compare Secure boot platform keys and TPM module functions

I plan to buy new motherboard and TPM  to increase security against rootkits and bootkits, firmware replacing and unallowed changes. I am not advanced computer user. I have looked through manual for Asus motherboard M5a97plus to place in existing computer. Its secure boot function has possibility to change settings of (Platform Key) and (Key Exchange Key or Key Enrollment Key) db management (authorized signatures daTabaSE). I shall use on single computer with no networkI want to know such things:

1. Can I create PK and KEk keys?

2. Should I create them to improve computer security?

3. Are they created automatically or somebody should create them if I can not?

4. Can TPm module give me additional security? The function of PK, Kek, DB management are described so:

a. The Platform Key locks and secures the firmware from any non-permissible changes. The system verifies the PK before your system enters the OS.

B. The Kek manages the signature database and revoked signature database.

c. THe database lists the signers or images of Uefi applications, operating system loaders and UEFI drivers that you can load on the single computer.

5. Are the signers and images mentioned in point 4.c. made by Microsoft, software or hard ware manufacturers?

6. Can motherboard with these functions block the loading of the system or some components if it will find mismatch with original images, firmware etc. 

May 11th, 2015 11:38am

Hi,

Q1:

Secure boot is not a technology of Microsoft, we couldn't provide more accurate answers with this problem. However as far as I know, PK is a public key and you don't need to create it, KEK too. 

Q2:

You can just enable Secure Boot to improve computer security.

Q3:

See: https://technet.microsoft.com/en-us/library/dn747883.aspx?f=255&MSPPError=-2147217396

Q4

See:http://en.wikipedia.org/wiki/Trusted_Platform_Module

Q5:

See: https://www.linuxfoundation.org/sites/main/files/lf_uefi_secure_boot_open_platforms.pdf

Q6:

Refer to the description about Secure Boot.

Note: Since the website is not hosted by Microsoft, the link may change without notice. Microsoft does not guarantee the accuracy of this information. 

Free Windows Admin Tool Kit Click here and download it now
May 12th, 2015 4:54am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics