This page was not yet optimized for use on mobile devices.
Nuvoton NPCT7xx TPM 2.0 Cryptographic Engine
Certificate details
| Certificate ID | #5057 |
|---|---|
| Status | active |
| Validation dates | 15.09.2025 |
| Sunset date | 14-09-2030 |
| Standard | FIPS 140-3 |
| Security level | 1 |
| Type | Hardware |
| Embodiment | Single Chip |
| Caveat | When operated in approved mode; No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs |
| Exceptions |
|
| Description | Nuvoton NPCT7xx TPM 2.0 Cryptographic Engine is a hardware cryptographic module that implements advanced cryptographic algorithms, including symmetric and asymmetric cryptography; as well as key generation and random number generation. |
| Vendor | Nuvoton Technology Corporation http://www.nuvoton.com |
| Lab | atsec information security corporation |
| Algorithms |
|
| References | This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates. |
Security policy
Extracted keywords
Symmetric Algorithms
AES, AES-256, AES-, CAST, HMAC, HMAC-SHA-256, HMAC-SHA-384, CMACAsymmetric Algorithms
ECDH, ECDSA, ECC, DH, Diffie-HellmanHash functions
SHA-1Schemes
MAC, Key AgreementRandomness
DRBG, RNG, RBGElliptic Curves
P-256, P-384Block cipher modes
CTR, OFB, GCM, CCMTrusted Execution Environments
PSP, SSCSecurity level
Level 1, Level 3, level 3, level 1Side-channel analysis
physical tampering, fault injectionAutomated analysis
Automated inference - use with caution
All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.CPE matches
Cross-references
No references are available for this certificate.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate was first processed.
{
"_type": "sec_certs.sample.fips.FIPSCertificate",
"cert_id": 5057,
"dgst": "f06436fba104193e",
"heuristics": {
"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
"algorithms": {
"_type": "Set",
"elements": [
"#A4792",
"RSA SigGen (FIPS186-4)A4792",
"AES-OFBA4792",
"ECDSA SigVer (FIPS186-4)A4792",
"ECDSA KeyVer (FIPS186-4)A4792",
"RSA Signature PrimitiveA4792",
"KTS-IFCA4792",
"KDF SP800-108A4792",
"KAS-ECC-SSC Sp800-56Ar3A4792",
"ECDSA SigGen (FIPS186-4)A4792",
"KDA OneStep Sp800-56Cr1A4792",
"SHA-1A4792",
"KAS-ECC Sp800-56Ar3A4792",
"AES-CTRA4792",
"AES-CFB128A4792",
"HMAC-SHA2-256A4792",
"Conditioning Component Block Cipher Derivation Function SP800-90BA4792",
"RSA SigVer (FIPS186-4)A4792",
"Counter DRBGA4792",
"RSA KeyGen (FIPS186-4)A4792",
"SHA2-256A4792",
"HMAC-SHA2-384A4792",
"SHA2-384A4792",
"HMAC-SHA-1A4792",
"ECDSA KeyGen (FIPS186-4)A4792"
]
},
"cpe_matches": {
"_type": "Set",
"elements": [
"cpe:2.3:h:nuvoton:npct7xx:-:*:*:*:*:*:*:*"
]
},
"direct_transitive_cves": null,
"extracted_versions": {
"_type": "Set",
"elements": [
"2.0"
]
},
"indirect_transitive_cves": null,
"module_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": null,
"indirectly_referenced_by": null,
"indirectly_referencing": null
},
"module_prunned_references": {
"_type": "Set",
"elements": []
},
"policy_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": null,
"indirectly_referenced_by": null,
"indirectly_referencing": null
},
"policy_prunned_references": {
"_type": "Set",
"elements": []
},
"related_cves": null,
"verified_cpe_matches": null
},
"pdf_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
"br1_deviations": 0,
"br1_tables": {
"_type": "sec_certs.heuristics.br1.table_parsing.model.br1_tables.BR1Tables",
"approved_algorithms": {
"entries": [
{
"algorithm": "AES-CFB128",
"cavpCertName": "A4792",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-CTR",
"cavpCertName": "A4792",
"properties": "Direction - Encrypt Key Length - 128, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-OFB",
"cavpCertName": "A4792",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "Conditioning Component Block Cipher Derivation Function SP800-90B",
"cavpCertName": "A4792",
"properties": "Key Length - 256",
"reference": "SP 800-90B"
},
{
"algorithm": "Counter DRBG",
"cavpCertName": "A4792",
"properties": "Prediction Resistance - No Mode - AES-256 Derivation Function Enabled - No",
"reference": "SP 800-90A Rev. 1"
},
{
"algorithm": "ECDSA KeyGen (FIPS186-4)",
"cavpCertName": "A4792",
"properties": "Curve - P-256, P-384",
"reference": "FIPS 186-4"
},
{
"algorithm": "ECDSA KeyVer (FIPS186-4)",
"cavpCertName": "A4792",
"properties": "Curve - P-256, P-384",
"reference": "FIPS 186-4"
},
{
"algorithm": "ECDSA SigGen (FIPS186-4)",
"cavpCertName": "A4792",
"properties": "Component - No, Yes Curve - P-256, P-384 Hash Algorithm - SHA2-256, SHA2-384",
"reference": "FIPS 186-4"
},
{
"algorithm": "ECDSA SigVer (FIPS186-4)",
"cavpCertName": "A4792",
"properties": "Component - No Curve - P-256, P-384",
"reference": "FIPS 186-4"
},
{
"algorithm": "HMAC-SHA-1",
"cavpCertName": "A4792",
"properties": "Key Length - Key Length: 160-240 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2-256",
"cavpCertName": "A4792",
"properties": "Key Length - Key Length: 160-1024 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2-384",
"cavpCertName": "A4792",
"properties": "Key Length - Key Length: 160-2048 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "KAS-ECC Sp800-56Ar3",
"cavpCertName": "A4792",
"properties": "Domain Parameter Generation Methods - P-256, P-384 Function - Key Pair Generation, Partial Validation Scheme - fullUnified - KAS Role - Initiator, Responder Key Length - 1024",
"reference": "SP 800-56A Rev. 3"
},
{
"algorithm": "KAS-ECC-SSC Sp800-56Ar3",
"cavpCertName": "A4792",
"properties": "Domain Parameter Generation Methods - P-256, P-384 Scheme - fullUnified - KAS Role - initiator, responder",
"reference": "SP 800-56A Rev. 3"
},
{
"algorithm": "KDA OneStep Sp800-56Cr1",
"cavpCertName": "A4792",
"properties": "Derived Key Length - 1024 Shared Secret Length - Shared Secret Length: 384-768 Increment 8",
"reference": "SP 800-56C Rev. 2"
},
{
"algorithm": "KDF SP800-108",
"cavpCertName": "A4792",
"properties": "KDF Mode - Counter",
"reference": "SP 800-108 Rev. 1"
},
{
"algorithm": "KTS-IFC",
"cavpCertName": "A4792",
"properties": "Modulo - 2048, 3072, 4096 Key Generation Methods - rsakpg1-crt Scheme - KTS-OAEP-basic - KAS Role - initiator, responder Key Length - 384",
"reference": "SP 800-56B Rev. 2"
},
{
"algorithm": "RSA KeyGen (FIPS186-4)",
"cavpCertName": "A4792",
"properties": "Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Private Key Format - Chinese Remainder Theorem",
"reference": "FIPS 186-4"
},
{
"algorithm": "RSA SigGen (FIPS186-4)",
"cavpCertName": "A4792",
"properties": "Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096",
"reference": "FIPS 186-4"
},
{
"algorithm": "RSA Signature Primitive (CVL)",
"cavpCertName": "A4792",
"properties": "Private Key Format - crt",
"reference": "FIPS 186-4"
},
{
"algorithm": "RSA SigVer (FIPS186-4)",
"cavpCertName": "A4792",
"properties": "Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096",
"reference": "FIPS 186-4"
},
{
"algorithm": "SHA-1",
"cavpCertName": "A4792",
"properties": "-",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-256",
"cavpCertName": "A4792",
"properties": "-",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-384",
"cavpCertName": "A4792",
"properties": "-",
"reference": "FIPS 180-4"
}
],
"found": true,
"section": 2,
"subsection": 5
},
"approved_services": {
"entries": [
{
"description": "Used to initiate a startup process, where the TPM state is either reset or loaded from a saved state.",
"indicator": "\u002700\u0027",
"inputs": "Startup Type",
"name": "TPM2_Startup",
"outputs": "N/A",
"rolesSspAccess": "Unauthentica ted - nullSeed: Z - nullProof: Z - platformAuth: Z - platformPolic",
"secFunImpl": "Entropy Source"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "y: Z - endorsement Policy: Z - ownerPolicy: Z - lockoutPolicy : Z - Asymmetric Signing Keys (authValue): Z - Asymmetric Signing Keys (seed value): Z - Asymmetric Signing Keys (sensitive data): Z - Asymmetric Signing Keys (authPolicy): Z - Asymmetric Signing Keys (public data): Z - Asymmetric Encryption Keys (authValue): Z - Asymmetric Encryption Keys (seedValue): Z - Asymmetric Encryption Keys (sensitive data): Z - Asymmetric Encryption Keys (authPolicy): Z - Asymmetric Encryption Keys (public data): Z - Symmetric",
"secFunImpl": ""
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "Encryption Keys (authValue): Z - Symmetric Encryption Keys (seedValue): Z - Symmetric Encryption Keys (sensitive data): Z - Symmetric Signing Keys (authValue): Z - Symmetric Signing Keys (seedValue): Z - Symmetric Signing Keys (sensitive data): Z - Session (sessionKey): Z - DRBG state: Z - DRBG Entropy Input: G,Z - Transient DRBG state: Z",
"secFunImpl": ""
},
{
"description": "Used to prepare the TPM for a power cycle.",
"indicator": "\u002700\u0027",
"inputs": "Shutdown Type",
"name": "TPM2_Shutdown",
"outputs": "N/A",
"rolesSspAccess": "Unauthentica ted",
"secFunImpl": "None"
},
{
"description": "Perform Self-Test of selected algorithms.",
"indicator": "\u002701\u0027",
"inputs": "List of algorithms to be tested",
"name": "TPM2_IncrementalSelfTe st",
"outputs": "To do list of the selected algorithms All algorithms mentioned in Table 22",
"rolesSspAccess": "Unauthentica ted - Asymmetric Signing Keys (authValue): E - Asymmetric Signing Keys (seed value): E - Asymmetric Signing Keys (sensitive",
"secFunImpl": "AES- CFB128 AES- CTR AES- OFB CTR_D RBG ECDSA KeyGen ECDSA KeyVer ECDSA"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "data): E - Asymmetric Signing Keys (authPolicy): E - Asymmetric Signing Keys (public data): E - Asymmetric Encryption Keys (authValue): E - Asymmetric Encryption Keys (seedValue): E - Asymmetric Encryption Keys (sensitive data): E - Asymmetric Encryption Keys (authPolicy): E - Asymmetric Encryption Keys (public data): E - Symmetric Encryption Keys (authValue): E - Symmetric Encryption Keys (seedValue): E - Symmetric Encryption Keys (sensitive data): E - Symmetric Signing Keys (authValue): E - Symmetric Signing Keys (seedValue):",
"secFunImpl": "SigGen ECDSA SigVer HMAC KAS- ECC KAS- ECC- SSC KDA KBKDF KTS RSA RSA KeyGen RSA SigGen RSA SigGen Primitiv e RSA SigVer SHA"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "E - Symmetric Signing Keys (sensitive data): E",
"secFunImpl": ""
},
{
"description": "Perform Self-Test of all functions or only those that have not previously been tested.",
"indicator": "\u002701\u0027",
"inputs": "Choose whether to perform the test everything (fullTest = YES) or only the untested functions (fullTest = NO)",
"name": "TPM2_SelfTest",
"outputs": "N/A",
"rolesSspAccess": "Unauthentica ted - Asymmetric Signing Keys (authValue): E - Asymmetric Signing Keys (seed value): E - Asymmetric Signing Keys (sensitive data): E - Asymmetric Signing Keys (authPolicy): E - Asymmetric Signing Keys (public data): E - Asymmetric Encryption Keys (authValue): E - Asymmetric Encryption Keys (seedValue): E - Asymmetric Encryption Keys (sensitive data): E - Asymmetric Encryption Keys (authPolicy): E - Asymmetric Encryption Keys (public data): E - Symmetric Encryption Keys",
"secFunImpl": "AES- CFB128 AES- CTR AES- OFB CTR_D RBG ECDSA KeyGen ECDSA KeyVer ECDSA SigGen ECDSA SigVer HMAC KAS- ECC KAS- ECC- SSC KDA KBKDF KTS RSA RSA KeyGen RSA SigGen RSA SigGen Primitiv e RSA SigVer SHA"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "(authValue): E - Symmetric Encryption Keys (seedValue): E - Symmetric Encryption Keys (sensitive data): E - Symmetric Signing Keys (authValue): E - Symmetric Signing Keys (seedValue): E - Symmetric Signing Keys (sensitive data): E",
"secFunImpl": ""
},
{
"description": "Returns manufacturer- specific information regarding the results of a self-test and an indication of the test status.",
"indicator": "\u002700\u0027",
"inputs": "N/A",
"name": "TPM2_GetTestResult",
"outputs": "test result data (manufacturer- specific information), test result",
"rolesSspAccess": "Unauthentica ted",
"secFunImpl": "None"
},
{
"description": "Start authorization session.",
"indicator": "\u002701\u0027",
"inputs": "Session Parameters: session Type, encryption algorithm, key size, hash algorithm",
"name": "TPM2_StartAuthSession",
"outputs": "tpmKey, authValue, nonce size, encrypted salt, session Type, encryption algorithm, key size, hash algorithm",
"rolesSspAccess": "Unauthentica ted - platformAuth: E - Asymmetric Encryption Keys (authValue): E - Asymmetric Encryption Keys (seedValue): E - Asymmetric Encryption Keys (sensitive data): E - Asymmetric Encryption",
