| Standard | FIPS 140-3 |
|---|---|
| Overall level | 2 |
| Module type | Hardware |
| Embodiment | Single Chip |
| Status | Active |
| Sunset date | 12/7/2030 |
| Caveat | When installed, initialized and configured as specified in Section 11 of the Security Policy; When operated in approved mode |
| Vendor | STMicroelectronics |
flowchart LR
%% Deterministic review-risk graph for Trusted Platform Module ST33KTPM2A / ST33KTPM2I
%% Review prompts and evidence gaps, NOT vulnerability findings.
subgraph CMVP["CMVP-disclosed clues"]
C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>recovery<br/>upgrade<br/>update</i>"]
C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Status output</i>"]
C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>application</i>"]
end
subgraph Inference["Derived inference"]
I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
end
subgraph Risk["Reviewer question"]
R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
end
subgraph Evidence["Evidence needed to close"]
E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
end
C2 --> I2 --> R2 --> E2
C3 --> I3 --> R3 --> E3
C6 --> I6 --> R6 --> E6
classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
class C2,C3,C6 clue;
class I2,I3,I6 infer;
class R2,R3,R6 risk;
class E2,E3,E6 evidence;flowchart LR
%% Deterministic clue tier for Trusted Platform Module ST33KTPM2A / ST33KTPM2I
%% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
subgraph CMVP["CMVP-disclosed clues (deterministic)"]
C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>recovery<br/>upgrade<br/>update</i><br/>src: text:keyword"]
C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Status output</i><br/>src: text:keyword"]
C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>application</i><br/>src: text:keyword"]
end
classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
class C2,C3,C6 clueLow;STMicroelectronics Trusted Platform Module ST33KTPM2A / ST33KTPM2I Document Version: 04-02 Date: 2025-11-13 Public Material – May be reproduced only in its original entirety (without revision).
| # | Section | Page |
|---|
Public Material – May be reproduced only in its original entirety (without revision).
| Item | Page |
|---|---|
| Table 1: Security Levels | 6 |
| Table 2: Tested Module Identification – Hardware | 9 |
| Table 3: Modes List and Description | 11 |
| Table 4: Approved Algorithms | 13 |
| Table 5: Vendor-Affirmed Algorithms | 13 |
| Table 6: Non-Approved, Allowed Algorithms | 14 |
| Table 7: Non-Approved, Allowed Algorithms with No Security Claimed | 14 |
| Table 8: Non-Approved, Not Allowed Algorithms | 15 |
| Table 9: Security Function Implementations | 18 |
| Table 10: Entropy Certificates | 18 |
| Table 11: Entropy Sources | 19 |
| Table 12: Ports and Interfaces | 20 |
| Table 13 – UFQFPN32 / UFQFPN32 WF Pins Definition | 22 |
| Table 14 – TSSOP20 Pins Definition | 23 |
| Table 15 – WLCSP24 Pins Definition | 24 |
| Table 16: Authentication Methods | 25 |
| Table 17: Roles | 26 |
| Table 18 – Mapping between services | 26 |
| Table 19: Approved Services | 62 |
| Table 20: Non-Approved Services | 67 |
| Table 21: Mechanisms and Actions Required | 71 |
| Table 22: EFP/EFT Information | 72 |
| Table 23: Hardness Testing Temperatures | 73 |
| Table 24: Storage Areas | 75 |
| Table 25: SSP Input-Output Methods | 76 |
| Table 26: SSP Zeroization Methods | 77 |
| Table 27: SSP Table 1 | 79 |
| Table 28: SSP Table 2 | 82 |
| Table 29 – Security Strength of a Key Depending on the Underlying Algorithm Used and its Size | 83 |
| Table 30: Pre-Operational Self-Tests | 84 |
| Table 31: Conditional Self-Tests | 85 |
| Table 32: Pre-Operational Periodic Information | 86 |
| Table 33: Conditional Periodic Information | 87 |
| Table 34: Error States | 87 |
| Table 35 – List of policy commands to use in a policy session | 89 |
| Table 36 – ZA9 Module Configuration | 89 |
| Table 37 – AC5 Module Configuration | 90 |
| Table 38 – ZB1 Module Configuration | 90 |
| Table 39 – AD6 Module Configuration | 90 |
| Table 40 – References | 95 |
| Table 41 – Acronyms and Definitions | 96 |
| Figure 1 – HW block diagram | 8 |
Public Material – May be reproduced only in its original entirety (without revision).
| Section | Title | Security Level |
|---|---|---|
| 1 | General | 2 |
| 2 | Cryptographic module specification | 2 |
| 3 | Cryptographic module interfaces | 2 |
| 4 | Roles, services, and authentication | 2 |
| 5 | Software/Firmware security | 2 |
| 6 | Operational environment | N/A |
| 7 | Physical security | 3 |
| 8 | Non-invasive security | N/A |
| 9 | Sensitive security parameter management | 2 |
| 10 | Self-tests | 2 |
| 11 | Life-cycle assurance | 2 |
| 12 | Mitigation of other attacks | N/A |
| Overall Level | 2 |
This document is the non-proprietary FIPS 140-3 Security Policy for the STMicroelectronics Trusted Platform Module ST33KTPM2A / ST33KTPM2I (ST33KTPM2A is also branded commercially “STSAFE-V100TPM”). It contains the security rules under which the Module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for an overall Security Level 2 module.
The FIPS 140-3 security levels for the Module are listed in table below: Table 1: Security Levels Public Material – May be reproduced only in its original entirety (without revision).
The ST33KTPM2A / ST33KTPM2I module, hereafter denoted as the Module, is a fully integrated security module implementing the revision 1.59 of the Trusted Computing Group (TCG) specification for Trusted Platform Modules (TPM) version 2.0.
Purpose and Use: The Module is intended for use by US Federal agencies or other markets that require FIPS 140-3 validated Level 2. The Module is designed to be integrated into personal computers or any other embedded electronic systems. TPM is primarily used for cryptographic keys generation, keys storage, keys management and secure storage for digital certificates. Module Type: Hardware Module Embodiment: SingleChip Module Characteristics: Cryptographic Boundary: The cryptographic boundary of the Module is defined as the perimeter of the IC package and both versions of the Module are represented in the next figure. The Module is composed of:
Figure 1
| Model and/or Part Number | Hardware Version | Firmware Version | Processors | Features |
|---|---|---|---|---|
| ST33KTPM2A | ST33K1M5A revB | 10.512 (dec.) 0x00.0A.02.00 (hex.) | ST33K1M5A | SPI or I2C. The interface is exclusive and selectable dynamically during product boot. Available as a UFQFPN32WF or TSSOP20 package. |
| ST33KTPM2I | ST33K1M5A revB | 10.512 (dec.) 0x00.0A.02.00 (hex.) | ST33K1M5A | SPI or I2C. The interface is exclusive and selectable dynamically during product boot. Available as a UFQFPN32WF or WLCSP24 package. |
Tested Module Identification
| Mode Name | Description | Type | Status Indicator | |
|---|---|---|---|---|
| Normal mode | TPM is in normal operation mode when all pre- operational and conditional self- tests (apart from FW load and PCT tests) are complete. All approved services are usable. The corresponding indicator reports if the service uses an approved cryptographic algorithm or security function. | Approved | TPM2_GetCapability (capability = TPM_CAP_VENDOR_PROPERTIES) with the sub-capability TPM_SUBCAP_VENDOR_TPMA_MODES = 0x7 shall be used. It outputs a 2-bit indicator equals to 01b if the module is in an approved mode of operation |
Figure 3
No components have been excluded from the cryptographic boundary. Public Material – May be reproduced only in its original entirety (without revision).
| Mode Name | Description | Type | Status Indicator | |
|---|---|---|---|---|
| Non- approved mode of operation | The module enters a non-approved mode if one of the non-approved services is used by the operator. | Non- Approved | TPM2_GetCapability (capability = TPM_CAP_VENDOR_PROPERTIES) with the sub-capability TPM_SUBCAP_VENDOR_TPMA_MODES = 0x7 shall be used. It outputs a 2-bit indicator equals to 10b if the module is in a non- approved mode of operation |
| Algorithm | CAVP Cert | Properties | Reference |
|---|---|---|---|
| AES-CBC | A5356 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-CFB128 | A5356 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-CTR | A5356 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-ECB | A5356 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-OFB | A5356 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
| ECDSA KeyGen (FIPS186-4) | A5358 | Curve - P-256, P-384, P-521 Secret Generation Mode - Extra Bits | FIPS 186-4 |
| ECDSA KeyVer (FIPS186-4) | A5358 | Curve - P-256, P-384, P-521 | FIPS 186-4 |
| ECDSA SigGen (FIPS186-4) | A5358 | Component - No Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512, SHA3-256, SHA3-384 | FIPS 186-4 |
| ECDSA SigVer (FIPS186-4) | A5358 | Component - No Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512, SHA3-256, SHA3-384 | FIPS 186-4 |
| EDDSA KeyGen | A5359 | Curve - ED-448 | FIPS 186-5 |
| EDDSA KeyVer | A5359 | Curve - ED-448 | FIPS 186-5 |
| EDDSA SigGen | A5359 | Curve - ED-448 | FIPS 186-5 |
| EDDSA SigVer | A5359 | Curve - ED-448 | FIPS 186-5 |
Table 3: Modes List and Description
Approved Algorithms: The Module implements the Approved cryptographic algorithms listed in the table below: Public Material – May be reproduced only in its original entirety (without revision).
| Algorithm | CAVP Cert | Properties | Reference |
|---|---|---|---|
| Hash DRBG | A5351 | Prediction Resistance - No Mode - SHA2-256 | SP 800-90A Rev. 1 |
| HMAC-SHA-1 | A5355 | Key Length - Key Length: 8-8192 Increment 8 | FIPS 198-1 |
| HMAC-SHA2-256 | A5355 | Key Length - Key Length: 8-8192 Increment 8 | FIPS 198-1 |
| HMAC-SHA2-384 | A5355 | Key Length - Key Length: 8-8192 Increment 8 | FIPS 198-1 |
| HMAC-SHA2-512 | A5355 | Key Length - Key Length: 8-8192 Increment 8 | FIPS 198-1 |
| HMAC-SHA3-256 | A5355 | Key Length - Key Length: 8-8192 Increment 8 | FIPS 198-1 |
| HMAC-SHA3-384 | A5355 | Key Length - Key Length: 8-8192 Increment 8 | FIPS 198-1 |
| KAS-ECC Sp800- 56Ar3 | A5358 | Domain Parameter Generation Methods - P-256, P-384, P-521 Function - Full Validation, Key Pair Generation Scheme - fullUnified - KAS Role - Initiator, Responder KDF Methods - oneStepKdf - Key Length - 128 onePassDh - KAS Role - Initiator, Responder KDF Methods - oneStepKdf - Key Length - 128 | SP 800-56A Rev. 3 |
| KDF SP800-108 | A5354 | KDF Mode - Counter Supported Lengths - Supported Lengths: 160-512 Increment 8 | SP 800-108 Rev. 1 |
| KTS-IFC | A5357 | Modulo - 2048, 3072, 4096 Key Generation Methods - rsakpg1-basic Scheme - KTS-OAEP-basic - KAS Role - initiator, responder Key Transport Method - Key Length - 256 | SP 800-56B Rev. 2 |
| LMS SigVer | A5360 | LMS Modes - LMS_SHA256_M32_H10 | SP 800-208 |
| RSA Decryption Primitive Sp800-56Br2 (CVL) | A5357 | Modulo - 2048, 3072, 4096 | SP 800-56B Rev. 2 |
| RSA KeyGen (FIPS186-5) | A5357 | Key Generation Mode - probable Modulo - 2048, 3072, 4096 Primality Tests - 2pow100 Private Key Format - standard | FIPS 186-5 |
Public Material – May be reproduced only in its original entirety (without revision).
| Algorithm | CAVP Cert | Properties | Reference |
|---|---|---|---|
| RSA SigGen (FIPS186-5) | A5357 | Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pss | FIPS 186-5 |
| RSA SigVer (FIPS186-5) | A5357 | Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pss | FIPS 186-5 |
| SHA-1 | A5352 | Message Length - Message Length: 160, 0-65528 Increment 8 | FIPS 180-4 |
| SHA-1 | A5353 | Message Length - Message Length: 160, 0-65528 Increment 8 | FIPS 180-4 |
| SHA2-256 | A5352 | Message Length - Message Length: 256, 0-65528 Increment 8 | FIPS 180-4 |
| SHA2-256 | A5353 | Message Length - Message Length: 256, 0-65528 Increment 8 | FIPS 180-4 |
| SHA2-384 | A5352 | Message Length - Message Length: 384, 0-65528 Increment 8 | FIPS 180-4 |
| SHA2-384 | A5353 | Message Length - Message Length: 384, 0-65528 Increment 8 | FIPS 180-4 |
| SHA2-512 | A5352 | Message Length - Message Length: 512, 0-65528 Increment 8 | FIPS 180-4 |
| SHA2-512 | A5353 | Message Length - Message Length: 512, 0-65528 Increment 8 | FIPS 180-4 |
| SHA3-256 | A5352 | Message Length - Message Length: 0- 65528 Increment 8 | FIPS 202 |
| SHA3-384 | A5352 | Message Length - Message Length: 0- 65528 Increment 8 | FIPS 202 |
| Name | Properties | Implementation | Reference |
|---|---|---|---|
| CKG | Key Type:Symmetric | N/A | Section 4, Example 1 of [133r2]; IG D.H |
| CKG- Asym | Key Type:Asymmetric | N/A | Section 4, Example 1 of [133r2]; IG D.H |
| Name | Properties | Implementation | Reference | ||||
|---|---|---|---|---|---|---|---|
| ECC BP P-256 | brainpool256r1: | ECDSA [186] (KeyGen, PKV, SigGen, SigVer), KAS [56Ar3] | [RFC5639], IG C.A ([IG]) |
Table 4: Approved Algorithms Vendor-Affirmed Algorithms: The Module implements the Vendor Affirmed cryptographic algorithms listed. D.H N/A Table 5: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: The Module implements the Non-Approved, but Allowed cryptographic algorithms listed. Public Material – May be reproduced only in its original entirety (without revision).
| Name | Properties | Implementation | Reference |
|---|---|---|---|
| ECC BP P-384 | brainpool384r1: | ECDSA [186] (KeyGen, PKV, SigGen, SigVer), KAS [56Ar3] | [RFC5639], IG C.A ([IG]) |
| ECC BP P-512 | brainpool512r1: | ECDSA [186] (KeyGen, PKV, SigGen, SigVer), KAS [56Ar3] | [RFC5639], IG C.A ([IG]) |
| Name | Caveat | Use and Function | |
|---|---|---|---|
| XOR | No security claimed per IG 2.4.A with the example of scenario #1. The algorithm: * is not used except for this purpose * does not access or share CSPs in a way that counters the requirements of the IG * not intended to be used as a security function. * can't be confused for a security function | Obfuscation of input or output data |
| Name | Use and Function |
|---|---|
| ECC BN P-256 (non-compliant) | Key generation, digital signature generation based on ECC BN P-256 |
| ECC derived keys (non-compliant) | Secret exchange or digital signature generation/verification |
| ECDAA (non- compliant) | Key generation, digital signature generation |
| ECDSA (non- compliant) | Digital signature with an ECC signing key generated with an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL), derived from a derivation parent key, or a key loaded in the NULL hierarchy |
| ECSchnorr (non- compliant) | Key generation, digital signature generation and verification |
| HMAC (non- compliant) | Key length < 112 bits for message authentication |
| KAS (non- compliant) | Key agreement with an ECC key that has an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL) |
| KBKDF (non- compliant) | Non-Approved key derivation usage |
Table 6: Non-Approved, Allowed Algorithms The Module implements the Non-Approved, Allowed cryptographic Algorithms with No Security The Module implements the Non-Approved, Not Allowed cryptographic algorithms listed. Public Material – May be reproduced only in its original entirety (without revision).
