[tpm2] NXP i.MX8X security co-processor?

Andy Purcell <andy_purcell at keysight.com>
Newsgroups dev.linux.lists.tpm2
Message-ID < <SA1PR17MB54320CDCC7FB67A6516DCC059FCF9@SA1PR17MB5432.namprd17.prod.outlook.com>>
Hello,

This is my first email to this tpm2 group and hope this is the right forum.

I am investigating the security capabilities of NXP arm i.MX8X processor.
This arm processor has a "security co-processor" but not an actual hardware TPM.

I must determine if this chip, coupled with existing software (or minimal new software), can provide a software layer that functions like a real hardware TPM 2.0.

The implementation must
1.      Create a pair of asymmetric crypto keys (private, public)
a.      RSA 2048 bits (or better)
b.      Private key must exist in persisted secure storage - not visible, can never be exported
2.      Be used to create an acceptable Certificate Signing Request suitable to send to a CA.
3.      Provide a unique TPM Serial Number
4.      Provide any necessary attestation
5.      Run on Linux O/S

Any advice/suggestions?

AP
attachment.htm (text/html, 1.7 KB)
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Exchange Server">
<!-- converted from rtf -->
<style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left: #800000 2px solid; } --></style>
</head>
<body>
<font face="Calibri" size="2"><span style="font-size:11pt;">
<div>Hello,</div>
<div>&nbsp;</div>
<div>This is my first email to this tpm2 group and hope this is the right forum. </div>
<div>&nbsp;</div>
<div>I am investigating the security capabilities of NXP arm i.MX8X processor. </div>
<div>This arm processor has a &#8220;security co-processor&#8221; but not an actual hardware TPM. </div>
<div>&nbsp;</div>
<div>I must determine if this chip, coupled with existing software (or minimal new software), can provide a software layer that functions like a real hardware TPM 2.0. </div>
<div>&nbsp;</div>
<div>The implementation must </div>
<ol style="margin:0;padding-left:36pt;list-style-type:decimal;">
<li>Create a pair of asymmetric crypto keys (private, public)</li></ol>
<ol style="margin:0;padding-left:72pt;list-style-type:lower-alpha;">
<li>RSA 2048 bits (or better)</li><li>Private key must exist in persisted secure storage &#8211; not visible, can never be exported </li></ol>
<ol start="2" style="margin:0;padding-left:36pt;list-style-type:decimal;">
<li>Be used to create an acceptable Certificate Signing Request suitable to send to a CA. </li><li>Provide a unique TPM Serial Number </li><li>Provide any necessary attestation</li><li>Run on Linux O/S </li></ol>
<div>&nbsp;</div>
<div>Any advice/suggestions? </div>
<div>&nbsp;</div>
<div>AP</div>
<div>&nbsp;</div>
<div>&nbsp;</div>
<div>&nbsp;</div>
</span></font>
</body>
</html>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.