"secFunImpl": "CTR_D RBG KAS- ECC KBKDF KTS RSA"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "Keys (authPolicy): E - Asymmetric Encryption Keys (public data): E - Ephemeral Key Agreement Keys: G,E - Session (salt): G,E - Session (sessionKey): G,E - Session (symKey): G,E",
"secFunImpl": ""
},
{
"description": "Allows a policy authorization session to be returned to its initial state.",
"indicator": "\u002700\u0027",
"inputs": "session handle",
"name": "TPM2_PolicyRestart",
"outputs": "N/A",
"rolesSspAccess": "Unauthentica ted - Session (sessionKey): E - Session (symKey): E Object User - Session (sessionKey): E - Session",
"secFunImpl": "None"
},
{
"description": "Creation of an ordinary object.",
"indicator": "\u002701\u0027",
"inputs": "Parent handle, sensitive data, public template, outside info, creationPCR",
"name": "TPM2_Create",
"outputs": "private portion, public portion, creation data, hash value, creation ticket (see TPM2_CertifyC reation)",
"rolesSspAccess": "Object User - Asymmetric Signing Keys (authValue): G - Asymmetric Signing Keys (seed value): G - Asymmetric Signing Keys (sensitive data): G - Asymmetric Signing Keys (authPolicy): G - Asymmetric Signing Keys (public data): G",
"secFunImpl": "CTR_D RBG Entropy Source ECDSA KeyGen HMAC RSA KeyGen SHA KBKDF AES key generati on HMAC key generati on KTS (AES +"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "- Asymmetric Encryption Keys (authValue): G - Asymmetric Encryption Keys (seedValue): G - Asymmetric Encryption Keys (sensitive data): G - Asymmetric Encryption Keys (authPolicy): G - Asymmetric Encryption Keys (public data): G - Symmetric Encryption Keys (authValue): G - Symmetric Encryption Keys (seedValue): G - Symmetric Encryption Keys (sensitive data): G - Symmetric Signing Keys (authValue): G - Symmetric Signing Keys (seedValue): G - Symmetric Signing Keys (sensitive data): G",
"secFunImpl": "HMAC) key unwrap ping KTS (AES + HMAC) key wrappin g"
},
{
"description": "Loading an protected object.",
"indicator": "\u002701\u0027",
"inputs": "Parent handle, private portion, public portion",
"name": "TPM2_Load",
"outputs": "Object handle, name of the loaded object",
"rolesSspAccess": "Object User - Asymmetric Signing Keys (authValue): W - Asymmetric Signing Keys (seed value): W - Asymmetric Signing Keys (sensitive data): W - Asymmetric Signing Keys (authPolicy): W - Asymmetric Signing Keys (public data): W - Asymmetric Encryption Keys (authValue): W - Asymmetric Encryption Keys (seedValue): W - Asymmetric Encryption Keys (sensitive data): W - Asymmetric Encryption Keys (authPolicy): W - Asymmetric Encryption Keys (public data): W - Symmetric Encryption Keys (authValue): W - Symmetric Encryption Keys (seedValue):",
"secFunImpl": "HMAC KAS- ECC- SSC KBKDF SHA KTS (AES + HMAC) key unwrap ping"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "W - Symmetric Encryption Keys (sensitive data): W - Symmetric Signing Keys (authValue): W - Symmetric Signing Keys (seedValue): W - Symmetric Signing Keys (sensitive data): W - Object Ephemeral Keys (symKey): E - Object Ephemeral Keys (hmacKey): E",
"secFunImpl": ""
},
{
"description": "Loading an external object.",
"indicator": "\u002701\u0027",
"inputs": "Private portion, public portion, associated hierarchy",
"name": "TPM2_LoadExternal",
"outputs": "Object handle, name of the loaded object",
"rolesSspAccess": "Unauthentica ted - Asymmetric Signing Keys (authValue): W - Asymmetric Signing Keys (seed value): W - Asymmetric Signing Keys (sensitive data): W - Asymmetric Signing Keys (authPolicy): W - Asymmetric Signing Keys (public data): W - Asymmetric Encryption Keys (authValue): W - Asymmetric",
"secFunImpl": "HMAC KAS- ECC- SSC SHA"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "Encryption Keys (seedValue): W - Asymmetric Encryption Keys (sensitive data): W - Asymmetric Encryption Keys (authPolicy): W - Asymmetric Encryption Keys (public data): W - Symmetric Encryption Keys (authValue): W - Symmetric Encryption Keys (seedValue): W - Symmetric Encryption Keys (sensitive data): W - Symmetric Signing Keys (authValue): W - Symmetric Signing Keys (seedValue): W - Symmetric Signing Keys (sensitive data): W",
"secFunImpl": ""
},
{
"description": "Allows access to the public area of a loaded object.",
"indicator": "\u002700\u0027",
"inputs": "object handle",
"name": "TPM2_ReadPublic",
"outputs": "public area of object, name of object, qualified name of object",
"rolesSspAccess": "Unauthentica ted - Asymmetric Signing Keys (authValue): R - Asymmetric Signing Keys (seed value):",
"secFunImpl": "SHA"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "R - Asymmetric Signing Keys (sensitive data): R - Asymmetric Signing Keys (authPolicy): R - Asymmetric Signing Keys (public data): R - Asymmetric Encryption Keys (authValue): R - Asymmetric Encryption Keys (seedValue): R - Asymmetric Encryption Keys (sensitive data): R - Asymmetric Encryption Keys (authPolicy): R - Asymmetric Encryption Keys (public data): R - Symmetric Encryption Keys (authValue): R - Symmetric Encryption Keys (seedValue): R - Symmetric Encryption Keys (sensitive data): R - Symmetric Signing Keys (authValue):",
"secFunImpl": ""
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "R - Symmetric Signing Keys (seedValue): R - Symmetric Signing Keys (sensitive data): R",
"secFunImpl": ""
},
{
"description": "Decrypts an object credential.",
"indicator": "\u002701\u0027",
"inputs": "active handle, key handle, credential blob, secret",
"name": "TPM2_ActivateCredential",
"outputs": "decrypted certificate information",
"rolesSspAccess": "Object Administrator - Asymmetric Signing Keys (authValue): E - Asymmetric Signing Keys (seed value): E - Asymmetric Signing Keys (sensitive data): E - Asymmetric Signing Keys (authPolicy): E - Asymmetric Signing Keys (public data): E - Credential Ephemeral Keys (symKey): R,E - Credential Ephemeral Keys (hmacKey): R,E - Ephemeral Key Agreement Keys: E Object User - Asymmetric Signing Keys (authValue): E - Asymmetric Signing Keys (seed value): E",
"secFunImpl": "KTS RSA KAS- ECC KBKDF KTS (AES + HMAC) key unwrap ping"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "- Asymmetric Signing Keys (sensitive data): E - Asymmetric Signing Keys (authPolicy): E - Asymmetric Signing Keys (public data): E - Credential Ephemeral Keys (symKey): R,E - Credential Ephemeral Keys (hmacKey): R,E - Ephemeral Key Agreement Keys: E",
"secFunImpl": ""
},
{
"description": "Encrypts object credential.",
"indicator": "\u002701\u0027",
"inputs": "Object handle, credential, object name",
"name": "TPM2_MakeCredential",
"outputs": "encrypted secret, credentialBlob",
"rolesSspAccess": "Unauthentica ted - Asymmetric Signing Keys (authValue): E - Asymmetric Signing Keys (seed value): E - Asymmetric Signing Keys (sensitive data): E - Asymmetric Signing Keys (authPolicy): E - Asymmetric Signing Keys (public data): E - Credential Ephemeral Keys (symKey): R,E - Credential",
"secFunImpl": "CTR_D RBG KTS RSA ECDSA KeyGen KAS- ECC KTS (AES + HMAC) key wrappin g KBKDF"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "Ephemeral Keys (hmacKey): R,E - Ephemeral Key Agreement Keys: E",
"secFunImpl": ""
},
{
"description": "Returns the data in a loaded Sealed Data Object.",
"indicator": "\u002700\u0027",
"inputs": "item handle",
"name": "TPM2_Unseal",
"outputs": "unsealed data",
"rolesSspAccess": "Object User",
"secFunImpl": "None"
},
{
"description": "Change the authorization secret of an object.",
"indicator": "\u002701\u0027",
"inputs": "Object handle, parent handle, new authValue",
"name": "TPM2_ObjectChangeAut h",
"outputs": "private area containing new authValue",
"rolesSspAccess": "Object Administrator - Object Ephemeral Keys (symKey): R,W,E - Object Ephemeral Keys (hmacKey): R,W,E - Asymmetric Signing Keys (authValue): R,W - Asymmetric Signing Keys (seed value): R,W - Asymmetric Signing Keys (sensitive data): R,W - Asymmetric Signing Keys (authPolicy): R,W - Asymmetric Signing Keys (public data): R,W - Asymmetric Encryption Keys (authValue): R,W - Asymmetric Encryption Keys (seedValue): R,W",
"secFunImpl": "CTR_D RBG KBKDF SHA KTS (AES + HMAC) key unwrap ping KTS (AES + HMAC) key wrappin g"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "- Asymmetric Encryption Keys (sensitive data): R,W - Asymmetric Encryption Keys (authPolicy): R,W - Asymmetric Encryption Keys (public data): R,W - Symmetric Encryption Keys (authValue): R,W - Symmetric Encryption Keys (seedValue): R,W - Symmetric Encryption Keys (sensitive data): R,W - Symmetric Signing Keys (authValue): R,W - Symmetric Signing Keys (seedValue): R,W - Symmetric Signing Keys (sensitive data): R,W",
"secFunImpl": ""
},
{
"description": "Creation and loading of an ordinary or a derived object.",
"indicator": "\u002701\u0027",
"inputs": "Parent handle, private portion, public key portion",
"name": "TPM2_CreateLoaded",
"outputs": "Object handle, private portion, public portion, Name of the loaded object",
"rolesSspAccess": "Object User - ppSeed: E - epSeed: E - spSeed: E - nullSeed: E - platformAuth: E - endorsement Auth: E - ownerAuth: E",
"secFunImpl": "CTR_D RBG Entropy Source ECDSA KeyGen HMAC KBKDF RSA KeyGen SHA AES key"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "- Object Ephemeral Keys (symKey): G,W,E - Object Ephemeral Keys (hmacKey): G,W,E - Asymmetric Signing Keys (authValue): G,W - Asymmetric Signing Keys (seed value): G,W - Asymmetric Signing Keys (sensitive data): G,W - Asymmetric Signing Keys (authPolicy): G,W - Asymmetric Signing Keys (public data): G,W - Asymmetric Encryption Keys (authValue): G,W - Asymmetric Encryption Keys (seedValue): G,W - Asymmetric Encryption Keys (sensitive data): G,W - Asymmetric Encryption Keys (authPolicy): G,W - Asymmetric Encryption Keys (public data): G,W - Symmetric",
"secFunImpl": "generati on HMAC key generati on KTS (AES + HMAC) key wrappin g"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "Encryption Keys (authValue): G,W - Symmetric Encryption Keys (seedValue): G,W - Symmetric Encryption Keys (sensitive data): G,W - Symmetric Signing Keys (authValue): G,W - Symmetric Signing Keys (seedValue): G,W - Symmetric Signing Keys (sensitive data): G,W",
"secFunImpl": ""
},
{
"description": "Duplicates a loaded object to a new parent object.",
"indicator": "\u002701\u0027",
"inputs": "Object handle, new parent handle, encryption key, symmetric algorithm for key wrapping",
"name": "TPM2_Duplicate",
"outputs": "Encrypted key, duplicate object, seed value (asymetrically encrypted)",
"rolesSspAccess": "Duplicate - Asymmetric Encryption Keys (authValue): R,E - Asymmetric Encryption Keys (seedValue): R,E - Asymmetric Encryption Keys (sensitive data): R,E - Asymmetric Encryption Keys (authPolicy): R,E - Asymmetric Encryption Keys (public data): R,E - Duplication Ephemeral Keys",
"secFunImpl": "CTR_D RBG ECDSA KeyGen KAS- ECC KBKDF KTS RSA SHA KTS (AES + HMAC) key wrappin g"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "(symKey): E - Duplication Ephemeral Keys (hmacKey): E - Ephemeral Key Agreement Keys: E - Asymmetric Signing Keys (authValue): R - Asymmetric Signing Keys (seed value): R - Asymmetric Signing Keys (sensitive data): R - Asymmetric Signing Keys (authPolicy): R - Asymmetric Signing Keys (public data): R - Symmetric Encryption Keys (authValue): R - Symmetric Encryption Keys (seedValue): R - Symmetric Encryption Keys (sensitive data): R - Symmetric Signing Keys (authValue): R - Symmetric Signing Keys (seedValue): R - Symmetric Signing Keys",
"secFunImpl": ""
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "(sensitive data): R",
"secFunImpl": ""
},
{
"description": "Rewraps a duplicated object with a new parent key.",
"indicator": "\u002701\u0027",
"inputs": "Old parent, new parent, duplicate object, name of object to be wrapped, seed value for the symmetric key and HMAC key",
"name": "TPM2_Rewrap",
"outputs": "New duplicate object, seed for new object (encrypted with new parent\u0027s asymmetric key)",
"rolesSspAccess": "Object User - Duplication Ephemeral Keys (symKey): E - Duplication Ephemeral Keys (hmacKey): E - Ephemeral Key Agreement Keys: E - Asymmetric Signing Keys (authValue): R - Asymmetric Signing Keys (seed value): R - Asymmetric Signing Keys (sensitive data): R - Asymmetric Signing Keys (authPolicy): R - Asymmetric Signing Keys (public data): R - Asymmetric Encryption Keys (authValue): R - Asymmetric Encryption Keys (seedValue): R - Asymmetric Encryption Keys (sensitive data): R - Asymmetric Encryption Keys (authPolicy):",
