Skip to main content

TPM driver

discrete TPM module seated on its board header, three-quarter view shown with

The TPM driver connects Windows to the Trusted Platform Module, letting BitLocker seal keys to Platform Configuration Registers and satisfying the Windows 11 TPM 2.0 requirement.

At a Glance

Hardware Familysystem storage
Categorytpm
OSwin11, win10
VendorsInfineon, Nuvoton, STMicroelectronics

Hardware identification

tight crop on the TPM module and header pins

tight crop on the TPM module and header pins

Reference overview

The device role, software boundary, and compatibility concepts covered on this page.

Device class

A tpm driver belongs to the TPM hardware category. Examples are associated with Infineon, Nuvoton, STMicroelectronics hardware.

What it controls

The TPM driver connects Windows to the Trusted Platform Module, letting BitLocker seal keys to Platform Configuration Registers and satisfying the Windows 11 TPM 2.0 requirement.

Topics in this reference

  • • Hardware and operating-system boundary
  • • Protocols and component architecture
  • • Observable device states
  • • Platform compatibility terminology

What this driver does

A Trusted Platform Module is a small, isolated cryptographic processor with its own protected storage. It performs a fixed menu of security operations: generating and storing keys that never leave the chip, hashing boot measurements, and signing attestation statements that prove what code the machine booted. The TPM driver, tpm.sys in Windows, is the transport that carries commands and responses between the OS and that processor over the TPM's command interface. The module comes in three physical forms, and the driver abstracts all of them. A discrete TPM (dTPM) is a dedicated chip soldered to the board or on a header. Intel PTT and AMD fTPM are firmware TPMs, running the same TPM 2.0 command set inside a protected mode of the CPU rather than in separate silicon. To Windows they look alike, because the driver presents one standard interface regardless of the underlying implementation. The module's most-used feature is measured boot. As each stage of the boot chain runs, its hash is extended into a Platform Configuration Register, a PCR, producing a chain of values that uniquely reflects the code path taken. BitLocker seals its volume key to a chosen set of PCRs, so the key is released only when the machine boots the exact configuration it was sealed against, which is what ties disk encryption to boot integrity. The TPM also anchors identity and attestation. It holds an Endorsement Key burned in at manufacture, derives an attestation identity key, and can sign a quote of its PCR state for a remote verifier. Windows uses these for device health attestation and for anti-cheat and enterprise scenarios that demand proof the machine is in a known-good state, all mediated through the same driver.

Close-up view of tpm driver hardware and its main physical components
TPM driver connected wirelessly and physically to typical peripherals in its ecosystem

Observable states associated with this device class

These states describe how hardware, firmware, operating-system services, and a driver can interact. They do not identify a cause on their own.

  • BitLocker demands its 48-digit recovery key on every boot even though the disk and hardware are unchanged
  • AMD fTPM causes brief, repeating stutters or audio dropouts during gaming or heavy I/O
  • Windows 11 setup reports the PC is unsupported because no TPM 2.0 is detected
  • The security processor shows a yellow triangle or 'device cannot start' in Device Manager
  • An anti-cheat system refuses to launch a game, citing a missing or non-compliant TPM 2.0
  • tpm.msc reports the TPM is not ready, or shows a 1.2 module where 2.0 is expected

How it works in a real system

Drivers operate in the background as translators. This setup shows the software, connection, and physical hardware that the TPM driver supports.

A real-world tpm driver setup with its supporting software and hardware

Compatibility model

Driver compatibility is defined by the device hardware identifier, the operating-system driver model, processor architecture, and the interfaces implemented by the hardware or firmware. A shared device class does not imply that packages from different manufacturers are interchangeable.

Vendor Comparison
Operating-system contextArchitecture notes
Windows 11The Windows 11 driver model is primarily 64-bit. Actual compatibility depends on the device hardware ID, processor architecture, firmware interface, and package signature.
Windows 10Windows 10 exists in multiple releases and architectures. Actual compatibility depends on the device hardware ID, Windows release, processor architecture, and package signature.