Specifications: IC: INFINEON SLB9665
Type:
TCG Compliance:
TCG PC Client Platform TPM Profile (PTP) Specification; Family 2.0 (Trusted Platform Module Library; Family 2.0)
TCG PC Client Specific TPM Interface Specification (TIS), Version 1.3 (TPM Main Specification; Family 1.2 Revision 116)
Low standby power consumption
Defends Against:
Fault injection attacks
Physical attacks
Side channel attacks
Differential fault analysis attacks
RNG attacks
Sensor and test mode attacks
Dictionary attacks
Support OS:
Support Windows 8.1, Windows 10 Bitlocker.
Supported on X299, AM4 and newer platform motherboards.
Specifications: Controller: ASPEED AST2500
Feature: Base Board Management Controller (IPMI2.0 with iKVM support)
VGA (1920x1200@60Hz 32bpp)
Memory: 2 SPI flash ROM 32MB
1 DDR4 SDRAM 4Gb
Physical Status
Form Factor: Low profile PCIe add-in-card
Dimensions: 168.45 x 68.9 mm
I/O
Upstream interface: PCI Express2.0 x1
External: 1 RJ45 via Realtek RTL8211E for dedicated IPMI LAN (10/100/1000 Mbps), 1 DB-15 (VGA)
Internal connectors: 2 SMBus header
1 x PMBus header
1 x IPMB header
1 x BMC reset
1 x BMC debug header
1 x V BIOS or system BIOS ROM
2 x BMC ROM
1 x Dual ROM select header
1 x TPM (13-pin, LPC)
1 x LPC header (13-pin)
2 x Fan header
1 x USB2.0 (5-pin): KVM and standby power
1 x header (18-pin): GPIO, NCSI
1 x header (18-pin): case open, system fail, GPIO, SMBus, PECI, voltage monitoring
1 x COM port (9-pin)
1 x micro-SD connector
1 x ...
Security: Cryptographically signed firmware
Data at Rest Encryption (SEDs with local or external key mgmt)
Secure Boot
Secure Erase
Secured Component Verification (Hardware integrity check)
Silicon Root of Trust
System Lockdown (requires iDRAC9 Enterprise or Datacenter)
TPM 2.0 FIPS, CC-TCG certified, TPM 2.0 China NationZ
Security: Cryptographically signed firmware
Data at Rest Encryption (SEDs with local or external key mgmt)
Secure Boot
Secured Component Verification (Hardware integrity check)
Secure Erase
Silicon Root of Trust
System Lockdown (requires iDRAC9 Enterprise or Datacenter)
TPM 2.0 FIPS, CC-TCG certified, TPM 2.0 China NationZ
Security: Cryptographically signed firmware
Data at Rest Encryption (SEDs with local or external key mgmt)
Secure Boot
Secure Erase
Secured Component Verification (Hardware integrity check)
Silicon Root of Trust
System Lockdown (requires iDRAC9 Enterprise or Datacenter)
TPM 2.0 FIPS, CC-TCG certified, TPM 2.0 China NationZ
Security: Cryptographically signed firmware
Data at Rest Encryption (SEDs with local or external key mgmt)
Secure Boot
Secure Erase
Secured Component Verification (Hardware integrity check)
Silicon Root of Trust
System Lockdown (requires iDRAC9 Enterprise or Datacenter)
TPM 2.0 FIPS, CC-TCG certified, TPM 2.0 China NationZ
Security: Cryptographically signed firmware
Data at Rest Encryption (SEDs with local or external key mgmt)
Secure Boot
Secure Erase
Secured Component Verification (Hardware integrity check)
Silicon Root of Trust
System Lockdown (requires iDRAC9 Enterprise or Datacenter)
TPM 2.0 FIPS, CC-TCG certified, TPM 2.0 China NationZ
Security: Cryptographically signed firmware
Data at Rest Encryption (SEDs with local or external key mgmt)
Secure Boot
Secure Erase
Secured Component Verification (Hardware integrity check)
Silicon Root of Trust
System Lockdown (requires iDRAC9 Enterprise or Datacenter)
TPM 2.0 FIPS, CC-TCG certified, TPM 2.0 China NationZ
Security: Cryptographically signed firmware
Secure Boot
Secure Erase
Silicon Root of Trust
System Lockdown (requires iDRAC9 Enterprise or Datacenter)
TPM 2.0 FIPS, CC-TCG certified, TPM 2.0 China NationZ
Secured Component Verification (Hardware integrity check)
Data at Rest Encryption (SEDs with local or external key mgmt)
Security: Cryptographically signed firmware
Data at Rest Encryption (SEDs with local or external key mgmt)
Secure Boot
Secure Erase
Secured-core server
Secured Component Verification (Hardware integrity check)
Silicon Root of Trust
System Lockdown (requires iDRAC9 Enterprise or Datacenter)
TPM 2.0 FIPS, CC-TCG certified, TPM 2.0 China NationZ
Security: UEFI Secure Boot and Secure Start support
Immutable Silicon Root of Trust
FIPS 140-3 validation (iLO 6 certification in progress)
Common Criteria certification (iLO 6 certification in progress)
Configurable for PCI DSS compliance
Advanced Encryption Standard (AES) and Triple Data Encryption Standard (3DES) on browser
Support for Commercial National Security Algorithms (CNSA)
Tamper-free updates -- components digitally signed and verified
Secure Recovery -- recover critical firmware to known good state on detection of compromised firmware
Ability to rollback firmware
Secure erase of NAND
TPM (Trusted Platform Module) 2.0
Front bezel key-lock feature -- standard, available in both Tower and Rack models
Padlock slot, standard
Kensington Lock slot, standard
Chassis Intrusion detection option