Where should the root key live? Flash can be read, fuses are limited, and a discrete TPM adds cost and board space.
This webinar shows how wolfPUF and wolfTPM eliminate the need to store the firmware TPM’s NV integrity key as a secret on the device. wolfPUF reconstructs a device-unique key from the power-on state of on-chip SRAM using BCH and HKDF. Only non-secret helper data is stored. wolfTPM provides TPM 2.0 functionality, including v1.85 post-quantum support and SPDM, on an existing processor core. See how the two technologies work together to regenerate the key protecting the fTPM’s NV storage from silicon at every boot.
This webinar will cover:
- Reconstruct device-unique keys from SRAM using BCH and HKDF
- Port an fTPM with TPM 2.0, post-quantum, and SPDM support
- Regenerate the fTPM NV root key from silicon at every boot
- Examine the security benefits, limitations, and supported platforms
- Watch the PUF-backed fTPM operate live on embedded hardware
Ask the Expert: Answers Key Questions
Our experts answer key questions about what attendees will learn
How does wolfPUF derive a device-unique key from SRAM?
wolfPUF uses the power-on state of on-chip SRAM with BCH error correction and HKDF. Only non-secret helper data is stored.
How do wolfPUF and wolfTPM work together?
wolfPUF reconstructs the key protecting the fTPM’s NV storage from silicon at every boot. Examine what this design provides and where its threat-model boundaries lie.
What does wolfTPM provide on the processor?
wolfTPM provides TPM 2.0 functionality on an existing processor core, including v1.85 post-quantum support and SPDM.
Date: September 1 | 9 AM PT
Register to see the PUF-backed fTPM operate live on a NUCLEO-H563ZI and AMD Zynq-7000 ZC702.
As always, our webinar will include Q&A throughout. If you have questions about any of the above, please contact us at facts@wolfssl.com or call us at +1 425 245 8247.
Download wolfSSL Now

