HP Threat Research Blog Advancing Endpoint Protection Against Physical Attacks: The Innovation Behind HP TPM Guard

March 24, 2026 Category: Threat Research By: HP Wolf Security Comments: 0

Advancing Endpoint Protection Against Physical Attacks: The Innovation Behind HP TPM Guard

We rely on laptops for nearly every aspect of our working lives, which means they end up storing sensitive information that must be protected – confidential files, email, credentials, and often customer or employee data. When a device goes missing – whether lost or stolen – the real risk isn’t the cost of replacing the hardware, it is the data that may be exposed.

Against this backdrop, attackers have steadily expanded their focus from targeting software alone to interfering with a device’s security by exploiting hardware and firmware. Even a few minutes of physical access can be enough for an attacker to tamper with a device. Without the right defenses, it’s even possible to capture the cryptographic keys and other system secrets that are critical for securing the device and the data it holds, including the keys used to secure full disk encryption solutions like BitLocker in Windows.

These physical attacks don’t require the specialized and expensive equipment that once limited who could attempt them. Affordable tools costing under $20 USD, and widely shared tutorials, have dramatically lowered the barrier to entry, making techniques once associated with advanced research accessible to far more attackers than before.

Physical attacks on devices are becoming easier and cheaper

Figure 1 – Timeline showing falling expertise needed to perform a TPM bus sniffing attack

This growing trend matters because hardware attacks tend to be difficult to detect, stop and recover from, leaving significant gaps and blind spots in an enterprise’s defenses. In particular, physical attacks that succeed in breaking full disk encryption solutions like BitLocker can be catastrophic for a business – from exposing data that triggers financial and regulatory repercussions, to giving an attacker unauthorized access to other systems within an organization.

The rise in physical attacks calls for stronger hardware protection. Today, modern commercial PCs include a certified Trusted Platform Module (TPM) – a discrete hardware security chip that protects cryptographic keys inside a secure boundary. While the TPM provides important hardware protections, it alone cannot stop the advanced physical attack methods that have become cheaper and easier to perform in recent years. This is why HP is introducing HP TPM Guard – a new hardware security capability built into HP commercial PCs that applies a security-by-design approach to protect all software running on the device from this class of physical attacks.

Physical attacks on TPMs that break full disk encryption

Today, most organizations rely on full disk encryption solutions to protect device data, assuming that if a laptop is lost or stolen it remains protected and does not need to be reported to regulators as a potential data loss event.

Many full disk encryption solutions, including BitLocker, use the TPM to protect the disk decryption key. In practice, enterprises almost always configure full disk encryption schemes to automatically release the key if the expected firmware configuration is reported to the TPM during the boot process. This is done for convenience so that the encrypted drive is unlocked without any user interaction. On Windows, this TPM‑only mode is the default BitLocker configuration.

But this convenience has a major weakness. While the TPM validates early‑boot measurements to confirm the expected firmware was used during boot, it releases the disk decryption key to the CPU unencrypted. This key travels to the CPU over a hardware bus – a communication channel on the motherboard that carries data between components – where it is exposed to interception. Some firmware TPM implementations exist in chipsets without exposing an external bus, but none currently provide end users with the assurance that comes from third-party security evaluation under the Trusted Computing Group’s Certification program[1].

TPM bus sniffing attacks

In a TPM bus sniffing attack, a physical attacker who gains even brief access to the device can tap this hardware bus, capture the key as it moves from the TPM to the CPU, and bypass full disk encryption entirely. With the cleartext disk decryption key – such as BitLocker’s Volume Master Key (VMK) – the attacker can decrypt the entire drive offline, rendering all data readable and bypassing authentication, OS policies, and access controls.

Full disk encryption in TPM-only mode assumes the path between the TPM and CPU is trustworthy, but when that path is exposed on the motherboard, it becomes a high‑value target.

Certified TPMs have supported parameter encryption for years to protect communication from sniffing attacks, but it is left to individual software developers to implement. In practice, too many software solutions do not use this important security feature.

While adding extra authentication factors, like a boot-time PIN, strengthens protection for unattended devices, the resulting user friction and support costs mean many organizations still default to TPM-only mode. This creates a predictable attack window that attackers not only understand well, but can now exploit with tools that are cheaper and more accessible than ever.

Figure 2 – TPM bus sniffing attack showing how a BitLocker VMK can be intercepted to bypass full disk encryption

TPM move and interposition attacks

A second, more advanced type of physical attack – known as a TPM move attack – bypasses full disk encryption by exploiting the inability for the TPM to reliably verify the system it is running on. By physically moving a discrete TPM into another environment that mimics the expected platform state, the attacker can trick the TPM into believing it is still in its original device.

