetTestResult command. The first 4 bytes of response indicate self-tests status. If they are equal to 0, selftests completed successfully. If not, the subsequent 4 bytes indicate the list of algorithms not fully self-tested. FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 41
11LIFE-CYCLE ASSURANCE
11.1Module installation During installation of the module: • Connection of the module with its environment must be done accordingly to the pinout description given at §3.1.
11.2Module initialization No initialization procedures are required.
11.3Module operation
11.3.1Approved modes of operation TPM is operated in an approved mode of operation as long as no non-approved service using a non-approved algorithm (listed resp. in Table 15 and Table 14), is used. No specific rules of operation are required to operate this module at FIPS 140-3 Level 1.
11.3.2Normal operation TPM is in normal operation mode when all pre-operational and conditional self-tests (apart from FW load and PCT tests) are complete. All approved and non-approved services are listed resp. in Table 14 and Table 15 with the corresponding indicator reporting if the service uses an approved cryptographic algorithm or security function.
11.3.3Error modes TPM may reach specific states depending on the sequence of operations that occurred.
11.3.3.1Shutdown mode The shutdown mode is an infinite HW reset loop that may be exit only by a power-off/power- on sequence. This state is entered when TPM detects a failure of the FW integrity verification during the TPM boot sequence. No output control or data is available in this mode.
11.3.3.2Failure state Failure state is a state of the TPM that restricts the executable commands to TPM2_GetCapability and TPM2_GetTestResult (status services). TPM answers to all other commands with the error code TPM_RC_FAILURE (0x101) and doesn’t process the requested service. This state is entered when a self-test fails (except FW integrity test during the boot sequence). This state can be exit with a reset of the TPM.
11.3.3.3Non-approved mode of operation The module enters a non-approved mode if one of the non-approved services listed in Table 15 is used by the operator. To check if the TPM is in a non-approved mode of operation, TPM2_GetCapability (capability = TPM_CAP_VENDOR_PROPERTIES) with the sub- capability TPM_SUBCAP_VENDOR_TPMA_MODES = 0x7 shall be used. It outputs a 2-bit indicator equals to 0x2 or 0x3 if the module is in a non-approved mode of operation.
11.4Module termination End-of-life of the product requires the following zeroization commands to be executed: • TPM2_Clear • TPM2_ChangeEPS • TPM2_ChangePPS

FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 42
12 MITIGATIONS OF OTHER ATTACKS

The security module does not claim mitigation of other attacks. FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 43
Reference TPM2.0 standardDocument
[TPM2.0 Part1]TPM2.0 Main, Part 1, Architecture, rev 1.59, TCG
[TPM2.0 Part2]TPM2.0 Main, Part 2, Structures, rev 1.59, TCG
[TPM2.0 Part3]TPM2.0 Main, Part 3, Commands, rev 1.59, TCG
[TPM2.0 Part4]TPM2.0 Main, Part 4, Supporting routines, rev 1.59, TCG
[TPM2.0 PTP]TCG PC Client Platform TPM Profile (PTP) Specification, rev. 1.05
[TPM2.0 FIPS 140-3]FIPS 140-3 standardTCG FIPS 140-3 Guidance for TPM2.0, v1.0, TCG
[ISO/IEC 19790]Information technology — Security techniques — Security requirements for cryptographic modules, ISO/IEC 19790:2012I
[ISO/IEC 24759]Information technology — Security techniques — Test requirements for cryptographic modules, ISO/IEC 24759:2017I
[FIPS 140-3]FIPS PUB 140-3, Security Requirements for Cryptographic Modules, National Institute of Standards and Technology (NIST), March 22, 2019
[NIST SP800-140]NIST Special Publication 800-140, FIPS 140-3 Derived Test Requirements (DTR), CMVP Validation Authority Updates to ISO/IEC 24759, March 2020
[NIST SP800-140A]NIST Special Publication 800-140A, CMVP Documentation Requirements, CMVP Validation Authority Updates to ISO/IEC 24759, March 2020
[NIST SP800-140B]NIST Special Publication 800-140B, CMVP Security Policy Requirements, CMVP Validation Authority Updates to ISO/IEC 24759 and ISO/IEC 19790 Annex B, March 2020
[NIST SP800-140C]NIST Special Publication 800-140Cr1, CMVP Approved Security Functions, CMVP Validation Authority Updates to ISO/IEC 24759, May 2022
[NIST SP800-140D]NIST Special Publication 800-140Dr1, CMVP Approved Sensitive Security Parameter Generation and Establishment Methods, CMVP Validation Authority Updates to ISO/IEC 24759, May 2022
[NIST SP800-140E]NIST Special Publication 800-140E, CMVP Approved Authentication Mechanisms, CMVP Validation Authority Requirements for ISO/IEC 19790:2012 Annex E and ISO/IEC 24759 Section 6.17, March 2020
[NIST SP800-140F]NIST Special Publication 800-140F, CMVP Approved Non-Invasive Attack Mitigation Test Metrics, CMVP Validation Authority Updates to ISO/IEC 24759, March 2020
13 REFERENCES
Page 44
ReferenceDocument
[FIPS 140-3 IG]NIST approved security functionsNational Institute of Standards and Technology and Canadian Centre for Cyber Security, Implementation Guidance for FIPS 140-3 and the Cryptographic Module Validation Program
[SP800-131Ar2]National Institute of Standards and Technology, Transitions: Recommendation for Transitioning the Use of Cryptographic Algorithms and Key Lengths, March 2019.
[FIPS 197]National Institute of Standards and Technology, Advanced Encryption Standard (AES), Federal Information Processing Standards Publication 197, November 2001
[SP800-38A]National Institute of Standards and Technology, Recommendation for Block Cipher Modes of Operation: Methods and Techniques, December 2001.
[SP800-38F]National Institute of Standards and Technology, Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping, December 2012.
[FIPS 186-4]National Institute of Standards and Technology, Digital Signature Standard (DSS), Federal Information Processing Standards Publication 186-4, July 2013
[FIPS 180-4]National Institute of Standards and Technology, Secure Hash Standard, Federal Information Processing Standards Publication 180-4, August 2015
[FIPS 202]National Institute of Standards and Technology, SHA3 Standard: Permutation-Based Hash and Extendable-Output Functions, August 2015
[FIPS 198-1]National Institute of Standards and Technology, The Keyed-Hash Message Authentication Code, NIST Computer Security Division Page 3 07/26/2011, (HMAC), Federal Information Processing Standards Publication 198-1, July, 2008
[SP800-135]National Institute of Standards and Technology, Recommendation for Existing Application-Specific Key Derivation Functions, December 2011.
[SP800-108]National Institute of Standards and Technology, Recommendation for Key Derivation Using Pseudorandom Functions, October 2009.
[SP800-90A]National Institute of Standards and Technology, Recommendation for Random Number Generation Using Deterministic Random Bit Generators, June 2015.
[SP800-56A] Rev 3National Institute of Standards and Technology, Recommendation for Pair- Wise Key Establishment Schemes Using Discrete Logarithm Cryptography, April 2018.
[SP800-56B] Rev 2National Institute of Standards and Technology, Recommendation for Pair- Wise Key-Establishment Using Integer Factorization Cryptography, March 2019
[SP800-56C] Rev 1National Institute of Standards and Technology, Recommendation for Key- Derivation Methods in Key-Establishment Schemes, April 2018
[SP800-133] Rev 2National Institute of Standards and Technology, Recommendation for Cryptographic Key Generation, June 2020

FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 45
TermDefinition
AESAdvanced Encryption Standard
COCrypto Officer
DESData Encryption Standard
DSAPDelegate Specific Authorization Protocol
EKEndorsement Key
FIPSFederal Information Processing Standard
FUMField Upgrade Mode
GPIOGeneral Purpose I/O
HMACKeyed-Hashing for Message Authentication
HWHardware
KDFKey derivation function
NISTNational Institute of Standards and Technology
NVNon-volatile (memory)
OIAPObject-Independent Authorization Protocol
OSAPObject Specific Authorization Protocol
PCRPlatform Configuration Register
RSARivest Shamir Adelman
RTMRoot of Trust for Measurement
RTRRoot of Trust for Reporting
SHASecure Hash Algorithm
SPISerial Peripheral Interface
SRKStorage Root Key
TCGTrusted Computed Group
TPMTrusted Platform Module
TSSTPM Software Stack
14 ACRONYMS

FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT

Page 46

IMPORTANT NOTICE – PLEASE READ CAREFULLY STMicroelectronics NV and its subsidiaries (“ST”) reserve the right to make changes, corrections, enhancements, modifications, and improvements to ST products and/or to this document at any time without notice. Purchasers should obtain the latest relevant information on ST products before placing orders. ST products are sold pursuant to ST’s terms and conditions of sale in place at the time of order acknowledgement. Purchasers are solely responsible for the choice, selection, and use of ST products and ST assumes no liability for application assistance or the design of Purchasers’ products. No license, express or implied, to any intellectual property right is granted by ST herein. Resale of ST products with provisions different from the information set forth herein shall void any warranty granted by ST for such product. ST and the ST logo are trademarks of ST. All other product or service names are the property of their respective owners. Information in this document supersedes and replaces information previously supplied in any prior versions of this document. This document may be reproduced only in its original entirety without revision. www.st.com FIPS140-3 SECURITY POLICY NON-PROPRIETARY DOCUMENT