All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Trusted Platform Module ST33KTPM2X / ST33KTPM2XSPI

Certificate#5109StandardFIPS 140-3Level2TypeHardwareEmbodimentSingle ChipStatusActiveVendorSTMicroelectronics
Medium review priority  ·  exposes HSM/SE firmware trust anchor  ·  last validated 7 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level2
Module typeHardware
EmbodimentSingle Chip
StatusActive
Sunset date12/14/2030
CaveatWhen installed, initialized and configured as specified in Section 11 of the Security Policy; When operated in approved mode
VendorSTMicroelectronics

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Trusted Platform Module ST33KTPM2X / ST33KTPM2XSPI
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>recovery<br/>upgrade<br/>update</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>Unauthenticated<br/>UnAuth</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C6 clue;
  class I2,I3,I6 infer;
  class R2,R3,R6 risk;
  class E2,E3,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Trusted Platform Module ST33KTPM2X / ST33KTPM2XSPI
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>recovery<br/>upgrade<br/>update</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>Unauthenticated<br/>UnAuth</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C6 clueLow;

Security Policy, page by page

Page 1

STMicroelectronics Trusted Platform Module ST33KTPM2X / ST33KTPM2XSPI Document Version: 01-01 Date: 2025-12-01 Public Material – May be reproduced only in its original entirety (without revision).

Page 2
Table of Contents
#SectionPage
Page 3

Public Material – May be reproduced only in its original entirety (without revision).

Page 4
List of Tables
ItemPage
Table 1: Security Levels5
Table 2: Tested Module Identification – Hardware8
Table 3 – KE2 Module Configuration9
Table 4 – KE3 Module Configuration9
Table 5 – KG8 Module Configuration9
Table 6 – KG9 Module Configuration10
Table 7 – KJ5 Module Configuration10
Table 8 – KJ0 Module Configuration10
Table 9 – KJ1 Module Configuration11
Table 10: Modes List and Description12
Table 11: Approved Algorithms13
Table 12: Vendor-Affirmed Algorithms13
Table 13: Non-Approved, Allowed Algorithms with No Security Claimed13
Table 14: Non-Approved, Not Allowed Algorithms14
Table 15: Security Function Implementations19
Table 16: Entropy Certificates19
Table 17: Entropy Sources20
Table 18: Ports and Interfaces21
Table 19 – UFQFPN32 Pins Definition23
Table 20: Authentication Methods24
Table 21: Roles25
Table 22 – Mapping between services25
Table 23: Approved Services67
Table 24: Non-Approved Services73
Table 25: Mechanisms and Actions Required77
Table 26: EFP/EFT Information78
Table 27: Hardness Testing Temperatures78
Table 28: Storage Areas80
Table 29: SSP Input-Output Methods81
Table 30: SSP Zeroization Methods82
Table 31: SSP Table 184
Table 32: SSP Table 288
.96
Table 34: Pre-Operational Self-Tests97
Table 35: Conditional Self-Tests98
Table 36: Pre-Operational Periodic Information99
Table 37: Conditional Periodic Information100
Table 38: Error States100
Table 39 – List of policy commands to use in a policy session102
Table 40 – References106
Table 41 – Acronyms and Definitions107
Page 5
List of Figures
ItemPage
Figure 1 – HW block diagram7
Figure 2 – UFQFPN32 Package8
Figure 3 – UFQFPN32 Pinout Diagram23
Figure 4 – Firmware block diagram75
Page 6
2 Cryptographic Module Specification

The ST33KTPM2X / ST33KTPM2XSPI module, hereafter denoted as the Module, is a fully integrated security module implementing the revision 1.59 of the Trusted Computing Group (TCG) specification for Trusted Platform Modules (TPM) version 2.0.

2.1 Description

Purpose and Use: The Module is intended for use by US Federal agencies or other markets that require FIPS 140-3 validated level 2. The Module is designed to be integrated into personal computers or any other embedded electronic systems. TPM is primarily used for cryptographic keys generation, keys storage, keys management and secure storage for digital certificates. Module Type: Hardware Module Embodiment: SingleChip Module Characteristics: Cryptographic Boundary: The cryptographic boundary of the Module is defined as the perimeter of the IC package and is represented in the next figure. The Module is composed of:

Page 7

Figure 1

Page 8
Model and/or Part NumberHardware VersionFirmware VersionProcessorsFeatures
ST33KTPM2XST33K1M5T revC & revD9.512 (dec.) 0x00.09.02.00 (hex.)ST33K1M5TSPI or I2C The interface is exclusive and selectable dynamically during product boot.
ST33KTPM2XSPIST33K1M5T revC & revD9.512 (dec.) 0x00.09.02.00 (hex.)ST33K1M5TSPI

Module Configuration*

2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification

Page 9
Module name / HW P/NST33KTPM2XSPI
PackageUFQFPN32
InterfaceSPI
MarkingKTPM KE2
FW version00.09.02.00 (9.512)
TPM2.0 revision1.59
Module Configuration*
Module name / HW P/NST33KTPM2X
PackageUFQFPN32
InterfaceSPI / I2C
MarkingKTPM KE3
FW version00.09.02.00 (9.512)
TPM2.0 revision1.59
Module Configuration*
Module name / HW P/NST33KTPM2XSPI
PackageUFQFPN32
InterfaceSPI
MarkingKTPM KG8
FW version00.09.02.00 (9.512)
TPM2.0 revision1.59

Module Configuration*

The default firmware version of KE3 is 9.256. To operate with firmware version 9.512, module must be first field upgraded to 9.512. The default firmware version of KG8 is 9.257. To operate with firmware version 9.512, module must be first field upgraded to 9.512. The default firmware version of KG9 is 9.257. To operate with firmware version 9.512, module must be first field upgraded to 9.512. Public Material – May be reproduced only in its original entirety (without revision).

Page 10
Module name / HW P/NST33KTPM2X
PackageUFQFPN32
InterfaceSPI / I2C
MarkingKTPM KG9
FW version00.09.02.00 (9.512)
TPM2.0 revision1.59
Module Configuration*
Module name / HW P/NST33KTPM2XSPI
PackageUFQFPN32
InterfaceSPI
MarkingKTPM KJ5
FW version00.09.02.00 (9.512)
TPM2.0 revision1.59
Module Configuration*
Module name / HW P/NST33KTPM2XSPI
PackageUFQFPN32
InterfaceSPI
MarkingKTPM KJ0
FW version00.09.02.00 (9.512)
TPM2.0 revision1.59
Module Configuration*
Module name / HW P/NST33KTPM2X

The default firmware version of KJ5 is 9.258. To operate with firmware version 9.512, module must be first field upgraded to 9.512. Public Material – May be reproduced only in its original entirety (without revision).

Page 11
PackageUFQFPN32
InterfaceSPI / I2C
MarkingKTPM KJ1
FW version00.09.02.00 (9.512)
TPM2.0 revision1.59
Mode NameDescriptionTypeStatus Indicator
Normal modeTPM is in normal operation mode when all pre- operational and conditional self- tests (apart from FW load and PCT tests) are complete. All approved services are usable. The corresponding indicator reports if the service uses an approved cryptographic algorithm or security function.ApprovedTPM2_GetCapability (capability = TPM_CAP_VENDOR_PROPERTIES) with the sub-capability TPM_SUBCAP_VENDOR_TPMA_MODES = 0x7 shall be used. It outputs a 2-bit indicator equals to 01b if the module is in an approved mode of operation
Non- approved mode of operationThe module enters a non-approved mode if one of the non-approvedNon- ApprovedTPM2_GetCapability (capability = TPM_CAP_VENDOR_PROPERTIES) with the sub-capability TPM_SUBCAP_VENDOR_TPMA_MODES = 0x7 shall be used. It outputs a 2-bit indicator

Table 9 – KJ1 Module Configuration The current FIPS 140-3 level 2 Security Policy applies to the Module configurations listed above when the Module is configured in FIPS 140-3 level 2 mode with the command TPM2_SetCapability. For the configurations supporting both SPI and I2C interfaces, the selection of the mode is done during the boot

2.3 Excluded Components

N/A Public Material – May be reproduced only in its original entirety (without revision).

Page 12

Mode Name

Description services is used by the operator.

Type

Status Indicator equals to 10b if the module is in a non-approved mode of operation

AlgorithmCAVP CertPropertiesReference
AES-CBCA5356-SP 800-38A
AES-CFB128A5356-SP 800-38A
AES-CTRA5356-SP 800-38A
AES-ECBA5356-SP 800-38A
AES-OFBA5356-SP 800-38A
ECDSA KeyGen (FIPS186-4)A5358-FIPS 186-4
ECDSA KeyVer (FIPS186-4)A5358-FIPS 186-4
ECDSA SigGen (FIPS186-4)A5358-FIPS 186-4
ECDSA SigVer (FIPS186-4)A5358-FIPS 186-4
Hash DRBGA5351-SP 800-90A Rev. 1
HMAC-SHA-1A5355-FIPS 198-1
HMAC-SHA2-256A5355-FIPS 198-1
HMAC-SHA2-384A5355-FIPS 198-1
HMAC-SHA2-512A5355-FIPS 198-1
HMAC-SHA3-256A5355-FIPS 198-1
HMAC-SHA3-384A5355-FIPS 198-1
KAS-ECC Sp800-56Ar3A5358-SP 800-56A Rev. 3
KDF SP800-108A5354-SP 800-108 Rev. 1
KTS-IFCA5357-SP 800-56B Rev. 2
LMS SigVerA5360-SP 800-208
RSA Decryption Primitive Sp800-56Br2 (CVL)A5357-SP 800-56B Rev. 2
RSA KeyGen (FIPS186-5)A5357-FIPS 186-5
RSA SigGen (FIPS186-5)A5357-FIPS 186-5
RSA SigVer (FIPS186-5)A5357-FIPS 186-5
SHA-1A5352-FIPS 180-4

Table 10: Modes List and Description

2.5 Algorithms

Approved Algorithms: The Module implements the Approved cryptographic algorithms listed in the table below. Public Material – May be reproduced only in its original entirety (without revision).

Page 13
AlgorithmCAVP CertPropertiesReference
SHA-1A5353-FIPS 180-4
SHA2-256A5352-FIPS 180-4
SHA2-256A5353-FIPS 180-4
SHA2-384A5352-FIPS 180-4
SHA2-384A5353-FIPS 180-4
SHA2-512A5352-FIPS 180-4
SHA2-512A5353-FIPS 180-4
SHA3-256A5352-FIPS 202
SHA3-384A5352-FIPS 202
NamePropertiesImplementationReference
CKGKey Type:SymmetricN/ASection 4, Example 1 of [133r2]; IG D.H
CKG- AsymKey Type:AsymmetricN/ASection 4, Example 1 of [133r2]; IG D.H
NameCaveatUse and Function
XORNo security claimed per IG 2.4.A with the example of scenario #1. The algorithm: * is not used except for this purpose * does not access or share CSPs in a way that counters the requirements of the IG * not intended to be used as a security function. * can't be confused for a security functionObfuscation of input or output data

Table 11: Approved Algorithms Vendor-Affirmed Algorithms: The Module implements the Vendor Affirmed cryptographic algorithms listed. D.H N/A Table 12: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: Non-Approved, Allowed Algorithms with No Security Claimed: The Module implements the Non-Approved, Allowed cryptographic Algorithms with No Security Table 13: Non-Approved, Allowed Algorithms with No Security Claimed Non-Approved, Not Allowed Algorithms: Public Material – May be reproduced only in its original entirety (without revision).

Page 14
NameUse and Function
ECC BN P-256 (non-compliant)Key generation, digital signature generation based on ECC BN P-256
ECC derived keys (non-compliant)Secret exchange or digital signature generation/verification
ECDAA (non- compliant)Key generation, digital signature generation
ECDSA (non- compliant)Digital signature with an ECC signing key generated with an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL), derived from a derivation parent key, or a key loaded in the NULL hierarchy
ECSchnorr (non- compliant)Key generation, digital signature generation and verification
HMAC (non- compliant)Key length < 112 bits for message authentication
KAS (non- compliant)Key agreement with an ECC key that has an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL)
KBKDF (non- compliant)Non-Approved key derivation usage
KTS-IFC (non- compliant)Key encapsulation with an RSA decryption key that has an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL)
RSA (non- compliant)1024-bit RSA digital signature generation or with a key loaded in the Null hierarchy
RSA with no padding mode (null scheme) (non-compliant)Key transport
RSAES-PKCS1- v1_5 (non- compliant)Key transport
SHA-1 (non- compliant)Digital signature generation

The Module implements the Non-Approved, Not Allowed cryptographic algorithms listed. Table 14: Non-Approved, Not Allowed Algorithms

2.6 Security Function Implementations

Next table shows the Security Function Implementations that the Module implements: Public Material – May be reproduced only in its original entirety (without revision).

Page 15
NameTypeDescriptionPropertiesAlgorithms
KeyGenAsymKeyPair- KeyGenKey-Pair GenerationPublications:FIPS 186-5ECDSA KeyGen (FIPS186-4): (A5358) CKG-Asym: () Key Type: Asymmetric RSA KeyGen (FIPS186-5): (A5357)
KeyVerAsymKeyPair- KeyVerKey-Pair VerificationPublications:FIPS 186-5ECDSA KeyVer (FIPS186-4): (A5358)
KeyValAsymKeyPair- PubKeyValKey-pair ValidationPublications:186-5KAS-ECC Sp800-56Ar3: (A5358) Function: Full Validation KTS-IFC: (A5357) Function: partialVal
AES-ENCBC-UnAuthUnauthenticated EncryptionPublication:FIPS 197AES-CBC: (A5356) AES-CFB128: (A5356) AES-CTR: (A5356) AES-ECB: (A5356) AES-OFB: (A5356)
AES-DECBC-UnAuthUnauthenticated DecryptionPublication:FIPS 197AES-CBC: (A5356) AES-CFB128: (A5356) AES-CTR: (A5356) AES-ECB: (A5356) AES-OFB: (A5356)
SigGenDigSig-SigGenSignature GenerationPublication:FIPS 186-5ECDSA SigGen

Public Material – May be reproduced only in its original entirety (without revision).

Page 16
NameTypeDescriptionPropertiesAlgorithms
(FIPS186-4): (A5358) RSA SigGen (FIPS186-5): (A5357) SHA2-256: (A5352) SHA2-384: (A5352) SHA2-512: (A5352) SHA3-256: (A5352) SHA3-384: (A5352)
SigVerDigSig-SigVerSignature VerificationPublications:FIPS 186-5LMS SigVer: (A5360) ECDSA SigVer (FIPS186-4): (A5358) RSA SigVer (FIPS186-5): (A5357) SHA2-256: (A5352) SHA2-384: (A5352) SHA2-512: (A5352) SHA3-256: (A5352) SHA3-384: (A5352)
DRBGDRBGRandom Number GenerationPublication: :SP800- 90AHash DRBG: (A5351) Method: SHA2- 256 SHA2-256: (A5352)
ENT-ESVENT-ESVESVPublications:SP800- 90BSHA2-256: (A5352) Conditioning Component: SHA2-256

Public Material – May be reproduced only in its original entirety (without revision).

Page 17
NameTypeDescriptionPropertiesAlgorithms
KASKAS-FullKey establishmentPublications:SP 800-56A, Rev 3KAS-ECC Sp800-56Ar3: (A5358) Schemes: fullUnified, onePassDH KDF: oneStepKDF SHA-1: (A5352) SHA2-256: (A5352) SHA2-384: (A5352) SHA2-512: (A5352) SHA3-256: (A5352) SHA3-384: (A5352)
KTS-IFCKTS-EncapKey EncapsulationPublication:SP 800- 56B rev 2, IG D.G Method:KTS- OAEP-basicKTS-IFC: (A5357) RSA Decryption Primitive Sp800-56Br2: (A5357)
KTSKTS-WrapKey transportPublication:SP 800- 38F, IG D.GHMAC-SHA2- 256: (A5355) AES-CFB128: (A5356)
KBKDFKBKDFKey-Based Key DerivationPublications:SP800- 108KDF SP800- 108: (A5354) SHA-1: (A5353) SHA2-256: (A5353) SHA2-384: (A5353) SHA2-512: (A5353) SHA3-256: (A5352) SHA3-384: (A5352)

Public Material – May be reproduced only in its original entirety (without revision).

Page 18
NameTypeDescriptionPropertiesAlgorithms
MACMACMessage AuthenticationPublication:FIPS198HMAC-SHA-1: (A5355) HMAC-SHA2- 256: (A5355) HMAC-SHA2- 384: (A5355) HMAC-SHA2- 512: (A5355) HMAC-SHA3- 256: (A5355) HMAC-SHA3- 384: (A5355) SHA-1: (A5352) SHA2-256: (A5352) SHA2-384: (A5352) SHA2-512: (A5352) SHA3-256: (A5352) SHA3-384: (A5352)
SHASHASecure HashPublications:FIPS 180-4, FIPS 202SHA-1: (A5353, A5352) SHA2-256: (A5352, A5353) SHA2-384: (A5352, A5353) SHA2-512: (A5352, A5353) SHA3-256: (A5352) SHA3-384: (A5352)
CKGCKGSymmetric Key GenerationPublications:SP800- 133rev2, Section 4; IG D.HHash DRBG: (A5351)

Public Material – May be reproduced only in its original entirety (without revision).

Page 19
NameTypeDescriptionPropertiesAlgorithms
KAS-KeyGenKAS-KeyGenKAS-ECC Key GenerationPublication:SP800- 56Arev3KAS-ECC Sp800-56Ar3: (A5358)
Cert NumberVendor Name
E41STMicroelectronics
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
Trusted Platform Module ST33KTPM2X, ST33KTPM2XSPI, ST33KTPM2XI2C,PhysicalST33K1M5T/A platforms1 bit0.819266 bitsA5352 (SHA2-256)

Table 15: Security Function Implementations

2.7 Algorithm Specific Information

Notes: KAS [56Ar3] - Per [IG] D.F Scenario 2 path (2), compliant key agreement scheme where testing is performed end-to-end for the shared secret computation and a KDF compliant with <KDA>. With/without key confirmation.

2.8 RBG and Entropy

The Module implements:

Page 20

Name ST33KTPM2A, ST33KTPM2I entropy source

Type

Operational Environment

Sample Size

Entropy per Sample

Conditioning Component

2.9 Key Generation

For Key Generation methods, see Section 2.6 Security Function Implementations above.

2.10 Key Establishment

Key Agreement Information For Key Establishment methods, see Section 2.6 Security Function Implementations above. Key Transport Information For Key Transport methods, see Section 2.6 Security Function Implementations above.

2.11 Industry Protocols

The Module does not implement any Industry Protocols. Public Material – May be reproduced only in its original entirety (without revision).

Page 21
Physical PortLogical Interface(s)Data That Passes
SPI_NSS / SPI_CLK / SPI_MOSI / I2C_SCL / I2C_SDA / RESET / PPControl InputControl parts of the TPM commands provided to the security module. It concerns all bytes of a command except plaintext data, ciphertext data and SSPs (entered with the data input interface).
SPI_NSS / SPI_CLK / SPI_MISO / I2C_SCL / I2C_SDA / PIRQControl OutputControl parts of the TPM responses output by the security module. It concerns all bytes of a response except plaintext data, ciphertext data and SSPs (output with the data output interface) and except the responseCode of a response (output with the status output interface)
SPI_NSS / SPI_CLK / SPI_MISO / I2C_SCL / I2C_SDA / PIRQStatus OutputStatus output by the security module (responseCode parameter of a response)
SPI_NSS / SPI_CLK / SPI_MOSI / I2C_SCL / I2C_SDAData InputData (plaintext data, ciphertext data and SSPs) provided to the security module as part of an input processing command
SPI_NSS / SPI_CLK / SPI_MISO / I2C_SCL / I2C_SDAData OutputData (plaintext data, ciphertext data and SSPs) output by the security module as part of the response to a processing command
VCC / GNDPowerPower interface of the security module
3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

The Module’s ports and associated FIPS-defined logical interface categories are listed below. Table 18: Ports and Interfaces Additional details concerning the ports and interfaces of TPM: 1. Control and data inputs are multiplexed over the same physical interface. Control and data are distinguished by properly parsing input TPM command parameters according to input structures description, indicated for each command in [TPM2.0 Part3]. Some commands only deal with Public Material – May be reproduced only in its original entirety (without revision).

Page 22
  1. Status, data and control output are multiplexed over the same physical interface. Status, data and control are distinguished by properly setting output TPM response parameters according to output structures description, indicated for each command in [TPM2.0 Part3].
  2. The logical state machine and the command structure parsing of the module prevent from using input data externally from the “data input path” and prevent from outputting data externally from the “data output path”.
  3. While performing key generation or key zeroisation (no manual key entry on TPM), the output data path is logically disconnected while the output status path remains connected to report any possible failure during command processing. Generally, the output data path is only connected when TPM outputs response containing data.
  4. To prevent the inadvertent output of CSPs in plaintext form on TPM2_Duplicate, the two following independent internal actions are performed: a. Verification of the encryptedDuplication attribute of the key to be duplicated b. Verification of the handle of the new parent of the key to be duplicated encryptedDuplication attribute must be set to 0 and new handle must be set to the null handle to authorize outputting the private part of the key in plaintext form.
  5. The logical state machine and command structure of the module guarantees the inhibition of all data output via the data output interface whenever an error state exists and while doing selftests.
  6. The status output interface remains active during the error state to output the status of the security module with the service TPM2_GetCapability and TPM2_GetTestResult.
3.2 Pinout description

The pin layout for the UFQFPN32 package is shown in the next figure. The ST33KTPM2X security module supports both SPI and I2C physical interfaces but only one interface is configured during TPM boot. The interface configured remains active until the next module reset. The ST33KTPM2XSPI security module only supports the SPI physical interface. Public Material – May be reproduced only in its original entirety (without revision).

Page 23
SignalTypeDescription*
VCCInputPower supply. This pin must be connected to 1.8V or 3.3V DC power rail supplied by the motherboard.
GNDInputGND has to be connected to the main motherboard ground.
RESETInputReset used to re-initialize the device
I2C SCL / GPIO5Input or Input/OutputI²C serial clock (Open drain with no weak pull-up resistor) or GPIO if SPI interface is selected
I2C SDA / GPIO6Input/OutputI²C serial data (Open drain with no weak pull-up resistor) or GPIO if SPI interface is selected
PIRQOutputIRQ used by TPM to generate an interrupt
SPI CLK / GPIO1Input or Input/OutputSPI serial clock (output from master) or GPIO if I2C interface is selected
SPI NSS / GPIO2Input or Input/OutputSPI slave select (active low; output from master) or GPIO if I2C interface is selected
SPI MISO / GPIO0Output or Input/OutputSPI Master Input, Slave Output (output from slave) or GPIO if I2C interface is selected
SPI MOSI / GPIO3Input or Input/OutputSPI Master Output, Slave Input (output from master) or GPIO if I2C interface is selected
GPI8InputGPI default to low. The level of this pin on the rising edge of the RESET signal is used to determine the physical interface to use (high level corresponds to SPI configuration and low-level to I2C)
PPInputPhysical presence, active high, internal pull-down. Used to indicate Physical Presence to the TPM.
NC-Not Connected: connected to the die but not usable. May be left unconnected. Internal pull-down.

UFQFPN32 configuration The pin layout for the UFWFPN32 package is shown in the next figure.

32 NC
31 NC
28 NC
27 NC
26 NC
25 NC

Figure 3

Page 24
Method NameDescriptionSecurity MechanismStrength Each AttemptStrength per Minute
Challenge- response authenticationThe challenge-response mechanism uses an authorization value (authValue) as HMAC key or part of an HMAC key. The authValue is entered into the Module during the creation/loading of an object (key, NV index) or during replacement of the default value (hierarchies). The Module enforces a minimum size of 14 bytes.MACMinimum strength is reached with an authValue of 14 bytes: 1/2^112 = 1.92*10^- 34Probability of a successful random attempt during a one-minute period is equal to 60000*1.92*10^- 34 = 1.15*10^-29 (considering 60000 trials per minute). Assuming a minimum command duration of 1ms, 60000 trials can be executed during a one-minute period.
Enhanced authorizationEnhanced authorization includes a policy command (i.e., TPM2_PolicyAuthValue, TPM2_PolicySigned, TPM2_PolicyAuthorize, TPM2_PolicySecret, TPM2_PolicyTicket) requiring the knowledge of an authValue or the proof of the ownership of a signing key. It can also be a bound session, which also requires proving knowledge of an authValue of an object.MAC or SigVerMinimum strength is reached with an authValue of 14 bytes: 1/2^112 = 1.92*10^- 34 or an RSA 2048 signature with a security strength of 112 bitsProbability of a successful random attempt during a one-minute period is equal to 60000*1.92*10^- 34 = 1.15*10^-29 (considering 60000 trials per minute). Assuming a minimum command duration of 1ms, 60000 trials can be executed during a one-minute period.
4 Roles, Services, and Authentication
4.1 Authentication Methods

The Module implements the following authentication techniques in accordance with the Level 2 requirements: Table 20: Authentication Methods Public Material – May be reproduced only in its original entirety (without revision).

Page 25
NameTypeOperator TypeAuthentication Methods
Crypto officer (CO)RoleAdministrator of the ModuleChallenge-response authentication Enhanced authorization
User (U)RoleUser of the ModuleChallenge-response authentication Enhanced authorization
Mandatory service requested from [ISO/IEC 19790]*Corresponding services from the security module
Show module’s versioning informationTPM2_GetCapability
Show statusTPM2_GetTestResult
Perform self-testsTPM2_SelfTest
Perform approved security functionsSee approved services listed in next table
Perform zeroizationSee services listed in section 9.3 SSP Zeroization Methods.
4.2 Roles

The Roles Table below lists all operator roles supported by the Module. Table 21: Roles The Module does not provide a maintenance role or maintenance interface and does not support concurrent operators. The role is implicitly selected by the TPM operator on service execution by proving the knowledge of the enhanced authorization commands sequence and/or the authorization value of an object. All services are accessible under the roles defined above and no specific access rights are considered to operate with keys and SSPs. Full services inputs and outputs are defined in [TPM2.0 Part3]. Next table Table 22 – Mapping between services All approved services implemented by the Module are listed in the table below: The SSPs modes of access shown in the table below are defined as:

G = Generate: The Module generates or derives the SSP.
R = Read: The SSP is read from the Module (e.g., the SSP is output).
W = Write: The SSP is updated, imported, or written to the Module (SSP is input).
E = Execute: The Module uses the SSP in performing a cryptographic operation.

Public Material – May be reproduced only in its original entirety (without revision).

Page 26
NameDescriptionIndi cato rInputsOutputsSecu rity Fun ctio nsSSP Access
TPM2_InitReboot or power-on of the TPM.Non - secu rity rele vantNoneNoneNon eUnauthe nticated - nullSeed: Z - nullProof : Z - platform Auth: Z - objSeed: Z - objAuth: Z - objSens: Z - objPub: Z

Some details about information in the table:

Page 27

Name

Description

Indi cato r

Inputs

Outputs

Secu rity Fun ctio ns

SSP Access - sesSalt: Z - sesHmac Key: Z - sesSymK ey: Z - contextK ey: Z - drbgSeed : Z - objSym Key: Z - objHmac Key: Z - contextE ncKey: Z - dupSeed: Z - dupInSy mKey: Z - dupOutS ymKey: Z - dupOutH macKey: Z - creSeed: Z -

Z :Z Z Z Z Z Public Material – May be reproduced only in its original entirety (without revision).

Page 28
NameDescriptionIndi cato rInputsOutputsSecu rity Fun ctio nsSSP Access creSymK ey: Z - creHmac Key: Z - ephSens EccKey: Z - ephPubE ccKey: Z - seqAuth: Z - tdrbgStat e: Z - fuSymK ey: Z - diagSym Key: Z
TPM2_StartupSet-up the TPM after a power cycle.App rove dStartup typeNoneENT - ESV DRB GUnauthe nticated - phSeed: G - ehSeed: G - shSeed: G - phProof: G - ehProof: G - shProof:

Z Z e: Z G G G Public Material – May be reproduced only in its original entirety (without revision).

Page 29
NameDescriptionIndi cato rInputsOutputsSecu rity Fun ctio nsSSP Access G - contextK ey: G - drbgSeed : G - drbgStat e: G - nullSeed: G - nullProof : G
TPM2_Shutdown (I)Prepare the TPM for a power cycle.Non - secu rity rele vantShutdow n typeNoneNon eUnauthe nticated
TPM2_SelfTest (I)Self-tests executionApp rove dFull or backgrou nd self- testsSelf-test result if full self-tests requiredAES - ENC AES - DEC SigG en SigV er DRB G ENT - ESV KAS KB KDF MAUnauthe nticated

G :G e: G G :G G Public Material – May be reproduced only in its original entirety (without revision).

Page 30
NameDescriptionIndi cato rInputsOutputsSecu rity Fun ctio nsSSP Access
C SHA
TPM2_IncrementalSelf Test (I)Incremental self-tests executionApp rove dList of tests to passList of remaining testsAES - ENC AES - DEC SigG en SigV er DRB G ENT - ESV KAS KB KDF MA C SHAUnauthe nticated
TPM2_GetTestResult (I)Get self-tests resultNon - secu rity rele vantNoneSelf-tests statusKB KDFUnauthe nticated - diagSym Key: G,E,Z - diagSym Seed: E
TPM2_StartAuthSessi on (I/E/D)Session commandApp rove dDecrypti on key handle; Binding entity handle; Encrypte d salt; NonceNonce TPMKAS KTS -IFC KB KDFUnauthe nticated - sesHmac Key: G,W - sesSymK ey: G,W

C C G,E,Z Public Material – May be reproduced only in its original entirety (without revision).

Page 31
NameDescriptionIndi cato rInputs caller; Session Type (HMAC or Policy)OutputsSecu rity Fun ctio nsSSP Access - sesSalt: W,E,Z - objSens: E - objAuth: E - nvAuth: E - platform Auth: E - endorse mentAut h: E - ownerAu th: E - lockoutA uth: E - seqAuth: E
TPM2_PolicyRestart (I)Policy session restartNon - secu rity rele vantSession handleNoneNon eUnauthe nticated
TPM2_Create (I/E/D)Object creationApp rove dParent object handle Object sensitive part Object publicObject private part (encrypted) Object public part Creation data Digest of creationKey Gen AES - ENC SigG en SigVUser (U) - objSeed: G,R,E - objSym Key: G,E,Z

E E h: E E d Public Material – May be reproduced only in its original entirety (without revision).

Page 32
NameDescriptionIndi cato rInputsOutputsSecu rity Fun ctio nsSSP Access
template Creation data List of PCRdata Ticket to be used by TPM2_Cert ifyCreation( )er DRB G ENT - ESV KTS KB KDF MA C SHA CK G KAS - Key Gen- objHmac Key: G,E,Z - objSens: G,R,E - objPub: G,R,E - drbgStat e: W,E - objAuth: W,R - nullProof : E - phProof: E - ehProof: E - shProof: E
TPM2_Load (I/E/D)Object loadingApp rove dParent object handle Object private part (encrypt ed) Object public partName of the loaded objectKey Ver AES - DEC KTS KB KDF MA C SHAUser (U) - objSym Key: G,W,E,Z - objHmac Key: G,W,E,Z - objSens: W,E - objPub: W

- E E E G,W,E,Z G,W,E,Z W,E W Public Material – May be reproduced only in its original entirety (without revision).

Page 33
NameDescriptionIndi cato rInputsOutputsSecu rity Fun ctio nsSSP Access - objSeed: W,E - objAuth: W
TPM2_LoadExternal (I/E/D)External object loadingApp rove dObject public part Hierarch yName of the loaded objectKey ValUnauthe nticated - objPub: W - objSens: W - objAuth: W - objSeed: W
TPM2_ReadPublic (I)Read public part of a loaded objectApp rove dHandle of an objectObject public part Object name Object qualified nameNon eUnauthe nticated - objPub: R
TPM2_ActivateCreden tial (I/E/D)Enables the association of a credential with an object in a way that ensures that the TPM has validated the parameters of the credentialed objectApp rove dHandle of the object with credentia ls Handle of a loaded private key Encrypte d credentia lDecrypted certificate informationAES - DEC KAS KTS -IFC KTS KB KDF MA C SHACrypto officer (CO) - creSymK ey: G,E,Z - creHmac Key: G,E,Z - objSens: E -

W,E W W W W R C l Public Material – May be reproduced only in its original entirety (without revision).

Page 34
NameDescriptionIndi cato rInputs Encrypte d seedOutputsSecu rity Fun ctio nsSSP Access creSeed: W,E,Z
TPM2_MakeCredentia l (I/E/D)Allows the TPM to perform the actions required of a Certificate Authority (CA) in creating a TPM2B_ID_O BJECT containing an activation credentialApp rove dHandle of a loaded public key Credenti al informati on Name of the object with credentia lsEncrypted credential Encrypted seedAES - ENC KAS KTS -IFC KTS KB KDF MA C SHAUnauthe nticated - creSeed: G,R,E,Z - creSymK ey: G,E,Z - creHmac Key: G,E,Z - objPub: E
TPM2_Unseal (I/E/D)Returns the data in a loaded Sealed Data ObjectApp rove dHandle of a loaded data objectUnsealed dataNon eUser (U) - objSens: R
TPM2_ObjectChange Auth (I/E/D)Changes the authorization secret for a TPM-resident objectApp rove dHandle of an object Handle of the parent of the object New authoriza tion valueObject private partAES - ENC KB KDF MA C SHAUser (U) - objSeed: R,E - objSens: R - drbgStat e: W,E - objAuth: R - objSym Key: E - objHmac Key: E

G,R,E,Z d G,E,Z G,E,Z E R,E R R Public Material – May be reproduced only in its original entirety (without revision).

Page 35
NameDescriptionIndi cato rInputsOutputsSecu rity Fun ctio nsSSP Access
TPM2_CreateLoaded (I/E/D)Creates an object and loads it in the TPMApp rove dParent object handle Object sensitive part Object public templateObject private part (encrypted) Object public part Creation object nameKey Gen Key Ver AES - ENC SigG en SigV er DRB G ENT - ESV KAS KB KDF MA C SHA CK G KAS - Key GenCrypto officer (CO) - objSeed: G,R,E - objSym Key: G,E - objHmac Key: G,E - objSens: G,R,E - objPub: G,R,E - tdrbgStat e: G,W,E - drbgStat e: W,E - objAuth: W,R - nullSeed: E - phSeed: E - ehSeed: E - shSeed: E - nullProof : E - phProof:

G,R,E G,R,E G (I/E/D) W,R C E G E E E :E Public Material – May be reproduced only in its original entirety (without revision).

Page 36

Name

Description

Indi cato r

Inputs

Outputs

Secu rity Fun ctio ns

SSP Access E - ehProof: E - shProof: E - ekRsa: E - ekEcc: E - shProofF orReseed : G,E User (U) - objSeed: G,E - objSym Key: G,E - objHmac Key: G,E - objSens: G,R - objPub: G,R,E - tdrbgStat e: G,W,E - drbgStat e: W - objAuth: W - nullSeed:

E E E E E : G,E G,E G,R G,R,E e: G,W,E e: W W Public Material – May be reproduced only in its original entirety (without revision).

Page 37
NameDescriptionIndi cato rInputsOutputsSecu rity Fun ctio nsSSP Access E - phSeed: E - ephSens EccKey: E - shSeed: E - nullProof : E - phProof: E - ehProof: E - shProofF orReseed : G,E - ekRsa: E - ekEcc: E
TPM2_Duplicate (I/E/D)Duplicates a loaded object so that it may be used in a different hierarchyApp rove dHandle of the loaded object to duplicate Handle of the new parent Optional symmetr ic encrypti on keyEncryption key for inner wrapper Duplicated object private part (encrypted) Encrypted seedAES - ENC DRB G KTS -IFC KAS KTS KB KDF MA C SHAUser (U) - dupSeed: G,R,E,Z - objSeed: R - dupOutS ymKey: G,E,Z - dupInSy mKey:

E E E E :E E E : G,E E E d Public Material – May be reproduced only in its original entirety (without revision).

Page 38
NameDescriptionIndi cato rInputsOutputsSecu rity Fun ctio nsSSP Access
CK GG,R,W,E ,Z - dupOutH macKey: G,E,Z - objSens: R - objAuth: R - drbgStat e: W,E - objPub: E
TPM2_Rewrap (I/E/D)Rewraps a duplicated object with a new parent keyApp rove dHandle of the old parent Handle of the new parent Duplicat ed object private part (encrypt ed) Name of the object being rewrappe d Encrypte d seedDuplicated object private part (encrypted) Encrypted seedAES - ENC AES - DEC KAS KTS -IFC KTS KB KDF MA C SHA CK GUser (U) - dupOutS ymKey: G,E,Z - dupOutH macKey: G,E,Z - objSens: R,W,E - dupSeed: R,W,E,Z - objSeed: R,W - dupInSy mKey: W,Z - drbgStat

G ,Z G,E,Z R R e: W,E E C G Public Material – May be reproduced only in its original entirety (without revision).

Page 39
NameDescriptionIndi cato rInputsOutputsSecu rity Fun ctio nsSSP Access e: W,E - objPub: E - objAuth: R,W
TPM2_Import (I/E/D)Allows an object to be encrypted using the symmetric encryption values of a Storage KeyApp rove dHandle of the new parent Duplicat ed object private part (encrypt ed) Object public part Encrypte d seed Encrypti on key for inner wrapperObject private part (encrypted)AES - ENC AES - DEC KAS KTS -IFC KTS KB KDF MA C SHA CK GUser (U) - objSens: R,W,E,Z - objSeed: R,W,Z - objPub: W,E,Z - dupOutS ymKey: W,E,Z - objAuth: R,W,Z - drbgStat e: E - dupSeed: E,W,Z - dupInSy mKey: E,W,Z - dupOutH macKey: W,E,Z
TPM2_RSA_Encrypt (I/E/D)Performs RSA encryptionApp rove dRSA public key handle MessageEncrypted outputKTS -IFCUnauthe nticated - objPub: E

e: W,E E R,W R,W,E,Z R,W,Z W,E,Z W,E,Z R,W,Z e: E E,W,Z E,W,Z W,E,Z E Public Material – May be reproduced only in its original entirety (without revision).

Page 40
NameDescriptionIndi cato rInputs to encrypt RSA scheme to useOutputsSecu rity Fun ctio nsSSP Access
TPM2_RSA_Decrypt (I/E/D)Performs RSA decryptionApp rove dRSA private key handle Cipherte xt to decrypt RSA scheme to useDecrypted outputKTS -IFCUser (U) - objSens: Z
TPM2_ECDH_KeyGe n (I/E/D)Shared secret value computation using ECDHApp rove dECC key public part handleShared secret Ephemeral public keyKAS - Key GenUnauthe nticated - ephSens EccKey: G,E,Z - ephPubE ccKey: G,R,Z - drbgStat e: W,E - objPub: E
TPM2_ECDH_ZGen (I/E/D)Shared secret value recovery using ECDHApp rove dHandle of a loaded ECC key Ephemer al public keyRecovered shared secretKASUser (U) - ephPubE ccKey: W,E,Z - objSens: E
TPM2_ECC_Paramete rs (I)Returns the parameters of an ECC curveNon - secuID of an ECC curveCurve parametersNon eUnauthe nticated

d G,E,Z G,R,Z e: W,E E (I/E/D) W,E,Z E Public Material – May be reproduced only in its original entirety (without revision).

Page 41
NameDescription identified by its TCG-assigned curveIDIndi cato r rity rele vantInputsOutputsSecu rity Fun ctio nsSSP Access
TPM2_EncryptDecrypt (I/E)Symmetric encryption or decryptionApp rove dSymmetr ic key handle Decrypti on or encrypti on indicator Input IV Data ModeEncrypted or decrypted data Output IV (for chaining)AES - ENC AES - DECUser (U) - objSens: E
TPM2_EncryptDecrypt 2 (I/E/D)Symmetric encryption or decryptionApp rove dSymmetr ic key handle Decrypti on or encrypti on indicator Input IV Data ModeEncrypted or decrypted data Output IV (for chaining)AES - ENC AES - DECUser (U) - objSens: E
TPM2_Hash (I/E/D)Performs a hash operation on dataApp rove dData to hash Hash algorith m Hierarch y to use for ticketDigest Ticket linked to the input hierarchyMA C SHAUnauthe nticated - nullProof : E - phProof: E - ehProof: E - shProof: E

m E E Public Material – May be reproduced only in its original entirety (without revision).

Page 42
NameDescriptionIndi cato rInputsOutputsSecu rity Fun ctio nsSSP Access
TPM2_HMAC (I/E/D)Performs a HMAC operation on dataApp rove dSymmetr ic signing key handle Data to HMAC Hash algorith mHMACMA CUser (U) - objSens: E
TPM2_GetRandom (I/E)Outputs random bytes from a DRBGApp rove dNumber of random bytes to generateOutput random bytesDRB GUnauthe nticated - drbgStat e: W,E
TPM2_StirRandom (I/D)Reseed the state of a DRBGApp rove dAddition al informati onNoneDRB G ENT - ESVUnauthe nticated - drbgSeed : W,E,Z - drbgStat e: W,E
TPM2_HMAC_Start (I/D)Starts an HMAC sequenceApp rove dHandle of an HMAC key Authoriz ation value for sequence Hash algorith mSequence handleMA CUser (U) - seqAuth: W - objSens: E
TPM2_HashSequence Start (I/D)Starts a hash or an event sequenceApp rove dAuthoriz ation value for sequence Hash algorith mSequence handleSHAUnauthe nticated - seqAuth: W

d m (I/E) G d e: W,E m m Public Material – May be reproduced only in its original entirety (without revision).

Page 43
NameDescriptionIndi cato rInputsOutputsSecu rity Fun ctio nsSSP Access
TPM2_SequenceUpdat e (I/D)Adds data to a hash or HMAC sequenceApp rove dSequenc e handle Data to hash/HM ACNoneMA C SHAUser (U) - objSens: E
TPM2_SequenceComp lete (I/E/D)Adds last part of data to a hash or HMAC sequence and returns the resultApp rove dSequenc e handle Data to hash/HM AC Hierarch y for ticketHMAC or digest Ticket linked to the input hierarchyMA C SHAUser (U) - nullProof : E - phProof: E - ehProof: E - shProof: E - objSens: E - seqAuth: Z
TPM2_EventSequence Complete (I/D)Adds last part of data to a hash or HMAC sequence and returns the result in a digest listApp rove dHandle of PCR to extend Sequenc e handle Data to hash/HM ACList of digests computed for the PCRMA C SHAUser (U) - objSens: E - seqAuth: Z
TPM2_Certify (I/E/D)Proves that an object with a specific Name is loaded in the TPMApp rove dHandle of the object to certify Handle of a signing key QualifyiCertificatio n structure Signature over the certification structureSigG en DRB G KB KDF MA C SHAUser (U) - drbgStat e: W,E - objSens: E -

E :E E E E Z Public Material – May be reproduced only in its original entirety (without revision).

Page 44
NameDescriptionIndi cato rInputsOutputsSecu rity Fun ctio nsSSP Access
ng data Signatur e schemeCK GshProof: E
TPM2_CertifyCreation (I/E/D)Proves the association between an object and its creation dataApp rove dHandle of the object to certify Handle of a signing key Qualifyi ng data Signatur e scheme Ticket Creation hashCertificatio n structure Signature over the certification structureSigG en DRB G KB KDF MA C SHA CK GUser (U) - drbgStat e: W,E - objSens: E - nullProof : E - phProof: E - ehProof: E - shProof: E
TPM2_Quote (I/E/D)Quotes PCR valuesApp rove dHandle of a signing key Qualifyi ng data Selection of PCRs Signatur e schemeQuoted information Signature over the quoted informationSigG en DRB G KB KDF MA C SHA CK GUser (U) - drbgStat e: W,E - objSens: E - shProof: E
TPM2_GetSessionAud itDigest (I/E/D)Returns a digital signature of the audit session digestApp rove dHandle of a privacy administ rator Handle of a signingAudit information Signature over the quoted informationSigG en KB KDF DRB G MA CCrypto officer (CO) - objSens: E - shProof:

E G C G d Public Material – May be reproduced only in its original entirety (without revision).

Page 45
NameDescriptionIndi cato rInputsOutputsSecu rity Fun ctio nsSSP Access
key Handle of an audit session Qualifyi ng data Signatur e schemeSHA CK GE - drbgStat e: W,E
TPM2_GetCommandA uditDigest (I/E/D)Returns the current value of the command audit digest, a digest of the commands being audited, and the audit hash algorithmApp rove dHandle of a privacy administ rator Handle of a signing key Qualifyi ng data Signatur e schemeAudit information Signature over the quoted informationSigG en DRB G KB KDF MA C SHA CK GCrypto officer (CO) - drbgStat e: W,E - objSens: E - shProof: E
TPM2_GetTime (I/E/D)Returns the current values of Time and ClockApp rove dHandle of a privacy administ rator Handle of a signing key Qualifyi ng data Signatur e schemeAttestation data Signature over the attestation dataSigG en KB KDF DRB G MA C SHA CK GCrypto officer (CO) - drbgStat e: W,E - objSens: E - shProof: E
TPM2_CertifyX509 (I/E/D)X.509 certificate generationApp rove dHandle of the object to certify Handle of aAdditional certificate information Digest SignatureSigG en SHAUser (U) - drbgStat e: W,E -

E E Public Material – May be reproduced only in its original entirety (without revision).

Page 46
NameDescriptionIndi cato rInputs signing key Partial certificat e Signatur e schemeOutputs over the digestSecu rity Fun ctio nsSSP Access objSens: E
TPM2_VerifySignatur e (I/D)Uses loaded keys to validate a signature on a message with the message digest passed to the TPMApp rove dHandle of a public key Digest of a message Signatur e to be testedValidation ticketSigV er MA CUnauthe nticated - objPub: E - nullProof : E - phProof: E - ehProof: E - shProof: E
TPM2_Sign (I/D)Causes the TPM to sign an externally provided hash with the specified symmetric or asymmetric signing keyApp rove dHandle of a signing key Digest to be signed Scheme Proof ticket for digestSignature over the digestSigG en DRB G MA C SHAUser (U) - objSens: E - nullProof : E - phProof: E - ehProof: E - shProof: E

e E E :E E E E Public Material – May be reproduced only in its original entirety (without revision).

Page 47
NameDescriptionIndi cato rInputsOutputsSecu rity Fun ctio nsSSP Access
TPM2_SetCommandC odeAuditStatus (I)Changes the audit status of a command or to set the hash algorithm used for the audit digestNon - secu rity rele vantAuthoriz ation handle Hash algorith mNoneNon eCrypto officer (CO)
TPM2_PCR_Extend (I)Updates the indicated PCRApp rove dPCR handle List of digests used to extend PCRsNoneSHAUnauthe nticated
TPM2_PCR_Event (I/D)Updates the indicated PCR and reports list of digestsApp rove dPCR handle Event dataDigestsSHAUnauthe nticated
TPM2_PCR_Read (I)Returns the values of all PCR specified in pcrSelectionInNon - secu rity rele vantSelection of PCR to readPCR informationNon eUnauthe nticated
TPM2_PCR_Allocate (I)Sets the desired PCR allocation of PCR and algorithmsNon - secu rity rele vantSelection of PCR to allocatePCR allocation informationNon eCrypto officer (CO)
TPM2_PCR_Reset (I)Sets the PCR in all banks to zeroNon - secu rity rele vantPCR to resetnoneNon eUnauthe nticated
_TPM_Hash_StartIndicates to the TPM interface the start of an H-CRTMApp rove dNoneNoneSHAUnauthe nticated

d d Public Material – May be reproduced only in its original entirety (without revision).

Page 48
NameDescription measurement sequenceIndi cato rInputsOutputsSecu rity Fun ctio nsSSP Access
_TPM_Hash_DataIndicates to the TPM interface data to be included in the H-CRTM measurement sequenceApp rove dDataNoneSHAUnauthe nticated
TPM_Hash_EndIndicates to the TPM interface the end of the H-CRTM measurement sequenceApp rove dNoneNoneSHAUnauthe nticated
TPM2_PolicySigned (I/E/D)Includes a signed authorization in a policyApp rove dSignatur e key handle Policy session handle Nonce TPM Digest Signatur e Expiratio n of authoriza tion Policy reference valuePolicy timeout Policy ticketSigV er MA C SHAUnauthe nticated - objPub: E - nullProof : E - phProof: E - ehProof: E - shProof: E
TPM2_PolicySecret (I/E/D)Includes a secret-based authorization to a policyApp rove dAuthoriz ation object handle Policy session handle NoncePolicy timeout Policy ticketMA C SHAUser (U) - nullProof : E - phProof: E -

d d C Public Material – May be reproduced only in its original entirety (without revision).

Page 49
NameDescriptionIndi cato rInputs TPM Digest Expiratio n of authoriza tion Policy reference valueOutputsSecu rity Fun ctio nsSSP Access ehProof: E - shProof: E
TPM2_PolicyTicket (I/D)Includes a ticket in a policyApp rove dPolicy session handle Nonce TPM Digest Expiratio n of authoriza tion Policy reference value Authoriz ation object name TicketNoneMA C SHAUnauthe nticated - nullProof : E - phProof: E - ehProof: E - shProof: E
TPM2_PolicyOR (I)Allows options in authorizations without requiring that the TPM evaluate all the optionsApp rove dPolicy session handle List of digestsNoneSHAUnauthe nticated
TPM2_PolicyPCR (I/D)Causes conditional gating of a policy based on PCRApp rove dPolicy session handle Expected digest valueNoneSHAUnauthe nticated

Public Material – May be reproduced only in its original entirety (without revision).

