Enhancing TPM security in the Linux Kernel @socallinuxexpo
Enhancing TPM security in the Linux Kernel  @socallinuxexpo
Uploaded July 2026 | Updated September 2026, 1 week ago
Talk by James Bottomley

socallinuxexpo.org/scale/23x/presentations/enhancing-tpm-security-linux-kernel

Note: Unfortunately the first few minutes of the talk are missing due to a technical issue.

Recent security updates to Linux, such as the new Systemd Unified Kernel Image rely on the discrete or firmware integrated TPM (Trusted Platform Module) to verify boot and release secrets securely. However, there are many known attacks against the TPM chip itself. We will discuss the newly upstreamed Linux Kernel TPM security patches, which not only provide a basis for securely communicating with the TPM but also provide a novel defences against a wide variety of TPM based attacks by using a unique (to Linux) null key scheme. This talk will cover what TPM based attacks are (including interposer attacks), how the Trusted Computing Group expects you to tell you're talking to a real TPM and how you can communicate with it securely and use its policy statements to govern key use and release. We will then move on to how the new Linux Kernel patches extend this and can be leveraged to validate the TPM on every boot and continually monitoring it for any TPM interposer substitutions in real time.  The new TPM trust verification tools are available under LGPL as ancillary tools in the upser space openssl tpm engine project.
Enhancing TPM security in the Linux KernelAgents for Healthcare Chart ReviewSource Available is Thriving but Open Source is DyingThe Transparency Stack: LA Countys Open-Source Model for Public-Facing Analytics and TrustGPU Sharing Done Right: Secrets, Security, and ScalingHow You Can Embrace Communications and Community and Learn to Love ReviewsThe Hidden Lives of Temp Tables: Unraveling MySQL Internal ManagementPostgres as an AI Control Plane: Building RAG + MCP Workflows Inside the DatabaseWhat Developers Should Know About Hardware ArchitectureBuilding an Open-Source AI Factory with Upstream Projects - A PrimerDid VS Code Quietly Become a Go-To Postgres Tool?Demystifying Kubernetes API Priority and Fairness
Southern California Linux Expo |

Enhancing TPM security in the Linux Kernel

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER