// This file was extracted from the TCG Published // Trusted Platform Module Library // Part 4: Supporting Routines // Family "2.0" // Level 00 Revision 01.16 // October 30, 2014 #ifndef _IMPLEMENTATION_H_ #define _IMPLEMENTATION_H_ #include "BaseTypes.h" #include "TPMB.h" #undef TRUE #undef FALSE // // This table is built in to TpmStructures() Change these definitions to turn all algorithms or commands on or // off // #define ALG_YES YES #define ALG_NO NO #define CC_YES YES #define CC_NO NO // // From TPM 2.0 Part 2: Table 4 - Defines for Logic Values // #define TRUE 1 #define FALSE 0 #define YES 1 #define NO 0 #define SET 1 #define CLEAR 0 // // From Vendor-Specific: Table 1 - Defines for Processor Values // #define BIG_ENDIAN_TPM NO #define LITTLE_ENDIAN_TPM YES #define NO_AUTO_ALIGN NO // // From Vendor-Specific: Table 2 - Defines for Implemented Algorithms // #define ALG_RSA ALG_YES #define ALG_SHA1 ALG_YES #define ALG_HMAC ALG_YES #define ALG_AES ALG_YES #define ALG_MGF1 ALG_YES #define ALG_XOR ALG_YES #define ALG_KEYEDHASH ALG_YES #define ALG_SHA256 ALG_YES #define ALG_SHA384 ALG_YES #define ALG_SHA512 ALG_YES #define ALG_SM3_256 ALG_NO #define ALG_SM4 ALG_NO #define ALG_RSASSA (ALG_YES*ALG_RSA) #define ALG_RSAES (ALG_YES*ALG_RSA) #define ALG_RSAPSS (ALG_YES*ALG_RSA) #define ALG_OAEP (ALG_YES*ALG_RSA) #define ALG_ECC ALG_YES #define ALG_ECDH (ALG_YES*ALG_ECC) #define ALG_ECDSA (ALG_YES*ALG_ECC) #ifdef EMBEDDED_MODE #define ALG_ECDAA (ALG_NO*ALG_ECC) #define ALG_SM2 (ALG_NO*ALG_ECC) #define ALG_ECSCHNORR (ALG_NO*ALG_ECC) #else #define ALG_ECDAA (ALG_YES*ALG_ECC) #define ALG_SM2 (ALG_YES*ALG_ECC) #define ALG_ECSCHNORR (ALG_YES*ALG_ECC) #endif #define ALG_ECMQV (ALG_NO*ALG_ECC) #define ALG_SYMCIPHER ALG_YES #define ALG_KDF1_SP800_56A (ALG_YES*ALG_ECC) #define ALG_KDF2 ALG_NO #define ALG_KDF1_SP800_108 ALG_YES #define ALG_CTR ALG_YES #define ALG_OFB ALG_YES #define ALG_CBC ALG_YES #define ALG_CFB ALG_YES #define ALG_ECB ALG_YES // // From Vendor-Specific: Table 4 - Defines for Key Size Constants // #define RSA_KEY_SIZES_BITS {1024,2048} #define RSA_KEY_SIZE_BITS_1024 RSA_ALLOWED_KEY_SIZE_1024 #define RSA_KEY_SIZE_BITS_2048 RSA_ALLOWED_KEY_SIZE_2048 #define MAX_RSA_KEY_BITS 2048 #define MAX_RSA_KEY_BYTES 256 #define AES_KEY_SIZES_BITS {128,256} #define AES_KEY_SIZE_BITS_128 AES_ALLOWED_KEY_SIZE_128 #define AES_KEY_SIZE_BITS_256 AES_ALLOWED_KEY_SIZE_256 #define MAX_AES_KEY_BITS 256 #define MAX_AES_KEY_BYTES 32 #define MAX_AES_BLOCK_SIZE_BYTES \ MAX(AES_128_BLOCK_SIZE_BYTES, \ MAX(AES_256_BLOCK_SIZE_BYTES, 0)) #define SM4_KEY_SIZES_BITS {128} #define SM4_KEY_SIZE_BITS_128 SM4_ALLOWED_KEY_SIZE_128 #define MAX_SM4_KEY_BITS 128 #define MAX_SM4_KEY_BYTES 16 #define MAX_SM4_BLOCK_SIZE_BYTES \ MAX(SM4_128_BLOCK_SIZE_BYTES, 0) #define CAMELLIA_KEY_SIZES_BITS {128} #define CAMELLIA_KEY_SIZE_BITS_128 CAMELLIA_ALLOWED_KEY_SIZE_128 #define MAX_CAMELLIA_KEY_BITS 128 #define MAX_CAMELLIA_KEY_BYTES 16 #define MAX_CAMELLIA_BLOCK_SIZE_BYTES \ MAX(CAMELLIA_128_BLOCK_SIZE_BYTES, 0) // // From Vendor-Specific: Table 5 - Defines for Implemented Curves // #define ECC_NIST_P256 YES #define ECC_NIST_P384 YES #define ECC_BN_P256 YES #define ECC_CURVES {\ TPM_ECC_BN_P256, TPM_ECC_NIST_P256, TPM_ECC_NIST_P384} #define ECC_KEY_SIZES_BITS {256, 384} #define ECC_KEY_SIZE_BITS_256 #define ECC_KEY_SIZE_BITS_384 #define MAX_ECC_KEY_BITS 384 #define MAX_ECC_KEY_BYTES 48 // // From Vendor-Specific: Table 6 - Defines for Implemented Commands // #define CC_ActivateCredential CC_YES #define CC_Certify CC_YES #define CC_CertifyCreation CC_YES // #define CC_ChangeEPS CC_YES #define CC_ChangePPS CC_YES #define CC_Clear CC_YES #define CC_ClearControl CC_YES #define CC_ClockRateAdjust CC_YES #define CC_ClockSet CC_YES #define CC_Commit (CC_YES*ALG_ECC) #define CC_ContextLoad CC_YES #define CC_ContextSave CC_YES #define CC_Create CC_YES #define CC_CreatePrimary CC_YES #define CC_DictionaryAttackLockReset CC_YES #define CC_DictionaryAttackParameters CC_YES #define CC_Duplicate CC_YES #define CC_ECC_Parameters (CC_YES*ALG_ECC) #define CC_ECDH_KeyGen (CC_YES*ALG_ECC) #define CC_ECDH_ZGen (CC_YES*ALG_ECC) #define CC_EncryptDecrypt CC_YES #define CC_EventSequenceComplete CC_YES #define CC_EvictControl CC_YES #define CC_FieldUpgradeData CC_NO #define CC_FieldUpgradeStart CC_NO #define CC_FirmwareRead CC_NO #define CC_FlushContext CC_YES #define CC_GetCapability CC_YES #define CC_GetCommandAuditDigest CC_YES #define CC_GetRandom CC_YES #define CC_GetSessionAuditDigest CC_YES #define CC_GetTestResult CC_YES #define CC_GetTime CC_YES #define CC_Hash CC_YES #define CC_HashSequenceStart CC_YES #define CC_HierarchyChangeAuth CC_YES #define CC_HierarchyControl CC_YES #define CC_HMAC CC_YES #define CC_HMAC_Start CC_YES #define CC_Import CC_YES #define CC_IncrementalSelfTest CC_YES #define CC_Load CC_YES #define CC_LoadExternal CC_YES #define CC_MakeCredential CC_YES #define CC_NV_Certify CC_YES #define CC_NV_ChangeAuth CC_YES #define CC_NV_DefineSpace CC_YES #define CC_NV_Extend CC_YES #define CC_NV_GlobalWriteLock CC_YES #define CC_NV_Increment CC_YES #define CC_NV_Read CC_YES #define CC_NV_ReadLock CC_YES #define CC_NV_ReadPublic CC_YES #define CC_NV_SetBits CC_YES #define CC_NV_UndefineSpace CC_YES #define CC_NV_UndefineSpaceSpecial CC_YES #define CC_NV_Write CC_YES #define CC_NV_WriteLock CC_YES #define CC_ObjectChangeAuth CC_YES #define CC_PCR_Allocate CC_YES #define CC_PCR_Event CC_YES #define CC_PCR_Extend CC_YES #define CC_PCR_Read CC_YES #define CC_PCR_Reset CC_YES #define CC_PCR_SetAuthPolicy CC_YES #define CC_PCR_SetAuthValue CC_YES #define CC_PolicyAuthorize CC_YES #define CC_PolicyAuthValue CC_YES #define CC_PolicyCommandCode CC_YES #define CC_PolicyCounterTimer CC_YES #define CC_PolicyCpHash CC_YES #define CC_PolicyDuplicationSelect CC_YES #define CC_PolicyGetDigest CC_YES #define CC_PolicyLocality CC_YES #define CC_PolicyNameHash CC_YES #define CC_PolicyNV CC_YES #define CC_PolicyOR CC_YES #define CC_PolicyPassword CC_YES #define CC_PolicyPCR CC_YES #define CC_PolicyPhysicalPresence CC_YES #define CC_PolicyRestart CC_YES #define CC_PolicySecret CC_YES #define CC_PolicySigned CC_YES #define CC_PolicyTicket CC_YES #define CC_PP_Commands CC_YES #define CC_Quote CC_YES #define CC_ReadClock CC_YES #define CC_ReadPublic CC_YES #define CC_Rewrap CC_YES #define CC_RSA_Decrypt (CC_YES*ALG_RSA) #define CC_RSA_Encrypt (CC_YES*ALG_RSA) #define CC_SelfTest CC_YES #define CC_SequenceComplete CC_YES #define CC_SequenceUpdate CC_YES #define CC_SetAlgorithmSet CC_YES #define CC_SetCommandCodeAuditStatus CC_YES #define CC_SetPrimaryPolicy CC_YES #define CC_Shutdown CC_YES #define CC_Sign CC_YES #define CC_StartAuthSession CC_YES #define CC_Startup CC_YES #define CC_StirRandom CC_YES #define CC_TestParms CC_YES #define CC_Unseal CC_YES #define CC_VerifySignature CC_YES #define CC_ZGen_2Phase (CC_YES*ALG_ECC) #define CC_EC_Ephemeral (CC_YES*ALG_ECC) #define CC_PolicyNvWritten CC_YES // // From Vendor-Specific: Table 7 - Defines for Implementation Values // #define FIELD_UPGRADE_IMPLEMENTED NO #define BSIZE UINT16 #define BUFFER_ALIGNMENT 4 #define IMPLEMENTATION_PCR 24 #define PLATFORM_PCR 24 #define DRTM_PCR 17 #define HCRTM_PCR 0 #define NUM_LOCALITIES 5 #define MAX_HANDLE_NUM 3 #define MAX_ACTIVE_SESSIONS 64 #define CONTEXT_SLOT UINT16 #define CONTEXT_COUNTER UINT64 #define MAX_LOADED_SESSIONS 3 #define MAX_SESSION_NUM 3 #define MAX_LOADED_OBJECTS 3 #define MIN_EVICT_OBJECTS 2 #define PCR_SELECT_MIN ((PLATFORM_PCR+7)/8) #define PCR_SELECT_MAX ((IMPLEMENTATION_PCR+7)/8) #define NUM_POLICY_PCR_GROUP 1 #define NUM_AUTHVALUE_PCR_GROUP 1 #define MAX_CONTEXT_SIZE 2048 #define MAX_DIGEST_BUFFER 1024 #define MAX_NV_INDEX_SIZE 2048 // #define MAX_NV_BUFFER_SIZE 1024 #define MAX_CAP_BUFFER 1024 #ifdef EMBEDDED_MODE // This must be matched by the package using this library! #define NV_MEMORY_SIZE 11980 // Versioning NV storage format will allow to smoothly migrate NVRAM contents. // Versions: // 1 - full non-serialized objects in NVMEM, max SHA digest is SHA-256 // 2 - a mix of serialized and non-serialized objects in NVMEM, max SHA digest // is SHA-512. Eviction objects can be stored either serialized or // non-serialized. The size of the stored entity smaller than // sizeof(OBJECT) is considered an indication of the serialized form. #define NV_FORMAT_VERSION 2 #else #define NV_MEMORY_SIZE 16384 #endif #define NUM_STATIC_PCR 16 #define MAX_ALG_LIST_SIZE 64 #define TIMER_PRESCALE 100000 #define PRIMARY_SEED_SIZE 32 #define CONTEXT_ENCRYPT_ALG TPM_ALG_AES #define CONTEXT_ENCRYPT_KEY_BITS MAX_SYM_KEY_BITS #define CONTEXT_ENCRYPT_KEY_BYTES ((CONTEXT_ENCRYPT_KEY_BITS+7)/8) #define CONTEXT_INTEGRITY_HASH_ALG TPM_ALG_SHA256 #define CONTEXT_INTEGRITY_HASH_SIZE SHA256_DIGEST_SIZE #define PROOF_SIZE CONTEXT_INTEGRITY_HASH_SIZE #define NV_CLOCK_UPDATE_INTERVAL 12 #define NUM_POLICY_PCR 1 #define MAX_COMMAND_SIZE 4096 #define MAX_RESPONSE_SIZE 4096 #define ORDERLY_BITS 8 #define MAX_ORDERLY_COUNT ((1< (b) ? (a) : (b)) #endif #define MAX_HASH_BLOCK_SIZE ( \ MAX(ALG_SHA1 * SHA1_BLOCK_SIZE, \ MAX(ALG_SHA256 * SHA256_BLOCK_SIZE, \ MAX(ALG_SHA384 * SHA384_BLOCK_SIZE, \ MAX(ALG_SM3_256 * SM3_256_BLOCK_SIZE, \ MAX(ALG_SHA512 * SHA512_BLOCK_SIZE, \ 0 )))))) #define MAX_DIGEST_SIZE ( \ MAX(ALG_SHA1 * SHA1_DIGEST_SIZE, \ MAX(ALG_SHA256 * SHA256_DIGEST_SIZE, \ MAX(ALG_SHA384 * SHA384_DIGEST_SIZE, \ MAX(ALG_SM3_256 * SM3_256_DIGEST_SIZE, \ MAX(ALG_SHA512 * SHA512_DIGEST_SIZE, \ 0 )))))) #if MAX_DIGEST_SIZE == 0 || MAX_HASH_BLOCK_SIZE == 0 #error "Hash data not valid" #endif #define HASH_COUNT (ALG_SHA1+ALG_SHA256+ALG_SHA384+ALG_SM3_256+ALG_SHA512) // // Define the 2B structure that would hold any hash block // TPM2B_TYPE(MAX_HASH_BLOCK, MAX_HASH_BLOCK_SIZE); // // Folloing typedef is for some old code // typedef TPM2B_MAX_HASH_BLOCK TPM2B_HASH_BLOCK; #ifndef MAX #define MAX(a, b) ((a) > (b) ? (a) : (b)) #endif #ifndef ALG_CAMELLIA # define ALG_CAMELLIA NO #endif #ifndef MAX_CAMELLIA_KEY_BITS # define MAX_CAMELLIA_KEY_BITS 0 # define MAX_CAMELLIA_BLOCK_SIZE_BYTES 0 #endif #ifndef ALG_SM4 # define ALG_SM4 NO #endif #ifndef MAX_SM4_KEY_BITS # define MAX_SM4_KEY_BITS 0 # define MAX_SM4_BLOCK_SIZE_BYTES 0 #endif #ifndef ALG_AES # define ALG_AES NO #endif #ifndef MAX_AES_KEY_BITS # define MAX_AES_KEY_BITS 0 # define MAX_AES_BLOCK_SIZE_BYTES 0 #endif #define MAX_SYM_KEY_BITS ( \ MAX(MAX_CAMELLIA_KEY_BITS * ALG_CAMELLIA, \ MAX(MAX_SM4_KEY_BITS * ALG_SM4, \ MAX(MAX_AES_KEY_BITS * ALG_AES, \ 0)))) #define MAX_SYM_KEY_BYTES ((MAX_SYM_KEY_BITS + 7) / 8) #define MAX_SYM_BLOCK_SIZE ( \ MAX(MAX_CAMELLIA_BLOCK_SIZE_BYTES * ALG_CAMELLIA, \ MAX(MAX_SM4_BLOCK_SIZE_BYTES * ALG_SM4, \ MAX(MAX_AES_BLOCK_SIZE_BYTES * ALG_AES, \ 0)))) #if MAX_SYM_KEY_BITS == 0 || MAX_SYM_BLOCK_SIZE == 0 # error Bad size for MAX_SYM_KEY_BITS or MAX_SYM_BLOCK_SIZE #endif // // Define the 2B structure for a seed // TPM2B_TYPE(SEED, PRIMARY_SEED_SIZE); #define UNREFERENCED_PARAMETER(x) (void)(x) #endif // _IMPLEMENTATION_H_