Skip to content

Add Infineon PSOC Control C3 on-board TPM demo - #12

Open
dgarske wants to merge 1 commit into
wolfSSL:mainfrom
dgarske:psoc_c3_onboard_demo
Open

dgarske wants to merge 1 commit into
wolfSSL:mainfrom
dgarske:psoc_c3_onboard_demo

Conversation

@dgarske

@dgarske dgarske commented Oct 5, 2026

Copy link
Copy Markdown
Member

Runs the whole demonstration on the microcontroller: the MCU drives a TPM 2.0 over I2C and performs post-quantum signing, a sealed secret bound to a measurement, PCR and endorsement certificate reads, and an SPDM session. No host takes part in the cryptography; it supplies a screen.

What it adds

  • Infineon/PSoC_Control_C3_Onboard_Demo/ - one firmware image whose acts are selected by a command byte on the console, emitting newline-delimited JSON
  • .../tpm_io_i2c_c3.c - TPM IO callback over wolfBoot's I2C driver
  • .../rng_seed.c - seeds wolfCrypt's DRBG from the TPM, the board having no entropy source of its own
  • .../wolfboot-demo.config - wolfBoot partitions sized for this image, which does not fit the stock psoc_c3 layout, with boot progress on the console
  • .../host/ - browser front end and a command-line driver for the same acts
  • .../BUILD.md - every build command written out, no wrapper scripts

The application is signed and verified by wolfBoot; make factory assembles the bootloader and the signed application into one flashable image. wolfTPM is unmodified. Needs wolfSSL/wolfBoot#915

Hardware / test status

Validated end to end on a PSOC Control C3 (C3M6) EVK with a TPM 2.0 on the mikroBUS connector, over the J-Link CDC console at 115200. Every act ran against the part, the sealed-secret sequence twice in succession, and the set was left cycling overnight without a failure. The host front end was run on both Windows and Linux against the same board, including the debug-probe reset behind the console tab.

Scope

The post-quantum TLS tab runs against wolfTPM's firmware TPM, not the fitted part, and says so on screen: the part's firmware implements only the pre-hash form of ML-DSA, which TLS CertificateVerify cannot use. That tab needs a
second wolfTPM built for the host, which host/README.md covers; every other tab is the fitted silicon. The endorsement tab proves the key match for the P-256 certificate only; the other rows report that no match was attempted.

@dgarske dgarske self-assigned this Oct 5, 2026
Copilot AI balanced review requested due to automatic review settings October 5, 2026 23:00

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Serial timeout and baud defects, unsafe certificate rendering, and incorrect SPDM success reporting can break or misrepresent core demonstrations.

Review effort: Balanced
Findings: 3 High severity · 5 Medium severity · 6 Low severity

Open (14)
What changed in this PR

Adds a complete PSoC Control C3 firmware and host interface for driving an attached TPM over I2C, including ML-DSA, sealing, PCR, endorsement, and SPDM demonstrations.

Changes:

  • Adds MCU firmware, TPM transport, cryptographic acts, diagnostics, and wolfBoot packaging.
  • Adds a browser UI and serial command-line tooling.
  • Documents building, flashing, operation, and measured performance.
File Description
README.md Links and summarizes the demo.
.../​.gitignore Excludes generated artifacts.
.../​BUILD.md Documents build and flashing.
.../​Makefile Builds, signs, and assembles firmware.
.../​README.md Documents firmware acts and benchmarks.
.../​act_sign.c Implements ML-DSA signing and verification.
.../​act_sign.h Declares the signing act.
.../​act_spdm.c Implements the SPDM act.
.../​act_spdm.h Declares the SPDM act.
.../​console_write.c Routes diagnostic output to UART.
.../​demo_acts.c Dispatches console-selected TPM acts.
.../​demo_util.c Provides board, timing, and output utilities.
.../​demo_util.h Declares shared utilities.
.../​fault_report.c Reports MCU faults over UART.
.../​firmware/​reset-board.jlink Resets the MCU and TPM.
.../​heap.c Provides a fixed embedded heap.
.../​i2c_trace.c Records TPM I2C transfers.
.../​i2c_trace.h Declares optional I2C tracing.
.../​mldsa_bench.c Benchmarks ML-DSA verification.
.../​mldsa_onboard.c Runs the standalone signing demonstration.
.../​rng_seed.c Seeds wolfCrypt from the TPM RNG.
.../​tpm_identity.c Reads TPM identity on-device.
.../​tpm_io_i2c_c3.c Implements wolfTPM I2C transport.
.../​user_settings.h Configures ML-DSA verification.
.../​user_settings_tpm.h Configures wolfTPM and SPDM support.
.../​wolfboot-demo.config Defines the enlarged wolfBoot layout.
.../​host/​README.md Documents host operation.
.../​host/​capture-tabs.sh Automates UI screenshots.
.../​host/​onboard.py Drives firmware over serial.
.../​host/​requirements.txt Lists host dependencies.
.../​host/​shot.py Captures headless browser screenshots.
.../​host/​sse_probe.py Probes streamed demo events.
.../​host/​templates/​index.html Implements the browser interface.
.../​host/​x509_lite.py Parses displayed certificate fields.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +293 to +296
spdm_acts_v$(APP_VERSION)_signed.bin: spdm_acts.bin
$(WOLFBOOT_DIR)/tools/keytools/sign $(SIGN_ALG) $< $(SIGN_KEY) $(APP_VERSION)

