[tpm2] Re: How to store AES key inside the TPM and then use it?
Gabriele Saturni <gabriele.saturni at wsense.it>
| Newsgroups | dev.linux.lists.tpm2 |
|---|---|
| Message-ID | <CAFruog32AO9iLzRgOp4wD_2qQnV3nTHCwxJdPFCNywiZrK--jQ@mail.gmail.com> |
Thanks for the answers, basing on your experiences, since I have storage available outside the TPM, which of the two proposed approaches is the best (in terms of both security and efficiency)? Il giorno gio 3 feb 2022 alle ore 04:27 Steven Clark <davolfman(a)gmail.com> ha scritto: > For small data it's also possible to store it sealed as a "keyedhash" and > put it in one of the NVM "persistent object" locations as if it's key. > > On Wed, Feb 2, 2022, 1:06 PM Kenneth Goldman <kgoldman(a)us.ibm.com> wrote: > >> There are two ways. Note that, since you're encrypting outside the TPM, >> the 'key' is just a byte stream to the TPM. >> >> >> >> 1. If you have storage available, create the key as sealed data using >> 'create'. Retrieve the key with 'unseal', with application specific >> authorization for the unseal operation. >> 2. If you have no external storage available, create the key as an NV >> index using NVdefinespace. Retrieve the key using NV read, again with >> application specific authorization for the read. >> >> >> >> *From:* Gabriele Saturni <gabriele.saturni(a)wsense.it> >> *Sent:* Wednesday, February 2, 2022 12:31 PM >> *To:* tpm2(a)lists.01.org >> *Subject:* [EXTERNAL] [tpm2] How to store AES key inside the TPM and >> then use it? >> >> >> >> Hi to everybody, I'm pretty new to the TPM and looking for a way to store >> a premade AES key inside the TPM and retrieve it for encrypting the data of >> my application. Is there any way to do it since a lot of TPM does not >> support AES ? ZjQcmQRYFpfptBannerStart >> >> Hi to everybody, >> >> I'm pretty new to the TPM and looking for a way to store a premade AES >> key inside the TPM and retrieve it for encrypting the data of my >> application. Is there any way to do it since a lot of TPM does not support >> AES ? >> >> >> >> Thank you for your time >> _______________________________________________ >> tpm2 mailing list -- tpm2(a)lists.01.org >> To unsubscribe send an email to tpm2-leave(a)lists.01.org >> %(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s > > -- Gabriele Saturni, PhD R&D Developer, WSense Srl E-mail: gabriele.saturni(a)wsense.it <giovanni.pagnotta(a)wsense.it> WSense Srl web site: https://www.wsense.it/ This message is confidential. Any unauthorised disclosure, use or dissemination, either whole or partial, is prohibited. If you are not the intended recipient of the message, please notify the sender immediately. Questo messaggio e riservato;Qualsiasi pubblicazione, utilizzo o diffusione, anche parziale di questo messaggio, deve essere preventivamente autorizzata. Nel caso in cui non foste destinatari del presente messaggio,vogliate cortesemente avvertire immediatamente il mittente. Ce message est confidentiel. Toute publication, utilisation ou diffusion, meme partielle, doit etre autorisee prealablement. Si vous n' etes pas destinataire de ce message, merci d'en avertir immediatement l'expediteur.
