You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Returns a cryptogram that encrypts and authenticates the device attestation public key stored in MCU. The commands `secrets-init` and `secure-channel-handshake-2` must be executed before calling this command.
653
+
654
+
Example:
655
+
```
656
+
secrets-get-mcu-device-key
657
+
OK 638c8a83ddc8fd84cddf5a0a4fa3d9615146cd341685dca942bab1132c2bc99b
658
+
```
659
+
660
+
### secrets-certdev-write
661
+
Writes the X.509 device attestation certificate issued by the Trezor Company for the attestation key stored in MCU.
662
+
663
+
Example:
664
+
```
665
+
secrets-certdev-write <hexadecimal string>
666
+
OK
667
+
```
668
+
669
+
### secrets-certdev-read
670
+
Retrieves the X.509 device attestation certificate issued by the Trezor Company for the attestation key stored in MCU.
671
+
672
+
Example:
673
+
```
674
+
secrets-certdev-read
675
+
OK <hexadecimal string>
676
+
```
677
+
651
678
### optiga-pair
652
679
Writes the pairing secret to the Optiga chip to pair it with the MCU. The command `secrets-init` must be executed before calling this command.
653
680
@@ -675,17 +702,17 @@ optiga-certinf-read
675
702
OK <hexadecimal string>
676
703
```
677
704
678
-
### optiga-certinf-write
679
-
Writes the X.509 certificate issued by the Trezor Company for the device.
705
+
### optiga-certdev-write
706
+
Writes the X.509 certificate issued by the Trezor Company for the device attestation key stored in Optiga.
680
707
681
708
Example:
682
709
```
683
-
optiga-certinf-write <hexadecimal string>
710
+
optiga-certdev-write <hexadecimal string>
684
711
OK
685
712
```
686
713
687
-
### optiga-certdev-red
688
-
Retrieves the X.509 certificate issued by the Trezor Company for the device.
714
+
### optiga-certdev-read
715
+
Retrieves the X.509 certificate issued by the Trezor Company for the device attestation key stored in Optiga.
689
716
690
717
Example:
691
718
```
@@ -694,7 +721,7 @@ OK <hexadecimal string>
694
721
```
695
722
696
723
### optiga-certfido-write
697
-
Writes the X.509 certificate issued by the Trezor Company for the FIDO attestation key.
724
+
Writes the X.509 certificate issued by the Trezor Company for the FIDO attestation key stored in Optiga.
698
725
699
726
Example:
700
727
```
@@ -703,7 +730,7 @@ OK
703
730
```
704
731
705
732
### optiga-certfido-read
706
-
Retrieves the X.509 certificate issued by the Trezor Company for the FIDO attestation key.
733
+
Retrieves the X.509 certificate issued by the Trezor Company for the FIDO attestation key stored in Optiga.
707
734
708
735
Example:
709
736
```
@@ -947,6 +974,145 @@ tropic-get-chip-id
947
974
OK 00000001000000000000000000000000000000000000000000000000000000000000000001000000054400000000FFFFFFFFFFFF01F00F000544545354303103001300000B54524F50494330312D4553FFFFFFFF000100000000FFFF000100000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF13000300
948
975
```
949
976
977
+
### tropic-certtropic-read
978
+
979
+
Reads the X.509 certificate issued by Tropic Square for the Tropic chip.
980
+
981
+
Example:
982
+
```
983
+
tropic-certtropic-read
984
+

985
+
```
986
+
987
+
### tropic-lock-check
988
+
989
+
Returns 'YES' if the Tropic chip has been locked, otherwise returns 'NO'.
990
+
991
+
Example:
992
+
```
993
+
tropic-lock-check
994
+
OK YES
995
+
```
996
+
997
+
### tropic-pair
998
+
999
+
Pairs the MCU with the Tropic chip. This command is idempotent, meaning it can be called multiple times without changing the state of the device. This command is irreversible and cannot be undone. The command `secrets-init` must be executed before calling this command.
1000
+
1001
+
Example:
1002
+
```
1003
+
tropic-pair
1004
+
OK
1005
+
```
1006
+
1007
+
### tropic-get-access-credential
1008
+
1009
+
Returns a cryptogram that encrypts and authenticates the Tropic pairing private key and authenticates the Tropic public key. The commands `secrets-init` and `secure-channel-handshake-2` must be executed before calling this command.
