[tpm2] NXP i.MX8X security co-processor?
Andy Purcell <andy_purcell at keysight.com>
| Newsgroups | dev.linux.lists.tpm2 |
|---|---|
| Message-ID | < <SA1PR17MB54320CDCC7FB67A6516DCC059FCF9@SA1PR17MB5432.namprd17.prod.outlook.com>> |
Hello, This is my first email to this tpm2 group and hope this is the right forum. I am investigating the security capabilities of NXP arm i.MX8X processor. This arm processor has a "security co-processor" but not an actual hardware TPM. I must determine if this chip, coupled with existing software (or minimal new software), can provide a software layer that functions like a real hardware TPM 2.0. The implementation must 1. Create a pair of asymmetric crypto keys (private, public) a. RSA 2048 bits (or better) b. Private key must exist in persisted secure storage - not visible, can never be exported 2. Be used to create an acceptable Certificate Signing Request suitable to send to a CA. 3. Provide a unique TPM Serial Number 4. Provide any necessary attestation 5. Run on Linux O/S Any advice/suggestions? AP
attachment.htm
(text/html, 1.7 KB)
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Exchange Server">
<!-- converted from rtf -->
<style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left: #800000 2px solid; } --></style>
</head>
<body>
<font face="Calibri" size="2"><span style="font-size:11pt;">
<div>Hello,</div>
<div> </div>
<div>This is my first email to this tpm2 group and hope this is the right forum. </div>
<div> </div>
<div>I am investigating the security capabilities of NXP arm i.MX8X processor. </div>
<div>This arm processor has a “security co-processor” but not an actual hardware TPM. </div>
<div> </div>
<div>I must determine if this chip, coupled with existing software (or minimal new software), can provide a software layer that functions like a real hardware TPM 2.0. </div>
<div> </div>
<div>The implementation must </div>
<ol style="margin:0;padding-left:36pt;list-style-type:decimal;">
<li>Create a pair of asymmetric crypto keys (private, public)</li></ol>
<ol style="margin:0;padding-left:72pt;list-style-type:lower-alpha;">
<li>RSA 2048 bits (or better)</li><li>Private key must exist in persisted secure storage – not visible, can never be exported </li></ol>
<ol start="2" style="margin:0;padding-left:36pt;list-style-type:decimal;">
<li>Be used to create an acceptable Certificate Signing Request suitable to send to a CA. </li><li>Provide a unique TPM Serial Number </li><li>Provide any necessary attestation</li><li>Run on Linux O/S </li></ol>
<div> </div>
<div>Any advice/suggestions? </div>
<div> </div>
<div>AP</div>
<div> </div>
<div> </div>
<div> </div>
</span></font>
</body>
</html>