[tpm2] Re: How to store AES key inside the TPM and then use it?

Roberts, William C <william.c.roberts at intel.com>
Newsgroups dev.linux.lists.tpm2
Message-ID <DM6PR11MB34344426CB816F97BE19468EB82C9@DM6PR11MB3434.namprd11.prod.outlook.com>
Intel TPM's support AES, but it's not widely available in other TPM's. It's better to "seal" the key to the TPM and then "unseal"
it as you need it and use it in software crypto. See "Seal Data to the TPM" in examples: https://tpm2-tools.readthedocs.io/en/stable/man/tpm2_create.1/

Bill
________________________________
From: Steven Clark <davolfman(a)gmail.com>
Sent: Wednesday, February 2, 2022 12:07 PM
To: Gabriele Saturni <gabriele.saturni(a)wsense.it>
Cc: tpm2 <tpm2(a)lists.01.org>
Subject: [tpm2] Re: How to store AES key inside the TPM and then use it?

As far as I know, no one produces a TPM with bulk symmetric encryption features.  It would be both slow and likely to have export law problems.

On Wed, Feb 2, 2022, 9:32 AM Gabriele Saturni <gabriele.saturni(a)wsense.it<mailto:gabriele.saturni(a)wsense.it>> wrote:
Hi to everybody,
I'm pretty new to the TPM and looking for a way to store a premade AES key inside the TPM and retrieve it for encrypting the data of my application. Is there any way to do it since a lot of TPM does not support AES ?

Thank you for your time
_______________________________________________
tpm2 mailing list -- tpm2(a)lists.01.org<mailto:tpm2(a)lists.01.org>
To unsubscribe send an email to tpm2-leave(a)lists.01.org<mailto:tpm2-leave(a)lists.01.org>
%(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s
attachment.htm (text/html, 2.9 KB)
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Intel TPM's support AES, but it's not widely available in other TPM's. It's better to &quot;seal&quot; the key to the TPM and then &quot;unseal&quot;</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
it as you need it and use it in software crypto. See &quot;Seal Data to the TPM&quot; in examples:&nbsp;<a href="https://tpm2-tools.readthedocs.io/en/stable/man/tpm2_create.1/" id="LPNoLPOWALinkPreview">https://tpm2-tools.readthedocs.io/en/stable/man/tpm2_create.1/</a></div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="_Entity _EType_OWALinkPreview _EId_OWALinkPreview _EReadonly_1"></div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Bill</div>
<div id="appendonsend"></div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> Steven Clark &lt;[email protected]&gt;<br>
<b>Sent:</b> Wednesday, February 2, 2022 12:07 PM<br>
<b>To:</b> Gabriele Saturni &lt;[email protected]&gt;<br>
<b>Cc:</b> tpm2 &lt;[email protected]&gt;<br>
<b>Subject:</b> [tpm2] Re: How to store AES key inside the TPM and then use it?</font>
<div>&nbsp;</div>
</div>
<div>
<div dir="auto">As far as I know, no one produces a TPM with bulk symmetric encryption features.&nbsp; It would be both slow and likely to have export law problems.</div>
<br>
<div class="x_gmail_quote">
<div dir="ltr" class="x_gmail_attr">On Wed, Feb 2, 2022, 9:32 AM Gabriele Saturni &lt;<a href="mailto:[email protected]">[email protected]</a>&gt; wrote:<br>
</div>
<blockquote class="x_gmail_quote" style="margin:0 0 0 .8ex; border-left:1px #ccc solid; padding-left:1ex">
<div dir="ltr">
<div>Hi to everybody,<br>
</div>
<div>I'm pretty new to the TPM and looking for a way to store a premade AES key inside the TPM and retrieve it for encrypting the data of my application. Is there any way to do it since a lot of TPM does not support AES ?</div>
<div><br>
</div>
<div>Thank you for your time</div>
</div>
_______________________________________________<br>
tpm2 mailing list -- <a href="mailto:[email protected]" target="_blank" rel="noreferrer">
[email protected]</a><br>
To unsubscribe send an email to <a href="mailto:[email protected]" target="_blank" rel="noreferrer">
[email protected]</a><br>
%(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s</blockquote>
</div>
</div>
</body>
</html>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.