Infineon Optiga SLB9670 vs SLB9672 TPM

We offer our LetsTrust TPM, which is based on the Infineon SLB9672 TPM chip. Previously we used the SLB9670.

What are the differences between Infineon Optiga SLB9670 and SLB9672?

attributeSLB9670SLB9672 (FW16.xx)
Compliant to TPM Main Specification, Family “2.0”yesyes, Level 00, Revision 01.59
certified according to
FIPS 140-2 Level 2
yesyes; physical security level 3 targeted
further certificationsN/ACommon Criteria for Information Technology Security
Evaluation (CC), Version 3.1 Rev.5, level EAL4+, AVA_VAN.4 (moderate) according to TCG PC Client TPM Protection
Profile
interfaceSPI, up to 43 MHzSPI, up to 33 MHz
certification criteria met for platform qualificationIntel TXT, Microsoft Windows, Google ChromebookIntel TXT, Microsoft Windows
Random number generator (RNG) according to NIST SP800-90Ayesyes, using entropy source according to NIST SP800-90B
PersonalizationFull personalization with Endorsement Key (EK) and EK certificateFull personalization with 4 Endorsement Keys (EK) and 4 EK certificates (RSA 2048, RSA 3072, ECC NIST P256,
ECC NIST P384)
Temperature rangesstandard: -20..+85°C
enhanced: -40..+85°C
standard: -40°C .. +85°C
enhanced: -40°C .. +105°C
package optionsPG-VQFN-32-13 packagePG-UQFN-32-1,-2 package
standby power consumptiontyp. 110µAtyp. 120 µA
PCRs24 PCRs (SHA-1 or SHA-256)24 PCRs (SHA-1 or SHA-256)
NV memoryMinimum of 6962 bytes free NV memory51 kByte NV memory
NV countersUp to 8 NV countersUnlimited amount of NV counters (only depending on NV memory utilization)
loaded sessionsUp to 3 loaded sessions (TPM_PT_HR_LOADED_MIN)Up to 3 loaded sessions (TPM_PT_HR_LOADED_MIN)
active sessionsUp to 64 active sessions (TPM_PT_ACTIVE_SESSIONS_MAX)Up to 64 active sessions (TPM_PT_ACTIVE_SESSIONS_MAX)
loaded transient ObjectsUp to 3 loaded transient Objects (TPM_PT_HR_TRANSIENT_MIN)Up to 3 loaded transient Objects (TPM_PT_HR_TRANSIENT_MIN)
loaded persistent ObjectsUp to 7 loaded persistent Objects (TPM_PT_HR_PERSISTENT_MIN)Up to 7 loaded persistent Objects (TPM_PT_HR_PERSISTENT_MIN)
further capabilities and parametersUp to 1 kByte for command parameters and response parameters
Up to 768 Byte for NV read or NV write
1420 Byte I/O buffer
N/A
further capabilities and parametersN/APre-generation of up to 7 RSA key pairs
RSA key generation (1024, 2048, 3072 and 4096 bit)
ECC (NIST P256, BN P256, NIST P384)
SHA1, SHA256, SHA384

How can I identify which TPM (SLB9670 or SLB9672) I am using?

Read the capabilities with the command TPM2_GetCapability:

propertySLB9670 valueSLB9672 value
TPM_PT_MANUFACTURER“IFX”“IFX”
TPM_PT_VENDOR_STRING_1“SLB9”“SLB9”
TPM_PT_VENDOR_STRING_2“670”“672”
TPM_PT_VENDOR_STRING_3NULLNULL
TPM_PT_VENDOR_STRING_4NULLNULL
TPM_PT_FIRMWARE_VERSION_1Major and minor version (for instance, 0x00070055
indicates V7.85)
Major and minor version (for instance, 0x0010000A
indicates V16.10)
TPM_PT_FIRMWARE_VERSION_2Build number and Common Criteria certification state (for
instance, 0x0011CB00 or 0x0011CB02)
Byte 1: reserved for future use (0x00)
Byte 2 and 3: Build number (for instance, 0x11CB)
Byte 4: Common Criteria certification state, 0x00 means
TPM is CC certified, 0x02 means TPM is not certified
Build number and Common Criteria certification state (for
instance, 0x00406800 or 0x00406802)1)
Byte 1: reserved for future use (0x00)
Byte 2 and 3: Build number (for instance, 0x4068)1)
Byte 4: Common Criteria certification state/mode:
0x00 = TPM operational mode/TPM is CC certified
0x02 = TPM operational mode/TPM is not certified
0x60 = Manually entered TPM firmware recovery mode
(triggered externally for testing purposes)
0x61 = TPM firmware recovery mode (triggered by code
integrity failure detection)
0x62 = TPM firmware update mode
TPM_PT_MODESBit 0 (FIPS_140_2) = 1
Bits 1..31 = 0
Bit 0 (FIPS_140_2) = 1
Bits 1..31 = 0

Resources: datasheets

What is the LetsTrust TPM? Can I use it with Raspberry Pi boards?

LetsTrust TPM is based on the Infineon Optiga TPM SLB9672. LetsTrust TPM is a compact TPM solution for Raspberry Pi platforms. It is optimal for evaluation, or production purposes. We have customers who purchased several thousand LetsTrust TPM units, for production use.

The product is available as a product family – with a standard solution, for integration using the SPI interface. We also offer an I2C variant, and a special compact variant which can be used with the standard Raspberry Pi case, called LetsTrust TPM Pro.

The LetsTrust TPM can be part of your compliance solution for EU CRA (cyber resilience act) compliance for products based on Raspberry Pi.