This is called the Endorsement Key, and you're correct, it never leaves the TPM. The TPM is a "black box" to the OS.