| Name | Use and Function |
|---|---|
| KTS-IFC (non- compliant) | Key encapsulation with an RSA decryption key that has an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL) |
| RSA (non- compliant) | 1024-bit RSA digital signature generation or with a key loaded in the Null hierarchy |
| RSA with no padding mode (null scheme) (non-compliant) | Key transport |
| RSAES-PKCS1- v1_5 (non- compliant) | Key transport |
| SHA-1 (non- compliant) | Digital signature generation |
| X448 (non- compliant) | Key generation, key agreement scheme based on Curve448 |
| Name | Type | Description | Properties | Algorithms |
|---|---|---|---|---|
| KeyGe n | AsymKeyPair -KeyGen | Key-Pair Generation | Publications:FIPS 186-5 | ECDSA KeyGen (FIPS186-4): (A5358) EDDSA KeyGen: (A5359) Curves: Ed448 CKG-Asym: () Key Type: Asymmetric RSA KeyGen (FIPS186- 5): (A5357) |
| KeyVer | AsymKeyPair -KeyVer | Key-Pair Verification | Publications:FIPS 186-5 | ECDSA KeyVer (FIPS186- 4): (A5358) EDDSA KeyVer: (A5359) Curves: Ed448 |
| KeyVal | AsymKeyPair -PubKeyVal | Key-pair Validation | Publications:186-5 | KAS-ECC Sp800-56Ar3: (A5358) Function: Full Validation KTS-IFC: (A5357) Function: partialVal |
| AES- ENC | BC-UnAuth | Unauthenticate d Encryption | Publication:FIPS 197 | AES-CBC: (A5356) AES-CFB128: (A5356) AES-CTR: (A5356) AES-ECB: (A5356) AES-OFB: (A5356) |
| SigGen | DigSig- SigGen | Signature Generation | Publication:FIPS 186-5 | ECDSA SigGen (FIPS186- 4): (A5358) Curves: P-256, P-384, P- |
Table 8: Non-Approved, Not Allowed Algorithms
Next table shows the Security Function Implementations that the Module implements: Public Material – May be reproduced only in its original entirety (without revision).
| Name | Type | Description | Properties | Algorithms |
|---|---|---|---|---|
| 521, brainpool256r1, brainpool384r1, brainpool512r1 EDDSA SigGen: (A5359) Curves: Ed448 RSA SigGen (FIPS186-5): (A5357) Key Sizes: 2048, 3072, 4096 SHA: SHA2-256, SHA2- 384, SHA2-512, SHA3- 256, SHA3-384 SHA2-256: (A5352) SHA2-384: (A5352) SHA2-512: (A5352) SHA3-256: (A5352) SHA3-384: (A5352) | ||||
| SigVer | DigSig- SigVer | Signature Verification | Publications:FIPS 186-5 | LMS SigVer: (A5360) LMS: LMOTS_SHA256_N32_W 4 LMS_SHA256_M32_H10 ECDSA SigVer (FIPS186- 4): (A5358) Curves: P-256, P-384, P- 521, brainpool256r1, brainpool384r1, brainpool512r1 EDDSA SigVer: (A5359) Curves: Ed448 RSA SigVer (FIPS186-5): (A5357) Key Sizes: 2048, 3072, 4096 SHA2-256: (A5352) SHA2-384: (A5352) SHA2-512: (A5352) SHA3-256: (A5352) SHA3-384: (A5352) |
| DRBG | DRBG | Random Number Generation | Publication: :SP800-90A | Hash DRBG: (A5351) Method: SHA2-256 SHA2-256: (A5352) |
| ENT- ESV | ENT-ESV | ESV | Publications:SP800 -90B | SHA2-256: (A5352) Conditioning Component: SHA2-256 |
| KAS | KAS-Full | Key establishment | Publications:SP 800-56A, Rev 3 | KAS-ECC Sp800-56Ar3: (A5358) Schemes: fullUnified, onePassDH |
Public Material – May be reproduced only in its original entirety (without revision).
| Name | Type | Description | Properties | Algorithms |
|---|---|---|---|---|
| KDF: oneStepKDF SHA-1: (A5352) SHA2-256: (A5352) SHA2-384: (A5352) SHA2-512: (A5352) SHA3-256: (A5352) SHA3-384: (A5352) | ||||
| KTS- IFC | KTS-Encap | Key Encapsulation | Publication:SP 800- 56B rev 2, IG D.G Method:KTS- OAEP-basic | KTS-IFC: (A5357) RSA Decryption Primitive Sp800-56Br2: (A5357) |
| KTS | KTS-Wrap | Key transport | Publication:SP 800- 38F, IG D.G | HMAC-SHA2-256: (A5355) AES-CFB128: (A5356) |
| KBKDF | KBKDF | Key-Based Key Derivation | Publications:SP800 -108 | KDF SP800-108: (A5354) SHA-1: (A5353) SHA2-256: (A5353) SHA2-384: (A5353) SHA2-512: (A5353) SHA3-256: (A5352) SHA3-384: (A5352) |
| MAC | MAC | Message Authentication | Publication:FIPS19 8 | HMAC-SHA-1: (A5355) HMAC-SHA2-256: (A5355) HMAC-SHA2-384: (A5355) HMAC-SHA2-512: (A5355) HMAC-SHA3-256: (A5355) HMAC-SHA3-384: (A5355) SHA-1: (A5352) SHA2-256: (A5352) SHA2-384: (A5352) SHA2-512: (A5352) SHA3-256: (A5352) SHA3-384: (A5352) |
| SHA | SHA | Secure Hash | Publications:FIPS 180-4, FIPS 202 | SHA-1: (A5353, A5352) SHA2-256: (A5352, A5353) SHA2-384: (A5352, A5353) SHA2-512: (A5352, A5353) SHA3-256: (A5352) SHA3-384: (A5352) |
Public Material – May be reproduced only in its original entirety (without revision).
| Name | Type | Description | Properties | Algorithms |
|---|---|---|---|---|
| CKG | CKG | Symmetric Key Generation | Publications:SP800 -133rev2, Section 4; IG D.H | Hash DRBG: (A5351) |
| KAS- KeyGe n | KAS-KeyGen | KAS-ECC Key Generation | Publication:SP800- 56Arev3 | KAS-ECC Sp800-56Ar3: (A5358) |
| AES- DEC | BC-UnAuth | Unauthenticate d Decryption | Publication:FIPS 197 | AES-CBC: (A5356) AES-CFB128: (A5356) AES-CTR: (A5356) AES-ECB: (A5356) AES-OFB: (A5356) |
| Cert Number | Vendor Name | |
|---|---|---|
| E41 | STMicroelectronics |
| Name | Type | Operational Environment | Sample Size | Entropy per Sample | Conditioning Component |
|---|---|---|---|---|---|
| Trusted Platform Module ST33KTPM2X, ST33KTPM2XSPI, ST33KTPM2XI2C, | Physical | ST33K1M5T/A platforms | 1 bit | 0.819266 bits | A5352 (SHA2-256) |
n Table 9: Security Function Implementations
Notes: KAS [56Ar3] - Per [IG] D.F Scenario 2 path (2), compliant key agreement scheme where testing is performed end-to-end for the shared secret computation and key derivation.
The Module implements:
Name ST33KTPM2A, ST33KTPM2I entropy source
Type
Operational Environment
Sample Size
Entropy per Sample
Conditioning Component
For Key Generation, see Section 2.5 and Section 2.6 above.
Key Agreement Information For Key Agreement, see Section 2.5 and Section 2.6 above. Key Transport Information For Key Transport, see Section 2.5 and Section 2.6 above.
The Module does not implement any Industry Protocols. Public Material – May be reproduced only in its original entirety (without revision).
| Physical Port | Logical Interface(s) | Data That Passes |
|---|---|---|
| SPI_NSS / SPI_CLK / SPI_MOSI / I2C_SCL / I2C_SDA / RESET / PP | Control Input | Control parts of the TPM commands provided to the security module. It concerns all bytes of a command except plaintext data, ciphertext data and SSPs (entered with the data input interface). |
| SPI_NSS / SPI_CLK / SPI_MISO / I2C_SCL / I2C_SDA / PIRQ | Control Output | Control parts of the TPM responses output by the security module. It concerns all bytes of a response except plaintext data, ciphertext data and SSPs (output with the data output interface) and except the responseCode of a response (output with the status output interface) |
| SPI_NSS / SPI_CLK / SPI_MISO / I2C_SCL / I2C_SDA / PIRQ | Status Output | Status output by the security module (responseCode parameter of a response) |
| SPI_NSS / SPI_CLK / SPI_MOSI / I2C_SCL / I2C_SDA | Data Input | Data (plaintext data, ciphertext data and SSPs) provided to the security module as part of an input processing command |
| SPI_NSS / SPI_CLK / SPI_MISO / I2C_SCL / I2C_SDA | Data Output | Data (plaintext data, ciphertext data and SSPs) output by the security module as part of the response to a processing command |
| VCC / GND | Power | Power interface of the security module |
The Module’s ports and associated logical interface categories are listed below: Table 12: Ports and Interfaces Additional details concerning the ports and interfaces of TPM: 1. Control and data inputs are multiplexed over the same physical interface. Control and data are distinguished by properly parsing input TPM command parameters according to input structures description, indicated for each command in [TPM2.0 Part3]. Some commands only deal with Public Material – May be reproduced only in its original entirety (without revision).
The pin layouts for the various packages are shown in the next figures. The ST33KTPM2A / ST33KTPM2I security modules support both SPI and I2C physical interfaces but only one interface is configured during TPM boot. The interface configured remains active until the next module reset. Public Material – May be reproduced only in its original entirety (without revision).
| Signal | Type | Description |
|---|---|---|
| VCC | Input | Power supply. This pin must be connected to 1.8V or 3.3V DC power rail supplied by the motherboard. |
| GND | Input | GND has to be connected to the main motherboard ground. |
| RESET | Input | Reset used to re-initialize the device |
| I2C SCL / GPIO5 | Input or Input/Output | I²C serial clock (Open drain with no weak pull-up resistor) or GPIO if SPI interface is selected |
| I2C SDA / GPIO6 | Input/Output | I²C serial data (Open drain with no weak pull-up resistor) or GPIO if SPI interface is selected |
| PIRQ | Output | IRQ used by TPM to generate an interrupt |
| SPI CLK / GPIO1 | Input or Input/Output | SPI serial clock (output from master) or GPIO if I2C interface is selected |
| SPI NSS / GPIO2 | Input or Input/Output | SPI slave select (active low; output from master) or GPIO if I2C interface is selected |
| SPI MISO / GPIO0 | Output or Input/Output | SPI Master Input, Slave Output (output from slave) or GPIO if I2C interface is selected |
| SPI MOSI / GPIO3 | Input or Input/Output | SPI Master Output, Slave Input (output from master) or GPIO if I2C interface is selected |
| GPI8 | Input | GPI default to low. The level of this pin on the rising edge of the RESET signal is used to determine the physical interface to use (high level corresponds to SPI configuration and low-level to I2C) |
| PP | Input | Physical presence, active high, internal pull-down. Used to indicate Physical Presence to the TPM. |
| NC | - | Not Connected: connected to the die but not usable. May be left unconnected. Internal pull-down. |
UFQFPN32 / UFQFPN32 WF configuration The pin layouts for the UFWFPN32 / UFWFPN32 WF packages are shown in the next figure. Figure 5
| Signal | Type | Description |
|---|---|---|
| VCC | Input | Power supply. This pin must be connected to 1.8V or 3.3V DC power rail supplied by the motherboard. |
| GND | Input | GND has to be connected to the main motherboard ground. |
| RESET | Input | Reset used to re-initialize the device |
| I2C SCL / GPIO5 | Input or Input/Output | I²C serial clock (Open drain with no weak pull-up resistor) or GPIO if SPI interface is selected |
| I2C SDA / GPIO6 | Input/Output | I²C serial data (Open drain with no weak pull-up resistor) or GPIO if SPI interface is selected |
| PIRQ | Output | IRQ used by TPM to generate an interrupt |
| SPI CLK / GPIO1 | Input or Input/Output | SPI serial clock (output from master) or GPIO if I2C interface is selected |
| SPI NSS / GPIO2 | Input or Input/Output | SPI slave select (active low; output from master) or GPIO if I2C interface is selected |
| SPI MISO / GPIO0 | Output or Input/Output | SPI Master Input, Slave Output (output from slave) or GPIO if I2C interface is selected |
| SPI MOSI / GPIO3 | Input or Input/Output | SPI Master Output, Slave Input (output from master) or GPIO if I2C interface is selected |
| I2C SEL | Input | This pin must be connected to an external pull-down resistor to activate the I²C protocol during product boot time. It can remain unconnected for the SPI protocol. This pin is internal pull-up by default and becomes internal floating after I²C activation. |
| PP | Input | Physical presence, active high, internal pull-down. Used to indicate Physical Presence to the TPM. |
| NiC | - | Not internally connected: not connected to the die. May be left unconnected but no impact on TPM if connected. |
TSSOP20 configuration The pin layouts for the TSSOP20 package are shown in the next figure. Figure 6
| Signal | Type | Description |
|---|---|---|
| VCC | Input | Power supply. This pin must be connected to 1.8V or 3.3V DC power rail supplied by the motherboard. |
| GND | Input | GND has to be connected to the main motherboard ground. |
| RESET | Input | Reset used to re-initialize the device |
| I2C SCL / GPIO5 | Input or Input/Output | I²C serial clock (Open drain with no weak pull-up resistor) or GPIO if SPI interface is selected |
| I2C SDA / GPIO6 | Input/Output | I²C serial data (Open drain with no weak pull-up resistor) or GPIO if SPI interface is selected |
| PIRQ | Output | IRQ used by TPM to generate an interrupt |
| SPI CLK / GPIO1 | Input or Input/Output | SPI serial clock (output from master) or GPIO if I2C interface is selected |
| SPI NSS / GPIO2 | Input or Input/Output | SPI slave select (active low; output from master) or GPIO if I2C interface is selected |
| SPI MISO / GPIO0 | Output or Input/Output | SPI Master Input, Slave Output (output from slave) or GPIO if I2C interface is selected |
| SPI MOSI / GPIO3 | Input or Input/Output | SPI Master Output, Slave Input (output from master) or GPIO if I2C interface is selected |
| I2C SEL | Input | This pin must be connected to an external pull-down resistor to activate the I²C protocol during product boot time. It can remain unconnected for the SPI protocol. This pin is internal pull-up by default and becomes internal floating after I²C activation. |
| PP | Input | Physical presence, active high, internal pull-down. Used to indicate Physical Presence to the TPM. |
WLCSP24 configuration The pin layouts for the WLCSP24 package are shown in the next figure. Figure 7
| Method Name | Description | Security Mechanism | Strength Each Attempt | Strength per Minute |
|---|---|---|---|---|
| Challenge- response authentication | The challenge-response mechanism uses an authorization value (authValue) as HMAC key or part of an HMAC key. The authValue is entered into the Module during the creation/loading of an object (key, NV index) or during replacement of the default value (hierarchies). The Module enforces a minimum size of 14 bytes. | MAC | Minimum strength is reached with an authValue of 14 bytes: 1/2^112 = 1.92*10^- 34 | Probability of a successful random attempt during a one-minute period is equal to 60000*1.92*10^-34 = 1.15*10^-29 (considering 60000 trials per minute). Assuming a minimum command duration of 1ms, 60000 trials can be executed during a one-minute period. |
| Enhanced authorization | Enhanced authorization includes a policy command (i.e., TPM2_PolicyAuthValue, TPM2_PolicySigned, TPM2_PolicyAuthorize, TPM2_PolicySecret, TPM2_PolicyTicket) requiring the knowledge of an authValue or the proof of the ownership of a signing key. It can also be a bound session, which also requires proving knowledge of an authValue of an object. | SigVer | Minimum strength is reached with an authValue of 14 bytes: 1/2^112 = 1.92*10^- 34 or an RSA 2048 signature with a security strength of 112 bits | Probability of a successful random attempt during a one-minute period is equal to 60000*1.92*10^-34 = 1.15*10^-29 (considering 60000 trials per minute). Assuming a minimum command duration of 1ms, 60000 trials can be executed during a one-minute period. |
The Module implements the following authentication techniques in accordance with the Level 2 requirements: Table 16: Authentication Methods
The Roles Table below lists all operator roles supported by the Module. Public Material – May be reproduced only in its original entirety (without revision).