Page 50
NameDescriptionIndi cato rInputs PCR selectionOutputsSecu rity Fun ctio nsSSP Access
TPM2_PolicyLocality (I)Indicates that the policy will be limited to a specific localityApp rove dPolicy session handle LocalityNoneSHAUnauthe nticated
TPM2_PolicyNV (I/D)Causes conditional gating of a policy based on the contents of an NV IndexApp rove dAuthoriz ation handle NV index handle Policy session handle Operand, offset, operatio nNoneSHAUser (U)
TPM2_PolicyCounterT imer (I/D)Causes conditional gating of a policy based on the contents of the TPMS_TIME_I NFO structureApp rove dPolicy session handle Operand, offset, operatio nNoneSHAUnauthe nticated
TPM2_PolicyComman dCode (I)Limits policy to a specific command codeApp rove dPolicy session handle Comman d codeNoneSHAUnauthe nticated
TPM2_PolicyPhysical Presence (I)Physical presence will need to be asserted at the time the authorization is performedApp rove dPolicy session handleNoneSHAUnauthe nticated

d n n Public Material – May be reproduced only in its original entirety (without revision).

Page 51
NameDescriptionIndi cato rInputsOutputsSecu rity Fun ctio nsSSP Access
TPM2_PolicyCpHash (I/D)Allows a policy to be bound to a specific command and command parametersApp rove dPolicy session handle Digest to add to policyNoneSHAUnauthe nticated
TPM2_PolicyNameHa sh (I/D)Allows a policy to be bound to a specific set of TPM entities without being bound to the parameters of the commandApp rove dPolicy session handle Digest to add to policyNoneSHAUnauthe nticated
TPM2_PolicyDuplicati onSelect (I/D)Allows qualification of duplication to allow duplication to a selected new parentApp rove dPolicy session handle Object name to be duplicate d New Parent name Object name inclusion indicatorNoneSHAUnauthe nticated
TPM2_PolicyAuthoriz e (I/D)Check a ticket issued from the signature verification of a new policy so that it may be used in an existing policyApp rove dPolicy session handle Digest of the policy being approved Policy qualifier Key name TicketNoneMA C SHAUnauthe nticated - nullProof : E - phProof: E - ehProof: E -

d d E Public Material – May be reproduced only in its original entirety (without revision).

Page 52
NameDescriptionIndi cato rInputsOutputsSecu rity Fun ctio nsSSP Access shProof: E
TPM2_PolicyAuthVal ue (I)Allows a policy to be bound to the authorization value of the authorized entityApp rove dPolicy session handleNoneSHAUnauthe nticated
TPM2_PolicyPassword (I)Allows a policy to be bound to the authorization value of the authorized objectApp rove dPolicy session handleNoneSHAUnauthe nticated
TPM2_PolicyGetDiges t (I/E)Returns the current policyDigest of a policy sessionNon - secu rity rele vantPolicy session handlePolicy digestNon eUnauthe nticated
TPM2_PolicyNvWritte n (I)Allows a policy to be bound to the TPMA_NV_W RITTEN attributesApp rove dPolicy session handle NV index written indicatorNoneSHAUnauthe nticated
TPM2_PolicyTemplate (I/D)Allows a policy to be bound to a specific creation templateApp rove dPolicy session handle Digest to add to policyNoneSHAUnauthe nticated
TPM2_PolicyAuthoriz eNV (I)Provides a capability that is the equivalent of a revocable policyApp rove dSource handle for authoriza tion NV index toNoneSHAUser (U)

E d Public Material – May be reproduced only in its original entirety (without revision).

Page 53
NameDescriptionIndi cato rInputs read Policy session handleOutputsSecu rity Fun ctio nsSSP Access
TPM2_CreatePrimary (I/E/D)Creates a Primary Object under one of the Primary Seeds or a Temporary Object under TPM_RH_NUL LApp rove dPrimary handle Key sensitive data Key public template Creation data Creation PCRObject handle Object Public part Creation data Digest of creation data Creation ticket Name of the objectKey Gen Key Ver SigG en SigV er DRB G KB KDF MA C SHA CK G KAS - Key GenCrypto officer (CO) - objSeed: G,E,Z - objSym Key: G,E,Z - objHmac Key: G,E,Z - objSens: G,E,Z - objPub: G,R,E,Z - tdrbgStat e: G,W,E,Z - drbgStat e: W,E - objAuth: W - nullSeed: E - phSeed: E - ehSeed: E

G,E,Z - E E E Public Material – May be reproduced only in its original entirety (without revision).

Page 54
NameDescriptionIndi cato rInputsOutputsSecu rity Fun ctio nsSSP Access - shSeed: E - nullProof : E - phProof: E - ehProof: E - shProof: E - ekRsa: E - ekEcc: E - shProofF orReseed : G,E
TPM2_HierarchyContr ol (I)Enables and disables use of a hierarchy and its associated NV storageNon - secu rity rele vantPrimary handle Hierarch y to enable or disable Enable or disable indicatorNoneNon eCrypto officer (CO)
TPM2_SetPrimaryPoli cy (I/D)Sets the authorization policy for a hierarchyNon - secu rity rele vantPrimary handle Policy digest Hash algorith mNoneNon eCrypto officer (CO)

E :E E E E E E : G,E m Public Material – May be reproduced only in its original entirety (without revision).

Page 55
NameDescriptionIndi cato rInputsOutputsSecu rity Fun ctio nsSSP Access
TPM2_ChangePPS (I)Replaces the current platform primary seed (PPS) with a value from the RNG and sets platformPolicy to the default initialization valueApp rove dAuthoriz ation handleNoneDRB GCrypto officer (CO) - drbgStat e: W,E - phProof: Z - phSeed: Z - objSeed: Z - objSens: Z - objPub: Z
TPM2_ChangeEPS (I)Replaces the current endorsement primary seed EPS) with a value from the RNG and sets endorsementPol icy to the default initialization valueApp rove dAuthoriz ation handleNoneDRB GCrypto officer (CO) - drbgStat e: W,E - ehSeed: Z - ehProof: Z - objSeed: Z - objSens: Z - objPub: Z - ekRsa: Z

Z Z e: W,E Z Z Z Z Z Public Material – May be reproduced only in its original entirety (without revision).

Page 56
NameDescriptionIndi cato rInputsOutputsSecu rity Fun ctio nsSSP Access - ekEcc: Z
TPM2_Clear (I)Removes all TPM context associated with a specific OwnerApp rove dAuthoriz ation handleNoneDRB GCrypto officer (CO) - drbgStat e: W,E - shSeed: Z - ehProof: Z - shProof: Z - shProofF orReseed : Z - objSeed: Z - objSens: Z - objPub: Z - objAuth: Z
TPM2_ClearControl (I)Disables and enables the execution of TPM2_Clear()Non - secu rity rele vantAuthoriz ation handle Set or clear disableO wnerFla gNoneNon eCrypto officer (CO)

Z e: W,E Z Z G :Z Z Z Z Z g Public Material – May be reproduced only in its original entirety (without revision).

Page 57
NameDescriptionIndi cato rInputsOutputsSecu rity Fun ctio nsSSP Access
TPM2_HierarchyChan geAuth (I/D)Changes the authValue of hierarchiesNon - secu rity rele vantAuthoriz ation handle New authoriza tion valueNoneNon eCrypto officer (CO) - lockoutA uth: W - endorse mentAut h: W - ownerAu th: W - platform Auth: W
TPM2_DictionaryAtta ckLockReset (I)Cancels the effect of a TPM lockout due to several successive authorization failuresNon - secu rity rele vantAuthoriz ation handleNoneNon eCrypto officer (CO)
TPM2_DictionaryAtta ckParameters (I)Changes the lockout parametersNon - secu rity rele vantAuthoriz ation handle newMax Tries, newReco veryTim e and lockoutR ecovery valuesNoneNon eCrypto officer (CO)
TPM2_VendorCmdFie ldUpgradeStart (I)Initiates a field upgrade sessionApp rove dApprove dNoneSigV er KB KDF SHA CK GCrypto officer (CO) - fuSigEC CKey: E -

- G Public Material – May be reproduced only in its original entirety (without revision).

Page 58
NameDescriptionIndi cato rInputsOutputsSecu rity Fun ctio nsSSP Access fuSigLM SKey: E - fuSymK ey: G - fuSymSe ed: E
TPM2_VendorCmdFie ldUpgradeData (I)Conveys firmware in a field upgrade sessionApp rove dField upgrade data blobCompletion indicatorAES - DEC SHAUnauthe nticated - fuSymK ey: E,Z
TPM2_ContextSaveSaves a session context, object context, or sequence object context outside the TPMApp rove dSaved handleContextAES - ENC KTS KB KDF MA C CK GUnauthe nticated - contextE ncKey: G,E,Z - objSeed: R - objSens: R - objPub: R - objAuth: R - nullProof : E - phProof: E - ehProof: E - shProof:

G,E,Z R d :E E E Public Material – May be reproduced only in its original entirety (without revision).

Page 59
NameDescriptionIndi cato rInputsOutputsSecu rity Fun ctio nsSSP Access E - sesHmac Key: R - seqAuth: R - contextK ey: E
TPM2_ContextLoadReloads a context that has been saved by TPM2_Context Save()App rove dContextLoaded handleAES - DEC KTS KB KDF MA C CK GUnauthe nticated - contextE ncKey: G,E,Z - objSeed: W - objSens: W - objPub: W - objAuth: W - nullProof : E - phProof: E - ehProof: E - shProof: E - sesHmac

E R G,E,Z W W C :E G E E E Public Material – May be reproduced only in its original entirety (without revision).

Page 60
NameDescriptionIndi cato rInputsOutputsSecu rity Fun ctio nsSSP Access Key: W - seqAuth: W - contextK ey: E
TPM2_FlushContextCauses all context associated with a loaded object, sequence object, or session to be removed from TPM memoryApp rove dFlush handleNoneNon eUnauthe nticated - objSeed: Z - objSens: Z - objPub: Z - objAuth: Z
TPM2_EvictControl (I)Allows certain Transient Objects to be made persistent or a persistent object to be evictedApp rove dAuthoriz ation handle Loaded object handle Persisten t handleNoneNon eCrypto officer (CO) - objSeed: W,Z - objSens: W,Z - objPub: W,Z - objAuth: W,Z - sesHmac Key: W - sesSymK ey: W

W Z W,Z Public Material – May be reproduced only in its original entirety (without revision).

Page 61
NameDescriptionIndi cato rInputsOutputsSecu rity Fun ctio nsSSP Access
TPM2_ReadClock (I)Reads the current TPMS_TIME_I NFO structureNon - secu rity rele vantNoneCurrent timeNon eUnauthe nticated
TPM2_ClockSet (I)Advances the value of the TPM's clockNon - secu rity rele vantNew timeNoneNon eCrypto officer (CO)
TPM2_ClockRateAdju st (I)Adjusts the rate of advance of Clock and TimeNon - secu rity rele vantAuthoriz ation handle Clock update rate adjustme ntNoneNon eCrypto officer (CO)
TPM2_GetCapability (I)Returns various information regarding the TPM and its current stateNon - secu rity rele vantCapabilit y, property, property countMore data availability indicator Capability dataNon eUnauthe nticated
TPM2_SetCapability (I/D)Set specific data in the TPM, such as TPM configurations, which may change the TPM's function and behaviorNon - secu rity rele vantCapabilit y dataNoneNon eCrypto officer (CO)
TPM2_TestParms (I)Checks if specific combinations of algorithm parameters are supportedNon - secu rity rele vantAlgorith m paramete rsNoneNon eUnauthe nticated

Public Material – May be reproduced only in its original entirety (without revision).

Page 62
NameDescriptionIndi cato rInputsOutputsSecu rity Fun ctio nsSSP Access
TPM2_NV_DefineSpa ce (I/D)Defines the attributes of an NV Index and causes the TPM to reserve space to hold the data associated with the NV IndexApp rove dAuthoriz ation handle NV authoriza tion value NV public paramete rsNoneNon eCrypto officer (CO) - nvAuth: W
TPM2_NV_UndefineS pace (I)Removes an Index from the TPMApp rove dAuthoriz ation handle NV index to deleteNoneNon eCrypto officer (CO) - nvAuth: Z
TPM2_NV_UndefineS paceSpecial (I)Removal of a platform- created NV Index that has TPMA_NV_PO LICY_DELET E SETApp rove dPlatform authoriza tion handle NV index to deleteNoneNon eCrypto officer (CO) - nvAuth: Z
TPM2_NV_ReadPubli c (I/E)Reads the public area and Name of an NV IndexApp rove dNV indexNV index public area Name of the NV indexSHAUnauthe nticated
TPM2_NV_Write (I/D)Writes a value to an area in NV memory that was previously defined by TPM2_NV_Def ineSpace()Non - secu rity rele vantAuthoriz ation handle NV index to write Data to write Offset in the NV index areaNoneNon eUser (U)

Z d Public Material – May be reproduced only in its original entirety (without revision).

Page 63
NameDescriptionIndi cato rInputsOutputsSecu rity Fun ctio nsSSP Access
TPM2_NV_Increment (I)Increments the value in an NV Index that has the TPM_NT_COU NTER attributeNon - secu rity rele vantAuthoriz ation handle NV index to incremen tNoneNon eUser (U)
TPM2_NV_Extend (I/D)Extends a value to an area in NV memory that was previously defined by TPM2_NV_Def ineSpace()App rove dAuthoriz ation handle NV index to extend Data to extendNoneSHAUser (U)
TPM2_NV_SetBits (I)Sets bits in an NV Index that was created as a bit fieldNon - secu rity rele vantAuthoriz ation handle NV index to extend Data to OR with NV contentNoneNon eUser (U)
TPM2_NV_WriteLock (I)Inhibits further writes of the NV Index if the TPMA_NV_W RITEDEFINE or TPMA_NV_W RITE_STCLEA R attributes of an NV location are SETNon - secu rity rele vantAuthoriz ation handle NV indexNoneNon eUser (U)
TPM2_NV_GlobalWri teLock (I)Sets TPMA_NV_W RITELOCKED for all indexes that have theirNon - secu rityAuthoriz ation handleNoneNon eCrypto officer (CO)

t d Public Material – May be reproduced only in its original entirety (without revision).

Page 64
NameDescription TPMA_NV_GL OBALLOCK attribute SETIndi cato r rele vantInputsOutputsSecu rity Fun ctio nsSSP Access
TPM2_NV_Read (I/E)Reads a value from an area in NV memory previously defined by TPM2_NV_Def ineSpace()Non - secu rity rele vantAuthoriz ation handle NV index to be read Size and offset in NV areaData readNon eUser (U)
TPM2_NV_ReadLock (I)Prevents further reads of the NV Index until the next TPM2_Startup (TPM_SU_CLE AR) if TPMA_NV_RE AD_STCLEAR is SETNon - secu rity rele vantAuthoriz ation handle NV index to be lockedNoneNon eUser (U)
TPM2_NV_ChangeAu th (I/D)Allows the authValue of an NV Index to be changedApp rove dNV index New authoriza tion valueNoneNon eUser (U) - nvAuth: W
TPM2_NV_Certify (I/E/D)Certifies the contents of an NV Index or portion of an NV IndexApp rove dHandle of signing key Authoriz ation handle NV index Qualifyi ng data Scheme Size andStructure that was signed SignatureSigG en KB KDF MA C SHAUser (U) - objSens: E - shProof: E

d Public Material – May be reproduced only in its original entirety (without revision).

Page 65
NameDescriptionIndi cato rInputs offset in NV areaOutputsSecu rity Fun ctio nsSSP Access
TPM2_VendorCmdSet Mode (I)Sets the low power modeNon - secu rity rele vantAuthoriz ation handle Low power configur ation structureNoneNon eCrypto officer (CO)
TPM2_VendorCmdSet CommandSet (I)Activates and locks commandsNon - secu rity rele vantAuthoriz ation handle Comman d code Activatio n and lock indicator sNoneNon eCrypto officer (CO)
TPM2_VendorCmdSet CommandSetLock (I)Prevents locking commandsNon - secu rity rele vantAuthoriz ation handleNoneNon eCrypto officer (CO)
TPM2_VendorCmdGet Random2 (I/E)Get random value from DRBGApp rove dNumber of bytes to generateRandom valueNon eUnauthe nticated - drbgStat e: W,E
TPM2_VendorCmdGP IOConfig (I)Configures GPIONon - secu rity rele vantAuthoriz ation handle GPIO configur ationNoneNon eUnauthe nticated
TPM2_VendorCmdGet Random800_90B (I/E)Get random value from ESV Cert. #E41App rove dNumber of bytes to generateRandom valueENT - ESVUnauthe nticated

s e: W,E Public Material – May be reproduced only in its original entirety (without revision).

