 |
BIIM Support |
 |
|
|
|
|
|
BioCert® Intelligent Identity Manager Support
Trusted Platform Module
The Trusted Platform Module (TPM) provides the ability to run
the system or applications more securely and makes
communications more trustworthy.
A TPM provides the first level of trust by hardening the base
platform and system software in the following areas:
- Protected Storage– Hardware-protected storage of
sensitive data that may include user passwords, certificates
and other credentials
- Platform Authentication– Attestable authentication of
the platform that ensures that the platform is secure
- Protected Cryptographic Processes– Hardware-protected
key generation, random number generation, and hash and
digital signature
- Platform Trust State– Ability to communicate the
attestable trust state of the platform
The following topic sections provide additional information
about TPM functionality supported in BioCert® Identity:
Configuring TPM Authentication
To configure the TPM authentication method:
- In BioCert® Identity, select
Authentication and Credentials.
- Select Credentials tab.
- In the list of authentication methods, select
TPM Authentication and the click
Properties.
- In TPM Authentication Properties
dialog box, configure the desired settings, and then
click OK to save the changes.
Registering TPM
Important
The Trusted Platform Module must be initialized prior to
registering TPM credentials. The initialization is performed
outside the BioCert® Identity, usually by Security
Platform Settings tools provided by Infineon or HP.
To register a Trusted Platform Module (TPM):
- In BioCert® Identity, select
My Identity.
- Select Register Credentials. The
BioCert® Registration Wizard is
displayed.
- On the Authentication Methods
dialog box, select the TPM Basic User Key
Password, and then select Next.
- On the Register with Trusted Platform Module
dialog box, type your Basic User Key password, and then
click Finish.
Using Trusted Platform Module
Logging on to BioCert® Identity using TPM
authentication
To log on to BioCert® Identity using a Trusted Platform
Module (TPM):
- Launch the BioCert® Logon Wizard.
- On the Introduce Yourself screen,
type the user name, and then click Next.
- On the Logon Policy screen, select
the TPM Password authentication method,
and then click Next.
- On the Enter TPM Password screen,
type your Basic User Key password. After the password is
validated, you will be logged on to BioCert® Identity.
Encrypting a user record with TPM
BioCert® Identity encrypts the user data automatically
after the TPM is installed and properly initialized.
To verify and change the type of encryption of the user
data:
- In BioCert® Identity, select
Settings.
- Select Security tab.
- Select the desired type of encryption, and then
click OK to save the changes.
Managing a Trusted Platform Module
A Trusted Platform Module (TPM) is managed through the HP
Embedded Security Manager for ProtectTools. This tool allows
the user to initialize the TPM, manage platform settings,
perform migration, obtain current status, and perform other
TPM-related operations. Refer to the Embedded Security
Manager online help for details.
Note
BioCert® Identity installation does not install the HP
Embedded Security Manager for ProtectTools.
|