"secFunImpl": "CTR_D RBG ECDSA KeyGen KAS- ECC KBKDF KTS RSA KTS (AES + HMAC) key unwrap ping KTS (AES + HMAC) key wrappin g"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "R - Asymmetric Encryption Keys (public data): R - Symmetric Encryption Keys (authValue): R - Symmetric Encryption Keys (seedValue): R - Symmetric Encryption Keys (sensitive data): R - Symmetric Signing Keys (authValue): R - Symmetric Signing Keys (seedValue): R - Symmetric Signing Keys (sensitive data): R",
"secFunImpl": ""
},
{
"description": "Import a duplicated object to be next loaded inside the TPM.",
"indicator": "\u002701\u0027",
"inputs": "Parent handle, encryption key, public area of object to be imported, encrypted duplicate object, duplicate object seed, algorithm for key wrapping",
"name": "TPM2_Import",
"outputs": "Private portion encrypted with the symmetric key of parent handle",
"rolesSspAccess": "Object User - Asymmetric Encryption Keys (authValue): R,E - Asymmetric Encryption Keys (seedValue): R,E - Asymmetric Encryption Keys (sensitive data): R,E - Asymmetric Encryption Keys (authPolicy): R,E - Asymmetric",
"secFunImpl": "CTR_D RBG HMAC KAS- ECC KBKDF KTS RSA SHA KTS (AES + HMAC) key unwrap ping"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "Encryption Keys (public data): R,E - Duplication Ephemeral Keys (symKey): E - Duplication Ephemeral Keys (innerSymKe y): E - Ephemeral Key Agreement Keys: E - Asymmetric Signing Keys (authValue): R - Asymmetric Signing Keys (seed value): R - Asymmetric Signing Keys (sensitive data): R - Asymmetric Signing Keys (authPolicy): R - Asymmetric Signing Keys (public data): R - Symmetric Encryption Keys (authValue): R - Symmetric Encryption Keys (seedValue): R - Symmetric Encryption Keys (sensitive data): R - Symmetric Signing Keys (authValue): R",
"secFunImpl": ""
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "- Symmetric Signing Keys (seedValue): R - Symmetric Signing Keys (sensitive data): R",
"secFunImpl": ""
},
{
"description": "RSA Encryption.",
"indicator": "\u002701\u0027",
"inputs": "Key handle, message, padding scheme, label",
"name": "TPM2_RSA_Encrypt",
"outputs": "Cipher text",
"rolesSspAccess": "Unauthentica ted - Asymmetric Encryption Keys (authValue): E - Asymmetric Encryption Keys (seedValue): E - Asymmetric Encryption Keys (sensitive data): E - Asymmetric Encryption Keys (authPolicy): E - Asymmetric Encryption Keys (public data): E",
"secFunImpl": "KTS RSA"
},
{
"description": "RSA Decryption.",
"indicator": "\u002701\u0027",
"inputs": "Key handle, cipher text, scheme, label",
"name": "TPM2_RSA_Decrypt",
"outputs": "Plaintext",
"rolesSspAccess": "Unauthentica ted - Asymmetric Encryption Keys (authValue): E - Asymmetric Encryption Keys (seedValue): E - Asymmetric Encryption Keys (sensitive data): E - Asymmetric Encryption",
"secFunImpl": "KTS RSA"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "Keys (authPolicy): E - Asymmetric Encryption Keys (public data): E",
"secFunImpl": ""
},
{
"description": "Ephemeral key pair generation and Shared Secret Calculation.",
"indicator": "\u002701\u0027",
"inputs": "Key handle",
"name": "TPM2_ECDH_KeyGen",
"outputs": "zPoint, public point",
"rolesSspAccess": "Unauthentica ted - Ephemeral User ECC Keys: G",
"secFunImpl": "ECDSA KeyGen KAS- ECC- SSC"
},
{
"description": "Shared Secret Calculation.",
"indicator": "\u002701\u0027",
"inputs": "Key handle, public point",
"name": "TPM2_ECDH_Zgen",
"outputs": "Output point",
"rolesSspAccess": "Object User - Ephemeral User ECC Keys: G",
"secFunImpl": "KAS- ECC- SSC"
},
{
"description": "Returns the parameters of an ECC curve identified by its TCG-assigned curveID.",
"indicator": "\u002700\u0027",
"inputs": "Curve id",
"name": "TPM2_ECC_Parameters",
"outputs": "ECC parameters for selected curve",
"rolesSspAccess": "Unauthentica ted",
"secFunImpl": "None"
},
{
"description": "Symmetric encryption or decryption of user data.",
"indicator": "\u002701\u0027",
"inputs": "Key handle, encrypt/decr ypt, mode, IV, ciphertext/pla intext",
"name": "TPM2_EncryptDecrypt",
"outputs": "Plaintext/cipher text, IV",
"rolesSspAccess": "Object User - Symmetric Encryption Keys (authValue): E - Symmetric Encryption Keys (seedValue): E - Symmetric Encryption Keys (sensitive data): E",
"secFunImpl": "AES- CFB128 AES- CTR AES- OFB"
},
{
"description": "Symmetric encryption or decryption of user data.",
"indicator": "\u002701\u0027",
"inputs": "Key handle, encrypt/decr ypt, mode, IV, ciphertext/pla intext",
"name": "TPM2_EncryptDecrypt2",
"outputs": "Plaintext/cipher text, IV",
"rolesSspAccess": "Object User - Symmetric Encryption Keys (authValue): E - Symmetric Encryption Keys (seedValue): E - Symmetric",
"secFunImpl": "AES- CFB128 AES- CTR AES- OFB"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "Encryption Keys (sensitive data): E",
"secFunImpl": ""
},
{
"description": "Performs a hash operation on user data.",
"indicator": "\u002701\u0027",
"inputs": "Data, hash algorithm, hierarchy",
"name": "TPM2_Hash",
"outputs": "Digest, validation ticket",
"rolesSspAccess": "Unauthentica ted - Symmetric Signing Keys (authValue): E - Symmetric Signing Keys (seedValue): E - Symmetric Signing Keys (sensitive data): E",
"secFunImpl": "HMAC SHA"
},
{
"description": "Performs a HMAC operation on user data.",
"indicator": "\u002701\u0027",
"inputs": "Key handle, HMAC data, hash algorithm",
"name": "TPM2_HMAC",
"outputs": "Returned HMAC",
"rolesSspAccess": "Object User - Symmetric Signing Keys (authValue): E - Symmetric Signing Keys (seedValue): E - Symmetric Signing Keys (sensitive data): E",
"secFunImpl": "HMAC"
},
{
"description": "Random number generation.",
"indicator": "\u002701\u0027",
"inputs": "Number of bytes requested",
"name": "TPM2_GetRandom",
"outputs": "Random bytes",
"rolesSspAccess": "Unauthentica ted - DRBG state: G,E - DRBG Entropy Input: E - Transient DRBG state: G,E",
"secFunImpl": "CTR_D RBG"
},
{
"description": "Reseed random number generator.",
"indicator": "\u002701\u0027",
"inputs": "Key handle, auth value, hash algorithm",
"name": "TPM2_StirRandom",
"outputs": "Sequence handle",
"rolesSspAccess": "Unauthentica ted - DRBG Entropy Input: G",
"secFunImpl": "CTR_D RBG Entropy Source"
},
{
"description": "HMAC session start",
"indicator": "\u002701\u0027",
"inputs": "Key handle, auth value,",
"name": "TPM2_HMAC_Start",
"outputs": "Sequence handle",
"rolesSspAccess": "Object User - Symmetric Signing Keys",
"secFunImpl": "HMAC"
},
{
"description": "",
"indicator": "",
"inputs": "algorithms to be used",
"name": "",
"outputs": "",
"rolesSspAccess": "(authValue): E - Symmetric Signing Keys (seedValue): E - Symmetric Signing Keys (sensitive data): E",
"secFunImpl": ""
},
{
"description": "Hash session start",
"indicator": "\u002701\u0027",
"inputs": "Auth value, hash algorithm",
"name": "TPM2_HashSequenceSta rt",
"outputs": "Sequence handle",
"rolesSspAccess": "Unauthentica ted - Symmetric Signing Keys (authValue): E - Symmetric Signing Keys (seedValue): E - Symmetric Signing Keys (sensitive",
"secFunImpl": "SHA"
},
{
"description": "Sequence update",
"indicator": "\u002701\u0027",
"inputs": "Sequence handle, data to add to hash",
"name": "TPM2_SequenceUpdate",
"outputs": "N/A",
"rolesSspAccess": "Unauthentica ted - Symmetric Signing Keys (authValue): E - Symmetric Signing Keys (seedValue): E - Symmetric Signing Keys (sensitive data): E",
"secFunImpl": "HMAC SHA"
},
{
"description": "Sequence complete",
"indicator": "\u002701\u0027",
"inputs": "Sequence handle, data, hierarchy",
"name": "TPM2_SequenceComplet e",
"outputs": "Returned HMAC or message digest, ticket",
"rolesSspAccess": "Unauthentica ted - Symmetric Signing Keys (authValue): E - Symmetric Signing Keys (seedValue): E - Symmetric Signing Keys",
"secFunImpl": "HMAC SHA"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "(sensitive data): E",
"secFunImpl": ""
},
{
"description": "Event sequence complete",
"indicator": "\u002701\u0027",
"inputs": "Data",
"name": "TPM2_EventSequenceCo mplete",
"outputs": "List of digests",
"rolesSspAccess": "Object User - Symmetric Signing Keys (authValue): E - Symmetric Signing Keys (seedValue): E - Symmetric Signing Keys (sensitive data): E",
"secFunImpl": "HMAC SHA"
},
{
"description": "Proves the association between an object and its creation data",
"indicator": "\u002701\u0027",
"inputs": "Sign handle, object handle, qualifying data, creation hash, scheme, creation ticket",
"name": "TPM2_CertifyCreation",
"outputs": "Certify info, signature",
"rolesSspAccess": "Object Administrator - shProof: E - Asymmetric Signing Keys (authValue): E - Asymmetric Signing Keys (seed value): E - Asymmetric Signing Keys (sensitive data): E - Asymmetric Signing Keys (authPolicy): E - Asymmetric Signing Keys (public data): E - Symmetric Signing Keys (authValue): E - Symmetric Signing Keys (seedValue): E - Symmetric Signing Keys (sensitive data): E Object User - shProof: E - Asymmetric",
"secFunImpl": "ECDSA SigGen HMAC KBKDF RSA SigGen SHA"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "Signing Keys (authValue): E - Asymmetric Signing Keys (seed value): E - Asymmetric Signing Keys (sensitive data): E - Asymmetric Signing Keys (authPolicy): E - Asymmetric Signing Keys (public data): E - Symmetric Signing Keys (authValue): E - Symmetric Signing Keys (seedValue): E - Symmetric Signing Keys (sensitive",
"secFunImpl": ""
},
{
"description": "Quotes PCR values",
"indicator": "\u002701\u0027",
"inputs": "sign handle, qualifying data, scheme, PCR selection",
"name": "TPM2_Quote",
"outputs": "quoted information, signature",
"rolesSspAccess": "Object User - Asymmetric Signing Keys (authValue): E - Asymmetric Signing Keys (seed value): E - Asymmetric Signing Keys (sensitive data): E - Asymmetric Signing Keys (authPolicy): E - Asymmetric Signing Keys (public data): E - Symmetric Signing Keys",
"secFunImpl": "ECDSA SigGen HMAC KBKDF RSA SigGen SHA"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "(authValue): E - Symmetric Signing Keys (seedValue): E - Symmetric Signing Keys (sensitive data): E",
"secFunImpl": ""
},
{
"description": "Returns a digital signature of the audit session digest",
"indicator": "\u002701\u0027",
"inputs": "Privacy administrator handle, sign handle, session handle, qualifying data, scheme",
"name": "TPM2_GetSessionAuditDi gest",
"outputs": "Audit info, signature",
"rolesSspAccess": "Object User - Asymmetric Signing Keys (authValue): E - Asymmetric Signing Keys (seed value): E - Asymmetric Signing Keys (sensitive data): E - Asymmetric Signing Keys (authPolicy): E - Asymmetric Signing Keys (public data): E - Symmetric Signing Keys (authValue): E - Symmetric Signing Keys (seedValue): E - Symmetric Signing Keys (sensitive data): E - Session (sessionKey): E - Session (symKey): E",
"secFunImpl": "ECDSA SigGen HMAC KBKDF RSA SigGen SHA"
},
{
"description": "Returns the current value of the command audit digest",
"indicator": "\u002701\u0027",
"inputs": "Privacy administrator handle, sign handle, qualifying",
"name": "TPM2_GetCommandAudi tDigest",
"outputs": "Audit info, signature",
"rolesSspAccess": "Object User - Asymmetric Signing Keys (authValue): E",
"secFunImpl": "ECDSA SigGen HMAC KBKDF RSA"
},
{
"description": "",
"indicator": "",
"inputs": "data, scheme",
"name": "",
"outputs": "",
"rolesSspAccess": "- Asymmetric Signing Keys (seed value): E - Asymmetric Signing Keys (sensitive data): E - Asymmetric Signing Keys (authPolicy): E - Asymmetric Signing Keys (public data): E - Symmetric Signing Keys (authValue): E - Symmetric Signing Keys (seedValue): E - Symmetric Signing Keys (sensitive",
"secFunImpl": "SigGen SHA"
},
{
"description": "Returns the current values of Time and Clock",
"indicator": "\u002701\u0027",
"inputs": "Privacy administrator handle, sign handle, qualifying data, scheme",
"name": "TPM2_GetTime",
"outputs": "Time info, signature",
"rolesSspAccess": "Object User - Asymmetric Signing Keys (authValue): E - Asymmetric Signing Keys (seed value): E - Asymmetric Signing Keys (sensitive data): E - Asymmetric Signing Keys (authPolicy): E - Asymmetric Signing Keys (public data): E - Symmetric Signing Keys (authValue): E - Symmetric",
"secFunImpl": "ECDSA SigGen HMAC KBKDF RSA SigGen SHA"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "Signing Keys (seedValue): E - Symmetric Signing Keys (sensitive data): E - shProof: E - endorsement Auth: R",
"secFunImpl": ""
},
{
"description": "Uses loaded keys to validate a signature on a message with the message digest passed to the TPM.",
