A dedicated security processor, discrete or firmware-based, that generates and stores cryptographic keys so they cannot be extracted from the device. Operating systems use it for disk-encryption key protection, measured boot, and hardware-backed device identities. TPM 2.0 is a baseline requirement for Windows 11 and underpins features such as device attestation and non-exportable certificate keys.