All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Trusted Platform Module ST33KTPM2A / ST33KTPM2I

Certificate#5103StandardFIPS 140-3Level2TypeHardwareEmbodimentSingle ChipStatusActiveVendorSTMicroelectronics
Medium review priority  ·  exposes HSM/SE firmware trust anchor  ·  last validated 7 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level2
Module typeHardware
EmbodimentSingle Chip
StatusActive
Sunset date12/7/2030
CaveatWhen installed, initialized and configured as specified in Section 11 of the Security Policy; When operated in approved mode
VendorSTMicroelectronics

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Trusted Platform Module ST33KTPM2A / ST33KTPM2I
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>recovery<br/>upgrade<br/>update</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Status output</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C6 clue;
  class I2,I3,I6 infer;
  class R2,R3,R6 risk;
  class E2,E3,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Trusted Platform Module ST33KTPM2A / ST33KTPM2I
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>recovery<br/>upgrade<br/>update</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Status output</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C6 clueLow;

Security Policy, page by page

Page 1

STMicroelectronics Trusted Platform Module ST33KTPM2A / ST33KTPM2I Document Version: 04-02 Date: 2025-11-13 Public Material – May be reproduced only in its original entirety (without revision).

Page 2
Table of Contents
#SectionPage
Page 3

Public Material – May be reproduced only in its original entirety (without revision).

Page 4
List of Tables
ItemPage
Table 1: Security Levels6
Table 2: Tested Module Identification – Hardware9
Table 3: Modes List and Description11
Table 4: Approved Algorithms13
Table 5: Vendor-Affirmed Algorithms13
Table 6: Non-Approved, Allowed Algorithms14
Table 7: Non-Approved, Allowed Algorithms with No Security Claimed14
Table 8: Non-Approved, Not Allowed Algorithms15
Table 9: Security Function Implementations18
Table 10: Entropy Certificates18
Table 11: Entropy Sources19
Table 12: Ports and Interfaces20
Table 13 – UFQFPN32 / UFQFPN32 WF Pins Definition22
Table 14 – TSSOP20 Pins Definition23
Table 15 – WLCSP24 Pins Definition24
Table 16: Authentication Methods25
Table 17: Roles26
Table 18 – Mapping between services26
Table 19: Approved Services62
Table 20: Non-Approved Services67
Table 21: Mechanisms and Actions Required71
Table 22: EFP/EFT Information72
Table 23: Hardness Testing Temperatures73
Table 24: Storage Areas75
Table 25: SSP Input-Output Methods76
Table 26: SSP Zeroization Methods77
Table 27: SSP Table 179
Table 28: SSP Table 282
Table 29 – Security Strength of a Key Depending on the Underlying Algorithm Used and its Size83
Table 30: Pre-Operational Self-Tests84
Table 31: Conditional Self-Tests85
Table 32: Pre-Operational Periodic Information86
Table 33: Conditional Periodic Information87
Table 34: Error States87
Table 35 – List of policy commands to use in a policy session89
Table 36 – ZA9 Module Configuration89
Table 37 – AC5 Module Configuration90
Table 38 – ZB1 Module Configuration90
Table 39 – AD6 Module Configuration90
Table 40 – References95
Table 41 – Acronyms and Definitions96
Figure 1 – HW block diagram8
Page 5

Public Material – May be reproduced only in its original entirety (without revision).

Page 6
SectionTitleSecurity Level
1General2
2Cryptographic module specification2
3Cryptographic module interfaces2
4Roles, services, and authentication2
5Software/Firmware security2
6Operational environmentN/A
7Physical security3
8Non-invasive securityN/A
9Sensitive security parameter management2
10Self-tests2
11Life-cycle assurance2
12Mitigation of other attacksN/A
Overall Level2
1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy for the STMicroelectronics Trusted Platform Module ST33KTPM2A / ST33KTPM2I (ST33KTPM2A is also branded commercially “STSAFE-V100TPM”). It contains the security rules under which the Module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for an overall Security Level 2 module.

1.2 Security Levels

The FIPS 140-3 security levels for the Module are listed in table below: Table 1: Security Levels Public Material – May be reproduced only in its original entirety (without revision).

Page 7
2 Cryptographic Module Specification

The ST33KTPM2A / ST33KTPM2I module, hereafter denoted as the Module, is a fully integrated security module implementing the revision 1.59 of the Trusted Computing Group (TCG) specification for Trusted Platform Modules (TPM) version 2.0.

2.1 Description

Purpose and Use: The Module is intended for use by US Federal agencies or other markets that require FIPS 140-3 validated Level 2. The Module is designed to be integrated into personal computers or any other embedded electronic systems. TPM is primarily used for cryptographic keys generation, keys storage, keys management and secure storage for digital certificates. Module Type: Hardware Module Embodiment: SingleChip Module Characteristics: Cryptographic Boundary: The cryptographic boundary of the Module is defined as the perimeter of the IC package and both versions of the Module are represented in the next figure. The Module is composed of:

Page 8

Figure 1

Page 9
Model and/or Part NumberHardware VersionFirmware VersionProcessorsFeatures
ST33KTPM2AST33K1M5A revB10.512 (dec.) 0x00.0A.02.00 (hex.)ST33K1M5ASPI or I2C. The interface is exclusive and selectable dynamically during product boot. Available as a UFQFPN32WF or TSSOP20 package.
ST33KTPM2IST33K1M5A revB10.512 (dec.) 0x00.0A.02.00 (hex.)ST33K1M5ASPI or I2C. The interface is exclusive and selectable dynamically during product boot. Available as a UFQFPN32WF or WLCSP24 package.
2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification

Page 10
Mode NameDescriptionTypeStatus Indicator
Normal modeTPM is in normal operation mode when all pre- operational and conditional self- tests (apart from FW load and PCT tests) are complete. All approved services are usable. The corresponding indicator reports if the service uses an approved cryptographic algorithm or security function.ApprovedTPM2_GetCapability (capability = TPM_CAP_VENDOR_PROPERTIES) with the sub-capability TPM_SUBCAP_VENDOR_TPMA_MODES = 0x7 shall be used. It outputs a 2-bit indicator equals to 01b if the module is in an approved mode of operation

Figure 3

2.3 Excluded Components

No components have been excluded from the cryptographic boundary. Public Material – May be reproduced only in its original entirety (without revision).

Page 11
Mode NameDescriptionTypeStatus Indicator
Non- approved mode of operationThe module enters a non-approved mode if one of the non-approved services is used by the operator.Non- ApprovedTPM2_GetCapability (capability = TPM_CAP_VENDOR_PROPERTIES) with the sub-capability TPM_SUBCAP_VENDOR_TPMA_MODES = 0x7 shall be used. It outputs a 2-bit indicator equals to 10b if the module is in a non- approved mode of operation
AlgorithmCAVP CertPropertiesReference
AES-CBCA5356Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB128A5356Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CTRA5356Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5356Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-OFBA5356Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
ECDSA KeyGen (FIPS186-4)A5358Curve - P-256, P-384, P-521 Secret Generation Mode - Extra BitsFIPS 186-4
ECDSA KeyVer (FIPS186-4)A5358Curve - P-256, P-384, P-521FIPS 186-4
ECDSA SigGen (FIPS186-4)A5358Component - No Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512, SHA3-256, SHA3-384FIPS 186-4
ECDSA SigVer (FIPS186-4)A5358Component - No Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512, SHA3-256, SHA3-384FIPS 186-4
EDDSA KeyGenA5359Curve - ED-448FIPS 186-5
EDDSA KeyVerA5359Curve - ED-448FIPS 186-5
EDDSA SigGenA5359Curve - ED-448FIPS 186-5
EDDSA SigVerA5359Curve - ED-448FIPS 186-5

Table 3: Modes List and Description

2.5 Algorithms

Approved Algorithms: The Module implements the Approved cryptographic algorithms listed in the table below: Public Material – May be reproduced only in its original entirety (without revision).

Page 12
AlgorithmCAVP CertPropertiesReference
Hash DRBGA5351Prediction Resistance - No Mode - SHA2-256SP 800-90A Rev. 1
HMAC-SHA-1A5355Key Length - Key Length: 8-8192 Increment 8FIPS 198-1
HMAC-SHA2-256A5355Key Length - Key Length: 8-8192 Increment 8FIPS 198-1
HMAC-SHA2-384A5355Key Length - Key Length: 8-8192 Increment 8FIPS 198-1
HMAC-SHA2-512A5355Key Length - Key Length: 8-8192 Increment 8FIPS 198-1
HMAC-SHA3-256A5355Key Length - Key Length: 8-8192 Increment 8FIPS 198-1
HMAC-SHA3-384A5355Key Length - Key Length: 8-8192 Increment 8FIPS 198-1
KAS-ECC Sp800- 56Ar3A5358Domain Parameter Generation Methods - P-256, P-384, P-521 Function - Full Validation, Key Pair Generation Scheme - fullUnified - KAS Role - Initiator, Responder KDF Methods - oneStepKdf - Key Length - 128 onePassDh - KAS Role - Initiator, Responder KDF Methods - oneStepKdf - Key Length - 128SP 800-56A Rev. 3
KDF SP800-108A5354KDF Mode - Counter Supported Lengths - Supported Lengths: 160-512 Increment 8SP 800-108 Rev. 1
KTS-IFCA5357Modulo - 2048, 3072, 4096 Key Generation Methods - rsakpg1-basic Scheme - KTS-OAEP-basic - KAS Role - initiator, responder Key Transport Method - Key Length - 256SP 800-56B Rev. 2
LMS SigVerA5360LMS Modes - LMS_SHA256_M32_H10SP 800-208
RSA Decryption Primitive Sp800-56Br2 (CVL)A5357Modulo - 2048, 3072, 4096SP 800-56B Rev. 2
RSA KeyGen (FIPS186-5)A5357Key Generation Mode - probable Modulo - 2048, 3072, 4096 Primality Tests - 2pow100 Private Key Format - standardFIPS 186-5

Public Material – May be reproduced only in its original entirety (without revision).

Page 13
AlgorithmCAVP CertPropertiesReference
RSA SigGen (FIPS186-5)A5357Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pssFIPS 186-5
RSA SigVer (FIPS186-5)A5357Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pssFIPS 186-5
SHA-1A5352Message Length - Message Length: 160, 0-65528 Increment 8FIPS 180-4
SHA-1A5353Message Length - Message Length: 160, 0-65528 Increment 8FIPS 180-4
SHA2-256A5352Message Length - Message Length: 256, 0-65528 Increment 8FIPS 180-4
SHA2-256A5353Message Length - Message Length: 256, 0-65528 Increment 8FIPS 180-4
SHA2-384A5352Message Length - Message Length: 384, 0-65528 Increment 8FIPS 180-4
SHA2-384A5353Message Length - Message Length: 384, 0-65528 Increment 8FIPS 180-4
SHA2-512A5352Message Length - Message Length: 512, 0-65528 Increment 8FIPS 180-4
SHA2-512A5353Message Length - Message Length: 512, 0-65528 Increment 8FIPS 180-4
SHA3-256A5352Message Length - Message Length: 0- 65528 Increment 8FIPS 202
SHA3-384A5352Message Length - Message Length: 0- 65528 Increment 8FIPS 202
NamePropertiesImplementationReference
CKGKey Type:SymmetricN/ASection 4, Example 1 of [133r2]; IG D.H
CKG- AsymKey Type:AsymmetricN/ASection 4, Example 1 of [133r2]; IG D.H
NamePropertiesImplementationReference
ECC BP P-256brainpool256r1:ECDSA [186] (KeyGen, PKV, SigGen, SigVer), KAS [56Ar3][RFC5639], IG C.A ([IG])

Table 4: Approved Algorithms Vendor-Affirmed Algorithms: The Module implements the Vendor Affirmed cryptographic algorithms listed. D.H N/A Table 5: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: The Module implements the Non-Approved, but Allowed cryptographic algorithms listed. Public Material – May be reproduced only in its original entirety (without revision).

Page 14
NamePropertiesImplementationReference
ECC BP P-384brainpool384r1:ECDSA [186] (KeyGen, PKV, SigGen, SigVer), KAS [56Ar3][RFC5639], IG C.A ([IG])
ECC BP P-512brainpool512r1:ECDSA [186] (KeyGen, PKV, SigGen, SigVer), KAS [56Ar3][RFC5639], IG C.A ([IG])
NameCaveatUse and Function
XORNo security claimed per IG 2.4.A with the example of scenario #1. The algorithm: * is not used except for this purpose * does not access or share CSPs in a way that counters the requirements of the IG * not intended to be used as a security function. * can't be confused for a security functionObfuscation of input or output data
NameUse and Function
ECC BN P-256 (non-compliant)Key generation, digital signature generation based on ECC BN P-256
ECC derived keys (non-compliant)Secret exchange or digital signature generation/verification
ECDAA (non- compliant)Key generation, digital signature generation
ECDSA (non- compliant)Digital signature with an ECC signing key generated with an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL), derived from a derivation parent key, or a key loaded in the NULL hierarchy
ECSchnorr (non- compliant)Key generation, digital signature generation and verification
HMAC (non- compliant)Key length < 112 bits for message authentication
KAS (non- compliant)Key agreement with an ECC key that has an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL)
KBKDF (non- compliant)Non-Approved key derivation usage

Table 6: Non-Approved, Allowed Algorithms The Module implements the Non-Approved, Allowed cryptographic Algorithms with No Security The Module implements the Non-Approved, Not Allowed cryptographic algorithms listed. Public Material – May be reproduced only in its original entirety (without revision).

Page 15
NameUse and Function
KTS-IFC (non- compliant)Key encapsulation with an RSA decryption key that has an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL)
RSA (non- compliant)1024-bit RSA digital signature generation or with a key loaded in the Null hierarchy
RSA with no padding mode (null scheme) (non-compliant)Key transport
RSAES-PKCS1- v1_5 (non- compliant)Key transport
SHA-1 (non- compliant)Digital signature generation
X448 (non- compliant)Key generation, key agreement scheme based on Curve448
NameTypeDescriptionPropertiesAlgorithms
KeyGe nAsymKeyPair -KeyGenKey-Pair GenerationPublications:FIPS 186-5ECDSA KeyGen (FIPS186-4): (A5358) EDDSA KeyGen: (A5359) Curves: Ed448 CKG-Asym: () Key Type: Asymmetric RSA KeyGen (FIPS186- 5): (A5357)
KeyVerAsymKeyPair -KeyVerKey-Pair VerificationPublications:FIPS 186-5ECDSA KeyVer (FIPS186- 4): (A5358) EDDSA KeyVer: (A5359) Curves: Ed448
KeyValAsymKeyPair -PubKeyValKey-pair ValidationPublications:186-5KAS-ECC Sp800-56Ar3: (A5358) Function: Full Validation KTS-IFC: (A5357) Function: partialVal
AES- ENCBC-UnAuthUnauthenticate d EncryptionPublication:FIPS 197AES-CBC: (A5356) AES-CFB128: (A5356) AES-CTR: (A5356) AES-ECB: (A5356) AES-OFB: (A5356)
SigGenDigSig- SigGenSignature GenerationPublication:FIPS 186-5ECDSA SigGen (FIPS186- 4): (A5358) Curves: P-256, P-384, P-

Table 8: Non-Approved, Not Allowed Algorithms

2.6 Security Function Implementations

Next table shows the Security Function Implementations that the Module implements: Public Material – May be reproduced only in its original entirety (without revision).