If this succeeds, the TPM will release its keys even though the legitimate CPU and firmware are no longer present. Because TPMs lack a cryptographic binding between the TPM and the CPU, this check can be defeated. This allows attackers to extract keys in ways the original design did not account for.

Alongside TPM move attacks, interposition attacks target the communication channel itself. Rather than relocating the TPM, the attacker inserts hardware between the CPU and the TPM to intercept, alter, or replay TPM commands. This allows an attacker to manipulate traffic in ways that can also bypass full disk encryption, for example by replaying trusted boot measurements.

How physical TPM attacks elevate the impact of lost and stolen devices

The rise of TPM bus sniffing and other physical attacks has changed what it means for a laptop to be lost or stolen. Because attackers can capture full disk encryption keys from an unprotected CPU-TPM path, the loss of a device can lead to the rapid compromise of sensitive data. Full disk encryption alone no longer guarantees confidentiality if an attacker can extract the key from a missing device.

This risk is amplified by how long it often takes for organizations to realise a device is missing. HP research found that in 83% of lost and stolen laptop incidents, more than an hour passed before IT teams were notified – and 42% were not reported for more than a full day[2]. That delay gives adversaries ample time to carry out physical attacks that defeat full disk encryption and extract the data stored on the device.

This makes securing the hardware channels that carry secrets like full disk encryption keys essential to limit the impact of inevitably lost and stolen PCs.

Introducing HP TPM Guard: Securing the CPU-TPM path against physical attacks

We are introducing HP TPM Guard into our commercial PCs as a direct response to the growing threat of physical attacks against TPMs. As attackers have shown, protecting keys inside the TPM is no longer enough – it’s also necessary to protect the path between the TPM and CPU. TPM Guard is designed to ensure that bus sniffing attacks against the TPM can no longer be used to extract full disk encryption keys or compromise the hardware root of trust.

To achieve this, HP worked closely with our CPU and TPM silicon partners to strengthen the architecture itself, closing the long‑standing blind spot at the bus level. TPM Guard cryptographically secures the communication channel between the CPU and the TPM using the industry‑standard Security Protocol and Data Model (SPDM). With this protection in place, all TPM responses – including full disk encryption keys – are sent through an authenticated and encrypted tunnel rather than travelling across the motherboard in cleartext. This makes physical bus sniffing attacks ineffective. TPM Guard is the world’s first hardware solution to stop physical TPM bus attacks[3].

Beyond this, TPM Guard also protects against advanced TPM move and interposition attacks. During manufacturing, HP establishes a pre‑shared hardware key that binds the TPM to its specific CPU. This binding ensures that a TPM removed from its original device – or presented with replayed measurements – can’t be tricked into releasing its secrets. Only the authorized host can establish the cryptographically validated session required for the TPM to operate.

By combining encrypted bus communication with platform‑level binding, TPM Guard protects customers from an entire class of physical TPM bus sniffing, move and interposition attacks. It gives organizations the assurance of a Trusted Computing Group Certified TPM, while removing the architectural weakness that enabled attackers to exploit and defeat full disk encryption. Because it works beneath the operating system (OS), it protects existing full disk encryption solutions and other software that uses the TPM without requiring OS patches.

Advancing the PC industry’s defenses

HP TPM Guard brings secure-by-design hardware protection to every PC user, protecting BitLocker deployments of all sizes from this growing risk of physical attacks. It is particularly important for customers in regulated industries, government, and organizations handling sensitive data – where device loss or theft carries especially high impact and any data exposure may need to be reported to regulators, making strong mitigation critical.

The introduction of TPM Guard is part of HP’s ongoing commitment to raise the bar for endpoint security, building on robust, certified hardware roots of trust that protect devices at every stage, beginning in the factory and through to decommissioning.

This approach reflects how HP has innovated in endpoint security for more than twenty years. Our HP Security Lab focuses on analyzing and identifying threat trends early, designing practical defenses for future products and solutions, and working with industry standards bodies to raise the baseline for everyone. For TPM Guard, we are already working with industry partners in the Trusted Computing Group to standardize new TPM SPDM support so it can be adopted by other vendors in the years ahead.

References

[1] For information about the Trusted Computing Group’s TPM Certification program, see: https://trustedcomputinggroup.org/membership/certification/

[2] Based on a survey of 6,055 office workers for HP’s Securing the Device Lifecycle Report.

[3] Based on HP internal analysis of business-class PCs with discrete TPM implementations as of February 2026. HP TPM Guard is a hardware-enforced security feature that protects TPM-to-CPU communications against certain physical attack techniques, including bus probing. Actual protection effectiveness may vary depending on system configuration and attack methods. HP TPM Guard is only available on specific PC platforms and may require a BIOS update.

About the Author

HP Wolf Security

Recent Posts

2026-03-24T13:29:26+00:00March 24th, 2026|Threat Research|