Sistimi ea Tšireletso ea TPM Likhomphutheng tsa Desktop
Tšireletso ea komporo ea desktop ha e sa khona ho itšetleha feela ka liphasewete tsa ho kena kapa software ea antivirus. Litlhaselo tsa sejoale-joale tse kang bosholu ba data, ransomware, taolo ea firmware, le boiteko ba ho qoba ts'ebetso ea ho qala li hloka tšireletso ho qala ho tloha motsotsong oo sesebelisoa se buloang ka oona. Theknoloji e 'ngoe e sebelisoang haholo ho matlafatsa motheo ona oa ts'ireletso ke Trusted Platform Module (TPM). TPM e sebetsa e le "motso oa ts'epo" o thehiloeng ho hardware o thusang ho netefatsa botšepehi ba sistimi, o sireletsa linotlolo tsa cryptographic, le ho tšehetsa likarolo tse tsoetseng pele tsa ts'ireletso tsamaisong ea ts'ebetso.
TPM ke eng?
TPM ke chip ea ts'ireletso kapa module e etselitsoeng ho boloka le ho sebetsana le linotlolo tsa cryptographic ka mokhoa o sireletsehileng. Li-TPM li ka nka libopeho tse latelang:
1. TPM e sa bonahaleng: chip e arohaneng ea 'mele ho motherboard (ka kakaretso e matla ka ho fetisisa mabapi le ho itšehla thajana).
2. Firmware TPM (fTPM): e kenngwa tshebetsong ka firmware ho CPU kapa chipset (mohlala, AMD fTPM).
3. TPM e kopantsoeng: e kopantsoe le li-chipset tse itseng.
Likhomphutheng tsa sejoale-joale, TPM hangata e fumaneha e le TPM 2.0, e leng tekanyetso e ncha hobane e tšehetsa mefuta e mengata ea li-algorithms tsa cryptographic le maemo a ts'ireletso ho feta TPM 1.2.
Hobaneng TPM e le ea bohlokoa lik'homphieutheng tsa desktop?
Lik'homphieutha tsa desktop hangata li sebelisetsoa mosebetsi oa ofisi, lipapali, moralo le tlhahiso ea litaba—ho bolelang hore li boloka lintlha tse ngata tsa bohlokoa: litokomane, mangolo a tumello ea ak'haonte, phihlello ea VPN, litifikeiti, kapa linotlolo tsa encryption. Lik'homphieutha tsa desktop le tsona li tobana le liphephetso tse ikhethang: lisebelisoa li ntlafatsoa khafetsa, li tsamaisoa habonolo, 'me ka linako tse ling li arolelanoa ke basebelisi ba bangata. TPM e thusa ho thibela likotsi tse latelang:
– Bosholu ba data ha sesebediswa se lahlehile/se fihlelletswe ke motho e mong: ka ho ngolwa ha data ho itshetlehileng ka TPM, data e dula e notletswe leha polokelo e ka iswa sesebediswa se seng.
– Litlhaselo tsa Bootkit/firmware: TPM e ka rekota le ho netefatsa botšepehi ba ts'ebetso ea boot.
– Bosholu ba dinotlolo tsa cryptographic: dinotlolo tsa poraefete di ka bolokwa ho TPM ho etsa hore ho be thata le ho feta hore malware a di tshware.
Tsela eo TPM e sebetsang ka eona e bonolo
TPM e sebetsa e le "sebaka" se senyenyane bakeng sa ts'ebetso ea cryptographic. Ha sistimi e hloka ho hlahisa, ho boloka, kapa ho sebelisa linotlolo (mohlala, bakeng sa encryption ea disk), TPM e ka:
– Theha para ya dinotlolo (tsa setjhaba/tsa poraefete) ho TPM.
– Boloka linotlolo tsa poraefete e le hore li se ke tsa ntšoa habonolo.
– Etsa mesebetsi ea crypto (mohlala, ho saena kapa ho hlakola mongolo) ntle le ho senola senotlolo sa poraefete sa sistimi e sebetsang.
Khopolo ea bohlokoa ho TPM ke PCR (Platform Configuration Registers). Li-PCR li boloka "li-fingerprint" (li-hashe) tsa likarolo tsa boot tse kang firmware, li-bootloader, le li-configurations tse itseng. Haeba liphetoho tse sa lumelloang li etsahala—mohlala, bootloader e fetoloa—boleng ba PCR boa fetoha. Phetoho ena e ka baka ho haneloa ha phihlello ho senotlolo kapa ea baka mokhoa oa ho hlaphoheloa.
