Trusted Platform Module from Infineon

Nov 15, 2008 22 Replies

Snake oil or a good addition to a secure system?



"Trusted Platform Module from Infineon: hardware based security microcontroller that stores keys, passwords and digital certificates and protects this data from external software attacks and physical theft."



"TPM offers state-of-the-art security features, such as an active shielding that sends a continuous stream of random data over the surface of the chip. Apart from active shielding, the chip features the true random number generator (RNG), hardware accelerated RSA crypto algorithms with key lengths of up to 2,048 bit and hash algorithms required by the Trusted Computing Group specification."



"The basis for the Infineon TPM is the mature technology of the 66P secure controllers. In addition to the well proven, true random number generator and asymmetric RSA coprocessor (which was upgraded to 2048-bit key length) Infineon has realized the hash coprocessor (SHA-1 and MD5) and the LPC interface. Security measures such as active shielding, as well as frequency and temperature sensors, are part of the product just as they are in all the other 66P based products. This gives the Infineon TPM the highest level of security protection in the world."



"GIGABTE Ultra TPM provides an added layer of security by allowing users to store their digital signature key on a USB thumb drive, so when they step away from their system, they can take the key with them, locking up their data and preventing unauthorized access while they are away. (Optional backup of key stored in BIOS in case of misplaced key.)"


formatting link
formatting link
formatting link
formatting link
formatting link
formatting link
formatting link
formatting link
formatting link



It should be well-known by now that while well-designed TPMs and similar hardware can protect your keys from theft, they cannot in general prevent misuse.

This may or may not be valuable, depending on your threat model. For me, I mostly care about preventing misuse of keys. In theory, I do that by not allowing attackers access to my computers.

A more interesting use of TPMs is to give the system designer control over your system _after_ you've bought it, preventing you from tampering with it. This application is attractive for some, though strangely seldom for the system owner.

Kristian Gjøsteen

TPM is bad all the way around. I can secure my own system, thank you. Some people will be fooled into thinking their computer is being protected FOR them, but in reality, it is FROM them. TPM is against privacy, against anonymity, and against democracy, a way of making users put on their own handcuffs to which someone else keeps the key.

formatting link

"These chips are part of the PC hardware, permanently assigning a unique identifier to each computer, and theoretically permitting virtually fool-proof verification of your identity to other computers on the internet."

I'll stick with old Pentium II's before I use a new computer crippled with that junk. You no longer own the computer hardware that you paid for - the people selling it to you do because *they* decide what you can and can't do with it. Add in the work being done on "IP Traceback" and you can see where we're going with this: who sent what where, and who exactly was talking to who.

Freedom? [** America, The Police State **] Rights? Privacy? In a shocking twist of fate, our once great country is now ... ... a police state! http://www.hermes-press.com/police_state.htm finger jayjwa at host atr2.ath.cx ===============================

The specs

formatting link
make for an interesting read (IMHO). Its full of interesting notions, although the spec itself can be hard to decipher.

By itself it does nothing, but it seems it is designed to cover a lot of different security scenarios - including the scary ones where you dont "own" your computer anymore, but also the more useful ones where nobody can set a trojan in your BIOS, bootloader or such.

It all depends on who controls the TPM. If you are the TPM's owner (meaning that it's you the one who has the owner's authorization data) then you are in control.

What does the owner's authorization get you?

Assume for the moment that the TPM is being used by an application to store the keys for some copyrighted content. The application wants to enforce a limited number of plays, and an expiration date. It also wants to make sure that the OS hasn't been patched to log traffic to the sound and video hardware. As I understand it, this is one of the things the TPM is supposed to be able to do (hide data from the owner against his interests in favor of the interests of the copyright holder).

Does having owner's authorization allow you to see those keys anyway? If so, I wonder what the point is. Does having owner's authorization at least let me see what stuff has been put in there (not the content

- just a directory of license keys & whatnot) and allow me to delete excess junk? (I'm sure there *is* an error for "TPM is full").

In that case the owner of the computer is not the owner of the TPM. This has been the core of the debate around the devices like TPM. Without rehashing the entire debate, there are valid points on both sides. At the core TPM is just a tool, very much like a hammer, a hammer it can either build a house, or take a life, I'll leave the rest to the reader, but we don't ban hammers, but we also actually own them. Joe

Well, maybe that was the intent, but my bet is that there's going to be at least one user out there who manages to become the owner of his own TPM. It might even be someone with access to a chip design facility, or who works for the manufacturer.

