Skip to content

File syn_tpm2.c

FileList > crypto > syn_tpm2.c

Go to the source code of this file

TCG TPM 2.0 Command Marshaller & Measured Boot Engine Implementation.

  • #include "../port/syn_port_system.h"
  • #include "syn_tpm2.h"
  • #include <string.h>

Public Functions

Type Name
uint32_t syn_tpm2_get_last_rc (const SYN_TPM2_Context * ctx)
Get last TPM 2.0 response code returned by TPM hardware.
SYN_Status syn_tpm2_get_random (SYN_TPM2_Context * ctx, uint16_t num_bytes, uint8_t * out_random, uint16_t * out_len)
Generate cryptographic true random bytes from TPM TRNG (TPM2_GetRandom).
SYN_Status syn_tpm2_init (SYN_TPM2_Context * ctx, const SYN_TPM2_Config * cfg)
Initialize TPM 2.0 Context.
SYN_Status syn_tpm2_nv_read (SYN_TPM2_Context * ctx, uint32_t auth_handle, uint32_t nv_index, uint16_t offset, uint16_t size, uint8_t * out_data, uint16_t * out_len)
Read data from secure Non-Volatile storage index (TPM2_NV_Read).
SYN_Status syn_tpm2_nv_write (SYN_TPM2_Context * ctx, uint32_t auth_handle, uint32_t nv_index, uint16_t offset, const uint8_t * in_data, uint16_t size)
Write data to secure Non-Volatile storage index (TPM2_NV_Write).
SYN_Status syn_tpm2_pcr_extend (SYN_TPM2_Context * ctx, uint32_t pcr_index, uint16_t hash_alg, const uint8_t * in_digest, size_t digest_len)
Extend Platform Configuration Register with measurement digest (TPM2_PCR_Extend).
SYN_Status syn_tpm2_pcr_read (SYN_TPM2_Context * ctx, uint32_t pcr_index, uint16_t hash_alg, uint8_t * out_digest, size_t * out_digest_len)
Read single Platform Configuration Register (TPM2_PCR_Read).
SYN_Status syn_tpm2_quote (SYN_TPM2_Context * ctx, uint32_t key_handle, const uint8_t * qualifying_data, size_t qual_len, uint32_t pcr_mask, SYN_TPM2_QuoteResult * out_quote)
Generate Remote Attestation Quote over PCR values (TPM2_Quote).
SYN_Status syn_tpm2_self_test (SYN_TPM2_Context * ctx, bool full_test)
Execute TPM2_SelfTest command.
SYN_Status syn_tpm2_startup (SYN_TPM2_Context * ctx, uint16_t startup_type)
Execute TPM2_Startup command.

Public Static Functions

Type Name
SYN_Status tpm2_execute_command (SYN_TPM2_Context * ctx, size_t cmd_len, size_t * out_resp_len)
Execute TPM 2.0 command over transport and parse standard response header.
bool tpm2_read_bytes (const uint8_t * buf, size_t * pos, size_t max_len, uint8_t * out_data, size_t len)
Read raw byte array from buffer.
bool tpm2_read_u16 (const uint8_t * buf, size_t * pos, size_t max_len, uint16_t * out_v)
Read 16-bit unsigned integer from big-endian buffer.
bool tpm2_read_u32 (const uint8_t * buf, size_t * pos, size_t max_len, uint32_t * out_v)
Read 32-bit unsigned integer from big-endian buffer.
bool tpm2_write_bytes (uint8_t * buf, size_t * pos, size_t max_len, const uint8_t * data, size_t len)
Write raw byte array into buffer.
bool tpm2_write_pw_auth_session (uint8_t * tx, size_t * pos, size_t max_len)
Helper to write standard empty Password Authorization Session area.
bool tpm2_write_u16 (uint8_t * buf, size_t * pos, size_t max_len, uint16_t v)
Write 16-bit unsigned integer in big-endian network byte order.
bool tpm2_write_u32 (uint8_t * buf, size_t * pos, size_t max_len, uint32_t v)
Write 32-bit unsigned integer in big-endian network byte order.

Public Functions Documentation

function syn_tpm2_get_last_rc

Get last TPM 2.0 response code returned by TPM hardware.

uint32_t syn_tpm2_get_last_rc (
    const SYN_TPM2_Context * ctx
) 

Parameters:

  • ctx Context instance.

