TPM2 (Trusted Platform Module) userspace development
 help / color / mirror / Atom feed
From: Florian.Schreiner at infineon.com
To: tpm2@lists.01.org
Subject: [tpm2] Re: Infineon SLB 9670 lifetime
Date: Mon, 24 Feb 2020 13:16:29 +0000	[thread overview]
Message-ID: <47b2eea5f3bb4ec2bd1a251b82c8371e@infineon.com> (raw)
In-Reply-To: CAOCvsSmo1xAx3XJic852-uf0yb8rQ731m9Wz9DKt_kuUZU5ehw@mail.gmail.com

[-- Attachment #1: Type: text/plain, Size: 1286 bytes --]

The TPM usage is not related to any attack, because it refers to usage of the TPM cryptography in the system. In PCs and notebooks/tablets the usage is lower, because there is typically only one main user. There are also servers in the consumer domain, which are used by multiple users ins parallel. Server manufacturer estimate the TPM usage with 5%.
Given the attacks on security software (e.g. heartbleed), it’s probably an even worse idea to use software (with the basic hw accelerator of the CPU) to generate data. The question is if there is a better alternative.

Best,
Florian


From: Steven Clark <davolfman(a)gmail.com>
Sent: Freitag, 21. Februar 2020 18:19
To: Tomasz Przybysz <tomasz.przybysz(a)mikronika.com.pl>
Cc: tpm2 <tpm2(a)lists.01.org>
Subject: [tpm2] Re: Infineon SLB 9670 lifetime

Caution: This e-mail originated outside Infineon Technologies. Do not click on links or open attachments unless you validate it is safe<http://iweb.infineon.com/en-US/Support/security/CDC/pse/Pages/pce.aspx>.


5% usage is honestly a crazy amount.  Given recent timing attack research it's probably not a good idea to be generating that much data about a TPM.  For lighter use, it could easily be 2 seconds a day (on recent kernels) instead of 2 minutes an hour.

[-- Attachment #2: attachment.htm --]
[-- Type: text/html, Size: 5103 bytes --]

             reply	other threads:[~2020-02-24 13:16 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2020-02-24 13:16 Florian.Schreiner [this message]
  -- strict thread matches above, loose matches on Subject: below --
2020-02-24  7:06 [tpm2] Re: Infineon SLB 9670 lifetime Tomasz Przybysz
2020-02-21 17:18 Steven Clark
2020-02-21 13:52 Alexander Steffen
2020-02-21 12:18 Emmanuel Deloget
2020-02-21 12:01 Florian.Schreiner
2020-02-21  7:34 Luke Hinds
2020-02-21  0:39 nicolasoliver03

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=47b2eea5f3bb4ec2bd1a251b82c8371e@infineon.com \
    --to=tpm2@lists.01.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox