Meaning
Cryptographic storage locations within a trusted platform module hold cryptographic hashes of the software and configuration states of a computing system. Security frameworks use a platform configuration register to record the integrity of the boot process and the current operating environment. These registers can only be updated through an extend operation, which combines the existing value with a new hash to create a chain of evidence.
This mechanism ensures that the final value represents every piece of software that has executed since the system started.
Integrity Measurement
Software components are measured by calculating a hash of their binary code before they are allowed to run. Each measurement is then recorded into a platform configuration register to create a verifiable log. If a malicious actor modifies the boot loader or the kernel, the resulting hash in the register will not match the expected value.
Policy Enforcement
Access to secret keys or encrypted disks is often tied to the state of the hardware. A platform configuration register provides the proof needed to unlock these resources only when the system is in a known good state. This process, known as sealing, prevents data from being accessed if the computer is booted into a compromised or unauthorized operating system.
Attestation Protocol
External entities can verify the security posture of a remote device by requesting the contents of its registers. The value in a platform configuration register is signed by the trusted platform module to prove its authenticity. This allows a central server to determine if a client is compliant with corporate security policies before granting network access.