cTPM: a cloud TPM for cross-device trusted applications
Chen Chen, Himanshu Raj, Stefan Saroiu, Alec Wolman · 2014
suited for cross-device scenarios in trusted mobile ap-plications because they hinder the seamless sharing of data across multiple devices. This paper presents cTPM, an extension of the TPM’s design that adds an addi-tional root key to the TPM and shares that root key with the cloud. As a result, the cloud can create and share TPM-protected keys and data across multiple devices owned by one user. Further, the additional key lets the cTPM allocate cloud-backed remote storage so that each TPM can benefit from a trusted real-time clock and high-performance, non-volatile storage. This paper shows that cTPM is practical, versatile, and easily applicable to trusted mobile applications. Our simple change to the TPM specification is viable because its fundamental concepts – a primary root key and off-chip, NV storage – are already found in the current spec-ification, TPM 2.0. By avoiding a clean-slate redesign, we sidestep the difficult challenge of re-verifying the se-curity properties of a new TPM design. We demonstrate cTPM’s versatility with two case studies: extending Pas-ture with additional functionality, and re-implementing TrInc without the need for extra hardware. 1