作者: Ryan Charles Catherman , David Carroll Challener , James Patrick Hoff
DOI:
关键词:
摘要: A method and system for ensuring security-compliant creation signing of endorsement keys manufactured TPMs. The are generated the TPM. TPM vendor selects an N-byte secret stores in along with keys. number cannot be read outside is also provided to OEM's credential server. During key (EK) process, generates key, which comprises both public a hash key. server matches within second received (from key) secret. EK certificate inserted into only when match confirmed.