Menu
Trusted Platform Module (TPM)

One of the best ways to keep your data secure is to encrypt it. Encryption involves the use of an encryption key, basically a huge number, that is used in a mathematical operation (called a cipher) performed on the original data. The encrypted result (called ciphertext) is unreadable to anyone who does not have the key used to encrypt it.

The problem with encryption is that the encryption key is vulnerable during the encrypting and decrypting stages of the operation. The TPM is an embedded security chip, usually installed on the motherboard, that stores encryption keys in a protected EEPROM. When the TPM stores encryption keys, it encrypts them so that they can be decrypted only by the TPM.

Because the TPM uses its own internal firmware and logic circuits for processing instructions, it is not exposed to operating system vulnerabilities.

TPM uses two classes of encryption keys: migratable and non-migratable. Migratable keys protect data that can be moved to another computer. If the user wants data restricted to a single computer, they can use a non-migratable encryption key.

TPM is initially disabled on a new PC. The user can enable TPM in the system's BIOS. In the BIOS screen select "Trusted Platform Module" and then select "Enable". Once TPM is enabled in the BIOS, a TPM management application should be setup, and the first task performed with this software should be to backup the encryption keys.

TPM Security Management Software

Several vendors provide TPM security management software. Wave Systems provides the Embassy Trust Suite, Dell provides the Control Point Security Manager, and Intel provides Active Management Technology.

These software provide such features as; list system devices and display their current security status, allow administrators to set login and document security, encrypt disks, and setup devices such as fingerprint readers and smart card controllers.

More information can be found in the Microsoft Technet article: Windows Trusted Platform Module Management Step-by-Step Guide


Learn more at amazon.com

More Windows Administration Information:
• Set Windows Defender to Scan Core Operating System Files
• Avoid the Indigestion of Cookies
• Beginner's Guide to Computer Forensics
• What is Phishing and How to Safeguard Against It
• No Software on the Market Removes All Spyware
• What is 2-Factor Authentication?
• Remove Spyware with Spybot - Search & Destroy
• How to Protect Yourself Against Keyloggers
• Root Kit - The Hackers Backdoor to Your Computer
• Beware The Many Forms of Ransomware