Page 16
NameTypeDescriptionPropertiesAlgorithms
521, brainpool256r1, brainpool384r1, brainpool512r1 EDDSA SigGen: (A5359) Curves: Ed448 RSA SigGen (FIPS186-5): (A5357) Key Sizes: 2048, 3072, 4096 SHA: SHA2-256, SHA2- 384, SHA2-512, SHA3- 256, SHA3-384 SHA2-256: (A5352) SHA2-384: (A5352) SHA2-512: (A5352) SHA3-256: (A5352) SHA3-384: (A5352)
SigVerDigSig- SigVerSignature VerificationPublications:FIPS 186-5LMS SigVer: (A5360) LMS: LMOTS_SHA256_N32_W 4 LMS_SHA256_M32_H10 ECDSA SigVer (FIPS186- 4): (A5358) Curves: P-256, P-384, P- 521, brainpool256r1, brainpool384r1, brainpool512r1 EDDSA SigVer: (A5359) Curves: Ed448 RSA SigVer (FIPS186-5): (A5357) Key Sizes: 2048, 3072, 4096 SHA2-256: (A5352) SHA2-384: (A5352) SHA2-512: (A5352) SHA3-256: (A5352) SHA3-384: (A5352)
DRBGDRBGRandom Number GenerationPublication: :SP800-90AHash DRBG: (A5351) Method: SHA2-256 SHA2-256: (A5352)
ENT- ESVENT-ESVESVPublications:SP800 -90BSHA2-256: (A5352) Conditioning Component: SHA2-256
KASKAS-FullKey establishmentPublications:SP 800-56A, Rev 3KAS-ECC Sp800-56Ar3: (A5358) Schemes: fullUnified, onePassDH

Public Material – May be reproduced only in its original entirety (without revision).

Page 17
NameTypeDescriptionPropertiesAlgorithms
KDF: oneStepKDF SHA-1: (A5352) SHA2-256: (A5352) SHA2-384: (A5352) SHA2-512: (A5352) SHA3-256: (A5352) SHA3-384: (A5352)
KTS- IFCKTS-EncapKey EncapsulationPublication:SP 800- 56B rev 2, IG D.G Method:KTS- OAEP-basicKTS-IFC: (A5357) RSA Decryption Primitive Sp800-56Br2: (A5357)
KTSKTS-WrapKey transportPublication:SP 800- 38F, IG D.GHMAC-SHA2-256: (A5355) AES-CFB128: (A5356)
KBKDFKBKDFKey-Based Key DerivationPublications:SP800 -108KDF SP800-108: (A5354) SHA-1: (A5353) SHA2-256: (A5353) SHA2-384: (A5353) SHA2-512: (A5353) SHA3-256: (A5352) SHA3-384: (A5352)
MACMACMessage AuthenticationPublication:FIPS19 8HMAC-SHA-1: (A5355) HMAC-SHA2-256: (A5355) HMAC-SHA2-384: (A5355) HMAC-SHA2-512: (A5355) HMAC-SHA3-256: (A5355) HMAC-SHA3-384: (A5355) SHA-1: (A5352) SHA2-256: (A5352) SHA2-384: (A5352) SHA2-512: (A5352) SHA3-256: (A5352) SHA3-384: (A5352)
SHASHASecure HashPublications:FIPS 180-4, FIPS 202SHA-1: (A5353, A5352) SHA2-256: (A5352, A5353) SHA2-384: (A5352, A5353) SHA2-512: (A5352, A5353) SHA3-256: (A5352) SHA3-384: (A5352)

Public Material – May be reproduced only in its original entirety (without revision).

Page 18
NameTypeDescriptionPropertiesAlgorithms
CKGCKGSymmetric Key GenerationPublications:SP800 -133rev2, Section 4; IG D.HHash DRBG: (A5351)
KAS- KeyGe nKAS-KeyGenKAS-ECC Key GenerationPublication:SP800- 56Arev3KAS-ECC Sp800-56Ar3: (A5358)
AES- DECBC-UnAuthUnauthenticate d DecryptionPublication:FIPS 197AES-CBC: (A5356) AES-CFB128: (A5356) AES-CTR: (A5356) AES-ECB: (A5356) AES-OFB: (A5356)
Cert NumberVendor Name
E41STMicroelectronics
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
Trusted Platform Module ST33KTPM2X, ST33KTPM2XSPI, ST33KTPM2XI2C,PhysicalST33K1M5T/A platforms1 bit0.819266 bitsA5352 (SHA2-256)

n Table 9: Security Function Implementations

2.7 Algorithm Specific Information

Notes: KAS [56Ar3] - Per [IG] D.F Scenario 2 path (2), compliant key agreement scheme where testing is performed end-to-end for the shared secret computation and key derivation.

2.8 RBG and Entropy

The Module implements:

Page 19

Name ST33KTPM2A, ST33KTPM2I entropy source

Type

Operational Environment

Sample Size

Entropy per Sample

Conditioning Component

2.9 Key Generation

For Key Generation, see Section 2.5 and Section 2.6 above.

2.10 Key Establishment

Key Agreement Information For Key Agreement, see Section 2.5 and Section 2.6 above. Key Transport Information For Key Transport, see Section 2.5 and Section 2.6 above.

2.11 Industry Protocols

The Module does not implement any Industry Protocols. Public Material – May be reproduced only in its original entirety (without revision).

Page 20
Physical PortLogical Interface(s)Data That Passes
SPI_NSS / SPI_CLK / SPI_MOSI / I2C_SCL / I2C_SDA / RESET / PPControl InputControl parts of the TPM commands provided to the security module. It concerns all bytes of a command except plaintext data, ciphertext data and SSPs (entered with the data input interface).
SPI_NSS / SPI_CLK / SPI_MISO / I2C_SCL / I2C_SDA / PIRQControl OutputControl parts of the TPM responses output by the security module. It concerns all bytes of a response except plaintext data, ciphertext data and SSPs (output with the data output interface) and except the responseCode of a response (output with the status output interface)
SPI_NSS / SPI_CLK / SPI_MISO / I2C_SCL / I2C_SDA / PIRQStatus OutputStatus output by the security module (responseCode parameter of a response)
SPI_NSS / SPI_CLK / SPI_MOSI / I2C_SCL / I2C_SDAData InputData (plaintext data, ciphertext data and SSPs) provided to the security module as part of an input processing command
SPI_NSS / SPI_CLK / SPI_MISO / I2C_SCL / I2C_SDAData OutputData (plaintext data, ciphertext data and SSPs) output by the security module as part of the response to a processing command
VCC / GNDPowerPower interface of the security module
3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

The Module’s ports and associated logical interface categories are listed below: Table 12: Ports and Interfaces Additional details concerning the ports and interfaces of TPM: 1. Control and data inputs are multiplexed over the same physical interface. Control and data are distinguished by properly parsing input TPM command parameters according to input structures description, indicated for each command in [TPM2.0 Part3]. Some commands only deal with Public Material – May be reproduced only in its original entirety (without revision).

Page 21
  1. Status, data and control output are multiplexed over the same physical interface. Status, data, and control are distinguished by properly setting output TPM response parameters according to output structures description, indicated for each command in [TPM2.0 Part3].
  2. The logical state machine and the command structure parsing of the Module prevent the Module from using input data externally from the “data input path” and prevent the Module from outputting data externally from the “data output path”.
  3. While performing key generation or key zeroization (no manual key entry on TPM), the output data path is logically disconnected while the output status path remains connected to report any possible failure during command processing. Generally, the output data path is only connected when TPM outputs response containing data.
  4. To prevent the inadvertent output of CSPs in plaintext form on TPM2_Duplicate, the two following independent internal actions are performed: a. Verification of the encryptedDuplication attribute of the key to be duplicated b. Verification of the handle of the new parent of the key to be duplicated encryptedDuplication attribute must be set to 0 and new handle must be set to the null handle to authorize outputting the private part of the key in plaintext form.
  5. The logical state machine and command structure of the Module guarantees the inhibition of all data output via the data output interface whenever an error state exists and while doing selftests.
  6. The status output interface remains active during the error state to output the status of the security module with the service TPM2_GetCapability and TPM2_GetTestResult.
3.2 Pinout description

The pin layouts for the various packages are shown in the next figures. The ST33KTPM2A / ST33KTPM2I security modules support both SPI and I2C physical interfaces but only one interface is configured during TPM boot. The interface configured remains active until the next module reset. Public Material – May be reproduced only in its original entirety (without revision).

Page 22
SignalTypeDescription
VCCInputPower supply. This pin must be connected to 1.8V or 3.3V DC power rail supplied by the motherboard.
GNDInputGND has to be connected to the main motherboard ground.
RESETInputReset used to re-initialize the device
I2C SCL / GPIO5Input or Input/OutputI²C serial clock (Open drain with no weak pull-up resistor) or GPIO if SPI interface is selected
I2C SDA / GPIO6Input/OutputI²C serial data (Open drain with no weak pull-up resistor) or GPIO if SPI interface is selected
PIRQOutputIRQ used by TPM to generate an interrupt
SPI CLK / GPIO1Input or Input/OutputSPI serial clock (output from master) or GPIO if I2C interface is selected
SPI NSS / GPIO2Input or Input/OutputSPI slave select (active low; output from master) or GPIO if I2C interface is selected
SPI MISO / GPIO0Output or Input/OutputSPI Master Input, Slave Output (output from slave) or GPIO if I2C interface is selected
SPI MOSI / GPIO3Input or Input/OutputSPI Master Output, Slave Input (output from master) or GPIO if I2C interface is selected
GPI8InputGPI default to low. The level of this pin on the rising edge of the RESET signal is used to determine the physical interface to use (high level corresponds to SPI configuration and low-level to I2C)
PPInputPhysical presence, active high, internal pull-down. Used to indicate Physical Presence to the TPM.
NC-Not Connected: connected to the die but not usable. May be left unconnected. Internal pull-down.

UFQFPN32 / UFQFPN32 WF configuration The pin layouts for the UFWFPN32 / UFWFPN32 WF packages are shown in the next figure. Figure 5

Page 23
SignalTypeDescription
VCCInputPower supply. This pin must be connected to 1.8V or 3.3V DC power rail supplied by the motherboard.
GNDInputGND has to be connected to the main motherboard ground.
RESETInputReset used to re-initialize the device
I2C SCL / GPIO5Input or Input/OutputI²C serial clock (Open drain with no weak pull-up resistor) or GPIO if SPI interface is selected
I2C SDA / GPIO6Input/OutputI²C serial data (Open drain with no weak pull-up resistor) or GPIO if SPI interface is selected
PIRQOutputIRQ used by TPM to generate an interrupt
SPI CLK / GPIO1Input or Input/OutputSPI serial clock (output from master) or GPIO if I2C interface is selected
SPI NSS / GPIO2Input or Input/OutputSPI slave select (active low; output from master) or GPIO if I2C interface is selected
SPI MISO / GPIO0Output or Input/OutputSPI Master Input, Slave Output (output from slave) or GPIO if I2C interface is selected
SPI MOSI / GPIO3Input or Input/OutputSPI Master Output, Slave Input (output from master) or GPIO if I2C interface is selected
I2C SELInputThis pin must be connected to an external pull-down resistor to activate the I²C protocol during product boot time. It can remain unconnected for the SPI protocol. This pin is internal pull-up by default and becomes internal floating after I²C activation.
PPInputPhysical presence, active high, internal pull-down. Used to indicate Physical Presence to the TPM.
NiC-Not internally connected: not connected to the die. May be left unconnected but no impact on TPM if connected.

TSSOP20 configuration The pin layouts for the TSSOP20 package are shown in the next figure. Figure 6

Page 24
SignalTypeDescription
VCCInputPower supply. This pin must be connected to 1.8V or 3.3V DC power rail supplied by the motherboard.
GNDInputGND has to be connected to the main motherboard ground.
RESETInputReset used to re-initialize the device
I2C SCL / GPIO5Input or Input/OutputI²C serial clock (Open drain with no weak pull-up resistor) or GPIO if SPI interface is selected
I2C SDA / GPIO6Input/OutputI²C serial data (Open drain with no weak pull-up resistor) or GPIO if SPI interface is selected
PIRQOutputIRQ used by TPM to generate an interrupt
SPI CLK / GPIO1Input or Input/OutputSPI serial clock (output from master) or GPIO if I2C interface is selected
SPI NSS / GPIO2Input or Input/OutputSPI slave select (active low; output from master) or GPIO if I2C interface is selected
SPI MISO / GPIO0Output or Input/OutputSPI Master Input, Slave Output (output from slave) or GPIO if I2C interface is selected
SPI MOSI / GPIO3Input or Input/OutputSPI Master Output, Slave Input (output from master) or GPIO if I2C interface is selected
I2C SELInputThis pin must be connected to an external pull-down resistor to activate the I²C protocol during product boot time. It can remain unconnected for the SPI protocol. This pin is internal pull-up by default and becomes internal floating after I²C activation.
PPInputPhysical presence, active high, internal pull-down. Used to indicate Physical Presence to the TPM.

WLCSP24 configuration The pin layouts for the WLCSP24 package are shown in the next figure. Figure 7

Page 25
Method NameDescriptionSecurity MechanismStrength Each AttemptStrength per Minute
Challenge- response authenticationThe challenge-response mechanism uses an authorization value (authValue) as HMAC key or part of an HMAC key. The authValue is entered into the Module during the creation/loading of an object (key, NV index) or during replacement of the default value (hierarchies). The Module enforces a minimum size of 14 bytes.MACMinimum strength is reached with an authValue of 14 bytes: 1/2^112 = 1.92*10^- 34Probability of a successful random attempt during a one-minute period is equal to 60000*1.92*10^-34 = 1.15*10^-29 (considering 60000 trials per minute). Assuming a minimum command duration of 1ms, 60000 trials can be executed during a one-minute period.
Enhanced authorizationEnhanced authorization includes a policy command (i.e., TPM2_PolicyAuthValue, TPM2_PolicySigned, TPM2_PolicyAuthorize, TPM2_PolicySecret, TPM2_PolicyTicket) requiring the knowledge of an authValue or the proof of the ownership of a signing key. It can also be a bound session, which also requires proving knowledge of an authValue of an object.SigVerMinimum strength is reached with an authValue of 14 bytes: 1/2^112 = 1.92*10^- 34 or an RSA 2048 signature with a security strength of 112 bitsProbability of a successful random attempt during a one-minute period is equal to 60000*1.92*10^-34 = 1.15*10^-29 (considering 60000 trials per minute). Assuming a minimum command duration of 1ms, 60000 trials can be executed during a one-minute period.
4 Roles, Services, and Authentication
4.1 Authentication Methods

The Module implements the following authentication techniques in accordance with the Level 2 requirements: Table 16: Authentication Methods

4.2 Roles

The Roles Table below lists all operator roles supported by the Module. Public Material – May be reproduced only in its original entirety (without revision).

Page 26
NameTypeOperator TypeAuthentication Methods
Crypto officer (CO)RoleAdministrator of the ModuleChallenge-response authentication Enhanced authorization
User (U)RoleUser of the ModuleChallenge-response authentication Enhanced authorization
Mandatory service requested from [ISO/IEC 19790]Corresponding services from the security module
Show module’s versioning informationTPM2_GetCapability
Show statusTPM2_GetTestResult
Perform self-testsTPM2_SelfTest
Perform Approved security functionsSee Approved services listed in next table
Perform zeroizationSee services listed in section 9.3 SSP Zeroization Methods.

Table 17: Roles The Module does not provide a maintenance role or maintenance interface and does not support concurrent operators. The role is implicitly selected by the TPM operator on service execution by proving the knowledge of the enhanced authorization commands sequence and/or the authorization value of an object. All services are accessible under the roles defined above and no specific access rights are considered to operate with keys and SSPs. Full services inputs and outputs are defined in [TPM2.0 Part3]. The next table Table 18 – Mapping between services The SSPs modes of access shown in the table below are defined as:

G = Generate: The Module generates or derives the SSP.
R = Read: The SSP is read from the Module (e.g., the SSP is output).
W = Write: The SSP is updated, imported, or written to the Module (SSP is input).
E = Execute: The Module uses the SSP in performing a cryptographic operation.

Some details about information found in the table:

Page 27
NameDescriptionIndi cato rInputsOutputsSecu rity Func tionsSSP Access
TPM2_InitReboot or power-on of the TPM.00bNoneNoneUnauthen ticated - nullSeed: Z - nullProof: Z - platformA uth: Z - objSeed: Z - objAuth: Z - objSens: Z - objPub: Z - sesSalt: Z - sesHmac Key: Z - sesSymK ey: Z - contextK ey: Z - objSymK
Page 28

Name

Description

Indi cato r

Inputs

Outputs

Secu rity Func tions

SSP Access ey: Z - objHmac Key: Z - contextE ncKey: Z - dupSeed: Z - dupInSy mKey: Z - dupOutS ymKey: Z - dupOutH macKey: Z - creSeed: Z - creSymK ey: Z - creHmac Key: Z - ephSens EccKey: Z - ephPubE ccKey: Z - seqAuth: Z - drbgSeed : Z - tdrbgStat e: Z - fuSymKe

r Z Z Z Z Z :Z e: Z Public Material – May be reproduced only in its original entirety (without revision).

Page 29
NameDescriptionIndi cato rInputsOutputsSecu rity Func tionsSSP Access y: Z - diagSym Key: Z
TPM2_StartupSet-up the TPM after a power cycle.01bStartup typeNoneDRB G ENT- ESVUnauthen ticated - phSeed: G - ehSeed: G - shSeed: G - phProof: G - ehProof: G - shProof: G - contextK ey: G - drbgSeed : G - drbgState : G - nullSeed: G - nullProof: G
TPM2_Shutdown (I)Prepare the TPM for a power cycle.00bShutdow n typeNoneNoneUnauthen ticated
TPM2_SelfTest (I)Self-tests execution01bFull or backgrou nd self- testsSelf-test result if full self-tests requiredAES- ENC SigG en SigV er DRB GUnauthen ticated

r y: Z G G G G G :G :G G G G Public Material – May be reproduced only in its original entirety (without revision).

Page 30
NameDescriptionIndi cato rInputsOutputsSecu rity Func tionsSSP Access
ENT- ESV KAS KBK DF MAC SHA AES- DEC
TPM2_IncrementalSelf Test (I)Incremental self-tests execution01bList of tests to passList of remaining testsAES- ENC SigG en SigV er DRB G ENT- ESV KAS KBK DF MAC SHA AES- DECUnauthen ticated
TPM2_GetTestResult (I)Get self-tests result00bNoneSelf-tests statusKBK DFUnauthen ticated - diagSym Key: G,E,Z - diagSym Seed: E
TPM2_StartAuthSessio n (I/E/D)Session command01bDecrypti on key handle; Binding entity handle; Encrypte d salt; Nonce caller; SessionNonce TPMKAS KTS- IFC KBK DFUnauthen ticated - sesHmac Key: G,W - sesSymK ey: G,W - sesSalt: W,E,Z -

r G,E,Z Public Material – May be reproduced only in its original entirety (without revision).

Page 31
NameDescriptionIndi cato rInputs Type (HMAC or Policy)OutputsSecu rity Func tionsSSP Access objSens: E - objAuth: E - nvAuth: E - platformA uth: E - endorse mentAuth : E - ownerAut h: E - lockoutA uth: E - seqAuth: E
TPM2_PolicyRestart (I)Policy session restart00bSession handleNoneNoneUnauthen ticated
TPM2_Create (I/E/D)Object creation01bParent object handle Object sensitive part Object public template Creation data List of PCRObject private part (encrypted) Object public part Creation data Digest of creation data Ticket to be used by TPM2_Cert ifyCreation( )Key Gen AES- ENC SigG en SigV er DRB G ENT- ESV KTS KBK DF MAC SHA CKG KAS- Key GenUser (U) - objSeed: G,R,E - objSymK ey: G,E,Z - objHmac Key: G,E,Z - objSens: G,R,E - objPub: G,R,E - drbgState : W,E - objAuth: W,R - nullProof:

r E :E h: E E G G,E,Z ) Public Material – May be reproduced only in its original entirety (without revision).

Page 32
NameDescriptionIndi cato rInputsOutputsSecu rity Func tionsSSP Access E - phProof: E - ehProof: E - shProof: E
TPM2_Load (I/E/D)Object loading01bParent object handle Object private part (encrypt ed) Object public partName of the loaded objectKeyV er KTS KBK DF MAC SHA AES- DECUser (U) - objSymK ey: G,W,E,Z - objHmac Key: G,W,E,Z - objSens: W,E - objPub: W - objSeed: W,E - objAuth: W
TPM2_LoadExternal (I/E/D)External object loading01bObject public part Hierarch yName of the loaded objectKeyV alUnauthen ticated - objPub: W - objSens: W - objAuth: W - objSeed: W
TPM2_ReadPublic (I)Read public part of a loaded object01bHandle of an objectObject public part Object name ObjectNoneUnauthen ticated - objPub: R

r E E E E W,E W W y W W R Public Material – May be reproduced only in its original entirety (without revision).

Page 33
NameDescriptionIndi cato rInputsOutputs qualified nameSecu rity Func tionsSSP Access
TPM2_ActivateCredent ial (I/E/D)Enables the association of a credential with an object in a way that ensures that the TPM has validated the parameters of the credentialed object01bHandle of the object with credentia ls Handle of a loaded private key Encrypte d credentia l Encrypte d seedDecrypted certificate informationKAS KTS- IFC KTS KBK DF MAC SHA AES- DECCrypto officer (CO) - creSymK ey: G,E,Z - creHmac Key: G,E,Z - objSens: E - creSeed: W,E,Z
TPM2_MakeCredential (I/E/D)Allows the TPM to perform the actions required of a Certificate Authority (CA) in creating a TPM2B_ID_O BJECT containing an activation credential01bHandle of a loaded public key Credenti al informati on Name of the object with credentia lsEncrypted credential Encrypted seedAES- ENC KAS KTS- IFC KTS KBK DF MAC SHAUnauthen ticated - creSeed: G,R,E,Z - creSymK ey: G,E,Z - creHmac Key: G,E,Z - objPub: E
TPM2_Unseal (I/E/D)Returns the data in a loaded Sealed Data Object01bHandle of a loaded data objectUnsealed dataNoneUser (U) - objSens: R
TPM2_ObjectChangeA uth (I/E/D)Changes the authorization secret for a TPM-resident object01bHandle of an object Handle of the parent of the objectObject private partAES- ENC KBK DF MAC SHAUser (U) - objSeed: R,E - objSens: R -

r d l W,E,Z Public Material – May be reproduced only in its original entirety (without revision).

Page 34
NameDescriptionIndi cato rInputs New authoriza tion valueOutputsSecu rity Func tionsSSP Access drbgState : W,E - objAuth: R - objSymK ey: E - objHmac Key: E
TPM2_CreateLoaded (I/E/D)Creates an object and loads it in the TPM01bParent object handle Object sensitive part Object public templateObject private part (encrypted) Object public part Creation object nameKey Gen KeyV er AES- ENC SigG en SigV er DRB G ENT- ESV KAS KBK DF MAC SHA CKG KAS- Key GenCrypto officer (CO) - objSeed: G,R,E - objSymK ey: G,E - objHmac Key: G,E - objSens: G,R,E - objPub: G,R,E - tdrbgStat e: G,W,E - drbgState : W,E - objAuth: W,R - nullSeed: E - phSeed: E - ehSeed: E - shSeed: E - nullProof: E

r G,R,E E E E Public Material – May be reproduced only in its original entirety (without revision).

Page 35

Name

Description

Indi cato r

Inputs

Outputs

Secu rity Func tions

SSP Access - phProof: E - ehProof: E - shProof: E - ekRsa: E - ekEcc: E - shProofF orReseed : G,E User (U) - objSeed: G,E - objSymK ey: G,E - objHmac Key: G,E - objSens: G,R - objPub: G,R,E - tdrbgStat e: G,W,E - drbgState : W - objAuth: W - nullSeed: E - phSeed: E - ephSens EccKey:

r E E E E E : G,E G,E G,R G,R,E e: G,W,E :W W E E Public Material – May be reproduced only in its original entirety (without revision).

Page 36
NameDescriptionIndi cato rInputsOutputsSecu rity Func tionsSSP Access E - shSeed: E - nullProof: E - phProof: E - ehProof: E - shProofF orReseed : G,E - ekRsa: E - ekEcc: E
TPM2_Duplicate (I/E/D)Duplicates a loaded object so that it may be used in a different hierarchy01bHandle of the loaded object to duplicate Handle of the new parent Optional symmetri c encryptio n keyEncryption key for inner wrapper Duplicated object private part (encrypted) Encrypted seedAES- ENC DRB G KTS- IFC KAS KTS KBK DF MAC SHA CKGUser (U) - dupSeed: G,R,E,Z - objSeed: R - dupOutS ymKey: G,E,Z - dupInSy mKey: G,R,W,E, Z - dupOutH macKey: G,E,Z - objSens: R - objAuth: R - drbgState

r E E E E E : G,E E E G,R,E,Z R G G,E,Z R R Public Material – May be reproduced only in its original entirety (without revision).

Page 37
NameDescriptionIndi cato rInputsOutputsSecu rity Func tionsSSP Access : W,E - objPub: E
TPM2_Rewrap (I/E/D)Rewraps a duplicated object with a new parent key01bHandle of the old parent Handle of the new parent Duplicat ed object private part (encrypt ed) Name of the object being rewrapp ed Encrypte d seedDuplicated object private part (encrypted) Encrypted seedAES- ENC AES- DEC KAS KTS- IFC KTS KBK DF MAC SHA CKGUser (U) - dupOutS ymKey: G,E,Z - dupOutH macKey: G,E,Z - objSens: R,W,E - dupSeed: R,W,E,Z - objSeed: R,W - dupInSy mKey: W,Z - drbgState : W,E - objPub: E - objAuth: R,W
TPM2_Import (I/E/D)Allows an object to be encrypted using the symmetric encryption values of a Storage Key01bHandle of the new parent Duplicat ed object private part (encrypt ed) Object public part Encrypte d seedObject private part (encrypted)AES- ENC AES- DEC KAS KTS- IFC KTS KBK DF MAC SHA CKGUser (U) - objSens: R,W,E,Z - objSeed: R,W,Z - objPub: W,E,Z - dupOutS ymKey: W,E,Z - objAuth: R,W,Z

r : W,E E E R,W Public Material – May be reproduced only in its original entirety (without revision).

Page 38
NameDescriptionIndi cato rInputs Encrypti on key for inner wrapperOutputsSecu rity Func tionsSSP Access - drbgState : E - dupSeed: E,W,Z - dupInSy mKey: E,W,Z - dupOutH macKey: W,E,Z
TPM2_RSA_Encrypt (I/E/D)Performs RSA encryption01bRSA public key handle Message to encrypt RSA scheme to useEncrypted outputKTS- IFCUnauthen ticated - objPub: E
TPM2_RSA_Decrypt (I/E/D)Performs RSA decryption01bRSA private key handle Cipherte xt to decrypt RSA scheme to useDecrypted outputKTS- IFCUser (U) - objSens: Z
TPM2_ECDH_KeyGen (I/E/D)Shared secret value computation using ECDH01bECC key public part handleShared secret Ephemeral public keyKAS KAS- Key GenUnauthen ticated - ephSens EccKey: G,E,Z - ephPubE ccKey: G,R,Z - drbgState

r E,W,Z E,W,Z W,E,Z G,R,Z Public Material – May be reproduced only in its original entirety (without revision).

Page 39
NameDescriptionIndi cato rInputsOutputsSecu rity Func tionsSSP Access : W,E - objPub: E
TPM2_ECDH_ZGen (I/E/D)Shared secret value recovery using ECDH01bHandle of a loaded ECC key Ephemer al public keyRecovered shared secretKASUser (U) - ephPubE ccKey: W,E,Z - objSens: E
TPM2_ECC_Paramete rs (I)Returns the parameters of an ECC curve identified by its TCG-assigned curveID00bID of an ECC curveCurve parametersNoneUnauthen ticated
TPM2_EncryptDecrypt (I/E)Symmetric encryption or decryption01bSymmetr ic key handle Decrypti on or encryptio n indicator Input IV Data ModeEncrypted or decrypted data Output IV (for chaining)AES- ENC AES- DECUser (U) - objSens: E
TPM2_EncryptDecrypt 2 (I/E/D)Symmetric encryption or decryption01bSymmetr ic key handle Decrypti on or encryptio n indicator Input IV Data ModeEncrypted or decrypted data Output IV (for chaining)AES- ENC AES- DECUser (U) - objSens: E
TPM2_Hash (I/E/D)Performs a hash operation on data01bData to hash Hash algorithm Hierarch y to use for ticketDigest Ticket linked to the input hierarchyMAC SHAUnauthen ticated - nullProof: E - phProof:

r : W,E E (I/E/D) W,E,Z E Public Material – May be reproduced only in its original entirety (without revision).

Page 40
NameDescriptionIndi cato rInputsOutputsSecu rity Func tionsSSP Access E - ehProof: E - shProof: E
TPM2_HMAC (I/E/D)Performs a HMAC operation on data01bSymmetr ic signing key handle Data to HMAC Hash algorithmHMACMACUser (U) - objSens: E
TPM2_GetRandom (I/E)Outputs random bytes from a DRBG01bNumber of random bytes to generateOutput random bytesDRB GUnauthen ticated - drbgState : W,E
TPM2_StirRandom (I/D)Reseed the state of a DRBG01bAddition al informati onNoneDRB G ENT- ESVUnauthen ticated - drbgSeed : W,E,Z - drbgState : W,E
TPM2_HMAC_Start (I/D)Starts an HMAC sequence01bHandle of an HMAC key Authoriz ation value for sequenc e Hash algorithmSequence handleMACUser (U) - seqAuth: W - objSens: E
TPM2_HashSequence Start (I/D)Starts a hash or an event sequence01bAuthoriz ation value for sequenc e Hash algorithmSequence handleSHAUnauthen ticated - seqAuth: W

r E E E (I/E) G : W,E E W Public Material – May be reproduced only in its original entirety (without revision).