factory: wolfboot spdm_acts_v$(APP_VERSION)_signed.bin
Comment on lines +507 to +510
if (rc != TPM_RC_SUCCESS) {
demo_fail("wolfTPM2_Init", rc);
demo_put("{\"event\":\"ready\",\"tpm\":false}\r\n");
}
Comment on lines +1356 to +1365
$("ek-summary").innerHTML = !count
? "No endorsement certificates found."
: decoded
? "<b>" + count + " certificates</b> read from the TPM's own NV storage. " +
"Each one was written at manufacture and states, signed by the issuer, " +
"that this is a <b>" + (san.model || "TPM") + "</b> from <b>" +
decodeMfg(san.manufacturer) + "</b>, firmware " +
(san.version || "unknown") + "."
: "<b>" + count + " certificates</b> read from the TPM's own NV storage, " +
"each written there at manufacture and signed by the issuer.";
Comment on lines +211 to +214
if (rc == TPM_RC_SUCCESS)
rc = discover(dev);
finish(dev, 1, rc == TPM_RC_SUCCESS ? 1 : 0);
goto restore;
Comment on lines +47 to +51
# Long enough for ML-DSA key creation and signing, which together take a few
# seconds on this part and vary by more than a factor of two run to run.
DEFAULT_TIMEOUT = 30.0
# A gap this long with nothing arriving means the act is over or stuck.
DEFAULT_IDLE = 5.0
| `S` | as `s`, with ML-DSA-65 instead of 87 |
| `T` | as `t`, with ML-DSA-65 instead of 87 |
| `l` | sealed secret: seal to a PCR, unseal, extend, fail, reset |
| `e` | endorsement: read the EK certificates out of NV |
Comment on lines +8 to +9
page is the same whether the acts run on the board or, for the two that cannot
run on silicon, against wolfTPM's firmware TPM.
Comment on lines +228 to +230
<span id="claim-text">A post-quantum TPM, driven by wolfTPM. Keys are generated
inside the chip and never leave it &mdash; every tab below is that same silicon
doing real work, live.</span>
<li data-k="key"><span class="mark">2</span><span>TPM generates ML-DSA key pair</span><span class="detail"></span></li>
<li data-k="sign"><span class="mark">3</span><span>TPM signs digest (private key never leaves)</span><span class="detail"></span></li>
<li data-k="tamper"><span class="mark">!</span><span>Signature bit flipped</span><span class="detail"></span></li>
<li data-k="verify"><span class="mark">4</span><span>Host verifies with wolfCrypt</span><span class="detail"></span></li>
Comment on lines +407 to +408
<p class="lead">The SPI bus between a host and a TPM is plaintext: four
wires and a cheap logic analyser read every command and every response.
@dgarske
dgarske force-pushed the psoc_c3_onboard_demo branch 5 times, most recently from f3cfd4d to 60f1d76 Compare October 6, 2026 16:36
@dgarske
dgarske force-pushed the psoc_c3_onboard_demo branch from 60f1d76 to 729124e Compare October 6, 2026 21:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants