Trusted Platform Module (TPM)
🚧 Documentation is under development
The RidgeRun Platform Security Manual guide is currently under active development. Some sections may be incomplete or change without notice.
Questions? Contact RidgeRun or email to support@ridgerun.com.
- Introduction
- General Security Concepts
- Getting Started
- Contact Us
- Sponsor your Favorite Feature
Trusted Platform Module
The Trusted Platform Module, more commonly known as a TPM, is a security component designed to enhance the security of a system. A TPM is a secure cryptoprocessor that provides hardware-protected functions for cryptographic operations, key management, and platform integrity.
Some common uses of a TPM include:
- Generating and securely storing cryptographic keys.
- Providing device identity and authentication using keys protected by the TPM.
- Helping verify platform integrity by recording security measurements taken during the boot process.
During the boot process, software and configuration data can be measured to provide information about the state of the system. In this context, measuring typically means computing a cryptographic hash of a component before it is loaded or executed and recording that measurement in the TPM's Platform Configuration Registers (PCRs).
This process is known as Measured Boot. The collected measurements can later be used to determine whether the system booted with the expected software and configuration.
It is important to understand that Measured Boot does not normally prevent a system from booting in the same way that Secure Boot can prevent unauthorized software from executing. Instead, it records measurements that can later be evaluated locally or remotely to determine the state of the system.
The TPM protects the integrity of these measurements by storing them in its PCRs, where measurements are extended rather than simply overwritten. This makes the resulting PCR values dependent on the sequence of measurements taken during the boot process.
Here, the concept of attestation comes into play. Attestation can be defined as the process of providing evidence about the state or identity of a system so that another party can evaluate whether it can be trusted. In the context of embedded system security, attestation can use measurements collected during the boot process to provide evidence about the software and configuration state of a system.
While discrete TPMs are a common implementation, other types of TPMs can also provide functionality defined by the Trusted Computing Group (TCG) specifications. Common TPM implementations include:
- Discrete TPMs (dTPMs): Dedicated hardware chips that implement TPM functionality in a separate semiconductor package. Because the TPM operates independently from the main processor and operating system, it can provide strong isolation for cryptographic operations and protected key material. Some discrete TPMs also include physical tamper-resistance features and may be certified according to applicable security standards.
- Integrated TPMs (iTPMs): TPM functionality integrated into another hardware component rather than implemented as a separate chip. They provide hardware-based protection but may offer different levels of physical isolation and tamper resistance compared with discrete TPMs.
- Firmware TPMs (fTPMs): Firmware-based implementations that typically execute within a hardware-protected environment, such as a Trusted Execution Environment (TEE). Their security therefore depends partly on the isolation and security mechanisms provided by the underlying platform.
- Virtual TPMs (vTPMs): Virtualized TPM implementations commonly used with virtual machines. They provide TPM functionality to a guest environment while relying on the hypervisor and underlying platform to provide isolation and protection.
- Software TPMs: Software implementations or emulators of TPM functionality that execute within a conventional software environment. Because they do not provide the same hardware-backed isolation as hardware or firmware TPM implementations, they are primarily useful for development, testing, and simulation.
The following table compares different TPM implementations. Source: Trusted Computing Group, TPM 2.0: A Brief Introduction.
| Trust Element | Security Levels | Security Features | Relative Cost | Typical Application |
|---|---|---|---|---|
| Discrete TPM | Highest | Tamper resistant hardware | $$$ | Critical Systems |
| Integrated TPM | Higher | Hardware | $$ | Gateways |
| Firmware TPM | High | TEE | $ | Entertainment systems |
| Software TPM | N/A | N/A | $$ | Testing and prototyping |
| Virtual TPM | High | Hypervisor | $ | Cloud environment |