Bulk encryption capabilities of a TPM



I have a question regarding bulk encryption capabilities of a TPM
(Trusted Platform Module). I was reading IBM/Intel documentation on
use of TPM, and they mention that TPMs can perform bulk encryption.
However according to Atmel's (a manufacturer of TPM) documentation, it
seems like bulk encryption is NOT supported by their TPM chip. They
says this is due to the cost, and NOT due to technical reasons. So I
am confused.

Maybe IBM's definition "bulk" is different than Atmel's. When I hear
the word "bulk", it means several (100+) GB of data to me. Can anyone
please clarify if TPM is the best option for performing bulk
encryption or not.

My follow up question is, if the cryptographic engine of the TPM can
NOT be used for let's say encrypting a whole drive, how does the
external encryption module (hardware (ASIC) or software (wavesys))
accesses the wrapped encryption keys from the TPM?
- Do the wrapped encryption keys get decrypted in the TPM and get sent
to the external encryption module for a short period of time; or
- does the external encryption module access the unwrapped key from
the TPM, without actually possessing a copy of it.

If possible, please give scenarios with assymetric / symmetric bulk
encryption keys.
Thanks.

--
Saqib Ali, CISSP, ISSAP
Support http://www.capital-punishment.net
-----------
"I fear, if I rebel against my Lord, the retribution of an Awful Day
(The Day of Resurrection)" Al-Quran 6:15
-----------



Relevant Pages

  • Re: Why not encrypt the whole Hard Drives?
    ... Seagate drives and/or the machines that use the TPM chips impose the ... what the administrative overhead is ... encryption key using the TPM will impose any overhead, ... > Cost and performance impact are the usual arguments. ...
    (Security-Basics)
  • Re: data encryption and data recovery?
    ... is not likely to have the key for the encryption. ... TPM chipsets have been widely endorsed by both hardware and software ... event a data recovery service must hace access to the drive it can ... giving out his or her keys to a data recovery outfit. ...
    (comp.sys.ibm.pc.hardware.storage)
  • Re: Bulk encryption capabilities of a TPM
    ... the word "bulk", it means several GB of data to me. ... Now the TPM has to only decrypt / encrypt this bulk ... whatever) and asks TPM to decrypt the blob. ...
    (Security-Basics)
  • Does IBE or ECC crypto switch to a traditional symmetric scheme for bulk data?
    ... 3DES, RC5, or AES for the purpose of encrypting the actual bulk of the ... Or do they actually use their own encryption scheme from the ... HSM where the host computer never needs to know what the private key ...
    (sci.crypt)
  • Re: MS Vista BitLocker - volume or drive?
    ... If you don't have TPM on your computer, and DON'T want to use a USB ... Drive for a Startup key, then you are limited to volume encryption. ...
    (Security-Basics)