The idea was to put a second, secure computer into every device. This "trusted platform module" (or, sometimes, "technical protection measure") would be tamper-evident and tamper-resistant, contain some factory-installed, non-modifiable cryptographic signing keys, and run an extremely limited set of programs. It would observe and record the code your computer ran, from the bootloader to the OS and on up.
42/