Security: What is TPM?

Whoever works with sensitive data every day, tries to secure them as good as possible. One way to encrypt data is the Trusted Platform Module (TPM). In the first article of our new series about security, we will explain what this is all about.

The Trusted Platform Module (TPM) is a chip that is integrated into many systems and offers more security. It is used primarily in PCs, notebooks, mobile phones, but also in entertainment electronics. A device with TPM, adapted operating system and suitable software is called trusted computing platform (abbr.: TC platform).

What are the advantages of TPM?

The advantages of TPM are security and encryption as well as the identification of devices. For example, each chip contains a unique cryptographic key by which the computer can be identified – only if the owner allows reading it out.
In addition, cryptographic keys can be stored in the TPM in order to save encrypted data outside of the TPM. The keys are generated, used and securely stored within the TPM, so they are protected against software attacks. Other benefits include better licensing and data protection. The owner of the system can sign data to prove his origin. In addition, changes to the system can be detected using the TPM that have been made for example by malicious programs or by users.

What keys are used in the TPM?

The Endorsement Key (EK) is an RSA key pair (the abbreviation RSA stands for the three mathematicians Rivest, Shamier and Adleman, who developed this cryptographic method) and is specifically assigned to each TPM. The key length is 2048 bits. The RSA key pair consists of a private key that never leaves the TPM and decrypts or signs data, as well as a public key used to encrypt and check signatures. The key can be created outside of the TPM and can also be deleted and re-created.

The Storage Root Key (SRK) is created when an admin or user takes over the systems, that means, that the owner of the computer changes. The SRK is also an RSA key with a length of 2048 bits. As the name implies, the SRK is the root of the TPM key tree as it encrypts other keys used.

The Attestation Identity Keys (AIKs) are RSA keys with a length of 2048 bits. They are created using the Endorsement Keys and protect the privacy of the user. The AIKs can somehow be seen as a pseudonym for the EK, so that is can remain anonymous.

How can TPM be used?

The TPM chip, which is integrated into the hardware, is of course crucial for the use of TPM. This is partly inherently on the motherboard; alternatively the module can often be optionally installed, if a TPM header is present. However, the right software is required in order to use TPM. To protect the software from easy manipulation, a secure operating system such as Windows 10 IoT Enterprise is recommended.

Which spo-comm Mini-PCs offer TPM?

In the spo-comm systems spo-book WINDBOX III Advanced, spo-book NOVA CUBE Q87 and spo-book BOX N2930, a TPM chip is actually integrated (TPM 1.2). The successor of the spo-book WINDBOX III Advanced will be released in the third quarter of 2017 and will include the new TPM 2.0, which was published in 2014. In addition, TPM can be optionally installed in the systems spo-book TURO Q87, spo-book EXPANDED Q170 and spo-book NINETEEN Q170.

More on this topic

12 Apr 2017 Array ( [id] => 260 [title] => What’s new? Bluetooth 5, TPM and high demand for SSDs [authorId] => [active] => 1 [shortDescription] => A lot has happened in the last few weeks. This month we have some news about the new Bluetooth standard, the Trusted Platform Module and we explain the rising prices for SSDs. In addition: Product change in the spo-comm range and everything about Windows 10 IoT Enterprise. [description] =>

Even faster, even better: Bluetooth 5

A few weeks ago, developers of the Bluetooth Special Interest Group (SIG) presented Bluetooth 5. The fifth version of the radio standard promises a faster data transmission, further distanced and thereby also saves energy in some cases. These changes mainly affect Bluetooth Low Energy (BLE) for small, current-saving systems. With these, the data rate can even double. Manufacturers of radio chips have already announced that the new standard will be available soon.

More security for Mini-PCs: Trusted Platform Module (TPM)

The Trusted Platform Module is a chip that is integrated into many systems and provides more security. The TPM can be used to encrypt a hard drive, identify a computer and detect changes, such as malware. More information about TPM and the spo-comm Systems possessing the chip, will soon be available on our blog.

Rising SSD prices due to high demand: Improvement is finally in sight

Due to the increased demand for NAND memories (=a type flash memory used for SSDs), the prices for SSDs have risen a lot in the recent months. This is because on the one hand SSDs are increasingly popular because of their multiple advantages. This also results in an increased demand for the more favorable so called TLC memory. On the other hand, NAND modules are also required for smartphones. While a price increase of up to 16% was expected for the first quarter, the situation should slowly ease in the second quarter.

