Arshad Noor
2016-02-17 22:09:18 UTC
Hi,
I had a question on whether a specific capability exists on the TPM -
1.2 or 2.0; hopefully, its an easy answer.
Assuming a TPM has been initialized with the following key-hierarchy:
+-------+
| SRK |
+-------+
|
|
+-------------+
| Storage Key |
+-------------+
|
|
+-------------------------------+
| Some symmetric key (AES/TDES) |
+-------------------------------+
|
+---------------+
| |
+-------------------------+ +-------------------------+
| Some encrypted secret-1 | | Some encrypted secret-2 |
+-------------------------+ +-------------------------+
Is there a mechanism to send secrets (1 and 2) into the TPM (with the
encrypted symmetric key) so the encrypted-key and the secrets are
decrypted inside AND the two plaintext secrets compared inside the
TPM with just a boolean result coming out: True for a match, False
otherwise.
Thanks in advance.
Arshad Noor
StrongAuth, Inc.
I had a question on whether a specific capability exists on the TPM -
1.2 or 2.0; hopefully, its an easy answer.
Assuming a TPM has been initialized with the following key-hierarchy:
+-------+
| SRK |
+-------+
|
|
+-------------+
| Storage Key |
+-------------+
|
|
+-------------------------------+
| Some symmetric key (AES/TDES) |
+-------------------------------+
|
+---------------+
| |
+-------------------------+ +-------------------------+
| Some encrypted secret-1 | | Some encrypted secret-2 |
+-------------------------+ +-------------------------+
Is there a mechanism to send secrets (1 and 2) into the TPM (with the
encrypted symmetric key) so the encrypted-key and the secrets are
decrypted inside AND the two plaintext secrets compared inside the
TPM with just a boolean result coming out: True for a match, False
otherwise.
Thanks in advance.
Arshad Noor
StrongAuth, Inc.