Configure dictionary attack threshold

Determines the number of allowed Trusted Platform Module authentication attempts, before dictionary attack defending measures are taken.

Enabled: Specify how many authentication attempts should be allowed for keys (e.g. used for Security Platform User authentication), owner, and for the access of sealed data (e.g. used by Windows BitLocker in combination with PIN), before dictionary attack defending measures are taken.

Disabled: The dictionary attack threshold cannot be configured. The default values are in effect.

Default value: Enabled. Owner: 3 attempts. Key: 5 attempts. Data: 10 attempts.

This policy is only relevant for Security Platforms with an Infineon Trusted Platform Module 1.2. It needs to be set before Security Platform Initialization. Subsequent changes of this policy will only be effective after the next defense level reset.
If this policy is not configured, then the same settings can be set individually for each platform in stand-alone mode via Initialization Wizard. In this case no defense level reset is needed for the settings to be effective.
Note that all Security Platform users share the number of allowed user authentication attempts. Consider this if there are multiple parallel users on a system (e.g. using Fast User Switching).

Supported on:

Registry HiveHKEY_LOCAL_MACHINE
Registry PathSoftware\Policies\Infineon\TPM Software
Value NameDictionaryAttackThreshold_Pol
Value TypeREG_DWORD
Enabled Value1
Disabled Value0

Key authentication

Allowed attempts:

Registry HiveHKEY_LOCAL_MACHINE
Registry PathSoftware\Policies\Infineon\TPM Software
Value NameDictionaryAttackThresholdUser
Value TypeREG_DWORD
Default Value5
Min Value1
Max Value10

Owner authentication

Allowed attempts:

Registry HiveHKEY_LOCAL_MACHINE
Registry PathSoftware\Policies\Infineon\TPM Software
Value NameDictionaryAttackThresholdOwner
Value TypeREG_DWORD
Default Value3
Min Value1
Max Value10

Data authentication

Allowed attempts:

Registry HiveHKEY_LOCAL_MACHINE
Registry PathSoftware\Policies\Infineon\TPM Software
Value NameDictionaryAttackThresholdData
Value TypeREG_DWORD
Default Value10
Min Value1
Max Value10

ifxsppol.admx