InvestorsHub Logo
icon url

reach567

09/27/07 7:32 PM

#152297 RE: reach567 #152223

Steven Sprague post on Grawrock's blog:


http://communities.intel.com/openport/blogs/proexpert/2007/09/25/hello-world


Sep 26, 2007 11:28 AM Reply steven.sprague


David,

This is a great place to educate everyone on the role and capabilities of TPMs on a Vpro platform. I enjoyed your post and welcome to blogging. There is so much that any IT shop can do with a TPM today. With ten's of millions of units already in the market it is a very valuable asset to improve the security of any network today. You touched on the TPM's role in integrity measurment, it should also be noted that the TPM can be used to form the foundation of any Network access control solution.
The first step in any NAC installation is to establish strong machine identity this is done with either 802.1x or ipsec both of these technologies support client certificate based identity. These technologies set up the location for integrity measurments to be evaluated. It is trivial for IT to use the TPM to generate the key pair for these certificates. The result is that the private key is now held in tamper resistant silicon and can't be migrated by a user or malware. This ensures that only approved machines are ever on the network and that all machines can have integrity measuments reported.

I look forward to discussing the number of roles that the TPM can support for the Vpro platform

Steven