attachment.htm
(text/html, 5.2 KB)
<div dir="ltr">Thanks for the answers, basing on your experiences, since I have storage available outside the TPM, which of the two proposed approaches is the best (in terms of both security and efficiency)?<br></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">Il giorno gio 3 feb 2022 alle ore 04:27 Steven Clark <<a href="mailto:[email protected]" target="_blank">[email protected]</a>> ha scritto:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="auto">For small data it's also possible to store it sealed as a "keyedhash" and put it in one of the NVM "persistent object" locations as if it's key.</div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, Feb 2, 2022, 1:06 PM Kenneth Goldman <<a href="mailto:[email protected]" target="_blank">[email protected]</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"> <div lang="EN-US"> <div> <p class="MsoNormal">There are two ways. Note that, since you're encrypting outside the TPM, the 'key' is just a byte stream to the TPM.<u></u><u></u></p> <p class="MsoNormal"><u></u> <u></u></p> <ol style="margin-top:0in" type="1" start="1"> <li style="margin-left:0in">If you have storage available, create the key as sealed data using 'create'. Retrieve the key with 'unseal', with application specific authorization for the unseal operation.<u></u><u></u></li><li style="margin-left:0in">If you have no external storage available, create the key as an NV index using NVdefinespace. Retrieve the key using NV read, again with application specific authorization for the read.<u></u><u></u></li></ol> <p class="MsoNormal"><u></u> <u></u></p> <div> <div style="border-color:rgb(225,225,225) currentcolor currentcolor;border-style:solid none none;border-width:1pt medium medium;padding:3pt 0in 0in"> <p class="MsoNormal" style="margin-left:0.5in"><b>From:</b> Gabriele Saturni <<a href="mailto:[email protected]" rel="noreferrer" target="_blank">[email protected]</a>> <br> <b>Sent:</b> Wednesday, February 2, 2022 12:31 PM<br> <b>To:</b> <a href="mailto:[email protected]" rel="noreferrer" target="_blank">[email protected]</a><br> <b>Subject:</b> [EXTERNAL] [tpm2] How to store AES key inside the TPM and then use it?<u></u><u></u></p> </div> </div> <p class="MsoNormal" style="margin-left:0.5in"><u></u> <u></u></p> <p class="MsoNormal" style="margin-left:0.5in"><span><span style="font-size:1pt;color:white">Hi to everybody, I'm pretty new to the TPM and looking for a way to store a premade AES key inside the TPM and retrieve it for encrypting the data of my application. Is there any way to do it since a lot of TPM does not support AES ? </span></span><span style="font-size:1pt;color:white">ZjQcmQRYFpfptBannerStart</span> <u></u><u></u></p> <div> <div> <p class="MsoNormal" style="margin-left:0.5in">Hi to everybody,<u></u><u></u></p> </div> <div> <p class="MsoNormal" style="margin-left:0.5in">I'm pretty new to the TPM and looking for a way to store a premade AES key inside the TPM and retrieve it for encrypting the data of my application. Is there any way to do it since a lot of TPM does not support AES ?<u></u><u></u></p> </div> <div> <p class="MsoNormal" style="margin-left:0.5in"><u></u> <u></u></p> </div> <div> <p class="MsoNormal" style="margin-left:0.5in">Thank you for your time<u></u><u></u></p> </div> </div> </div> </div> _______________________________________________<br> tpm2 mailing list -- <a href="mailto:[email protected]" rel="noreferrer" target="_blank">[email protected]</a><br> To unsubscribe send an email to <a href="mailto:[email protected]" rel="noreferrer" target="_blank">[email protected]</a><br> %(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s</blockquote></div> </blockquote></div><br clear="all"><br>-- <br><div dir="ltr"><div dir="ltr"><div>Gabriele Saturni, PhD<br></div><div><div dir="ltr">R&D Developer, WSense Srl<br>E-mail: <a href="mailto:[email protected]" target="_blank">[email protected]</a><br></div><div dir="ltr">WSense Srl web site: <a href="https://www.wsense.it/" rel="noreferrer" style="color:rgb(17,85,204)" target="_blank">https://www.wsense.it/</a></div></div><div><br></div><div><div>This message is confidential. Any unauthorised disclosure, use or dissemination, either whole or partial, is prohibited. If you are not the intended recipient of the message, please notify the sender immediately.</div><div><div><br></div><div>Questo messaggio e riservato;Qualsiasi pubblicazione, utilizzo o diffusione, anche parziale di questo messaggio, deve essere preventivamente autorizzata. Nel caso in cui non foste destinatari del presente messaggio,vogliate cortesemente avvertire immediatamente il mittente. <br><br>Ce message est confidentiel. Toute publication, utilisation ou diffusion, meme partielle, doit etre autorisee prealablement. Si vous n' etes pas destinataire de ce message, merci d'en avertir immediatement l'expediteur.</div></div></div></div></div>