Soru

Zorluk: OrtaHardware and Embedded Systems Security

A logistics enterprise is deploying thousands of handheld mobile terminals to remote distribution staff. The devices operate in physically untrusted environments and store sensitive customer authentication data. The security engineering team mandates that each device must validate system integrity from power-on through operating system initialization using hardware-bound cryptographic measurements, while securely storing full-disk encryption keys on a dedicated cryptoprocessor integrated into the endpoint's motherboard. Which of the following hardware security controls BEST meets this requirement?

  1. Trusted Platform Module (TPM)Cevap
  2. B
    Hardware Security Module (HSM)
  3. C
    Self-Encrypting Drive (SED)
  4. D
    Software Key Store with Asymmetric Public Key Infrastructure (PKI)

Cevap

Trusted Platform Module (TPM)
The correct option is the Trusted Platform Module (TPM). A TPM is a hardware-based cryptoprocessor integrated into endpoint motherboards that securely generates and stores cryptographic keys, while providing platform integrity measurements (measured boot) to ensure firmware and system boot files have not been compromised.

Adım Adım Çözüm

1
Analyze the endpoint hardware security requirements specified in the scenario.
Identified two primary requirements: motherboard-integrated hardware cryptoprocessor key storage and hardware-bound platform boot integrity measurement on individual mobile endpoints.
Security controls must match both the form factor (endpoint motherboard) and functional requirements (boot integrity and key protection).
2
Evaluate hardware security mechanisms against the requirement profile.
A Trusted Platform Module (TPM) is designed specifically for endpoint systems to store cryptographic keys isolated from the main CPU and verify boot integrity metrics via Platform Configuration Registers (PCRs).
Other options either target data center infrastructure (HSM), focus strictly on storage media encryption (SED), or lack hardware-level isolation (software key stores).

Anahtar Kavram

Trusted Platform Module (TPM) and Endpoint Hardware Security
Tahmini Süre:1m 30s
Bu soruyu puanla