Page 41
NameDescriptionIndi cato rInputsOutputsSecu rity Func tionsSSP Access
TPM2_SequenceUpda te (I/D)Adds data to a hash or HMAC sequence01bSequenc e handle Data to hash/HM ACNoneMAC SHAUser (U) - objSens: E
TPM2_SequenceComp lete (I/E/D)Adds last part of data to a hash or HMAC sequence and returns the result01bSequenc e handle Data to hash/HM AC Hierarch y for ticketHMAC or digest Ticket linked to the input hierarchyMAC SHAUser (U) - nullProof: E - phProof: E - ehProof: E - shProof: E - objSens: E - seqAuth: Z
TPM2_EventSequence Complete (I/D)Adds last part of data to a hash or HMAC sequence and returns the result in a digest list01bHandle of PCR to extend Sequenc e handle Data to hash/HM ACList of digests computed for the PCRMAC SHAUser (U) - objSens: E - seqAuth: Z
TPM2_Certify (I/E/D)Proves that an object with a specific Name is loaded in the TPM01bHandle of the object to certify Handle of a signing key Qualifyin g data Signatur e schemeCertification structure Signature over the certification structureSigG en DRB G KBK DF MAC SHA CKGUser (U) - drbgState : W,E - objSens: E - shProof: E
TPM2_CertifyCreation (I/E/D)Proves the association01bHandle of theCertification structureSigG enUser (U) -

r E E E Z e Public Material – May be reproduced only in its original entirety (without revision).

Page 42
NameDescriptionIndi cato rInputsOutputsSecu rity Func tionsSSP Access
between an object and its creation dataobject to certify Handle of a signing key Qualifyin g data Signatur e scheme Ticket Creation hashSignature over the certification structureDRB G KBK DF MAC SHA CKGdrbgState : W,E - objSens: E - nullProof: E - phProof: E - ehProof: E - shProof: E
TPM2_Quote (I/E/D)Quotes PCR values01bHandle of a signing key Qualifyin g data Selection of PCRs Signatur e schemeQuoted information Signature over the quoted informationSigG en DRB G KBK DF MAC SHA CKGUser (U) - drbgState : W,E - objSens: E - shProof: E
TPM2_GetSessionAudi tDigest (I/E/D)Returns a digital signature of the audit session digest01bHandle of a privacy administr ator Handle of a signing key Handle of an audit session Qualifyin g data Signatur e schemeAudit information Signature over the quoted informationSigG en KBK DF DRB G MAC SHA CKGCrypto officer (CO) - drbgState : W,E - objSens: E - shProof: E

r E E e Public Material – May be reproduced only in its original entirety (without revision).

Page 43
NameDescriptionIndi cato rInputsOutputsSecu rity Func tionsSSP Access
TPM2_GetCommandA uditDigest (I/E/D)Returns the current value of the command audit digest, a digest of the commands being audited, and the audit hash algorithm01bHandle of a privacy administr ator Handle of a signing key Qualifyin g data Signatur e schemeAudit information Signature over the quoted informationSigG en DRB G KBK DF MAC SHA CKGCrypto officer (CO) - drbgState : W,E - objSens: E - shProof: E
TPM2_GetTime (I/E/D)Returns the current values of Time and Clock01bHandle of a privacy administr ator Handle of a signing key Qualifyin g data Signatur e schemeAttestation data Signature over the attestation dataSigG en KBK DF DRB G MAC SHA CKGCrypto officer (CO) - drbgState : W,E - objSens: E - shProof: E
TPM2_CertifyX509 (I/E/D)X.509 certificate generation01bHandle of the object to certify Handle of a signing key Partial certificat e Signatur e schemeAdditional certificate information Digest Signature over the digestSigG en SHAUser (U) - drbgState : W,E - objSens: E
TPM2_VerifySignature (I/D)Uses loaded keys to validate a signature on a01bHandle of a public keyValidation ticketSigV er MACUnauthen ticated - objPub: E

r E e G E e e e Public Material – May be reproduced only in its original entirety (without revision).

Page 44
NameDescription message with the message digest passed to the TPMIndi cato rInputs Digest of a message Signatur e to be testedOutputsSecu rity Func tionsSSP Access - nullProof: E - phProof: E - ehProof: E - shProof: E
TPM2_Sign (I/D)Causes the TPM to sign an externally provided hash with the specified symmetric or asymmetric signing key01bHandle of a signing key Digest to be signed Scheme Proof ticket for digestSignature over the digestSigG en DRB G MAC SHAUser (U) - objSens: E - nullProof: E - phProof: E - ehProof: E - shProof: E
TPM2_SetCommandC odeAuditStatus (I)Changes the audit status of a command or to set the hash algorithm used for the audit digest00bAuthoriz ation handle Hash algorithmNoneNoneCrypto officer (CO)
TPM2_PCR_Extend (I)Updates the indicated PCR01bPCR handle List of digests used to extend PCRsNoneSHAUnauthen ticated
TPM2_PCR_Event (I/D)Updates the indicated PCR and reports list of digests01bPCR handle Event dataDigestsSHAUnauthen ticated

r E E G E Public Material – May be reproduced only in its original entirety (without revision).

Page 45
NameDescriptionIndi cato rInputsOutputsSecu rity Func tionsSSP Access
TPM2_PCR_Read (I)Returns the values of all PCR specified in pcrSelectionIn00bSelection of PCR to readPCR informationNoneUnauthen ticated
TPM2_PCR_Allocate (I)Sets the desired PCR allocation of PCR and algorithms00bSelection of PCR to allocatePCR allocation informationNoneCrypto officer (CO)
TPM2_PCR_Reset (I)Sets the PCR in all banks to zero00bPCR to resetnoneNoneUnauthen ticated
_TPM_Hash_StartIndicates to the TPM interface the start of an H-CRTM measurement sequence01bNoneNoneSHAUnauthen ticated
_TPM_Hash_DataIndicates to the TPM interface data to be included in the H-CRTM measurement sequence01bDataNoneSHAUnauthen ticated
TPM_Hash_EndIndicates to the TPM interface the end of the H-CRTM measurement sequence01bNoneNoneSHAUnauthen ticated
TPM2_PolicySigned (I/E/D)Includes a signed authorization in a policy01bSignatur e key handle Policy session handle Nonce TPM Digest Signatur e Expiratio n of authorizaPolicy timeout Policy ticketSigV er MAC SHAUnauthen ticated - objPub: E - nullProof: E - phProof: E - ehProof: E

r E E e E Public Material – May be reproduced only in its original entirety (without revision).

Page 46
NameDescriptionIndi cato rInputs tion Policy referenc e valueOutputsSecu rity Func tionsSSP Access - shProof: E
TPM2_PolicySecret (I/E/D)Includes a secret-based authorization to a policy01bAuthoriz ation object handle Policy session handle Nonce TPM Digest Expiratio n of authoriza tion Policy referenc e valuePolicy timeout Policy ticketMAC SHAUser (U) - nullProof: E - phProof: E - ehProof: E - shProof: E
TPM2_PolicyTicket (I/D)Includes a ticket in a policy01bPolicy session handle Nonce TPM Digest Expiratio n of authoriza tion Policy referenc e value Authoriz ation object name TicketNoneMAC SHAUnauthen ticated - nullProof: E - phProof: E - ehProof: E - shProof: E
TPM2_PolicyOR (I)Allows options in authorizations without requiring that the TPM01bPolicy session handle List of digestsNoneSHAUnauthen ticated

r E E E E E E Public Material – May be reproduced only in its original entirety (without revision).

Page 47
NameDescription evaluate all the optionsIndi cato rInputsOutputsSecu rity Func tionsSSP Access
TPM2_PolicyPCR (I/D)Causes conditional gating of a policy based on PCR01bPolicy session handle Expecte d digest value PCR selectionNoneSHAUnauthen ticated
TPM2_PolicyLocality (I)Indicates that the policy will be limited to a specific locality01bPolicy session handle LocalityNoneSHAUnauthen ticated
TPM2_PolicyNV (I/D)Causes conditional gating of a policy based on the contents of an NV Index01bAuthoriz ation handle NV index handle Policy session handle Operand , offset, operatio nNoneSHAUser (U)
TPM2_PolicyCounterTi mer (I/D)Causes conditional gating of a policy based on the contents of the TPMS_TIME_I NFO structure01bPolicy session handle Operand , offset, operatio nNoneSHAUnauthen ticated
TPM2_PolicyComman dCode (I)Limits policy to a specific command code01bPolicy session handle Comman d codeNoneSHAUnauthen ticated
TPM2_PolicyPhysicalP resence (I)Physical presence will need to be asserted at the time the authorization is performed01bPolicy session handleNoneSHAUnauthen ticated

r n n Public Material – May be reproduced only in its original entirety (without revision).

Page 48
NameDescriptionIndi cato rInputsOutputsSecu rity Func tionsSSP Access
TPM2_PolicyCpHash (I/D)Allows a policy to be bound to a specific command and command parameters01bPolicy session handle Digest to add to policyNoneSHAUnauthen ticated
TPM2_PolicyNameHas h (I/D)Allows a policy to be bound to a specific set of TPM entities without being bound to the parameters of the command01bPolicy session handle Digest to add to policyNoneSHAUnauthen ticated
TPM2_PolicyDuplicatio nSelect (I/D)Allows qualification of duplication to allow duplication to a selected new parent01bPolicy session handle Object name to be duplicate d New Parent name Object name inclusion indicatorNoneSHAUnauthen ticated
TPM2_PolicyAuthorize (I/D)Check a ticket issued from the signature verification of a new policy so that it may be used in an existing policy01bPolicy session handle Digest of the policy being approve d Policy qualifier Key name TicketNoneMAC SHAUnauthen ticated - nullProof: E - phProof: E - ehProof: E - shProof: E
TPM2_PolicyAuthValu e (I)Allows a policy to be bound to the authorization value of the01bPolicy session handleNoneSHAUnauthen ticated

r Public Material – May be reproduced only in its original entirety (without revision).

Page 49
NameDescription authorized entityIndi cato rInputsOutputsSecu rity Func tionsSSP Access
TPM2_PolicyPassword (I)Allows a policy to be bound to the authorization value of the authorized object01bPolicy session handleNoneSHAUnauthen ticated
TPM2_PolicyGetDigest (I/E)Returns the current policyDigest of a policy session00bPolicy session handlePolicy digestNoneUnauthen ticated
TPM2_PolicyNvWritten (I)Allows a policy to be bound to the TPMA_NV_W RITTEN attributes01bPolicy session handle NV index written indicatorNoneSHAUnauthen ticated
TPM2_PolicyTemplate (I/D)Allows a policy to be bound to a specific creation template01bPolicy session handle Digest to add to policyNoneSHAUnauthen ticated
TPM2_PolicyAuthorize NV (I)Provides a capability that is the equivalent of a revocable policy01bSource handle for authoriza tion NV index to read Policy session handleNoneSHAUser (U)
TPM2_CreatePrimary (I/E/D)Creates a Primary Object under one of the Primary Seeds or a Temporary Object under TPM_RH_NUL L01bPrimary handle Key sensitive data Key public template Creation dataObject handle Object Public part Creation data Digest of creation data Creation ticket NameKey Gen KeyV er AES- ENC SigG en SigV erCrypto officer (CO) - objSeed: G,E,Z - objSymK ey: G,E,Z -

r Public Material – May be reproduced only in its original entirety (without revision).

Page 50
NameDescriptionIndi cato rInputsOutputsSecu rity Func tionsSSP Access
Creation PCRof the objectDRB G KBK DF MAC SHA CKG KAS- Key GenobjHmac Key: G,E,Z - objSens: G,E,Z - objPub: G,R,E,Z - tdrbgStat e: G,W,E,Z - drbgState : W,E - objAuth: W - nullSeed: E - phSeed: E - ehSeed: E - shSeed: E - nullProof: E - phProof: E - ehProof: E - shProof: E - ekRsa: E - ekEcc: E - shProofF orReseed : G,E

r e: G,W,E,Z : W,E W E E E E E E E E E E : G,E Public Material – May be reproduced only in its original entirety (without revision).

Page 51
NameDescriptionIndi cato rInputsOutputsSecu rity Func tionsSSP Access
TPM2_HierarchyContr ol (I)Enables and disables use of a hierarchy and its associated NV storage00bPrimary handle Hierarch y to enable or disable Enable or disable indicatorNoneNoneCrypto officer (CO)
TPM2_SetPrimaryPolic y (I/D)Sets the authorization policy for a hierarchy00bPrimary handle Policy digest Hash algorithmNoneNoneCrypto officer (CO)
TPM2_ChangePPS (I)Replaces the current platform primary seed (PPS) with a value from the RNG and sets platformPolicy to the default initialization value01bAuthoriz ation handleNoneDRB GCrypto officer (CO) - drbgState : W,E - phProof: Z - phSeed: Z - objSeed: Z - objSens: Z - objPub: Z
TPM2_ChangeEPS (I)Replaces the current endorsement primary seed EPS) with a value from the RNG and sets endorsementP olicy to the default01bAuthoriz ation handleNoneDRB GCrypto officer (CO) - drbgState : W,E - ehSeed: Z - ehProof:

r G Z Z Public Material – May be reproduced only in its original entirety (without revision).

Page 52
NameDescription initialization valueIndi cato rInputsOutputsSecu rity Func tionsSSP Access Z - objSeed: Z - objSens: Z - objPub: Z - ekRsa: Z - ekEcc: Z
TPM2_Clear (I)Removes all TPM context associated with a specific Owner01bAuthoriz ation handleNoneDRB GCrypto officer (CO) - drbgState : W,E - shSeed: Z - ehProof: Z - shProof: Z - shProofF orReseed : Z - objSeed: Z - objSens: Z - objPub: Z - objAuth: Z
TPM2_ClearControl (I)Disables and enables the execution of TPM2_Clear()00bAuthoriz ation handle Set or clear disableO wnerFlagNoneNoneCrypto officer (CO)

r Z Z Z Z Z : W,E Z Z G :Z Z Z Z Z Public Material – May be reproduced only in its original entirety (without revision).

