Describes the TCG-compliant trusted platform module, presenting operational guidelines, associated error messages, benefits, and step-by-step instructions for verifying TPM status and certificates.
A TCG-compliant trusted platform module is a hardware security feature that
-
adheres to Trusted Computing Group (TCG) specifications
-
uses strong cryptographic algorithms such as ECC P384 algorithm for secure identification and attestation, and
-
protects device boot integrity and secure communication through hardware-backed security features.
Additional reference information
These hardware-backed security features enable the creation of Initial Device Identifier (IDevID) and Initial Attestation Keys (IAK), supporting compliance with modern security standards such as TLS 1.3. They also provide resilient fallback mechanisms, including AIKIDO-based keys, if ECC is not provisioned in the TPM or TPM hardware is unavailable. Attestation capabilities are enhanced through new PCR 0–8 measurements. TPM support now includes a SHA-384 bank of PCRs for measured boot, further strengthening trust in early boot stages.
IDevID is a factory-installed digital certificate that uniquely and securely identifies a device, typically using its public key and manufacturer-signed credentials. It authenticates devices when they first connect to a network, ensuring that only genuine, trusted hardware is allowed access. This mechanism is commonly applied in secure onboarding, supply chain security, and zero-touch provisioning scenarios.
|
Feature Name |
Release Information |
Feature Description |
|---|---|---|
|
TCG-compliant Trusted Platform Module |
Release 25.4.1 |
Introduced in this release on: Modular Systems (8800 [LC ASIC: Q100, Q200, P100])* Device security and cryptographic identity are enhanced through new support for a TCG-compliant Trusted Platform Module (TPM) with ECC P-384 key pairs. This feature enables TLS 1.3–based secure communication for critical onboarding workflows such as BootZ and sZTP. Enrolment and attestation are strengthened through TPM PCR 0–8 measurements, establishing a hardware-rooted chain of trust from early boot stage. CLI:
*This feature is only supported on Cisco 8800-RP2-S hardware variants. |
Starting Cisco IOS XR Software Release these features are migrated to TPM:
-
gRPC Extensible Manageability Services Daemon (EMSD)
-
Attestation APP
-
EnrollZ/AttestZ