Specifications

6 Trusted Platform Module Quick Reference
Hard Drive Image Backup Procedures
To allow for emergency recovery from a hard drive failure, frequent images of
the hard drive should be created and stored in a secure location. In the event of
a hard drive failure, the latest image can be restored to a new hard drive and
access to the encrypted data may be re-established.
NOTE
All encrypted and unencrypted data that was added after the last image
was created will be lost.
Clear Text Backup (Optional)
It is recommended that system owners follow the Hard Drive Image Backup
Procedures. To backup select files without creating a drive image, files can be
moved from secured programs or drive letters to an unencrypted directory. The
unencrypted (clear text) files may then be backed up to a removable media and
stored in a secure location. The advantage of the clear text backup is that no
TPM key is required to restore the data. This option is not recommended
because the data is exposed during backup and restore.
Trusted Platform Module Ownership
The Trusted Platform Module is disabled by default when shipped and the
owner/end customer of the system assumes “ownership” of the TPM. This permits
the owner of the system to control initialization of the TPM and create all the
passwords associated with the TPM that is used to protect their keys and data.
System builders/integrators may install both the Infineon Security Platform
software and the Wave System EMBASSY Trust Suite, but SHOULD NOT
attempt to use or activate the TPM or either software package.
Enabling the Trusted Platform Module
The Trusted Platform Module is disabled by default when shipped to insure that
the owner/end customer of the system initializes the TPM and configures all
security passwords. The owner/end customer should use the following steps to
enable the TPM.
1. While the PC is displaying the splash screen (or POST screen), press the
<F2> key to enter BIOS.
2. Use the arrow keys to go to the Advanced Menu, select Peripheral
Configuration, and then press the <Enter> key.
3. Select the Trusted Platform Module, press <Enter>, and select Enabled and
press <Enter> again (display should show: Trusted Platform
Module [Enabled]).
4. Press the <F10> key, select Ok and press <Enter>.
5. System should reboot and start Microsoft Windows.