I have been recently looking into TPM 2.0 technology and I'm trying to figure out how to preserve keyhendle after let's say application rerun. I figured I need to use TPM2_ContextSave as this function wraps and encrypts all the blobs and whatnot so that only TPM that created the context can read it back. This, therefore, should be the correct way to store your "keys" in a file for instance.
Should you need to use this key for decrypting or signing later (PC reboot, app rerun), TPM2_ContextLoad should give u the context (handle if you're loading keyhandle). This is as much as I got from Trusted Computing Group
docs.
TSS.MSR is a API with .NET variant. And my question lies with Tpm2ContextSaveRequest and Tpm2ContextLoadRequest.
Tpm2ContextSaveRequest has a constructor for TpmHandle. So this structure should be ok to write into a file and read later.
Tpm2ContextLoadRequest however has only Context constrictor.
Context has some other constructors calling for some other TpmHandle and ulong and it is at this point I'm getting lost in what is going on.
How do I achieve keeping my handle through app reruns?