| Name | Type | Operator Type | Authentication Methods |
|---|---|---|---|
| Crypto officer (CO) | Role | Administrator of the Module | Challenge-response authentication Enhanced authorization |
| User (U) | Role | User of the Module | Challenge-response authentication Enhanced authorization |
| Mandatory service requested from [ISO/IEC 19790] | Corresponding services from the security module |
|---|---|
| Show module’s versioning information | TPM2_GetCapability |
| Show status | TPM2_GetTestResult |
| Perform self-tests | TPM2_SelfTest |
| Perform Approved security functions | See Approved services listed in next table |
| Perform zeroization | See services listed in section 9.3 SSP Zeroization Methods. |
Table 17: Roles The Module does not provide a maintenance role or maintenance interface and does not support concurrent operators. The role is implicitly selected by the TPM operator on service execution by proving the knowledge of the enhanced authorization commands sequence and/or the authorization value of an object. All services are accessible under the roles defined above and no specific access rights are considered to operate with keys and SSPs. Full services inputs and outputs are defined in [TPM2.0 Part3]. The next table Table 18 – Mapping between services The SSPs modes of access shown in the table below are defined as:
| • | G = Generate: The Module generates or derives the SSP. |
| • | R = Read: The SSP is read from the Module (e.g., the SSP is output). |
| • | W = Write: The SSP is updated, imported, or written to the Module (SSP is input). |
| • | E = Execute: The Module uses the SSP in performing a cryptographic operation. |
Some details about information found in the table:
| Name | Description | Indi cato r | Inputs | Outputs | Secu rity Func tions | SSP Access |
|---|---|---|---|---|---|---|
| TPM2_Init | Reboot or power-on of the TPM. | 00b | None | None | Unauthen ticated - nullSeed: Z - nullProof: Z - platformA uth: Z - objSeed: Z - objAuth: Z - objSens: Z - objPub: Z - sesSalt: Z - sesHmac Key: Z - sesSymK ey: Z - contextK ey: Z - objSymK |
Name
Description
Indi cato r
Inputs
Outputs
Secu rity Func tions
SSP Access ey: Z - objHmac Key: Z - contextE ncKey: Z - dupSeed: Z - dupInSy mKey: Z - dupOutS ymKey: Z - dupOutH macKey: Z - creSeed: Z - creSymK ey: Z - creHmac Key: Z - ephSens EccKey: Z - ephPubE ccKey: Z - seqAuth: Z - drbgSeed : Z - tdrbgStat e: Z - fuSymKe
r Z Z Z Z Z :Z e: Z Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Indi cato r | Inputs | Outputs | Secu rity Func tions | SSP Access y: Z - diagSym Key: Z |
|---|---|---|---|---|---|---|
| TPM2_Startup | Set-up the TPM after a power cycle. | 01b | Startup type | None | DRB G ENT- ESV | Unauthen ticated - phSeed: G - ehSeed: G - shSeed: G - phProof: G - ehProof: G - shProof: G - contextK ey: G - drbgSeed : G - drbgState : G - nullSeed: G - nullProof: G |
| TPM2_Shutdown (I) | Prepare the TPM for a power cycle. | 00b | Shutdow n type | None | None | Unauthen ticated |
| TPM2_SelfTest (I) | Self-tests execution | 01b | Full or backgrou nd self- tests | Self-test result if full self-tests required | AES- ENC SigG en SigV er DRB G | Unauthen ticated |
r y: Z G G G G G :G :G G G G Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Indi cato r | Inputs | Outputs | Secu rity Func tions | SSP Access |
|---|---|---|---|---|---|---|
| ENT- ESV KAS KBK DF MAC SHA AES- DEC | ||||||
| TPM2_IncrementalSelf Test (I) | Incremental self-tests execution | 01b | List of tests to pass | List of remaining tests | AES- ENC SigG en SigV er DRB G ENT- ESV KAS KBK DF MAC SHA AES- DEC | Unauthen ticated |
| TPM2_GetTestResult (I) | Get self-tests result | 00b | None | Self-tests status | KBK DF | Unauthen ticated - diagSym Key: G,E,Z - diagSym Seed: E |
| TPM2_StartAuthSessio n (I/E/D) | Session command | 01b | Decrypti on key handle; Binding entity handle; Encrypte d salt; Nonce caller; Session | Nonce TPM | KAS KTS- IFC KBK DF | Unauthen ticated - sesHmac Key: G,W - sesSymK ey: G,W - sesSalt: W,E,Z - |
r G,E,Z Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Indi cato r | Inputs Type (HMAC or Policy) | Outputs | Secu rity Func tions | SSP Access objSens: E - objAuth: E - nvAuth: E - platformA uth: E - endorse mentAuth : E - ownerAut h: E - lockoutA uth: E - seqAuth: E |
|---|---|---|---|---|---|---|
| TPM2_PolicyRestart (I) | Policy session restart | 00b | Session handle | None | None | Unauthen ticated |
| TPM2_Create (I/E/D) | Object creation | 01b | Parent object handle Object sensitive part Object public template Creation data List of PCR | Object private part (encrypted) Object public part Creation data Digest of creation data Ticket to be used by TPM2_Cert ifyCreation( ) | Key Gen AES- ENC SigG en SigV er DRB G ENT- ESV KTS KBK DF MAC SHA CKG KAS- Key Gen | User (U) - objSeed: G,R,E - objSymK ey: G,E,Z - objHmac Key: G,E,Z - objSens: G,R,E - objPub: G,R,E - drbgState : W,E - objAuth: W,R - nullProof: |
r E :E h: E E G G,E,Z ) Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Indi cato r | Inputs | Outputs | Secu rity Func tions | SSP Access E - phProof: E - ehProof: E - shProof: E |
|---|---|---|---|---|---|---|
| TPM2_Load (I/E/D) | Object loading | 01b | Parent object handle Object private part (encrypt ed) Object public part | Name of the loaded object | KeyV er KTS KBK DF MAC SHA AES- DEC | User (U) - objSymK ey: G,W,E,Z - objHmac Key: G,W,E,Z - objSens: W,E - objPub: W - objSeed: W,E - objAuth: W |
| TPM2_LoadExternal (I/E/D) | External object loading | 01b | Object public part Hierarch y | Name of the loaded object | KeyV al | Unauthen ticated - objPub: W - objSens: W - objAuth: W - objSeed: W |
| TPM2_ReadPublic (I) | Read public part of a loaded object | 01b | Handle of an object | Object public part Object name Object | None | Unauthen ticated - objPub: R |
r E E E E W,E W W y W W R Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Indi cato r | Inputs | Outputs qualified name | Secu rity Func tions | SSP Access |
|---|---|---|---|---|---|---|
| TPM2_ActivateCredent ial (I/E/D) | Enables the association of a credential with an object in a way that ensures that the TPM has validated the parameters of the credentialed object | 01b | Handle of the object with credentia ls Handle of a loaded private key Encrypte d credentia l Encrypte d seed | Decrypted certificate information | KAS KTS- IFC KTS KBK DF MAC SHA AES- DEC | Crypto officer (CO) - creSymK ey: G,E,Z - creHmac Key: G,E,Z - objSens: E - creSeed: W,E,Z |
| TPM2_MakeCredential (I/E/D) | Allows the TPM to perform the actions required of a Certificate Authority (CA) in creating a TPM2B_ID_O BJECT containing an activation credential | 01b | Handle of a loaded public key Credenti al informati on Name of the object with credentia ls | Encrypted credential Encrypted seed | AES- ENC KAS KTS- IFC KTS KBK DF MAC SHA | Unauthen ticated - creSeed: G,R,E,Z - creSymK ey: G,E,Z - creHmac Key: G,E,Z - objPub: E |
| TPM2_Unseal (I/E/D) | Returns the data in a loaded Sealed Data Object | 01b | Handle of a loaded data object | Unsealed data | None | User (U) - objSens: R |
| TPM2_ObjectChangeA uth (I/E/D) | Changes the authorization secret for a TPM-resident object | 01b | Handle of an object Handle of the parent of the object | Object private part | AES- ENC KBK DF MAC SHA | User (U) - objSeed: R,E - objSens: R - |
r d l W,E,Z Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Indi cato r | Inputs New authoriza tion value | Outputs | Secu rity Func tions | SSP Access drbgState : W,E - objAuth: R - objSymK ey: E - objHmac Key: E | |
|---|---|---|---|---|---|---|---|
| TPM2_CreateLoaded (I/E/D) | Creates an object and loads it in the TPM | 01b | Parent object handle Object sensitive part Object public template | Object private part (encrypted) Object public part Creation object name | Key Gen KeyV er AES- ENC SigG en SigV er DRB G ENT- ESV KAS KBK DF MAC SHA CKG KAS- Key Gen | Crypto officer (CO) - objSeed: G,R,E - objSymK ey: G,E - objHmac Key: G,E - objSens: G,R,E - objPub: G,R,E - tdrbgStat e: G,W,E - drbgState : W,E - objAuth: W,R - nullSeed: E - phSeed: E - ehSeed: E - shSeed: E - nullProof: E |
r G,R,E E E E Public Material – May be reproduced only in its original entirety (without revision).
Name
Description
Indi cato r
Inputs
Outputs
Secu rity Func tions
SSP Access - phProof: E - ehProof: E - shProof: E - ekRsa: E - ekEcc: E - shProofF orReseed : G,E User (U) - objSeed: G,E - objSymK ey: G,E - objHmac Key: G,E - objSens: G,R - objPub: G,R,E - tdrbgStat e: G,W,E - drbgState : W - objAuth: W - nullSeed: E - phSeed: E - ephSens EccKey:
r E E E E E : G,E G,E G,R G,R,E e: G,W,E :W W E E Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Indi cato r | Inputs | Outputs | Secu rity Func tions | SSP Access E - shSeed: E - nullProof: E - phProof: E - ehProof: E - shProofF orReseed : G,E - ekRsa: E - ekEcc: E | |
|---|---|---|---|---|---|---|---|
| TPM2_Duplicate (I/E/D) | Duplicates a loaded object so that it may be used in a different hierarchy | 01b | Handle of the loaded object to duplicate Handle of the new parent Optional symmetri c encryptio n key | Encryption key for inner wrapper Duplicated object private part (encrypted) Encrypted seed | AES- ENC DRB G KTS- IFC KAS KTS KBK DF MAC SHA CKG | User (U) - dupSeed: G,R,E,Z - objSeed: R - dupOutS ymKey: G,E,Z - dupInSy mKey: G,R,W,E, Z - dupOutH macKey: G,E,Z - objSens: R - objAuth: R - drbgState |
r E E E E E : G,E E E G,R,E,Z R G G,E,Z R R Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Indi cato r | Inputs | Outputs | Secu rity Func tions | SSP Access : W,E - objPub: E |
|---|---|---|---|---|---|---|
| TPM2_Rewrap (I/E/D) | Rewraps a duplicated object with a new parent key | 01b | Handle of the old parent Handle of the new parent Duplicat ed object private part (encrypt ed) Name of the object being rewrapp ed Encrypte d seed | Duplicated object private part (encrypted) Encrypted seed | AES- ENC AES- DEC KAS KTS- IFC KTS KBK DF MAC SHA CKG | User (U) - dupOutS ymKey: G,E,Z - dupOutH macKey: G,E,Z - objSens: R,W,E - dupSeed: R,W,E,Z - objSeed: R,W - dupInSy mKey: W,Z - drbgState : W,E - objPub: E - objAuth: R,W |
| TPM2_Import (I/E/D) | Allows an object to be encrypted using the symmetric encryption values of a Storage Key | 01b | Handle of the new parent Duplicat ed object private part (encrypt ed) Object public part Encrypte d seed | Object private part (encrypted) | AES- ENC AES- DEC KAS KTS- IFC KTS KBK DF MAC SHA CKG | User (U) - objSens: R,W,E,Z - objSeed: R,W,Z - objPub: W,E,Z - dupOutS ymKey: W,E,Z - objAuth: R,W,Z |
r : W,E E E R,W Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Indi cato r | Inputs Encrypti on key for inner wrapper | Outputs | Secu rity Func tions | SSP Access - drbgState : E - dupSeed: E,W,Z - dupInSy mKey: E,W,Z - dupOutH macKey: W,E,Z |
|---|---|---|---|---|---|---|
| TPM2_RSA_Encrypt (I/E/D) | Performs RSA encryption | 01b | RSA public key handle Message to encrypt RSA scheme to use | Encrypted output | KTS- IFC | Unauthen ticated - objPub: E |
| TPM2_RSA_Decrypt (I/E/D) | Performs RSA decryption | 01b | RSA private key handle Cipherte xt to decrypt RSA scheme to use | Decrypted output | KTS- IFC | User (U) - objSens: Z |
| TPM2_ECDH_KeyGen (I/E/D) | Shared secret value computation using ECDH | 01b | ECC key public part handle | Shared secret Ephemeral public key | KAS KAS- Key Gen | Unauthen ticated - ephSens EccKey: G,E,Z - ephPubE ccKey: G,R,Z - drbgState |
r E,W,Z E,W,Z W,E,Z G,R,Z Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Indi cato r | Inputs | Outputs | Secu rity Func tions | SSP Access : W,E - objPub: E |
|---|---|---|---|---|---|---|
| TPM2_ECDH_ZGen (I/E/D) | Shared secret value recovery using ECDH | 01b | Handle of a loaded ECC key Ephemer al public key | Recovered shared secret | KAS | User (U) - ephPubE ccKey: W,E,Z - objSens: E |
| TPM2_ECC_Paramete rs (I) | Returns the parameters of an ECC curve identified by its TCG-assigned curveID | 00b | ID of an ECC curve | Curve parameters | None | Unauthen ticated |
| TPM2_EncryptDecrypt (I/E) | Symmetric encryption or decryption | 01b | Symmetr ic key handle Decrypti on or encryptio n indicator Input IV Data Mode | Encrypted or decrypted data Output IV (for chaining) | AES- ENC AES- DEC | User (U) - objSens: E |
| TPM2_EncryptDecrypt 2 (I/E/D) | Symmetric encryption or decryption | 01b | Symmetr ic key handle Decrypti on or encryptio n indicator Input IV Data Mode | Encrypted or decrypted data Output IV (for chaining) | AES- ENC AES- DEC | User (U) - objSens: E |
| TPM2_Hash (I/E/D) | Performs a hash operation on data | 01b | Data to hash Hash algorithm Hierarch y to use for ticket | Digest Ticket linked to the input hierarchy | MAC SHA | Unauthen ticated - nullProof: E - phProof: |
r : W,E E (I/E/D) W,E,Z E Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Indi cato r | Inputs | Outputs | Secu rity Func tions | SSP Access E - ehProof: E - shProof: E |
|---|---|---|---|---|---|---|
| TPM2_HMAC (I/E/D) | Performs a HMAC operation on data | 01b | Symmetr ic signing key handle Data to HMAC Hash algorithm | HMAC | MAC | User (U) - objSens: E |
| TPM2_GetRandom (I/E) | Outputs random bytes from a DRBG | 01b | Number of random bytes to generate | Output random bytes | DRB G | Unauthen ticated - drbgState : W,E |
| TPM2_StirRandom (I/D) | Reseed the state of a DRBG | 01b | Addition al informati on | None | DRB G ENT- ESV | Unauthen ticated - drbgSeed : W,E,Z - drbgState : W,E |
| TPM2_HMAC_Start (I/D) | Starts an HMAC sequence | 01b | Handle of an HMAC key Authoriz ation value for sequenc e Hash algorithm | Sequence handle | MAC | User (U) - seqAuth: W - objSens: E |
| TPM2_HashSequence Start (I/D) | Starts a hash or an event sequence | 01b | Authoriz ation value for sequenc e Hash algorithm | Sequence handle | SHA | Unauthen ticated - seqAuth: W |
r E E E (I/E) G : W,E E W Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Indi cato r | Inputs | Outputs | Secu rity Func tions | SSP Access |
|---|---|---|---|---|---|---|
| TPM2_SequenceUpda te (I/D) | Adds data to a hash or HMAC sequence | 01b | Sequenc e handle Data to hash/HM AC | None | MAC SHA | User (U) - objSens: E |
| TPM2_SequenceComp lete (I/E/D) | Adds last part of data to a hash or HMAC sequence and returns the result | 01b | Sequenc e handle Data to hash/HM AC Hierarch y for ticket | HMAC or digest Ticket linked to the input hierarchy | MAC SHA | User (U) - nullProof: E - phProof: E - ehProof: E - shProof: E - objSens: E - seqAuth: Z |
| TPM2_EventSequence Complete (I/D) | Adds last part of data to a hash or HMAC sequence and returns the result in a digest list | 01b | Handle of PCR to extend Sequenc e handle Data to hash/HM AC | List of digests computed for the PCR | MAC SHA | User (U) - objSens: E - seqAuth: Z |
| TPM2_Certify (I/E/D) | Proves that an object with a specific Name is loaded in the TPM | 01b | Handle of the object to certify Handle of a signing key Qualifyin g data Signatur e scheme | Certification structure Signature over the certification structure | SigG en DRB G KBK DF MAC SHA CKG | User (U) - drbgState : W,E - objSens: E - shProof: E |
| TPM2_CertifyCreation (I/E/D) | Proves the association | 01b | Handle of the | Certification structure | SigG en | User (U) - |
r E E E Z e Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Indi cato r | Inputs | Outputs | Secu rity Func tions | SSP Access |
|---|---|---|---|---|---|---|
