Barge.....The mechanics of Attestation
The unique key in the TPM, known as the
endorsement key (EK), is generated during
manufacturing. To validate that the EK comes
from a valid TPM the manufacturer creates an
endorsement credential that states that the
EK in question comes from a valid TPM. So while
anyone could create a SW EK and claim it comes
from a valid TPM they would not have avalid
endorsement credential to accompany that claim.
This implies that those who rely on an EK will
validate that it comes from a valid TPM.
The TPM manufacturer decides on which TTP(CA)
they use,TPM manufacturers are asked to
destroy their copy of the E.K key after it's
been embedded on the chip.
Enterprises are then free to choose a CA or their
OWN INTERNAL SERVER,rather than trust the TPM
manufacturers CA.
So Who are Infineon,Atmel,ST Micro &
NSM's CA?
Doma.