"indicator": "\u002701\u0027",
"inputs": "Key handle, digest, signature",
"name": "TPM2_VerifySignature",
"outputs": "Validation",
"rolesSspAccess": "Unauthentica ted - Asymmetric Signing Keys (authValue): E - Asymmetric Signing Keys (seed value): E - Asymmetric Signing Keys (sensitive data): E - Asymmetric Signing Keys (authPolicy): E - Asymmetric Signing Keys (public data): E - Symmetric Signing Keys (authValue): E - Symmetric Signing Keys (seedValue): E - Symmetric Signing Keys (sensitive data): E",
"secFunImpl": "HMAC RSA SigVer"
},
{
"description": "Causes the TPM to sign an externally provided hash with the specified symmetric or asymmetric signing key.",
"indicator": "\u002701\u0027",
"inputs": "Key handle, digest, scheme, validation",
"name": "TPM2_Sign",
"outputs": "Signature",
"rolesSspAccess": "Object User - Asymmetric Signing Keys (authValue): E - Asymmetric Signing Keys (seed value):",
"secFunImpl": "HMAC RSA SigGen Primitiv e ECDSA SigGen"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "E - Asymmetric Signing Keys (sensitive data): E - Asymmetric Signing Keys (authPolicy): E - Asymmetric Signing Keys (public data): E - Symmetric Signing Keys (authValue): E - Symmetric Signing Keys (seedValue): E - Symmetric Signing Keys (sensitive data): E",
"secFunImpl": "Compon ent"
},
{
"description": "Used by the Privacy Administrator or platform to change the audit status of a command or to set the hash algorithm used for the audit digest, but not both at the same time.",
"indicator": "\u002700\u0027",
"inputs": "Auth handle, hash algorithm, list of commands to be audited, list of commands to no longer be audited",
"name": "TPM2_SetCommandCod eAuditStatus",
"outputs": "N/A",
"rolesSspAccess": "Object User",
"secFunImpl": "None"
},
{
"description": "Updates the indicated PCR",
"indicator": "\u002701\u0027",
"inputs": "PCR handle, digests",
"name": "TPM2_PCR_Extend",
"outputs": "N/A",
"rolesSspAccess": "Object User",
"secFunImpl": "SHA"
},
{
"description": "Updates the indicated PCR and reports a list of digests",
"indicator": "\u002701\u0027",
"inputs": "PCR handle, event data",
"name": "TPM2_PCR_Event",
"outputs": "Digests",
"rolesSspAccess": "Object User",
"secFunImpl": "SHA"
},
{
"description": "Returns the values of all PCR specified in pcrSelectionIn.",
"indicator": "\u002700\u0027",
"inputs": "PCT section to read",
"name": "TPM2_PCR_Read",
"outputs": "PCR update counter, returned PCR section, PCR values",
"rolesSspAccess": "Unauthentica ted",
"secFunImpl": "None"
},
{
"description": "Used to set the desired PCR",
"indicator": "\u002700\u0027",
"inputs": "Auth handle, PCR",
"name": "TPM2_PCR_Allocate",
"outputs": "Allocation success, max",
"rolesSspAccess": "Object User -",
"secFunImpl": "None"
},
{
"description": "allocation of PCR and algorithms. Requires Platform Authorization.",
"indicator": "",
"inputs": "allocation selection",
"name": "",
"outputs": "number of PCR, size needed, size available",
"rolesSspAccess": "platformAuth: E",
"secFunImpl": ""
},
{
"description": "Used to associate a policy with a PCR or group of PCRs. The policy determines the conditions under which a PCR may be extended or reset.",
"indicator": "\u002700\u0027",
"inputs": "Auth handle, auth policy, hash algorithm",
"name": "TPM2_PCR_SetAuthPolic y",
"outputs": "N/A",
"rolesSspAccess": "Object User - platformAuth: E",
"secFunImpl": "None"
},
{
"description": "Changes the authValue of a PCR or group of PCRs.",
"indicator": "\u002700\u0027",
"inputs": "PCR handle, auth value",
"name": "TPM2_PCR_SetAuthValu e",
"outputs": "N/A",
"rolesSspAccess": "Object User",
"secFunImpl": "None"
},
{
"description": "Used to set the PCR in all banks to zero.",
"indicator": "\u002700\u0027",
"inputs": "PCR handle",
"name": "TPM2_PCR_Reset",
"outputs": "N/A",
"rolesSspAccess": "Object User",
"secFunImpl": "None"
},
{
"description": "Policy based on signing key",
"indicator": "\u002701\u0027",
"inputs": "Signing key handle, policy session handle, TPM nonce, command parameter digest, policy reference, expiration, signed authorization",
"name": "TPM2_PolicySigned",
"outputs": "Timeout, policy ticket",
"rolesSspAccess": "Unauthentica ted - phProof: E - ehProof: E - shProof: E - nullProof: E - Session (sessionKey): E",
"secFunImpl": "ECDSA SigVer HMAC RSA SigVer SHA"
},
{
"description": "Policy based on an entity\u0027s authValue",
"indicator": "\u002701\u0027",
"inputs": "Auth handle, policy session handle, TPM nonce, command parameter digest, policy reference, expiration, signed authorization",
"name": "TPM2_PolicySecret",
"outputs": "Timeout, policy ticket",
"rolesSspAccess": "Object User - phProof: E - ehProof: E - shProof: E - nullProof: E",
"secFunImpl": "HMAC SHA"
},
{
"description": "Policy based on ticket (produced by PolicySigned or PolicySecret)",
"indicator": "\u002701\u0027",
"inputs": "Policy session handle, TPM nonce, command parameter digest, policy",
"name": "TPM2_PolicyTicket",
"outputs": "N/A",
"rolesSspAccess": "Unauthentica ted - phProof: E - ehProof: E - shProof: E - nullProof: E - Session",
"secFunImpl": "HMAC SHA"
},
{
"description": "",
"indicator": "",
"inputs": "reference, auth name, ticket",
"name": "",
"outputs": "",
"rolesSspAccess": "(sessionKey): E",
"secFunImpl": ""
},
{
"description": "Policy enabling multiple authentication options",
"indicator": "\u002701\u0027",
"inputs": "Policy session handle, list of hash values",
"name": "TPM2_PolicyOR",
"outputs": "N/A",
"rolesSspAccess": "Unauthentica ted",
"secFunImpl": "SHA"
},
{
"description": "Policy based on PCR",
"indicator": "\u002701\u0027",
"inputs": "Policy session handle, PCR digest, PCRs to include the digest",
"name": "TPM2_PolicyPCR",
"outputs": "N/A",
"rolesSspAccess": "Unauthentica ted",
"secFunImpl": "SHA"
},
{
"description": "Policy based on Locality",
"indicator": "\u002701\u0027",
"inputs": "Policy session handle, allowed localities for the policy",
"name": "TPM2_PolicyLocality",
"outputs": "N/A",
"rolesSspAccess": "Unauthentica ted",
"secFunImpl": "SHA"
},
{
"description": "Policy based on contents of an NV Index",
"indicator": "\u002701\u0027",
"inputs": "Auth handle, nv index, policy session handle, operand B, offset of NV index for the start of operand A, operation",
"name": "TPM2_PolicyNV",
"outputs": "N/A",
"rolesSspAccess": "Object User",
"secFunImpl": "SHA"
},
{
"description": "Policy based on time",
"indicator": "\u002701\u0027",
"inputs": "Policy session handle, operand B, offset of TPMS_TIME _INFO for operand A, operation",
"name": "TPM2_PolicyCounterTim er",
"outputs": "N/A",
"rolesSspAccess": "Unauthentica ted",
"secFunImpl": "SHA"
},
{
"description": "Policy based on command code",
"indicator": "\u002701\u0027",
"inputs": "Policy session handle, command code",
"name": "TPM2_PolicyCommandC ode",
"outputs": "N/A",
"rolesSspAccess": "Unauthentica ted",
"secFunImpl": "SHA"
},
{
"description": "Policy based on Physical Presence",
"indicator": "\u002701\u0027",
"inputs": "Policy session handle",
"name": "TPM2_PolicyPhysicalPre sence",
"outputs": "N/A",
"rolesSspAccess": "Unauthentica ted",
"secFunImpl": "SHA"
},
{
"description": "Policy bound to specific command with specific parameters and specific objects",
"indicator": "\u002701\u0027",
"inputs": "Policy session handle, cpHash",
"name": "TPM2_PolicyCpHash",
"outputs": "N/A",
"rolesSspAccess": "Unauthentica ted",
"secFunImpl": "SHA"
},
{
"description": "Policy bound to specific objects",
"indicator": "\u002701\u0027",
"inputs": "Policy session handle, digest to be added to the policy",
"name": "TPM2_PolicyNameHash",
"outputs": "N/A",
"rolesSspAccess": "Unauthentica ted",
"secFunImpl": "SHA"
},
{
"description": "Policy limiting duplication to only a selected parent",
"indicator": "\u002701\u0027",
"inputs": "Policy session handle, object name, new parent name, included object name",
"name": "TPM2_PolicyDuplicationS elect",
"outputs": "N/A",
"rolesSspAccess": "Unauthentica ted",
"secFunImpl": "SHA"
},
{
"description": "Policy enabling policy to change",
"indicator": "\u002701\u0027",
"inputs": "Policy Session, digest of policy being approved, signing key, ticket",
"name": "TPM2_PolicyAuthorize",
"outputs": "N/A",
"rolesSspAccess": "Unauthentica ted - Session (sessionKey): E",
"secFunImpl": "HMAC SHA"
},
{
"description": "Policy bound to authValue of authorized entity (requiring HMAC session)",
"indicator": "\u002701\u0027",
"inputs": "Policy session handle",
"name": "TPM2_PolicyAuthValue",
"outputs": "N/A",
"rolesSspAccess": "Unauthentica ted",
"secFunImpl": "SHA"
},
{
"description": "Policy bound to authValue of authorized entity (requiring password session)",
"indicator": "\u002701\u0027",
"inputs": "Policy session handle",
"name": "TPM2_PolicyPassword",
"outputs": "N/A",
"rolesSspAccess": "Unauthentica ted",
"secFunImpl": "SHA"
},
{
"description": "Returns the current policyDigest of the session.",
"indicator": "\u002700\u0027",
"inputs": "Policy session handle",
"name": "TPM2_PolicyGetDigest",
"outputs": "Policy digest",
"rolesSspAccess": "Unauthentica ted",
"secFunImpl": "None"
},
{
"description": "Policy based on WRITTEN attribute of NV Index",
"indicator": "\u002701\u0027",
"inputs": "Policy session handle",
"name": "TPM2_PolicyNvWritten",
"outputs": "Policy digest",
"rolesSspAccess": "Unauthentica ted",
"secFunImpl": "SHA"
},
{
"description": "Policy bound to specific creation template",
"indicator": "\u002701\u0027",
"inputs": "Policy session handle, indication whether NV index is required to be written",
"name": "TPM2_PolicyTemplate",
"outputs": "N/A",
"rolesSspAccess": "Unauthentica ted",
"secFunImpl": "SHA"
},
{
"description": "Policy bound to policy stored in an NV Index",
"indicator": "\u002701\u0027",
"inputs": "Auth handle, nv index, policy session handle",
"name": "TPM2_PolicyAuthorizeNV",
"outputs": "N/A",
"rolesSspAccess": "Object User",
"secFunImpl": "SHA"
},
{
"description": "Creates a Primary Object",
"indicator": "\u002701\u0027",
"inputs": "Primary handle, sensitive data, data to provide verifiable linkage between object and owner data, creation PCR",
"name": "TPM2_CreatePrimary",
"outputs": "Object handle, public portion, creation data, creation hash, creation ticket, name",
"rolesSspAccess": "Object User - ppSeed: E - epSeed: E - spSeed: E - nullSeed: E - platformAuth: E - endorsement Auth: E - ownerAuth: E - Object Ephemeral Keys (symKey): G,W,E - Object Ephemeral Keys (hmacKey): G,W,E - Endorsement Keys (private values): R - Asymmetric Signing Keys (authValue): G,W - Asymmetric Signing Keys (seed value): G,W",
"secFunImpl": "CTR_D RBG Entropy Source ECDSA KeyGen HMAC RSA KeyGen SHA AES key generati on HMAC key generati on"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "- Asymmetric Signing Keys (sensitive data): G,W - Asymmetric Signing Keys (authPolicy): G,W - Asymmetric Signing Keys (public data): G,W - Asymmetric Encryption Keys (authValue): G,W - Asymmetric Encryption Keys (seedValue): G,W - Asymmetric Encryption Keys (sensitive data): G,W - Asymmetric Encryption Keys (authPolicy): G,W - Asymmetric Encryption Keys (public data): G,W - Symmetric Encryption Keys (authValue): G,W - Symmetric Encryption Keys (seedValue): G,W - Symmetric Encryption Keys (sensitive data): G,W - Symmetric Signing Keys (authValue): G,W",
"secFunImpl": ""
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "- Symmetric Signing Keys (seedValue): G,W - Symmetric Signing Keys (sensitive data): G,W",
"secFunImpl": ""
},
{
"description": "Returns the current policyDigest of the session.",
"indicator": "\u002700\u0027",
"inputs": "Auth handle, the enable being modified, state",
"name": "TPM2_HierarchyControl",
"outputs": "N/A",
"rolesSspAccess": "Object User - platformAuth: E - endorsement Auth: E - ownerAuth: E - Asymmetric Signing Keys (authValue): Z - Asymmetric Signing Keys (seed value): Z - Asymmetric Signing Keys (sensitive data): Z - Asymmetric Signing Keys (authPolicy): Z - Asymmetric Signing Keys (public data): Z - Asymmetric Encryption Keys (authValue): Z - Asymmetric Encryption Keys (seedValue): Z - Asymmetric Encryption Keys (sensitive data): Z - Asymmetric Encryption",
"secFunImpl": "None"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "Keys (authPolicy): Z - Asymmetric Encryption Keys (public data): Z - Symmetric Encryption Keys (authValue): Z - Symmetric Encryption Keys (seedValue): Z - Symmetric Encryption Keys (sensitive data): Z - Symmetric Signing Keys (authValue): Z - Symmetric Signing Keys (seedValue): Z - Symmetric Signing Keys (sensitive data): Z",
"secFunImpl": ""
