File syn_tpm2.h¶
FileList > crypto > syn_tpm2.h
Go to the source code of this file
TCG TPM 2.0 Command Marshaller, Measured Boot, & Hardware Root-of-Trust Engine. More...
#include "../common/syn_defs.h"#include "../net/syn_transport.h"#include <stdbool.h>#include <stddef.h>#include <stdint.h>
Classes¶
| Type | Name |
|---|---|
| struct | SYN_TPM2_Config TPM 2.0 Context Configuration Descriptor. |
| struct | SYN_TPM2_Context TPM 2.0 Client Instance Context. |
| struct | SYN_TPM2_QuoteResult TPM 2.0 Attestation Quote Output Structure. |
Public Functions¶
| Type | Name |
|---|---|
| uint32_t | syn_tpm2_get_last_rc (const SYN_TPM2_Context * ctx) Get last TPM 2.0 response code returned by TPM hardware. |
| SYN_Status | syn_tpm2_get_random (SYN_TPM2_Context * ctx, uint16_t num_bytes, uint8_t * out_random, uint16_t * out_len) Generate cryptographic true random bytes from TPM TRNG (TPM2_GetRandom). |
| SYN_Status | syn_tpm2_init (SYN_TPM2_Context * ctx, const SYN_TPM2_Config * cfg) Initialize TPM 2.0 Context. |
| SYN_Status | syn_tpm2_nv_read (SYN_TPM2_Context * ctx, uint32_t auth_handle, uint32_t nv_index, uint16_t offset, uint16_t size, uint8_t * out_data, uint16_t * out_len) Read data from secure Non-Volatile storage index (TPM2_NV_Read). |
| SYN_Status | syn_tpm2_nv_write (SYN_TPM2_Context * ctx, uint32_t auth_handle, uint32_t nv_index, uint16_t offset, const uint8_t * in_data, uint16_t size) Write data to secure Non-Volatile storage index (TPM2_NV_Write). |
| SYN_Status | syn_tpm2_pcr_extend (SYN_TPM2_Context * ctx, uint32_t pcr_index, uint16_t hash_alg, const uint8_t * in_digest, size_t digest_len) Extend Platform Configuration Register with measurement digest (TPM2_PCR_Extend). |
| SYN_Status | syn_tpm2_pcr_read (SYN_TPM2_Context * ctx, uint32_t pcr_index, uint16_t hash_alg, uint8_t * out_digest, size_t * out_digest_len) Read single Platform Configuration Register (TPM2_PCR_Read). |
| SYN_Status | syn_tpm2_quote (SYN_TPM2_Context * ctx, uint32_t key_handle, const uint8_t * qualifying_data, size_t qual_len, uint32_t pcr_mask, SYN_TPM2_QuoteResult * out_quote) Generate Remote Attestation Quote over PCR values (TPM2_Quote). |
| SYN_Status | syn_tpm2_self_test (SYN_TPM2_Context * ctx, bool full_test) Execute TPM2_SelfTest command. |
| SYN_Status | syn_tpm2_startup (SYN_TPM2_Context * ctx, uint16_t startup_type) Execute TPM2_Startup command. |
Macros¶
| Type | Name |
|---|---|
| define | SYN_TPM2_ALG_NULL 0x0010U |
| define | SYN_TPM2_ALG_SHA256 0x000BU |
| define | SYN_TPM2_ALG_SHA384 0x000CU |
| define | SYN_TPM2_CC_GETRANDOM 0x0000017BU |
| define | SYN_TPM2_CC_NV_READ 0x0000014EU |
| define | SYN_TPM2_CC_NV_WRITE 0x00000137U |
| define | SYN_TPM2_CC_PCR_EXTEND 0x00000182U |
| define | SYN_TPM2_CC_PCR_READ 0x0000017EU |
| define | SYN_TPM2_CC_QUOTE 0x00000158U |
| define | SYN_TPM2_CC_SELFTEST 0x00000143U |
| define | SYN_TPM2_CC_STARTUP 0x00000144U |
| define | SYN_TPM2_MAX_DIGEST_LEN 48U |
| define | SYN_TPM2_MAX_QUOTE_LEN 256U |
| define | SYN_TPM2_RC_SUCCESS 0x00000000U |
| define | SYN_TPM2_RH_OWNER 0x40000001U |
| define | SYN_TPM2_RH_PLATFORM 0x4000000CU |
| define | SYN_TPM2_RS_PW 0x40000009U |
| define | SYN_TPM2_ST_NO_SESSIONS 0x8001U |
| define | SYN_TPM2_ST_SESSIONS 0x8002U |
| define | SYN_TPM2_SU_CLEAR 0x0000U |
| define | SYN_TPM2_SU_STATE 0x0001U |
Detailed Description¶
Implements a zero-heap, deterministic TCG TPM 2.0 command serializer and response parser:
* Direct interface over SPI / I2C / LPC TCG FIFO hardware interface (SYN_Transport).