It’s time for a change: WINDBOX II Plus goes EOL

Unfortunately everything has its end: Our very popular spo-book WINDBOX II Plus is End of Life (EOL) and is now completely replaced by the spo-book WINDBOX II Quad. Thanks to the same dimensions and also the same connections – only one USB was upgraded from 2.0 to the current 3.0 standard – the product change should not cause any problems. The WINDBOX II Quad also features a newer quad-core processor and Windows 10. Drivers for the old system are from now on available here.

Windows 10 IoT Enterprise: Find all information on our blog now!

It is hard to believe that our Windows 10 IoT weeks are already over. Over the past five weeks we’ve introduced you to a new topic every Tuesday: from general introductions, to the benefits of the OS, customizing and security features, to Microsoft’s new licensing policy. And if you do not have enough time to read, just take a look at our overview page. We have summarized the most important information short and sweet, just for you.

[views] => 14 [displayDate] => DateTime Object ( [date] => 2017-04-12 12:30:00.000000 [timezone_type] => 3 [timezone] => Europe/Berlin ) [categoryId] => 234 [template] => [metaKeyWords] => [metaDescription] => [metaTitle] => [tags] => Array ( ) [author] => [assignedArticles] => Array ( ) [media] => Array ( [0] => Array ( [id] => 3845 [blogId] => 260 [mediaId] => 49417 [preview] => 1 [media] => Array ( [id] => 49417 [albumId] => 7 [name] => Whatsnew_17_04 [description] => [path] => media/image/Whatsnew_17_04.png [type] => IMAGE [extension] => jpg [userId] => 56 [created] => DateTime Object ( [date] => 2019-11-06 00:00:00.000000 [timezone_type] => 3 [timezone] => Europe/Berlin ) [fileSize] => 228901 [width] => 1500 [height] => 1000 ) ) ) [attribute] => Array ( [id] => 257 [blogId] => 260 [attribute1] => NULL [attribute2] => [attribute3] => [attribute4] => [attribute5] => [attribute6] => [digi1Inactivateblogarticle] => 0 [digi1Sponsoredpost] => 0 [digi1Featuredpost] => 0 [digi1Hideblogdetailsite] => 0 [digi1Showleftsidebarblogdetailsite] => 0 [digi1Disablecommentfunction] => 0 [digi1Hideimageslider] => 0 [digi1Relatedblogarticle1] => 270 [digi1Relatedblogarticle2] => 250 [digi1Relatedblogarticle3] => 130 [digi1Relatedblogarticle4] => [digi1Relatedblogarticle5] => [isReference] => 0 [relatedItem] => ) [comments] => Array ( ) ) 1
know-how

What’s new? Bluetooth 5, TPM and high demand for SSDs

A lot has happened in the last few weeks. This month we have some news about the new Bluetooth standard, the Trusted Platform Module and we explain the rising prices for SSDs. In addition: Product change in the spo-comm range and everything about Windows 10 IoT Enterprise.
27 Jul 2017 Array ( [id] => 274 [title] => Security: Powerguard SSD [authorId] => [active] => 1 [shortDescription] => In an industrial environment data loss is often a critical point. If you can’t rely on a uninterruptible power supply (UPS) for reasons of cost or space, there’s a new possibility to provide more security: with so-called Powerguard SSDs. [description] =>

SSDs with the Powerguard function operate with integrated tantalum capacitors which are permanently charged with 12 volts. In case of an unexpected blackout, the SSD can act as a kind of UPS. The power in the SSD is maintained until all memory processes are completed and the data is saved. Due to this, Powerguard prevents data loss and ensures more security. This is interesting for critical applications in an industrial environment as well as networking and server technology, but also for mobile and in-vehicle solutions.

Powerguard SSD now available at spo-comm

This UPS technology was developed by the storage manufacturer Cervoz, which now offers Powerguard SSDs and mSATAs in various sizes. From now on spo-comm offers a 128 GB Powerguard SSD as a choice for all Mini-PCs in the product range. Other sizes are available upon request.

