Files
2024-03-15 15:07:16 +00:00

1165 lines
33 KiB
HTML

<!doctype html>
<html lang="en" class="no-js">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width,initial-scale=1">
<link rel="canonical" href="https://twpm.dasharo.com/roadmap/">
<link rel="icon" href="../images/favicon.png">
<meta name="generator" content="mkdocs-1.4.2, mkdocs-material-8.5.10">
<title>Index - Trustworthy Platform Module (TwPM)</title>
<link rel="stylesheet" href="../assets/stylesheets/main.975780f9.min.css">
<link rel="stylesheet" href="../assets/stylesheets/palette.2505c338.min.css">
<link rel="preconnect" href="https://fonts.gstatic.com" crossorigin>
<link rel="stylesheet" href="https://fonts.googleapis.com/css?family=Roboto:300,300i,400,400i,700,700i%7CRoboto+Mono:400,400i,700,700i&display=fallback">
<style>:root{--md-text-font:"Roboto";--md-code-font:"Roboto Mono"}</style>
<link rel="stylesheet" href="../stylesheets/extra.css">
<script>__md_scope=new URL("..",location),__md_hash=e=>[...e].reduce((e,_)=>(e<<5)-e+_.charCodeAt(0),0),__md_get=(e,_=localStorage,t=__md_scope)=>JSON.parse(_.getItem(t.pathname+"."+e)),__md_set=(e,_,t=localStorage,a=__md_scope)=>{try{t.setItem(a.pathname+"."+e,JSON.stringify(_))}catch(e){}}</script>
</head>
<body dir="ltr" data-md-color-scheme="default" data-md-color-primary="None" data-md-color-accent="None">
<input class="md-toggle" data-md-toggle="drawer" type="checkbox" id="__drawer" autocomplete="off">
<input class="md-toggle" data-md-toggle="search" type="checkbox" id="__search" autocomplete="off">
<label class="md-overlay" for="__drawer"></label>
<div data-md-component="skip">
<a href="#roadmap" class="md-skip">
Skip to content
</a>
</div>
<div data-md-component="announce">
</div>
<header class="md-header md-header--lifted" data-md-component="header">
<nav class="md-header__inner md-grid" aria-label="Header">
<a href=".." title="Trustworthy Platform Module (TwPM)" class="md-header__button md-logo" aria-label="Trustworthy Platform Module (TwPM)" data-md-component="logo">
<img src="../images/dasharo-logo.png" alt="logo">
</a>
<label class="md-header__button md-icon" for="__drawer">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M3 6h18v2H3V6m0 5h18v2H3v-2m0 5h18v2H3v-2Z"/></svg>
</label>
<div class="md-header__title" data-md-component="header-title">
<div class="md-header__ellipsis">
<div class="md-header__topic">
<span class="md-ellipsis">
Trustworthy Platform Module (TwPM)
</span>
</div>
<div class="md-header__topic" data-md-component="header-topic">
<span class="md-ellipsis">
Index
</span>
</div>
</div>
</div>
<label class="md-header__button md-icon" for="__search">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M9.5 3A6.5 6.5 0 0 1 16 9.5c0 1.61-.59 3.09-1.56 4.23l.27.27h.79l5 5-1.5 1.5-5-5v-.79l-.27-.27A6.516 6.516 0 0 1 9.5 16 6.5 6.5 0 0 1 3 9.5 6.5 6.5 0 0 1 9.5 3m0 2C7 5 5 7 5 9.5S7 14 9.5 14 14 12 14 9.5 12 5 9.5 5Z"/></svg>
</label>
<div class="md-search" data-md-component="search" role="dialog">
<label class="md-search__overlay" for="__search"></label>
<div class="md-search__inner" role="search">
<form class="md-search__form" name="search">
<input type="text" class="md-search__input" name="query" aria-label="Search" placeholder="Search" autocapitalize="off" autocorrect="off" autocomplete="off" spellcheck="false" data-md-component="search-query" required>
<label class="md-search__icon md-icon" for="__search">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M9.5 3A6.5 6.5 0 0 1 16 9.5c0 1.61-.59 3.09-1.56 4.23l.27.27h.79l5 5-1.5 1.5-5-5v-.79l-.27-.27A6.516 6.516 0 0 1 9.5 16 6.5 6.5 0 0 1 3 9.5 6.5 6.5 0 0 1 9.5 3m0 2C7 5 5 7 5 9.5S7 14 9.5 14 14 12 14 9.5 12 5 9.5 5Z"/></svg>
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M20 11v2H8l5.5 5.5-1.42 1.42L4.16 12l7.92-7.92L13.5 5.5 8 11h12Z"/></svg>
</label>
