3 ms·
Author here: TPMs are not a TEE (trusted execution environment), and the TEE included in AMD's CPUs function completely separately from the TPM. So you could di
by hnj2 3y ago
Author here: TPMs are not a TEE (trusted execution environment), and the TEE included in AMD's CPUs function completely separately from the TPM. So you could disable the TPM and still have the TEE run DRM code.
The fact that both TEE and fTPM run on the PSP (or AMD-SP) might add a little confusion, but is nevertheless interesting.
- labcomputer 3y ago> TPMs are not a TEE (trusted execution environment), I was using the phrase “trusted environment” more generally than that. I do not mean a separate environment from the main CPU. Rather, that applications (like software DRM, or even the graphics driver) running on the CPU can’t trust the OS to enforce access controls without a secure boot environment. How do you know that windows won’t let the user spin up a debugger and dump all your memory (or load a modified driver that lets them dump the frame buffer after content has been decrypted) for later use? You need to trust that you are running in an environment where users haven’t just loaded whatever kernel modules or graphics drivers they want. TPM is generally how you get a secure boot chain, so it is a prerequisite. Hence, TPM facilitates DRM.
- bo1024 3y agoThanks for this clarification!