A logistics enterprise is deploying thousands of handheld mobile terminals to remote distribution staff. The devices operate in physically untrusted environments and store sensitive customer authentication data. The security engineering team mandates that each device must validate system integrity from power-on through operating system initialization using hardware-bound cryptographic measurements, while securely storing full-disk encryption keys on a dedicated cryptoprocessor integrated into the endpoint's motherboard. Which of the following hardware security controls BEST meets this requirement?
- Trusted Platform Module (TPM)Cevap
- BHardware Security Module (HSM)
- CSelf-Encrypting Drive (SED)
- DSoftware Key Store with Asymmetric Public Key Infrastructure (PKI)
Cevap
Trusted Platform Module (TPM)
The correct option is the Trusted Platform Module (TPM). A TPM is a hardware-based cryptoprocessor integrated into endpoint motherboards that securely generates and stores cryptographic keys, while providing platform integrity measurements (measured boot) to ensure firmware and system boot files have not been compromised.
Adım Adım Çözüm
Anahtar Kavram
Trusted Platform Module (TPM) and Endpoint Hardware Security
Tahmini Süre:1m 30s