Page 53
NameDescriptionIndi cato rInputsOutputsSecu rity Func tionsSSP Access
TPM2_HierarchyChan geAuth (I/D)Changes the authValue of hierarchies00bAuthoriz ation handle New authoriza tion valueNoneNoneCrypto officer (CO) - lockoutA uth: W - endorse mentAuth : W - ownerAut h: W - platformA uth: W
TPM2_DictionaryAttac kLockReset (I)Cancels the effect of a TPM lockout due to several successive authorization failures00bAuthoriz ation handleNoneNoneCrypto officer (CO)
TPM2_DictionaryAttac kParameters (I)Changes the lockout parameters00bAuthoriz ation handle newMax Tries, newRec overyTim e and lockoutR ecovery valuesNoneNoneCrypto officer (CO)
TPM2_VendorCmdFiel dUpgradeStart (I)Initiates a field upgrade session01bApprove dNoneSigV er KBK DF SHA CKGCrypto officer (CO) - fuSigEC CKey: E - fuSigLMS Key: E - fuSymKe y: G

r :W h: W y: G Public Material – May be reproduced only in its original entirety (without revision).

Page 54
NameDescriptionIndi cato rInputsOutputsSecu rity Func tionsSSP Access - fuSymSe ed: E
TPM2_VendorCmdFiel dUpgradeData (I)Conveys firmware in a field upgrade session01bField upgrade data blobCompletion indicatorAES- DEC SHAUnauthen ticated - fuSymKe y: E,Z
TPM2_ContextSaveSaves a session context, object context, or sequence object context outside the TPM01bSaved handleContextAES- ENC KTS KBK DF MAC CKGUnauthen ticated - contextE ncKey: G,E,Z - objSeed: R - objSens: R - objPub: R - objAuth: R - nullProof: E - phProof: E - ehProof: E - shProof: E - contextK ey: E - sesHmac Key: R - seqAuth: R
TPM2_ContextLoadReloads a context that01bContextLoaded handleAES- DECUnauthen ticated

r y: E,Z G,E,Z R R R E E R Public Material – May be reproduced only in its original entirety (without revision).

Page 55
NameDescriptionIndi cato rInputsOutputsSecu rity Func tionsSSP Access
has been saved by TPM2_Context Save()KTS KBK DF MAC CKG- contextE ncKey: G,E,Z - objSeed: W - objSens: W - objPub: W - objAuth: W - nullProof: E - phProof: E - ehProof: E - shProof: E - contextK ey: E - sesHmac Key: W - seqAuth: W
TPM2_FlushContextCauses all context associated with a loaded object, sequence object, or session to be removed from TPM memory01bFlush handleNoneUnauthen ticated - objSeed: Z - objSens: Z - objPub: Z - objAuth: Z

r W W W W E E E E W Z Public Material – May be reproduced only in its original entirety (without revision).

Page 56
NameDescriptionIndi cato rInputsOutputsSecu rity Func tionsSSP Access
TPM2_EvictControl (I)Allows certain Transient Objects to be made persistent or a persistent object to be evicted01bAuthoriz ation handle Loaded object handle Persiste nt handleNoneNoneCrypto officer (CO) - objSeed: W,Z - objSens: W,Z - objPub: W,Z - objAuth: W,Z
TPM2_ReadClock (I)Reads the current TPMS_TIME_I NFO structure00bNoneCurrent timeNoneUnauthen ticated
TPM2_ClockSet (I)Advances the value of the TPM's clock00bNew timeNoneNoneCrypto officer (CO)
TPM2_ClockRateAdjus t (I)Adjusts the rate of advance of Clock and Time00bAuthoriz ation handle Clock update rate adjustme ntNoneNoneCrypto officer (CO)
TPM2_GetCapability (I)Returns various information regarding the TPM and its current state00bCapabilit y, property, property countMore data availability indicator Capability dataNoneUnauthen ticated
TPM2_SetCapability (I/D)Set specific data in the TPM, such as TPM configurations, which may change the TPM's function and behavior00bCapabilit y dataNoneNoneCrypto officer (CO)
TPM2_TestParms (I)Checks if specific combinations00bAlgorith mNoneNoneUnauthen ticated

r W,Z W,Z W,Z W,Z Public Material – May be reproduced only in its original entirety (without revision).

Page 57
NameDescription of algorithm parameters are supportedIndi cato rInputs paramet ersOutputsSecu rity Func tionsSSP Access
TPM2_NV_DefineSpac e (I/D)Defines the attributes of an NV Index and causes the TPM to reserve space to hold the data associated with the NV Index01bAuthoriz ation handle NV authoriza tion value NV public paramet ersNoneNoneCrypto officer (CO) - nvAuth: W
TPM2_NV_UndefineSp ace (I)Removes an Index from the TPM01bAuthoriz ation handle NV index to deleteNoneNoneCrypto officer (CO) - nvAuth: Z
TPM2_NV_UndefineSp aceSpecial (I)Removal of a platform- created NV Index that has TPMA_NV_PO LICY_DELETE SET01bPlatform authoriza tion handle NV index to deleteNoneNoneCrypto officer (CO) - nvAuth: Z
TPM2_NV_ReadPublic (I/E)Reads the public area and Name of an NV Index01bNV indexNV index public area Name of the NV indexSHAUnauthen ticated
TPM2_NV_Write (I/D)Writes a value to an area in NV memory that was previously defined by TPM2_NV_Def ineSpace()00bAuthoriz ation handle NV index to write Data to write Offset in the NV index areaNoneNoneUser (U)
TPM2_NV_Increment (I)Increments the value in an NV Index that has the00bAuthoriz ation handle NV index toNoneNoneUser (U)

r Public Material – May be reproduced only in its original entirety (without revision).

Page 58
NameDescription TPM_NT_COU NTER attributeIndi cato rInputs incremen tOutputsSecu rity Func tionsSSP Access
TPM2_NV_Extend (I/D)Extends a value to an area in NV memory that was previously defined by TPM2_NV_Def ineSpace()01bAuthoriz ation handle NV index to extend Data to extendNoneSHAUser (U)
TPM2_NV_SetBits (I)Sets bits in an NV Index that was created as a bit field00bAuthoriz ation handle NV index to extend Data to OR with NV contentNoneNoneUser (U)
TPM2_NV_WriteLock (I)Inhibits further writes of the NV Index if the TPMA_NV_W RITEDEFINE or TPMA_NV_W RITE_STCLEA R attributes of an NV location are SET00bAuthoriz ation handle NV indexNoneNoneUser (U)
TPM2_NV_GlobalWrite Lock (I)Sets TPMA_NV_W RITELOCKED for all indexes that have their TPMA_NV_GL OBALLOCK attribute SET00bAuthoriz ation handleNoneNoneCrypto officer (CO)
TPM2_NV_Read (I/E)Reads a value from an area in NV memory previously defined by TPM2_NV_Def ineSpace()00bAuthoriz ation handle NV index to be read Size andData readNoneUser (U)

r Public Material – May be reproduced only in its original entirety (without revision).

Page 59
NameDescriptionIndi cato rInputs offset in NV areaOutputsSecu rity Func tionsSSP Access
TPM2_NV_ReadLock (I)Prevents further reads of the NV Index until the next TPM2_Startup (TPM_SU_CL EAR) if TPMA_NV_RE AD_STCLEAR is SET00bAuthoriz ation handle NV index to be lockedNoneNoneUser (U)
TPM2_NV_ChangeAut h (I/D)Allows the authValue of an NV Index to be changed01bNV index New authoriza tion valueNoneNoneUser (U) - nvAuth: W
TPM2_NV_Certify (I/E/D)Certifies the contents of an NV Index or portion of an NV Index01bHandle of signing key Authoriz ation handle NV index Qualifyin g data Scheme Size and offset in NV areaStructure that was signed SignatureSigG en KBK DF MAC SHAUser (U) - objSens: E - shProof: E
TPM2_VendorCmdSet Mode (I)Sets the low power mode00bAuthoriz ation handle Low power configura tion structureNoneNoneCrypto officer (CO)
TPM2_VendorCmdSet CommandSet (I)Activates and locks commands00bAuthoriz ation handle Comman d code Activatio n andNoneNoneCrypto officer (CO)

r Public Material – May be reproduced only in its original entirety (without revision).

Page 60
NameDescriptionIndi cato rInputs lock indicator sOutputsSecu rity Func tionsSSP Access
TPM2_VendorCmdSet CommandSetLock (I)Prevents locking commands00bAuthoriz ation handleNoneNoneCrypto officer (CO)
TPM2_VendorCmdGet Random2 (I/E)Get random value from DRBG01bNumber of bytes to generateRandom valueNoneUnauthen ticated - drbgState : W,E
TPM2_VendorCmdGPI OConfig (I)Configures GPIO00bAuthoriz ation handle GPIO configura tionNoneNoneUnauthen ticated
TPM2_VendorCmdGet Random800_90B (I/E)Get random value from ENT (P)01bNumber of bytes to generateRandom valueENT- ESVUnauthen ticated
TPM2_VendorCmdCha ngeObjectDeletionAuth (I)Modifies deletion authorization for an object00bAuthoriz ation handle Platform authoriza tion use indicatorNoneNoneCrypto officer (CO)
TPM2_VendorCmdRes toreEK (I)Restore EK RSA or EK ECC in case of deletion by TPM2_Change EPS01bAuthoriz ation handleNoneNoneCrypto officer (CO) - ekRsa: W - ekEcc: W
TPM2_VendorCmdZer oizeEK (I)Zeroize EK RSA and EK ECC01bAuthoriz ation handleNoneNoneCrypto officer (CO) - ekRsa: Z - ekEcc: Z
TPM2_VendorCmdSig nCauses the TPM to sign a message with the specified01bHandle of a signing keySignature over the messageSigG en DRBUser (U) - objSens: E

r s : W,E W Z Public Material – May be reproduced only in its original entirety (without revision).

Page 61
NameDescriptionIndi cato rInputsOutputsSecu rity Func tionsSSP Access
asymmetric signing keyMessage to be signed Context SchemeG SHA- objPub: E - nullProof: E - phProof: E - ehProof: E - shProof: E
TPM2_VendorCmdVeri fySignatureUses loaded keys to validate a signature on a message with the message digest passed to the TPM01bHandle of a public key Signed message Context Signatur e to be testedNoneSigV erUnauthen ticated - objPub: E - nullProof: E - phProof: E - ehProof: E - shProof: E
TPM2_VendorCmdSet BackgroundSlotsConfi gConfigure the RSA background key slots00bAuthoriz ation handle Slots configura tionNoneNoneCrypto officer (CO)
TPM2_PP_CommandsDetermines which commands require assertion of Physical Presence00bAuthoriz ation handle List of comman ds to add and list of comman d to removeNoneNoneCrypto officer (CO)

r E E E E E E E E Public Material – May be reproduced only in its original entirety (without revision).

Page 62
NameDescriptionIndi cato rInputsOutputsSecu rity Func tionsSSP Access
Integrity mechanism provided by sessionsThis service is not callable from TPM interface but is only used internally by any command and response with an authorization area. It consists in computing the integrity of the received command or transmitted response.01bComman d or responseIntegrity valueDRB G KBK DF MAC SHA CKGUnauthen ticated - sesHmac Key: E,Z
Encryption mechanism provided by sessionsThis service is not callable from TPM interface but is only used internally by any command and response with an encryption or decryption session. It consists in decrypting the first parameter of a received command or encrypting the first parameter of a transmitted response.01bComman d or responseEncrypted parameterAES- ENC AES- DEC DRB G KBK DF SHA CKGUnauthen ticated - sesSymK ey: G,E,Z

r Table 19: Approved Services Public Material – May be reproduced only in its original entirety (without revision).

Page 63

The integrity mechanism provided by sessions is not directly callable from the security module external interfaces. Function is used (or might be used) by the services listed in this table. When a service is usable with a session, (I) is added next to the service name. When a service can additionally use the encryption mechanism of a session, (I/E) is added next to the service name. The encryption mechanism provided by sessions is not directly callable from the security module external interfaces. Function is used (or might be used) by the services listed in this table. When a service is usable with a session, (I) is added next to the service name. When a service can additionally use the encryption mechanism of a session, (I/E) is added next to the service name. Public Material – May be reproduced only in its original entirety (without revision).

Page 64
NameDescriptionAlgorithmsRole
TPM2_Create; TPM2_CreateLoaded; TPM2_Load; TPM2_LoadExternalCreation or loading of an ECC key with a non-approved elliptic curve; Creation or loading of an ECC key for a non-approved key agreement usage; Creation or loading of an ECC signing key with an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL);Creation or loading of an RSA decryption key with an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL); Creation or loading of a 1024-bit RSA keyECC BN P-256 (non-compliant) RSA (non- compliant) X448 (non- compliant)User
TPM2_CreateLoadedDerivation of an ECC key from a derivation parent keyECC derived keys (non- compliant) KBKDF (non- compliant)User
TPM2_Load; TPM2_LoadExternalLoading of an ECC or RSA key (sensitive and public parts) in the NULL hierarchyECC BN P-256 (non-compliant) RSA (non- compliant)User
TPM2_Duplicate; TPM2_Rewrap; TPM2_ImportKey transport with a 1024-bit RSA key Key agreement scheme with a non-approved ECC curve Key agreement scheme with an ECC key used in a non-approved key agreement usageECC BN P-256 (non-compliant) KAS (non- compliant) RSA (non- compliant) X448 (non- compliant)User
TPM2_RSA_Encrypt; TPM2_RSA_DecryptKey transport with a non-approved scheme: * RSAES-PKCS1- v1_5 * RSA with no padding mode (null scheme) Key transport with an RSA decryption key: * Generated with an undeterminedKTS-IFC (non- compliant) RSA with noUser

All Approved services implemented by the Module are listed in the table below: Public Material – May be reproduced only in its original entirety (without revision).

Page 65
NameDescriptionAlgorithmsRole
scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL) * Loaded in the NULL hierarchypadding mode (null scheme) (non-compliant) RSAES- PKCS1-v1_5 (non-compliant)
TPM2_ECDH_KeyGenUse of a non-approved elliptic curve: * ECC key with curve BN P- 256 Use of an ECC key for a non-approved key agreement usage: * ECC key with curve Curve448ECC BN P-256 (non-compliant) X448 (non- compliant)N/A
TPM2_ECDH_ZGenUse of an ECC key: * Generated on curve BN P-256 * For a non- approved key agreement usage * Derived from a derivation parent key * Loaded in the NULL hierarchyECC BN P-256 (non-compliant) X448 (non- compliant) KBKDF (non- compliant)User
TPM2_ZGen_2PhaseThis command is only usable jointly with TPM2_EC_Ephemeral service that is non approved as using key derivation to generate ECC keysECC derived keys (non- compliant) KBKDF (non- compliant)User
TPM2_HMACHMAC generation with a key length < 112 bitsHMAC (non- compliant)User
TPM2_HMAC_Start; TPM2_SequenceUpdate; TPM2_SequenceCompleteHMAC generation with a key length < 112 bitsHMAC (non- compliant)User
TPM2_Certify; TPM2_CertifyCreation; TPM2_Quote; TPM2_GetSessionAuditDigest; TPM2_GetCommandAuditDigest; TPM2_GetTime; TPM2_CertifyX509Digital signature with a non-approved signature scheme: * ECC signature with ECDAA signature scheme * ECC signature with ECSchnorr signature scheme * RSA signature with key length of 1024 bits * ECC or RSA signature key using SHA-1 as digest method * ECC signature with curve BN P-256; Digital signature with an ECC signing key generated with an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL); Digital signature with an ECC signing keyECC BN P-256 (non-compliant) ECDAA (non- compliant) ECDSA (non- compliant) ECSchnorr (non-compliant)User/CO

Public Material – May be reproduced only in its original entirety (without revision).