},
{
"description": "Allows setting of the authorization policy for the lockout (lockoutPolicy), the platform hierarchy (platformPolicy), the storage hierarchy (ownerPolicy), and the endorsement hierarchy (endorsementPolicy) .",
"indicator": "\u002700\u0027",
"inputs": "Auth handle, auth policy, hash algorithm",
"name": "TPM2_SetPrimaryPolicy",
"outputs": "N/A",
"rolesSspAccess": "Object User - platformAuth: E - endorsement Auth: E - ownerAuth: E - lockoutAuth: E - platformPolic y: G",
"secFunImpl": "None"
},
{
"description": "Changes the current platform primary seed (PPS)",
"indicator": "\u002701\u0027",
"inputs": "Auth handle",
"name": "TPM2_ChangePPS",
"outputs": "N/A",
"rolesSspAccess": "Object User - platformPolic y: E",
"secFunImpl": "CTR_D RBG"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "- ppSeed: Z - phProof: Z - Asymmetric Signing Keys (authValue): Z - Asymmetric Signing Keys (seed value): Z - Asymmetric Signing Keys (sensitive data): Z - Asymmetric Signing Keys (authPolicy): Z - Asymmetric Signing Keys (public data): Z - Asymmetric Encryption Keys (authValue): Z - Asymmetric Encryption Keys (seedValue): Z - Asymmetric Encryption Keys (sensitive data): Z - Asymmetric Encryption Keys (authPolicy): Z - Asymmetric Encryption Keys (public data): Z - Symmetric Encryption Keys (authValue): Z - Symmetric Encryption Keys (seedValue):",
"secFunImpl": ""
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "Z - Symmetric Encryption Keys (sensitive data): Z - Symmetric Signing Keys (authValue): Z - Symmetric Signing Keys (seedValue): Z - Symmetric Signing Keys (sensitive data): Z",
"secFunImpl": ""
},
{
"description": "Changes the current endorsement primary seed (EPS)",
"indicator": "\u002701\u0027",
"inputs": "Auth handle",
"name": "TPM2_ChangeEPS",
"outputs": "N/A",
"rolesSspAccess": "Object User - platformPolic y: E - epSeed: Z - ehProof: Z - endorsement Auth: Z - Asymmetric Signing Keys (authValue): Z - Asymmetric Signing Keys (seed value): Z - Asymmetric Signing Keys (sensitive data): Z - Asymmetric Signing Keys (authPolicy): Z - Asymmetric Signing Keys (public data): Z - Asymmetric Encryption Keys (authValue): Z - Asymmetric Encryption",
"secFunImpl": "CTR_D RBG"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "Keys (seedValue): Z - Asymmetric Encryption Keys (sensitive data): Z - Asymmetric Encryption Keys (authPolicy): Z - Asymmetric Encryption Keys (public data): Z - Symmetric Encryption Keys (authValue): Z - Symmetric Encryption Keys (seedValue): Z - Symmetric Encryption Keys (sensitive data): Z - Symmetric Signing Keys (authValue): Z - Symmetric Signing Keys (seedValue): Z - Symmetric Signing Keys (sensitive data): Z",
"secFunImpl": ""
},
{
"description": "Zeroizes all TPM context associated with a specific Owner.",
"indicator": "\u002701\u0027",
"inputs": "Auth handle",
"name": "TPM2_Clear",
"outputs": "N/A",
"rolesSspAccess": "Object User - platformAuth: E - lockoutAuth: E,Z - epSeed: Z - spSeed: Z - shProof: Z",
"secFunImpl": "CTR_D RBG"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "endorsement Auth: Z - ownerAuth: Z - endorsement Policy: Z - ownerPolicy: Z - lockoutPolicy : Z - NV Index (authValue): Z - NV Index (authPolicy): Z",
"secFunImpl": ""
},
{
"description": "Disables and enables the execution of TPM2_Clear().",
"indicator": "\u002700\u0027",
"inputs": "Auth handle, disable flag",
"name": "TPM2_ClearControl",
"outputs": "N/A",
"rolesSspAccess": "Object User - platformAuth: E - lockoutAuth: E",
"secFunImpl": "None"
},
{
"description": "Allows the authorization secret for a hierarchy or lockout to be changed using the current authorization value as the command authorization.",
"indicator": "\u002700\u0027",
"inputs": "Auth handle, new auth value",
"name": "TPM2_HierarchyChange Auth",
"outputs": "N/A",
"rolesSspAccess": "Object User - platformAuth: E - endorsement Auth: E - ownerAuth: E - lockoutAuth: E",
"secFunImpl": "None"
},
{
"description": "Cancels the effect of a TPM lockout due to a number of successive authorization failures.",
"indicator": "\u002700\u0027",
"inputs": "Lock handle",
"name": "TPM2_DictionaryAttackLo ckReset",
"outputs": "N/A",
"rolesSspAccess": "Object User - lockoutAuth: E",
"secFunImpl": "None"
},
{
"description": "Changes the lockout parameters.",
"indicator": "\u002700\u0027",
"inputs": "Lock handle, max tries, recovery time before failure count",
"name": "TPM2_DictionaryAttackP arameters",
"outputs": "N/A",
"rolesSspAccess": "Object User - lockoutAuth: E",
"secFunImpl": "None"
},
{
"description": "",
"indicator": "",
"inputs": "increases, lockout recovery time",
"name": "",
"outputs": "",
"rolesSspAccess": "",
"secFunImpl": ""
},
{
"description": "Used to determine which commands require assertion of Physical Presence (PP) in addition to platformAuth/platfor mPolicy.",
"indicator": "\u002700\u0027",
"inputs": "Auth handle, list of commands to be asserted, list of commands to no longer be asserted",
"name": "TPM2_PP_Commands",
"outputs": "N/A",
"rolesSspAccess": "Object User",
"secFunImpl": "None"
},
{
"description": "Save a (object, object sequence or session) context",
"indicator": "\u002701\u0027",
"inputs": "Save handle",
"name": "TPM2_ContextSave",
"outputs": "Context",
"rolesSspAccess": "Unauthentica ted - phProof: E - Context Ephemeral Keys (symKey): E - Context Ephemeral Keys (hmacKey): E - Session (salt): R",
"secFunImpl": "KBKDF KTS (AES + HMAC) key unwrap ping"
},
{
"description": "Reload a context",
"indicator": "\u002701\u0027",
"inputs": "Context",
"name": "TPM2_ContextLoad",
"outputs": "Loaded handle",
"rolesSspAccess": "Unauthentica ted - phProof: E - Context Ephemeral Keys (symKey): E - Context Ephemeral Keys (hmacKey): E - Session (salt): R",
"secFunImpl": "KBKDF KTS (AES + HMAC) key wrappin g"
},
{
"description": "Causes all context associated with a loaded object, sequence object, or session to be removed from TPM memory.",
"indicator": "\u002700\u0027",
"inputs": "Item to flush",
"name": "TPM2_FlushContext",
"outputs": "N/A",
"rolesSspAccess": "Unauthentica ted - Session (sessionKey): Z - Asymmetric Signing Keys (authValue): Z",
"secFunImpl": "None"
},
{
"description": "Allows certain Transient Objects to be made persistent or a persistent object to be evicted.",
"indicator": "\u002700\u0027",
"inputs": "Auth handle, object handle, persistent handle",
"name": "TPM2_EvictControl",
"outputs": "N/A",
"rolesSspAccess": "Object User - platformAuth: E - ownerAuth: E - Asymmetric Signing Keys (authValue): W - Asymmetric Signing Keys (seed value): W - Asymmetric Signing Keys (sensitive data): W - Asymmetric Signing Keys (authPolicy): W - Asymmetric Signing Keys (public data): W - Asymmetric Encryption Keys (authValue): W - Asymmetric Encryption Keys (seedValue): W - Asymmetric Encryption Keys (sensitive data): W - Asymmetric Encryption Keys (authPolicy): W - Asymmetric Encryption Keys (public data): W - Symmetric Encryption Keys (authValue):",
"secFunImpl": "None"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "W - Symmetric Encryption Keys (seedValue): W - Symmetric Encryption Keys (sensitive data): W - Symmetric Signing Keys (authValue): W - Symmetric Signing Keys (seedValue): W - Symmetric Signing Keys (sensitive data): W",
"secFunImpl": ""
},
{
"description": "Reads the current TPMS_TIME_INFO structure that contains the current setting of Time, Clock, resetCount, and restartCount.",
"indicator": "\u002700\u0027",
"inputs": "N/A",
"name": "TPM2_ReadClock",
"outputs": "Current time",
"rolesSspAccess": "Unauthentica ted",
"secFunImpl": "None"
},
{
"description": "Used to advance the value of the TPM\u0027s Clock.",
"indicator": "\u002700\u0027",
"inputs": "Auth handle, New time to set",
"name": "TPM2_ClockSet",
"outputs": "N/A",
"rolesSspAccess": "Object User - platformAuth: E - ownerAuth: E",
"secFunImpl": "None"
},
{
"description": "Adjusts the rate of advance of Clock and Time to provide a better approximation to real time.",
"indicator": "\u002700\u0027",
"inputs": "Auth handle, rate adjustment",
"name": "TPM2_ClockRateAdjust",
"outputs": "N/A",
"rolesSspAccess": "Object User - platformAuth: E - ownerAuth: E",
"secFunImpl": "None"
},
{
"description": "Shows various information regarding the TPM and its current state. This can also be used to return module\u0027s name and",
"indicator": "\u002700\u0027",
"inputs": "Property to be read",
"name": "TPM2_GetCapability (Show status/version)",
"outputs": "Returned information.",
"rolesSspAccess": "Unauthentica ted",
"secFunImpl": "None"
},
{
"description": "versioning information.",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "",
"secFunImpl": ""
},
{
"description": "Used to check to see if specific combinations of algorithm parameters are supported.",
"indicator": "\u002700\u0027",
"inputs": "Parameters",
"name": "TPM2_TestParms",
"outputs": "Success or error",
"rolesSspAccess": "Unauthentica ted",
"secFunImpl": "None"
},
{
"description": "Defines the attributes of an NV Index and causes the TPM to reserve space to hold the data associated with the NV Index.",
"indicator": "\u002700\u0027",
"inputs": "Auth handle, auth value, public parameters of the NV areaauth handle, auth value, public parameters of the NV area",
"name": "TPM2_NV_DefineSpace",
"outputs": "N/A",
"rolesSspAccess": "Object User - platformAuth: E - ownerAuth: E - NV Index (authValue): G - NV Index (authPolicy): G - Endorsement Keys (public values): E",
"secFunImpl": "None"
},
{
"description": "Removes an Index from the TPM.",
"indicator": "\u002700\u0027",
"inputs": "Auth handle, NV index",
"name": "TPM2_NV_UndefineSpac e",
"outputs": "N/A",
"rolesSspAccess": "Object User - platformAuth: E - ownerAuth: E - NV Index (authValue): Z - NV Index (authPolicy): Z",
"secFunImpl": "None"
},
{
"description": "Allows removal of a platform-created NV Index that has TPMA_NV_POLICY _DELETE SET .",
"indicator": "\u002700\u0027",
"inputs": "NV index, platform",
"name": "TPM2_NV_UndefineSpac eSpecial",
"outputs": "N/A",
"rolesSspAccess": "Object Administrator - platformAuth: E - ownerAuth: E - NV Index (authValue): Z - NV Index (authPolicy): Z Object User",
"secFunImpl": "None"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "- platformAuth: E - ownerAuth: E - NV Index (authValue): Z - NV Index (authPolicy): Z",
"secFunImpl": ""
},
{
"description": "Read public area and name of an NV Index",
"indicator": "\u002701\u0027",
"inputs": "NV index",
"name": "TPM2_NV_ReadPublic",
"outputs": "NV public area, NV name",
"rolesSspAccess": "Unauthentica ted",
"secFunImpl": "SHA"
},
{
"description": "Writes a value to an area in NV memory that was previously defined by TPM2_NV_DefineSp ace().",
"indicator": "\u002700\u0027",
"inputs": "Auth handle, nv index, data to write, offset",
"name": "TPM2_NV_Write",
"outputs": "N/A",
"rolesSspAccess": "Object User",
"secFunImpl": "None"
},
{
"description": "Used to increment the value in an NV Index that has the TPM_NT_COUNTE R attribute. The data value of the NV Index is incremented by one.",
"indicator": "\u002700\u0027",
"inputs": "auth handle, NV index",
"name": "TPM2_NV_Increment",
"outputs": "N/A",
"rolesSspAccess": "Object User",
"secFunImpl": "None"
},
{
"description": "Extend data to an NV Index",
"indicator": "\u002701\u0027",
"inputs": "auth handle, nv index, data",
"name": "TPM2_NV_Extend",
"outputs": "N/A",
"rolesSspAccess": "Object User",
"secFunImpl": "SHA"
},
{
"description": "Used to SET bits in an NV Index that was created as a bit field.",
"indicator": "\u002700\u0027",
"inputs": "auth handle, NV index, bits",
"name": "TPM2_NV_SetBits",
"outputs": "N/A",
"rolesSspAccess": "Object User",
"secFunImpl": "None"
},
{
"description": "If the TPMA_NV_WRITED EFINE or TPMA_NV_WRITE_ STCLEAR attributes of an NV location are SET, then this service may be used to inhibit further writes of the NV Index.",
"indicator": "\u002700\u0027",
"inputs": "Auth handle, nv index",
"name": "TPM2_NV_WriteLock",
"outputs": "N/A",
"rolesSspAccess": "Object User",
"secFunImpl": "None"
},
{
"description": "Will SET TPMA_NV_WRITEL OCKED for all indexes that have their TPMA_NV_GLOBAL LOCK attribute SET.",
"indicator": "\u002700\u0027",
"inputs": "Auth handle",
"name": "TPM2_NV_GlobalWriteLo ck",
"outputs": "N/A",
"rolesSspAccess": "Object User - platformAuth: E - ownerAuth: E",
"secFunImpl": "None"
},
{
"description": "Reads a value from an area in NV memory previously defined by TPM2_NV_DefineSp ace().",
"indicator": "\u002700\u0027",
"inputs": "Auth handle, nv index, number of octets to read, offset",
