| 数据搜索系统,热门电子元器件搜索 |
|
ST33TPHF20SPI 数据表(PDF) 21 Page - STMicroelectronics |
|
|
|||||||||||||||||||||||||||||
ST33TPHF20SPI 数据表(HTML) 21 Page - STMicroelectronics |
|
21 / 47 page ![]() FIPS140-2 SECURITY POLICY Page 21 of 47 NON-PROPRIETARY DOCUMENT 2 IDENTIFICATION AND AUTHENTICATION POLICY This chapter gives details about the roles managed by TPM. 2.1 Roles Services proposed by TPM are accessible under different roles. Next table defines the different roles supported by the TPM. Table 15: Roles Role Description Type of authentication Authentication data Crypto officer (CO) Role that requires knowledge of the authValue or authPolicy associated to one of the hierarchy (incl. lockout). Role based 256-bit secret data (authValue and/or authPolicy) User (U) Role that requires knowledge of the authValue or authPolicy associated to one object or NV index. Role based 160-bit or 256-bit secret data (authValue and/or authPolicy). Authorization depends on userWithAuth object attribute. Admin (A) The object Administrator controls the certification of an object (TPM2_Certify and TPM2_ActivateCredential) and controls changing of the authValue of an object (TPM2_ObjectChangeAuth). Role based 160-bit or 256-bit secret data (authValue and/or authPolicy). Authorization depends on adminWithPolicy object attribute. DUP (D) This authorization role is only used for TPM2_Duplicate(). If duplication is allowed, authorization must always be provided by a policy session and the authPolicy equation of the object must contain a command that sets the policy command code to TPM_CC_Duplicate. Role based 160-bit or 256-bit secret data (authPolicy). Some commands can also be executed without any authorization role. Those commands are marked as NA in the service list table (Table 18: Command support table). The security module does NOT provide a Maintenance Role or Maintenance Interface and does NOT support concurrent operators. Roles are implicitly selected by TPM operator on command execution (cf. Table 18 for correspondence between service and supported role) by proving knowledge of the authorization value or knowledge of the policy sequence (nature of authorization session indicates the type of authorization) that are associated with the object the command is operating on. An operator might switch from one role to another by executing commands requiring different roles and proving knowledge of the authorization value or policy sequence of objects the role is associated to. 2.2 Authentication 2.2.1 Description In FIPS approved mode of operation, TPM uses a mechanism for authorization that consists in: 1. Opening an authorization session that may be of the following types: a. HMAC b. Policy |
|
链接网址 |
| ALLDATASHEET是否为您带来帮助? [ DONATE ] |
关于 Alldatasheet | 广告服务 | 联系我们 | 隐私政策 | 数据表链接 | 链接交换 | 制造商名单 All Rights Reserved©Alldatasheet.com |
| Russian : Alldatasheetru.com | Korean : Alldatasheet.co.kr | Spanish : Alldatasheet.es | French : Alldatasheet.fr | Italian : Alldatasheetit.com Portuguese : Alldatasheetpt.com | Polish : Alldatasheet.pl | Vietnamese : Alldatasheet.vn Indian : Alldatasheet.in | Mexican : Alldatasheet.com.mx | British : Alldatasheet.co.uk | New Zealand : Alldatasheet.co.nz |
|
Family Site : ic2ic.com |
icmetro.com |