New TCG-DMTF collaboration to optimize the authentication and communication of devices

Date Published: September, 14, 2026

Industry-wide interoperability in platform security has today been strengthened, thanks to a joint development effort between the Trusted Computing Group (TCG) and DMTF that improves how devices securely recognize and communicate with each other.

DMTF’s libspdm is a key software component – and an implementation of the Security Protocol and Data Model (SPDM) specification – that helps devices check each other’s identity and communicate securely. By including Trusted Platform Module (TPM) support, the organization has taken a practical step forward to strengthen interoperability of devices, expand developer flexibility, and reinforce industry alignment around trusted platform security.

“We welcome DMTF’s decision to integrate TPM capabilities into libspdm,” said TCG President Joe Pennisi. “Not only does it highlight the importance of cooperation between standards organizations, but by bringing the two technologies together in accessible reference code, we can help implementers understand how perfectly they complement one another.”

The work builds upon the formal cooperation between TCG and DMTF. In 2021, the organizations established a work register identifying areas of technical collaboration intended to improve alignment between SPDM and TCG technologies and to support more secure and interoperable platform implementations.

The SPDM specification, developed by DMTF, provides standardized mechanisms for component authentication, measurement reporting, attestation, key exchange, and the establishment of secured communications. The new libspdm TPM backend enables implementations to make use of TPM-protected key material and platform measurements during selected operations.

Because private-key operations can be performed without exporting the underlying private key from the TPM, the integration also provides developers with a reference pattern for combining SPDM’s protocol-level security functions with a hardware-backed Root-of-Trust.

Current libspdm documentation describes TPM integration for:

  • Retrieving SPDM certificate chains from TPM NV storage
  • Signing SPDM challenge responses using TPM-resident private keys
  • Providing measurement data derived from TPM PCRs
  • Performing signing operations used during SPDM key exchange

DMTF’s spdm-emu reference environment also demonstrates the integration using swtpm – a software TPM. This enables developers to build and test TPM-backed SPDM flows without requiring dedicated TPM hardware during initial development. The libspdm TPM integration layer is designed to connect to either TPM hardware or an appropriate software TPM environment.

“We’re pleased to introduce TPM support in libspdm, accompanied by implementation documentation and an emulator-based validation environment,” said DMTF President Jeff Hilland. “This open-source reference implementation helps developers explore and validate interoperable SPDM-based security solutions utilizing TPMs, serving as a demonstration of how industry standard development organizations can work closely together to improve solutions for our members and the industry.”

More information about the TPM can be found on the TCG website.

 -END-

About TCG

TCG is a not-for-profit organization formed to develop, define and promote open, vendor-neutral, global industry specifications and standards, supportive of a hardware-based root of trust, for interoperable trusted computing platforms.

TCG enables secure computing through open standards and specifications. Benefits of TCG include protection of business-critical data and systems, secure authentication and strong protection of user identities, and the establishment of strong machine identity and network integrity. More than a billion devices include TCG technologies.

X: @TrustedComputin

LinkedIn: https://www.linkedin.com/company/trusted-computing-group/

 

About DMTF

DMTF, an industry standards organization, creates open manageability specifications spanning diverse emerging and traditional IT infrastructures including cloud, virtualization, network, servers, and storage. Member companies and alliance partners worldwide collaborate on standards including Redfish, SPDM, SMBIOS, MCTP, PLDM, and more to improve the interoperable management of information technologies. Nationally and internationally recognized by ANSI and ISO, DMTF standards enable a more integrated and cost-effective approach to management through interoperable solutions. DMTF enables the simultaneous development of Open Source and Open Standards through the support, tools, and infrastructure needed for efficient development and collaboration. For a complete list of our standards and initiatives, visit the Standards and Technologies section of the DMTF website.

DMTF is led by a diverse board of directors from Broadcom Inc., Cisco, Dell Technologies, Hewlett Packard Enterprise, Intel Corporation, Lenovo, Positivo Tecnologia S.A., and Verizon.

X: @DMTF

LinkedIn: LinkedIn

Join

Membership in the Trusted Computing Group is your key to participating with fellow industry stakeholders in the quest to develop and promote trusted computing technologies.

Join Now

Trusted Computing

Standards-based Trusted Computing technologies developed by TCG members now are deployed in enterprise systems, storage systems, networks, embedded systems, and mobile devices and can help secure cloud computing and virtualized systems.

Read more

Specifications

Trusted Computing Group announced that its TPM 2.0 (Trusted Platform Module) Library Specification was approved as a formal international standard under ISO/IEC (the International Organization for Standardization and the International Electrotechnical Commission). TCG has 90+ specifications and guidance documents to help build a trusted computing environment.

Read More