Page 66
NameDescriptionAlgorithmsRole
derived from a derivation parent key; Digital signature with an ECC or RSA key loaded in the NULL hierarchyRSA (non- compliant) SHA-1 (non- compliant)
TPM2_CommitGeneration of an ECC key through key derivation methodKBKDF (non- compliant)User
TPM2_EC_EphemeralGeneration of an ECC key through key derivation methodKBKDF (non- compliant)User
TPM2_VerifySignatureDigital signature verification with a non-approved signature scheme or a non-approved curve: * ECDAA signature scheme * ECSchnorr signature scheme * ECC signature with curve BN P- 256ECC BN P-256 (non-compliant) ECDAA (non- compliant) ECSchnorr (non-compliant)NA
TPM2_SignDigital signature generation with a non-approved signature scheme: * ECC signature with ECDAA signature scheme * ECC signature with ECSchnorr signature scheme * RSA signature with key length of 1024 bits * ECC or RSA signature key using SHA-1 as digest method * ECC signature with curve BN P-256; Digital signature with an ECC signing key generated with an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL); Digital signature with an ECC signing key derived from a derivation parent key; Digital signature with an ECC or RSA key loaded in the NULL hierarchyECC BN P-256 (non-compliant) ECDAA (non- compliant) ECDSA (non- compliant) ECSchnorr (non-compliant) RSA (non- compliant) SHA-1 (non- compliant)User
TPM2_PolicySignedDigital signature verification with a non-approved signature scheme or a non-approved curve: * ECDAA signature scheme * ECSchnorr signature scheme * ECC signature with curve BN P- 256ECC BN P-256 (non-compliant) ECDAA (non- compliant) ECSchnorr (non-compliant)N/A
TPM2_CreatePrimaryCreation and loading of an ECC key with a non-approved elliptic curve: * ECC key with curve BN P-256 Use of an ECC key for aECC BN P-256 (non-compliant)CO

Public Material – May be reproduced only in its original entirety (without revision).

Page 67
NameDescriptionAlgorithmsRole
non-approved key agreement usage: * ECC key with curve Curve448 Creation and loading of an ECC signing key with an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL) Creation and loading of an RSA decryption key with an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL)X448 (non- compliant)
TPM2_NV_CertifyDigital signature with a non-approved signature scheme: * ECC signature with ECDAA signature scheme * ECC signature with ECSchnorr signature scheme * RSA signature with key length of 1024 bits * ECC or RSA signature key using SHA-1 as digest method * ECC signature with curve BN P-256; Digital signature with an ECC signing key generated with an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL); Digital signature with an ECC key derived from a derivation parent key; Digital signature with an ECC or RSA key loaded in the NULL hierarchyECC BN P-256 (non-compliant) ECDAA (non- compliant) ECDSA (non- compliant) ECSchnorr (non-compliant) RSA (non- compliant) SHA-1 (non- compliant)User

Table 20: Non-Approved Services Public Material – May be reproduced only in its original entirety (without revision).

Page 68
4.5 External Software/Firmware Loaded

Loading of firmware onto the Module can be achieved by using two services:

Page 69
5 Software/Firmware Security
5.1 Integrity Techniques

The Module is composed of the following firmware component(s):

5.2 Initiate on Demand

The operator can initiate the integrity test on demand by using the TPM2_SelfTest command with the full parameter set to YES or by using the TPM2_IncrementalSelfTest command. Public Material – May be reproduced only in its original entirety (without revision).

Page 70
6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Limited The operational environment of the Module is “limited” because it allows loading authenticated firmware that meets all applicable requirements of [140-3] standard. Data outputs are inhibited until the loading session has completed successfully. Execution of the successfully loaded FW is only effective after the next reset of the security module. New firmware versions must be validated through the FIPS 140-3 validation process. Any other firmware loaded into this module is out of the scope of this validation and requires a separate FIPS 140-3 validation. The core memory loader (CML) represented in Figure 8 is non-modifiable, only the TPM instances are modifiable by using an authenticated firmware upgrade mechanism. The security module contains two instances of the FW but only one FW instance is executed after a boot sequence. Public Material – May be reproduced only in its original entirety (without revision).

Page 71
MechanismInspection FrequencyInspection Guidance
Hard opaque packageDependent on the security module integration environment varies from once per month to once per yearVisual inspection of the package to confirm that it has not been damaged by an external action
7 Physical Security

The security module is production grade and meets the Physical Security protection requirements for single-chip module at FIPS 140-3 Level 3.

7.1 Mechanisms and Actions Required

Zeroization Zeroization of CSPs can be triggered by specific services as detailed in Section 9.3. It occurs in a sufficiently small time-period to prevent the recovery of the sensitive data between start of zeroization and the zeroization completion. Physical security mechanisms The security module is encapsulated in a hard opaque package to prevent direct observation of internal security components. It implements additional security mechanisms:

7.2 EFP/EFT Information

EFT has been performed for all security module configurations. Low and high temperatures have been measured at a nominal voltage of 3.3V. Low and high voltage have been measured at ambient temperature (25°C). The nominal operating ranges are:

Page 72
Temp/Voltage TypeTemperature or VoltageEFP or EFTResult
LowTemperature-77°C (ST33KTPM2A in UFQFPN32 WF); -70 (ST33KTPM2I in UFQFPN32 WF); -70 (ST33KTPM2A in TSSOP20); -75 (ST33KTPM2I in WLCSP24)EFTShutdown
HighTemperature165°C (ST33KTPM2A in UFQFPN32 WF); 160 (ST33KTPM2I in UFQFPN32 WF); 145 (ST33KTPM2A in TSSOP20); 160 (ST33KTPM2I in WLCSP24)EFTShutdown
LowVoltage1.4VEFTShutdown
HighVoltage4.3VEFTShutdown

Table 22: EFP/EFT Information Public Material – May be reproduced only in its original entirety (without revision).

Page 73
Temperature TypeTemperature
LowTemperature-40°C
HighTemperature105°C
7.3 Hardness Testing Temperature Ranges

Hardness testing was conducted at the temperature indicated in the table below: Table 23: Hardness Testing Temperatures Public Material – May be reproduced only in its original entirety (without revision).

Page 74
8 Non-Invasive Security
8.1 Mitigation Techniques

The Module does not claim support of non-invasive attack mitigation techniques referenced in [140F]. Public Material – May be reproduced only in its original entirety (without revision).

Page 75
Storage Area NameDescriptionPersistence Type
Dynamic RAMVolatile memory used to store SSPs between two consecutive resets or power-on/power-off sequence of the security module. SSPs don't persist after command execution. This area is marked as RAM on the HW block diagram.Dynamic
Static RAMVolatile memory used to store SSPs between two consecutive resets or power-on/power-off sequence of the security module. SSPs persist after command execution. This area is marked as RAM on the HW block diagram.Static
NVRAMNon-volatile memory (flash-based) used to store SSPs and make them persistent to a reset or a power-off/power-on sequence of the security module. This area is marked as flash memory on the HW block diagram.Static
NameFromToFormat TypeDistribution TypeEntry TypeSFI or Algorithm
Input plaintext to NVRAMOutside of cryptographi c boundaryNVRAMPlaintextManualElectronic
Input protected to NVRAMOutside of cryptographi c boundaryNVRAMEncryptedManualElectronicKTS
Input plaintext to RAMOutside of cryptographi c boundaryStatic RAMPlaintextManualElectronic
Input protected to RAMOutside of cryptographi c boundaryStatic RAMEncryptedManualElectronicKTS
Output plaintext from NVRAMNVRAMOutside of cryptographic boundaryPlaintextManualElectronic
Output protected from NVRAMNVRAMOutside of cryptographic boundaryEncryptedManualElectronicKTS
9 Sensitive Security Parameters Management
9.1 Storage Areas
9.2 SSP Input-Output Methods

Public Material – May be reproduced only in its original entirety (without revision).

Page 76
NameFromToFormat TypeDistribution TypeEntry TypeSFI or Algorithm
Output plaintext from RAMStatic RAMOutside of cryptographic boundaryPlaintextManualElectronic
Output protected from RAMStatic RAMOutside of cryptographic boundaryEncryptedManualElectronicKTS
Input asym. encrypte d to RAMOutside of cryptographi c boundaryStatic RAMEncryptedManualElectronicKTS-IFC
Output asym. encrypte d to RAMStatic RAMOutside of cryptographic boundaryEncryptedManualElectronicKTS-IFC

Table 25: SSP Input-Output Methods Public Material – May be reproduced only in its original entirety (without revision).

Page 77
Zeroization MethodDescriptionRationaleOperator Initiation
TPM2_InitZeroization of all volatile SSPs. Explicit zeroization indicator provided by service completion status.N/AActivation of reset signal
TPM2_ClearZeroization of all contexts associated with an Owner. Explicit zeroization indicator provided by service completion status.SSPs linked to an Owner must not persist if the Owner changesSend TPM2_Clear command
TPM2_StartupZeroization of platformAuth. Explicit zeroization indicator provided by service completion status.Zeroize platformAuth before its first use after a resetSend TPM2_Startup command
TPM2_ChangePPSZeroize the platform primary seed and flush all transient and persistent objects in the Platform hierarchy. Explicit zeroization indicator provided by service completion status.Platform hierarchy renewalSend TPM2_ChangePPS command
TPM2_ChangeEPSZeroize the endorsement primary seed and flush all transient and persistent objects in the Endorsement hierarchy. Explicit zeroization indicator provided by service completion status.Endorsement hierarchy renewalSend TPM2_ChangeEPS command
TPM2_EvictControlZeroize an object from NVRAM. Explicit zeroization indicator provided by service completion status.Method required to zeroize a dedicated object in NVRAMSend TPM2_EvictControl command
TPM2_FlushContextZeroize an object from RAM. Explicit zeroization indicator provided by service completion status.Method required to zeroize a dedicated object in RAMSend TPM2_FlushContext command
AutomaticZeroize SSPs at the end of a command processing. Implicit zeroization indication.Method for limited life cycle SSPsNo, zeroization is automatic.
TPM2_NV_UndefineSpace TPM2_NV_UndefineSpaceSpecialZeroize a NV index. Explicit zeroization indicator provided by service completion status.Method required to flush NV indices from NVRAMSend TPM2_NV_UndefineSpace command. Send TPM2_NV_UndefineSpaceSpecial command
TPM2_VendorCmdZeroizeEKZeroize the endorsement key provisioned. Explicit zeroization indicator provided by service completion status.Mandatory zeroization method for EK SSPsSend TPM2_VendorCmdZeroizeEK command
TPM2_SequenceComplete TPM2_EventSequenceCompleteZeroize a hash or HMAC sequence. Explicit zeroization indicator provided by service completion status.Method required to flush sequences from RAMSend TPM2_SequenceComplete command. Send TPM2_EventSequenceComplete command
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
nullProofProof (secret value) of the null hierarchy512 - 256Symmetric key - CSPDRBGKBKDF MAC
phProofProof (secret value) of the platform hierarchy512 - 256Symmetric key - CSPDRBGMAC
ehProofProof (secret value) of the endorsement hierarchy512 - 256Symmetric key - CSPDRBGMAC
shProofProof (secret value) of the storage hierarchy512 - 256Symmetric key - CSPDRBGKBKDF MAC
shProofForReseedRandom value512 - 256Entropy source - CSPENT-ESVDRBG
platformAuthAuthentication value for the platform hierarchy512 - 128 to 256 (depending on the underlying hash algorithm used)Authentication value / Symmetric key - CSPKBKDF MAC
endorsementAuthAuthentication value for the endorsement hierarchy512 - 128 to 256 (depending on the underlying hash algorithm used)Authentication value / Symmetric key - CSPKBKDF MAC
9.3 SSP Zeroization Methods

Table 26: SSP Zeroization Methods All usage of these SSPs by the Module are described in the services detailed in section 4. The next table lists the SSPs used as keys. Temporary storage duration column was removed for readability purposes because when temporary storage is indicated, duration corresponds to the duration of a command execution. The algorithms indicated in “Generate by” and “Used by” columns correspond to items in the SFI table. Public Material – May be reproduced only in its original entirety (without revision).

Page 78
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
ownerAuthAuthentication value for the storage hierarchy512 - 128 to 256 (depending on the underlying hash algorithm used)Authentication value / Symmetric key - CSPKBKDF MAC
lockoutAuthAuthentication value for the lockout hierarchy512 - 128 to 256 (depending on the underlying hash algorithm used)Authentication value / Symmetric key - CSPKBKDF MAC
objSeedSeed value for object generation512 - 128 to 256Data, Symmetric key - CSPDRBG KBKDFKBKDF SHA
objAuthObject's authorization value112 to 512 - 112 to 256Authentication value / Symmetric key - CSPKBKDF MAC
objSymKeyEncryption key of object private part256 - 256Symmetric key - CSPKBKDFAES- ENC AES- DEC
objHmacKeyIntegrity key of object private part160, 256, 384, 512 - 128 to 256Symmetric key - CSPKBKDFMAC
objSensObject private part2048, 3072, 4096 (RSA); 128, 192, 256 (AES); 256, 384, 521 (ECC); 448 (EdDSA); 112 to 1024 (HMAC) - 112 to 256Symmetric or asymmetric private key - CSPKeyGen KBKDF CKG KAS-KeyGenAES- ENC AES- DEC SigGen KAS KBKDF MAC
objPubObject public part2048, 3072, 4096 (RSA); 512, 768, 1056 (ECC); 448 (EdDSA) - 112 to 256Asymmetric public key - PSPKeyGen KAS-KeyGenSigVer KAS KTS- IFC
nvAuthAuthorization of NV index112 to 512 - 112 to 256Authentication value / Symmetric key - CSPKBKDF MAC
sesSaltSalt for keys diversification160, 256, 384, 512 - 128 to 256Symmetric key - CSPN/AKASKBKDF
sesHmacKeyHMAC session key160, 256, 384, 512 - 128 to 256Symmetric key - CSPKBKDFKBKDF MAC
sesSymKeyEncrypted session key128, 192, 256 - 128 to 256Symmetric key - CSPKBKDFAES- ENC AES- DEC
contextKeyDerivation key for context protection128 - 128Symmetric key - CSPDRBGKBKDF
contextEncKeyWrapping key for context protection256 - 256Symmetric key - CSPKBKDFAES- ENC AES- DEC
dupInSymKeyWrapping key for duplicated object128, 192, 256 - 128 to 256Symmetric key - CSPDRBGAES- ENC AES- DEC
dupSeedSeed for protection keys derivation160 to 512 - 128 to 256Symmetric key - CSPDRBG KASKASKBKDF
dupOutSymKeyEncryption key for duplicated objects128, 192, 256 - 128 to 256Symmetric key - CSPKBKDFAES- ENC AES- DEC
dupOutHmacKeyHMAC key for duplicated objects160, 256, 384, 512 - 128 to 256Symmetric key - CSPKBKDFMAC
creSeedSeed for credential keys derivation160 to 512 - 128 to 256Symmetric key - CSPKASKBKDF

Public Material – May be reproduced only in its original entirety (without revision).

