| поискавой системы для электроныых деталей |
|
ST33TPHF20SPI датащи(PDF) 23 Page - STMicroelectronics |
|
|
|||||||||||||||||||||||||||||
ST33TPHF20SPI датащи(HTML) 23 Page - STMicroelectronics |
|
23 / 47 page ![]() FIPS140-2 SECURITY POLICY Page 23 of 47 NON-PROPRIETARY DOCUMENT 3 ACCESS CONTROL POLICY This chapter gives details about the services, keys and CSPs that the TPM manages. 3.1 List of Keys and CSPs Table 17: Keys and CSPs list Keys/CSPs Description Zeroized Index Name Hierarchies 1 nullSeed 32 bytes primary seed values resp. for NULL, platform, endorsement and storage hierarchies. NullSeed is a random value generated by HDRBG at each TPM power-up. PpSeed / epSeed / spSeed are random values generated by HDRBG at first TPM power-up. They are used as keys for: KDFa to derive seedValue and sensitive during object creation (cf. [TPM2.0 Part1 r1.16] §27.6.4) KDFa to generate a symmetric encryption key used in TPM2B_PRIVATE structure en/decryption. KDFa to generate HMAC key used in TPM2B_PRIVATE integrity protection generation or verification They are used as seeds for: DRBG to generate random as input to prime numbers (RSA) and private key generation (ECC) TPM reset 2 ppSeed TPM2_Change PPS 3 epSeed TPM2_Change EPS 4 spSeed TPM2_Clear 5 nullProof 32 bytes secret values resp. for NULL, platform, endorsement and storage hierarchies. NullProof is a random value generated by HDRBG at each TPM power-up. PhProof / ehProof / shProof are random values generated by HDRBG at first TPM power-up. They are used as keys for: KDFa to generate context encryption key and IV (cf. [TPM2.0 Part1 r1.16] §30.3.1) HMAC to compute context blob integrity (cf. [TPM2.0 Part1 r1.16] §30.3.2) HMAC to compute/verify tickets shProof is used also as key for: KDFa to generate obfuscation value used in attestation commands (cf. [TPM2.0 Part1 r1.16] §36.7) TPM reset 6 phProof TPM2_Change PPS 7 ehProof TPM2_Clear 8 shProof TPM2_Clear 9 platformAuth 32 bytes authorization data (authValue) used in authorization session based resp. on platform, endorsement, and storage or lockout hierarchy authorization. PlatformAuth is set to 0 at each TPM2_Startup (CLEAR). EndorsementAuth / ownerAuth / lockoutAuth are set to 0 at first TPM power-up. Primary auth values can be changed with command TPM2_HierarchyChangeAuth. They are used as keys for: HMAC authorization in case of unsalted and unbound session KDFa to generate session key used in HMAC authorization in case of bound session They are used as part of keys for: HMAC authorization in case of salted or bound session (key is concatenation of sessionKey and authValue) KDFa to generate session key used in HMAC authorization in case of salted and bound session (key is concatenation of authValue and salt) TPM2_Startup 10 endorsementAuth TPM2_Clear / TPM2_Change EPS 11 ownerAuth TPM2_Clear 12 lockoutAuth TPM2_Clear |
|
ссылки URL |
| Вашему бизинису помогли Аллдатащит? [ DONATE ] |
Что такое Аллдатащит | реклама | контакт | Конфиденциальность | Ссылка на техническое описание | обмен ссыками | поиск по производителю All Rights Reserved©Alldatasheet.com |
| Russian : Alldatasheetru.com | Korean : Alldatasheet.co.kr | Spanish : Alldatasheet.es | French : Alldatasheet.fr | Italian : Alldatasheetit.com Portuguese : Alldatasheetpt.com | Polish : Alldatasheet.pl | Vietnamese : Alldatasheet.vn Indian : Alldatasheet.in | Mexican : Alldatasheet.com.mx | British : Alldatasheet.co.uk | New Zealand : Alldatasheet.co.nz |
|
Family Site : ic2ic.com |
icmetro.com |