Backup and Restore Security Platform Data

Infineon Security Platform

Infineon Security Platform Solution

Backup and Restore Security Platform Data

Security Platform Backup includes all data required in case of emergency. After a hardware or storage media failure or a Trusted Platform Module failure, Security Platform Restoration reestablishes access to Security Platform Features for all users.

In addition you can backup and restore your Personal Secure Drive data. Data from other applications using the Security Platform Solution (e.g. Secure e-mail) is not included in Security Platform backup.

  • In server mode Backup and Restoration of user credentials and settings is handled by Trusted Computing Management Server, except Backup and Restoration of Personal Secure Drive (PSD) image files.
  • The update of user credentials and settings which is handled by Trusted Computing Management Server is also based on Backup and Restore.

Backup Scope

Security Platform backup comprises the following data:

Security Platform Credentials and Settings
Backup Contents A copy of the user-specific credentials and settings which are stored on the Security Platform.
Purpose Restoration of user-specific credentials and settings after a hardware or storage media failure.
Otherwise users could not access Security Platform Features anymore and user data would be lost.
Archives
  • Automatically written Backup Archive ("System Backup Archive", e.g. file SPSystemBackup.xml and folder SPSystemBackup): Set up by Security Platform Administrator. Contains credentials and settings of all Security Platform Users (for one or multiple Security Platform computers). Also contains computer identification and user identification, which are used to match computers and users during the restoration process.
  • Manually written Backup Archive (e.g. SPBackupArchive.xml): Created by Security Platform User. Contains credentials and settings of one Security Platform User (for one Security Platform computer). Also contains computer identification and user identification, which are used to match computer and user during the restoration process.
Emergency Recovery
Backup Contents All Security Platform Basic User Keys, encrypted specifically for Emergency Recovery.
Purpose Re-encryption of all Basic User Keys after a Trusted Platform Module failure. In this case a new Security Platform has to be set up and a new owner is created. Emergency Recovery allows the re-encryption of Basic User Keys from the old owner to the new one.
Otherwise users could not access Security Platform Features anymore and user data would be lost.
Archives
  • Emergency Recovery data for all users is included in automatically written Backup Archives. It is also included for the concerned user in manually written Backup Archives, if Automatic Backup has already been configured at the time the manual backup is performed.
  • Emergency Recovery Token (e.g. SPEmRecToken.xml) or combined Emergency Recovery/Password Reset Token (e.g. SpToken_<PCName>.xml): Created by Security Platform Administrator. Is required for a restoration of Emergency Recovery data.
Personal Secure Drive
Backup Contents A copy of the PSD credentials, configuration settings and encrypted data.
Purpose Restoration of PSD encrypted data and configuration settings after a hardware or storage media failure.
Otherwise users could not decrypt their PSD data anymore.

Notes:

  • In contrast to the PSD Backup, standard hard disk backup tools produce unencrypted backups.
  • If the PSD credentials are lost and no credential backup is available, but the PSD image file or backup image file is available, this data can be recovered via Personal Secure Drive Recovery.

Archives
  • PSD configuration settings are included in both automatically written Backup Archives and manually written Backup Archives.
  • PSD backup file (e.g. SpPSDBackup.fsb): A backup copy of the PSD image file may be created during a Security Platform User's manual backup.

Types of Backup

Type Explanation
System Backup ("Automatic Backup") Always includes credentials and settings of computer and all users which are initialized at the time the system backup is performed (including Emergency Recovery data).

Details on how to perform System Backup

Manual Backup Includes credentials and settings of computer and current user.
Includes Emergency Recovery data for current user, if Automatic Backup has already been configured at the time the manual backup is performed.
Optionally you can backup currently configured Personal Secure Drive (PSD) image files for the current user.

Details on how to perform Manual Backup

Restoration Cases

Depending on the type of emergency there are different restoration cases:

Restoration Case Affected Restoration Scope
Broken hard disk or lost data Security Platform Credentials and Settings, Personal Secure Drive
New Trusted Platform Module Emergency Recovery
New Security Platform to be initialized Emergency Recovery, Security Platform Credentials and Settings, Personal Secure Drive

How to Backup and Restore

How to configure automatic backups ("System Backup") Software Component to use
Administrative Task: Configure automatic backups for all users (including Security Platform Credentials and Settings, Emergency Recovery and PSD configuration settings).

If Security Platform is not yet initialized:

Configuration via Quick Initialization Wizard

Here the System Backup is automatically configured with default settings.