Returns:

32-bit TPM response code (e.g. TPM_RC_SUCCESS = 0).


function syn_tpm2_get_random

Generate cryptographic true random bytes from TPM TRNG (TPM2_GetRandom).

SYN_Status syn_tpm2_get_random (
    SYN_TPM2_Context * ctx,
    uint16_t num_bytes,
    uint8_t * out_random,
    uint16_t * out_len
) 

Parameters:

  • ctx Context instance.
  • num_bytes Number of random bytes requested.
  • out_random Buffer to receive random bytes.
  • out_len Pointer to receive actual number of bytes returned.

Returns:

SYN_OK on success.


function syn_tpm2_init

Initialize TPM 2.0 Context.

SYN_Status syn_tpm2_init (
    SYN_TPM2_Context * ctx,
    const SYN_TPM2_Config * cfg
) 

Parameters:

  • ctx Context instance.
  • cfg Configuration descriptor.

Returns:

SYN_OK on success, SYN_INVALID_PARAM on invalid parameter.


function syn_tpm2_nv_read

Read data from secure Non-Volatile storage index (TPM2_NV_Read).

SYN_Status syn_tpm2_nv_read (
    SYN_TPM2_Context * ctx,
    uint32_t auth_handle,
    uint32_t nv_index,
    uint16_t offset,
    uint16_t size,
    uint8_t * out_data,
    uint16_t * out_len
) 

Parameters:

  • ctx Context instance.
  • auth_handle Authorization handle (e.g. SYN_TPM2_RH_OWNER).
  • nv_index NVRAM index (e.g. 0x01500000).
  • offset Byte offset within NV area.
  • size Number of bytes to read.
  • out_data Output buffer.
  • out_len Pointer to receive bytes read.

Returns:

SYN_OK on success.


function syn_tpm2_nv_write

Write data to secure Non-Volatile storage index (TPM2_NV_Write).

SYN_Status syn_tpm2_nv_write (
    SYN_TPM2_Context * ctx,
    uint32_t auth_handle,
    uint32_t nv_index,
    uint16_t offset,
    const uint8_t * in_data,
    uint16_t size
) 

Parameters:

  • ctx Context instance.
  • auth_handle Authorization handle (e.g. SYN_TPM2_RH_OWNER).
  • nv_index NVRAM index.
  • offset Byte offset within NV area.
  • in_data Data buffer to write.
  • size Number of bytes to write.

Returns:

SYN_OK on success.


function syn_tpm2_pcr_extend

Extend Platform Configuration Register with measurement digest (TPM2_PCR_Extend).

SYN_Status syn_tpm2_pcr_extend (
    SYN_TPM2_Context * ctx,
    uint32_t pcr_index,
    uint16_t hash_alg,
    const uint8_t * in_digest,
    size_t digest_len
) 

Parameters:

  • ctx Context instance.
  • pcr_index PCR register index (0..23).
  • hash_alg Hash algorithm (SYN_TPM2_ALG_SHA256 or SYN_TPM2_ALG_SHA384).
  • in_digest Digest bytes to extend PCR with.
  • digest_len Length of in_digest (must match hash algorithm).

Returns:

SYN_OK on success.


function syn_tpm2_pcr_read

Read single Platform Configuration Register (TPM2_PCR_Read).

SYN_Status syn_tpm2_pcr_read (
    SYN_TPM2_Context * ctx,
    uint32_t pcr_index,
    uint16_t hash_alg,
    uint8_t * out_digest,
    size_t * out_digest_len
) 

Parameters:

  • ctx Context instance.
  • pcr_index PCR register index (0..23).
  • hash_alg Hash algorithm bank (SYN_TPM2_ALG_SHA256 or SYN_TPM2_ALG_SHA384).
  • out_digest Output buffer to receive digest.
  • out_digest_len Pointer to receive digest length (32 for SHA-256, 48 for SHA-384).

Returns:

SYN_OK on success.


function syn_tpm2_quote

Generate Remote Attestation Quote over PCR values (TPM2_Quote).

SYN_Status syn_tpm2_quote (
    SYN_TPM2_Context * ctx,
    uint32_t key_handle,
    const uint8_t * qualifying_data,
    size_t qual_len,
    uint32_t pcr_mask,
    SYN_TPM2_QuoteResult * out_quote
) 

Parameters:

  • ctx Context instance.
  • key_handle Attestation signing key handle (e.g. AK / EK).
  • qualifying_data Nonce / qualifying data to prevent replay.
  • qual_len Length of qualifying data.
  • pcr_mask 24-bit bitmask of PCRs to include in quote.
  • out_quote Pointer to receive quote structure.