Likarolo tsa bohlokoa tsa TPM ho desktop
1. Polokelo e sireletsehileng haholoanyane ea senotlolo sa cryptographic
TPM e boloka dinotlolo ka mokhoa o sireletsehileng. Sena se bohlokwa bakeng sa dinotlolo tse bonolo haholo tse kang:
– senotlolo sa ho encryption sa disk e felletseng,
- disetifikeiti tsa netefatso ya khamphani,
– senotlolo sa ho saena ka dijithale.
Leha e se 100% e sa sireletsehang litlhaselong tsohle, TPM e etsa hore bosholu ba linotlolo bo be thata haholo ho feta ho boloka linotlolo faeleng e tloaelehileng ho disk.
2. E tšehetsa ho encryption ea drive (mohlala, BitLocker)
Ho Windows, TPM e atisa ho sebediswa bakeng sa BitLocker. Ka TPM, senotlolo sa ho notlolla drive se ka "tlangwa" (se kwalwa) boemong bo itseng ba ho qala. Sephetho:
– Haeba polokelo e tlosoa mme e kentswe ka har'a PC e 'ngoe, data e lula e patiloe.
– Haeba ho na le phetoho e belaetsang ea boot, BitLocker e kopa senotlolo sa ho hlaphoheloa.
Li-desktop tsa ofisi, motswako oa TPM + PIN o atisa ho khothaletsoa: TPM e boloka botšepehi, PIN e eketsa ntlha ea netefatso, e leng se etsang hore e sireletsehe haholoanyane haeba sesebelisoa se utsuoa.
3. Boot e Sireletsehileng le Boot e Lekaneng
Secure Boot e netefatsa hore ke dikarolo tse tshepahalang feela tse sebediswang. TPM e eketsa lera le leng ka Measured Boot, e tlalehang di-hashe tsa dikarolo tsa boot ho PCR. Sena se dumella sistimi ho:
– lemoha liphetoho ketane ea boot,
– etsa bopaki (netefatso ea botšepehi) lits'ebeletsong tsa tsamaiso ea lisebelisoa marang-rang a koporasi.
4. Tšireletso le netefatso ea mangolo a tumello
Ho Windows ea sejoale-joale, TPM e bapala karolo likarolong tse kang:
– Windows Hello (PIN/biometric) e hokahanyang mangolo a bopaki le sesebediswa,
– tshireletso ya mangolo a itseng a boitshupo kgahlanong le bosholu ba malware,
– tšehetso bakeng sa litifikeiti tsa karete e bohlale ea inthanete.
Bakeng sa lik'hamphani, sena se ka ntlafatsa ts'ireletso ea ho kena ntle le ho itšetleha kamehla ka li-password tse bonolo ho li hakanya kapa tsa phishing.
TPM 2.0 le bohlokoa ba eona ho Windows 11
Lebaka le leng leo TPM e seng e tumme hakaale ke hobane Windows 11 e hloka TPM 2.0 disebedisweng tse ngata. Sena ha se feela "moedi," empa ho ena le hoo ke ho netefatsa botsitso ba dikarolo tsa tshireletso tsa sejwalejwale, tse kang:
– tšireletso e matla ea lieta,
– tšehetso ea ho patala sesebelisoa,
– tshireletso e ntlafetseng bakeng sa tsamaiso ya Windows.
Khomphutheng ea desktop e ikhethileng, sena se bolela hore basebelisi ba hloka ho netefatsa hore bo-motherboard ba bona le CPU li tšehetsa TPM 2.0 (ebang ke ka TPM e arohaneng kapa fTPM) le ho e nolofalletsa ho BIOS/UEFI.
Mokhoa oa ho nolofalletsa TPM khomphuteng ea desktop
TPM ka kakaretso e ka buloa ka BIOS/UEFI. Lebitso la khetho le ka fapana ho latela morekisi:
– Ho Intel, ka linako tse ling e bitsoa PTT (Platform Trust Technology).
– Ho AMD, hangata e bitsoa AMD fTPM.
– Libotong tse itseng tsa mama ho na le hlooho bakeng sa mojule oa TPM o arohaneng.
Hang ha e se e kentswe tshebetsong, sistimi e sebetsang hangata e ka lemoha TPM. Ho Windows, o ka hlahloba ka ho thaepa `tpm.msc` ho Run ho bona boemo ba TPM le mofuta.
Meeli le lintho tseo u lokelang ho li ela hloko
TPM ha se "antivirus" mme ha e tiise hore e na le boits'ireletso bo felletseng. Ho na le lintlha tse 'maloa tsa bohlokoa:
1. TPM ha e thibele malware eohle
Haeba o pepesehetse malware e sebetsang ha sistimi e ntse e kene, TPM e ke ke ea thibela ka bohona ho utsuoa ha data e seng e pepesitsoe. TPM e matla haholoanyane ho sireletseng linotlolo le botšepehi ba boot.
2. Liphetoho tsa Hardware/firmware li ka baka ho hlaphoheloa
Ho nkela dikarolo tse itseng sebaka, ho ntjhafatsa BIOS, ho fetola tlhophiso ya boot, kapa ho tsamaisa drive ho ka baka kopo ya senotlolo sa ho hlaphoheloa (haholoholo ka BitLocker). Sena se tlwaelehile kaha TPM e lemoha phetoho.
3. Bohlokoa ba senotlolo sa ho hlaphoheloa ha bekapo
Haeba o sebedisa BitLocker, senotlolo sa ho hlaphoheloa se lokela ho bolokwa ka mokhoa o sireletsehileng (mohlala, akhaonteng ya Microsoft, Active Directory, kapa mookameli wa phasewete wa kgwebo). Ntle le senotlolo sa ho hlaphoheloa, data e ka notlelwa ka ho sa feleng.
4. TPM e arohaneng khahlanong le fTPM
Hangata li-TPM tse arohaneng li itšehla thajana, ha li-fTPM li itšetlehile ka ts'ebetsong ea firmware. Leha ho le joalo, maemong a mangata a desktop, fTPM e ntse e fana ka lintlafatso tse kholo tsa ts'ireletso ho feta ho se be le TPM.
Mekhoa e metle ea ho sebelisa TPM ho li-desktop
Ho eketsa melemo ea TPM, mekhoa e 'maloa e khothaletsoang:
– Kenya TPM 2.0 tshebetsong mme o sebedise mokgwa wa UEFI (eseng wa legend).
– Kenya tshebetsong Secure Boot haeba sesebediswa le OS di e tshehetsa.
– Sebelisa BitLocker (kapa mokhoa o mong oa ho boloka li-disk encryption o sebelisang TPM) haholo-holo ha u boloka lintlha tsa bohlokoa.
– Nahana ka TPM + PIN bakeng sa disebediswa tse kotsing ya ho utsuwa.
– Boloka senotlolo sa ho hlaphoheloa sebakeng se sireletsehileng se arohaneng le sesebediswa.
– Etsa lintlafatso tsa BIOS/UEFI le OS khafetsa ho koala likheo tsa ts'ireletso.
Qetello
TPM ke karolo ea bohlokoa ts'ireletsong ea lik'homphieutha tsa sejoale-joale tsa desktop. Ka ho boloka linotlolo tsa cryptographic ka mokhoa o sireletsehileng, ho tšehetsa ho ngoloa ha drive, ho netefatsa botšepehi ba ts'ebetso ea ho qala, le ho nolofalletsa netefatso e matla, TPM e fana ka motheo oa ts'ireletso ho tloha motsotsong oo sesebelisoa se qalang ho sebetsa ka oona. Le hoja e se tharollo e lekanang le tsohle litšokelong tsohle, TPM e sebetsa hantle haholo e le "lera la motheo" la ts'ireletso - haholo-holo ha e kopantsoe le Secure Boot, ho ngoloa ha disk, le mekhoa e metle ea tsamaiso ea mangolo. Bakeng sa basebelisi ba lapeng le ba khoebo, ho nolofalletsa le ho sebelisa TPM ke mohato o sebetsang oa ho fokotsa kotsi ea ho robeha ha data le litlhaselo tse tsoetseng pele lik'homphieutheng tsa desktop.
Haeba o lakatsa, nka fetola sengoloa sena hore e be mofuta o tekheniki haholoanyane (ho buisana ka PCR, ho tiisa/ho notlolla, bopaki) kapa mofuta o tsebahalang haholo bakeng sa babali ba seng tekheniki.