Overview - ISO/IEC 11889-1:2009 (Trusted Platform Module - Part 1: Overview)
ISO/IEC 11889-1:2009 is the informative overview for the Trusted Platform Module (TPM) family of standards. It explains the role of a TPM in establishing a trusted platform, describes core concepts (trust boundary, roots of trust, transitive trust), and summarizes how a TPM supports protected storage, integrity measurement, and integrity reporting. Part 1 is non‑normative and is intended to give architects, implementers and evaluators the conceptual foundation; normative specifications appear in ISO/IEC 11889 parts 2–4.
Key topics and technical highlights
- Trusted Platform concepts: definitions of trust, roots of trust (RTM, RTS, RTR), and the trusted building block (TBB) that complements the TPM to form the trust boundary.
- Transitive (inductive) trust: how a root of trust can extend trust to additional platform components by reliable measurement and reporting.
- Integrity measurement and reporting: use of Platform Configuration Registers (PCRs) to store digests, procedures for measuring platform components, and attestation semantics.
- Protected storage: role of the Storage Root Key (SRK) and hierarchy for encrypted objects; support for AIKs (Attestation Identity Keys), signing keys and storage keys.
- Attestation and authentication: distinctions among attestation by the TPM, attestation to and of the platform, and platform authentication using TPM-resident keys (e.g., EK, AIK).
- TPM components and operational states: summary of TPM functions, naming conventions, protected capabilities, privacy considerations, and supported cryptographic algorithms.
- References and mapping: Part 1 maps to the Trusted Computing Group (TCG) TPM 1.2 specification and points to Parts 2–4 for design principles, structures and commands.
Practical applications and users
ISO/IEC 11889-1:2009 is useful for:
- System architects and security engineers designing hardware‑anchored trust in PCs, embedded devices or servers.
- TPM designers and vendors, as a conceptual guide (designers must use Parts 2–4 and platform‑specific specs for implementation).
- Software developers and integrators implementing attestation, disk/file encryption, secure key storage, VPN/802.1x authentication, or PKI workflows leveraging TPMs.
- Evaluators, auditors and product managers assessing how a TPM contributes to platform integrity and privacy.
Keywords: ISO/IEC 11889-1:2009, Trusted Platform Module, TPM overview, trust boundary, root of trust, integrity measurement, attestation, protected storage, AIK, SRK.
Related standards