"name": "TPM2_NV_Read",
"outputs": "Data",
"rolesSspAccess": "Object User",
"secFunImpl": "None"
},
{
"description": "If TPMA_NV_READ_S TCLEAR is SET in an Index, then this service may be used to prevent further reads of the NV Index until the next TPM2_Startup (TPM_SU_CLEAR).",
"indicator": "\u002700\u0027",
"inputs": "Auth handle, nv index",
"name": "TPM2_NV_ReadLock",
"outputs": "N/A",
"rolesSspAccess": "Object User",
"secFunImpl": "None"
},
{
"description": "Allows the authorization secret for an NV Index to be changed.",
"indicator": "\u002700\u0027",
"inputs": "NV index, new auth value",
"name": "TPM2_NV_ChangeAuth",
"outputs": "N/A",
"rolesSspAccess": "Object Administrator - NV Index (authValue): W - NV Index (authPolicy): W",
"secFunImpl": "None"
},
{
"description": "Certify contents of an NV Index.",
"indicator": "\u002701\u0027",
"inputs": "Qualifying data, scheme, size, offset",
"name": "TPM2_NV_Certify",
"outputs": "Certify info, signature",
"rolesSspAccess": "Object User - Asymmetric Signing Keys (authValue): E - Asymmetric Signing Keys (seed value): E - Asymmetric Signing Keys (sensitive data): E - Asymmetric Signing Keys (authPolicy): E - Asymmetric Signing Keys",
"secFunImpl": "ECDSA SigGen HMAC RSA SigGen SHA"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "(public data): E - Symmetric Signing Keys (authValue): E - Symmetric Signing Keys (seedValue): E - Symmetric Signing Keys (sensitive data): E",
"secFunImpl": ""
},
{
"description": "Used to set the time remaining before an Authenticated Countdown Timer (ACT) expires.",
"indicator": "\u002700\u0027",
"inputs": "Act handle, start timeout value",
"name": "TPM2_ACT_SetTimeout",
"outputs": "N/A",
"rolesSspAccess": "Object User",
"secFunImpl": "None"
},
{
"description": "Used to verify arguments and protect the input firmware payload",
"indicator": "\u002701\u0027",
"inputs": "Firmware payload",
"name": "NTC_FIELD_UPGRADE",
"outputs": "N/A",
"rolesSspAccess": "Object Administrator - Firmware Update Keys (ECC): E - Firmware Update Keys (AES): E",
"secFunImpl": "AES- CTR ECDSA SigVer"
}
],
"found": true,
"section": 4,
"subsection": 3
},
"authentication_methods": {
"entries": [],
"found": false,
"section": 4,
"subsection": 1
},
"cond_self_tests": {
"entries": [
{
"algorithmOrTest": "Counter DRBG (A4792)",
"condition": "Upon first invocation of service that uses the algorithm.",
"details": "Random Number Generation",
"indicator": "Successful boot",
"testMethod": "KAT",
"testProps": "256-bit key",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA2-384 (A4792)",
"condition": "Upon first invocation of service that uses the algorithm.",
"details": "Verify",
"indicator": "Successful boot",
"testMethod": "KAT",
"testProps": "384 bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "KDF SP800- 108 (A4792)",
"condition": "Upon first invocation of service that uses the algorithm.",
"details": "Key Derivation",
"indicator": "Successful boot",
"testMethod": "KAT",
"testProps": "SHA2-256",
"type": "CAST"
},
{
"algorithmOrTest": "KDA OneStep Sp800-56Cr1 (A4792)",
"condition": "Upon first invocation of service that uses the algorithm.",
"details": "Key Derivation",
"indicator": "Successful boot",
"testMethod": "KAT",
"testProps": "SHA2-256",
"type": "CAST"
},
{
"algorithmOrTest": "SHA-1 (A4792)",
"condition": "Upon first invocation of service that uses the algorithm.",
"details": "Message Digest",
"indicator": "Successful boot",
"testMethod": "KAT",
"testProps": "SHA-1",
"type": "CAST"
},
{
"algorithmOrTest": "SHA2-256 (A4792)",
"condition": "Upon first invocation of service that",
"details": "Message Digest",
"indicator": "Successful boot",
"testMethod": "KAT",
"testProps": "SHA2-256",
"type": "CAST"
},
{
"algorithmOrTest": "",
"condition": "uses the algorithm.",
"details": "",
"indicator": "",
"testMethod": "",
"testProps": "",
"type": ""
},
{
"algorithmOrTest": "SHA2-384 (A4792)",
"condition": "Upon first invocation of service that uses the algorithm.",
"details": "Message Digest",
"indicator": "Successful boot",
"testMethod": "KAT",
"testProps": "SHA2-384",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CFB128 (A4792)",
"condition": "Upon first invocation of service that uses the algorithm.",
"details": "Encryption / Decryption",
"indicator": "Successful boot",
"testMethod": "KAT",
"testProps": "128, 256 bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CTR (A4792)",
"condition": "Upon first invocation of service that uses the algorithm.",
"details": "Encryption / Decryption",
"indicator": "Successful boot",
"testMethod": "KAT",
"testProps": "128, 256 bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-OFB (A4792)",
"condition": "Upon first invocation of service that uses the algorithm.",
"details": "Encryption / Decryption",
"indicator": "Successful boot",
"testMethod": "KAT",
"testProps": "128, 256 bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "RSA SigGen (FIPS186-4) (A4792)",
"condition": "Upon first invocation of service that uses the algorithm.",
"details": "Signature Generation",
"indicator": "Successful boot",
"testMethod": "KAT",
"testProps": "2048-bit modulus; Hash: SHA2- 256",
"type": "CAST"
},
{
"algorithmOrTest": "RSA SigVer (FIPS186-4) (A4792)",
"condition": "Upon first invocation of service that uses the algorithm.",
"details": "Signature Verification",
"indicator": "Successful boot",
"testMethod": "KAT",
"testProps": "2048-bit modulus; Hash: SHA2- 256",
"type": "CAST"
},
{
"algorithmOrTest": "ECDSA SigGen (FIPS186-4) (A4792)",
"condition": "Upon first invocation of service that uses the algorithm.",
"details": "Signature Generation",
"indicator": "Successful boot",
"testMethod": "KAT",
"testProps": "Curve: P- 256; Hash: SHA2-256",
"type": "CAST"
},
{
"algorithmOrTest": "ECDSA SigVer (FIPS186-4) (A4792)",
"condition": "Upon first invocation of service that uses the algorithm.",
"details": "Signature Verification",
"indicator": "Successful boot",
"testMethod": "KAT",
"testProps": "Curve: P- 256; Hash: SHA2-256",
"type": "CAST"
},
{
"algorithmOrTest": "KAS-ECC Sp800-56Ar3 (A4792)",
"condition": "Upon first invocation of service that",
"details": "Shared Secret Computation",
"indicator": "Successful boot",
"testMethod": "KAT",
"testProps": "Curve: P-256",
"type": "CAST"
},
{
"algorithmOrTest": "",
"condition": "uses the algorithm.",
"details": "",
"indicator": "",
"testMethod": "",
"testProps": "",
"type": ""
},
{
"algorithmOrTest": "KTS-IFC (A4792)",
"condition": "Upon first invocation of service that uses the algorithm.",
"details": "RSA Key Transport",
"indicator": "Successful boot",
"testMethod": "KAT",
"testProps": "2048-bit modulus",
"type": "CAST"
},
{
"algorithmOrTest": "ECDSA KeyGen (FIPS186-4) (A4792)",
"condition": "Performed every time ECC key pair is generated",
"details": "Signature Generation / Signature Verification",
"indicator": "Key pair returned to caller",
"testMethod": "PCT",
"testProps": "P-256, P-384 curves",
"type": "PCT"
},
{
"algorithmOrTest": "RSA KeyGen (FIPS186-4) (A4792)",
"condition": "Performed every time RSA key pair is generated",
"details": "Encryption / Decryption tested for RSA key pairs generated for approved key transport and Signature Generation / Signature Verification tested for RSA key pairs generated for digital signatures",
"indicator": "Key pair returned to caller",
"testMethod": "PCT",
"testProps": "2048, 3072, 4096 bit keys",
"type": "PCT"
},
{
"algorithmOrTest": "ECDSA SigVer (SW/FW Load Test)",
"condition": "Firmware Update",
"details": "Firmware update test during the firmware update. The digital signature is verified on the firmware image using an ECDSA signature verification algorithm, utilizing a 384-bit",
"indicator": "Successful Firmware load",
"testMethod": "SW/FW Load Test",
"testProps": "P-384 Curves",
"type": "SW/FW Load"
}
],
"found": true,
"section": 10,
"subsection": 2
},
"error_states": {
"entries": [
{
"conditions": "Endorsement Key creation failure, Internal NV inconsistency Fingerprint value in TPM2_ContextLoad doesn\u0027t",
"description": "General Failure",
"indicator": "returns TPM_RC_FAILURE",
"name": "General Failure",
"recoveryMethod": "Platform Reset or power cycle"
},
{
"conditions": "match Post-field upgrade problem",
"description": "",
"indicator": "",
"name": "",
"recoveryMethod": ""
},
{
"conditions": "Internal integrity error - indicative of fault injection attack or internal functional fault",
"description": "Failure in conditional CAST, Conditional PCT or FW Integrity Test failure",
"indicator": "returns SELF_TEST_FAILURE",
"name": "Self-Test Failure",
"recoveryMethod": "Power cycle"
}
],
"found": true,
"section": 10,
"subsection": 4
},
"mechanisms_actions": {
"entries": [
{
"inspectFreq": "Determined by the operator",
"inspectGuidance": "Observe the coating surrounding the chip for any signs of damage",
"mechanism": "Hard tamper-evident coating"
}
],
"found": true,
"section": 7,
"subsection": 1
},
"modes_of_operation": {
"entries": [
{
"description": "Default mode entered when the TPM powers up and has completed self tests for SHS (SHA-1, SHA2-256, SHA2-384), HMAC, AES, DRBG, KBKDF and KDF algorithms which are used for basic TPM commands.",
"name": "Transient mode",
"statusIndicator": "Same as section 4.3",
"type": "Approved"
},
{
"description": "This mode can be entered by either forcing to run the self tests for all algorithms using \u0027TPM2_SelfTest\u0027 command or by explicitly calling service that will require use of algorithms not tested in transient mode. This corresponds to all commands except the ones listed in section 6.5.1.6, of platform TPM profile specification and the command \u0027TPM2_IncrementalSelfTest\u0027.",
"name": "Full approved mode of operation",
"statusIndicator": "Same as section 4.3",
"type": "Approved"
},
{
"description": "Automatically entered whenever a non-approved service is invoked.",
"name": "Non- Approved mode of operation",
"statusIndicator": "Same as section 4.3",
"type": "Non- Approved"
}
],
"found": true,
"section": 2,
"subsection": 4
},
"non_approved_allowed_NSC": {
"entries": [
{
"caveat": "Allowed as per IG 2.4.A",
"name": "ECDSA SigVer Component",
"use": "Non-Security Related Input Verification (No authentication claimed)"
}
],
"found": true,
"section": 2,
"subsection": 5
},
"non_approved_allowed_algos": {
"entries": [],
"found": false,
"section": 2,
"subsection": 5
},
"non_approved_not_allowed": {
"entries": [
{
"name": "RSA signature generation using SHA-1",
"use": "Digital signature generation"
},
{
"name": "ECDSA signature generation using SHA-1",
"use": "Digital signature generation"
},
{
"name": "RSA Key Transport",
"use": "RSA Key Transport with Non-Approved Padding schemes RSAES-PKCS- v1.5/NULL"
},
{
"name": "CKG",
"use": "HMAC key generation with Key Size \u003c 112 bits"
},
{
"name": "HMAC",
"use": "Message Authentication Code using HMAC with Key Size \u003c 112 bits"
},
{
"name": "KAS-ECC-SSC",
"use": "ECC Shared Secret Calculation with Derived Asymmetric ECC Key"
}
],
"found": true,
"section": 2,
"subsection": 5
},
"non_approved_services": {
"entries": [
{
"alg_accessed": "CKG",
"description": "Creation of an ordinary object",
"name": "TPM2_Create",
"role": "Object User"
},
{
"alg_accessed": "KAS-ECC-SSC",
"description": "Loading an protected object",
"name": "TPM2_Load",
"role": "Object User"
},
{
"alg_accessed": "KAS-ECC-SSC",
"description": "Loading an external object",
"name": "TPM2_LoadExternal",
"role": "None"
},
{
"alg_accessed": "CKG",
"description": "Creation and loading of an ordinary or a derived object",
"name": "TPM2_CreateLoaded",
"role": "Object User"
},
{
"alg_accessed": "RSA Key Transport",
"description": "RSA Encryption",
"name": "TPM2_RSA_Encrypt",
"role": "None"
},
{
"alg_accessed": "RSA Key Transport",
"description": "RSA Decryption",
"name": "TPM2_RSA_Decrypt",
"role": "Object User"
},
{
"alg_accessed": "KAS-ECC-SSC",
"description": "Shared Secret Calculation with TPM static key and provided public key (1e,1s)",
"name": "TPM2_ECDH_ZGen",
"role": "Object User"
},
{
"alg_accessed": "KAS-ECC-SSC",
"description": "Ephemeral key pair derivation and Shared Secret Calculation with TPM ephemeral and static key and provided ephemeral and static key (2e,2s)",
"name": "TPM2_ZGen_2Phase",
"role": "Object User"
},
{
"alg_accessed": "HMAC",
"description": "Performs a HMAC operation on user data",
"name": "TPM2_HMAC",
"role": "Object User"
},
{
"alg_accessed": "HMAC",
"description": "HMAC session start",
"name": "TPM2_HMAC_Start",
