Overview
ISO/IEC 11889-2:2009 - "Information technology - Trusted Platform Module - Part 2: Design principles" defines the design principles and operational behavior for the Trusted Platform Module (TPM). Part 2 focuses on the TPM’s base operating modes, core cryptographic building blocks, interoperability requirements, authorization and transport protocols, and use of TPM resources (keys, PCRs, NV storage). The document is normative in large part and uses RFC‑2119 keywords (MUST/SHOULD/MAY) to state requirements. TPM implementers should also consult platform‑specific specifications for a complete build.
Key topics and technical requirements
- TPM architecture and components: input/output, cryptographic co‑processor, key generation, HMAC, RNG, SHA‑1 engine, execution engine, NV memory, power detection and physical presence mechanisms.
- Cryptographic primitives and interoperability: references to SHA‑1, AES and RSA, and use of established schemes (OAEP, PKCS#1, HMAC) for encryption, signing and integrity. The part prescribes acceptable algorithms and key selection guidance for interoperability.
- Key lifecycle and identity: Endorsement Key (EK) creation and protection, Attestation Identity Keys (AIKs), Storage Root Key (SRK), and rules for key use and migration.
- Roots of trust: Root of Trust for Reporting (RTR) and Root of Trust for Storage (RTS), platform identity and privacy considerations, PCR (Platform Configuration Register) usage and measurement model.
- Authorization & transport: authorization protocols (OIAP, OSAP), transport sessions, ADIP/ADCP/AACP protocols, handling brute‑force/dictionary attack risks, and session management.
- Operational states & lifecycle: initialization, self‑test, startup, enabling/activating/ownership, clearing TPM, field upgrades and maintenance.
- Non‑volatile storage & counters: NV storage design principles, monotonic counters, audit/tracking and transport protection.
- Advanced functions: Direct Anonymous Attestation (DAA), certified migration, delegation model, time stamping and tick architecture.
Practical applications and who uses it
- TPM silicon vendors and firmware developers use this standard to design compliant TPM chips and internal services.
- Platform OEMs and BIOS/UEFI integrators implement TPM interfaces, PCR measurements and ownership workflows.
- Security architects and solution integrators leverage the standard to build trusted computing features: secure boot, measured launch, hardware-backed key storage, remote attestation and secure credential storage.
- Certification bodies and evaluators use the document alongside evaluation standards (e.g., ISO/IEC 19790) when assessing TPM security.
Related standards
- ISO/IEC 11889 (other parts: Part 1 Overview, Part 3 Structures, Part 4 Commands)
- Cryptographic and protocol references cited: ISO/IEC SHA and AES standards, PKCS#1, IEEE P1363, IETF RFC 2104/2119, and ISO/IEC 19790 (security evaluation).
Keywords: ISO/IEC 11889-2:2009, Trusted Platform Module, TPM design principles, TPM architecture, EK, AIK, PCR, RTR, RTS, TPM authorization protocols, TPM interoperability.