Motion Computing Tablet PC TRUSTED PLATFORM MODULE (TPM) ACTIVATION User Guide
Trusted Platform Module Activation With the Infineon Security Platform Tools and the built-in Trusted Computing Group compliant Trusted Platform Module (TPM), you can create and manage digital certificates for user and platform authentication. These features are most commonly used by enterprises and require system administrator action before the individual Tablet PC user can access the security features. For individual users, the TPM can be used as an authentication device within Motion OmniPass. This is useful if you want to lock a document to the Tablet PC. Routine archival and backup procedures within an enterprise is a highly recommended practice. This is essential when using the advanced security features provided by Motion TM OmniPass TM and the TPM. Using an effective backup procedure is the only way to recover your data if the TPM fails, is cleared, or you experience a failure of the motherboard. You should perform off-system archival and backup procedures on a routine basis in your organization. Off-system archival and backup procedures require that the backup be made to a device or media other than the Tablet PC that you are using. Remember, there is no possibility of recovering any TPM-protected data if a recovery archive has not been created. For more information, see the OmniPass Help and the Infineon Help. To access the OmniPass Help: 1. Open the Motion Dashboard. 2. Tap Motion OmniPass. 3. In the Action section, tap Help. To access the Infineon Help: 1. Open the Motion Dashboard. 2. Tap Infineon TPM. 3. Tap Getting Started Guide. 4. In the left panel, double-tap Welcome to the Infineon Security Platform. 5. In the left panel, double-tap Getting Started Guide. 6. In the left panel, double-tap the book icon to expand the main topic and access sub-topics. 2 Trusted Platform Module (TPM) Activation
**Print these instructions before beginning the set up** SET UP AND CONFIGURE THE TPM 1. Go to C:\WINDOWS\Motion\Infineon_TPM. 2. Run setup.exe. 3. When the Tablet PC reboots, stop at the BIOS screen. a. While the Tablet PC is booting, a white screen (BIOS screen) with the Motion and Intel logos appears. b. As soon as the BIOS screen appears, press the Rotate button to interrupt the boot process and enter the BIOS. 3. Use the arrow keys on a keyboard or the buttons on the front of the Tablet PC to go to the Security tab. 4. Make sure the TPM is Enabled. Tap Disabled to select it, then tap Disabled again to Enable the TPM. NOTE: To prevent unauthorized users from accidentally tampering with the TPM and destroying sensitive data, set a supervisor password in the BIOS. 5. At the bottom of the screen (shown in the figure below), tap F10 to Save and Exit the BIOS. Trusted Platform Module (TPM) Activation 3
INITIALIZE THE TPM If your TPM has not been initialized for your Tablet PC, perform the following procedure. Perform this procedure only once to initialize the TPM for your Tablet PC. To initialize the TPM for your Tablet PC, you must be logged on to the computer as an administrator. 1. Open the Infineon Security Platform Settings tool by opening the Motion Dashboard. To open the Motion Dashboard, press the Motion Dashboard button on the Tablet PC or go to the menu Start > All Programs > Motion Resources > Motion Dashboard. 2. In the Motion Dashboard, tap Infineon TPM. 3. Tap the User Settings tab. A dialog box opens showing Security Platform is not initialized. Do you want to start the Infineon Security platform Initialization Wizard? 4. Tap Yes. The Infineon Security Platform Initialization Wizard opens. 5. Tap Next to start the wizard. 6. Enter the owner password. The owner password is similar to the administrator password for a computer. However, unlike a computer, the TPM can have only one owner. NOTE: For improved security, the owner password and the administrator password should not be the same. 7. Tap Next. 8. Decide whether to create a new recovery archive, and then tap Next. NOTE: Motion strongly recommends that you create a new recovery archive. After creating your recovery archive, store it in a location other than on the same computer. 9. If you have chosen to create a new recovery archive, the next screen prompts you for a password. Enter a password and tap Next. 10. Browse to select the location for the recovery token, and then tap Next. 11. Confirm the actions that the wizard is about to perform and tap Next. 12. Before you finish using the Infineon Security platform Initialization Wizard, you have the option to select Start Security Platform User Initialization Wizard. If you intend to use the TPM for this account, put a check in the box and tap Finish. 4 Trusted Platform Module (TPM) Activation
SET UP THE USER To use the TPM on a Tablet PC, you must be designated as a user. If you are not designated as a user, you can manually add yourself using the Infineon Security Platform User Initialization Wizard. 1. Open the Infineon Security Platform Settings tool by opening the Motion Dashboard. To open the Motion Dashboard, press the Motion Dashboard button on the Tablet PC or go to the menu Start > All Programs > Motion Resources > Motion Dashboard. 2. In the Motion Dashboard, tap Infineon TPM. 3. Tap the User Settings tab. A dialog box opens showing Security Platform is not initialized for the current user. Do you want to start the Infineon Security Platform Initialization Wizard? 4. Tap Yes. The Security Platform User Initialization Wizard opens. 5. Tap Next to start the wizard. The next screen prompts you for a basic user key password that you create. 6. Enter a password and tap Next. 7. Confirm the actions that the wizard is about to take and tap Next. 8. Select the TPM features you want to enable and tap Next. The selections include: Secure email - Check this selection to use digital certificates to secure email. File and folder encryption (EFS) - TPM-protected encryption keys. Check this selection to use TPM within Windows EFS encryption. Personal secure drive - Check this selection to create an encrypted partition on your hard drive, which can be viewed and accessed only by you. To learn more about these features, go to Start > All Programs > Infineon Security Platform Tools > Getting Started Guide. Depending on the features you want to enable, the wizard guides you through the set-up of those features. Once you complete the wizard, you are required to restart the computer. Trusted Platform Module (TPM) Activation 5
Enrolling the TPM in OmniPass NOTE: Use the following procedure only if you are not already enrolled in OmniPass. If you are enrolled in OmniPass and want to enroll the TPM in OmniPass, you must make settings changes in the Motion Dashboard: In the Motion Dashboard, select Motion OmniPass > Manage OmniPass Users and Settings > Change User Setting > Enroll Authentication Devices. To use the TPM as an authentication device, you must enroll the device in OmniPass. 1. Open Motion OmniPass by opening the Motion Dashboard. To open the Motion Dashboard, press the Motion Dashboard button on the Tablet PC or go to the menu Start > All Programs > Motion Resources > Motion Dashboard. 2. In the Motion Dashboard, tap Motion OmniPass. Or, select the menu Start > All Programs > Motion OmniPass > Omnipass Control Center. 3. To enroll a device, go to Manage OmniPass Users and Settings > Add a new user to OmniPass. Enter your windows logon information. If you are not set up on a domain, Domain should be the computer name. 4. Tap Next. 5. Tap the TPM icon, and then tap Next. 6. Select Use the digital certificate that OmniPass has automatically created for me. Or, select a digital certificate that you have installed and tap Next. 7. In the dialog box, enter your user password and select the box to remember the password for all applications. Tap OK. Note: If you are following strong security practices, this step is not recommended. 8. A message opens stating the TPM has been successfully enrolled. Complete the enrollment wizard. 9. When a dialog box opens asking if you want OmniPass to log you on, tap Yes. 6 Trusted Platform Module (TPM) Activation
Setting up the authentication rules The TPM can be configured as a required authentication device within OmniPass. 1. In the main OmniPass window, go to Manage OmniPass Users and Settings > Change User Settings > Set user authentication rules and policies. You are asked to verify your identity with OmniPass. 2. To verify your identity, tap the TPM icon or key icon. The Set Authentication Rules window opens. 3. Select each box where you want TPM authentication to be a requirement. For example, if you selected File and Folder Encryption and Decryption, the TPM is required to decrypt any file that was encrypted on that Tablet PC. Trusted Platform Module (TPM) Activation 7
2006 Motion Computing, Inc. (March 2006) All Rights Reserved - TPM Activation Rev. TD-03 8 Trusted Platform Module (TPM) Activation