3 ms·
Without bootloader integration, what's the difference between adding a TPM vs an HSM like [0]? Does TPM just have a more standardized interface? [0] https://ww
by fakesheriff 5y ago
Without bootloader integration, what's the difference between adding a TPM vs an HSM like [0]? Does TPM just have a more standardized interface?
[0] https://www.zymbit.com/2020/11/10/blog-security-module-raspberry-pi/ https://www.zymbit.com/2020/11/10/blog-security-module-raspb...
- geerlingguy 5y agoYou can actually add both—there's a partial GPIO header for the Zymkey 4i on the board. But yeah, I think the idea is TPM is a bit more standardized across hardware, so some software that uses it would not need any tweaks to run on the Pi with a TPM built-in.
- gruez 5y ago>But yeah, I think the idea is TPM is a bit more standardized across hardware But there are USB HSMs, along with smart cards (which are also HSMs). Aren't those pretty standard?
- tadfisher 5y agoSort of; the communication protocol is standard (CCID), but the actual HSM interface varies. Yubikeys implement the OpenPGP smartcard interface, for example, as well as PKCS #11. The TPM specification has its own crypto interface that is standard across all hardware, so you can do things like generate a key and perform crypto operations without requiring the hardware implement a particular interface beyond whatever TPM version you require. There are advantages and disadvantages to both approaches. On Linux, TPMs are implemented in the kernel, and CCID is handled by userspace drivers.
- pmorici 5y agoThe Zymbit is trying to make up for the lack of secureboot/tpm integration on the Pi by securing the enclosure and monitoring that perimeter.