Trusted Computing Education

Trusted Computing Group has partnered with OST2 (OpenSecurityTraining2) to build a series of module based training utilizing TCG technologies. This training is free and open to anyone who is interested in building your skills with TCG technologies. Classes are currently under development on an ongoing basis and new courses will be announced through TCG, OST2 and on this web page in due course.

For more information about the TCG partnership with OST2, click here.

Trusted Computing 1101: Introductory Trusted Platform Module (TPM) usage

Topics include:

  • Use TPM for digital signing and sealing secrets
  • Use TPM for HMAC and hashing
  • Use TPM as a secure storage
  • How to enable the TPM’s protection against Machine-in-the-middle (MITM) attacks
  • Protecting external data using a TPM
  • Understand TPM internals and capabilities

8h21m on average to complete.

Trusted Computing 1102: Intermediate Trusted Platform Module (TPM) usage

Topics include:

  • Introduction to the Enhanced System API (ESAPI) and the tpm2-tss
  • The Endorsement Hierarchy and the Endorsement Key
  • Machine identity and TPM based identification
  • What are Platform Configuration Registers (PCRs)
  • What is attestation and how to use TPM2 Quote
  • TPM Policy and extended authorization

10h on average to complete.

Trusted Computing 1103: Advanced Trusted Platform Module (TPM) usage

Topics include:

  • Introduction to the Feature API (FAPI) using tpm2-tss
  • Advanced TPM Policy using PolicyLocality, PolicyNV and PolicyCounterTimer
  • Full Disk Encryption (FDE) using TPM 2.0 operations
  • Importing external key pairs and loading external keys into a TPM 2.0
  • Key Attestation

12h on average to complete.

Trusted Computing 2202: TPM 2.0 Programming using Python and the tpm2-pytss libraries

Topics include:

  • Enhanced System API aka ESAPI in Python
  • Feature API aka FAPI in Python
  • Creating Keys and other TPM 2.0 Objects using FAPI and ESAPI
  • Using PCRs
  • Encrypted Sessions to protect traffic from hackers
  • Audit Sessions
  • HMAC Sessions for protecting passwords and providing integrity
  • tpm2-pytss bindings to libpolicy for flexible JSON based polcies
  • Credential Activation process even without TPMs
  • Object Protections and using them to send keys from remote servers
  • Handling Endoresement Keys
  • Serializing and Deserializing TPM data structurs
  • Converting native TPM 2.0 Key formats to PEM and DER
  • Writing Custom TCTIs in Python
  • Conclusionary video covering lessons learned and mistakes made by the author

Join

Membership in the Trusted Computing Group is your key to participating with fellow industry stakeholders in the quest to develop and promote trusted computing technologies.

Join Now

Trusted Computing

Standards-based Trusted Computing technologies developed by TCG members now are deployed in enterprise systems, storage systems, networks, embedded systems, and mobile devices and can help secure cloud computing and virtualized systems.

Read more

Specifications

Trusted Computing Group announced that its TPM 2.0 (Trusted Platform Module) Library Specification was approved as a formal international standard under ISO/IEC (the International Organization for Standardization and the International Electrotechnical Commission). TCG has 90+ specifications and guidance documents to help build a trusted computing environment.

Read More