| between an object and its creation data | object to certify Handle of a signing key Qualifyin g data Signatur e scheme Ticket Creation hash | Signature over the certification structure | DRB G KBK DF MAC SHA CKG | drbgState : W,E - objSens: E - nullProof: E - phProof: E - ehProof: E - shProof: E | ||
| TPM2_Quote (I/E/D) | Quotes PCR values | 01b | Handle of a signing key Qualifyin g data Selection of PCRs Signatur e scheme | Quoted information Signature over the quoted information | SigG en DRB G KBK DF MAC SHA CKG | User (U) - drbgState : W,E - objSens: E - shProof: E |
| TPM2_GetSessionAudi tDigest (I/E/D) | Returns a digital signature of the audit session digest | 01b | Handle of a privacy administr ator Handle of a signing key Handle of an audit session Qualifyin g data Signatur e scheme | Audit information Signature over the quoted information | SigG en KBK DF DRB G MAC SHA CKG | Crypto officer (CO) - drbgState : W,E - objSens: E - shProof: E |
r E E e Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Indi cato r | Inputs | Outputs | Secu rity Func tions | SSP Access |
|---|---|---|---|---|---|---|
| TPM2_GetCommandA uditDigest (I/E/D) | Returns the current value of the command audit digest, a digest of the commands being audited, and the audit hash algorithm | 01b | Handle of a privacy administr ator Handle of a signing key Qualifyin g data Signatur e scheme | Audit information Signature over the quoted information | SigG en DRB G KBK DF MAC SHA CKG | Crypto officer (CO) - drbgState : W,E - objSens: E - shProof: E |
| TPM2_GetTime (I/E/D) | Returns the current values of Time and Clock | 01b | Handle of a privacy administr ator Handle of a signing key Qualifyin g data Signatur e scheme | Attestation data Signature over the attestation data | SigG en KBK DF DRB G MAC SHA CKG | Crypto officer (CO) - drbgState : W,E - objSens: E - shProof: E |
| TPM2_CertifyX509 (I/E/D) | X.509 certificate generation | 01b | Handle of the object to certify Handle of a signing key Partial certificat e Signatur e scheme | Additional certificate information Digest Signature over the digest | SigG en SHA | User (U) - drbgState : W,E - objSens: E |
| TPM2_VerifySignature (I/D) | Uses loaded keys to validate a signature on a | 01b | Handle of a public key | Validation ticket | SigV er MAC | Unauthen ticated - objPub: E |
r E e G E e e e Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description message with the message digest passed to the TPM | Indi cato r | Inputs Digest of a message Signatur e to be tested | Outputs | Secu rity Func tions | SSP Access - nullProof: E - phProof: E - ehProof: E - shProof: E |
|---|---|---|---|---|---|---|
| TPM2_Sign (I/D) | Causes the TPM to sign an externally provided hash with the specified symmetric or asymmetric signing key | 01b | Handle of a signing key Digest to be signed Scheme Proof ticket for digest | Signature over the digest | SigG en DRB G MAC SHA | User (U) - objSens: E - nullProof: E - phProof: E - ehProof: E - shProof: E |
| TPM2_SetCommandC odeAuditStatus (I) | Changes the audit status of a command or to set the hash algorithm used for the audit digest | 00b | Authoriz ation handle Hash algorithm | None | None | Crypto officer (CO) |
| TPM2_PCR_Extend (I) | Updates the indicated PCR | 01b | PCR handle List of digests used to extend PCRs | None | SHA | Unauthen ticated |
| TPM2_PCR_Event (I/D) | Updates the indicated PCR and reports list of digests | 01b | PCR handle Event data | Digests | SHA | Unauthen ticated |
r E E G E Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Indi cato r | Inputs | Outputs | Secu rity Func tions | SSP Access |
|---|---|---|---|---|---|---|
| TPM2_PCR_Read (I) | Returns the values of all PCR specified in pcrSelectionIn | 00b | Selection of PCR to read | PCR information | None | Unauthen ticated |
| TPM2_PCR_Allocate (I) | Sets the desired PCR allocation of PCR and algorithms | 00b | Selection of PCR to allocate | PCR allocation information | None | Crypto officer (CO) |
| TPM2_PCR_Reset (I) | Sets the PCR in all banks to zero | 00b | PCR to reset | none | None | Unauthen ticated |
| _TPM_Hash_Start | Indicates to the TPM interface the start of an H-CRTM measurement sequence | 01b | None | None | SHA | Unauthen ticated |
| _TPM_Hash_Data | Indicates to the TPM interface data to be included in the H-CRTM measurement sequence | 01b | Data | None | SHA | Unauthen ticated |
| TPM_Hash_End | Indicates to the TPM interface the end of the H-CRTM measurement sequence | 01b | None | None | SHA | Unauthen ticated |
| TPM2_PolicySigned (I/E/D) | Includes a signed authorization in a policy | 01b | Signatur e key handle Policy session handle Nonce TPM Digest Signatur e Expiratio n of authoriza | Policy timeout Policy ticket | SigV er MAC SHA | Unauthen ticated - objPub: E - nullProof: E - phProof: E - ehProof: E |
r E E e E Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Indi cato r | Inputs tion Policy referenc e value | Outputs | Secu rity Func tions | SSP Access - shProof: E |
|---|---|---|---|---|---|---|
| TPM2_PolicySecret (I/E/D) | Includes a secret-based authorization to a policy | 01b | Authoriz ation object handle Policy session handle Nonce TPM Digest Expiratio n of authoriza tion Policy referenc e value | Policy timeout Policy ticket | MAC SHA | User (U) - nullProof: E - phProof: E - ehProof: E - shProof: E |
| TPM2_PolicyTicket (I/D) | Includes a ticket in a policy | 01b | Policy session handle Nonce TPM Digest Expiratio n of authoriza tion Policy referenc e value Authoriz ation object name Ticket | None | MAC SHA | Unauthen ticated - nullProof: E - phProof: E - ehProof: E - shProof: E |
| TPM2_PolicyOR (I) | Allows options in authorizations without requiring that the TPM | 01b | Policy session handle List of digests | None | SHA | Unauthen ticated |
r E E E E E E Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description evaluate all the options | Indi cato r | Inputs | Outputs | Secu rity Func tions | SSP Access |
|---|---|---|---|---|---|---|
| TPM2_PolicyPCR (I/D) | Causes conditional gating of a policy based on PCR | 01b | Policy session handle Expecte d digest value PCR selection | None | SHA | Unauthen ticated |
| TPM2_PolicyLocality (I) | Indicates that the policy will be limited to a specific locality | 01b | Policy session handle Locality | None | SHA | Unauthen ticated |
| TPM2_PolicyNV (I/D) | Causes conditional gating of a policy based on the contents of an NV Index | 01b | Authoriz ation handle NV index handle Policy session handle Operand , offset, operatio n | None | SHA | User (U) |
| TPM2_PolicyCounterTi mer (I/D) | Causes conditional gating of a policy based on the contents of the TPMS_TIME_I NFO structure | 01b | Policy session handle Operand , offset, operatio n | None | SHA | Unauthen ticated |
| TPM2_PolicyComman dCode (I) | Limits policy to a specific command code | 01b | Policy session handle Comman d code | None | SHA | Unauthen ticated |
| TPM2_PolicyPhysicalP resence (I) | Physical presence will need to be asserted at the time the authorization is performed | 01b | Policy session handle | None | SHA | Unauthen ticated |
r n n Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Indi cato r | Inputs | Outputs | Secu rity Func tions | SSP Access |
|---|---|---|---|---|---|---|
| TPM2_PolicyCpHash (I/D) | Allows a policy to be bound to a specific command and command parameters | 01b | Policy session handle Digest to add to policy | None | SHA | Unauthen ticated |
| TPM2_PolicyNameHas h (I/D) | Allows a policy to be bound to a specific set of TPM entities without being bound to the parameters of the command | 01b | Policy session handle Digest to add to policy | None | SHA | Unauthen ticated |
| TPM2_PolicyDuplicatio nSelect (I/D) | Allows qualification of duplication to allow duplication to a selected new parent | 01b | Policy session handle Object name to be duplicate d New Parent name Object name inclusion indicator | None | SHA | Unauthen ticated |
| TPM2_PolicyAuthorize (I/D) | Check a ticket issued from the signature verification of a new policy so that it may be used in an existing policy | 01b | Policy session handle Digest of the policy being approve d Policy qualifier Key name Ticket | None | MAC SHA | Unauthen ticated - nullProof: E - phProof: E - ehProof: E - shProof: E |
| TPM2_PolicyAuthValu e (I) | Allows a policy to be bound to the authorization value of the | 01b | Policy session handle | None | SHA | Unauthen ticated |
r Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description authorized entity | Indi cato r | Inputs | Outputs | Secu rity Func tions | SSP Access |
|---|---|---|---|---|---|---|
| TPM2_PolicyPassword (I) | Allows a policy to be bound to the authorization value of the authorized object | 01b | Policy session handle | None | SHA | Unauthen ticated |
| TPM2_PolicyGetDigest (I/E) | Returns the current policyDigest of a policy session | 00b | Policy session handle | Policy digest | None | Unauthen ticated |
| TPM2_PolicyNvWritten (I) | Allows a policy to be bound to the TPMA_NV_W RITTEN attributes | 01b | Policy session handle NV index written indicator | None | SHA | Unauthen ticated |
| TPM2_PolicyTemplate (I/D) | Allows a policy to be bound to a specific creation template | 01b | Policy session handle Digest to add to policy | None | SHA | Unauthen ticated |
| TPM2_PolicyAuthorize NV (I) | Provides a capability that is the equivalent of a revocable policy | 01b | Source handle for authoriza tion NV index to read Policy session handle | None | SHA | User (U) |
| TPM2_CreatePrimary (I/E/D) | Creates a Primary Object under one of the Primary Seeds or a Temporary Object under TPM_RH_NUL L | 01b | Primary handle Key sensitive data Key public template Creation data | Object handle Object Public part Creation data Digest of creation data Creation ticket Name | Key Gen KeyV er AES- ENC SigG en SigV er | Crypto officer (CO) - objSeed: G,E,Z - objSymK ey: G,E,Z - |
r Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Indi cato r | Inputs | Outputs | Secu rity Func tions | SSP Access | |
|---|---|---|---|---|---|---|---|
| Creation PCR | of the object | DRB G KBK DF MAC SHA CKG KAS- Key Gen | objHmac Key: G,E,Z - objSens: G,E,Z - objPub: G,R,E,Z - tdrbgStat e: G,W,E,Z - drbgState : W,E - objAuth: W - nullSeed: E - phSeed: E - ehSeed: E - shSeed: E - nullProof: E - phProof: E - ehProof: E - shProof: E - ekRsa: E - ekEcc: E - shProofF orReseed : G,E |
r e: G,W,E,Z : W,E W E E E E E E E E E E : G,E Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Indi cato r | Inputs | Outputs | Secu rity Func tions | SSP Access |
|---|---|---|---|---|---|---|
| TPM2_HierarchyContr ol (I) | Enables and disables use of a hierarchy and its associated NV storage | 00b | Primary handle Hierarch y to enable or disable Enable or disable indicator | None | None | Crypto officer (CO) |
| TPM2_SetPrimaryPolic y (I/D) | Sets the authorization policy for a hierarchy | 00b | Primary handle Policy digest Hash algorithm | None | None | Crypto officer (CO) |
| TPM2_ChangePPS (I) | Replaces the current platform primary seed (PPS) with a value from the RNG and sets platformPolicy to the default initialization value | 01b | Authoriz ation handle | None | DRB G | Crypto officer (CO) - drbgState : W,E - phProof: Z - phSeed: Z - objSeed: Z - objSens: Z - objPub: Z |
| TPM2_ChangeEPS (I) | Replaces the current endorsement primary seed EPS) with a value from the RNG and sets endorsementP olicy to the default | 01b | Authoriz ation handle | None | DRB G | Crypto officer (CO) - drbgState : W,E - ehSeed: Z - ehProof: |
r G Z Z Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description initialization value | Indi cato r | Inputs | Outputs | Secu rity Func tions | SSP Access Z - objSeed: Z - objSens: Z - objPub: Z - ekRsa: Z - ekEcc: Z |
|---|---|---|---|---|---|---|
| TPM2_Clear (I) | Removes all TPM context associated with a specific Owner | 01b | Authoriz ation handle | None | DRB G | Crypto officer (CO) - drbgState : W,E - shSeed: Z - ehProof: Z - shProof: Z - shProofF orReseed : Z - objSeed: Z - objSens: Z - objPub: Z - objAuth: Z |
| TPM2_ClearControl (I) | Disables and enables the execution of TPM2_Clear() | 00b | Authoriz ation handle Set or clear disableO wnerFlag | None | None | Crypto officer (CO) |
r Z Z Z Z Z : W,E Z Z G :Z Z Z Z Z Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Indi cato r | Inputs | Outputs | Secu rity Func tions | SSP Access |
|---|---|---|---|---|---|---|
| TPM2_HierarchyChan geAuth (I/D) | Changes the authValue of hierarchies | 00b | Authoriz ation handle New authoriza tion value | None | None | Crypto officer (CO) - lockoutA uth: W - endorse mentAuth : W - ownerAut h: W - platformA uth: W |
| TPM2_DictionaryAttac kLockReset (I) | Cancels the effect of a TPM lockout due to several successive authorization failures | 00b | Authoriz ation handle | None | None | Crypto officer (CO) |
| TPM2_DictionaryAttac kParameters (I) | Changes the lockout parameters | 00b | Authoriz ation handle newMax Tries, newRec overyTim e and lockoutR ecovery values | None | None | Crypto officer (CO) |
| TPM2_VendorCmdFiel dUpgradeStart (I) | Initiates a field upgrade session | 01b | Approve d | None | SigV er KBK DF SHA CKG | Crypto officer (CO) - fuSigEC CKey: E - fuSigLMS Key: E - fuSymKe y: G |
r :W h: W y: G Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Indi cato r | Inputs | Outputs | Secu rity Func tions | SSP Access - fuSymSe ed: E |
|---|---|---|---|---|---|---|
| TPM2_VendorCmdFiel dUpgradeData (I) | Conveys firmware in a field upgrade session | 01b | Field upgrade data blob | Completion indicator | AES- DEC SHA | Unauthen ticated - fuSymKe y: E,Z |
| TPM2_ContextSave | Saves a session context, object context, or sequence object context outside the TPM | 01b | Saved handle | Context | AES- ENC KTS KBK DF MAC CKG | Unauthen ticated - contextE ncKey: G,E,Z - objSeed: R - objSens: R - objPub: R - objAuth: R - nullProof: E - phProof: E - ehProof: E - shProof: E - contextK ey: E - sesHmac Key: R - seqAuth: R |
| TPM2_ContextLoad | Reloads a context that | 01b | Context | Loaded handle | AES- DEC | Unauthen ticated |
r y: E,Z G,E,Z R R R E E R Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Indi cato r | Inputs | Outputs | Secu rity Func tions | SSP Access |
|---|---|---|---|---|---|---|
| has been saved by TPM2_Context Save() | KTS KBK DF MAC CKG | - contextE ncKey: G,E,Z - objSeed: W - objSens: W - objPub: W - objAuth: W - nullProof: E - phProof: E - ehProof: E - shProof: E - contextK ey: E - sesHmac Key: W - seqAuth: W | ||||
| TPM2_FlushContext | Causes all context associated with a loaded object, sequence object, or session to be removed from TPM memory | 01b | Flush handle | None | Unauthen ticated - objSeed: Z - objSens: Z - objPub: Z - objAuth: Z |
r W W W W E E E E W Z Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Indi cato r | Inputs | Outputs | Secu rity Func tions | SSP Access |
|---|---|---|---|---|---|---|
| TPM2_EvictControl (I) | Allows certain Transient Objects to be made persistent or a persistent object to be evicted | 01b | Authoriz ation handle Loaded object handle Persiste nt handle | None | None | Crypto officer (CO) - objSeed: W,Z - objSens: W,Z - objPub: W,Z - objAuth: W,Z |
| TPM2_ReadClock (I) | Reads the current TPMS_TIME_I NFO structure | 00b | None | Current time | None | Unauthen ticated |
| TPM2_ClockSet (I) | Advances the value of the TPM's clock | 00b | New time | None | None | Crypto officer (CO) |
| TPM2_ClockRateAdjus t (I) | Adjusts the rate of advance of Clock and Time | 00b | Authoriz ation handle Clock update rate adjustme nt | None | None | Crypto officer (CO) |
| TPM2_GetCapability (I) | Returns various information regarding the TPM and its current state | 00b | Capabilit y, property, property count | More data availability indicator Capability data | None | Unauthen ticated |
| TPM2_SetCapability (I/D) | Set specific data in the TPM, such as TPM configurations, which may change the TPM's function and behavior | 00b | Capabilit y data | None | None | Crypto officer (CO) |
| TPM2_TestParms (I) | Checks if specific combinations | 00b | Algorith m | None | None | Unauthen ticated |
r W,Z W,Z W,Z W,Z Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description of algorithm parameters are supported | Indi cato r | Inputs paramet ers | Outputs | Secu rity Func tions | SSP Access |
|---|---|---|---|---|---|---|
| TPM2_NV_DefineSpac e (I/D) | Defines the attributes of an NV Index and causes the TPM to reserve space to hold the data associated with the NV Index | 01b | Authoriz ation handle NV authoriza tion value NV public paramet ers | None | None | Crypto officer (CO) - nvAuth: W |
| TPM2_NV_UndefineSp ace (I) | Removes an Index from the TPM | 01b | Authoriz ation handle NV index to delete | None | None | Crypto officer (CO) - nvAuth: Z |
| TPM2_NV_UndefineSp aceSpecial (I) | Removal of a platform- created NV Index that has TPMA_NV_PO LICY_DELETE SET | 01b | Platform authoriza tion handle NV index to delete | None | None | Crypto officer (CO) - nvAuth: Z |
| TPM2_NV_ReadPublic (I/E) | Reads the public area and Name of an NV Index | 01b | NV index | NV index public area Name of the NV index | SHA | Unauthen ticated |
| TPM2_NV_Write (I/D) | Writes a value to an area in NV memory that was previously defined by TPM2_NV_Def ineSpace() | 00b | Authoriz ation handle NV index to write Data to write Offset in the NV index area | None | None | User (U) |
| TPM2_NV_Increment (I) | Increments the value in an NV Index that has the | 00b | Authoriz ation handle NV index to | None | None | User (U) |
r Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description TPM_NT_COU NTER attribute | Indi cato r | Inputs incremen t | Outputs | Secu rity Func tions | SSP Access |
|---|---|---|---|---|---|---|
| TPM2_NV_Extend (I/D) | Extends a value to an area in NV memory that was previously defined by TPM2_NV_Def ineSpace() | 01b | Authoriz ation handle NV index to extend Data to extend | None | SHA | User (U) |
| TPM2_NV_SetBits (I) | Sets bits in an NV Index that was created as a bit field | 00b | Authoriz ation handle NV index to extend Data to OR with NV content | None | None | User (U) |
| TPM2_NV_WriteLock (I) | Inhibits further writes of the NV Index if the TPMA_NV_W RITEDEFINE or TPMA_NV_W RITE_STCLEA R attributes of an NV location are SET | 00b | Authoriz ation handle NV index | None | None | User (U) |
| TPM2_NV_GlobalWrite Lock (I) | Sets TPMA_NV_W RITELOCKED for all indexes that have their TPMA_NV_GL OBALLOCK attribute SET | 00b | Authoriz ation handle | None | None | Crypto officer (CO) |
| TPM2_NV_Read (I/E) | Reads a value from an area in NV memory previously defined by TPM2_NV_Def ineSpace() | 00b | Authoriz ation handle NV index to be read Size and | Data read | None | User (U) |
r Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Indi cato r | Inputs offset in NV area | Outputs | Secu rity Func tions | SSP Access |
|---|---|---|---|---|---|---|
| TPM2_NV_ReadLock (I) | Prevents further reads of the NV Index until the next TPM2_Startup (TPM_SU_CL EAR) if TPMA_NV_RE AD_STCLEAR is SET | 00b | Authoriz ation handle NV index to be locked | None | None | User (U) |
| TPM2_NV_ChangeAut h (I/D) | Allows the authValue of an NV Index to be changed | 01b | NV index New authoriza tion value | None | None | User (U) - nvAuth: W |
| TPM2_NV_Certify (I/E/D) | Certifies the contents of an NV Index or portion of an NV Index | 01b | Handle of signing key Authoriz ation handle NV index Qualifyin g data Scheme Size and offset in NV area | Structure that was signed Signature | SigG en KBK DF MAC SHA | User (U) - objSens: E - shProof: E |
| TPM2_VendorCmdSet Mode (I) | Sets the low power mode | 00b | Authoriz ation handle Low power configura tion structure | None | None | Crypto officer (CO) |
| TPM2_VendorCmdSet CommandSet (I) | Activates and locks commands | 00b | Authoriz ation handle Comman d code Activatio n and | None | None | Crypto officer (CO) |
r Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Indi cato r | Inputs lock indicator s | Outputs | Secu rity Func tions | SSP Access |
|---|---|---|---|---|---|---|
| TPM2_VendorCmdSet CommandSetLock (I) | Prevents locking commands | 00b | Authoriz ation handle | None | None | Crypto officer (CO) |
| TPM2_VendorCmdGet Random2 (I/E) | Get random value from DRBG | 01b | Number of bytes to generate | Random value | None | Unauthen ticated - drbgState : W,E |
| TPM2_VendorCmdGPI OConfig (I) | Configures GPIO | 00b | Authoriz ation handle GPIO configura tion | None | None | Unauthen ticated |
| TPM2_VendorCmdGet Random800_90B (I/E) | Get random value from ENT (P) | 01b | Number of bytes to generate | Random value | ENT- ESV | Unauthen ticated |
| TPM2_VendorCmdCha ngeObjectDeletionAuth (I) | Modifies deletion authorization for an object | 00b | Authoriz ation handle Platform authoriza tion use indicator | None | None | Crypto officer (CO) |
| TPM2_VendorCmdRes toreEK (I) | Restore EK RSA or EK ECC in case of deletion by TPM2_Change EPS | 01b | Authoriz ation handle | None | None | Crypto officer (CO) - ekRsa: W - ekEcc: W |
| TPM2_VendorCmdZer oizeEK (I) | Zeroize EK RSA and EK ECC | 01b | Authoriz ation handle | None | None | Crypto officer (CO) - ekRsa: Z - ekEcc: Z |
| TPM2_VendorCmdSig n | Causes the TPM to sign a message with the specified | 01b | Handle of a signing key | Signature over the message | SigG en DRB | User (U) - objSens: E |
r s : W,E W Z Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Indi cato r | Inputs | Outputs | Secu rity Func tions | SSP Access |
|---|---|---|---|---|---|---|
| asymmetric signing key | Message to be signed Context Scheme | G SHA | - objPub: E - nullProof: E - phProof: E - ehProof: E - shProof: E | |||
| TPM2_VendorCmdVeri fySignature | Uses loaded keys to validate a signature on a message with the message digest passed to the TPM | 01b | Handle of a public key Signed message Context Signatur e to be tested | None | SigV er | Unauthen ticated - objPub: E - nullProof: E - phProof: E - ehProof: E - shProof: E |
| TPM2_VendorCmdSet BackgroundSlotsConfi g | Configure the RSA background key slots | 00b | Authoriz ation handle Slots configura tion | None | None | Crypto officer (CO) |
| TPM2_PP_Commands | Determines which commands require assertion of Physical Presence | 00b | Authoriz ation handle List of comman ds to add and list of comman d to remove | None | None | Crypto officer (CO) |
r E E E E E E E E Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Indi cato r | Inputs | Outputs | Secu rity Func tions | SSP Access |
|---|---|---|---|---|---|---|
| Integrity mechanism provided by sessions | This service is not callable from TPM interface but is only used internally by any command and response with an authorization area. It consists in computing the integrity of the received command or transmitted response. | 01b | Comman d or response | Integrity value | DRB G KBK DF MAC SHA CKG | Unauthen ticated - sesHmac Key: E,Z |
| Encryption mechanism provided by sessions | This service is not callable from TPM interface but is only used internally by any command and response with an encryption or decryption session. It consists in decrypting the first parameter of a received command or encrypting the first parameter of a transmitted response. | 01b | Comman d or response | Encrypted parameter | AES- ENC AES- DEC DRB G KBK DF SHA CKG | Unauthen ticated - sesSymK ey: G,E,Z |
r Table 19: Approved Services Public Material – May be reproduced only in its original entirety (without revision).
The integrity mechanism provided by sessions is not directly callable from the security module external interfaces. Function is used (or might be used) by the services listed in this table. When a service is usable with a session, (I) is added next to the service name. When a service can additionally use the encryption mechanism of a session, (I/E) is added next to the service name. The encryption mechanism provided by sessions is not directly callable from the security module external interfaces. Function is used (or might be used) by the services listed in this table. When a service is usable with a session, (I) is added next to the service name. When a service can additionally use the encryption mechanism of a session, (I/E) is added next to the service name. Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Algorithms | Role |
|---|---|---|---|
| TPM2_Create; TPM2_CreateLoaded; TPM2_Load; TPM2_LoadExternal | Creation or loading of an ECC key with a non-approved elliptic curve; Creation or loading of an ECC key for a non-approved key agreement usage; Creation or loading of an ECC signing key with an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL);Creation or loading of an RSA decryption key with an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL); Creation or loading of a 1024-bit RSA key | ECC BN P-256 (non-compliant) RSA (non- compliant) X448 (non- compliant) | User |
| TPM2_CreateLoaded | Derivation of an ECC key from a derivation parent key | ECC derived keys (non- compliant) KBKDF (non- compliant) | User |
| TPM2_Load; TPM2_LoadExternal | Loading of an ECC or RSA key (sensitive and public parts) in the NULL hierarchy | ECC BN P-256 (non-compliant) RSA (non- compliant) | User |
| TPM2_Duplicate; TPM2_Rewrap; TPM2_Import | Key transport with a 1024-bit RSA key Key agreement scheme with a non-approved ECC curve Key agreement scheme with an ECC key used in a non-approved key agreement usage | ECC BN P-256 (non-compliant) KAS (non- compliant) RSA (non- compliant) X448 (non- compliant) | User |
| TPM2_RSA_Encrypt; TPM2_RSA_Decrypt | Key transport with a non-approved scheme: * RSAES-PKCS1- v1_5 * RSA with no padding mode (null scheme) Key transport with an RSA decryption key: * Generated with an undetermined | KTS-IFC (non- compliant) RSA with no | User |
All Approved services implemented by the Module are listed in the table below: Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Algorithms | Role |
|---|---|---|---|
| scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL) * Loaded in the NULL hierarchy | padding mode (null scheme) (non-compliant) RSAES- PKCS1-v1_5 (non-compliant) | ||
| TPM2_ECDH_KeyGen | Use of a non-approved elliptic curve: * ECC key with curve BN P- 256 Use of an ECC key for a non-approved key agreement usage: * ECC key with curve Curve448 | ECC BN P-256 (non-compliant) X448 (non- compliant) | N/A |
| TPM2_ECDH_ZGen | Use of an ECC key: * Generated on curve BN P-256 * For a non- approved key agreement usage * Derived from a derivation parent key * Loaded in the NULL hierarchy | ECC BN P-256 (non-compliant) X448 (non- compliant) KBKDF (non- compliant) | User |
| TPM2_ZGen_2Phase | This command is only usable jointly with TPM2_EC_Ephemeral service that is non approved as using key derivation to generate ECC keys | ECC derived keys (non- compliant) KBKDF (non- compliant) | User |
| TPM2_HMAC | HMAC generation with a key length < 112 bits | HMAC (non- compliant) | User |
| TPM2_HMAC_Start; TPM2_SequenceUpdate; TPM2_SequenceComplete | HMAC generation with a key length < 112 bits | HMAC (non- compliant) | User |
| TPM2_Certify; TPM2_CertifyCreation; TPM2_Quote; TPM2_GetSessionAuditDigest; TPM2_GetCommandAuditDigest; TPM2_GetTime; TPM2_CertifyX509 | Digital signature with a non-approved signature scheme: * ECC signature with ECDAA signature scheme * ECC signature with ECSchnorr signature scheme * RSA signature with key length of 1024 bits * ECC or RSA signature key using SHA-1 as digest method * ECC signature with curve BN P-256; Digital signature with an ECC signing key generated with an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL); Digital signature with an ECC signing key | ECC BN P-256 (non-compliant) ECDAA (non- compliant) ECDSA (non- compliant) ECSchnorr (non-compliant) | User/CO |
Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Algorithms | Role |
|---|---|---|---|
| derived from a derivation parent key; Digital signature with an ECC or RSA key loaded in the NULL hierarchy | RSA (non- compliant) SHA-1 (non- compliant) | ||
| TPM2_Commit | Generation of an ECC key through key derivation method | KBKDF (non- compliant) | User |
| TPM2_EC_Ephemeral | Generation of an ECC key through key derivation method | KBKDF (non- compliant) | User |
| TPM2_VerifySignature | Digital signature verification with a non-approved signature scheme or a non-approved curve: * ECDAA signature scheme * ECSchnorr signature scheme * ECC signature with curve BN P- 256 | ECC BN P-256 (non-compliant) ECDAA (non- compliant) ECSchnorr (non-compliant) | NA |
| TPM2_Sign | Digital signature generation with a non-approved signature scheme: * ECC signature with ECDAA signature scheme * ECC signature with ECSchnorr signature scheme * RSA signature with key length of 1024 bits * ECC or RSA signature key using SHA-1 as digest method * ECC signature with curve BN P-256; Digital signature with an ECC signing key generated with an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL); Digital signature with an ECC signing key derived from a derivation parent key; Digital signature with an ECC or RSA key loaded in the NULL hierarchy | ECC BN P-256 (non-compliant) ECDAA (non- compliant) ECDSA (non- compliant) ECSchnorr (non-compliant) RSA (non- compliant) SHA-1 (non- compliant) | User |
| TPM2_PolicySigned | Digital signature verification with a non-approved signature scheme or a non-approved curve: * ECDAA signature scheme * ECSchnorr signature scheme * ECC signature with curve BN P- 256 | ECC BN P-256 (non-compliant) ECDAA (non- compliant) ECSchnorr (non-compliant) | N/A |
| TPM2_CreatePrimary | Creation and loading of an ECC key with a non-approved elliptic curve: * ECC key with curve BN P-256 Use of an ECC key for a | ECC BN P-256 (non-compliant) | CO |
Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Algorithms | Role | ||
|---|---|---|---|---|---|
| non-approved key agreement usage: * ECC key with curve Curve448 Creation and loading of an ECC signing key with an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL) Creation and loading of an RSA decryption key with an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL) | X448 (non- compliant) | ||||
| TPM2_NV_Certify | Digital signature with a non-approved signature scheme: * ECC signature with ECDAA signature scheme * ECC signature with ECSchnorr signature scheme * RSA signature with key length of 1024 bits * ECC or RSA signature key using SHA-1 as digest method * ECC signature with curve BN P-256; Digital signature with an ECC signing key generated with an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL); Digital signature with an ECC key derived from a derivation parent key; Digital signature with an ECC or RSA key loaded in the NULL hierarchy | ECC BN P-256 (non-compliant) ECDAA (non- compliant) ECDSA (non- compliant) ECSchnorr (non-compliant) RSA (non- compliant) SHA-1 (non- compliant) | User |
Table 20: Non-Approved Services Public Material – May be reproduced only in its original entirety (without revision).
