The creator of the key can prevent migration by the User by wrapping it with a non-migratable storage key
and loading random data for the MigrationAuthorizationData.
page 164
Dans tous tes commentaires tu sembles supposer que le "owner" du TPM est forcément le possesseur de la mcahine, alors que les specs n'interdisent pas à un OS comme Windows d'être ce owner. D'ailleurs si les applications DRM de Win exigent que Win soit owner, on devra laisser owner à Win pour pouvoir utiliser ces applications.
Pour roots of trust je te conseille de relire le début du PDF des specs...
Pourquoi t'entêtes-tu alors que le site officiel TCPA possede des documents affirmant haut et fort que le but est bien de permettre à un fournisseur de contenu distant d'identifier les logiciels de ta machine afin de choisir s'il décide de faire confiance ou non à ton OS (grace aux checksums de l'OS par TCPA créés lors du boot):
For example, before making content available to a remote user, it is likely that a provider
will need to know that the remote platform is trustworthy. The provider's platform (the
"challenger") queries the remote platform. During system boot, the challenged platform
creates a series of cryptographic digests (integrity metrics) that represent the method
used to build the software environment in the challenged platform. These digests are
statistically unique indications of the platform environment, yet they will occur in all
platforms with the same software environment.
When it receives the query from the challenger, the remote platform responds by digitally
signing and then sending the integrity metrics. The digital signature prevents tampering
Page 2
and allows the challenger to verify the signature. If the signature is verified, the
challenger can then determine whether the identity metrics are trustworthy. If so, the
challenger, in this case the service provider, can then deliver the content. The TCPA
system reports the metrics and lets the challenger make the final decision regarding the
trustworthiness of the remote platform. Based upon the reported integrity metrics, the
challenger can determine if the platform is configured in a trusted state. http://www.google.fr/search?q=cache:YDeLgyHUXDoC:www.trustedcomputi(...)
[^] # Re: Demontage en regle
Posté par free2.org . En réponse à la dépêche vérifications sur TCPA: je refuse d'avoir des puces et des softs TCPA dans mon ordinateur. Évalué à 1.
and loading random data for the MigrationAuthorizationData.
page 164
Dans tous tes commentaires tu sembles supposer que le "owner" du TPM est forcément le possesseur de la mcahine, alors que les specs n'interdisent pas à un OS comme Windows d'être ce owner. D'ailleurs si les applications DRM de Win exigent que Win soit owner, on devra laisser owner à Win pour pouvoir utiliser ces applications.
Pour roots of trust je te conseille de relire le début du PDF des specs...
Pourquoi t'entêtes-tu alors que le site officiel TCPA possede des documents affirmant haut et fort que le but est bien de permettre à un fournisseur de contenu distant d'identifier les logiciels de ta machine afin de choisir s'il décide de faire confiance ou non à ton OS (grace aux checksums de l'OS par TCPA créés lors du boot):
For example, before making content available to a remote user, it is likely that a provider
will need to know that the remote platform is trustworthy. The provider's platform (the
"challenger") queries the remote platform. During system boot, the challenged platform
creates a series of cryptographic digests (integrity metrics) that represent the method
used to build the software environment in the challenged platform. These digests are
statistically unique indications of the platform environment, yet they will occur in all
platforms with the same software environment.
When it receives the query from the challenger, the remote platform responds by digitally
signing and then sending the integrity metrics. The digital signature prevents tampering
Page 2
and allows the challenger to verify the signature. If the signature is verified, the
challenger can then determine whether the identity metrics are trustworthy. If so, the
challenger, in this case the service provider, can then deliver the content. The TCPA
system reports the metrics and lets the challenger make the final decision regarding the
trustworthiness of the remote platform. Based upon the reported integrity metrics, the
challenger can determine if the platform is configured in a trusted state.
http://www.google.fr/search?q=cache:YDeLgyHUXDoC:www.trustedcomputi(...)