[52416] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

RE: TPM & disk crypto

daemon@ATHENA.MIT.EDU (Kuehn, Ulrich)
Fri Oct 13 13:25:40 2006

X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
Date: Fri, 13 Oct 2006 16:19:55 +0200
in-reply-to: <452E89E6.9050000@solarsail.hcs.harvard.edu>
From: "Kuehn, Ulrich" <Ulrich.Kuehn@telekom.de>
To: <krstic@solarsail.hcs.harvard.edu>
Cc: <jamesd@echeque.com>, <cryptography@metzdowd.com>

> From: Ivan Krsti=E6 [mailto:krstic@solarsail.hcs.harvard.edu]=20
> Kuehn, Ulrich wrote:
> > Who is "we"? In the case of my own system I payed for (so=20
> speaking for=20
> > myself) I would like to have such a mechanism to have the=20
> system prove=20
> > to me before login that it is not tampered with. The TCG=20
> approach does=20
> > not provide this.
>=20
> What does "prove" mean here? Does having a hash of the system=20
> state for visual inspection before boot do it?
>=20
Well, reliably obtaining the end of a hash chain would do, but it would =
be very inconvenient to compare that manually (visually) to a hash =
written on a piece of paper in my wallet. That is not user-friendly. =
However, if the system provided a possibility to reliably stop the boot =
process when something is changed, that would do.

With reliably stopping the boot process I mean the following: Given that =
stage i of the process is running, it takes the hash of the next stage, =
compares that to an expected value. If they match, the current stage =
extends the TPM register (when also running the TCG stuff), and executes =
the next stage. If the computed and expected hashes do not match, the =
machine goes into a predetermined halt state.=20

Predetermined means that the system administrator (on behalf of the =
system owner) can determine the expected hash value.=20

I hope this makes it clear what I meant in the text quoted above.=20

To implement this the TCG-preBIOS would need to implement this halt =
state, possibly along with some other additional features like where to =
store the expected hashes etc.

Cheers,
Ulrich

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post