<nav class="md-search__options" aria-label="Search">
<button type="reset" class="md-search__icon md-icon" title="Clear" aria-label="Clear" tabindex="-1">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M19 6.41 17.59 5 12 10.59 6.41 5 5 6.41 10.59 12 5 17.59 6.41 19 12 13.41 17.59 19 19 17.59 13.41 12 19 6.41Z"/></svg>
</button>
</nav>
</form>
<div class="md-search__output">
<div class="md-search__scrollwrap" data-md-scrollfix>
<div class="md-search-result" data-md-component="search-result">
<div class="md-search-result__meta">
Initializing search
</div>
<ol class="md-search-result__list"></ol>
</div>
</div>
</div>
</div>
</div>
<div class="md-header__source">
<a href="https://github.com/dasharo/twpm-docs" title="Go to repository" class="md-source" data-md-component="source">
<div class="md-source__icon md-icon">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 448 512"><!--! Font Awesome Free 6.2.1 by @fontawesome - https://fontawesome.com License - https://fontawesome.com/license/free (Icons: CC BY 4.0, Fonts: SIL OFL 1.1, Code: MIT License) Copyright 2022 Fonticons, Inc.--><path d="M439.55 236.05 244 40.45a28.87 28.87 0 0 0-40.81 0l-40.66 40.63 51.52 51.52c27.06-9.14 52.68 16.77 43.39 43.68l49.66 49.66c34.23-11.8 61.18 31 35.47 56.69-26.49 26.49-70.21-2.87-56-37.34L240.22 199v121.85c25.3 12.54 22.26 41.85 9.08 55a34.34 34.34 0 0 1-48.55 0c-17.57-17.6-11.07-46.91 11.25-56v-123c-20.8-8.51-24.6-30.74-18.64-45L142.57 101 8.45 235.14a28.86 28.86 0 0 0 0 40.81l195.61 195.6a28.86 28.86 0 0 0 40.8 0l194.69-194.69a28.86 28.86 0 0 0 0-40.81z"/></svg>
</div>
<div class="md-source__repository">
GitHub
</div>
</a>
</div>
</nav>
<nav class="md-tabs" aria-label="Tabs" data-md-component="tabs">
<div class="md-tabs__inner md-grid">
<ul class="md-tabs__list">
<li class="md-tabs__item">
<a href=".." class="md-tabs__link">
Intro
</a>
</li>
<li class="md-tabs__item">
<a href="../tutorials/" class="md-tabs__link">
Tutorials
</a>
</li>
<li class="md-tabs__item">
<a href="../development/" class="md-tabs__link">
Development
</a>
</li>
<li class="md-tabs__item">
<a href="../explanation/" class="md-tabs__link">
Explanation
</a>
</li>
<li class="md-tabs__item">
<a href="../changelog/" class="md-tabs__link">
Changelog
</a>
</li>
<li class="md-tabs__item">
<a href="../contributing/" class="md-tabs__link">
Contributing
</a>
</li>
<li class="md-tabs__item">
<a href="./" class="md-tabs__link md-tabs__link--active">
Roadmap
</a>
</li>
</ul>
</div>
</nav>
</header>
<div class="md-container" data-md-component="container">
<main class="md-main" data-md-component="main">
<div class="md-main__inner md-grid">
<div class="md-sidebar md-sidebar--primary" data-md-component="sidebar" data-md-type="navigation" >
<div class="md-sidebar__scrollwrap">
<div class="md-sidebar__inner">
<nav class="md-nav md-nav--primary md-nav--lifted" aria-label="Navigation" data-md-level="0">
<label class="md-nav__title" for="__drawer">
<a href=".." title="Trustworthy Platform Module (TwPM)" class="md-nav__button md-logo" aria-label="Trustworthy Platform Module (TwPM)" data-md-component="logo">
<img src="../images/dasharo-logo.png" alt="logo">
</a>
Trustworthy Platform Module (TwPM)
</label>
<div class="md-nav__source">
<a href="https://github.com/dasharo/twpm-docs" title="Go to repository" class="md-source" data-md-component="source">
<div class="md-source__icon md-icon">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 448 512"><!--! Font Awesome Free 6.2.1 by @fontawesome - https://fontawesome.com License - https://fontawesome.com/license/free (Icons: CC BY 4.0, Fonts: SIL OFL 1.1, Code: MIT License) Copyright 2022 Fonticons, Inc.--><path d="M439.55 236.05 244 40.45a28.87 28.87 0 0 0-40.81 0l-40.66 40.63 51.52 51.52c27.06-9.14 52.68 16.77 43.39 43.68l49.66 49.66c34.23-11.8 61.18 31 35.47 56.69-26.49 26.49-70.21-2.87-56-37.34L240.22 199v121.85c25.3 12.54 22.26 41.85 9.08 55a34.34 34.34 0 0 1-48.55 0c-17.57-17.6-11.07-46.91 11.25-56v-123c-20.8-8.51-24.6-30.74-18.64-45L142.57 101 8.45 235.14a28.86 28.86 0 0 0 0 40.81l195.61 195.6a28.86 28.86 0 0 0 40.8 0l194.69-194.69a28.86 28.86 0 0 0 0-40.81z"/></svg>
