3 ms·
Note that I don't know anything about SGX, but skimming very briefly through the first part of the below slides [1], it may look like it's just the ability to c
by csl 10y ago
Note that I don't know anything about SGX, but skimming very briefly through the first part of the below slides [1], it may look like it's just the ability to create — at runtime — special memory regions that are unreadable outside of the process space (as in, when the region is created, even root can't unscramble that region).
Or are we talking about execution of pre-encrypted code on disk that the machine owner can't disassemble? Because the former sounds like a good idea, while the latter sounds like an insanely bad one.
[1] https://software.intel.com/sites/default/files/332680-002.pdf https://software.intel.com/sites/default/files/332680-002.pd...
- the8472 10y agoThe former combined with the authentication aspect enables the latter. 1. plain-text code gets loaded into enclave 2. enclave generates a keypair 3. enclave authenticates itself against a 3rd party (the DRM/malware mothership) and sends it the pubkey 4. mothership sends additional secrets / code, only decryptable by the enclave 5. you now have uninspectable code running on your machine And since the enclave can persist itself with the sealing key the handshake only has to happen once, e.g. during the installation phase which often happens with elevated privileges, i.e. also includes network access. Oh, and the enclave also has access to the rest of the process memory, i.e. the system is not shielded from the actions of said uninspectable code.