File syn_tpm2.c¶
FileList > crypto > syn_tpm2.c
Go to the source code of this file
TCG TPM 2.0 Command Marshaller & Measured Boot Engine Implementation.
#include "../port/syn_port_system.h"#include "syn_tpm2.h"#include <string.h>
Public Functions¶
| Type | Name |
|---|---|
| uint32_t | syn_tpm2_get_last_rc (const SYN_TPM2_Context * ctx) Get last TPM 2.0 response code returned by TPM hardware. |
| SYN_Status | syn_tpm2_get_random (SYN_TPM2_Context * ctx, uint16_t num_bytes, uint8_t * out_random, uint16_t * out_len) Generate cryptographic true random bytes from TPM TRNG (TPM2_GetRandom). |
| SYN_Status | syn_tpm2_init (SYN_TPM2_Context * ctx, const SYN_TPM2_Config * cfg) Initialize TPM 2.0 Context. |
| SYN_Status | syn_tpm2_nv_read (SYN_TPM2_Context * ctx, uint32_t auth_handle, uint32_t nv_index, uint16_t offset, uint16_t size, uint8_t * out_data, uint16_t * out_len) Read data from secure Non-Volatile storage index (TPM2_NV_Read). |
| SYN_Status | syn_tpm2_nv_write (SYN_TPM2_Context * ctx, uint32_t auth_handle, uint32_t nv_index, uint16_t offset, const uint8_t * in_data, uint16_t size) Write data to secure Non-Volatile storage index (TPM2_NV_Write). |
| SYN_Status | syn_tpm2_pcr_extend (SYN_TPM2_Context * ctx, uint32_t pcr_index, uint16_t hash_alg, const uint8_t * in_digest, size_t digest_len) Extend Platform Configuration Register with measurement digest (TPM2_PCR_Extend). |
| SYN_Status | syn_tpm2_pcr_read (SYN_TPM2_Context * ctx, uint32_t pcr_index, uint16_t hash_alg, uint8_t * out_digest, size_t * out_digest_len) Read single Platform Configuration Register (TPM2_PCR_Read). |
| SYN_Status | syn_tpm2_quote (SYN_TPM2_Context * ctx, uint32_t key_handle, const uint8_t * qualifying_data, size_t qual_len, uint32_t pcr_mask, SYN_TPM2_QuoteResult * out_quote) Generate Remote Attestation Quote over PCR values (TPM2_Quote). |
| SYN_Status | syn_tpm2_self_test (SYN_TPM2_Context * ctx, bool full_test) Execute TPM2_SelfTest command. |
| SYN_Status | syn_tpm2_startup (SYN_TPM2_Context * ctx, uint16_t startup_type) Execute TPM2_Startup command. |
Public Static Functions¶
| Type | Name |
|---|---|
| SYN_Status | tpm2_execute_command (SYN_TPM2_Context * ctx, size_t cmd_len, size_t * out_resp_len) Execute TPM 2.0 command over transport and parse standard response header. |
| bool | tpm2_read_bytes (const uint8_t * buf, size_t * pos, size_t max_len, uint8_t * out_data, size_t len) Read raw byte array from buffer. |
| bool | tpm2_read_u16 (const uint8_t * buf, size_t * pos, size_t max_len, uint16_t * out_v) Read 16-bit unsigned integer from big-endian buffer. |
| bool | tpm2_read_u32 (const uint8_t * buf, size_t * pos, size_t max_len, uint32_t * out_v) Read 32-bit unsigned integer from big-endian buffer. |
| bool | tpm2_write_bytes (uint8_t * buf, size_t * pos, size_t max_len, const uint8_t * data, size_t len) Write raw byte array into buffer. |
| bool | tpm2_write_pw_auth_session (uint8_t * tx, size_t * pos, size_t max_len) Helper to write standard empty Password Authorization Session area. |
| bool | tpm2_write_u16 (uint8_t * buf, size_t * pos, size_t max_len, uint16_t v) Write 16-bit unsigned integer in big-endian network byte order. |
| bool | tpm2_write_u32 (uint8_t * buf, size_t * pos, size_t max_len, uint32_t v) Write 32-bit unsigned integer in big-endian network byte order. |
Public Functions Documentation¶
function syn_tpm2_get_last_rc¶
Get last TPM 2.0 response code returned by TPM hardware.
Parameters:
ctxContext instance.
Returns:
32-bit TPM response code (e.g. TPM_RC_SUCCESS = 0).
function syn_tpm2_get_random¶
Generate cryptographic true random bytes from TPM TRNG (TPM2_GetRandom).
SYN_Status syn_tpm2_get_random (
SYN_TPM2_Context * ctx,
uint16_t num_bytes,
uint8_t * out_random,
uint16_t * out_len
)
Parameters:
ctxContext instance.num_bytesNumber of random bytes requested.out_randomBuffer to receive random bytes.out_lenPointer to receive actual number of bytes returned.
Returns:
SYN_OK on success.
function syn_tpm2_init¶
Initialize TPM 2.0 Context.
Parameters:
ctxContext instance.cfgConfiguration descriptor.
Returns:
SYN_OK on success, SYN_INVALID_PARAM on invalid parameter.
function syn_tpm2_nv_read¶
Read data from secure Non-Volatile storage index (TPM2_NV_Read).
SYN_Status syn_tpm2_nv_read (
SYN_TPM2_Context * ctx,
uint32_t auth_handle,
uint32_t nv_index,
uint16_t offset,
uint16_t size,
uint8_t * out_data,
uint16_t * out_len
)
Parameters:
ctxContext instance.auth_handleAuthorization handle (e.g. SYN_TPM2_RH_OWNER).nv_indexNVRAM index (e.g. 0x01500000).offsetByte offset within NV area.sizeNumber of bytes to read.out_dataOutput buffer.out_lenPointer to receive bytes read.
Returns:
SYN_OK on success.
function syn_tpm2_nv_write¶
Write data to secure Non-Volatile storage index (TPM2_NV_Write).
SYN_Status syn_tpm2_nv_write (
SYN_TPM2_Context * ctx,
uint32_t auth_handle,
uint32_t nv_index,
uint16_t offset,
const uint8_t * in_data,
uint16_t size
)
Parameters:
ctxContext instance.auth_handleAuthorization handle (e.g. SYN_TPM2_RH_OWNER).nv_indexNVRAM index.offsetByte offset within NV area.in_dataData buffer to write.sizeNumber of bytes to write.
Returns:
SYN_OK on success.
function syn_tpm2_pcr_extend¶
Extend Platform Configuration Register with measurement digest (TPM2_PCR_Extend).
SYN_Status syn_tpm2_pcr_extend (
SYN_TPM2_Context * ctx,
uint32_t pcr_index,
uint16_t hash_alg,
const uint8_t * in_digest,
size_t digest_len
)
Parameters:
ctxContext instance.pcr_indexPCR register index (0..23).hash_algHash algorithm (SYN_TPM2_ALG_SHA256 or SYN_TPM2_ALG_SHA384).in_digestDigest bytes to extend PCR with.digest_lenLength of in_digest (must match hash algorithm).
Returns:
SYN_OK on success.
function syn_tpm2_pcr_read¶
Read single Platform Configuration Register (TPM2_PCR_Read).
SYN_Status syn_tpm2_pcr_read (
SYN_TPM2_Context * ctx,
uint32_t pcr_index,
uint16_t hash_alg,
uint8_t * out_digest,
size_t * out_digest_len
)
Parameters:
ctxContext instance.pcr_indexPCR register index (0..23).hash_algHash algorithm bank (SYN_TPM2_ALG_SHA256 or SYN_TPM2_ALG_SHA384).out_digestOutput buffer to receive digest.out_digest_lenPointer to receive digest length (32 for SHA-256, 48 for SHA-384).
Returns:
SYN_OK on success.
function syn_tpm2_quote¶
Generate Remote Attestation Quote over PCR values (TPM2_Quote).
SYN_Status syn_tpm2_quote (
SYN_TPM2_Context * ctx,
uint32_t key_handle,
const uint8_t * qualifying_data,
size_t qual_len,
uint32_t pcr_mask,
SYN_TPM2_QuoteResult * out_quote
)
Parameters:
ctxContext instance.key_handleAttestation signing key handle (e.g. AK / EK).qualifying_dataNonce / qualifying data to prevent replay.qual_lenLength of qualifying data.pcr_mask24-bit bitmask of PCRs to include in quote.out_quotePointer to receive quote structure.
Returns:
SYN_OK on success.
function syn_tpm2_self_test¶
Execute TPM2_SelfTest command.
Parameters:
ctxContext instance.full_testIf true, tests all algorithms; if false, tests incrementally.
Returns:
SYN_OK on success.
function syn_tpm2_startup¶
Execute TPM2_Startup command.
Parameters:
ctxContext instance.startup_typeStartup mode (SYN_TPM2_SU_CLEAR or SYN_TPM2_SU_STATE).
Returns:
SYN_OK on success, SYN_ERROR on TPM failure.
Public Static Functions Documentation¶
function tpm2_execute_command¶
Execute TPM 2.0 command over transport and parse standard response header.
static SYN_Status tpm2_execute_command (
SYN_TPM2_Context * ctx,
size_t cmd_len,
size_t * out_resp_len
)
Parameters:
ctxContext instance.cmd_lenTotal command buffer length.out_resp_lenOutput response length.
Returns:
SYN_OK on TPM success, SYN_ERROR on transport or TPM RC error.
function tpm2_read_bytes¶
Read raw byte array from buffer.
static bool tpm2_read_bytes (
const uint8_t * buf,
size_t * pos,
size_t max_len,
uint8_t * out_data,
size_t len
)
Parameters:
bufSource buffer.posCurrent offset pointer.max_lenTotal available bytes.out_dataOutput destination.lenNumber of bytes to copy.
Returns:
true on success, false on underflow.
function tpm2_read_u16¶
Read 16-bit unsigned integer from big-endian buffer.
Parameters:
bufSource buffer.posCurrent offset pointer.max_lenTotal available bytes.out_vOutput pointer.
Returns:
true on success, false on underflow.
function tpm2_read_u32¶
Read 32-bit unsigned integer from big-endian buffer.
Parameters:
bufSource buffer.posCurrent offset pointer.max_lenTotal available bytes.out_vOutput pointer.
Returns:
true on success, false on underflow.
function tpm2_write_bytes¶
Write raw byte array into buffer.
static bool tpm2_write_bytes (
uint8_t * buf,
size_t * pos,
size_t max_len,
const uint8_t * data,
size_t len
)
Parameters:
bufTarget buffer.posCurrent offset pointer.max_lenMaximum buffer capacity.dataSource byte array.lenNumber of bytes to copy.
Returns:
true on success, false on overflow.
function tpm2_write_pw_auth_session¶
Helper to write standard empty Password Authorization Session area.
Parameters:
txCommand buffer.posOffset pointer.max_lenMaximum length.
Returns:
true on success.
function tpm2_write_u16¶
Write 16-bit unsigned integer in big-endian network byte order.
Parameters:
bufTarget buffer.posCurrent offset pointer (updated on write).max_lenMaximum buffer capacity.vValue to write.
Returns:
true on success, false on overflow.
function tpm2_write_u32¶
Write 32-bit unsigned integer in big-endian network byte order.
Parameters:
bufTarget buffer.posCurrent offset pointer (updated on write).max_lenMaximum buffer capacity.vValue to write.
Returns:
true on success, false on overflow.
The documentation for this class was generated from the following file src/syntropic/crypto/syn_tpm2.c