Back to Search Start Over

How To Bind A TPM's Attestation Keys With Its Endorsement Key.

Authors :
Chen, Liqun
Kassem, Nada El
Newton, Christopher J P
Source :
Computer Journal. Mar2024, Vol. 67 Issue 3, p988-1004. 17p.
Publication Year :
2024

Abstract

A trusted platform module is identified by its endorsement key, while it uses an attestation key to provide attestation services, for example, signing a set of platform configuration registers, providing a timestamp or certifying another of its keys. This paper addresses the problem of how a certificate authority binds the endorsement and attestation keys together. This is necessary for the authority to be able to reliably certify the attestation key. This key binding also enables the authority to revoke the attestation key should the endorsement key be compromised. We study all of the existing solutions and show that they either do not solve the problem or cannot be implemented with a real trusted platform module (or both). We propose a new solution which addresses this problem. We develop a security model for our solution and provide a rigorous security proof under this model. We have also implemented the solution using a real trusted platform module, and our implementation results show that this solution is feasible and efficient. [ABSTRACT FROM AUTHOR]

Details

Language :
English
ISSN :
00104620
Volume :
67
Issue :
3
Database :
Academic Search Index
Journal :
Computer Journal
Publication Type :
Academic Journal
Accession number :
176726134
Full Text :
https://doi.org/10.1093/comjnl/bxad037