Electronics Audience Network Report (text/Zhou Kaiyang) Hardware security chips or modules are actually nothing new. With the continuous introduction of hacker attack technology, higher security must not only start from software, but also start from hardware. Since Windows 11 was officially launched last year, discussions on the TPM 2.0 hardware security module have not stopped. Some view it as an additional hardware cost, while others are happy with increased security.
Although many users have used strange tricks to bypass this requirement, it can be said that there is no benefit to the security of the computer itself. So for users who do not want to sacrifice this layer of cyber attack protection, what solutions do they have?
Microsoft Pluton
In view of the independent TPM modules that require the cooperation of system OS, motherboard, processor and TPM chip manufacturers, Microsoft, which mainly promotes TPM 2.0, has proposed a TPM solution: directly build the TPM security processor into the chip, so that the motherboard does not require an additional TPM 2.0 module, and can perfectly realize BitLocker hard disk encryption, or store fingerprint or face biometric data used by Windows Hello.
In the market share that Windows system makes competitors difficult to reach, Microsoft's appeal can be imagined, and soon it boosted the support of Intel , AMD and Qualcomm . For example, the AMD Ryzen 6000 series CPU unveiled on CES 2022 this year announced the first integrated Pluton processor. Qualcomm announced its 8cx Gen 3 laptop SoC last year, also announced the integration of Microsoft's Pluton solution on its secure processing unit (SPU).

Ryzen 6000 series mobile processors / AMD
However, in addition to improving system security, Microsoft's Pluton may also have ulterior motives. Many developers in the open source circle said that this move is that Microsoft will not allow Linux to have the opportunity to seize the PC consumer market, because Linux now has support for TPM, and Microsoft's Pluton only supports Windows systems for the time being. According to Microsoft, their current focus is on optimizing Pluton's performance on Windows 11.
For Intel, which also recently launched the new CPU, it seems that they do not intend to integrate Pluton into the 12th generation Alder Lakes processor, but choose to continue to use Intel's own countermeasures, namely Intel Platform Trust technology (Intel PTT). According to Intel, processors that support PTT can provide the same capabilities as independent TPM 2.0 modules, such as certificate storage and key management, and also support all requirements of Microsoft for fTPM (firmware TPM) 2.0 and BitLocker hard disk encryption. The benefit for users is that there is no need for any additional physical chips.
Infineon OPTIGA
But for processors that do not support Pluton or fTPM, other non-integrated TPM solutions are often used, such as Infineon OPTIGA TPM. Many external TPM modules on the market use Infineon's OPTIGA SLB 9665 or SLB 6970. Both support TPM 2.0 and also support various mainstream symmetric and asymmetric encryption algorithms.
However, the emergence of quantum computing poses greater challenges to encryption, especially the confidentiality of encrypted data and the integrity of digital signatures. If future cyber attacks can be mastered, quantum computing can be used at will, cracking today's encryption algorithms is no problem, especially public key passwords such as RSA and Diffie-Hellman.

OPTIGA TPM SLB 9672 / Infineon
To meet these challenges, Infineon recently launched the new OPTIGA TPM SLB 9672. As a standardized TPM out of the box, SLB 9672 uses XMSS signatures, provides a firmware update mechanism protected by post-quantum encryption (PQC) technology, and supports the latest TCG specifications and TPM 2.0 standards. With the support of this mechanism, SLB 9672 can be updated even if the standard algorithm is no longer in a trusted state.
SLB 9672 not only natively supports the latest version of Microsoft Windows systems and major Linux distribution systems, but also provides extensible non-volatile memory, up to 51kB, for storing certificates and keys. SLB 9672 is divided into two versions, one is FW15.xx version, which is suitable as a standardized certification security solution for Microsoft's Windows environment. The 16.xx version provides enhanced security features, such as AES batch secrets, TPM unique IDs and EPS configurations. One of the models uses a temperature range from the standard -20℃ to +85℃ to -40℃ to +105℃.
summary
Microsoft's attitude of making up its mind to push TPM 2.0 is enough to show their importance to network security. Although Windows is no longer the weak system today, in today's world where network security is raging again, more hardware security will also provide more protection for its privacy. In my opinion, TPM 2.0 may be a "stumbling block" to prevent old users from upgrading to Windows 11, but its ultimate goal is to build a "moat" to maintain PC security.