Infineon Security Platform Solution |
Backup and Restore Security Platform Data
Security Platform Backup includes all data required in case of emergency. After a hardware or storage media failure or a Trusted Platform Module failure, Security Platform Restoration reestablishes access to Security Platform Features for all users.
In addition you can backup and restore your Personal Secure Drive data. Data from other applications using the Security Platform Solution (e.g. Secure e-mail) is not included in Security Platform backup.
|
Backup Scope
Security Platform backup comprises the following data:
Security Platform Credentials and Settings | |
Backup Contents | A copy of the user-specific credentials and settings which are stored on the Security Platform. |
Purpose | Restoration of user-specific credentials and settings after a hardware or storage media failure. Otherwise users could not access Security Platform Features anymore and user data would be lost. |
Archives |
|
Emergency Recovery | |
Backup Contents | All Security Platform Basic User Keys, encrypted specifically for Emergency Recovery. |
Purpose | Re-encryption of all Basic User Keys after a Trusted Platform Module failure. In this case a
new Security Platform has to be set up and a new owner is created. Emergency Recovery allows the re-encryption of Basic User Keys from the old owner to the new one. Otherwise users could not access Security Platform Features anymore and user data would be lost. |
Archives |
|
Personal Secure Drive | |
Backup Contents | A copy of the PSD credentials, configuration settings and encrypted data. |
Purpose | Restoration of PSD encrypted data and configuration settings after a hardware or storage media failure. Otherwise users could not decrypt their PSD data anymore. Notes:
|
Archives |
|
Types of Backup
Type | Explanation |
System Backup ("Automatic Backup") | Always includes credentials and settings of computer and all users which are initialized at the time the system backup is performed (including Emergency Recovery data). |
Manual Backup | Includes credentials and settings of computer and current user.
Includes Emergency Recovery data for current user, if Automatic Backup has already been configured at the time the manual backup is performed. Optionally you can backup currently configured Personal Secure Drive (PSD) image files for the current user. |
Restoration Cases
Depending on the type of emergency there are different restoration cases:
Restoration Case | Affected Restoration Scope |
Broken hard disk or lost data | Security Platform Credentials and Settings, Personal Secure Drive |
New Trusted Platform Module | Emergency Recovery |
New Security Platform to be initialized | Emergency Recovery, Security Platform Credentials and Settings, Personal Secure Drive |
How to Backup and Restore
How to configure automatic backups ("System Backup") | Software Component to use |
Administrative Task: Configure automatic backups for all users (including Security Platform Credentials and Settings, Emergency Recovery and PSD configuration settings). |
If Security Platform is not yet initialized: Configuration via Quick Initialization Wizard Here the System Backup is automatically configured with default settings. Configuration via Security Platform Initialization Wizard Follow the steps mentioned:
If Security Platform is already initialized: Settings Tool - Backup - Configure... Follow the steps mentioned:
In server mode this button is disabled as automatic backup is handled by Trusted Computing Management Server, i.e. no explicit configuration is necessary here by the user. |
How to backup ("Manual Backup") | Software Component to use |
User Task: Run backup manually for the current user. |
Follow the steps mentioned:
In server mode, you can only backup your Personal Secure Drives (PSD). In server mode, Trusted Computing Management Server performs the backup of user credentials and settings. Apart from the conditions mentioned above, this button is disabled, if Personal Secure Drive (PSD) is not configured. |
How to restore | Software Component to use |
Administrative Task: Prepare restoration for
certain users. User Task: Run restoration manually for current user. If restoration has been prepared for current user, then complete the restoration. If a manually written Backup Archive is available and no Emergency Recovery data needs to be restored, then a user can perform restoration without preparation by an administrator. |
Settings Tool - Backup - Restore All... |
How to restore ("Manual Restore") | Software Component to use |
User Task:
Run restoration manually for current user. If Emergency Recovery data is included in a manual backup and the current user is administrator, this backup can be used also for an Emergency Recovery restoration of the current user. |
Follow the steps mentioned:
In server mode, you can only restore your Personal Secure Drive (PSD). In server mode, Trusted Computing Management Server performs the restoration of credentials and settings. |
Policies related to Backup
- The configuration of automatic backups can be enforced by the policy Enforce configuration of Backup including Emergency Recovery.
- The target backup path for automatic backups can be enforced by the policy Backup archive location.
- The System Backup update after significant changes of Security Platform data can be enforced by the policy Enforce immediate System Backup.
©Infineon Technologies AG