Configuration via Security Platform Initialization Wizard

Follow the steps mentioned:

  • Launch Infineon Security Platform Settings Tool. In the Welcome page of Quick Initialization Wizard, select Advanced Initialization.
  • Select Security Platform initialization and click Next.
  • Set the Owner Password and click Next.
  • During the Initialization Wizard, check the checkbox Automatic Backup (includes Emergency Recovery) and click Next.
  • Browse to a location on the hard drive for saving the Backup Archive. A Backup Archive consisting of an XML file (e.g. SPSystemBackup.xml) and a folder (e.g. SPSystemBackup) will be created at the default location: \%ALLUSERSPROFILE%\My Documents\Security Platform.
  • The default scheduled backup is set to 12:00 PM, daily. To change the time, click Schedule..., select a start time to create a scheduled backup and click Ok, then click Next.
  • Select the option Create a new Recovery Token.
  • Browse to a location of your choice for saving the Emergency Recovery Token file (default file name: SPEmRecToken.xml).
  • Set a new token password and click Next.
  • Confirm the settings and click Next.
  • Check the checkbox Run automatic backup now. Click Finish on the Completion page.
  • Security Platform credentials and settings are backed up for the first time now. Regular backups will take place as scheduled.

If Security Platform is already initialized: Settings Tool - Backup - Configure...

Follow the steps mentioned:

  • Launch Infineon Security Platform Settings Tool and select Backup.
  • Click Configure... to launch the Initialization Wizard.
  • Browse to a location on the hard drive for saving the Backup Archive. A Backup Archive consisting of an XML file (e.g. SPSystemBackup.xml) and a folder (e.g. SPSystemBackup) will be created at the default location: \%ALLUSERSPROFILE%\My Documents\Security Platform.
  • The default scheduled backup is set to 12:00 PM, daily. To change the time, click Schedule..., select a start time to create a scheduled backup and click Ok, then click Next.
  • Confirm the settings and click Next.
  • Check the checkbox Run automatic backup now and click Finish on the Completion page.
  • Security Platform credentials and settings are backed up for the first time now. Regular backups will take place as scheduled.

In server mode this button is disabled as automatic backup is handled by Trusted Computing Management Server, i.e. no explicit configuration is necessary here by the user.

How to backup ("Manual Backup") Software Component to use
User Task: Run backup manually for the current user.

Follow the steps mentioned:

  • Launch Infineon Security Platform Settings Tool and select Backup. Settings Tool - Backup - Backup...
  • Click Backup... to launch the Backup Wizard.
  • Click Browse... and select a location on the hard drive for saving the Backup Archive (default file name: SpBackupArchive.xml). Click Next.
  • Configure your Personal Secure Drive backup settings (see Configure Personal Secure Drive Backup Settings) and click Next.
  • Confirm the settings and click Next.
  • Click Finish on the Completion page.

In server mode, you can only backup your Personal Secure Drives (PSD). In server mode, Trusted Computing Management Server performs the backup of user credentials and settings. Apart from the conditions mentioned above, this button is disabled, if Personal Secure Drive (PSD) is not configured.

How to restore Software Component to use
Administrative Task: Prepare restoration for certain users.
User Task: Run restoration manually for current user. If restoration has been prepared for current user, then complete the restoration.

If a manually written Backup Archive is available and no Emergency Recovery data needs to be restored, then a user can perform restoration without preparation by an administrator.

Settings Tool - Backup - Restore All...
How to restore ("Manual Restore") Software Component to use
User Task: Run restoration manually for current user.

If Emergency Recovery data is included in a manual backup and the current user is administrator, this backup can be used also for an Emergency Recovery restoration of the current user.

Follow the steps mentioned:

  • Launch Infineon Security Platform Settings Tool and select Backup. Security Module - Backup - Restore...
  • Click Restore... to launch the Backup Wizard.
  • If you want to restore your settings and credentials, check the checkbox Restore my settings and credentials. Click Browse... and navigate to the Backup Archive (default file name: SPBackupArchive.xml).
  • Click Next.
  • Authenticate yourself and click Next.
  • Confirm the settings and click Next.
  • If you want to restore one or more Personal Secure Drives, configure your Personal Secure Drive restoration settings (see Configure Personal Secure Drive Restore Settings).
  • Click Next.
  • Confirm the settings and click Next.
  • Optionally you can check the checkbox Start Security Platform User Initialization Wizard if you want to configure other Security Platform features.
  • Click Finish on the Completion page.
  • Your certificates are restored now. You can view your certificates in User Settings - Security Platform Certificates.
  • Right click on the Taskbar Notification Icon and load your Personal Secure Drives. Authenticate yourself.

In server mode, you can only restore your Personal Secure Drive (PSD). In server mode, Trusted Computing Management Server performs the restoration of credentials and settings.

Policies related to Backup


©Infineon Technologies AG