Page 66
NameDescriptionIndi cato rInputsOutputsSecu rity Fun ctio nsSSP Access
TPM2_VendorCmdCh angeObjectDeletionAu th (I)Modifies deletion authorization for an objectNon - secu rity rele vantAuthoriz ation handle Platform authoriza tion use indicatorNoneNon eCrypto officer (CO)
TPM2_VendorCmdRe storeEK (I)Restore EK RSA or EK ECC in case of deletion by TPM2_Change EPSApp rove dAuthoriz ation handleNoneNon eCrypto officer (CO) - ekRsa: W - ekEcc: W
TPM2_VendorCmdZer oizeEK (I)Zeroize EK RSA and EK ECCApp rove dAuthoriz ation handleNoneNon eCrypto officer (CO) - ekRsa: Z - ekEcc: Z
TPM2_VendorCmdSet BackgroundSlotsConfi gConfigure the RSA background key slotsNon - secu rity rele vantAuthoriz ation handle Slots configur ationNoneNon eCrypto officer (CO)
TPM2_PP_CommandsDetermines which commands require assertion of Physical PresenceNon - secu rity rele vantAuthoriz ation handle List of comman ds to add and list of comman d to removeNoneNon eCrypto officer (CO)
Integrity mechanism provided by sessionsThis service is not callable from TPMApp rove dComman d or responseIntegrity valueDRB G KBUnauthe nticated -

W Z Public Material – May be reproduced only in its original entirety (without revision).

Page 67
NameDescriptionIndi cato rInputsOutputsSecu rity Fun ctio nsSSP Access
interface but is only used internally by any command and response with an authorization area. It consists in computing the integrity of the received command or transmitted response.KDF MA C SHA CK GsesHmac Key: E,Z
Encryption mechanism provided by sessionsThis service is not callable from TPM interface but is only used internally by any command and response with an encryption or decryption session. It consists in decrypting the first parameter of a received command or encrypting the first parameter of a transmitted response.App rove dComman d or responseEncrypted parameterAES - ENC AES - DEC DRB G KB KDF SHA CK GUnauthe nticated - sesSymK ey: G,E,Z

G,E,Z Table 23: Approved Services Public Material – May be reproduced only in its original entirety (without revision).

Page 68

The integrity mechanism provided by sessions is not directly callable from the security module external interfaces. Function is used (or might be used) by the services listed in this table. When a service is usable with a session, (I) is added next to the service name. When a service can additionally use the encryption mechanism of a session, (I/E) is added next to the service name. The encryption mechanism provided by sessions is not directly callable from the security module external interfaces. Function is used (or might be used) by the services listed in this table. When a service is usable with a session, (I) is added next to the service name. When a service can additionally use the encryption mechanism of a session, (I/E) is added next to the service name. Public Material – May be reproduced only in its original entirety (without revision).

Page 69
NameDescriptionAlgorithmsRole
TPM2_Create; TPM2_CreateLoaded; TPM2_Load; TPM2_LoadExternalCreation or loading of an ECC key with a non-approved elliptic curve; Creation or loading of an ECC key for a non- approved key agreement usage; Creation or loading of an ECC signing key with an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL);Creation or loading of an RSA decryption key with an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL); Creation or loading of a 1024-bit RSA keyECC BN P- 256 (non- compliant) RSA (non- compliant)User
TPM2_CreateLoadedDerivation of an ECC key from a derivation parent keyECC derived keys (non- compliant) KBKDF (non- compliant)User
TPM2_Load; TPM2_LoadExternalLoading of an ECC or RSA key (sensitive and public parts) in the NULL hierarchyECC BN P- 256 (non- compliant) RSA (non- compliant)User
TPM2_Duplicate; TPM2_Rewrap; TPM2_ImportKey transport with a 1024-bit RSA key Key agreement scheme with a non-approved ECC curve Key agreement scheme with an ECC key used in a non-approved key agreement usageECC BN P- 256 (non- compliant) KAS (non- compliant) RSA (non- compliant)User

All approved services implemented by the Module are listed in the table below: Public Material – May be reproduced only in its original entirety (without revision).

Page 70
NameDescriptionAlgorithmsRole
TPM2_RSA_Encrypt; TPM2_RSA_DecryptKey transport with a non-approved scheme: * RSAES- PKCS1-v1_5 * RSA with no padding mode (null scheme) Key transport with an RSA decryption key: * Generated with an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL) * Loaded in the NULL hierarchyKTS-IFC (non- compliant) RSA with no padding mode (null scheme) (non- compliant) RSAES- PKCS1-v1_5 (non- compliant)User
TPM2_ECDH_KeyGenUse of a non-approved elliptic curve: * ECC key with curve BN P-256 Use of an ECC key for a non-approved key agreement usage: * ECC key with curve Curve448ECC BN P- 256 (non- compliant)N/A
TPM2_ECDH_ZGenUse of an ECC key: * Generated on curve BN P-256 * For a non-approved key agreement usage * Derived from a derivation parent key * Loaded in the NULL hierarchyECC BN P- 256 (non- compliant) KBKDF (non- compliant)User
TPM2_ZGen_2PhaseThis command is only usable jointly with TPM2_EC_Ephemeral service that is non approved as using key derivation to generate ECC keysECC derived keys (non- compliant) KBKDF (non- compliant)User
TPM2_HMACHMAC generation with a key length < 112 bitsHMAC (non- compliant)User
TPM2_HMAC_Start; TPM2_SequenceUpdate; TPM2_SequenceCompleteHMAC generation with a key length < 112 bitsHMAC (non- compliant)User
TPM2_Certify; TPM2_CertifyCreation; TPM2_Quote;Digital signature with a non-approved signature scheme: * ECC signature with ECDAA signature scheme * ECCECC BN P- 256 (non-User/CO

Public Material – May be reproduced only in its original entirety (without revision).

Page 71
NameDescriptionAlgorithmsRole
TPM2_GetSessionAuditDigest; TPM2_GetCommandAuditDigest; TPM2_GetTime; TPM2_CertifyX509signature with ECSchnorr signature scheme * RSA signature with key length of 1024 bits * ECC or RSA signature key using SHA-1 as digest method * ECC signature with curve BN P-256 Digital signature with an ECC signing key generated with an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL); Digital signature with an ECC signing derived from a derivation parent key; Digital signature with an ECC or RSA key loaded in the NULL hierarchycompliant) ECDAA (non- compliant) ECDSA (non- compliant) ECSchnorr (non- compliant) RSA (non- compliant) SHA-1 (non- compliant)
TPM2_CommitGeneration of an ECC key through key derivation methodKBKDF (non- compliant)User
TPM2_EC_EphemeralGeneration of an ECC key through key derivation methodKBKDF (non- compliant)User
TPM2_VerifySignatureDigital signature verification with a non-approved signature scheme or a non-approved curve: * ECDAA signature scheme * ECSchnorr signature scheme * ECC signature with curve BN P-256ECC BN P- 256 (non- compliant) ECDAA (non- compliant) ECSchnorr (non- compliant)NA
TPM2_SignDigital signature generation with a non-approved signature scheme: * ECC signature with ECDAA signature scheme * ECC signature with ECSchnorr signature scheme * RSA signature with key length of 1024 bits * ECC or RSA signature key using SHA-1 as digest method * ECC signature with curve BN P-256; Digital signature with an ECC signing key generated with an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme =ECC BN P- 256 (non- compliant) ECDAA (non- compliant) ECDSA (non- compliant) ECSchnorrUser

Public Material – May be reproduced only in its original entirety (without revision).

Page 72
NameDescriptionAlgorithmsRole
TPM_ALG_NULL); Digital signature with an ECC signing derived from a derivation parent key; Digital signature with an ECC or RSA key loaded in the NULL hierarchy(non- compliant) RSA (non- compliant) SHA-1 (non- compliant)
TPM2_PolicySignedDigital signature verification with a non-approved signature scheme or a non-approved curve: * ECDAA signature scheme * ECSchnorr signature scheme * ECC signature with curve BN P-256ECC BN P- 256 (non- compliant) ECDAA (non- compliant) ECSchnorr (non- compliant)N/A
TPM2_CreatePrimaryCreation and loading of an ECC key with a non-approved elliptic curve: * ECC key with curve BN P-256 Use of an ECC key for a non-approved key agreement usage: * ECC key with curve Curve448 Creation and loading of an ECC signing key with an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL) Creation and loading of an RSA decryption key with an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme = TPM_ALG_NULL)ECC BN P- 256 (non- compliant)CO
TPM2_NV_CertifyDigital signature with a non-approved signature scheme: * ECC signature with ECDAA signature scheme * ECC signature with ECSchnorr signature scheme * RSA signature with key length of 1024 bits * ECC or RSA signature key using SHA-1 as digest method * ECC signature with curve BN P-256 Digital signature with an ECC signing key generated with an undetermined scheme (field inPublic.buffer.parameters.scheme.scheme =ECC BN P- 256 (non- compliant) ECDAA (non- compliant) ECDSA (non- compliant) ECSchnorrUser

Public Material – May be reproduced only in its original entirety (without revision).

Page 73
NameDescriptionAlgorithmsRole
TPM_ALG_NULL) Digital signature with an ECC signing derived from a derivation parent key Digital signature with an ECC or RSA key loaded in the NULL hierarchy(non- compliant) RSA (non- compliant) SHA-1 (non- compliant)

Table 24: Non-Approved Services Public Material – May be reproduced only in its original entirety (without revision).

Page 74
4.5 External Software/Firmware Loaded

Loading of firmware on the Module can be achieved by using two services:

Page 75
5 Software/Firmware Security
5.1 Integrity Techniques

The Module is composed of the following firmware component(s):

5.2 Initiate on Demand

The operator can initiate the integrity test on demand by using the TPM2_SelfTest command with the full parameter set to YES or by using the TPM2_IncrementalSelfTest command. Public Material – May be reproduced only in its original entirety (without revision).

Page 76
6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Limited The operational environment of the Module is “limited” because it allows loading authenticated firmware that meets all applicable requirements of [140-3] standard. Data outputs are inhibited until the loading session has completed successfully. Execution of the successfully loaded FW is only effective after the next reset of the security module. New firmware versions must be validated through the FIPS 140-3 validation process. Any other firmware loaded into this module is out of the scope of this validation and requires a separate FIPS 140-3 validation. The core memory loader (CML) represented in Figure 4 is non-modifiable, only the TPM instances are modifiable by using an authenticated firmware upgrade mechanism. The security module contains two instances of the FW but only one FW instance is executed after a boot sequence. Public Material – May be reproduced only in its original entirety (without revision).

Page 77
MechanismInspection FrequencyInspection Guidance
Hard opaque packageDependent on the security module integration environment varies from once per month to once per yearVisual inspection of the package to confirm that it has not been damaged by an external action
7 Physical Security

The security module is production grade and meets the Physical Security protection requirements for single-chip module at FIPS 140-3 Level 3.

7.1 Mechanisms and Actions Required

Zeroisation Zeroisation of CSPs can be triggered by specific services as detailed in Section 9.3. It occurs in a sufficiently small time-period to prevent the recovery of the sensitive data between start of zeroisation and the zeroisation completeness. Physical security mechanisms The security module is encapsulated in a hard opaque package to prevent direct observation of internal security components. It implements additional security mechanisms:

7.2 User Placed Tamper Seals
7.3 Filler Panels
7.4 Fault Induction Mitigation

N/A Public Material – May be reproduced only in its original entirety (without revision).

Page 78
Temp/Voltage TypeTemperature or VoltageEFP or EFTResult
LowTemperature-60°C (ST33KTPM2XSPI) / -70°C (ST33KTPM2X)EFTShutdown
HighTemperature145°C (ST33KTPM2XSPI) / 145°C (ST33KTPM2X)EFTShutdown
LowVoltage1.5V (ST33KTPM2XSPI) / 1.4V (ST33KTPM2X)EFTShutdown
HighVoltage4.3V (ST33KTPM2XSPI) / 4.3V (ST33KTPM2X)EFTShutdown
Temperature TypeTemperature
LowTemperature-40°C
HighTemperature105°C

EFT has been performed for all security module configurations. Low and high temperatures have been measured at a nominal voltage of 3.3V. Low and high voltage have been measured at ambient temperature (25°C). The nominal operating ranges are:

7.6 Hardness Testing Temperature Ranges

Hardness testing was conducted at the temperature indicated in the table below. Table 27: Hardness Testing Temperatures Public Material – May be reproduced only in its original entirety (without revision).

Page 79
8 Non-Invasive Security
8.1 Mitigation Techniques

The Module does not claim support of non-invasive attack mitigation techniques referenced in [140F]. Public Material – May be reproduced only in its original entirety (without revision).

Page 80
Storage Area NameDescriptionPersistence Type
Dynamic RAMVolatile memory used to store SSPs between two consecutive resets or power-on/power-off sequence of the security module. SSPs don't persist after command execution. This area is marked as RAM on the HW block diagram.Dynamic
Static RAMVolatile memory used to store SSPs between two consecutive resets or power-on/power-off sequence of the security module. SSPs persist after command execution. This area is marked as RAM on the HW block diagram.Static
NVRAMNon-volatile memory (flash-based) used to store SSPs and make them persistent to a reset or a power-off/power-on sequence of the security module. This area is marked as flash memory on the HW block diagram.Static
Name Input plaintext to NVRAMFrom Outside of cryptographi c boundaryTo NVRAMFormat Type PlaintextDistributio n Type ManualEntry Type Electroni cSFI or Algorith m
Input protected to NVRAMOutside of cryptographi c boundaryNVRAMEncrypte dManualElectroni cKTS
Input plaintext to RAMOutside of cryptographi c boundaryStatic RAMPlaintextManualElectroni c
Input protected to RAMOutside of cryptographi c boundaryStatic RAMEncrypte dManualElectroni cKTS
Output plaintextNVRAMOutside of cryptographi c boundaryPlaintextManualElectroni c
9 Sensitive Security Parameters Management
9.1 Storage Areas
9.2 SSP Input-Output Methods

m c d c Public Material – May be reproduced only in its original entirety (without revision).

Page 81
Name from NVRAMFromToFormat TypeDistributio n TypeEntry TypeSFI or Algorith m
Output protected from NVRAMNVRAMOutside of cryptographi c boundaryEncrypte dManualElectroni cKTS
Output plaintext from RAMStatic RAMOutside of cryptographi c boundaryPlaintextManualElectroni c
Output protected from RAMStatic RAMOutside of cryptographi c boundaryEncrypte dManualElectroni cKTS
Input asym. encrypte d to RAMOutside of cryptographi c boundaryStatic RAMEncrypte dManualElectroni cKTS-IFC
Output asym. encrypte d to RAMStatic RAMOutside of cryptographi c boundaryEncrypte dManualElectroni cKTS-IFC

m d c d c Table 29: SSP Input-Output Methods Public Material – May be reproduced only in its original entirety (without revision).

Page 82
Zeroization MethodDescriptionRationaleOperator Initiation
TPM2_InitZeroization of all volatile SSPs. Explicit zeroization indicator provided by service completion status.N/AActivation of reset signal
TPM2_ClearZeroization of all contexts associated with an Owner. Explicit zeroization indicator provided by service completion status.SSPs linked to an Owner must not persist if the Owner changesSend TPM2_Clear command
TPM2_StartupZeroization of platformAuth. Explicit zeroization indicator provided by service completion status.Zeroize platformAuth before its first use after a resetSend TPM2_Startup command
TPM2_ChangePPSZeroize the platform primary seed and flush all transient and persistent objects in the Platform hierarchy. Explicit zeroization indicator provided by service completion status.Platform hierarchy renewalSend TPM2_ChangePPS command
TPM2_ChangeEPSZeroize the endorsement primary seed and flush all transient and persistent objects in the Endorsement hierarchy. Explicit zeroization indicator provided by service completion status.Endorsement hierarchy renewalSend TPM2_ChangeEPS command
TPM2_EvictControlZeroize an object from NVRAM. Explicit zeroization indicator provided by service completion status.Method required to zeroize a dedicated object in NVRAMSend TPM2_EvictControl command
TPM2_FlushContextZeroize an object from RAM. Explicit zeroization indicator provided by service completion status.Method required to zeroize a dedicated object in RAMSend TPM2_FlushContext command
AutomaticZeroize SSPs at the end of a command processing. Implicit zeroization indication.Method for limited life cycle SSPsNo, zeroization is automatic.
TPM2_NV_UndefineSpace TPM2_NV_UndefineSpaceSpecialZeroize a NV index. Explicit zeroization indicator provided by service completion status.Method required to flush NV indices from NVRAMSend TPM2_NV_UndefineSpace command. Send TPM2_NV_UndefineSpaceSpecial command
TPM2_VendorCmdZeroizeEKZeroize the endorsement key provisioned. Explicit zeroization indicator provided by service completion status.Mandatory zeroization method for EK SSPsSend TPM2_VendorCmdZeroizeEK command
TPM2_SequenceComplete TPM2_EventSequenceCompleteZeroize a hash or HMAC sequence. Explicit zeroization indicator provided by service completion status.Method required to flush sequences from RAMSend TPM2_SequenceComplete command. Send TPM2_EventSequenceComplete command

Name nullProof phProof ehProof shProof shProofForReseed platformAuth endorsementAuth

Description Proof (secret value) of the null hierarchy Proof (secret value) of the platform hierarchy Proof (secret value) of the endorsement hierarchy Proof (secret value) of the storage hierarchy Random value Authentication value for the platform hierarchy Authentication value for the endorsement hierarchy

Size - Strength 512 - 256 512 - 256 512 - 256 512 - 256 512 - 256 512 - 128 to 256 (depending on the underlying hash algorithm used) 512 - 128 to 256 (depending on the underlying hash algorithm used)

Type - Category Symmetric key - CSP Symmetric key - CSP Symmetric key - CSP Symmetric key - CSP Entropy source - CSP Authentication value / Symmetric key - CSP Authentication value / Symmetric key - CSP

Generated By DRBG DRBG DRBG DRBG ENT-ESV

Established By

Used By KBKDF MAC MAC MAC KBKDF MAC DRBG KBKDF MAC KBKDF MAC

9.3 SSP Zeroization Methods

Table 30: SSP Zeroization Methods All usage of these SSPs by the Module are described in the services detailed in section 4. Next table lists the SSPs used as keys: Public Material – May be reproduced only in its original entirety (without revision).

Page 83
Name ownerAuth lockoutAuth objSeed objAuth objSymKey objHmacKey objSens objPubDescription Authentication value for the storage hierarchy Authentication value for the lockout hierarchy Seed value for object generation Object's authorization value Encryption key of object private part Integrity key of object private part Object private part Object public partSize - Strength 512 - 128 to 256 (depending on the underlying hash algorithm used) 512 - 128 to 256 (depending on the underlying hash algorithm used) 512 - 128 to 256 112 to 512 - 112 to 256 256 - 256 160, 256, 384, 512 - 128 to 256 2048, 3072, 4096 (RSA) 128, 192, 256 (AES) 256, 384, 521 (ECC) 112 to 1024 (HMAC) - 112 to 256 2048, 3072, 4096 (RSA) 2*256, 2*384, 2*521 (ECC) - 112 to 256Type - Category Authentication value / Symmetric key - CSP Authentication value / Symmetric key - CSP Data, Symmetric key - CSP Authentication value / Symmetric key - CSP Symmetric key - CSP Symmetric key - CSP Symmetric or asymmetric private key - CSP Asymmetric public key - PSPGenerated By DRBG KBKDF KBKDF KBKDF KeyGen KBKDF CKG KAS-KeyGen KeyGen KAS-KeyGenEstablished ByUsed By KBKDF MAC KBKDF MAC KBKDF SHA KBKDF MAC AES- ENC AES- DEC MAC AES- ENC AES- DEC SigGen KAS KBKDF MAC SigVer KAS KTS- IFC
nvAuthAuthorization of NV index112 to 512 - 112 to 256Authentication value / Symmetric key - CSPKTSKBKDF MAC
sesSaltSalt for keys diversification160, 256, 384, 512 - 128 to 256Symmetric key - CSPN/AKASKBKDF
sesHmacKeyHMAC session key160, 256, 384, 512 - 128 to 256Symmetric key - CSPKBKDFKBKDF MAC
sesSymKeyEncrypted session key128, 192, 256 - 128 to 256Symmetric key - CSPKBKDFAES- ENC AES- DEC
contextKeyDerivation key for context protection128 - 128Symmetric key - CSPDRBGKBKDF
contextEncKeyWrapping key for context protection256 - 256Symmetric key - CSPKBKDFAES- ENC AES- DEC
dupInSymKeyWrapping key for duplicated object128, 192, 256 - 128 to 256Symmetric key - CSPDRBGAES- ENC AES- DEC
dupSeedSeed for protection keys derivation160 to 512 - 128 to 256Symmetric key - CSPDRBG KASKASKBKDF
dupOutSymKeyEncryption key for duplicated objects128, 192, 256 - 128 to 256Symmetric key - CSPKBKDFAES- ENC

Public Material – May be reproduced only in its original entirety (without revision).

Page 84
Name dupOutHmacKeyDescription HMAC key for duplicated objectsSize - Strength 160, 256, 384, 512 - 128 to 256Type - Category Symmetric key - CSPGenerated By KBKDFEstablished ByUsed By AES- DEC MAC
creSeedSeed for credential keys derivation160 to 512 - 128 to 256Symmetric key - CSPKASKBKDF
creSymKeyEncryption key for credentials128, 192, 256 - 128 to 256Symmetric key - CSPKBKDFAES- ENC AES- DEC
creHmacKeyHMAC key for credentials160, 256, 384, 512 - 128 to 256Symmetric key - CSPKBKDFMAC
ephSensEccKeyECC ephemeral private key256, 384, 521 - 128 to 256ECC private key - CSPKAS-KeyGenKAS
ephPubEccKeyECC ephemeral public key512, 768, 1056 - 128 to 256ECC public key - PSPKAS-KeyGenKAS
ekRsaProvisioned RSA endorsement key2048 - 112RSA private key - CSPInput during manufacturingKTS- IFC
ekEccProvisioned ECC endorsement key256, 384 - 128 to 192ECC private key - CSPInput during manufacturingKAS
fuSigECCKeyField upgrade ECC signature verification key384 - 192ECC public key - PSPInput during manufacturingSigVer
fuSigLMSKeyField upgrade LMS signature verification key32 - 128LMS public key - PSPInput during manufacturingSigVer
seqAuthAuthorization value for hash or HMAC sequence112 to 512 - 112 to 256Authentication value / Symmetric key - CSPN/AKBKDF MAC
nullSeedSeed of the null hierarchy512 - 256Seed - CSPENT-ESVDRBG
phSeedSeed of the platform hierarchy512 - 256Seed - CSPENT-ESVDRBG
ehSeedSeed of the endorsement hierarchy512 - 256Seed - CSPENT-ESVDRBG
shSeedSeed of the storage hierarchy512 - 256Seed - CSPENT-ESVDRBG
drbgStateInternal state (V and C secret values) of the DRBG (based on SHA256)256 - 256State - CSPDRBGDRBG
drbgSeedSeed value for the DRBG512 - 256Seed - CSPENT-ESVDRBG
tdrbgStateInternal state (V and C secret values) of the transient DRBG (based on SHA256) used to generate prime numbers for primary RSA keys256 - 256State - CSPDRBGDRBG
fuSymSeedSeed used for field upgrade symmetric key derivation256 - 256Symmetric key - NeitherInput during manufacturingKBKDF
fuSymKeyfield upgrade symmetric key256 - 256Symmetric key - NeitherKBKDFAES- DEC
diagSymSeedSeed used for diagnostic symmetric key derivation256 - 256Symmetric key - NeitherInput during manufacturingKBKDF
diagSymKeydiagnostic symmetric key256 - 256Symmetric key - NeitherKBKDFAES- ENC
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
nullProofStatic RAM:PlaintextUntil next resetTPM2_InitdrbgState:Generates contextEncKey:Derived From
phProofNVRAM:PlaintextAfter UseTPM2_ChangePPSdrbgState:Generates contextEncKey:Derived From

Table 31: SSP Table 1 Public Material – May be reproduced only in its original entirety (without revision).

Page 85
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
ehProofNVRAM:PlaintextAfter UseTPM2_ChangeEPS TPM2_CleardrbgState:Generates contextEncKey:Derived From
shProofNVRAM:PlaintextAfter UseTPM2_CleardrbgState:Generates contextEncKey:Derived From
shProofForReseedNVRAM:PlaintextAfter UseTPM2_CleartdrbgState:Reseeded From
platformAuthInput plaintext to RAM Input protected to RAMStatic RAM:PlaintextUntil next resetTPM2_InitsesHmacKey:Derived from, Protects (Integrity) sesSymKey:Encrypts
endorsementAuthInput plaintext to NVRAM Input protected to NVRAMNVRAM:PlaintextAfter UseTPM2_Clear TPM2_ChangeEPSsesHmacKey:Derived from, Protects (Integrity) sesSymKey:Derived from, Protects (Encrypts)
ownerAuthInput plaintext to NVRAM Input protected to NVRAMNVRAM:PlaintextAfter UseTPM2_ClearsesHmacKey:Derived from, Protects (Integrity) sesSymKey:Derived from, Protects (Encrypts)
lockoutAuthInput plaintext to NVRAM Input protected to NVRAMNVRAM:PlaintextAfter UseTPM2_ClearsesHmacKey:Derived from, Protects (Integrity) sesSymKey:Derived from, Protects (Encrypts)
objSeedInput protected to RAM Input plaintext to RAM Output protected from RAM Output protected from NVRAMStatic RAM:Plaintext NVRAM:PlaintextUntil object zeroization, shift to NVRAM or next resetTPM2_Init TPM2_Clear TPM2_ChangePPS TPM2_ChangeEPS TPM2_EvictControl TPM2_FlushContexttdrbgState:Derived From drbgState:Derived From objSymKey:Derived From objHmacKey:Derived From sesHmacKey:Protects (Integrity) sesSymKey:Protects (Encrypts)
objAuthInput plaintext to RAM Input protected to RAM Output protected from RAM Output protected from NVRAMStatic RAM:Plaintext NVRAM:PlaintextUntil object zeroization, shift to NVRAM or next resetTPM2_Init TPM2_Clear TPM2_ChangePPS TPM2_ChangeEPS TPM2_EvictControl TPM2_FlushContextsesHmacKey:Derived from, Protects (Integrity) sesSymKey:Derived from, Encrypts
objSymKeyDynamic RAM:Plaintext NVRAM:PlaintextAfter UseAutomaticobjAuth:Encrypted by objSens:Encrypted by platformAuth:Encrypted by endorsementAuth:Encrypted by ownerAuth:Encrypted by lockoutAuth:Encrypted by
objHmacKeyDynamic RAM:Encrypted NVRAM:PlaintextAfter UseAutomaticobjAuth:Protected by (Integrity) objSens:Protected by (Integrity) platformAuth:Protected by (Integrity) endorsementAuth:Protected by (Integrity) ownerAuth:Protected by (Integrity) lockoutAuth:Protected by (Integrity)
objSensInput plaintext to RAM Input protected to RAM Output protected from RAMStatic RAM:Plaintext NVRAM:PlaintextUntil object zeroization, shift to NVRAM or next resetTPM2_Init TPM2_Clear TPM2_ChangePPS TPM2_ChangeEPStdrbgState:Generates drbgState:Generates objSeed:Derives objSymKey:Encrypts

Public Material – May be reproduced only in its original entirety (without revision).

Page 86
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
Output protected from NVRAMTPM2_EvictControl TPM2_FlushContextobjHmacKey:Protects (Integrity) objPub:Paired With
objPubInput plaintext to RAM Output plaintext from NVRAM Output plaintext from RAMStatic RAM:Plaintext NVRAM:PlaintextUntil object zeroization, shift to NVRAM or next resetTPM2_Init TPM2_Clear TPM2_ChangePPS TPM2_ChangeEPS TPM2_EvictControl TPM2_FlushContextobjSens:Paired With
nvAuthInput plaintext to NVRAM Input protected to NVRAMNVRAM:PlaintextAfter UseTPM2_NV_UndefineSpace TPM2_NV_UndefineSpaceSpecialsesHmacKey:Derived from, Protects (Integrity) sesSymKey:Encrypts
sesSaltInput asym. encrypted to RAMDynamic RAM:PlaintextAfter UseAutomaticsesHmacKey:Derived From objPub:Encrypts
sesHmacKeyInput protected to RAM Output protected from RAMDynamic RAM:PlaintextAfter UseAutomaticnvAuth:Protected by (Integrity) contextKey:Encrypts contextEncKey:Encrypts platformAuth:Protected by (Integrity) endorsementAuth:Protected by (Integrity) ownerAuth:Protected by (Integrity) lockoutAuth:Protected by (Integrity) objAuth:Protected by (Integrity) seqAuth:Derives; Protected by (Integrity) dupInSymKey:Protected by (Integrity)
sesSymKeyDynamic RAM:PlaintextAfter UseAutomaticsesHmacKey:Derives platformAuth:Derives; Encrypts endorsementAuth:Derives; Encrypts ownerAuth:Derives; Encrypts lockoutAuth:Derives; Encrypts objAuth:Derives; Encrypts seqAuth:Derives; Encrypts nvAuth:Derives; Encrypts dupInSymKey:Encrypted by
contextKeyStatic RAM:PlaintextUntil next resetTPM2_InitdrbgState:Generates contextEncKey:Derived From
contextEncKeyDynamic RAM:PlaintextAfter UseAutomaticcontextKey:Derives nullProof:Derives phProof:Derives ehProof:Derives shProof:Derives
dupInSymKeyInput plaintext to RAM Input protected to RAM Output plaintext from RAM Output protected from RAMDynamic RAM:PlaintextAfter UseAutomaticsesSymKey:Encrypts sesHmacKey:Protects (Integrity) objSens:Encrypted by

Public Material – May be reproduced only in its original entirety (without revision).

Page 87
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
dupSeedInput asym. encrypted to RAM Output asym. encrypted to RAMDynamic RAM:PlaintextAfter UseAutomaticobjPub:Encrypts dupOutSymKey:Derived from dupOutHmacKey:Derived from
dupOutSymKeyDynamic RAM:PlaintextAfter UseAutomaticdupSeed:Derives objSens:Encrypted by objAuth:Encrypted by objSeed:Encrypted by
dupOutHmacKeyDynamic RAM:PlaintextAfter UseAutomaticdupSeed:Derives objSens:Protects (Integrity) objAuth:Protects (Integrity) objSeed:Protects (Integrity)
creSeedInput asym. encrypted to RAM Output asym. encrypted to RAMDynamic RAM:PlaintextAfter UseAutomaticcreSymKey:Derives creHmacKey:Derives objPub:Encrypts
creSymKeyDynamic RAM:PlaintextAfter UseAutomaticcreSeed:Derived From
creHmacKeyDynamic RAM:PlaintextAfter UseAutomaticcreSeed:Derived From
ephSensEccKeyDynamic RAM:PlaintextAfter UseAutomaticdrbgState:Generates
ephPubEccKeyInput plaintext to RAM Output plaintext from RAMDynamic RAM:PlaintextAfter UseAutomaticephSensEccKey:Derives
ekRsaNVRAM:PlaintextAfter UseTPM2_VendorCmdZeroizeEKobjSens:Derived From
ekEccNVRAM:PlaintextAfter UseTPM2_VendorCmdZeroizeEKobjSens:Derived From
fuSigECCKeyNVRAM:PlaintextAfter UseN/A
fuSigLMSKeyNVRAM:PlaintextAfter UseN/A
seqAuthInput plaintext to RAM Input protected to RAM Output protected from RAMDynamic RAM:PlaintextUntil use of zeroization command or next resetTPM2_SequenceComplete TPM2_EventSequenceCompletesesSymKey:Derived From sesHmacKey:Derived From
nullSeedStatic RAM:PlaintextUntil next resetTPM2_InittdrbgState:Instantiated with
phSeedNVRAM:PlaintextAfter UseTPM2_ChangePPStdrbgState:Instantiated with
ehSeedNVRAM:PlaintextAfter UseTPM2_ChangeEPStdrbgState:Instantiated with
shSeedNVRAM:PlaintextAfter UseTPM2_CleartdrbgState:Instantiated with
drbgStateStatic RAM:PlaintextUntil next reset or use of TPM2_ClearTPM2_Init TPM2_CleardrbgSeed:Instantiates
drbgSeedDynamic RAM:PlaintextAfter UseAutomaticdrbgState:Instantiated with
tdrbgStateDynamic RAM:PlaintextAfter UseAutomaticnullSeed:Instantiates phSeed:Instantiates ehSeed:Instantiates shSeed:Instantiates
fuSymSeedNVRAM:PlaintextAfter UseN/AfuSymKey:Derived From
fuSymKeyDynamic RAM:PlaintextAfter UseAutomaticfuSymSeed:Derives

Public Material – May be reproduced only in its original entirety (without revision).

Page 88
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
diagSymSeedNVRAM:PlaintextAfter UseN/AdiagSymKey:Derived From
diagSymKeyDynamic RAM:PlaintextAfter UseAutomaticdiagSymSeed:Derives
NameDescriptionSize (bits)StrengthTypeGenerated byEstablished byUsed byInputs / OutputsStorageTemporary Storage DurationZeroizationCategoryRelated SSPs
nullProofProof (secret value) of the null hierarchy512256Symmetric keyDRBGN/AKBKDF MAC-Static RAMUntil next resetTPM2_InitCSPDerived from drbgState contextEncKey can be derived from nullProof
phProofProof (secret value) of the platform hierarchy512256Symmetric keyDRBGN/AMAC-NVRAMAfter useTPM2_ChangePPSCSPDerived from drbgState contextEncKey can be derived from phProof
ehProofProof (secret value) of the endorsement hierarchy512256Symmetric keyDRBGN/AMAC-NVRAMAfter useTPM2_ChangeEPS TPM2_ClearCSPDerived from drbgState contextEncKey can be derived from ehProof
shProofProof (secret value) of the storage hierarchy512256Symmetric keyDRBGN/AKBKDF MAC-NVRAMAfter useTPM2_ClearCSPDerived from drbgState contextEncKey can be derived from shProof
shProofForRes eedRandom value512256Entropy sourceENT-ESVN/ADRBG-NVRAMAfter useTPM2_ClearCSPtdrbgState is reseeded with shProofForRes eed
platformAuthAuthentication value for the platform hierarchy512128 to 256 (depending on the underlying hash algorithm used)Authentication value / Symmetric keyN/AN/AKBKDF MACInput protected to RAM or Input plaintext to RAMStatic RAMUntil next resetTPM2_InitCSPsesHmacKey can be derived from platformAuth New input platformAuth value can be wrapped by sesSymKey and integrity protected by sesHmacKey

Table 32: SSP Table 2 Public Material – May be reproduced only in its original entirety (without revision).

Page 89
NameDescriptionSize (bits)StrengthTypeGenerated byEstablished byUsed byInputs / OutputsStorageTemporary Storage DurationZeroizationCategoryRelated SSPs
endorsementA uthAuthentication value for the endorsement hierarchy512128 to 256 (depending on the underlying hash algorithm used)Authentication value / Symmetric keyN/AN/AKBKDF MACInput protected to NVRAM or Input plaintext to NVRAMNVRAMAfter useTPM2_Clear TPM2_ChangeEPSCSPsesHmacKey and sesSymKey can be derived from endorsementA uth New input endorsementA uth value can be wrapped by sesSymKey and integrity protected by sesHmacKey
ownerAuthAuthentication value for the storage hierarchy512128 to 256 (depending on the underlying hash algorithm used)Authentication value / Symmetric keyN/AN/AKBKDF MACInput protected to NVRAM or Input plaintext to NVRAMNVRAMAfter useTPM2_ClearCSPsesHmacKey and sesSymKey can be derived from ownerAuth New input ownerAuth value can be wrapped by sesSymKey and integrity protected by sesHmacKey
lockoutAuthAuthentication value for the lockout hierarchy512128 to 256 (depending on the underlying hash algorithm used)Authentication value / Symmetric keyN/AN/AKBKDF MACInput protected to NVRAM or Input plaintext to NVRAMNVRAMAfter useTPM2_ClearCSPsesHmacKey and sesSymKey can be derived from lockoutAuth New input lockoutAuth value can be wrapped by sesSymKey and integrity protected by sesHmacKey
nullSeedSeed of the null hierarchy512256SeedENT-ESVN/ADRBG-Static RAMUntil next resetTPM2_InitCSPtdrbgState can be instantiated by nullSeed
phSeedSeed of the platform hierarchy512256SeedENT-ESVN/ADRBG-NVRAMAfter useTPM2_ChangePPSCSPtdrbgState can be instantiated by phSeed

Public Material – May be reproduced only in its original entirety (without revision).

Page 90
NameDescriptionSize (bits)StrengthTypeGenerated byEstablished byUsed byInputs / OutputsStorageTemporary Storage DurationZeroizationCategoryRelated SSPs
ehSeedSeed of the endorsement hierarchy512256SeedENT-ESVN/ADRBG-NVRAMAfter useTPM2_ChangeEPSCSPtdrbgState can be instantiated by ehSeed
shSeedSeed of the storage hierarchy512256SeedENT-ESVN/ADRBG-NVRAMAfter useTPM2_ClearCSPtdrbgState can be instantiated by shSeed
objSeedSeed value for object generation512128 to 256Data, Symmetric keyDRBG KBKDFN/ASHA KBKDFInput protected to RAM Input plaintext to RAM Output protected from RAM Output protected from NVRAMStatic RAM NVRAMUntil object zeroization, shift to NVRAM or next resetTPM2_Clear TPM2_ChangePPS TPM2_ChangeEPS TPM2_EvictControl TPM2_FlushContext TPM2_InitCSPcan be derived from tdrbgState for primary objects, from drbgState for ordinary objects can be protected by sesHmacKey and sesSymKey objSymKey and objHmacKey are derived from objSeed
objAuthObject’s authorization value112 to 512112 to 256Authentication value / Symmetric keyN/AN/AMAC KBKDFInput protected to RAM Input plaintext to RAM Output protected from RAM Output protected from NVRAMStatic RAM NVRAMUntil object zeroization, shift to NVRAM or next resetTPM2_Clear TPM2_ChangePPS TPM2_ChangeEPS TPM2_EvictControl TPM2_FlushContext TPM2_InitCSPcan be protected by sesHmacKey and sesSymKey sesHmacKey and sesSymKey can be derived from objAuth
objSymKeyEncryption key of object private part256256Symmetric keyKBKDFN/AAES-ENC, AES- DEC-Dynamic RAM NVRAMAfter useAutomaticCSPcan wrap platformAuth / endorsementAu th / ownerAuth / lockoutAuth / objAuth/objSens
objHmacKeyIntegrity key of object private part160, 256, 384, 512128 to 256Symmetric keyKBKDFN/AMAC-Dynamic RAM NVRAMAfter useAutomaticCSPcan protect platformAuth / endorsementAu th / ownerAuth / lockoutAuth / objAuth/objSens

Public Material – May be reproduced only in its original entirety (without revision).

Page 91
NameDescriptionSize (bits)StrengthTypeGenerated byEstablished byUsed byInputs / OutputsStorageTemporary Storage DurationZeroizationCategoryRelated SSPs
objSensObject private part2048, 3072, 4096 (RSA) 128, 192, 256 (AES) 256, 384, 512, 521, (ECC) 112 to 1024 (HMAC)112 to 256Symmetric or asymmetric private keyCKG KBKDF KAS-KeyGen KeyGenN/AAES-ENC, AES- DEC, KBKDF MAC KAS SigGen (RSA, ECDSA),Input protected to RAM Input plaintext to RAM Output protected from RAM Output protected from NVRAMStatic RAM NVRAMUntil object zeroization, shift to NVRAM or next resetTPM2_Clear TPM2_ChangePPS TPM2_ChangeEPS TPM2_EvictControl TPM2_FlushContext TPM2_InitCSPcan be generated from tdrbgState for primary objects, from drbgState for ordinary objects and derived from objSeed of its parent for derived objects objSymKey encrypts objSens objHmacKey can integrity protect objSens objPub: Paired With
objPubObject public part2048, 3072, 4096 (RSA) 2*256, 2*384, 2*521 (ECC)112 to 256Asymmetric public keyKeyGen (ECDSA, RSA) KAS-KeyGenN/AKAS, KTS-IFC, SigVer (RSA, ECDSA),Input plaintext to RAM Output plaintext from RAM Output plaintext from NVRAMStatic RAM NVRAMUntil object zeroization, shift to NVRAM or next resetTPM2_Clear TPM2_ChangePPS TPM2_ChangeEPS TPM2_EvictControl TPM2_FlushContext TPM2_InitPSPobjSens: Paired With
nvAuthAuthorization of NV index112 to 512112 to 256Authentication value / Symmetric keyN/AN/AKBKDF MACInput protected to NVRAM Input plaintext to NVRAMNVRAMAfter useTPM2_NV_UndefineS pace TPM2_NV_UndefineS paceSpecialCSPsesHmacKey can be derived from nvAuth New input nvAuth value can be wrapped by sesSymKey and integrity protected by sesHmacKey
sesSaltSalt for keys diversification160, 256, 384, 512128 to 256Symmetric keyN/AKASKBKDFInput asym. encrypted to RAMDynamic RAMAfter useAutomaticCSPsesHmacKey is derived from sesSalt

Public Material – May be reproduced only in its original entirety (without revision).

Page 92
NameDescriptionSize (bits)StrengthTypeGenerated byEstablished byUsed byInputs / OutputsStorageTemporary Storage DurationZeroizationCategoryRelated SSPs objPub wraps sesSalt
sesHmacKeyHMAC session key160, 256, 384, 512128 to 256Symmetric keyKBKDFN/AKBKDF MACInput protected to RAM Output protected from RAMDynamic RAMAfter useAutomaticCSPprotects nvAuth / platformAuth / endorsementAu th / ownerAuth / lockoutAuth / objAuth / seqAuth / dupInSymKey derived from seqAuth contextKey and contextEncKey keys can wrap sesHmacKey
sesSymKeyEncrypted session key128, 192, 256128 to 256Symmetric keyKBKDFN/AAES-ENC, AES- DEC-Dynamic RAMAfter useAutomaticCSPderived from and encrypts sesHmacKey and platformAuth / endorsementA uth / ownerAuth / lockoutAuth / objAuth / seqAuth
contextKeyDerivation key for context protection128128Symmetric keyDRBGN/AKBKDF-Static RAMUntil next resetTPM2_InitCSPgenerated from drbgState contextEncKey is derived from contextKey
contextEncKeyWrapping key for context protection256256Symmetric keyKBKDFN/AAES-ENC, AES- DEC-Dynamic RAMAfter useAutomaticCSPderived from contextKey and nullProof / phProof / ehProof / shProof
dupInSymKeyWrapping key for duplicated object128, 192, 256128 to 256Symmetric keyDRBGN/AAES-ENC, AES- DECInput plaintext to RAM Input protected to RAM Output plaintext from RAM Output protected from RAMDynamic RAMAfter useAutomaticCSPcan be wrapped by sesSymKey and protected by sesHmacKey Encrypts objSens

Public Material – May be reproduced only in its original entirety (without revision).

Page 93
NameDescriptionSize (bits)StrengthTypeGenerated byEstablished byUsed byInputs / OutputsStorageTemporary Storage DurationZeroizationCategoryRelated SSPs
dupSeedSeed for protection keys derivation160 to 512128 to 256Symmetric keyDRBG KASKASKBKDFInput asym. encrypted to RAM Output asym. encrypted from RAMDynamic RAMAfter useAutomaticCSPencrypted by objPub key (KTS-IFC or KAS) dupOutSymKe y and dupOutHmacK ey are derived from dupSeed
dupOutSymKe yEncryption key for duplicated objects128, 192, 256128 to 256Symmetric keyKBKDFN/AAES-ENC, AES- DEC-Dynamic RAMAfter useAutomaticCSPderived from dupSeed wraps objSens, objAuth, objSeed
dupOutHmacK eyMAC key for duplicated objects160, 256, 384, 512128 to 256Symmetric keyKBKDFN/AMAC-Dynamic RAMAfter useAutomaticCSPderived from dupSeed protects objSens, objAuth, objSeed
creSeedSeed for credential keys derivation160 to 512128 to 256Symmetric keyN/AKASKBKDFInput asym. encrypted to RAM Output asym. encrypted from RAMDynamic RAMAfter useAutomaticCSPcreSymKey and creHmacKey are derived from creSeed Encrypted by objPub
creSymKeyEncryption key for credentials128, 192, 256128 to 256Symmetric keyKBKDFN/AAES-ENC, AES- DEC-Dynamic RAMAfter useAutomaticCSPderived from creSeed
creHmacKeyHMAC key for credentials160, 256, 384, 512128 to 256Symmetric keyKBKDFN/AMAC-Dynamic RAMAfter useAutomaticCSPderived from creSeed
ephSensEccKe yECC ephemeral private key256, 384, 521128 to 256ECC private keyKAS-KEYGENN/AKAS-Dynamic RAMAfter useAutomaticCSPderived from drbgState
ephPubEccKeyECC ephemeral public key512, 768, 1056128 to 256ECC public keyKAS-KEYGENN/AKASInput plaintext to RAM Output plaintext from RAMDynamic RAMAfter useAutomaticPSPgenerated from ephSensEccKe y
ekRsaProvisioned RSA endorsement key2048112RSA private keyOther – Input during manufacturingN/AKTS-IFC-NVRAMAfter useTPM2_VendorCmdZer oizeEKCSPobjSens is generated from ekRsa

y Public Material – May be reproduced only in its original entirety (without revision).

Page 94
NameDescriptionSize (bits)StrengthTypeGenerated byEstablished byUsed byInputs / OutputsStorageTemporary Storage DurationZeroizationCategoryRelated SSPs
ekEccProvisioned ECC endorsement key256, 384128 to 192ECC private keyOther – Input during manufacturingN/AKAS-NVRAMAfter useTPM2_VendorCmdZer oizeEKCSPobjSens is generated from ekEcc
fuSigECCKeyField upgrade ECC signature verification key384192ECC public keyOther – Input during manufacturingN/ASigVer (ECDSA)-NVRAMAfter use-PSP-
fuSigLMSKeyField upgrade LMS signature verification key32128LMS public keyOther – Input during manufacturingN/ASigVer (LMS)-NVRAMAfter use-PSP-
seqAuthAuthorization value for hash or HMAC sequence112 to 512112 to 256Authentication value / Symmetric keyN/AN/AKBKDF MACInput plaintext to RAM Input protected to RAM Output protected from RAMDynamic RAMUntil use of zeroization command or next resetTPM2_SequenceCom plete TPM2_EventSequence CompleteCSPsesSymKey and sesHmacKey are derived from seqAuth
drbgStateInternal state (V and C secret values) of the DRBG (based on SHA256)256256StateDRBGN/ADRBG-Static RAMUntil next reset or use of TPM2_ClearTPM2_Clear TPM2_InitCSPseeded by drbgSeed
drbgSeedSeed value for the DRBG512256SeedENT-ESVN/ADRBG-Dynamic RAMAfter useAutomaticCSPseeds drbgState
tdrbgStateInternal state (V and C secret values) of the transient DRBG (based on SHA256) used to generate prime numbers for primary RSA keys.256256StateDRBGN/ADRBG-Dynamic RAMAfter useAutomaticCSPinstantiated by nullSeed / phSeed / ehSeed / shSeed
fuSymSeedSeed used for field upgrade symmetric key derivation256256Symmetric keyOther – Input during ManufacturingN/AKBKDF-NVRAMAfter useNonenon-SSPfuSymKey is derived from fuSymSeed
fuSymKeyfield upgrade symmetric key256256Symmetric keyKBKDFN/AAES-DEC-Dynamic RAMAfter useAutomaticnon-SSPfuSymKey is derived from fuSymSeed

Public Material – May be reproduced only in its original entirety (without revision).

Page 95
NameDescriptionSize (bits)StrengthTypeGenerated byEstablished byUsed byInputs / OutputsStorageTemporary Storage DurationZeroizationCategoryRelated SSPs
diagSymSeedSeed used for diagnostic symmetric key derivation256256Symmetric keyOther – Input during ManufacturingN/AKBKDF-NVRAMAfter useNonenon-SSPdiagSymKey is derived from diagSymSeed
diagSymKeydiagnostic symmetric key256256Symmetric keyKBKDFN/AAES-ENC-Dynamic RAMAfter useAutomaticnon-SSPdiagSymKey is derived from diagSymSeed

Public Material – May be reproduced only in its original entirety (without revision).