Loading of firmware onto the Module can be achieved by using two services:
The Module is composed of the following firmware component(s):
The operator can initiate the integrity test on demand by using the TPM2_SelfTest command with the full parameter set to YES or by using the TPM2_IncrementalSelfTest command. Public Material – May be reproduced only in its original entirety (without revision).
Type of Operational Environment: Limited The operational environment of the Module is “limited” because it allows loading authenticated firmware that meets all applicable requirements of [140-3] standard. Data outputs are inhibited until the loading session has completed successfully. Execution of the successfully loaded FW is only effective after the next reset of the security module. New firmware versions must be validated through the FIPS 140-3 validation process. Any other firmware loaded into this module is out of the scope of this validation and requires a separate FIPS 140-3 validation. The core memory loader (CML) represented in Figure 8 is non-modifiable, only the TPM instances are modifiable by using an authenticated firmware upgrade mechanism. The security module contains two instances of the FW but only one FW instance is executed after a boot sequence. Public Material – May be reproduced only in its original entirety (without revision).
| Mechanism | Inspection Frequency | Inspection Guidance | |||
|---|---|---|---|---|---|
| Hard opaque package | Dependent on the security module integration environment varies from once per month to once per year | Visual inspection of the package to confirm that it has not been damaged by an external action |
The security module is production grade and meets the Physical Security protection requirements for single-chip module at FIPS 140-3 Level 3.
Zeroization Zeroization of CSPs can be triggered by specific services as detailed in Section 9.3. It occurs in a sufficiently small time-period to prevent the recovery of the sensitive data between start of zeroization and the zeroization completion. Physical security mechanisms The security module is encapsulated in a hard opaque package to prevent direct observation of internal security components. It implements additional security mechanisms:
EFT has been performed for all security module configurations. Low and high temperatures have been measured at a nominal voltage of 3.3V. Low and high voltage have been measured at ambient temperature (25°C). The nominal operating ranges are:
| Temp/Voltage Type | Temperature or Voltage | EFP or EFT | Result |
|---|---|---|---|
| LowTemperature | -77°C (ST33KTPM2A in UFQFPN32 WF); -70 (ST33KTPM2I in UFQFPN32 WF); -70 (ST33KTPM2A in TSSOP20); -75 (ST33KTPM2I in WLCSP24) | EFT | Shutdown |
| HighTemperature | 165°C (ST33KTPM2A in UFQFPN32 WF); 160 (ST33KTPM2I in UFQFPN32 WF); 145 (ST33KTPM2A in TSSOP20); 160 (ST33KTPM2I in WLCSP24) | EFT | Shutdown |
| LowVoltage | 1.4V | EFT | Shutdown |
| HighVoltage | 4.3V | EFT | Shutdown |
Table 22: EFP/EFT Information Public Material – May be reproduced only in its original entirety (without revision).
| Temperature Type | Temperature |
|---|---|
| LowTemperature | -40°C |
| HighTemperature | 105°C |
Hardness testing was conducted at the temperature indicated in the table below: Table 23: Hardness Testing Temperatures Public Material – May be reproduced only in its original entirety (without revision).
The Module does not claim support of non-invasive attack mitigation techniques referenced in [140F]. Public Material – May be reproduced only in its original entirety (without revision).
| Storage Area Name | Description | Persistence Type |
|---|---|---|
| Dynamic RAM | Volatile memory used to store SSPs between two consecutive resets or power-on/power-off sequence of the security module. SSPs don't persist after command execution. This area is marked as RAM on the HW block diagram. | Dynamic |
| Static RAM | Volatile memory used to store SSPs between two consecutive resets or power-on/power-off sequence of the security module. SSPs persist after command execution. This area is marked as RAM on the HW block diagram. | Static |
| NVRAM | Non-volatile memory (flash-based) used to store SSPs and make them persistent to a reset or a power-off/power-on sequence of the security module. This area is marked as flash memory on the HW block diagram. | Static |
| Name | From | To | Format Type | Distribution Type | Entry Type | SFI or Algorithm | |
|---|---|---|---|---|---|---|---|
| Input plaintext to NVRAM | Outside of cryptographi c boundary | NVRAM | Plaintext | Manual | Electronic | ||
| Input protected to NVRAM | Outside of cryptographi c boundary | NVRAM | Encrypted | Manual | Electronic | KTS | |
| Input plaintext to RAM | Outside of cryptographi c boundary | Static RAM | Plaintext | Manual | Electronic | ||
| Input protected to RAM | Outside of cryptographi c boundary | Static RAM | Encrypted | Manual | Electronic | KTS | |
| Output plaintext from NVRAM | NVRAM | Outside of cryptographic boundary | Plaintext | Manual | Electronic | ||
| Output protected from NVRAM | NVRAM | Outside of cryptographic boundary | Encrypted | Manual | Electronic | KTS |
Public Material – May be reproduced only in its original entirety (without revision).
| Name | From | To | Format Type | Distribution Type | Entry Type | SFI or Algorithm |
|---|---|---|---|---|---|---|
| Output plaintext from RAM | Static RAM | Outside of cryptographic boundary | Plaintext | Manual | Electronic | |
| Output protected from RAM | Static RAM | Outside of cryptographic boundary | Encrypted | Manual | Electronic | KTS |
| Input asym. encrypte d to RAM | Outside of cryptographi c boundary | Static RAM | Encrypted | Manual | Electronic | KTS-IFC |
| Output asym. encrypte d to RAM | Static RAM | Outside of cryptographic boundary | Encrypted | Manual | Electronic | KTS-IFC |
Table 25: SSP Input-Output Methods Public Material – May be reproduced only in its original entirety (without revision).
| Zeroization Method | Description | Rationale | Operator Initiation |
|---|---|---|---|
| TPM2_Init | Zeroization of all volatile SSPs. Explicit zeroization indicator provided by service completion status. | N/A | Activation of reset signal |
| TPM2_Clear | Zeroization of all contexts associated with an Owner. Explicit zeroization indicator provided by service completion status. | SSPs linked to an Owner must not persist if the Owner changes | Send TPM2_Clear command |
| TPM2_Startup | Zeroization of platformAuth. Explicit zeroization indicator provided by service completion status. | Zeroize platformAuth before its first use after a reset | Send TPM2_Startup command |
| TPM2_ChangePPS | Zeroize the platform primary seed and flush all transient and persistent objects in the Platform hierarchy. Explicit zeroization indicator provided by service completion status. | Platform hierarchy renewal | Send TPM2_ChangePPS command |
| TPM2_ChangeEPS | Zeroize the endorsement primary seed and flush all transient and persistent objects in the Endorsement hierarchy. Explicit zeroization indicator provided by service completion status. | Endorsement hierarchy renewal | Send TPM2_ChangeEPS command |
| TPM2_EvictControl | Zeroize an object from NVRAM. Explicit zeroization indicator provided by service completion status. | Method required to zeroize a dedicated object in NVRAM | Send TPM2_EvictControl command |
| TPM2_FlushContext | Zeroize an object from RAM. Explicit zeroization indicator provided by service completion status. | Method required to zeroize a dedicated object in RAM | Send TPM2_FlushContext command |
| Automatic | Zeroize SSPs at the end of a command processing. Implicit zeroization indication. | Method for limited life cycle SSPs | No, zeroization is automatic. |
| TPM2_NV_UndefineSpace TPM2_NV_UndefineSpaceSpecial | Zeroize a NV index. Explicit zeroization indicator provided by service completion status. | Method required to flush NV indices from NVRAM | Send TPM2_NV_UndefineSpace command. Send TPM2_NV_UndefineSpaceSpecial command |
| TPM2_VendorCmdZeroizeEK | Zeroize the endorsement key provisioned. Explicit zeroization indicator provided by service completion status. | Mandatory zeroization method for EK SSPs | Send TPM2_VendorCmdZeroizeEK command |
| TPM2_SequenceComplete TPM2_EventSequenceComplete | Zeroize a hash or HMAC sequence. Explicit zeroization indicator provided by service completion status. | Method required to flush sequences from RAM | Send TPM2_SequenceComplete command. Send TPM2_EventSequenceComplete command |
| Name | Description | Size - Strength | Type - Category | Generated By | Established By | Used By |
|---|---|---|---|---|---|---|
| nullProof | Proof (secret value) of the null hierarchy | 512 - 256 | Symmetric key - CSP | DRBG | KBKDF MAC | |
| phProof | Proof (secret value) of the platform hierarchy | 512 - 256 | Symmetric key - CSP | DRBG | MAC | |
| ehProof | Proof (secret value) of the endorsement hierarchy | 512 - 256 | Symmetric key - CSP | DRBG | MAC | |
| shProof | Proof (secret value) of the storage hierarchy | 512 - 256 | Symmetric key - CSP | DRBG | KBKDF MAC | |
| shProofForReseed | Random value | 512 - 256 | Entropy source - CSP | ENT-ESV | DRBG | |
| platformAuth | Authentication value for the platform hierarchy | 512 - 128 to 256 (depending on the underlying hash algorithm used) | Authentication value / Symmetric key - CSP | KBKDF MAC | ||
| endorsementAuth | Authentication value for the endorsement hierarchy | 512 - 128 to 256 (depending on the underlying hash algorithm used) | Authentication value / Symmetric key - CSP | KBKDF MAC |
Table 26: SSP Zeroization Methods All usage of these SSPs by the Module are described in the services detailed in section 4. The next table lists the SSPs used as keys. Temporary storage duration column was removed for readability purposes because when temporary storage is indicated, duration corresponds to the duration of a command execution. The algorithms indicated in “Generate by” and “Used by” columns correspond to items in the SFI table. Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Size - Strength | Type - Category | Generated By | Established By | Used By | |
|---|---|---|---|---|---|---|---|
| ownerAuth | Authentication value for the storage hierarchy | 512 - 128 to 256 (depending on the underlying hash algorithm used) | Authentication value / Symmetric key - CSP | KBKDF MAC | |||
| lockoutAuth | Authentication value for the lockout hierarchy | 512 - 128 to 256 (depending on the underlying hash algorithm used) | Authentication value / Symmetric key - CSP | KBKDF MAC | |||
| objSeed | Seed value for object generation | 512 - 128 to 256 | Data, Symmetric key - CSP | DRBG KBKDF | KBKDF SHA | ||
| objAuth | Object's authorization value | 112 to 512 - 112 to 256 | Authentication value / Symmetric key - CSP | KBKDF MAC | |||
| objSymKey | Encryption key of object private part | 256 - 256 | Symmetric key - CSP | KBKDF | AES- ENC AES- DEC | ||
| objHmacKey | Integrity key of object private part | 160, 256, 384, 512 - 128 to 256 | Symmetric key - CSP | KBKDF | MAC | ||
| objSens | Object private part | 2048, 3072, 4096 (RSA); 128, 192, 256 (AES); 256, 384, 521 (ECC); 448 (EdDSA); 112 to 1024 (HMAC) - 112 to 256 | Symmetric or asymmetric private key - CSP | KeyGen KBKDF CKG KAS-KeyGen | AES- ENC AES- DEC SigGen KAS KBKDF MAC | ||
| objPub | Object public part | 2048, 3072, 4096 (RSA); 512, 768, 1056 (ECC); 448 (EdDSA) - 112 to 256 | Asymmetric public key - PSP | KeyGen KAS-KeyGen | SigVer KAS KTS- IFC | ||
| nvAuth | Authorization of NV index | 112 to 512 - 112 to 256 | Authentication value / Symmetric key - CSP | KBKDF MAC | |||
| sesSalt | Salt for keys diversification | 160, 256, 384, 512 - 128 to 256 | Symmetric key - CSP | N/A | KAS | KBKDF | |
| sesHmacKey | HMAC session key | 160, 256, 384, 512 - 128 to 256 | Symmetric key - CSP | KBKDF | KBKDF MAC | ||
| sesSymKey | Encrypted session key | 128, 192, 256 - 128 to 256 | Symmetric key - CSP | KBKDF | AES- ENC AES- DEC | ||
| contextKey | Derivation key for context protection | 128 - 128 | Symmetric key - CSP | DRBG | KBKDF | ||
| contextEncKey | Wrapping key for context protection | 256 - 256 | Symmetric key - CSP | KBKDF | AES- ENC AES- DEC | ||
| dupInSymKey | Wrapping key for duplicated object | 128, 192, 256 - 128 to 256 | Symmetric key - CSP | DRBG | AES- ENC AES- DEC | ||
| dupSeed | Seed for protection keys derivation | 160 to 512 - 128 to 256 | Symmetric key - CSP | DRBG KAS | KAS | KBKDF | |
| dupOutSymKey | Encryption key for duplicated objects | 128, 192, 256 - 128 to 256 | Symmetric key - CSP | KBKDF | AES- ENC AES- DEC | ||
| dupOutHmacKey | HMAC key for duplicated objects | 160, 256, 384, 512 - 128 to 256 | Symmetric key - CSP | KBKDF | MAC | ||
| creSeed | Seed for credential keys derivation | 160 to 512 - 128 to 256 | Symmetric key - CSP | KAS | KBKDF |
Public Material – May be reproduced only in its original entirety (without revision).
