News Focus
News Focus
icon url

SheldonLevine

03/08/05 10:29 PM

#72554 RE: Da_Deven_Dolla #72541

Da Deven Dolla, re: Computerworld and NTRU

Your assessment is correct, since applications could be developed against the TSP interface of the TSS (TSPi), provided by NTRU (or any other TSS vendor, for that matter).

There is really no new information in the Computerworld article - it is just a high-level introduction to the basic TSS and crypto architecture and developer tools used to create trusted apps. In essence, as you said, it is a "sales pitch" to raise awareness of the tools and technologies to application developers.

Personally, I doubt that many applications will be written directly against the TSS (TSPi, TCG Service Provider interface), at least intitially, since there is a learning curve and many developers are already familiar with MSCAPI or PKCS #11.

I tend to believe that most applications will continue to be written against MSCAPI or PKCS #11 and use a TPM-aware CSP to harden the security via the TPM. The most likely candidate to fill the CSP need for this scenario is the Wave TCG-Enabled CSP, because 1) it is being marketed and sold as part of a developer kit, 2) it is interoperable across all current TPM vendors, and 3) it adds value by offering key management functionality through a proprietary interface.

Also, existing applications that utilize MSCAPI can be hardened with minimal effort simply by "plugging in" the Wave CSP - regardless of the TPM vendor.

Now, all this having been said...I wonder about the exact nature of the Wave/NTRU relationship. Is the Wave CSP included with NTRU's CTSS, or is it just a marketing agreement? I can't seem to recall the exact details.

Wave and NTRU
http://www.ntru.com/products/ntru_wave.pdf#search='ntru%20tss%20wave%20csp'

NTRU CTSS product brief
http://www.ntru.com/products/ntru_ctss_brief.pdf

Wave TCG-Enabled Toolkit
http://www.wave.com/products/03-000172_TK.pdf

Regards

SL