</div>
<div class="md-source__repository">
GitHub
</div>
</a>
</div>
<ul class="md-nav__list" data-md-scrollfix>
<li class="md-nav__item md-nav__item--nested">
<input class="md-nav__toggle md-toggle" data-md-toggle="__nav_1" type="checkbox" id="__nav_1" >
<div class="md-nav__link md-nav__link--index ">
<a href="..">Intro</a>
</div>
<nav class="md-nav" aria-label="Intro" data-md-level="1">
<label class="md-nav__title" for="__nav_1">
<span class="md-nav__icon md-icon"></span>
Intro
</label>
<ul class="md-nav__list" data-md-scrollfix>
</ul>
</nav>
</li>
<li class="md-nav__item md-nav__item--nested">
<input class="md-nav__toggle md-toggle" data-md-toggle="__nav_2" type="checkbox" id="__nav_2" >
<div class="md-nav__link md-nav__link--index ">
<a href="../tutorials/">Tutorials</a>
<label for="__nav_2">
<span class="md-nav__icon md-icon"></span>
</label>
</div>
<nav class="md-nav" aria-label="Tutorials" data-md-level="1">
<label class="md-nav__title" for="__nav_2">
<span class="md-nav__icon md-icon"></span>
Tutorials
</label>
<ul class="md-nav__list" data-md-scrollfix>
<li class="md-nav__item">
<a href="../tutorials/building/" class="md-nav__link">
Building TwPM
</a>
</li>
<li class="md-nav__item">
<a href="../tutorials/mainboard-connection/" class="md-nav__link">
Connecting TwPM to the mainboard
</a>
</li>
</ul>
</nav>
</li>
<li class="md-nav__item md-nav__item--nested">
<input class="md-nav__toggle md-toggle" data-md-toggle="__nav_3" type="checkbox" id="__nav_3" >
<div class="md-nav__link md-nav__link--index ">
<a href="../development/">Development</a>
<label for="__nav_3">
<span class="md-nav__icon md-icon"></span>
</label>
</div>
<nav class="md-nav" aria-label="Development" data-md-level="1">
<label class="md-nav__title" for="__nav_3">
<span class="md-nav__icon md-icon"></span>
Development
</label>
<ul class="md-nav__list" data-md-scrollfix>
<li class="md-nav__item">
<a href="../development/verilog_modules/" class="md-nav__link">
Verilog modules
</a>
</li>
<li class="md-nav__item">
<a href="../development/soc_fpga_communication/" class="md-nav__link">
Communication between SoC and FPGA
</a>
</li>
<li class="md-nav__item">
<a href="../development/testing/" class="md-nav__link">
Testing
</a>
</li>
</ul>
</nav>
</li>
<li class="md-nav__item md-nav__item--nested">
<input class="md-nav__toggle md-toggle" data-md-toggle="__nav_4" type="checkbox" id="__nav_4" >
<div class="md-nav__link md-nav__link--index ">
<a href="../explanation/">Explanation</a>
<label for="__nav_4">
<span class="md-nav__icon md-icon"></span>
</label>
</div>
<nav class="md-nav" aria-label="Explanation" data-md-level="1">
<label class="md-nav__title" for="__nav_4">
<span class="md-nav__icon md-icon"></span>
Explanation
</label>
<ul class="md-nav__list" data-md-scrollfix>
<li class="md-nav__item">
<a href="../explanation/hardware-requirements/" class="md-nav__link">
Hardware requirements
</a>
</li>
<li class="md-nav__item">
<a href="../explanation/hardware-selection/" class="md-nav__link">
Hardware selection
</a>
</li>
<li class="md-nav__item">
<a href="../explanation/compliance/" class="md-nav__link">
Compliance
</a>
</li>
</ul>
</nav>
</li>
<li class="md-nav__item md-nav__item--nested">
<input class="md-nav__toggle md-toggle" data-md-toggle="__nav_5" type="checkbox" id="__nav_5" >
<div class="md-nav__link md-nav__link--index ">
<a href="../changelog/">Changelog</a>
</div>
<nav class="md-nav" aria-label="Changelog" data-md-level="1">
<label class="md-nav__title" for="__nav_5">