Page 79
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
creSymKeyEncryption key for credentials128, 192, 256 - 128 to 256Symmetric key - CSPKBKDFAES- ENC AES- DEC
creHmacKeyHMAC key for credentials160, 256, 384, 512 - 128 to 256Symmetric key - CSPKBKDFMAC
ephSensEccKeyECC ephemeral private key256, 384, 521 - 128 to 256ECC private key - CSPKAS-KeyGenKAS
ephPubEccKeyECC ephemeral public key512, 768, 1056 - 128 to 256ECC public key - PSPKAS-KeyGenKAS
ekRsaProvisioned RSA endorsement key2048 - 112RSA private key - CSPInput during manufacturingKTS- IFC
ekEccProvisioned ECC endorsement key256, 384 - 128 to 192ECC private key - CSPInput during manufacturingKAS
fuSigECCKeyField upgrade ECC signature verification key384 - 192ECC public key - PSPInput during manufacturingSigVer
fuSigLMSKeyField upgrade LMS signature verification key32 - 128LMS public key - PSPInput during manufacturingSigVer
seqAuthAuthorization value for hash or HMAC sequence112 to 512 - 112 to 256Authentication value / Symmetric key - CSPN/AKBKDF MAC
nullSeedSeed of the null hierarchy512 - 256Seed - CSPENT-ESVDRBG
phSeedSeed of the platform hierarchy512 - 256Seed - CSPENT-ESVDRBG
ehSeedSeed of the endorsement hierarchy512 - 256Seed - CSPENT-ESVDRBG
shSeedSeed of the storage hierarchy512 - 256Seed - CSPENT-ESVDRBG
drbgStateInternal state (V and C secret values) of the DRBG (based on SHA256)256 - 256State - CSPDRBGDRBG
drbgSeedSeed value for the DRBG512 - 256Seed - CSPENT-ESVDRBG
tdrbgStateInternal state (V and C secret values) of the transient DRBG (based on SHA256) used to generate prime numbers for primary RSA keys256 - 256State - CSPDRBGDRBG
fuSymSeedSeed used for field upgrade symmetric key derivation256 - 256Symmetric key - NeitherInput during manufacturingKBKDF
fuSymKeyfield upgrade symmetric key256 - 256Symmetric key - NeitherKBKDFAES- DEC
diagSymSeedSeed used for diagnostic symmetric key derivation256 - 256Symmetric key - NeitherInput during manufacturingKBKDF
diagSymKeydiagnostic symmetric key256 - 256Symmetric key - NeitherKBKDFAES- ENC
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
nullProofStatic RAM:PlaintextUntil next resetTPM2_InitdrbgState:Generates contextEncKey:Derived From
phProofNVRAM:PlaintextAfter UseTPM2_ChangePPSdrbgState:Generates contextEncKey:Derived From
ehProofNVRAM:PlaintextAfter UseTPM2_ChangeEPS TPM2_CleardrbgState:Generates contextEncKey:Derived From
shProofNVRAM:PlaintextAfter UseTPM2_CleardrbgState:Generates contextEncKey:Derived From
shProofForReseedNVRAM:PlaintextAfter UseTPM2_CleartdrbgState:Reseeded From
platformAuthInput plaintext to RAM Input protected to RAMStatic RAM:PlaintextUntil next resetTPM2_InitsesSymKey:Derived from, Protects (Encrypts) sesHmacKey:Derived from, Protects (Integrity)

Table 27: SSP Table 1 Public Material – May be reproduced only in its original entirety (without revision).

Page 80
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
endorsementAuthInput plaintext to NVRAM Input protected to NVRAMNVRAM:PlaintextAfter UseTPM2_Clear TPM2_ChangeEPSsesHmacKey:Derived from, Protects (Integrity) sesSymKey:Derived from, Protects (Encrypts)
ownerAuthInput plaintext to NVRAM Input protected to NVRAMNVRAM:PlaintextAfter UseTPM2_ClearsesHmacKey:Derived from, Protects (Integrity) sesSymKey:Derived from, Protects (Encrypts)
lockoutAuthInput plaintext to NVRAM Input protected to NVRAMNVRAM:PlaintextAfter UseTPM2_ClearsesHmacKey:Derived from, Protects (Integrity) sesSymKey:Derived from, Protects (Encrypts)
objSeedInput protected to RAM Input plaintext to RAM Output protected from RAM Output protected from NVRAMStatic RAM:Plaintext NVRAM:PlaintextUntil object zeroization, shift to NVRAM or next resetTPM2_Init TPM2_Clear TPM2_ChangePPS TPM2_ChangeEPS TPM2_EvictControl TPM2_FlushContexttdrbgState:Derived From drbgState:Derived From objSymKey:Derived From objHmacKey:Derived From sesHmacKey:Protects (Integrity) sesSymKey:Protects (Encrypts)
objAuthInput plaintext to RAM Input protected to RAM Output protected from RAM Output protected from NVRAMStatic RAM:Plaintext NVRAM:PlaintextUntil object zeroization, shift to NVRAM or next resetTPM2_Init TPM2_Clear TPM2_ChangePPS TPM2_ChangeEPS TPM2_EvictControl TPM2_FlushContextsesHmacKey:Derived from, Protects (Integrity) sesSymKey:Derived from, Encrypts
objSymKeyDynamic RAM:Plaintext NVRAM:PlaintextAfter UseAutomaticobjAuth:Encrypted by objSens:Encrypted by objSeed:Encrypted by
objHmacKeyDynamic RAM:Encrypted NVRAM:PlaintextAfter UseAutomaticobjAuth:Protected by (Integrity) objSens:Protected by (Integrity) objSeed:Protected by (Integrity)
objSensInput plaintext to RAM Input protected to RAM Output protected from RAM Output protected from NVRAMStatic RAM:Plaintext NVRAM:PlaintextUntil object zeroization, shift to NVRAM or next resetTPM2_Init TPM2_Clear TPM2_ChangePPS TPM2_ChangeEPS TPM2_EvictControl TPM2_FlushContexttdrbgState:Generates drbgState:Generates objSens:Derives objSymKey:Encrypts objHmacKey:Protects (Integrity) objPub:Paired With
objPubInput plaintext to RAM Output plaintext from NVRAM Output plaintext from RAMStatic RAM:Plaintext NVRAM:PlaintextUntil object zeroization, shift to NVRAM or next resetTPM2_Init TPM2_Clear TPM2_ChangePPS TPM2_ChangeEPS TPM2_EvictControl TPM2_FlushContextobjSens:Paired With
nvAuthInput plaintext to NVRAM Input protected to NVRAMNVRAM:PlaintextAfter UseTPM2_NV_UndefineSpace TPM2_NV_UndefineSpaceSpecialsesHmacKey:Derived from, Protects (Integrity) sesSymKey:Encrypts
sesSaltInput asym. encrypted to RAMDynamic RAM:PlaintextAfter UseAutomaticsesHmacKey:Derived From objPub:Encrypts
sesHmacKeyInput protected to RAM Output protected from RAMDynamic RAM:PlaintextAfter UseAutomaticnvAuth:Derives; Protected by (Integrity) contextKey:Encrypts contextEncKey:Encrypts platformAuth:Protected by (Integrity) endorsementAuth:Protected by

Public Material – May be reproduced only in its original entirety (without revision).

Page 81
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
(Integrity) ownerAuth:Protected by (Integrity) lockoutAuth:Protected by (Integrity) objAuth:Protected by (Integrity) seqAuth:Protected by (Integrity) dupInSymKey:Protected by (Integrity) dupSeed:Protected by (Integrity) creSeed:Protected by (Integrity)
sesSymKeyDynamic RAM:PlaintextAfter UseAutomaticsesHmacKey:Derives platformAuth:Derives; Encrypts endorsementAuth:Derives; Encrypts ownerAuth:Derives; Encrypts lockoutAuth:Derives; Encrypts objAuth:Derives; Encrypts seqAuth:Derives; Encrypts nvAuth:Derives; Encrypts dupInSymKey:Encrypted by
contextKeyStatic RAM:PlaintextUntil next resetTPM2_InitdrbgState:Generates contextEncKey:Derived From
contextEncKeyDynamic RAM:PlaintextAfter UseAutomaticcontextKey:Derives nullProof:Derives phProof:Derives ehProof:Derives shProof:Derives
dupInSymKeyInput plaintext to RAM Input protected to RAM Output plaintext from RAM Output protected from RAMDynamic RAM:PlaintextAfter UseAutomaticsesSymKey:Encrypts sesHmacKey:Protects (Integrity) objSens:Encrypted by
dupSeedInput asym. encrypted to RAM Output asym. encrypted to RAMDynamic RAM:PlaintextAfter UseAutomaticobjPub:Encrypts dupOutSymKey:Derived from dupOutHmacKey:Derived from
dupOutSymKeyDynamic RAM:PlaintextAfter UseAutomaticdupSeed:Derives objSens:Encrypted by objAuth:Encrypted by objSeed:Encrypted by
dupOutHmacKeyDynamic RAM:PlaintextAfter UseAutomaticdupSeed:Derives objSens:Protects (Integrity) objAuth:Protects (Integrity) objSeed:Protects (Integrity)
creSeedInput asym. encrypted to RAM Output asym. encrypted to RAMDynamic RAM:PlaintextAfter UseAutomaticcreSymKey:Derives creHmacKey:Derives objPub:Encrypts
creSymKeyDynamic RAM:PlaintextAfter UseAutomaticcreSeed:Derived From
creHmacKeyDynamic RAM:PlaintextAfter UseAutomaticcreSeed:Derived From
ephSensEccKeyDynamic RAM:PlaintextAfter UseAutomaticdrbgState:Generates

Public Material – May be reproduced only in its original entirety (without revision).

Page 82
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
ephPubEccKeyInput plaintext to RAM Output plaintext from RAMDynamic RAM:PlaintextAfter UseAutomaticephSensEccKey:Derives
ekRsaNVRAM:PlaintextAfter UseTPM2_VendorCmdZeroizeEKobjSens:Derived From
ekEccNVRAM:PlaintextAfter UseTPM2_VendorCmdZeroizeEKobjSens:Derived From
fuSigECCKeyNVRAM:PlaintextAfter UseN/A
fuSigLMSKeyNVRAM:PlaintextAfter UseN/A
seqAuthInput plaintext to RAM Input protected to RAM Output protected from RAMNVRAM:PlaintextUntil use of zeroization command or next resetTPM2_SequenceComplete TPM2_EventSequenceCompletesesSymKey:Derived From sesHmacKey:Derived From
nullSeedStatic RAM:PlaintextUntil next resetTPM2_InittdrbgState:Instantiated with
phSeedNVRAM:PlaintextAfter UseTPM2_ChangePPStdrbgState:Instantiated with
ehSeedNVRAM:PlaintextAfter UseTPM2_ChangeEPStdrbgState:Instantiated with
shSeedNVRAM:PlaintextAfter UseTPM2_CleartdrbgState:Instantiated with
drbgStateStatic RAM:PlaintextUntil next reset or use of TPM2_ClearTPM2_Init TPM2_CleardrbgSeed:Instantiates
drbgSeedDynamic RAM:PlaintextAfter UseAutomaticdrbgState:Instantiated with
tdrbgStateDynamic RAM:PlaintextAfter UseAutomaticnullSeed:Instantiates phSeed:Instantiates ehSeed:Instantiates shSeed:Instantiates
fuSymSeedNVRAM:PlaintextAfter UseN/AfuSymKey:Derived From
fuSymKeyDynamic RAM:PlaintextAfter UseAutomaticfuSymSeed:Derives
diagSymSeedNVRAM:PlaintextAfter UseN/AdiagSymKey:Derived From
diagSymKeyDynamic RAM:PlaintextAfter UseAutomaticdiagSymSeed:Derives
9.5 Transitions

The use of SHA-1 for digital signature generation is non-Approved and only available through non-Approved services. All other applications of SHA-1 are acceptable, where collision resistance is not required. Public Material – May be reproduced only in its original entirety (without revision).

Page 83
AlgorithmUnderlying algorithmKey size (bits)Security strength (bits)
KBKDFSHA-1size ≥ 128128
size < 128Key size
SHA2-256size ≥ 192192
size < 192Key size
SHA2-384 SHA2-512size ≥ 256256
size < 256Key size
HMACSHA-1size ≥ 128128
size < 128Key size
SHA2-256size ≥ 192192
size < 192Key size
SHA2-384 SHA2-512size ≥ 256256
size < 256Key size
DRBGSHA2-256-256
AES-128 / 192 / 256128 / 192 / 256
RSA-2048 / 3072 / 4096112 / 128 / 142
ECC-256 / 384 / 448 / 521128 / 192 / 224 / 256

The next table gives the security strength of a key depending on the underlying algorithm used and its Table 29

Page 84
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
Firmware integrity testCRC 16EDCSW/FW IntegritySuccessful execution of TPM2_Startup command indicates tests have been runFW integrity is verified by computing an EDC (CRC-16 [ISO13239]) and comparing it to reference values.
HW integrityHW registers verificationKATCritical FunctionSuccessful execution of TPM2_Startup command indicates tests have been runHW integrity is guaranteed via check of HW sensors. If failure is detected during boot sequence, status is set to FAIL, and error is returned.
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-CBC (A5356) EncryptAES-128-CBCKATCASTBit #7 clearAES CBC 128 encryption of known data compared to a reference value.Power On
AES-CBC (A5356) DecryptAES-128-CBCKATCASTBit #7 clearAES CBC 128 decryption of known encrypted data and comparison to the expected plaintext dataPower On
ECDSA KeyGen (FIPS186-4) (A5358)P-256, P-384, P-521PCTPCTKey creation failureDepending on the key purpose (signing or key establishment) an ECDSA signature is generated (k fixed and the message varies) and verified with pairwise consistency test as defined by [56Ar3] or a scalar multiplication is done and compared to the public key.Upon ECC Key Generation
ECDSA SigGen (FIPS186-4) (A5358)NIST P-256KATCASTBit #10 clearECDSA signature generation on known data with known key and k. Output of signature is compared to a reference signature.Power On
ECDSA SigVer (FIPS186-4) (A5358)NIST P-256KATCASTBit #10 clearECDSA signature verification on known signature with known key and k.Power On
EntropyRCT and APT[90B] Health- TestCASTBit #1 clearAIS31 and [90B] (RCT and APT) start-up health tests on ENT(P) output sequence. If test fails, test status is set to FAIL, and error is returnedAt each random bits generation
Firmware loadingECDSA P-384 and LMSSignature VerificationSW/FW LoadError returned on FW loading commandVerification of chained digest and signature to ensure authentication of the FWUpon firmware load
Hash DRBG (A5351)SHA2-256KATCASTBit #1 clearInstantiate then Reseed are seeded with a known seed value (64 bytes). Random is then generated with Generate API to output a 32-bytes value compared to a reference value (single test sequence done in accordance with §11.3 of [90A])Power On
HMAC-SHA-1 (A5355)HMAC-SHA1KATCASTBit #5 clearHMAC on known data and known key. Comparison of output to an expected MAC value (20 bytes)Power On
KAS-ECC Sp800-56Ar3 (A5358)NIST P-256KATCASTBit #9 clearPrimitive "Z" Computation and key derivation are implemented: a known private key d is used with a known point P of NIST P-256 curve to compute Q = dP. Key derivation of Q performed with SHA-1 underlying algorithm to output a key of 20 bytes that is compared to a refence valuePower On
KDF SP800-108 (A5354)N/AKATCASTBit #6 clearKDF on known data and known label. Comparison of output to an expected derivation value (32 bytes)Power On
10.1 Pre-Operational Self-Tests

The Module performs self-tests to ensure the proper operation of the Module. Per FIPS 140-3 these are categorized as either pre-operational self-tests or conditional self-tests. Pre-operational self–tests are available on demand by power cycling the Module. The Module performs the following pre-operational self-tests in the table below: Table 30: Pre-Operational Self-Tests

10.2 Conditional Self-Tests

The Module performs the following conditional self-tests as shown in the table below. The bit index indicated in the “Indicator” column corresponds to the index in the algo_status field in the TPM2_GetTestResult response. Public Material – May be reproduced only in its original entirety (without revision).