| Name | Description | Size - Strength | Type - Category | Generated By | Established By | Used By |
|---|---|---|---|---|---|---|
| creSymKey | Encryption key for credentials | 128, 192, 256 - 128 to 256 | Symmetric key - CSP | KBKDF | AES- ENC AES- DEC | |
| creHmacKey | HMAC key for credentials | 160, 256, 384, 512 - 128 to 256 | Symmetric key - CSP | KBKDF | MAC | |
| ephSensEccKey | ECC ephemeral private key | 256, 384, 521 - 128 to 256 | ECC private key - CSP | KAS-KeyGen | KAS | |
| ephPubEccKey | ECC ephemeral public key | 512, 768, 1056 - 128 to 256 | ECC public key - PSP | KAS-KeyGen | KAS | |
| ekRsa | Provisioned RSA endorsement key | 2048 - 112 | RSA private key - CSP | Input during manufacturing | KTS- IFC | |
| ekEcc | Provisioned ECC endorsement key | 256, 384 - 128 to 192 | ECC private key - CSP | Input during manufacturing | KAS | |
| fuSigECCKey | Field upgrade ECC signature verification key | 384 - 192 | ECC public key - PSP | Input during manufacturing | SigVer | |
| fuSigLMSKey | Field upgrade LMS signature verification key | 32 - 128 | LMS public key - PSP | Input during manufacturing | SigVer | |
| seqAuth | Authorization value for hash or HMAC sequence | 112 to 512 - 112 to 256 | Authentication value / Symmetric key - CSP | N/A | KBKDF MAC | |
| nullSeed | Seed of the null hierarchy | 512 - 256 | Seed - CSP | ENT-ESV | DRBG | |
| phSeed | Seed of the platform hierarchy | 512 - 256 | Seed - CSP | ENT-ESV | DRBG | |
| ehSeed | Seed of the endorsement hierarchy | 512 - 256 | Seed - CSP | ENT-ESV | DRBG | |
| shSeed | Seed of the storage hierarchy | 512 - 256 | Seed - CSP | ENT-ESV | DRBG | |
| drbgState | Internal state (V and C secret values) of the DRBG (based on SHA256) | 256 - 256 | State - CSP | DRBG | DRBG | |
| drbgSeed | Seed value for the DRBG | 512 - 256 | Seed - CSP | ENT-ESV | DRBG | |
| tdrbgState | Internal state (V and C secret values) of the transient DRBG (based on SHA256) used to generate prime numbers for primary RSA keys | 256 - 256 | State - CSP | DRBG | DRBG | |
| fuSymSeed | Seed used for field upgrade symmetric key derivation | 256 - 256 | Symmetric key - Neither | Input during manufacturing | KBKDF | |
| fuSymKey | field upgrade symmetric key | 256 - 256 | Symmetric key - Neither | KBKDF | AES- DEC | |
| diagSymSeed | Seed used for diagnostic symmetric key derivation | 256 - 256 | Symmetric key - Neither | Input during manufacturing | KBKDF | |
| diagSymKey | diagnostic symmetric key | 256 - 256 | Symmetric key - Neither | KBKDF | AES- ENC |
| Name | Input - Output | Storage | Storage Duration | Zeroization | Related SSPs | |
|---|---|---|---|---|---|---|
| nullProof | Static RAM:Plaintext | Until next reset | TPM2_Init | drbgState:Generates contextEncKey:Derived From | ||
| phProof | NVRAM:Plaintext | After Use | TPM2_ChangePPS | drbgState:Generates contextEncKey:Derived From | ||
| ehProof | NVRAM:Plaintext | After Use | TPM2_ChangeEPS TPM2_Clear | drbgState:Generates contextEncKey:Derived From | ||
| shProof | NVRAM:Plaintext | After Use | TPM2_Clear | drbgState:Generates contextEncKey:Derived From | ||
| shProofForReseed | NVRAM:Plaintext | After Use | TPM2_Clear | tdrbgState:Reseeded From | ||
| platformAuth | Input plaintext to RAM Input protected to RAM | Static RAM:Plaintext | Until next reset | TPM2_Init | sesSymKey:Derived from, Protects (Encrypts) sesHmacKey:Derived from, Protects (Integrity) |
Table 27: SSP Table 1 Public Material – May be reproduced only in its original entirety (without revision).
| Name | Input - Output | Storage | Storage Duration | Zeroization | Related SSPs |
|---|---|---|---|---|---|
| endorsementAuth | Input plaintext to NVRAM Input protected to NVRAM | NVRAM:Plaintext | After Use | TPM2_Clear TPM2_ChangeEPS | sesHmacKey:Derived from, Protects (Integrity) sesSymKey:Derived from, Protects (Encrypts) |
| ownerAuth | Input plaintext to NVRAM Input protected to NVRAM | NVRAM:Plaintext | After Use | TPM2_Clear | sesHmacKey:Derived from, Protects (Integrity) sesSymKey:Derived from, Protects (Encrypts) |
| lockoutAuth | Input plaintext to NVRAM Input protected to NVRAM | NVRAM:Plaintext | After Use | TPM2_Clear | sesHmacKey:Derived from, Protects (Integrity) sesSymKey:Derived from, Protects (Encrypts) |
| objSeed | Input protected to RAM Input plaintext to RAM Output protected from RAM Output protected from NVRAM | Static RAM:Plaintext NVRAM:Plaintext | Until object zeroization, shift to NVRAM or next reset | TPM2_Init TPM2_Clear TPM2_ChangePPS TPM2_ChangeEPS TPM2_EvictControl TPM2_FlushContext | tdrbgState:Derived From drbgState:Derived From objSymKey:Derived From objHmacKey:Derived From sesHmacKey:Protects (Integrity) sesSymKey:Protects (Encrypts) |
| objAuth | Input plaintext to RAM Input protected to RAM Output protected from RAM Output protected from NVRAM | Static RAM:Plaintext NVRAM:Plaintext | Until object zeroization, shift to NVRAM or next reset | TPM2_Init TPM2_Clear TPM2_ChangePPS TPM2_ChangeEPS TPM2_EvictControl TPM2_FlushContext | sesHmacKey:Derived from, Protects (Integrity) sesSymKey:Derived from, Encrypts |
| objSymKey | Dynamic RAM:Plaintext NVRAM:Plaintext | After Use | Automatic | objAuth:Encrypted by objSens:Encrypted by objSeed:Encrypted by | |
| objHmacKey | Dynamic RAM:Encrypted NVRAM:Plaintext | After Use | Automatic | objAuth:Protected by (Integrity) objSens:Protected by (Integrity) objSeed:Protected by (Integrity) | |
| objSens | Input plaintext to RAM Input protected to RAM Output protected from RAM Output protected from NVRAM | Static RAM:Plaintext NVRAM:Plaintext | Until object zeroization, shift to NVRAM or next reset | TPM2_Init TPM2_Clear TPM2_ChangePPS TPM2_ChangeEPS TPM2_EvictControl TPM2_FlushContext | tdrbgState:Generates drbgState:Generates objSens:Derives objSymKey:Encrypts objHmacKey:Protects (Integrity) objPub:Paired With |
| objPub | Input plaintext to RAM Output plaintext from NVRAM Output plaintext from RAM | Static RAM:Plaintext NVRAM:Plaintext | Until object zeroization, shift to NVRAM or next reset | TPM2_Init TPM2_Clear TPM2_ChangePPS TPM2_ChangeEPS TPM2_EvictControl TPM2_FlushContext | objSens:Paired With |
| nvAuth | Input plaintext to NVRAM Input protected to NVRAM | NVRAM:Plaintext | After Use | TPM2_NV_UndefineSpace TPM2_NV_UndefineSpaceSpecial | sesHmacKey:Derived from, Protects (Integrity) sesSymKey:Encrypts |
| sesSalt | Input asym. encrypted to RAM | Dynamic RAM:Plaintext | After Use | Automatic | sesHmacKey:Derived From objPub:Encrypts |
| sesHmacKey | Input protected to RAM Output protected from RAM | Dynamic RAM:Plaintext | After Use | Automatic | nvAuth:Derives; Protected by (Integrity) contextKey:Encrypts contextEncKey:Encrypts platformAuth:Protected by (Integrity) endorsementAuth:Protected by |
Public Material – May be reproduced only in its original entirety (without revision).
| Name | Input - Output | Storage | Storage Duration | Zeroization | Related SSPs | |
|---|---|---|---|---|---|---|
| (Integrity) ownerAuth:Protected by (Integrity) lockoutAuth:Protected by (Integrity) objAuth:Protected by (Integrity) seqAuth:Protected by (Integrity) dupInSymKey:Protected by (Integrity) dupSeed:Protected by (Integrity) creSeed:Protected by (Integrity) | ||||||
| sesSymKey | Dynamic RAM:Plaintext | After Use | Automatic | sesHmacKey:Derives platformAuth:Derives; Encrypts endorsementAuth:Derives; Encrypts ownerAuth:Derives; Encrypts lockoutAuth:Derives; Encrypts objAuth:Derives; Encrypts seqAuth:Derives; Encrypts nvAuth:Derives; Encrypts dupInSymKey:Encrypted by | ||
| contextKey | Static RAM:Plaintext | Until next reset | TPM2_Init | drbgState:Generates contextEncKey:Derived From | ||
| contextEncKey | Dynamic RAM:Plaintext | After Use | Automatic | contextKey:Derives nullProof:Derives phProof:Derives ehProof:Derives shProof:Derives | ||
| dupInSymKey | Input plaintext to RAM Input protected to RAM Output plaintext from RAM Output protected from RAM | Dynamic RAM:Plaintext | After Use | Automatic | sesSymKey:Encrypts sesHmacKey:Protects (Integrity) objSens:Encrypted by | |
| dupSeed | Input asym. encrypted to RAM Output asym. encrypted to RAM | Dynamic RAM:Plaintext | After Use | Automatic | objPub:Encrypts dupOutSymKey:Derived from dupOutHmacKey:Derived from | |
| dupOutSymKey | Dynamic RAM:Plaintext | After Use | Automatic | dupSeed:Derives objSens:Encrypted by objAuth:Encrypted by objSeed:Encrypted by | ||
| dupOutHmacKey | Dynamic RAM:Plaintext | After Use | Automatic | dupSeed:Derives objSens:Protects (Integrity) objAuth:Protects (Integrity) objSeed:Protects (Integrity) | ||
| creSeed | Input asym. encrypted to RAM Output asym. encrypted to RAM | Dynamic RAM:Plaintext | After Use | Automatic | creSymKey:Derives creHmacKey:Derives objPub:Encrypts | |
| creSymKey | Dynamic RAM:Plaintext | After Use | Automatic | creSeed:Derived From | ||
| creHmacKey | Dynamic RAM:Plaintext | After Use | Automatic | creSeed:Derived From | ||
| ephSensEccKey | Dynamic RAM:Plaintext | After Use | Automatic | drbgState:Generates |
Public Material – May be reproduced only in its original entirety (without revision).
| Name | Input - Output | Storage | Storage Duration | Zeroization | Related SSPs | |
|---|---|---|---|---|---|---|
| ephPubEccKey | Input plaintext to RAM Output plaintext from RAM | Dynamic RAM:Plaintext | After Use | Automatic | ephSensEccKey:Derives | |
| ekRsa | NVRAM:Plaintext | After Use | TPM2_VendorCmdZeroizeEK | objSens:Derived From | ||
| ekEcc | NVRAM:Plaintext | After Use | TPM2_VendorCmdZeroizeEK | objSens:Derived From | ||
| fuSigECCKey | NVRAM:Plaintext | After Use | N/A | |||
| fuSigLMSKey | NVRAM:Plaintext | After Use | N/A | |||
| seqAuth | Input plaintext to RAM Input protected to RAM Output protected from RAM | NVRAM:Plaintext | Until use of zeroization command or next reset | TPM2_SequenceComplete TPM2_EventSequenceComplete | sesSymKey:Derived From sesHmacKey:Derived From | |
| nullSeed | Static RAM:Plaintext | Until next reset | TPM2_Init | tdrbgState:Instantiated with | ||
| phSeed | NVRAM:Plaintext | After Use | TPM2_ChangePPS | tdrbgState:Instantiated with | ||
| ehSeed | NVRAM:Plaintext | After Use | TPM2_ChangeEPS | tdrbgState:Instantiated with | ||
| shSeed | NVRAM:Plaintext | After Use | TPM2_Clear | tdrbgState:Instantiated with | ||
| drbgState | Static RAM:Plaintext | Until next reset or use of TPM2_Clear | TPM2_Init TPM2_Clear | drbgSeed:Instantiates | ||
| drbgSeed | Dynamic RAM:Plaintext | After Use | Automatic | drbgState:Instantiated with | ||
| tdrbgState | Dynamic RAM:Plaintext | After Use | Automatic | nullSeed:Instantiates phSeed:Instantiates ehSeed:Instantiates shSeed:Instantiates | ||
| fuSymSeed | NVRAM:Plaintext | After Use | N/A | fuSymKey:Derived From | ||
| fuSymKey | Dynamic RAM:Plaintext | After Use | Automatic | fuSymSeed:Derives | ||
| diagSymSeed | NVRAM:Plaintext | After Use | N/A | diagSymKey:Derived From | ||
| diagSymKey | Dynamic RAM:Plaintext | After Use | Automatic | diagSymSeed:Derives |
The use of SHA-1 for digital signature generation is non-Approved and only available through non-Approved services. All other applications of SHA-1 are acceptable, where collision resistance is not required. Public Material – May be reproduced only in its original entirety (without revision).
| Algorithm | Underlying algorithm | Key size (bits) | Security strength (bits) | ||
|---|---|---|---|---|---|
| KBKDF | SHA-1 | size ≥ 128 | 128 | ||
| size < 128 | Key size | ||||
| SHA2-256 | size ≥ 192 | 192 | |||
| size < 192 | Key size | ||||
| SHA2-384 SHA2-512 | size ≥ 256 | 256 | |||
| size < 256 | Key size | ||||
| HMAC | SHA-1 | size ≥ 128 | 128 | ||
| size < 128 | Key size | ||||
| SHA2-256 | size ≥ 192 | 192 | |||
| size < 192 | Key size | ||||
| SHA2-384 SHA2-512 | size ≥ 256 | 256 | |||
| size < 256 | Key size | ||||
| DRBG | SHA2-256 | - | 256 | ||
| AES | - | 128 / 192 / 256 | 128 / 192 / 256 | ||
| RSA | - | 2048 / 3072 / 4096 | 112 / 128 / 142 | ||
| ECC | - | 256 / 384 / 448 / 521 | 128 / 192 / 224 / 256 |
The next table gives the security strength of a key depending on the underlying algorithm used and its Table 29
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details |
|---|---|---|---|---|---|
| Firmware integrity test | CRC 16 | EDC | SW/FW Integrity | Successful execution of TPM2_Startup command indicates tests have been run | FW integrity is verified by computing an EDC (CRC-16 [ISO13239]) and comparing it to reference values. |
| HW integrity | HW registers verification | KAT | Critical Function | Successful execution of TPM2_Startup command indicates tests have been run | HW integrity is guaranteed via check of HW sensors. If failure is detected during boot sequence, status is set to FAIL, and error is returned. |
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions |
|---|---|---|---|---|---|---|
| AES-CBC (A5356) Encrypt | AES-128-CBC | KAT | CAST | Bit #7 clear | AES CBC 128 encryption of known data compared to a reference value. | Power On |
| AES-CBC (A5356) Decrypt | AES-128-CBC | KAT | CAST | Bit #7 clear | AES CBC 128 decryption of known encrypted data and comparison to the expected plaintext data | Power On |
| ECDSA KeyGen (FIPS186-4) (A5358) | P-256, P-384, P-521 | PCT | PCT | Key creation failure | Depending on the key purpose (signing or key establishment) an ECDSA signature is generated (k fixed and the message varies) and verified with pairwise consistency test as defined by [56Ar3] or a scalar multiplication is done and compared to the public key. | Upon ECC Key Generation |
| ECDSA SigGen (FIPS186-4) (A5358) | NIST P-256 | KAT | CAST | Bit #10 clear | ECDSA signature generation on known data with known key and k. Output of signature is compared to a reference signature. | Power On |
| ECDSA SigVer (FIPS186-4) (A5358) | NIST P-256 | KAT | CAST | Bit #10 clear | ECDSA signature verification on known signature with known key and k. | Power On |
| Entropy | RCT and APT | [90B] Health- Test | CAST | Bit #1 clear | AIS31 and [90B] (RCT and APT) start-up health tests on ENT(P) output sequence. If test fails, test status is set to FAIL, and error is returned | At each random bits generation |
| Firmware loading | ECDSA P-384 and LMS | Signature Verification | SW/FW Load | Error returned on FW loading command | Verification of chained digest and signature to ensure authentication of the FW | Upon firmware load |
| Hash DRBG (A5351) | SHA2-256 | KAT | CAST | Bit #1 clear | Instantiate then Reseed are seeded with a known seed value (64 bytes). Random is then generated with Generate API to output a 32-bytes value compared to a reference value (single test sequence done in accordance with §11.3 of [90A]) | Power On |
| HMAC-SHA-1 (A5355) | HMAC-SHA1 | KAT | CAST | Bit #5 clear | HMAC on known data and known key. Comparison of output to an expected MAC value (20 bytes) | Power On |
| KAS-ECC Sp800-56Ar3 (A5358) | NIST P-256 | KAT | CAST | Bit #9 clear | Primitive "Z" Computation and key derivation are implemented: a known private key d is used with a known point P of NIST P-256 curve to compute Q = dP. Key derivation of Q performed with SHA-1 underlying algorithm to output a key of 20 bytes that is compared to a refence value | Power On |
| KDF SP800-108 (A5354) | N/A | KAT | CAST | Bit #6 clear | KDF on known data and known label. Comparison of output to an expected derivation value (32 bytes) | Power On |
The Module performs self-tests to ensure the proper operation of the Module. Per FIPS 140-3 these are categorized as either pre-operational self-tests or conditional self-tests. Pre-operational self–tests are available on demand by power cycling the Module. The Module performs the following pre-operational self-tests in the table below: Table 30: Pre-Operational Self-Tests
The Module performs the following conditional self-tests as shown in the table below. The bit index indicated in the “Indicator” column corresponds to the index in the algo_status field in the TPM2_GetTestResult response. Public Material – May be reproduced only in its original entirety (without revision).