<span class="md-nav__icon md-icon"></span>
Changelog
</label>
<ul class="md-nav__list" data-md-scrollfix>
</ul>
</nav>
</li>
<li class="md-nav__item md-nav__item--nested">
<input class="md-nav__toggle md-toggle" data-md-toggle="__nav_6" type="checkbox" id="__nav_6" >
<div class="md-nav__link md-nav__link--index ">
<a href="../contributing/">Contributing</a>
</div>
<nav class="md-nav" aria-label="Contributing" data-md-level="1">
<label class="md-nav__title" for="__nav_6">
<span class="md-nav__icon md-icon"></span>
Contributing
</label>
<ul class="md-nav__list" data-md-scrollfix>
</ul>
</nav>
</li>
<li class="md-nav__item md-nav__item--active md-nav__item--nested">
<input class="md-nav__toggle md-toggle" data-md-toggle="__nav_7" type="checkbox" id="__nav_7" checked>
<div class="md-nav__link md-nav__link--index md-nav__link--active">
<a href="./">Roadmap</a>
</div>
<nav class="md-nav" aria-label="Roadmap" data-md-level="1">
<label class="md-nav__title" for="__nav_7">
<span class="md-nav__icon md-icon"></span>
Roadmap
</label>
<ul class="md-nav__list" data-md-scrollfix>
</ul>
</nav>
</li>
</ul>
</nav>
</div>
</div>
</div>
<div class="md-sidebar md-sidebar--secondary" data-md-component="sidebar" data-md-type="toc" >
<div class="md-sidebar__scrollwrap">
<div class="md-sidebar__inner">
<nav class="md-nav md-nav--secondary" aria-label="Table of contents">
<label class="md-nav__title" for="__toc">
<span class="md-nav__icon md-icon"></span>
Table of contents
</label>
<ul class="md-nav__list" data-md-component="toc" data-md-scrollfix>
<li class="md-nav__item">
<a href="#1-public-site-with-documentation" class="md-nav__link">
1. Public site with documentation
</a>
</li>
<li class="md-nav__item">
<a href="#2-gather-hardware-requirements-and-choose-target-board" class="md-nav__link">
2. Gather hardware requirements and choose target board
</a>
</li>
<li class="md-nav__item">
<a href="#3-implement-lpc-protocol-in-fpga" class="md-nav__link">
3. Implement LPC protocol in FPGA
</a>
</li>
<li class="md-nav__item">
<a href="#4-implement-basic-tpm-registers-in-fpga" class="md-nav__link">
4. Implement basic TPM registers in FPGA
</a>
</li>
<li class="md-nav__item">
<a href="#5-implement-tpm-command-parsing-and-communication-between-fpga-and-mcu" class="md-nav__link">
5. Implement TPM command parsing and communication between FPGA and MCU
</a>
</li>
<li class="md-nav__item">
<a href="#6-base-tests" class="md-nav__link">
6. Base tests
</a>
</li>
<li class="md-nav__item">
<a href="#7-implement-spi-tpm-protocol" class="md-nav__link">
7. Implement SPI TPM protocol
</a>
</li>
<li class="md-nav__item">
<a href="#8-explore-the-usage-of-using-simpler-hardware-platform" class="md-nav__link">
8. Explore the usage of using simpler hardware platform
</a>
</li>
<li class="md-nav__item">
<a href="#9-flash-driver-for-tpm-stack" class="md-nav__link">
9. Flash driver for TPM stack
</a>
</li>
<li class="md-nav__item">
<a href="#10-unique-identification-and-randomness-source" class="md-nav__link">
10. Unique identification and randomness source
</a>
</li>
<li class="md-nav__item">
<a href="#11-manufacturing-process" class="md-nav__link">
11. Manufacturing process
</a>
</li>
<li class="md-nav__item">
<a href="#12-customizable-configuration" class="md-nav__link">
12. Customizable configuration
</a>
</li>
</ul>
</nav>
</div>
</div>
</div>
<div class="md-content" data-md-component="content">
<article class="md-content__inner md-typeset">
<a href="https://github.com/dasharo/twpm-docs/edit/master/docs/roadmap/index.md" title="Edit this page" class="md-content__button md-icon">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M20.71 7.04c.39-.39.39-1.04 0-1.41l-2.34-2.34c-.37-.39-1.02-.39-1.41 0l-1.84 1.83 3.75 3.75M3 17.25V21h3.75L17.81 9.93l-3.75-3.75L3 17.25Z"/></svg>
</a>
<!--
SPDX-FileCopyrightText: 2024 3mdeb <contact@3mdeb.com>
SPDX-License-Identifier: CC-BY-SA-4.0
-->
<h1 id="roadmap">Roadmap</h1>
<p><a href="https://nlnet.nl/project/TwPM/index.html">TwPM project</a> is funded by the
<a href="https://nlnet.nl">NLnet Foundation</a> via the
<a href="https://www.assure.ngi.eu/">NGI ASSURE</a>.</p>
<p><a href="https://3mdeb.com/">3mdeb</a> has proposed to implement the following tasks under
the grant agreement No 957073.</p>
<h2 id="1-public-site-with-documentation">1. Public site with documentation</h2>
<p>All of the documentation produced during this project should be publicly
available to users and developers.</p>
<p>Milestones:</p>
<ul>
<li>create repositories for the project</li>
<li>prepare server and domain name</li>
<li>describe project's purpose and phases</li>
<li>create placeholders for description of deviations from TPM specification,
software stack and documentation changelog that will be updated after each of
the remaining phases</li>
</ul>
<p>State: <a href="../">Done (this website)</a></p>
<h2 id="2-gather-hardware-requirements-and-choose-target-board">2. Gather hardware requirements and choose target board</h2>
<p>TPMs are connected to the mainboard of PC. They have maximum allowed power
consumption and boot time. Based on those requirements and additional factors
like cost, availability and ease of use with open source tools we have to choose
a board for reference implementation.</p>
<p>Milestones:</p>
<ul>
<li>documentation of hardware requirements</li>
<li>analysis and comparison of available boards</li>
<li>establishment of reference board</li>
<li>review and update existing documentation, add entry to changelog</li>
</ul>
<p>State: <a href="../changelog/#2023-04-20">Done</a></p>
<h2 id="3-implement-lpc-protocol-in-fpga">3. Implement LPC protocol in FPGA</h2>
<p>While the newest computers use SPI for connecting TPM devices to the mainboard,
slightly older, but still widely used hardware uses Low Pin Count (LPC)
interface. Implementing this protocol at software level through bit-banging
would require very high speed micro-controllers, which would make the cost and
power consumption unreasonably high. To the best of our knowledge, there are no
MCUs that have LPC controller included as a hardware part of SoC, due to the
fact that LPC is specific to PC only. For these reasons hardware implementation
is required.</p>
<p>Milestones:</p>
<ul>
<li>design and implementation of LPC peripheral in Verilog</li>
<li>simulation of synthesized code</li>
<li>documentation describing connection between designed TPM and mainboard</li>
<li>review and update existing documentation, add entry to changelog</li>
</ul>
<p>State: <a href="../changelog/#2023-04-20">Done</a></p>
<h2 id="4-implement-basic-tpm-registers-in-fpga">4. Implement basic TPM registers in FPGA</h2>
<p>Most of the hardware TPM registers must return result immediately or almost
immediately. MCUs and their communication with FPGA are not fast enough to
acknowledge, parse, prepare response and send it to host in time. Hardware
implementation is required for registers that require fast response.</p>
<p>Milestones:</p>
<ul>
<li>implementation of TPM register space</li>
<li>implementation of finite state machine for changing localities</li>
<li>review and update existing documentation, add entry to changelog</li>
</ul>
<p>State: <a href="../changelog/#2023-05-24">Done</a></p>
<h2 id="5-implement-tpm-command-parsing-and-communication-between-fpga-and-mcu">5. Implement TPM command parsing and communication between FPGA and MCU</h2>
<p>Minimal parsing of commands and responses (limited to just their sizes) must be
done on FPGA side in order to properly set status bits that host can use to
check whether TPM expects more bytes of command or has more bytes of response.