* Measured Boot PCR Operations (TPM2_PCR_Read, TPM2_PCR_Extend for SHA-256 / SHA-384).
* Hardware Cryptographic Entropy (TPM2_GetRandom).
* Hardware Identity & Remote Attestation Quotes (TPM2_Quote).
* Tamper-Proof Non-Volatile Storage (TPM2_NV_Read, TPM2_NV_Write).
* Power & Self-Test Lifecycle (TPM2_Startup, TPM2_SelfTest).
Public Functions Documentation¶
function syn_tpm2_get_last_rc¶
Get last TPM 2.0 response code returned by TPM hardware.
Parameters:
ctxContext instance.
Returns:
32-bit TPM response code (e.g. TPM_RC_SUCCESS = 0).
function syn_tpm2_get_random¶
Generate cryptographic true random bytes from TPM TRNG (TPM2_GetRandom).
SYN_Status syn_tpm2_get_random (
SYN_TPM2_Context * ctx,
uint16_t num_bytes,
uint8_t * out_random,
uint16_t * out_len
)
Parameters:
ctxContext instance.num_bytesNumber of random bytes requested.out_randomBuffer to receive random bytes.out_lenPointer to receive actual number of bytes returned.
Returns:
SYN_OK on success.
function syn_tpm2_init¶
Initialize TPM 2.0 Context.
Parameters:
ctxContext instance.cfgConfiguration descriptor.
Returns:
SYN_OK on success, SYN_INVALID_PARAM on invalid parameter.
function syn_tpm2_nv_read¶
Read data from secure Non-Volatile storage index (TPM2_NV_Read).
SYN_Status syn_tpm2_nv_read (
SYN_TPM2_Context * ctx,
uint32_t auth_handle,
uint32_t nv_index,
uint16_t offset,
uint16_t size,
uint8_t * out_data,
uint16_t * out_len
)
Parameters:
ctxContext instance.auth_handleAuthorization handle (e.g. SYN_TPM2_RH_OWNER).nv_indexNVRAM index (e.g. 0x01500000).offsetByte offset within NV area.sizeNumber of bytes to read.out_dataOutput buffer.out_lenPointer to receive bytes read.
Returns:
SYN_OK on success.
function syn_tpm2_nv_write¶
Write data to secure Non-Volatile storage index (TPM2_NV_Write).
SYN_Status syn_tpm2_nv_write (
SYN_TPM2_Context * ctx,
uint32_t auth_handle,
uint32_t nv_index,
uint16_t offset,
const uint8_t * in_data,
uint16_t size
)
Parameters:
ctxContext instance.auth_handleAuthorization handle (e.g. SYN_TPM2_RH_OWNER).nv_indexNVRAM index.offsetByte offset within NV area.in_dataData buffer to write.sizeNumber of bytes to write.
Returns:
SYN_OK on success.
function syn_tpm2_pcr_extend¶
Extend Platform Configuration Register with measurement digest (TPM2_PCR_Extend).
SYN_Status syn_tpm2_pcr_extend (
SYN_TPM2_Context * ctx,
uint32_t pcr_index,
uint16_t hash_alg,
const uint8_t * in_digest,
size_t digest_len
)
Parameters:
ctxContext instance.pcr_indexPCR register index (0..23).hash_algHash algorithm (SYN_TPM2_ALG_SHA256 or SYN_TPM2_ALG_SHA384).in_digestDigest bytes to extend PCR with.digest_lenLength of in_digest (must match hash algorithm).
