Hackers have attacked the U.S. NASDAQ stock trading computers. Experts say cyber security in some large emerging world powers is almost non-existent. U.K. government e-mail is compromised. These recent headlines prove that computer security is not only not solved, it is degrading.
Today’s essay is the first of two articles by Brian Berger, a director of the Trusted Computing Group, which is “a not-for-profit organization formed to develop, define and promote open, vendor-neutral, industry standards for trusted computing building blocks and software interfaces across multiple platforms.” What follows is entirely his work with minor edits.
* * *
Hackers have attacked the U.S. NASDAQ stock trading computers. Experts say cybersecurity in some large emerging world powers is almost non-existent. U.K. government e-mail is compromised. These recent headlines prove that computer security is not only not solved, it is degrading.
These and other issues could be mitigated if users simply activated existing security available in their systems. This basically free security feature is in more than 500 million desktop and portable computers, yet only a small fraction of the users have activated the embedded security, according to a study by Aberdeen Research.
Most people are not even aware of the security technology in their computer. That’s OK if the technology is enabled when they purchase the computer, but the Trusted Platform Module, or TPM, is an opt-in tool. The TPM, a secure cryptographic integrated circuit (IC), provides a hardware-based root of trust that enables improved computer and network security compared to software-only approaches that can be defeated by the same software they are attempting to detect and block. The TPM was developed by the Trusted Computing Group (TCG) as an open standard, so several companies compete to supply the TPM making it cost competitive. As a result, most leading computer companies install the technology in their computers. In addition to industry experts in computing software, hardware and services, TCG’s members also include companies that have a goal of improving the security in their own operations.
While it can be difficult to establish trust with people, you can easily establish a trusted relationship with a TPM-equipped machine and protect systems and networks. For consumers and enterprises that have PCs, servers and other products with a TPM, they just need to turn the TPM on. It only takes four easy steps. While not as easy as simply flipping a switch, for corporations with an IT organization it is a trivial technical challenge. Several companies offer tools to make the widespread implementation of the TPM in an organization even easier. With an activated TPM, users can easily encrypt files, folders and e-mails as well as more securely manage passwords to avoid unauthorized access to computers and networks.
The TPM provides a hardware security foundation for networks based on hooks in TCG’s Trusted Network Connect standard. A recent extension of that standard even provides secure social networking for machines through an interface to a Metadata Access Protocol (IF-MAP) server. In addition, self-encrypting drives have been introduced based on TCG’s Trusted Storage standard that takes advantage of the TPM.
More about implementing TPM in the next article.
* * *
Brian Berger is an executive vice president for Wave Systems Corporation. He manages the business, strategy and marketing functions that include product management, product positioning, marketing and sales direction for the company. Berger holds a key executive leadership position for the company to develop and implement the strategy for Trusted Computing. He has been involved in security products for the past 10 years including work with embedded hardware, client / server applications, PKI and biometrics. He has worked in the computer industry for over 20 years and has held several senior level positions in multinational companies. Berger holds three patents and has pending patents for security products and commerce transactions capabilities using security technology.
Trusted Computing Group is exhibiting at Infosecurity Europe 2011 – the No. 1 industry event in Europe – where information security professionals address the challenges of today while preparing for those of tomorrow. Held from April 19-21 at Earl’s Court, London, the event provides an unrivalled free education program, with exhibitors showcasing new and emerging technologies and offering practical and professional expertise. For further information please visit the conference We bsite.




