Re: [PATCH 1/4] integrity: TPM internel kernel interface

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Alan Cox <alan@...>
Cc: <linux-kernel@...>, <linux-security-module@...>
Date: Wednesday, August 13, 2008 - 12:39 pm

Alan Cox <alan@lxorguk.ukuu.org.uk> wrote on 08/13/2008 09:40:40 AM:


Replacing with alternative hardware is outside the attack model.  For this
use case, the TCG assumes the user will not be attacking himself.

Replacing with software is a valid remote attack.  It will be detected
through the TCG platform measurement process.  The local defense is
"sealing" data to trusted measurements.  The remote defense is
"attestation" or "quote", getting signed measurements and deciding
whether to trust them.


The TPM main specification (design principles) discusses measurements,>
reporting, attestation, and so on.

The "TCG PC Client Specific Implementation Specification For Conventional
BIOS" is specific to the PC platform (there are specifications for mobile
devices, printers, storage, etc.) but section 1.2 has a good discussion
of the concepts.

https://www.trustedcomputinggroup.org/home

(Feel free to email me privately if this is becoming off topic for the
mailing list.)

--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: [PATCH 1/4] integrity: TPM internel kernel interface, Christoph Hellwig, (Sat Aug 9, 2:46 pm)
Re: [PATCH 1/4] integrity: TPM internel kernel interface, Christoph Hellwig, (Tue Aug 12, 3:30 pm)
Re: [PATCH 1/4] integrity: TPM internel kernel interface, Kenneth Goldman, (Tue Aug 12, 4:57 pm)
Re: [PATCH 1/4] integrity: TPM internel kernel interface, Kenneth Goldman, (Mon Aug 18, 11:01 am)
Re: [PATCH 1/4] integrity: TPM internel kernel interface, Peter Dolding, (Fri Aug 15, 6:37 am)
Re: [PATCH 1/4] integrity: TPM internel kernel interface, Kenneth Goldman, (Fri Aug 15, 2:50 pm)
Re: [PATCH 1/4] integrity: TPM internel kernel interface, Kenneth Goldman, (Wed Aug 13, 9:58 am)
Re: [PATCH 1/4] integrity: TPM internel kernel interface, Kenneth Goldman, (Wed Aug 13, 9:46 am)
Re: [PATCH 1/4] integrity: TPM internel kernel interface, Kenneth Goldman, (Wed Aug 13, 12:39 pm)
Re: [PATCH 1/4] integrity: TPM internel kernel interface, Christoph Hellwig, (Wed Aug 13, 10:45 am)