Returns:
SYN_OK on success.
function syn_tpm2_pcr_read¶
Read single Platform Configuration Register (TPM2_PCR_Read).
SYN_Status syn_tpm2_pcr_read (
SYN_TPM2_Context * ctx,
uint32_t pcr_index,
uint16_t hash_alg,
uint8_t * out_digest,
size_t * out_digest_len
)
Parameters:
ctxContext instance.pcr_indexPCR register index (0..23).hash_algHash algorithm bank (SYN_TPM2_ALG_SHA256 or SYN_TPM2_ALG_SHA384).out_digestOutput buffer to receive digest.out_digest_lenPointer to receive digest length (32 for SHA-256, 48 for SHA-384).
Returns:
SYN_OK on success.
function syn_tpm2_quote¶
Generate Remote Attestation Quote over PCR values (TPM2_Quote).
SYN_Status syn_tpm2_quote (
SYN_TPM2_Context * ctx,
uint32_t key_handle,
const uint8_t * qualifying_data,
size_t qual_len,
uint32_t pcr_mask,
SYN_TPM2_QuoteResult * out_quote
)
Parameters:
ctxContext instance.key_handleAttestation signing key handle (e.g. AK / EK).qualifying_dataNonce / qualifying data to prevent replay.qual_lenLength of qualifying data.pcr_mask24-bit bitmask of PCRs to include in quote.out_quotePointer to receive quote structure.
Returns:
SYN_OK on success.
function syn_tpm2_self_test¶
Execute TPM2_SelfTest command.
Parameters:
ctxContext instance.full_testIf true, tests all algorithms; if false, tests incrementally.
Returns:
SYN_OK on success.
function syn_tpm2_startup¶
Execute TPM2_Startup command.
Parameters:
ctxContext instance.startup_typeStartup mode (SYN_TPM2_SU_CLEAR or SYN_TPM2_SU_STATE).
Returns:
SYN_OK on success, SYN_ERROR on TPM failure.
Macro Definition Documentation¶
define SYN_TPM2_ALG_NULL¶
Null algorithm
define SYN_TPM2_ALG_SHA256¶
SHA-256 (32 bytes)
define SYN_TPM2_ALG_SHA384¶
SHA-384 (48 bytes)
define SYN_TPM2_CC_GETRANDOM¶
TPM2_GetRandom
define SYN_TPM2_CC_NV_READ¶
TPM2_NV_Read
define SYN_TPM2_CC_NV_WRITE¶
TPM2_NV_Write
define SYN_TPM2_CC_PCR_EXTEND¶
TPM2_PCR_Extend
define SYN_TPM2_CC_PCR_READ¶
TPM2_PCR_Read
define SYN_TPM2_CC_QUOTE¶
TPM2_Quote
define SYN_TPM2_CC_SELFTEST¶
TPM2_SelfTest
define SYN_TPM2_CC_STARTUP¶
TPM2_Startup
define SYN_TPM2_MAX_DIGEST_LEN¶
Max hash digest length (SHA-384)
define SYN_TPM2_MAX_QUOTE_LEN¶
Max attest quote signature length
define SYN_TPM2_RC_SUCCESS¶
TPM 2.0 Success Return Code
define SYN_TPM2_RH_OWNER¶
Owner hierarchy
define SYN_TPM2_RH_PLATFORM¶
Platform hierarchy
define SYN_TPM2_RS_PW¶
Empty password authorization session
define SYN_TPM2_ST_NO_SESSIONS¶
Command/Response Tag: No session authorization
define SYN_TPM2_ST_SESSIONS¶
Command/Response Tag: With session authorization
define SYN_TPM2_SU_CLEAR¶
Startup clear (cold boot)
define SYN_TPM2_SU_STATE¶
Startup state (warm sleep resume)
The documentation for this class was generated from the following file src/syntropic/crypto/syn_tpm2.h