The TPM usage is not related to any attack, because it refers to usage of the TPM cryptography in the system. In PCs and notebooks/tablets the usage is lower, because there is typically only one main user. There are also servers in the consumer domain, which are used by multiple users ins parallel. Server manufacturer estimate the TPM usage with 5%.

Given the attacks on security software (e.g. heartbleed), it’s probably an even worse idea to use software (with the basic hw accelerator of the CPU) to generate data. The question is if there is a better alternative.

 

Best,

Florian

 

 

From: Steven Clark <davolfman@gmail.com>
Sent: Freitag, 21. Februar 2020 18:19
To: Tomasz Przybysz <tomasz.przybysz@mikronika.com.pl>
Cc: tpm2 <tpm2@lists.01.org>
Subject: [tpm2] Re: Infineon SLB 9670 lifetime

 

Caution: This e-mail originated outside Infineon Technologies. Do not click on links or open attachments unless you validate it is safe.

 

5% usage is honestly a crazy amount.  Given recent timing attack research it's probably not a good idea to be generating that much data about a TPM.  For lighter use, it could easily be 2 seconds a day (on recent kernels) instead of 2 minutes an hour.