July 25, 2018 – Mocana Corporation, a provider of mission-critical security solutions for industrial control systems and the Internet of Things (IoT), announced support for Trusted Platform Module (TPM) 2.0 to enable device manufacturers to build products that meet the highest standards for cybersecurity. Used to secure billions of computer hardware and financial systems, TPM technology uses a secret key embedded into a microchip or firmware. With Mocana, IoT device manufacturers can secure storage, communications, firmware updates and containerized applications.
TPM is an international standard for a secure cryptoprocessor, a dedicated microcontroller designed to secure hardware through integrated cryptographic keys. TPM was conceived by the Trusted Computing Group (TCG), a computer industry consortium, and was later standardized by International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) in 2009 as ISO/IEC 11889.
Key features and benefits of Mocana’s support of TPM 2.0 for IoT and industrial devices include:
- Ciphers Support: Support for ciphers including Elliptic Curve Cryptography (ECC), and 256 and 512-bit Secure Hash Algorithms (SHA) 2.
- Multiple Ownership of Keys: Separates owners for the TPM Endorsement Key (EK) for signing/attestation from the Storage Root Key (SRK) with support for Endorsement Hierarchies (EH) and Storage Hierarchies (SH).
- Seeding for entropy: Seeding and reseeding of a non-deterministic pseudorandom number generator with an entropy source internal to the TPM’s cryptographic boundary to ensure a degree of randomness for key generation.
- Support for Windows and Linux:Solution is optimized for embedded systems running Windows or Linux-based operating systems.
- Pre-integrated support: Multi-vendor support for TCG TPM 1.2 and 2.0 specification from Infineon, Nuvoton, and STMicro.
- Compliance with cybersecurity standards:Meets the requirements for US NIST 800-63B AAL3andsupport Proof of Possession of a secret for both Certificate Management over CMS (CMC) and the Enrollment of Secure Transport (EST).
- Secure storage: Support for use of certified TPM keys for the encryption of data at rest.
- Secure communications:Support for use of TPM keys for both asymmetric and symmetric key generation for SSL/TLS and IPsec.
- Firmware updates: Support for use of TPM keys to ensure devices are trusted before firmware is updated.
- Containerized applications:Ensures the trustworthiness of containerized applications using remote attestation.