Does the application know who owns the TPM? If it trusts the TPM owned by the user, it sounds like it's going to give away the farm, and there's a good chance the keys will be posted on the Internet.

There's also the problem that there are multiple sets of content providers and they don't all trust each other.

You can usually use someone else's hammer without too much worry that it will only hit nails belonging to the owner of the hammer.

Damn good explanation, Joe.

http://www.youtube.com/watch?v=fJVydzNJrno

snipped-for-privacy@burditt.org (Gordon Burditt) wrote in news:GbqdnePe5IJJ6r_UnZ2dnUVZ snipped-for-privacy@posted.internetamerica:

That one's a keeper - I shall quote it frequently (without attribution, of course :-)

Ross Anderson, Professor of Security Engineering at Cambridge University?s Computer Laboratory, has been quite vocal on the real implications of TPM (under whichever of many names that have been used to disguise its malevolence). Essentially, he says, "[TPM] transfers the ultimate control of your PC from you to whoever wrote the software it happens to be running." While somewhat dated, Anderson's Trusted Computing [TPM] FAQ still addresses many of the key points.

formatting link

Regards,

Note that it's not entirely a joke. There's a real issue that missiles may refuse to target friends of the manufacturer's country, even if the buyer of said missiles doesn't know that.

snipped-for-privacy@burditt.org (Gordon Burditt) wrote in news:dJOdndSlgfmmt77UnZ2dnUVZ snipped-for-privacy@posted.internetamerica:

One of the few remaining supports to morale against abject despair is cynical black humour.

Regards,

When you swing your hammer, it doesn't say to you, "Sorry, you're not allowed to drive spikes, only finishing nails" ... "only 10 per day" ... "Only nails bought from WalMart allowed" ... "You can't lend me to your co-worker" ... "your 20 usage days are up, self-destructing in 10 seconds"

We also aren't forced to install hammers when we ask for paint brushes. TPM is not being tacked on to benefit you, the purchaser and owner, it's being tacked on to retain after-purchase control. Soon, if TPM proponents have their way, and I'm sure they will because the public at large never complains about anything until after it's choking off their last life breath, you'll have a very hard time finding a system without TPM installed in it (think - go search eBay for your new PC, or perhaps a garage sale). Then comes the noncompatibility issues for those of us that run alterative operating systems that won't bend over for TPM like Windows surely will. At that point, it becomes a matter of w/TPM or do without, and TPM will be just tolerable enough most average users will put up with it. Look at the iPhone - people are tripping over themselves to get one.

formatting link

formatting link

Freedom? [** America, The Police State **] Rights? Privacy? In a shocking twist of fate, our once great country is now ... ... a police state! http://www.hermes-press.com/police_state.htm finger jayjwa at host atr2.ath.cx ===============================

What if you rented the hammer from a tool rental places? Then, in fact, your rental agreement probably does say you can't lend the hammer to anyone else.

Nonsense. If you aren't using Windows, you install the free, GPLed TPM drivers that have been available for Linux for years, if you want to use something that requires TPM.

--Tim Smith

It sounds like you have confused TPM with DRM. Everything you write above is true of DRM, but has little or nothing to do with TPM.

The above URL referenced DRM nine times, never mentions TPM.

And this one talks only about DRM. not mentioning TPM.

snipped-for-privacy@privacy.net wrote in news:r-qdnUvmguC4SLjURVn snipped-for-privacy@giganews.com:

If so, he has not erred by much. It is matter of means and ends. DRM is the end, TPM the means.

In fact, the ends are broader and more malevolent than just DRM, but this alone suffices to illuminate the thrust of TPM. TPM is, in fine, deeply inimical to users' interests.

Regards,

Good start. This means it depends on how the product is positioned in the marketplace. This normally will mean that to get profitable volumes, the primary target is likely to be corporate IT departments supporting laptops. Thus IT will end up "owning" executives. It may very well get over for a while on just this aspect alone.

Another damn optimist. The evil goes much farther than that, prole.

Thank you, it is intentionally vague and broad in that way precisely to make possible the ever so delicately deceptive marketing of TPM.

Sure, I'll bet Sony, Microsoft, and the others are working hard right now to make their stuff work well with Linux's TPM. What is the point to having something locked if you get to make your own locks? TPM is not for your benefit. If it is, I'll bet you think copy protect is as well...

Freedom? [** America, The Police State **] Rights? Privacy? In a shocking twist of fate, our once great country is now ... ... a police state! http://www.hermes-press.com/police_state.htm finger jayjwa at host atr2.ath.cx ===============================

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required