tpm: rename vendor data to priv and provide an accessor