Full command parsing and execution takes place on MCU, so FPGA has to implement
and expose buffer with command sent by host, along with any required metadata
like type of message in the buffer or currently active locality.</p>
<p>Milestones:</p>
<ul>
<li>implementation of FIFO on FPGA</li>
<li>implementation of command machine state</li>
<li>design, implementation and documentation of protocol of communication between
FPGA and MCU</li>
<li>application code for reading data from FIFO, passing parsed commands to the
TPM stack and writing responses back to FIFO</li>
<li>review and update existing documentation, add entry to changelog</li>
</ul>
<p>State: <a href="../changelog/#2024-01-16">Done</a></p>
<h2 id="6-base-tests">6. Base tests</h2>
<p>For testing of the implementation done so far, a subset of tpm2-tools commands
will be used. Only commands that do not depend on Protected Storage, RNG and
Primary Keys Certificates will be tested at this point.</p>
<p>Milestone:</p>
<ul>
<li>test suite: PCR operations (read, extend, reset values, locality protection)</li>
<li>test suite: object creation (primary, ordinary, derived objects of various
types)</li>
<li>test suite: cryptographic support functions (hash, HMAC, encryption, signing)</li>
<li>documentation of results</li>
<li>review and update existing documentation, add entry to changelog</li>
</ul>
<p>State: <a href="../changelog/#2024-01-16">Done</a></p>
<h2 id="7-implement-spi-tpm-protocol">7. Implement SPI TPM protocol</h2>
<p>SPI implementation on MCU may not be feasible because some of the registers must
return proper values immediately. This task consists of repeating all the tasks
that were done on FPGA side for LPC, but this time SPI is used as physical
interface.</p>
<p>Milestones:</p>
<ul>
<li>design and implementation of LPC peripheral in Verilog</li>
<li>simulation of synthesized code</li>
<li>documentation describing connection between designed TPM and mainboard</li>
<li>implementation of TPM register space</li>
<li>review and update existing documentation, add entry to changelog</li>
</ul>
<p>State: <a href="../changelog/#2024-03-14">Done</a></p>
<h2 id="8-explore-the-usage-of-using-simpler-hardware-platform">8. Explore the usage of using simpler hardware platform</h2>
<p>Additionally, we want to explore whether we can meet the TPM specification
requirements using simpler (and cheaper) microcontroller platform (with no FPGA
involved). That may not be feasible due to the hardware limitations, but it
is a great potential opportunity of increasing the adoption of the solution,
so that is why believe it makes sense to try to purse that and publish the
results.</p>
<p>Milestones:</p>
<ul>
<li>explore usage of the solution using simpler hardware platform (with no FPGA)</li>
<li>publish test results to the public documentation website</li>
<li>review and update existing documentation, add entry to changelog</li>
</ul>
<p>State: Done</p>
<h2 id="9-flash-driver-for-tpm-stack">9. Flash driver for TPM stack</h2>
<p>Nonvolatile storage is an integral part of TPM. It allows for saving user- or
vendor-defined data inside TPM, potentially with protection based on state of
TPM (PCR values, authorization sessions). With NVRAM implemented, additional
tests can be performed.</p>
<p>Milestones:</p>
<ul>
<li>flash driver for chosen board (if not available yet or has limited support)</li>
<li>integration of the TPM stack with flash driver</li>
<li>test suite: NV memory (persistent objects and data, vendor certificates)</li>
<li>test suite: attestation and authorization (quote, authorization sessions)</li>
<li>test suite: use in real-world scenario (Fobnail)</li>
<li>review and update existing documentation, add entry to changelog</li>
</ul>
<p>State: In progress</p>
<h2 id="10-unique-identification-and-randomness-source">10. Unique identification and randomness source</h2>
<p>Each TPM has to be uniquely identifiable. This uniqueness is used e.g. to create
primary seeds which are used to derive primary keys for various hierarchies.
Random number generator is also included in this task - unique registers (with
e.g. serial numbers) and RNG engines are usually specific to the given hardware.