"role": "Object User"
},
{
"alg_accessed": "HMAC",
"description": "Sequence update",
"name": "TPM2_SequenceUpdate",
"role": "Object User"
},
{
"alg_accessed": "HMAC",
"description": "Sequence complete",
"name": "TPM2_SequenceComplete",
"role": "Object User"
},
{
"alg_accessed": "HMAC",
"description": "Event sequence complete",
"name": "TPM2_EventSequenceComplete",
"role": "Object User"
},
{
"alg_accessed": "RSA signature generation using SHA-1 ECDSA signature generation using SHA-1 HMAC",
"description": "Proves that an object with a specific Name is loaded in the TPM",
"name": "TPM2_Certify",
"role": "Object Administrator, Object User"
},
{
"alg_accessed": "RSA signature generation using SHA-1 ECDSA signature generation using SHA-1 HMAC",
"description": "Proves the association between an object and its creation data",
"name": "TPM2_CertifyCreation",
"role": "Object Administrator, Object User"
},
{
"alg_accessed": "RSA signature generation using SHA-1 ECDSA signature generation using SHA-1 HMAC",
"description": "Quotes PCR values",
"name": "TPM2_Quote",
"role": "Object User"
},
{
"alg_accessed": "RSA signature generation using SHA-1 ECDSA signature generation using SHA-1 HMAC",
"description": "Returns a digital signature of the audit session digest",
"name": "TPM2_GetSessionAuditDigest",
"role": "Object User"
},
{
"alg_accessed": "RSA signature generation using SHA-1 ECDSA signature generation using",
"description": "Returns the current value of the command audit digest",
"name": "TPM2_GetCommandAuditDigest",
"role": "Object User"
},
{
"alg_accessed": "SHA-1 HMAC",
"description": "",
"name": "",
"role": ""
},
{
"alg_accessed": "RSA signature generation using SHA-1 ECDSA signature generation using SHA-1 HMAC",
"description": "Returns the current values of Time and Clock",
"name": "TPM2_GetTime",
"role": "Object User"
},
{
"alg_accessed": "KAS-ECC-SSC",
"description": "Ephemeral key pair derivation",
"name": "TPM2_EC_Ephemeral",
"role": "None"
},
{
"alg_accessed": "HMAC",
"description": "Uses loaded keys to validate a signature on a message with the message digest passed to the TPM.",
"name": "TPM2_VerifySignature",
"role": "None"
},
{
"alg_accessed": "RSA signature generation using SHA-1 ECDSA signature generation using SHA-1",
"description": "Causes the TPM to sign an externally provided hash with the specified symmetric or asymmetric signing key.",
"name": "TPM2_Sign",
"role": "Object User"
},
{
"alg_accessed": "HMAC",
"description": "Policy based on signing key",
"name": "TPM2_PolicySigned",
"role": "None"
},
{
"alg_accessed": "HMAC",
"description": "Policy based on an entity\u0027s authValue",
"name": "TPM2_PolicySecret",
"role": "Object User"
},
{
"alg_accessed": "HMAC",
"description": "Policy based on ticket (produced by PolicySigned or PolicySecret)",
"name": "TPM2_PolicyTicket",
"role": "None"
},
{
"alg_accessed": "HMAC",
"description": "Policy enabling policy to change",
"name": "TPM2_PolicyAuthorize",
"role": "None"
},
{
"alg_accessed": "CKG",
"description": "Creates a Primary Object",
"name": "TPM2_CreatePrimary",
"role": "Object User"
},
{
"alg_accessed": "RSA signature generation using SHA-1 ECDSA signature generation using SHA-1",
"description": "Certify contents of an NV Index",
"name": "TPM2_NV_Certify",
"role": "Object User"
}
],
"found": true,
"section": 4,
"subsection": 4
},
"ports_interfaces": {
"entries": [
{
"data": "Data provided to the chip as part of the data processing commands; Data output by the chip a part of the data processing commands; Control Input commands issued to the chip; Status data output by the chip",
"logicalInterface": "Data Input Data Output Control Input Status Output",
"physicalPort": "SPI Bus"
},
{
"data": "Data provided to the chip as part of the data processing commands; Data output by the chip a part of the data processing commands; Control Input commands issued to the chip; Status data output by the chip",
"logicalInterface": "Data Input Data Output Control Input Control Output",
"physicalPort": "I2C Bus"
},
{
"data": "Data provided to the chip as part of the data processing commands; Control Input commands issued to the chip",
"logicalInterface": "Data Input Control Input",
"physicalPort": "PP pin"
},
{
"data": "Power interface of the chip",
"logicalInterface": "Power",
"physicalPort": "Power"
}
],
"found": true,
"section": 3,
"subsection": 1
},
"roles": {
"entries": [
{
"authMethodList": "None",
"name": "Object Administrator",
"operatorType": "Crypto Officer",
"type": "Role"
},
{
"authMethodList": "None",
"name": "Object User",
"operatorType": "User",
"type": "Role"
},
{
"authMethodList": "None",
"name": "Duplicate",
"operatorType": "Crypto Officer",
"type": "Role"
}
],
"found": true,
"section": 4,
"subsection": 2
},
"security_levels": {
"entries": [
{
"level": "1",
"section": "1",
"title": "General"
},
{
"level": "1",
"section": "2",
"title": "Cryptographic module specification"
},
{
"level": "1",
"section": "3",
"title": "Cryptographic module interfaces"
},
{
"level": "1",
"section": "4",
"title": "Roles, services, and authentication"
},
{
"level": "1",
"section": "5",
"title": "Software/Firmware security"
},
{
"level": "N/A",
"section": "6",
"title": "Operational environment"
},
{
"level": "3",
"section": "7",
"title": "Physical security"
},
{
"level": "N/A",
"section": "8",
"title": "Non-invasive security"
},
{
"level": "1",
"section": "9",
"title": "Sensitive security parameter management"
},
{
"level": "1",
"section": "10",
"title": "Self-tests"
},
{
"level": "1",
"section": "11",
"title": "Life-cycle assurance"
},
{
"level": "N/A",
"section": "12",
"title": "Mitigation of other attacks"
},
{
"level": "1",
"section": "",
"title": "Overall Level"
}
],
"found": true,
"section": 1,
"subsection": 2
},
"self_tests": {
"entries": [
{
"algorithmOrTest": "HMAC-SHA2-256 (A4792)",
"details": "Performed on system startup",
"indicator": "Successful boot",
"testMethod": "Message Authentication Code (MAC)",
"testProps": "HMAC-SHA2- 256",
"type": "SW/FW Integrity"
}
],
"found": true,
"section": 10,
"subsection": 1
},
"ssp_io_methods": {
"entries": [
{
"dest": "RAM",
"distribution": "Automated",
"entry": "Electronic",
"format": "Encrypted",
"name": "TPM2_Load",
"sfiAlgo": "KTS (AES + HMAC) key unwrapping",
"source": "Entity using the module"
},
{
"dest": "RAM",
"distribution": "Automated",
"entry": "Electronic",
"format": "Encrypted",
"name": "TPM2_EvictControl",
"sfiAlgo": "KTS (AES + HMAC) key unwrapping",
"source": "Entity using the module"
},
{
"dest": "RAM",
"distribution": "Automated",
"entry": "Electronic",
"format": "Encrypted",
"name": "TPM2_Import",
"sfiAlgo": "KTS (AES + HMAC) key unwrapping",
"source": "Entity using the module"
},
{
"dest": "RAM",
"distribution": "Automated",
"entry": "Electronic",
"format": "Encrypted",
"name": "TPM2_Create (Import)",
"sfiAlgo": "KTS (AES + HMAC) key unwrapping",
"source": "Entity using the module"
},
{
"dest": "Entity using the module",
"distribution": "Automated",
"entry": "Electronic",
"format": "Encrypted",
"name": "TPM2_Create (Export)",
"sfiAlgo": "KTS (AES + HMAC) key wrapping",
"source": "RAM"
},
{
"dest": "RAM",
"distribution": "Automated",
"entry": "Electronic",
"format": "Encrypted",
"name": "TPM2_CreatePrimary (Import)",
"sfiAlgo": "KTS (AES + HMAC) key unwrapping",
"source": "Entity using the module"
},
{
"dest": "Entity using the module",
"distribution": "Automated",
"entry": "Electronic",
"format": "Encrypted",
"name": "TPM2_CreatePrimary (Export)",
"sfiAlgo": "KTS (AES + HMAC) key wrapping",
"source": "RAM"
},
{
"dest": "Entity using the module",
"distribution": "Automated",
"entry": "Electronic",
"format": "Encrypted",
"name": "TPM2_CreateLoaded",
"sfiAlgo": "KTS (AES + HMAC) key wrapping",
"source": "RAM"
},
{
"dest": "Entity using the module",
"distribution": "Automated",
"entry": "Electronic",
"format": "Encrypted",
"name": "TPM2_ContextLoad",
"sfiAlgo": "KTS (AES + HMAC) key wrapping",
"source": "RAM"
},
{
"dest": "RAM",
"distribution": "Automated",
"entry": "Electronic",
"format": "Encrypted",
"name": "TPM2_ContextSave",
"sfiAlgo": "KTS (AES + HMAC) key unwrapping",
"source": "Entity using the module"
},
{
"dest": "Entity using the module",
"distribution": "Automated",
"entry": "Electronic",
"format": "Encrypted",
"name": "TPM2_ReadPublic",
"sfiAlgo": "KTS (AES + HMAC) key wrapping",
"source": "RAM"
},
{
"dest": "RAM",
"distribution": "Automated",
"entry": "Electronic",
"format": "Encrypted",
"name": "TPM2_ObjectChangeAuth (Import)",
"sfiAlgo": "KTS (AES + HMAC) key unwrapping",
"source": "Entity using the module"
},
{
"dest": "Entity using the module",
"distribution": "Automated",
"entry": "Electronic",
"format": "Encrypted",
"name": "TPM2_ObjectChangeAuth (Export)",
"sfiAlgo": "KTS (AES + HMAC) key wrapping",
"source": "RAM"
},
{
"dest": "RAM",
"distribution": "Automated",
"entry": "Electronic",
"format": "Encrypted",
"name": "TPM2_NV_ChangeAuth (Import)",
"sfiAlgo": "KTS (AES + HMAC) key unwrapping",
"source": "Entity using the module"
},
{
"dest": "Entity using the module",
"distribution": "Automated",
"entry": "Electronic",
"format": "Encrypted",
"name": "TPM2_NV_ChangeAuth (Export)",
"sfiAlgo": "KTS (AES + HMAC) key wrapping",
"source": "RAM"
},
{
"dest": "RAM",
"distribution": "Automated",
"entry": "Electronic",
"format": "Encrypted",
"name": "TPM2_Rewrap (Import)",
"sfiAlgo": "KTS (AES + HMAC) key unwrapping",
"source": "Entity using the module"
},
{
"dest": "Entity using the module",
"distribution": "Automated",
"entry": "Electronic",
"format": "Encrypted",
"name": "TPM2_Rewrap (Export)",
"sfiAlgo": "KTS (AES + HMAC) key wrapping",
"source": "RAM"
},
{
"dest": "RAM",
"distribution": "Automated",
"entry": "Electronic",
"format": "Encrypted",
"name": "TPM2_HierarchyChangeAuth",
"sfiAlgo": "KTS (AES + HMAC) key unwrapping",
"source": "Entity using the module"
},
{
"dest": "RAM",
"distribution": "Automated",
"entry": "Electronic",
"format": "Encrypted",
"name": "TPM2_SetPrimaryPolicy",
"sfiAlgo": "KTS (AES + HMAC) key unwrapping",
"source": "Entity using the module"
},
{
"dest": "Entity using the module",
"distribution": "Manual",
"entry": "Electronic",
"format": "Plaintext",
"name": "TPM2_Duplicate (Import, Plain)",
"sfiAlgo": "",
"source": "RAM"
},
{
"dest": "Entity using the module",
"distribution": "Automated",
"entry": "Electronic",
"format": "Encrypted",
"name": "TPM2_Duplicate (Import, Encrypted)",
"sfiAlgo": "KTS (AES + HMAC) key unwrapping",
"source": "RAM"
},
{
"dest": "Entity using the module",
"distribution": "Manual",
"entry": "Electronic",
"format": "Plaintext",
"name": "TPM2_Duplicate (Export, Plain)",
"sfiAlgo": "",
"source": "RAM"
},
{
"dest": "Entity using the module",
"distribution": "Automated",
"entry": "Electronic",
"format": "Encrypted",
"name": "TPM2_Duplicate (Export, Encrypted)",
"sfiAlgo": "KTS (AES + HMAC) key wrapping",
"source": "RAM"
},
{
"dest": "RAM",
"distribution": "Automated",
"entry": "Electronic",
"format": "Plaintext",
"name": "TPM2_LoadExternal",
"sfiAlgo": "",
"source": "Entity using the module"
},
{
"dest": "RAM",
"distribution": "Automated",
"entry": "Electronic",
"format": "Encrypted",
"name": "TPM2_MakeCredential",
"sfiAlgo": "KTS (AES + HMAC) key unwrapping",
"source": "Entity using the module"
},
{
"dest": "Entity using the module",
"distribution": "Automated",
"entry": "Electronic",
"format": "Encrypted",
"name": "TPM2_ActivateCredential",
"sfiAlgo": "KTS (AES + HMAC) key wrapping",
"source": "RAM"
}
],
"found": true,
"section": 9,
"subsection": 2
},
"ssp_zeroization_methods": {
"entries": [
{
"description": "Procedurally clears the stack after ephemeral key is no longer needed",
"method": "Stack Cleaning",
"operatorId": "Automatically by the module",
"rationale": "Zeroize the stack contents in memory"
},
{
"description": "Removes all TPM context associated with a specific Owner",
"method": "TPM2_Clear",
"operatorId": "By invoking the TPM2_Clear service",
"rationale": "Zeroise objects in memory and persistent storage. Overwrites spSeed, shProof and ehProof with new values. Zeroize ownerAuth, ownerPolicy, endorsementAuth, endorsementPolicy, lockoutAuth, lockoutPolicy"
},
{
"description": "Changes the current endorsement primary seed (EPS)",
"method": "TPM2_ChangeEPS",
"operatorId": "By invoking the TPM2_ChangeEPS service",
"rationale": "epSeed is overwritten by random values from the DRBG. ehProof, endorsementAuth and endorsementPolicy are"
},
{
"description": "",
"method": "",
"operatorId": "",
"rationale": "zeroized. Flushes any resident objects."
},
{
"description": "Changes the current platform primary seed (PPS)",
"method": "TPM2_ChangePPS",
"operatorId": "By invoking the TPM2_ChangePPS service",
"rationale": "ppSeed is overwritten by random values from the DRBG. platformPolicy is zeroized. Flushes any resident objects."
},
{
"description": "Can be used to reset the module and have all variables go to the default initialization state",
"method": "TPM2_Startup",
"operatorId": "By invoking the TPM2_Startup service",
"rationale": "All variables are overwritten back the the default values (zeroed)."
},
{
"description": "Causes all context associated with a loaded object, sequence object, or session to be removed from TPM memory.",
"method": "TPM2_FlushContext",
"operatorId": "By invoking the TPM2_FlushContext service",
"rationale": "Clears objects from memory."
},
{
"description": "Removes an Index from the TPM.",
"method": "TPM2_NV_UndefineSpace",
"operatorId": "By invoking the TPM2_NV_UndefineSpace service",
"rationale": "Index is removed from the TPM."
},
{
"description": "This command enables and disables use of a hierarchy and its associated NV storage. The command allows phEnable, phEnableNV, shEnable, and ehEnable to be changed when the proper authorization is provided.",
"method": "TPM2_HierarchyControl",
"operatorId": "By invoking the TPM2_HierarchyControl service",
"rationale": "Zeroizes non-volatile stored values related to the disabled hierarchy"
},
{
"description": "Persistent memory is zeroized using a proprietary method",
"method": "Clear TPM",
"operatorId": "For further information and instructions on clearing the flash, contact the platform manufacturer or Nuvoton support",
"rationale": "Removes all module contents"
}
],
"found": true,
"section": 9,
"subsection": 3
},
"storage_areas": {
"entries": [
{
"description": "Storage location for firmware components and persistent SSPs.",
"name": "Flash",
"persistance": "Static"
},
{
"description": "Storage location for runtime operations and transient SSPs.",
"name": "RAM",
"persistance": "Dynamic"
},
{
"description": "Storage location for ephemeral keys.",
"name": "Stack",
"persistance": "Dynamic"
}
],
"found": true,
"section": 9,
"subsection": 1
},
"tested_module_id_hw": {
"entries": [
{
"features": "N/A",
"fwVersion": "7.2.4.1",
"hwVersion": "0x00FC",
"modelPartNum": "NPCT7xx embedded in UQFN16 package",
"processors": "NPCT7xx CPU"
},
{
"features": "N/A",
"fwVersion": "7.2.4.1",
"hwVersion": "0x00FC",
"modelPartNum": "NPCT7xx embedded in QFN32 package",
"processors": "NPCT7xx CPU"
},
{
"features": "N/A",
"fwVersion": "7.2.4.1",
"hwVersion": "0x00FC",
"modelPartNum": "NPCT7xx embedded in TSSOP28 package",
"processors": "NPCT7xx CPU"
}
],
"found": true,
"section": 2,
"subsection": 2
},
"tested_module_id_hw_hy": {
"entries": [],
"found": false,
"section": 2,
"subsection": 2
},
"tested_module_id_sw_fw_hy": {
"entries": [],
"found": false,
"section": 2,
"subsection": 2
},
"tested_op_env_sw_fw_hy": {
"entries": [],
"found": false,
"section": 2,
"subsection": 2
},
"vendor_affirmed_algos": {
"entries": [
{
"algoPropList": "Key Type:Symmetric and Asymmetric",
"implName": "N/A",
"name": "CKG",
"reference": "SP800-133, Rev2 Section 4, example 1"
}
],
"found": true,
"section": 2,
"subsection": 5
},
"vendor_affirmed_op_env_sw_fw_hy": {
"entries": [],
"found": false,
"section": 2,
"subsection": 2
}
},
"is_br1_format": true,
"keywords": {
"asymmetric_crypto": {
"ECC": {
"ECC": {
"ECC": 31
},
"ECDH": {
"ECDH": 4
},
"ECDSA": {
"ECDSA": 72
}
},
"FF": {
"DH": {
"DH": 4,
"Diffie-Hellman": 3
}
}
},
"certification_process": {},
"cipher_mode": {
"CCM": {
"CCM": 1
},
"CTR": {
"CTR": 6
},
"GCM": {
"GCM": 1
},
"OFB": {
"OFB": 4
}
},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {},
"crypto_protocol": {},
"crypto_scheme": {
"KA": {
"Key Agreement": 17
},
"MAC": {
"MAC": 7
}
},
"device_model": {},
"ecc_curve": {
"NIST": {
"P-256": 28,
"P-384": 36
}
},
"eval_facility": {
"atsec": {
"atsec": 118
}
},
"fips_cert_id": {},
"fips_certlike": {
"Certlike": {
"- PKCS 1": 2,
"AES 128": 1,
"AES-256": 1,
"HMAC 160": 2,
"HMAC 160, 256": 2,
"HMAC-SHA-1": 4,
"HMAC-SHA-256": 4,
"HMAC-SHA-384": 2,
"PKCS 1": 2,
"PKCS#1": 2,
"SHA-1": 23,
"SHA2- 256": 2,
"SHA2- 384": 1,
"SHA2-256": 11,
"SHA2-384": 12
}
},
"fips_security_level": {
"Level": {
"Level 1": 2,
"Level 3": 2,
"level 1": 1,
"level 3": 1
}
},
"hash_function": {
"SHA": {
"SHA1": {
"SHA-1": 23
}
}
},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {
"PRNG": {
"DRBG": 37
},
"RNG": {
"RBG": 18,
"RNG": 1
}
},
"side_channel_analysis": {
"FI": {
"fault injection": 1,
"physical tampering": 1
}
},
"standard_id": {
"FIPS": {
"FIPS 140-3": 126,
"FIPS 180-4": 4,
"FIPS 186-4": 11,
"FIPS 197": 1,
"FIPS 198-1": 4,
"FIPS PUB 140-3": 2,
"FIPS140-3": 1,
"FIPS186-4": 27
},
"NIST": {
"SP 800-108": 2,
"SP 800-133": 1,
"SP 800-140D": 1,
"SP 800-140F": 1,
"SP 800-38A": 3,
"SP 800-38B": 1,
"SP 800-38C": 1,
"SP 800-38D": 1,
"SP 800-38F": 1,
"SP 800-56A": 4,
"SP 800-56B": 2,
"SP 800-56C": 3,
"SP 800-90A": 1,
"SP 800-90B": 4
},
"PKCS": {
"PKCS 1": 2,
"PKCS#1": 1
}
},
"symmetric_crypto": {
"AES_competition": {
"AES": {
"AES": 79,
"AES-": 20,
"AES-256": 1
},
"CAST": {
"CAST": 33
}
},
"constructions": {
"MAC": {
"CMAC": 1,
"HMAC": 145,
"HMAC-SHA-256": 2,
"HMAC-SHA-384": 1
}
}
},
"tee_name": {
"AMD": {
"PSP": 4
},
"IBM": {
"SSC": 9
}
},
"tls_cipher_suite": {},
"vendor": {},
"vulnerability": {}
},
"module_algorithms": {
"_type": "Set",
"elements": [
"RSA SigGen (FIPS186-4)A4792",
"AES-OFBA4792",
"ECDSA SigVer (FIPS186-4)A4792",
"ECDSA KeyVer (FIPS186-4)A4792",
"RSA Signature PrimitiveA4792",
"KTS-IFCA4792",
"KDF SP800-108A4792",
"KAS-ECC-SSC Sp800-56Ar3A4792",
"ECDSA SigGen (FIPS186-4)A4792",
"KDA OneStep Sp800-56Cr1A4792",
"SHA-1A4792",
"KAS-ECC Sp800-56Ar3A4792",
"AES-CTRA4792",
"AES-CFB128A4792",
"HMAC-SHA2-256A4792",
"Conditioning Component Block Cipher Derivation Function SP800-90BA4792",
"RSA SigVer (FIPS186-4)A4792",
"Counter DRBGA4792",
"RSA KeyGen (FIPS186-4)A4792",
"SHA2-256A4792",
"HMAC-SHA2-384A4792",
"SHA2-384A4792",
"HMAC-SHA-1A4792",
"ECDSA KeyGen (FIPS186-4)A4792"
]
},
"policy_algorithms": {
"_type": "Set",
"elements": [
"#A4792"
]
},
"policy_metadata": {
"/Author": "renaudt nunez",
"/CreationDate": "D:20250910105216-04\u002700\u0027",
"/Creator": "Microsoft\u00ae Word for Microsoft 365",
"/MSIP_Label_b1479b79-36a9-4723-8bf6-a8305c972c78_ActionId": "5c050d8f-59c1-493a-b973-14cc618ffcb6",
"/MSIP_Label_b1479b79-36a9-4723-8bf6-a8305c972c78_ContentBits": "1",
"/MSIP_Label_b1479b79-36a9-4723-8bf6-a8305c972c78_Enabled": "true",
"/MSIP_Label_b1479b79-36a9-4723-8bf6-a8305c972c78_Method": "Privileged",
"/MSIP_Label_b1479b79-36a9-4723-8bf6-a8305c972c78_Name": "UNCLASSIFIED OFFICIAL USE ONLY",
"/MSIP_Label_b1479b79-36a9-4723-8bf6-a8305c972c78_SetDate": "2025-09-10T14:50:31Z",
"/MSIP_Label_b1479b79-36a9-4723-8bf6-a8305c972c78_SiteId": "da9cbe40-ec1e-4997-afb3-17d87574571a",
"/MSIP_Label_b1479b79-36a9-4723-8bf6-a8305c972c78_Tag": "10, 0, 1, 1",
"/ModDate": "D:20250910105216-04\u002700\u0027",
"/Producer": "Microsoft\u00ae Word for Microsoft 365",
"pdf_file_size_bytes": 1126303,
"pdf_hyperlinks": {
"_type": "Set",
"elements": [
"https://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf",
"https://csrc.nist.gov/publications/nistpubs/800-38D/SP-800-38D.pdf",
"https://www.ietf.org/rfc/rfc3447.txt",
"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf",
"https://csrc.nist.gov/CSRC/media/Projects/cryptographic-module-validation-program/documents/fips%20140-3/FIPS%20140-3%20IG.pdf",
"https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf",
"https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf",
"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90B.pdf",
"https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-135r1.pdf",
"https://csrc.nist.gov/publications/detail/sp/800-38b/final",
"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar2.pdf",
"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-133r2.pdf",
"https://doi.org/10.6028/NIST.FIPS.140-3",
"https://trustedcomputinggroup.org/tcg-tpm-v2-0-provisioning-guidance",
"https://trustedcomputinggroup.org/wp-content/uploads/PC-Client-Specific-Platform-TPM-Profile-for-TPM-2p0-v1p05p_r14_pub.pdf",
"https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38c.pdf",
"https://trustedcomputinggroup.org/resource/tpm-library-specification/",
"https://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf",
"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Ar3.pdf",
"https://trustedcomputinggroup.org/wp-content/uploads/TPM-2.0-Library-Spec-v1.59-Errata-v1.4_pub.pdf",
"https://csrc.nist.gov/publications/fips/fips197/fips-197.pdf",
"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90Ar1.pdf",
"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-140Br1.pdf"
]
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 117
}
},
"state": {
"_type": "sec_certs.sample.fips.InternalState",
"module": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": null,
"source_hash": null,
"txt_hash": null
},
"policy": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": "8b6c5238b3c5404f63fbe7c1836ce26db4aa8560462b563e8fc18df96e54d971",
"source_hash": "2ec0f3c5c0f6363870302538009831bf6093611cbcf9493bb65ab61125de9b75",
"txt_hash": "706ad52d1fed07b22199270442851534db1f220fb9affd59c9de2225b0e25bdc"
}
},
"web_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
"caveat": "When operated in approved mode; No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs",
"certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/November 2025_181225_1202.pdf",
"date_sunset": "2030-09-14",
"description": "Nuvoton NPCT7xx TPM 2.0 Cryptographic Engine is a hardware cryptographic module that implements advanced cryptographic algorithms, including symmetric and asymmetric cryptography; as well as key generation and random number generation.",
"embodiment": "Single Chip",
"exceptions": [
"Operational environment: N/A",
"Physical security: Level 3",
"Non-invasive security: N/A",
"Mitigation of other attacks: N/A"
],
"fw_versions": null,
"historical_reason": null,
"hw_versions": null,
"level": 1,
"mentioned_certs": {},
"module_name": "Nuvoton NPCT7xx TPM 2.0 Cryptographic Engine",
"module_type": "Hardware",
"revoked_link": null,
"revoked_reason": null,
"standard": "FIPS 140-3",
"status": "active",
"sw_versions": null,
"tested_conf": null,
"validation_history": [
{
"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
"date": "2025-09-15",
"lab": "atsec information security corporation",
"validation_type": "Initial"
}
],
"vendor": "Nuvoton Technology Corporation",
"vendor_url": "http://www.nuvoton.com"
}
}