##Discover Mini-PCs with Powerguard SSD

[views] => 18 [displayDate] => DateTime Object ( [date] => 2017-07-27 10:15:00.000000 [timezone_type] => 3 [timezone] => Europe/Berlin ) [categoryId] => 234 [template] => [metaKeyWords] => [metaDescription] => [metaTitle] => [tags] => Array ( ) [author] => [assignedArticles] => Array ( ) [media] => Array ( [0] => Array ( [id] => 3870 [blogId] => 274 [mediaId] => 55811 [preview] => 1 [media] => Array ( [id] => 55811 [albumId] => 23 [name] => Powerguard_SSDOOQywkccbQPlV [description] => [path] => media/image/Powerguard_SSDOOQywkccbQPlV.png [type] => IMAGE [extension] => jpg [userId] => 56 [created] => DateTime Object ( [date] => 2019-11-27 00:00:00.000000 [timezone_type] => 3 [timezone] => Europe/Berlin ) [fileSize] => 171873 [width] => 1500 [height] => 1000 ) ) ) [attribute] => Array ( [id] => 271 [blogId] => 274 [attribute1] => NULL [attribute2] => [attribute3] => [attribute4] => [attribute5] => [attribute6] => [digi1Inactivateblogarticle] => 0 [digi1Sponsoredpost] => 0 [digi1Featuredpost] => 0 [digi1Hideblogdetailsite] => 0 [digi1Showleftsidebarblogdetailsite] => 0 [digi1Disablecommentfunction] => 0 [digi1Hideimageslider] => 0 [digi1Relatedblogarticle1] => 270 [digi1Relatedblogarticle2] => 274 [digi1Relatedblogarticle3] => 272 [digi1Relatedblogarticle4] => [digi1Relatedblogarticle5] => [isReference] => 0 [relatedItem] => ) [comments] => Array ( ) ) 1
know-how

Security: Powerguard SSD

In an industrial environment data loss is often a critical point. If you can’t rely on a uninterruptible power supply (UPS) for reasons of cost or space, there’s a new possibility to provide more security: with so-called Powerguard SSDs.
5 Sep 2017 Array ( [id] => 280 [title] => Security: Mini-PC with battery as UPS [authorId] => [active] => 1 [shortDescription] => Another alternative to the uninterruptible power supply (UPS) is presented in the third part of our blog series about security: the Mini-PC with built-in battery. [description] =>

A blackout is always bad for PCs and server systems. Short failures in the millisecond range are already sufficient to turn off electronic devices. As a result, ongoing operations are aborted and unsaved data are lost. In order to protect oneself against this, a so-called UPS (abbreviation for uninterruptible power supply) is often used. In case of a blackout, these emergency power units can supply devices with battery power. Unfortunately they are often quite expensive, large and unwieldy.

Built-in battery instead of UPS

An alternative to an UPS are PCs with built-in battery pack, such as the spo-comm series MOVE and RUGGED. With this optional supplement, the power supply is sufficient to bridge a short failure of up to 10 minutes. Enough time to save operations, shutting down programs and turning off the Mini-PC. Also you have the possibility to configure the BIOS in order to complete all memory operations automatically and to shut down the PC properly.

This is also interesting for use in vehicles for which the MOVE series was originally designed. If the vehicle-PC is equipped with a battery, a sudden shutdown or stalling of the engine does not have any negative consequences for the ongoing operations.

##Discover the MOVE series of spo-comm

 

##Discover the RUGGED series of spo-comm

[views] => 63 [displayDate] => DateTime Object ( [date] => 2017-09-05 11:15:00.000000 [timezone_type] => 3 [timezone] => Europe/Berlin ) [categoryId] => 234 [template] => [metaKeyWords] => [metaDescription] => [metaTitle] => [tags] => Array ( ) [author] => [assignedArticles] => Array ( ) [media] => Array ( [0] => Array ( [id] => 3880 [blogId] => 280 [mediaId] => 55812 [preview] => 1 [media] => Array ( [id] => 55812 [albumId] => 23 [name] => Battery-Pack [description] => [path] => media/image/Battery-Pack.png [type] => IMAGE [extension] => jpg [userId] => 56 [created] => DateTime Object ( [date] => 2019-11-27 00:00:00.000000 [timezone_type] => 3 [timezone] => Europe/Berlin ) [fileSize] => 147135 [width] => 1500 [height] => 1000 ) ) ) [attribute] => Array ( [id] => 277 [blogId] => 280 [attribute1] => NULL [attribute2] => [attribute3] => [attribute4] => [attribute5] => [attribute6] => [digi1Inactivateblogarticle] => 0 [digi1Sponsoredpost] => 0 [digi1Featuredpost] => 0 [digi1Hideblogdetailsite] => 0 [digi1Showleftsidebarblogdetailsite] => 0 [digi1Disablecommentfunction] => 0 [digi1Hideimageslider] => 0 [digi1Relatedblogarticle1] => 274 [digi1Relatedblogarticle2] => 270 [digi1Relatedblogarticle3] => 278 [digi1Relatedblogarticle4] => [digi1Relatedblogarticle5] => [isReference] => 0 [relatedItem] => ) [comments] => Array ( ) ) 1
know-how

Security: Mini-PC with battery as UPS

Another alternative to the uninterruptible power supply (UPS) is presented in the third part of our blog series about security: the Mini-PC with built-in battery.