1010
+
1011
+
Example:
1012
+
```
1013
+
tropic-get-access-credential
1014
+
OK 03ca0e9d74ef59fa80a06161f3d2fceeb3e0c5e2db8182526d337aac78bad2d2ce4cacf05cdcd879843bcc43ed330199
1015
+
```
1016
+
1017
+
### tropic-get-fido-masking-key
1018
+
1019
+
Returns a cryptogram that encrypts and authenticates the FIDO masking key for the Tropic chip. The commands `secrets-init` and `secure-channel-handshake-2` must be executed before calling this command.
1020
+
1021
+
Example:
1022
+
```
1023
+
tropic-get-fido-masking-key
1024
+
OK dc106118a32feeef8d9211f54b9c8e9d571abe4cb104dc4ab087531cfee4574283ccf9c6f45e68be712f630d72d4999c
1025
+
```
1026
+
1027
+
### tropic-handshake
1028
+
1029
+
Establishes a secure channel with the Tropic chip. Expects a handshake request as input, returns a handshake response.
OK 09ad6ec70806318313c903094ae8fb63698051210dfa540ea7c7f7e588601dac478eee30432063964574879dee93250d8a5049
1034
+
```
1035
+
1036
+
### tropic-send-command
1037
+
1038
+
Sends a command to the Tropic chip and returns the response. The command `tropic-handshake` must be executed before calling this command.
1039
+
1040
+
Example:
1041
+
```
1042
+
tropic-send-command <hexadecimal string>
1043
+
OK <hexadecimal string>
1044
+
```
1045
+
1046
+
### tropic-certdev-read
1047
+
1048
+
Retrieves the X.509 certificate issued by the Trezor Company for the device attestation key stored in Tropic.
1049
+
1050
+
Example:
1051
+
```
1052
+
tropic-certdev-read
1053
+
OK <hexadecimal string>
1054
+
```
1055
+
1056
+
### tropic-certdev-write
1057
+
1058
+
Writes the X.509 certificate issued by the Trezor Company for the device attestation key stored in Tropic.
1059
+
1060
+
Example:
1061
+
```
1062
+
tropic-certdev-write <hexadecimal string>
1063
+
OK <hexadecimal string>
1064
+
```
1065
+
1066
+
### tropic-certfido-read
1067
+
1068
+
Retrieves the X.509 certificate issued by the Trezor Company for the FIDO attestation key stored in Tropic.
1069
+
1070
+
Example:
1071
+
```
1072
+
tropic-certfido-read
1073
+
OK <hexadecimal string>
1074
+
```
1075
+
1076
+
### tropic-certfido-write
1077
+
1078
+
Writes the X.509 certificate issued by the Trezor Company for the FIDO attestation key stored in Tropic.
1079
+
1080
+
Example:
1081
+
```
1082
+
tropic-certfido-write <hexadecimal string>
1083
+
OK <hexadecimal string>
1084
+
```
1085
+
1086
+
### tropic-lock
1087
+
1088
+
Configures the Tropic chip. This command is idempotent, meaning it can be called multiple times without changing the state of the device. This command is irreversible and cannot be undone. The command `tropic-pair` must be executed before calling this command.
1089
+
1090
+
Example:
1091
+
```
1092
+
tropic-lock
1093
+
OK <hexadecimal string>
1094
+
```
1095
+
1096
+
### secure-channel-handshake-1
1097
+
1098
+
Returns the first handshake message for establishing a secure channel between the device and HSM.
1099
+
1100
+
Example:
1101
+
```
1102
+
secure-channel-handshake-1
1103
+
OK 1e85285cbf805d0418be1f502a325806f68fa07c78fd63b7b960b2d0416f8b49
1104
+
```
1105
+
1106
+
### secure-channel-handshake-2
1107
+
1108
+
Establishes a secure channel between the device and HSM. Expects the second handshake message as input. The command `secure-channel-handshake-1` must be executed before calling this command.
Retrieves detailed information from the wireless power receiver, including chip identification, firmware version, configuration settings, and error status.
0 commit comments