3 ms·
Anyone know where the AES key is stored for the encrypted memory? Is is a fixed, hardcoded key inside the processor, or does the user set it by some means?
by laydn 9y ago
Anyone know where the AES key is stored for the encrypted memory? Is is a fixed, hardcoded key inside the processor, or does the user set it by some means?
- daxorid 9y agoSpeculation here. Since the PSP is effectively leveraging TrustZone, I'm guessing it's generated and stored inside the TrustZone itself. This article states it's generated by a hardware RNG, so user control is unlikely. One important factor missing from this article is the AES cipher mode being used. Not sure how you'd be able to use an authenticated mode and maintain random access, so maybe XTS or even ECB?
- amluto 9y agoSGX does it, but it's quite complicated. SME is unauthenticated AFAIK.
- TazeTSchnitzel 9y agoFor whole-system RAM encryption (SME, i.e. not VMs), it's generated by the processor at boot time, and stored within it. Short of finding some sort of silicon backdoor, you can't get at it. For SEV (VM encryption), I believe the keys are managed by the hypervisor.
- srcmap 9y agoFrom the article: "Secure Virtualized Encyrption (SEV). SEV in many ways resembles the SME, but in this case, it enables owners to encrypt virtual machines, isolating them from each other, hypervisors, and hosting software. " Sounds like the keys are managed by VMs can isolated from hypervisors/hosting software.