SDK for TESAIoT Dev Kit
API reference & tutorials (ModusToolbox)
Loading...
Searching...
No Matches
tesaiot_hsm_api.h File Reference
#include <stdint.h>
#include <stdbool.h>
#include <stddef.h>
#include "optiga_util.h"
#include "common/optiga_lib_types.h"

Go to the source code of this file.

Enumerations

enum  trustm_state_t {
  TRUSTM_STATE_IDLE = 0 , TRUSTM_STATE_PUBLISHING_CSR , TRUSTM_STATE_WAITING_FOR_MANIFEST , TRUSTM_STATE_APPLYING_UPDATE ,
  TRUSTM_STATE_WAITING_FOR_CERTIFICATE , TRUSTM_STATE_COMPLETE , TRUSTM_STATE_ERROR , TRUSTM_STATE_WAITING_FOR_JSON_BUNDLE ,
  TRUSTM_STATE_PROCESSING_JSON_BUNDLE , TRUSTM_STATE_WRITING_TRUST_ANCHOR , TRUSTM_STATE_VERIFYING_MANIFEST , TRUSTM_STATE_APPLYING_FRAGMENTS ,
  TRUSTM_STATE_PROTECTED_UPDATE_SUCCESS , TRUSTM_STATE_PROTECTED_UPDATE_FAILED
}

Functions

bool optiga_manager_init (callback_handler_t callback, void *context)
 Bring up the OPTIGA stack (idempotent); task context only — false if the chip did not answer.
optiga_util_t * optiga_manager_acquire (void)
 The shared optiga_util instance; NULL until optiga_manager_init() has run.
void optiga_manager_release (void)
 Release the acquired instance — exactly one per non-NULL acquire, on every exit.
bool optiga_manager_lock (void)
 Take the manager mutex; false when never initialised — the real "is the manager up?" test.
void optiga_manager_unlock (void)
 One unlock per successful lock, every early exit included; release a touch hold first.
bool optiga_chip_enter (void)
 Open a chip session (re-entrant per task); false is fatal for this call — and NOT an init check.
void optiga_chip_exit (void)
 One exit per successful enter; never call it after a failed enter.
void optiga_manager_touch_hold (void)
 Counted hold for the whole chip conversation; the first hold sleeps 50 ms.
void optiga_manager_touch_hold_reason (const char *reason)
 The same counted hold, plus the busy-modal string CM55 shows while touch is off.
void optiga_manager_touch_release (void)
 Decrement the hold counter — strict 1:1 with every hold, on every early return.
int publish_csr (uint8_t *csr, size_t csr_length, uint16_t target_oid, uint16_t trust_anchor_oid, uint32_t payload_version)
 Publish an already-built CSR for the platform to sign; weak — NULL-check first. Arms the ingest.
int tesaiot_publish_protected_update (const char *target_oid, const char *trust_anchor_oid, uint32_t payload_version, bool with_csr)
 Ask the platform for a Protected Update (OIDs as hex strings); weak — NULL-check first.
void tesaiot_run_protected_update_isolated_test (void)
 Interactive end-to-end Protected Update against the isolated test slot; blocks on scanf().
void trustm_update_state (trustm_state_t new_state, const char *status_code, const char *detail)
 A setter with a timestamp, not a dispatcher; set WAITING_* before the transport starts.
void trustm_reset_state (void)
 Back to IDLE, correlation id zeroed — this is what ends a run; call it at every exit.
uint16_t trustm_requested_target_oid (void)
 The target OID the last request named; weak — NULL-check and fall back to 0xE0E1.
uint16_t trustm_requested_anchor_oid (void)
 The trust anchor the last request named; weak — same pattern, default 0xE0E8.
const char * trustm_current_correlation_id (void)
 The in-flight run's id, or NULL; NULL means discard the inbound bundle — the replay defence.

Enumeration Type Documentation

◆ trustm_state_t

Where the enrolment state machine is.

Enumerator
TRUSTM_STATE_IDLE 
TRUSTM_STATE_PUBLISHING_CSR 
TRUSTM_STATE_WAITING_FOR_MANIFEST 
TRUSTM_STATE_APPLYING_UPDATE 
TRUSTM_STATE_WAITING_FOR_CERTIFICATE 
TRUSTM_STATE_COMPLETE 
TRUSTM_STATE_ERROR 
TRUSTM_STATE_WAITING_FOR_JSON_BUNDLE 
TRUSTM_STATE_PROCESSING_JSON_BUNDLE 
TRUSTM_STATE_WRITING_TRUST_ANCHOR 
TRUSTM_STATE_VERIFYING_MANIFEST 
TRUSTM_STATE_APPLYING_FRAGMENTS 
TRUSTM_STATE_PROTECTED_UPDATE_SUCCESS 
TRUSTM_STATE_PROTECTED_UPDATE_FAILED