Page 85
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
LMS SigVer (A5360)LMOTS_SHA256_N32_W4 LMS_SHA256_M32_H10KATCASTBit #8 clearLMS signature verification of known signature with known data and known key.Power On
RSA SigGen (FIPS186-5) (A5357)RSASSA-PKCS1-v1_5KATCASTBit #12 clearRSA signature generation on known data with a known key. Output of signature is compared to a reference signature (covers also KTS-IFC functionality)Power On
RSA SigVer (FIPS186-5) (A5357)RSASSA-PKCS1-v1_5KATCASTBit #12 clearRSA signature verification on a known signature with a known key (covers also KTS-IFC functionality)Power On
RSA KeyGen (FIPS186-5) (A5357)2048, 3072 or 4096-bitPCTPCTKey creation failureDepending on the key purpose (signing or encrypting) indicated in sign attribute of the key, encryption/decryption or signing/verification is done on known dataUpon RSA Key Generation
SHSSHA1, SHA2-256, SHA2-512, SHA3-256KATCASTBit #2 clear Bit #3 clear Bit #4 clearHash of known data and comparison of output to an expected digest. SHA-1, SHA2-256, SHA2-512 are tested twice to cover each of the two implementations covered by CAVP Cert. #A5352 and #A5353.Power On
EDDSA SigGen (A5359)Ed448KATCASTBit #11 clearEdDSA signature generation on known data with known key. Output of signature is compared to a reference signature.Power-On
EDDSA SigVer (A5359)Ed448KATCASTBit #11 clearSignature verification performed on the generated signaturePower-On
EDDSA KeyGen (A5359)Ed448PCTPCTKey creation failureAn EdDSA signature is generated and verified with pairwise consistency test.Upon EdDSA Key Generation

Table 31: Conditional Self-Tests Public Material – May be reproduced only in its original entirety (without revision).

Page 86
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
Firmware integrity testEDCSW/FW IntegrityOn demandManually
HW integrityKATCritical FunctionOn demandManually
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-CBC (A5356) EncryptKATCASTOn DemandManually
AES-CBC (A5356) DecryptKATCASTOn DemandManually
ECDSA KeyGen (FIPS186-4) (A5358)PCTPCTN/AManually
ECDSA SigGen (FIPS186-4) (A5358)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-4) (A5358)KATCASTOn DemandManually
Entropy[90B] Health- TestCASTOn DemandManually
Firmware loadingSignature VerificationSW/FW LoadOn DemandManually
Hash DRBG (A5351)KATCASTOn DemandManually
HMAC-SHA-1 (A5355)KATCASTOn DemandManually
KAS-ECC Sp800-56Ar3 (A5358)KATCASTOn DemandManually
KDF SP800-108 (A5354)KATCASTOn DemandManually
LMS SigVer (A5360)KATCASTOn DemandManually
RSA SigGen (FIPS186-5) (A5357)KATCASTOn DemandManually
RSA SigVer (FIPS186-5) (A5357)KATCASTOn DemandManually
RSA KeyGen (FIPS186-5) (A5357)PCTPCTN/AManually
SHSKATCASTOn DemandManually
10.3 Periodic Self-Test Information

Table 32: Pre-Operational Periodic Information Public Material – May be reproduced only in its original entirety (without revision).

Page 87
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
EDDSA SigGen (A5359)KATCASTOn DemandManually
EDDSA SigVer (A5359)KATCASTOn DemandManually
EDDSA KeyGen (A5359)PCTPCTN/AManually
NameDescriptionConditionsRecovery MethodIndicator
ES1The Module fails a KAT, PCT, FW or HW integrity verification, [90B] health testThe Module enters the failure stateReboot/Power cycle the moduleOutputs return code of TPM_RC_FAILURE, otherwise it indicates successful completion by TPM_RC_SUCCESS
ES2The Module fails a firmware loading testThe Module returns to normal stateNoneReturn code different from TPM_RC_SUCCESS sent on firmware upgrade start command

Table 33: Conditional Periodic Information

10.4 Error States

Table 34: Error States All cryptographic functions are inhibited while the Module is in an error state. Successful completion of self-tests can be verified through use of TPM2_GetTestResult command. The first 4 bytes of response indicate self-tests status. If they are equal to 0, self-tests completed successfully. If not, the subsequent 4 bytes indicate the list of algorithms not fully self-tested. Public Material – May be reproduced only in its original entirety (without revision).

Page 88
Policy commandAuthentication mechanismDescription
T PM2_PolicyAuthValueMessage Authentication CodeauthValue of authorized entity is used as HMAC key in authorization HMAC (as for HMAC session)
T PM2_ PolicySignedPublic Key Digital Signature Algorithm or Message Authentication CodeSignature with asymmetric or HMAC key
TPM2_ PolicyAuthorizeMessage Authentication CodeSignature with HMAC key being one of the hierarchy proofs
TPM2_PolicySecretMessage Authentication CodeauthValue of reference entity is provided in HMAC session, or policy session containing TPM2_PolicyAuthValue
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

Installation and Initialization: The following steps must be performed in order to securely install, initialize, and start up the Module in the FIPS 140-3 Approved mode of operation:

Page 89
TPM2_PolicyTicketMessage Authentication CodeSignature with HMAC key (one of the proofs) generated by TPM2_PolicySigned or TPM2_PolicySecret
Bound sessionMessage Authentication CodeauthValue of bound entity is used as KDK generated from KBKDF in session key derivation
Module Configuration
Module name / HW P/NST33KTPM2I
PackageUFQFPN32 WF, WLCSP24
InterfaceSPI / I2C
MarkingKTPMI ZA9
FW version00.0A.02.00 (10.512)
TPM2.0 revision1.59
Module Configuration
Module name / HW P/NST33KTPM2A
PackageUFQFPN32 WF, TSSOP20
InterfaceSPI / I2C

Table 35

Page 90
MarkingKTPMA AC5
FW version00.0A.02.00 (10.512)
TPM2.0 revision1.59
Module Configuration
Module name / HW P/NST33KTPM2I
PackageUFQFPN32 WF, WLCSP24
InterfaceSPI / I2C
MarkingKTPMI ZB1
FW version00.0A.02.00 (10.512)
TPM2.0 revision1.59
Module Configuration
Module name / HW P/NST33KTPM2A
PackageUFQFPN32 WF, TSSOP20
InterfaceSPI / I2C
MarkingSTV10TPM AD6
FW version00.0A.02.00 (10.512)
TPM2.0 revision1.59

The current FIPS 140-3 Level 2 Security Policy applies to the Module configurations listed above when the Module is configured in FIPS 140-3 Level 2 mode with the command TPM2_SetCapability. For the configurations supporting both SPI and I2C interfaces, the selection of the mode is done during the boot of the Module.

11.2 Administrator Guidance

No specific initialization procedure is required. Public Material – May be reproduced only in its original entirety (without revision).

Page 91
11.3 Non-Administrator Guidance

No initialization procedures are required.

11.4 Design and Rules

Rules of Operation

  1. The Module provides two operator roles: the Cryptographic Officer and the User role. Each role is associated with a set of services as detailed in the services table.
  2. The Module, evaluated at FIPS 140-3 Level 2, requires authentication to access some of the services as detailed in the services table.
  3. The Module allows the operator to initiate power-up self-tests by power cycling or resetting the Module.
  4. Power up self-tests do not require any operator action.
  5. Data output is inhibited during key generation, self-tests, zeroization, firmware loading, and error states.
  6. Status information does not contain CSPs or sensitive data that, if misused, could lead to a compromise of the Module.
  7. The Module does not support concurrent operators.
  8. The Module does not support a maintenance interface or role.
  9. The Module does not support manual key entry method.
  10. The Module does not have any proprietary external input/output devices used for entry/output of data.
  11. The Module does not output intermediate key values.
  12. The Module does not provide bypass services or ports/interfaces.
  13. The Module does not support a self-initiated cryptographic output capability.
  14. For all zeroization methods, the Module must be in direct control of the operator.
11.5 End of Life

End-of-life of the product requires the following zeroization commands to be executed to remove all CSPs from the memory of the Module:

Page 92
Page 93
12 Mitigation of Other Attacks

The Module does not implement any mitigation method against other attacks. Public Material – May be reproduced only in its original entirety (without revision).

Page 94
AbbreviationFull Specification Name
[TPM2.0 Part1]TPM2.0 Main, Part 1, Architecture, rev 1.59, TCG
[TPM2.0 Part2]TPM2.0 Main, Part 2, Structures, rev 1.59, TCG
[TPM2.0 Part3]TPM2.0 Main, Part 3, Commands, rev 1.59, TCG
[TPM2.0 Part4]TPM2.0 Main, Part 4, Supporting routines, rev 1.59, TCG
[PTP 1.06]TCG PC Client Platform TPM Profile (PTP) Specification, rev. 1.06
[ISO19790]International Standard, ISO/IEC 19790, Information technology — Security techniques — Test requirements for cryptographic modules, Third edition, March 2017
[ISO24759]International Standard, ISO/IEC 24759, Information technology — Security techniques — Test requirements for cryptographic modules, Second and Corrected version, 15 December 2015
[ISO13239]International Standard, ISO/IEC 13239, Information technology — Telecommunications and information exchange between systems — High-level data link control (HDLC) procedures, July 2002
[140-3]Security Requirements for Cryptographic Modules, March 22, 2019
[140]NIST Special Publication 800-140, FIPS 140-3 Derived Test Requirements (DTR), CMVP Validation Authority Updates to ISO/IEC 24759, March 2020
[140A]NIST Special Publication 800-140A, CMVP Documentation Requirements, CMVP Validation Authority Updates to ISO/IEC 24759, March 2020
[140Br1]NIST Special Publication 800-140B revision 1, CMVP Security Policy Requirements, CMVP Validation Authority Updates to ISO/IEC 24759 and ISO/IEC 19790 Annex B, November 2023
[140C]NIST Special Publication 800-140Cr2, CMVP Approved Security Functions, CMVP Validation Authority Updates to ISO/IEC 24759, July 2023
[140D]NIST Special Publication 800-140Dr2, CMVP Approved Sensitive Security Parameter Generation and Establishment Methods, CMVP Validation Authority Updates to ISO/IEC 24759, July 2023
[140E]NIST Special Publication 800-140E, CMVP Approved Authentication Mechanisms, CMVP Validation Authority Requirements for ISO/IEC 19790:2012 Annex E and ISO/IEC 24759 Section 6.17, March 2020
[140F]NIST Special Publication 800-140Fr1, CMVP Approved Non-Invasive Attack Mitigation Test Metrics, CMVP Validation Authority Updates to ISO/IEC 24759, August 2021
[IG]Implementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program, March 2024
[108]NIST Special Publication 800-108r1-upd1, Recommendation for Key Derivation Using Pseudorandom Functions (Revised), August 2022
[131A]Transitions: Recommendation for Transitioning the Use of Cryptographic Algorithms and Key Lengths, Revision 2, March 2019
[133]NIST Special Publication 800-133, Recommendation for Cryptographic Key Generation, Revision 2, June 2020

References and Definitions The following standards are referred to in this Security Policy: Public Material – May be reproduced only in its original entirety (without revision).

Page 95
AbbreviationFull Specification Name
[135]National Institute of Standards and Technology, Recommendation for Existing Application- Specific Key Derivation Functions, Special Publication 800-135rev1, December 2011
[186]National Institute of Standards and Technology, Digital Signature Standard (DSS), Federal Information Processing Standards Publication 186-5, Feb 2023
[197]National Institute of Standards and Technology, Advanced Encryption Standard (AES), Federal Information Processing Standards Publication 197-upd1, May, 2023
[198]National Institute of Standards and Technology, The Keyed-Hash Message Authentication Code (HMAC), Federal Information Processing Standards Publication 198-1, July, 2008
[180]National Institute of Standards and Technology, Secure Hash Standard, Federal Information Processing Standards Publication 180-4, August 2015
[202]FEDERAL INFORMATION PROCESSING STANDARDS PUBLICATION, SHA-3 Standard: Permutation- Based Hash and Extendable-Output Functions, FIPS PUB 202, August 2015
[208]National Institute of Standards and Technology, Recommendation for Stateful Hash-Based Signature Schemes, October 2020
[38A]National Institute of Standards and Technology, Recommendation for Block Cipher Modes of Operation, Methods and Techniques, Special Publication 800-38A, December 2001
[56Ar3]NIST Special Publication 800-56A Revision 3, Recommendation for Pair-Wise Key Establishment Schemes Using Discrete Logarithm Cryptography, April 2018
[56Br2]NIST Special Publication 800-56B Revision 2, Recommendation for Pair-Wise Key Establishment Schemes Using Finite Field Cryptography, March 2019
[90A]National Institute of Standards and Technology, Recommendation for Random Number Generation Using Deterministic Random Bit Generators, Special Publication 800-90A, Revision 1, June 2015
[90B]National Institute of Standards and Technology, Recommendation for the Entropy Sources Used for Random Bit Generation, Special Publication 800-90B, January 2018
[5639]Request for Comments, Elliptic Curve Cryptography (ECC) Brainpool Standard Curves and Curve Generation, March 2010

Table 40

Page 96
AcronymDefinition
APTAdaptive Proportion Test
BN P-256Barreto-Naehrig 256-bit elliptic curve
BP P-256Brainpool 256-bit elliptic curve
BP P-384Brainpool 384-bit elliptic curve
BP P-512Brainpool 512-bit elliptic curve
FWFirmware
HWHardware
KATKnow Answer Test
I2CInter-Integrated Circuit
MPUMemory Protection Unit
RCTRepetition Count Test
SPISerial Peripheral Interface
SSPSensitive Security Parameter
TCGTrusted Computing Group
TPMTrusted Platform Module

Table 41