FPGA can also be used if any of those isn't available or doesn't have enough
entropy on MCU.</p>
<p>Milestones:</p>
<ul>
<li>find and obtain enough bits of unique data identifying the platform</li>
<li>find and obtain enough bits of entropy for seeding PRNG</li>
<li>test suite: Windows HLK</li>
<li>review and update existing documentation, add entry to changelog</li>
</ul>
<p>State: In progress</p>
<h2 id="11-manufacturing-process">11. Manufacturing process</h2>
<p>Each TPM must be individually manufactured. This consists of committing vendor
certificate for TPM's primary Endorsement Key (EK) to its nonvolatile memory. As
each EK is unique, so is its certificate, and it must be sign by key which chain
of trust is rooted in publicly available vendor's root certificate.</p>
<p>Milestones:</p>
<ul>
<li>create manufacturing process</li>
<li>post the process on the documentation site</li>
<li>create script for automation of manufacturing process</li>
<li>review and update existing documentation, add entry to changelog</li>
</ul>
<p>State: Backlog</p>
<h2 id="12-customizable-configuration">12. Customizable configuration</h2>
<p>Platforms other than the reference one may support different functionalities, or
may have limited performance. To make transition to different hardware easier,
some options should be made configurable. This may include available hash
algorithms in TPM stack, physical interface used (LPC or SPI), presence of
hardware RNG engine, amount of nonvolatile memory.</p>
<p>Milestones:</p>
<ul>
<li>create easy to use build system integrating whole stack</li>
<li>prepare configuration file for whole project</li>
<li>review and update existing documentation, add entry to changelog</li>
</ul>
<p>State: In progress</p>
</article>
</div>
<script>var tabs=__md_get("__tabs");if(Array.isArray(tabs))e:for(var set of document.querySelectorAll(".tabbed-set")){var tab,labels=set.querySelector(".tabbed-labels");for(tab of tabs)for(var label of labels.getElementsByTagName("label"))if(label.innerText.trim()===tab){var input=document.getElementById(label.htmlFor);input.checked=!0;continue e}}</script>
</div>
<a href="#" class="md-top md-icon" data-md-component="top" hidden>
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M13 20h-2V8l-5.5 5.5-1.42-1.42L12 4.16l7.92 7.92-1.42 1.42L13 8v12Z"/></svg>
Back to top
</a>
</main>
<footer class="md-footer">
<nav class="md-footer__inner md-grid" aria-label="Footer" >
<a href="../contributing/" class="md-footer__link md-footer__link--prev" aria-label="Previous: Index" rel="prev">
<div class="md-footer__button md-icon">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M20 11v2H8l5.5 5.5-1.42 1.42L4.16 12l7.92-7.92L13.5 5.5 8 11h12Z"/></svg>
</div>
<div class="md-footer__title">
<div class="md-ellipsis">
<span class="md-footer__direction">
Previous
</span>
Index
</div>
</div>
</a>
</nav>
<div class="md-footer-meta md-typeset">
<div class="md-footer-meta__inner md-grid">
<div class="md-copyright">
Made with
<a href="https://squidfunk.github.io/mkdocs-material/" target="_blank" rel="noopener">
Material for MkDocs
</a>
</div>
</div>
</div>
</footer>
</div>
<div class="md-dialog" data-md-component="dialog">
<div class="md-dialog__inner md-typeset"></div>
</div>
<script id="__config" type="application/json">{"base": "..", "features": ["content.tabs.link", "navigation.instant", "navigation.tracking", "navigation.sections", "navigation.tabs", "navigation.tabs.sticky", "navigation.top", "navigation.indexes"], "search": "../assets/javascripts/workers/search.16e2a7d4.min.js", "translations": {"clipboard.copied": "Copied to clipboard", "clipboard.copy": "Copy to clipboard", "search.config.lang": "en", "search.config.pipeline": "trimmer, stopWordFilter", "search.config.separator": "[\\s\\-]+", "search.placeholder": "Search", "search.result.more.one": "1 more on this page", "search.result.more.other": "# more on this page", "search.result.none": "No matching documents", "search.result.one": "1 matching document", "search.result.other": "# matching documents", "search.result.placeholder": "Type to start searching", "search.result.term.missing": "Missing", "select.version.title": "Select version"}}</script>
<script src="../assets/javascripts/bundle.5a2dcb6a.min.js"></script>
</body>
</html>