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions |
|---|---|---|---|---|---|---|
| LMS SigVer (A5360) | LMOTS_SHA256_N32_W4 LMS_SHA256_M32_H10 | KAT | CAST | Bit #8 clear | LMS signature verification of known signature with known data and known key. | Power On |
| RSA SigGen (FIPS186-5) (A5357) | RSASSA-PKCS1-v1_5 | KAT | CAST | Bit #12 clear | RSA signature generation on known data with a known key. Output of signature is compared to a reference signature (covers also KTS-IFC functionality) | Power On |
| RSA SigVer (FIPS186-5) (A5357) | RSASSA-PKCS1-v1_5 | KAT | CAST | Bit #12 clear | RSA signature verification on a known signature with a known key (covers also KTS-IFC functionality) | Power On |
| RSA KeyGen (FIPS186-5) (A5357) | 2048, 3072 or 4096-bit | PCT | PCT | Key creation failure | Depending on the key purpose (signing or encrypting) indicated in sign attribute of the key, encryption/decryption or signing/verification is done on known data | Upon RSA Key Generation |
| SHS | SHA1, SHA2-256, SHA2-512, SHA3-256 | KAT | CAST | Bit #2 clear Bit #3 clear Bit #4 clear | Hash of known data and comparison of output to an expected digest. SHA-1, SHA2-256, SHA2-512 are tested twice to cover each of the two implementations covered by CAVP Cert. #A5352 and #A5353. | Power On |
| EDDSA SigGen (A5359) | Ed448 | KAT | CAST | Bit #11 clear | EdDSA signature generation on known data with known key. Output of signature is compared to a reference signature. | Power-On |
| EDDSA SigVer (A5359) | Ed448 | KAT | CAST | Bit #11 clear | Signature verification performed on the generated signature | Power-On |
| EDDSA KeyGen (A5359) | Ed448 | PCT | PCT | Key creation failure | An EdDSA signature is generated and verified with pairwise consistency test. | Upon EdDSA Key Generation |
Table 31: Conditional Self-Tests Public Material – May be reproduced only in its original entirety (without revision).
| Algorithm or Test | Test Method | Test Type | Period | Periodic Method |
|---|---|---|---|---|
| Firmware integrity test | EDC | SW/FW Integrity | On demand | Manually |
| HW integrity | KAT | Critical Function | On demand | Manually |
| Algorithm or Test | Test Method | Test Type | Period | Periodic Method |
|---|---|---|---|---|
| AES-CBC (A5356) Encrypt | KAT | CAST | On Demand | Manually |
| AES-CBC (A5356) Decrypt | KAT | CAST | On Demand | Manually |
| ECDSA KeyGen (FIPS186-4) (A5358) | PCT | PCT | N/A | Manually |
| ECDSA SigGen (FIPS186-4) (A5358) | KAT | CAST | On Demand | Manually |
| ECDSA SigVer (FIPS186-4) (A5358) | KAT | CAST | On Demand | Manually |
| Entropy | [90B] Health- Test | CAST | On Demand | Manually |
| Firmware loading | Signature Verification | SW/FW Load | On Demand | Manually |
| Hash DRBG (A5351) | KAT | CAST | On Demand | Manually |
| HMAC-SHA-1 (A5355) | KAT | CAST | On Demand | Manually |
| KAS-ECC Sp800-56Ar3 (A5358) | KAT | CAST | On Demand | Manually |
| KDF SP800-108 (A5354) | KAT | CAST | On Demand | Manually |
| LMS SigVer (A5360) | KAT | CAST | On Demand | Manually |
| RSA SigGen (FIPS186-5) (A5357) | KAT | CAST | On Demand | Manually |
| RSA SigVer (FIPS186-5) (A5357) | KAT | CAST | On Demand | Manually |
| RSA KeyGen (FIPS186-5) (A5357) | PCT | PCT | N/A | Manually |
| SHS | KAT | CAST | On Demand | Manually |
Table 32: Pre-Operational Periodic Information Public Material – May be reproduced only in its original entirety (without revision).
| Algorithm or Test | Test Method | Test Type | Period | Periodic Method |
|---|---|---|---|---|
| EDDSA SigGen (A5359) | KAT | CAST | On Demand | Manually |
| EDDSA SigVer (A5359) | KAT | CAST | On Demand | Manually |
| EDDSA KeyGen (A5359) | PCT | PCT | N/A | Manually |
| Name | Description | Conditions | Recovery Method | Indicator |
|---|---|---|---|---|
| ES1 | The Module fails a KAT, PCT, FW or HW integrity verification, [90B] health test | The Module enters the failure state | Reboot/Power cycle the module | Outputs return code of TPM_RC_FAILURE, otherwise it indicates successful completion by TPM_RC_SUCCESS |
| ES2 | The Module fails a firmware loading test | The Module returns to normal state | None | Return code different from TPM_RC_SUCCESS sent on firmware upgrade start command |
Table 33: Conditional Periodic Information
Table 34: Error States All cryptographic functions are inhibited while the Module is in an error state. Successful completion of self-tests can be verified through use of TPM2_GetTestResult command. The first 4 bytes of response indicate self-tests status. If they are equal to 0, self-tests completed successfully. If not, the subsequent 4 bytes indicate the list of algorithms not fully self-tested. Public Material – May be reproduced only in its original entirety (without revision).
| Policy command | Authentication mechanism | Description |
|---|---|---|
| T PM2_PolicyAuthValue | Message Authentication Code | authValue of authorized entity is used as HMAC key in authorization HMAC (as for HMAC session) |
| T PM2_ PolicySigned | Public Key Digital Signature Algorithm or Message Authentication Code | Signature with asymmetric or HMAC key |
| TPM2_ PolicyAuthorize | Message Authentication Code | Signature with HMAC key being one of the hierarchy proofs |
| TPM2_PolicySecret | Message Authentication Code | authValue of reference entity is provided in HMAC session, or policy session containing TPM2_PolicyAuthValue |
Installation and Initialization: The following steps must be performed in order to securely install, initialize, and start up the Module in the FIPS 140-3 Approved mode of operation:
| TPM2_PolicyTicket | Message Authentication Code | Signature with HMAC key (one of the proofs) generated by TPM2_PolicySigned or TPM2_PolicySecret |
|---|---|---|
| Bound session | Message Authentication Code | authValue of bound entity is used as KDK generated from KBKDF in session key derivation |
| Module Configuration | |
|---|---|
| Module name / HW P/N | ST33KTPM2I |
| Package | UFQFPN32 WF, WLCSP24 |
| Interface | SPI / I2C |
| Marking | KTPMI ZA9 |
| FW version | 00.0A.02.00 (10.512) |
| TPM2.0 revision | 1.59 |
| Module Configuration | |
|---|---|
| Module name / HW P/N | ST33KTPM2A |
| Package | UFQFPN32 WF, TSSOP20 |
| Interface | SPI / I2C |
Table 35
| Marking | KTPMA AC5 |
|---|---|
| FW version | 00.0A.02.00 (10.512) |
| TPM2.0 revision | 1.59 |
| Module Configuration | |
|---|---|
| Module name / HW P/N | ST33KTPM2I |
| Package | UFQFPN32 WF, WLCSP24 |
| Interface | SPI / I2C |
| Marking | KTPMI ZB1 |
| FW version | 00.0A.02.00 (10.512) |
| TPM2.0 revision | 1.59 |
| Module Configuration | |
|---|---|
| Module name / HW P/N | ST33KTPM2A |
| Package | UFQFPN32 WF, TSSOP20 |
| Interface | SPI / I2C |
| Marking | STV10TPM AD6 |
| FW version | 00.0A.02.00 (10.512) |
| TPM2.0 revision | 1.59 |
The current FIPS 140-3 Level 2 Security Policy applies to the Module configurations listed above when the Module is configured in FIPS 140-3 Level 2 mode with the command TPM2_SetCapability. For the configurations supporting both SPI and I2C interfaces, the selection of the mode is done during the boot of the Module.
No specific initialization procedure is required. Public Material – May be reproduced only in its original entirety (without revision).
No initialization procedures are required.
Rules of Operation
End-of-life of the product requires the following zeroization commands to be executed to remove all CSPs from the memory of the Module:
The Module does not implement any mitigation method against other attacks. Public Material – May be reproduced only in its original entirety (without revision).
| Abbreviation | Full Specification Name |
|---|---|
| [TPM2.0 Part1] | TPM2.0 Main, Part 1, Architecture, rev 1.59, TCG |
| [TPM2.0 Part2] | TPM2.0 Main, Part 2, Structures, rev 1.59, TCG |
| [TPM2.0 Part3] | TPM2.0 Main, Part 3, Commands, rev 1.59, TCG |
| [TPM2.0 Part4] | TPM2.0 Main, Part 4, Supporting routines, rev 1.59, TCG |
| [PTP 1.06] | TCG PC Client Platform TPM Profile (PTP) Specification, rev. 1.06 |
| [ISO19790] | International Standard, ISO/IEC 19790, Information technology — Security techniques — Test requirements for cryptographic modules, Third edition, March 2017 |
| [ISO24759] | International Standard, ISO/IEC 24759, Information technology — Security techniques — Test requirements for cryptographic modules, Second and Corrected version, 15 December 2015 |
| [ISO13239] | International Standard, ISO/IEC 13239, Information technology — Telecommunications and information exchange between systems — High-level data link control (HDLC) procedures, July 2002 |
| [140-3] | Security Requirements for Cryptographic Modules, March 22, 2019 |
| [140] | NIST Special Publication 800-140, FIPS 140-3 Derived Test Requirements (DTR), CMVP Validation Authority Updates to ISO/IEC 24759, March 2020 |
| [140A] | NIST Special Publication 800-140A, CMVP Documentation Requirements, CMVP Validation Authority Updates to ISO/IEC 24759, March 2020 |
| [140Br1] | NIST Special Publication 800-140B revision 1, CMVP Security Policy Requirements, CMVP Validation Authority Updates to ISO/IEC 24759 and ISO/IEC 19790 Annex B, November 2023 |
| [140C] | NIST Special Publication 800-140Cr2, CMVP Approved Security Functions, CMVP Validation Authority Updates to ISO/IEC 24759, July 2023 |
| [140D] | NIST Special Publication 800-140Dr2, CMVP Approved Sensitive Security Parameter Generation and Establishment Methods, CMVP Validation Authority Updates to ISO/IEC 24759, July 2023 |
| [140E] | NIST Special Publication 800-140E, CMVP Approved Authentication Mechanisms, CMVP Validation Authority Requirements for ISO/IEC 19790:2012 Annex E and ISO/IEC 24759 Section 6.17, March 2020 |
| [140F] | NIST Special Publication 800-140Fr1, CMVP Approved Non-Invasive Attack Mitigation Test Metrics, CMVP Validation Authority Updates to ISO/IEC 24759, August 2021 |
| [IG] | Implementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program, March 2024 |
| [108] | NIST Special Publication 800-108r1-upd1, Recommendation for Key Derivation Using Pseudorandom Functions (Revised), August 2022 |
| [131A] | Transitions: Recommendation for Transitioning the Use of Cryptographic Algorithms and Key Lengths, Revision 2, March 2019 |
| [133] | NIST Special Publication 800-133, Recommendation for Cryptographic Key Generation, Revision 2, June 2020 |
References and Definitions The following standards are referred to in this Security Policy: Public Material – May be reproduced only in its original entirety (without revision).
| Abbreviation | Full Specification Name |
|---|---|
| [135] | National Institute of Standards and Technology, Recommendation for Existing Application- Specific Key Derivation Functions, Special Publication 800-135rev1, December 2011 |
| [186] | National Institute of Standards and Technology, Digital Signature Standard (DSS), Federal Information Processing Standards Publication 186-5, Feb 2023 |
| [197] | National Institute of Standards and Technology, Advanced Encryption Standard (AES), Federal Information Processing Standards Publication 197-upd1, May, 2023 |
| [198] | National Institute of Standards and Technology, The Keyed-Hash Message Authentication Code (HMAC), Federal Information Processing Standards Publication 198-1, July, 2008 |
| [180] | National Institute of Standards and Technology, Secure Hash Standard, Federal Information Processing Standards Publication 180-4, August 2015 |
| [202] | FEDERAL INFORMATION PROCESSING STANDARDS PUBLICATION, SHA-3 Standard: Permutation- Based Hash and Extendable-Output Functions, FIPS PUB 202, August 2015 |
| [208] | National Institute of Standards and Technology, Recommendation for Stateful Hash-Based Signature Schemes, October 2020 |
| [38A] | National Institute of Standards and Technology, Recommendation for Block Cipher Modes of Operation, Methods and Techniques, Special Publication 800-38A, December 2001 |
| [56Ar3] | NIST Special Publication 800-56A Revision 3, Recommendation for Pair-Wise Key Establishment Schemes Using Discrete Logarithm Cryptography, April 2018 |
| [56Br2] | NIST Special Publication 800-56B Revision 2, Recommendation for Pair-Wise Key Establishment Schemes Using Finite Field Cryptography, March 2019 |
| [90A] | National Institute of Standards and Technology, Recommendation for Random Number Generation Using Deterministic Random Bit Generators, Special Publication 800-90A, Revision 1, June 2015 |
| [90B] | National Institute of Standards and Technology, Recommendation for the Entropy Sources Used for Random Bit Generation, Special Publication 800-90B, January 2018 |
| [5639] | Request for Comments, Elliptic Curve Cryptography (ECC) Brainpool Standard Curves and Curve Generation, March 2010 |
Table 40
| Acronym | Definition |
|---|---|
| APT | Adaptive Proportion Test |
| BN P-256 | Barreto-Naehrig 256-bit elliptic curve |
| BP P-256 | Brainpool 256-bit elliptic curve |
| BP P-384 | Brainpool 384-bit elliptic curve |
| BP P-512 | Brainpool 512-bit elliptic curve |
| FW | Firmware |
| HW | Hardware |
| KAT | Know Answer Test |
| I2C | Inter-Integrated Circuit |
| MPU | Memory Protection Unit |
| RCT | Repetition Count Test |
| SPI | Serial Peripheral Interface |
| SSP | Sensitive Security Parameter |
| TCG | Trusted Computing Group |
| TPM | Trusted Platform Module |
Table 41