Returns:

SYN_OK on success.


function syn_tpm2_self_test

Execute TPM2_SelfTest command.

SYN_Status syn_tpm2_self_test (
    SYN_TPM2_Context * ctx,
    bool full_test
) 

Parameters:

  • ctx Context instance.
  • full_test If true, tests all algorithms; if false, tests incrementally.

Returns:

SYN_OK on success.


function syn_tpm2_startup

Execute TPM2_Startup command.

SYN_Status syn_tpm2_startup (
    SYN_TPM2_Context * ctx,
    uint16_t startup_type
) 

Parameters:

  • ctx Context instance.
  • startup_type Startup mode (SYN_TPM2_SU_CLEAR or SYN_TPM2_SU_STATE).

Returns:

SYN_OK on success, SYN_ERROR on TPM failure.


Public Static Functions Documentation

function tpm2_execute_command

Execute TPM 2.0 command over transport and parse standard response header.

static SYN_Status tpm2_execute_command (
    SYN_TPM2_Context * ctx,
    size_t cmd_len,
    size_t * out_resp_len
) 

Parameters:

  • ctx Context instance.
  • cmd_len Total command buffer length.
  • out_resp_len Output response length.

Returns:

SYN_OK on TPM success, SYN_ERROR on transport or TPM RC error.


function tpm2_read_bytes

Read raw byte array from buffer.

static bool tpm2_read_bytes (
    const uint8_t * buf,
    size_t * pos,
    size_t max_len,
    uint8_t * out_data,
    size_t len
) 

Parameters:

  • buf Source buffer.
  • pos Current offset pointer.
  • max_len Total available bytes.
  • out_data Output destination.
  • len Number of bytes to copy.

Returns:

true on success, false on underflow.


function tpm2_read_u16

Read 16-bit unsigned integer from big-endian buffer.

static bool tpm2_read_u16 (
    const uint8_t * buf,
    size_t * pos,
    size_t max_len,
    uint16_t * out_v
) 

Parameters:

  • buf Source buffer.
  • pos Current offset pointer.
  • max_len Total available bytes.
  • out_v Output pointer.

Returns:

true on success, false on underflow.


function tpm2_read_u32

Read 32-bit unsigned integer from big-endian buffer.

static bool tpm2_read_u32 (
    const uint8_t * buf,
    size_t * pos,
    size_t max_len,
    uint32_t * out_v
) 

Parameters:

  • buf Source buffer.
  • pos Current offset pointer.
  • max_len Total available bytes.
  • out_v Output pointer.

Returns:

true on success, false on underflow.


function tpm2_write_bytes

Write raw byte array into buffer.

static bool tpm2_write_bytes (
    uint8_t * buf,
    size_t * pos,
    size_t max_len,
    const uint8_t * data,
    size_t len
) 

Parameters:

  • buf Target buffer.
  • pos Current offset pointer.
  • max_len Maximum buffer capacity.
  • data Source byte array.
  • len Number of bytes to copy.

Returns:

true on success, false on overflow.


function tpm2_write_pw_auth_session

Helper to write standard empty Password Authorization Session area.

static bool tpm2_write_pw_auth_session (
    uint8_t * tx,
    size_t * pos,
    size_t max_len
) 

Parameters:

  • tx Command buffer.
  • pos Offset pointer.
  • max_len Maximum length.

Returns:

true on success.


function tpm2_write_u16

Write 16-bit unsigned integer in big-endian network byte order.

static bool tpm2_write_u16 (
    uint8_t * buf,
    size_t * pos,
    size_t max_len,
    uint16_t v
) 

Parameters:

  • buf Target buffer.
  • pos Current offset pointer (updated on write).
  • max_len Maximum buffer capacity.
  • v Value to write.

Returns:

true on success, false on overflow.


function tpm2_write_u32

Write 32-bit unsigned integer in big-endian network byte order.

static bool tpm2_write_u32 (
    uint8_t * buf,
    size_t * pos,
    size_t max_len,
    uint32_t v
) 

Parameters:

  • buf Target buffer.
  • pos Current offset pointer (updated on write).
  • max_len Maximum buffer capacity.
  • v Value to write.

Returns:

true on success, false on overflow.



The documentation for this class was generated from the following file src/syntropic/crypto/syn_tpm2.c