Sounds great. Where can I, the owner of the device request the keys?
(*) A TPM that is special for being baked into the CPU, and for being a known quantity that can thus be updated via Windows Update and used for Secure Boot attestation, but a TPM all the same.