Page 96
Algorithm*Underlying algorithmKey size (bits)Security strength (bits)
KBKDFSHA-1size ≥ 128128
size < 128Key size
SHA2-256size ≥ 192192
size < 192Key size
SHA2-384 SHA2-512size ≥ 256256
size < 256Key size
HMACSHA-1size ≥ 128128
size < 128Key size
SHA2-256size ≥ 192192
size < 192Key size
SHA2-384 SHA2-512size ≥ 256256
size < 256Key size
DRBGSHA2-256-256
AES-128 / 192 / 256128 / 192 / 256
RSA-2048 / 3072 / 4096112 / 128 / 142
ECC-256 / 384 / 521128 / 192 / 256

Next table gives the security strength of a key depending on the underlying algorithm used and its size: Table 33 – Security Strength of a Key Depending on the Underlying Algorithm Used and its Size

9.5 Transitions

The module only supports the use of SHA-1 in the Approved mode of operation for non-digital signature applications as permitted by SP800-131Ar2. The module only permits the use of SHA-1 for the purposes of digital signatures in the non-Approved mode.

9.6 Additional Information

N/A Public Material – May be reproduced only in its original entirety (without revision).

Page 97
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
Firmware integrity testCRC 16EDCSW/FW IntegritySuccessful execution of TPM2_Startup command indicates tests have been runFW integrity is verified by computing an EDC (CRC-16 [ISO13239]) and comparing it to reference values.
HW integrityHW registers verificationKATCritical FunctionSuccessful execution of TPM2_Startup command indicates tests have been runHW integrity is guaranteed via check of HW sensors. If failure is detected during boot sequence, status is set to FAIL, and error is returned.
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-ENC (A5356)AES-128-CBCKATCASTBit #7 clearAES CBC 128 encryption of known data compared to a reference value.Power On
AES-DEC (A5356)AES-128-CBCKATCASTBit #7 clearAES CBC 128 decryption of known encrypted data and comparison to the expected plaintext dataPower On
ECDSA KeyGen (FIPS186-4) (A5358)P-256, P-384, P-521PCTPCTKey creation failureDepending on the key purpose (signing or key establishment) an ECDSA signature is generated (k fixed and the message varies) and verified with pairwise consistency test as defined by [56Ar3] or a scalar multiplication is done and compared to the public key.Upon ECC Key Generation
ECDSA SigGen (FIPS186-4) (A5358)NIST P-256KATCASTBit #10 clearECDSA signature generation on known data with known key and k. Output of signature is compared to a reference signature.Power On
ECDSA SigVer (FIPS186-4) (A5358)NIST P-256KATCASTBit #10 clearECDSA signature verification on known signature with known key and k.Power On
EntropyRCT and APT[90B] Health- TestCASTBit #1 clearAIS31 and [90B] (RCT and APT) start-up health tests on ESV #E41 output sequence. If test fails, test status is set to FAIL, and error is returnedAt each random bits generation
Firmware loadingECDSA P-384 and LMSSignature VerificationSW/FW LoadError returned on FW loading commandVerification of chained digest and signature to ensure authentication of the FWUpon firmware load
Hash DRBG (A5351)SHA2-256KATCASTBit #1 clearInstantiate then Reseed are seeded with a known seed value (64 bytes). Random is then generated with Generate API to output a 32-bytes value compared to a reference value (single test sequence done in accordance with §11.3 of [90A])Power On
HMAC-SHA-1 (A5355)HMAC-SHA1KATCASTBit #5 clearHMAC on known data and known key. Comparison of output to an expected MAC value (20 bytes)Power On
KAS-ECC Sp800-56Ar3 (A5358)NIST P-256KATCASTBit #9 clearPrimitive "Z" Computation and key derivation are implemented: a known private key d is used with a known point P of NIST P-256 curve to compute Q = dP. Key derivationPower On
10.1 Pre-Operational Self-Tests

The Module performs self-tests to ensure the proper operation of the Module. Per FIPS 140-3 these are categorized as either pre-operational self-tests or conditional self-tests. Pre-operational self–tests are available on demand by power cycling the Module. The Module performs the following pre-operational self-tests in the table below: Table 34: Pre-Operational Self-Tests

10.2 Conditional Self-Tests

The Module performs the following conditional self-tests in the table below. The bit index indicated in the “Indicator” column corresponds to the index in the algos_status field in the TPM2_GetTestResult response. Public Material – May be reproduced only in its original entirety (without revision).

Page 98
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails of Q performed with SHA-1 underlying algorithm to output a key of 20 bytes that is compared to a refence valueConditions
KDF SP800-108 (A5354)N/AKATCASTBit #6 clearKDF on known data and known label. Comparison of output to an expected derivation value (32 bytes)Power On
LMS SigVer (A5360)LMOTS_SHA256_N32_W4 LMS_SHA256_M32_H10KATCASTBit #8 clearLMS signature verification of known signature with known data and known key.Power On
RSA SigGen (FIPS186-5) (A5357)RSASSA-PKCS1-v1_5KATCASTBit #12 clearRSA signature generation on known data with a known key. Output of signature is compared to a reference signature (covers also KTS-IFC functionality)Power On
RSA SigVer (FIPS186-5) (A5357)RSASSA-PKCS1-v1_5KATCASTBit #12 clearRSA signature verification on a known signature with a known key (covers also KTS- IFC functionality)Power On
RSA KeyGen (FIPS186-5) (A5357)2048, 3072 or 4096-bitPCTPCTKey creation failureDepending on the key purpose (signing or encrypting) indicated in sign attribute of the key, encryption/decryption or signing/verification is done on known dataUpon RSA Key Generation
SHSSHA1, SHA2-256, SHA2-512, SHA3-256KATCASTBit #2 clear Bit #3 clear Bit #4 clearHash of known data and comparison of output to an expected digest. SHA-1, SHA2-256, SHA2-512 are tested twice to cover each of the two implementations covered by CAVP Cert. #A5352 and #A5353.Power On

Table 35: Conditional Self-Tests Public Material – May be reproduced only in its original entirety (without revision).

Page 99
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
Firmware integrity testEDCSW/FW IntegrityOn demandManually
HW integrityKATCritical FunctionOn demandManually
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-ENC (A5356)KATCASTOn DemandManually
AES-DEC (A5356)KATCASTOn DemandManually
ECDSA KeyGen (FIPS186-4) (A5358)PCTPCTN/AManually
ECDSA SigGen (FIPS186-4) (A5358)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-4) (A5358)KATCASTOn DemandManually
Entropy[90B] Health- TestCASTOn DemandManually
Firmware loadingSignature VerificationSW/FW LoadOn DemandManually
Hash DRBG (A5351)KATCASTOn DemandManually
HMAC-SHA-1 (A5355)KATCASTOn DemandManually
KAS-ECC Sp800-56Ar3 (A5358)KATCASTOn DemandManually
KDF SP800-108 (A5354)KATCASTOn DemandManually
LMS SigVer (A5360)KATCASTOn DemandManually
RSA SigGen (FIPS186-5) (A5357)KATCASTOn DemandManually
RSA SigVer (FIPS186-5) (A5357)KATCASTOn DemandManually
10.3 Periodic Self-Test Information

Table 36: Pre-Operational Periodic Information Public Material – May be reproduced only in its original entirety (without revision).

Page 100
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
RSA KeyGen (FIPS186-5) (A5357)PCTPCTN/AManually
SHSKATCASTOn DemandManually
NameDescriptionConditionsRecovery MethodIndicator
ES1The Module fails a KAT, PCT, FW or HW integrity verification, [90B] health testThe Module enters the failure stateReboot/Power cycle the moduleOutputs return code of TPM_RC_FAILURE, otherwise it indicates successful completion by TPM_RC_SUCCESS
ES2The Module fails a firmware loading testThe Module returns to normal stateNoneReturn code different from TPM_RC_SUCCESS sent on firmware upgrade start command

Table 37: Conditional Periodic Information

10.4 Error States

Table 38: Error States All cryptographic functions are inhibited while the module is in an error state. Successful completion of self-tests can be verified through use of TPM2_GetTestResult command. The first 4 bytes of response indicate self-tests status. If they are equal to 0, self-tests completed successfully. If not, the subsequent 4 bytes indicate the list of algorithms not fully self-tested. Public Material – May be reproduced only in its original entirety (without revision).

Page 101
Policy commands*Authentication mechanismDescription
T PM2_PolicyAuthValueMessage Authentication CodeauthValue of authorized entity is used as HMAC key in authorization HMAC (as for HMAC session)
T PM2_PolicySignedPublic Key Digital Signature Algorithm or Message Authentication CodeSignature with asymmetric or HMAC key
TPM2_PolicyAuthorizeMessage Authentication CodeSignature with HMAC key being one of the hierarchy proofs
TPM2_PolicySecretMessage Authentication CodeauthValue of reference entity is provided in HMAC session, or policy session containing TPM2_PolicyAuthValue
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

Installation and Initialization: The following steps must be performed in order to securely install, initialize, and start up the Module in the FIPS 140-3 Approved mode of operation:

Page 102
TPM2_PolicyTicketMessage Authentication CodeSignature with HMAC key (one of the proofs) generated by TPM2_PolicySigned or TPM2_PolicySecret
Bound sessionMessage Authentication CodeauthValue of bound entity is used as KDK generated from KBKDF in session key derivation

Table 39 – List of policy commands to use in a policy session TPM is operated in an approved mode of operation as long as no non-approved service using a nonapproved algorithm is used. No specific rules of operation are required to operate this module at FIPS 140-3 Level 2. TPM is in normal operation mode when all pre-operational and conditional self-tests (apart from firmware load and PCT tests) are complete. All approved and non-approved services with the corresponding indicator reporting if the service uses an approved cryptographic algorithm or a security function.

11.2 Administrator Guidance

No specific initialization procedure is required.

11.3 Non-Administrator Guidance

No initialization procedures are required.

11.4 Design and Rules

Rules of Operation

  1. The Module provides two operator roles: the Cryptographic Officer and the User role. Each role is associated with a set of services as detailed in Section 4.3.
  2. The Module, evaluated at FIPS 140-3 Level 2, requires authentication to access some of the services as detailed in Section 4.1.
  3. The Module allows the operator to initiate power-up self-tests by power cycling or resetting the Module.
  4. Power up self-tests do not require any operator action.
  5. Data output is inhibited during key generation, self-tests, zeroisation, firmware loading, and error states.
  6. Status information does not contain CSPs or sensitive data that if misused could lead to a compromise of the Module.
  7. The Module does not support concurrent operators.
  8. The Module does not support a maintenance interface or role.
  9. The Module does not support manual key entry method. Public Material – May be reproduced only in its original entirety (without revision).
Page 103
  1. The Module does not have any proprietary external input/output devices used for entry/output of data.
  2. The Module does not output intermediate key values.
  3. The Module does not provide bypass services or ports/interfaces.
  4. The Module does not support a self-initiated cryptographic output capability.
  5. For all zeroisation methods, the module must be in direct control of the operator.
11.5 Maintenance Requirements
11.6 End of Life
Table, extracted as text (did not parse into structured rows)
End-of-life of the product requires the following zeroisation commands to be executed to remove all CSPs from the memory of the module: •   TPM2_Init •   TPM2_Clear •   TPM2_ChangeEPS •   TPM2_ChangePPS •   TPM2_VendorCmdZeroizeEK •   TPM2_NV_UndefineSpace or TPM2_NV_UndefineSpaceSpecial Public Material – May be reproduced only in its original entirety (without revision).
Page 104
12 Mitigation of Other Attacks

The Module does not implement any mitigation method against other attacks. Public Material – May be reproduced only in its original entirety (without revision).

Page 105
Abbreviation*Full Specification Name
[TPM2.0 Part1]TPM2.0 Main, Part 1, Architecture, rev 1.59, TCG
[TPM2.0 Part2]TPM2.0 Main, Part 2, Structures, rev 1.59, TCG
[TPM2.0 Part3]TPM2.0 Main, Part 3, Commands, rev 1.59, TCG
[TPM2.0 Part4]TPM2.0 Main, Part 4, Supporting routines, rev 1.59, TCG
[PTP 1.06]TCG PC Client Platform TPM Profile (PTP) Specification, rev. 1.06
[FIPS TCG]TCG FIPS 140-3 guidance for TPM 2.0, version 1.0, rev. 1, January 30, 2024
[ISO19790]International Standard, ISO/IEC 19790, Information technology — Security techniques — Test requirements for cryptographic modules, Third edition, March 2017
[ISO24759]International Standard, ISO/IEC 24759, Information technology — Security techniques — Test requirements for cryptographic modules, Second and Corrected version, 15 December 2015
[ISO13239]International Standard, ISO/IEC 13239, Information technology — Telecommunications and information exchange between systems — High-level data link control (HDLC) procedures, July 2002
[140-3]Security Requirements for Cryptographic Modules, March 22, 2019
[140]NIST Special Publication 800-140, FIPS 140-3 Derived Test Requirements (DTR), CMVP Validation Authority Updates to ISO/IEC 24759, March 2020
[140A]NIST Special Publication 800-140A, CMVP Documentation Requirements, CMVP Validation Authority Updates to ISO/IEC 24759, March 2020
[140Br1]NIST Special Publication 800-140B revision 1, CMVP Security Policy Requirements, CMVP Validation Authority Updates to ISO/IEC 24759 and ISO/IEC 19790 Annex B, November 2023
[140C]NIST Special Publication 800-140Cr2, CMVP Approved Security Functions, CMVP Validation Authority Updates to ISO/IEC 24759, July 2023
[140D]NIST Special Publication 800-140Dr2, CMVP Approved Sensitive Security Parameter Generation and Establishment Methods, CMVP Validation Authority Updates to ISO/IEC 24759, July 2023
[140E]NIST Special Publication 800-140E, CMVP Approved Authentication Mechanisms, CMVP Validation Authority Requirements for ISO/IEC 19790:2012 Annex E and ISO/IEC 24759 Section 6.17, March 2020
[140F]NIST Special Publication 800-140Fr1, CMVP Approved Non-Invasive Attack Mitigation Test Metrics, CMVP Validation Authority Updates to ISO/IEC 24759, August 2021
[IG]Implementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program, October 23, 2024
[108]NIST Special Publication 800-108r1-upd1, Recommendation for Key Derivation Using Pseudorandom Functions (Revised), August 2022
[131A]Transitions: Recommendation for Transitioning the Use of Cryptographic Algorithms and Key Lengths, Revision 2, March 2019

References and Definitions The following standards are referred to in this Security Policy. Public Material – May be reproduced only in its original entirety (without revision).

Page 106
Abbreviation*Full Specification Name
[133]NIST Special Publication 800-133, Recommendation for Cryptographic Key Generation, Revision 2, June 2020
[135]National Institute of Standards and Technology, Recommendation for Existing Application- Specific Key Derivation Functions, Special Publication 800-135rev1, December 2011
[186]National Institute of Standards and Technology, Digital Signature Standard (DSS), Federal Information Processing Standards Publication 186-5, Feb 2023
[197]National Institute of Standards and Technology, Advanced Encryption Standard (AES), Federal Information Processing Standards Publication 197-upd1, May, 2023
[198]National Institute of Standards and Technology, The Keyed-Hash Message Authentication Code (HMAC), Federal Information Processing Standards Publication 198-1, July, 2008
[180]National Institute of Standards and Technology, Secure Hash Standard, Federal Information Processing Standards Publication 180-4, August 2015
[202]FEDERAL INFORMATION PROCESSING STANDARDS PUBLICATION, SHA-3 Standard: Permutation- Based Hash and Extendable-Output Functions, FIPS PUB 202, August 2015
[208]National Institute of Standards and Technology, Recommendation for Stateful Hash-Based Signature Schemes, October 2020
[38A]National Institute of Standards and Technology, Recommendation for Block Cipher Modes of Operation, Methods and Techniques, Special Publication 800-38A, December 2001
[56Ar3]NIST Special Publication 800-56A Revision 3, Recommendation for Pair-Wise Key Establishment Schemes Using Discrete Logarithm Cryptography, April 2018
[56Br2]NIST Special Publication 800-56B Revision 2, Recommendation for Pair-Wise Key Establishment Schemes Using Finite Field Cryptography, March 2019
[90A]National Institute of Standards and Technology, Recommendation for Random Number Generation Using Deterministic Random Bit Generators, Special Publication 800-90A, Revision 1, June 2015
[90B]National Institute of Standards and Technology, Recommendation for the Entropy Sources Used for Random Bit Generation, Special Publication 800-90B, January 2018
Acronym*Definition
APTAdaptive Proportion Test
BN P-256Barreto-Naehrig 256-bit elliptic curve
FWFirmware
HWHardware
KATKnow Answer Test
I2CInter-Integrated Circuit
MPUMemory Protection Unit
RCTRepetition Count Test
SPISerial Peripheral Interface

Table 40

Page 107
Acronym*Definition
SSPSensitive Security Parameter
TCGTrusted Computing Group
TPMTrusted Platform Module

Table 41