• [^] # Re: TCPA utilisé en synergie avec d'autres cryptages

    Posté par . En réponse à la dépêche TCPA confirmé pour Prescott. Évalué à 1.

    tout ton rainsonement repose sur le fait qu'il sera obligatoire de donner le controle de TCPA au possesseur du PC. or dans la norme on peut lire qeu cela est "desirable" (je cite).

    Non la norme dit que c'est "desirable" d'avoir une methode qui permet de creer un owner sur une puce qui n'en a pas sanst renvoyer le PC a l'usine.

    Si je boote sans les droits Owner je ne peut pas faire grand chose avec ma puce. Regarde lasection 7 du doc TCPA. Pour stocker, lire, ecrire, sceller ou migrer une clef j'ai besoin d'avoir une autorisation declaree soit sur l'entite, soit sur la clef elle meme.

    Qui cree les entites ? le owner :
    The creation of the authorization data is the responsibility of the entity owner. (section 5.4 de la doc)

    Qui accorde les droits ? Le owner(desole pour le barbarisme a repetiton mais "possesseur" ca me fait bizarre, je suis preneur d'une bonne traduction) :
    All entities from the Owner to the SRK to individual keys and data blobs have authorization data. This data may need to change at some point in time after the entity creation. The ADCP allows the entity owner to change the authorization data. The entity owner of a wrapped key is the owner of the parent key.(section 5.5 de la doc)

    Qui change les droits ?(tous en coeur maintenant)
    The TPM_ChangeAuth command allows the owner of an entity to change the authorization data for theentity..(section 5.6)

    Qui gere le owner ? (attention il n'y a pas de piege)
    The TPM_ChangeAuthOwner command allows the owner of an entity to change the authorization data for the TPM Owner or the SRK.
    Et oui c'est le Owner aussi.

    Bref si j'ai pas les droits a la fois sur le SRK et sur le TPM, je peux pas bouger(pas plus que les programmes qui tournent avec mes droits d'ailleurs). Ma puce ne me sert a rien.

    Kha