Wouldn’t that be the job of the software TCB to ensure only the appropriate user is given access (and prevent the user from accessing the TPM directly obviously)?
The TPM validates the state of the software TCB, and the software TCB validates the state of the lower layer, and so on.
> Wouldn’t that be the job of the software TCB to ensure only the appropriate user is given access (and prevent the user from accessing the TPM directly obviously)?
This only works with the current TPM design if there is one “appropriate user”.
The real world contains Chrome, BitLocker, various VMs and containers, etc. The TPM does not properly accommodate this world.