public inbox for cip-dev@lists.cip-project.org
 help / color / mirror / Atom feed
* Secure Data Encryption on board without TPM support ( AM62P)
@ 2025-06-02 18:03 Gupta, Ayush
  2025-06-02 18:37 ` [cip-dev] " Heinisch, Alexander
  2025-06-03 11:16 ` Jan Kiszka
  0 siblings, 2 replies; 4+ messages in thread
From: Gupta, Ayush @ 2025-06-02 18:03 UTC (permalink / raw)
  To: cip-dev@lists.cip-project.org
  Cc: Raghavendra, Vignesh, Adivi, Sai Sree Kartheek,
	jan.kiszka@siemens.com

[-- Attachment #1: Type: text/plain, Size: 1227 bytes --]

Dear CIP Development Team,

I am currently working on enabling encrypted storage for the TI's AM62P platform, which, as per current hardware capabilities, does not include TPM support.

To address this, I have implemented a working initramfs-crypt-hook-nontpm (link provided at the end)  solution that removes TPM dependencies. It utilizes a keyfile embedded directly into the initramfs for unlocking encrypted partitions during boot. The initramfs itself is considered secure as it is protected by verified boot (Secure Boot is enabled on the platform).

I would like to know if this is an acceptable and secure approach from the CIP security perspective for boards without TPM support. Additionally, are there any recommended alternatives or best practices for strengthening this method in scenarios where TPM support is not available?

Looking forward to your guidance.



Patch for

initramfs-crypt-hook-nontpm

recipes-initramfs/initramfs-crypt-hook-nontpm * main * 22CSB0C01_AYUSH GUPTA / am62x-security-features * GitLab<https://gitlab.com/ag22csb0c01/am62x-security-features/-/tree/main/recipes-initramfs/initramfs-crypt-hook-nontpm?ref_type=heads>


Best regards,
Ayush Gupta
Texas Instruments


[-- Attachment #2: Type: text/html, Size: 3901 bytes --]

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2025-06-05 11:38 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-06-02 18:03 Secure Data Encryption on board without TPM support ( AM62P) Gupta, Ayush
2025-06-02 18:37 ` [cip-dev] " Heinisch, Alexander
2025-06-03 11:16 ` Jan Kiszka
2025-06-05 11:38   ` Ayush Gupta

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox