Skip to content

Incorrect key mentioned for signing nonce #226

Description

@waseem-lite

According to this line in the tpm_enrollz.proto, the signature of the nonce sent initially by GetIakRequest is supposed to be created by IAK (Initial Attestation Key).

// [Optional] Signature of the nonce to be created by the IAK private key.
optional bytes nonce_signature = 4;

This is not possible and against the TPM specification. Attestation Key have restricted usage and can only sign digest that are created inside the TPM. This is as per the TPM specification, TPM 2.0 Part 1: Architecture, section 9.5.3.1 Types of Attestation. The section states,
"An Attestation Key (AK) is a particular type of signing key that has a restriction on its use, in order to prevent forgery (the signing of external data that has the same format as genuine attestation data). The restriction is that an AK may be used only to sign a digest that the TPM has created. "

Therefore such a signing operation that utilizes the IAK key is not possible. Its probable that the intent was to write iDevID and not IAK, but please clear this misunderstanding and let us know the expected behavior.

In case, the actual intent is to use IAK for this signature, can you please point to some examples or code snippets on how it can be achieved with TPM 2.0.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions