- Encrypt the private key using the key stored in TPM and remove the unencrypted private key from the filesystem - Used the encrypted key intermittently for software-based encryption/decryption Change-Id: I46fc24102365292d9af6b51c582e3a3f74b2af5e