Specifications
Trusted Platform Module Quick Reference 5
migratable key is that they can be used on one and only one TPM. In the event
of a system or TPM failure, all non-migratable keys and the data associated with
them will be inaccessible and unrecoverable.
The following precautions and procedures may assist in recovering
from any of the previously listed situations. Failure to implement
these security precautions and procedures may result in
unrecoverable data loss.
Password Procedures
The Infineon Security Platform software allows users to configure passwords
from 6 to 255 characters.
A good password should consist of:
• At least one upper case letter (A to Z)
• At least one numerical character (0 to 9)
• At least one symbol character (!, @, &, etc.)
Example Passwords: “I wear a Brown hat 2 worK @ least once-a-month” or
“uJGFak&%)adf35a9m”
✏ NOTE
Avoid using names or dates that can be easily guessed: birthdays,
anniversaries, family member names, pet names, etc.
All passwords associated with the Infineon Security Platform software (Owner,
Emergency Recovery Token, and User passwords) and the Wave Systems
EMBASSY Trust Suite are NOT RECOVERABLE and cannot be reset without
the original text. The system owner should document all passwords, store them
in a secured location (vault, safe deposit box, off-site storage, etc.), and have
them available for future use. These documents should be updated after any
password changes.
Emergency Recovery File Back Up Procedures
The Emergency Recovery Token (SPEmRecToken.xml) must be saved or
moved to a removable media (floppy, USB drive, CDR, flash media, etc). Once
this is done, the removable media should be stored in a secure location. DO
NOT LEAVE ANY COPIES of the Emergency Recovery Token on the hard
drive or within any hard drive image backups. If a copy of the Emergency
Recovery Token remains on the system, it could be used to compromise the
Trusted Platform Module and platform.
After completing the Infineon Security Platform User Initialization Wizard, a
copy of the Emergency Recovery Archive (SPEmRecArchive.xml) should be
copied to a removable media and stored in a secure location. This procedure
should be repeated after any password changes or the addition of a new user.