5 ms·
It does more than that. From the [ios security guide]: > The Secure Enclave provides all cryptographic operations for Data Protection key management and maint
by ikawe 9y ago
It does more than that.
From the [ios security guide]:
> The Secure Enclave provides all cryptographic operations for Data Protection key management and maintains the integrity of Data Protection even if the kernel has been compromised.
e.g. you can encrypt and decrypt, referencing a key by id, but without having the private key ever leave the enclave, even if the app or iOS kernel gets compromised.
[ios security guide] https://www.apple.com/business/docs/iOS_Security_Guide.pdf https://www.apple.com/business/docs/iOS_Security_Guide.pdf
The Secure Enclave section is pretty short and the entire document is very approachable.
- DennisP 9y agoSounds like basically what a cryptocurrency hardware wallet does. Several months ago I saw a project making wallet software that used the enclave. I forget who they were but I think they'll have a hard sell; everyone just reflexively assumed it was insecure because it was on a phone.
- ikawe 9y agoAnd yet you’d be hard pressed to do worse than any mainstream desktop OS.
- iancarroll 9y agoIndeed, cryptocurrency hardware wallets and the SEP are basically just HSMs (hardware security modules). It's unfortunate people would draw negative connotations from it being on a mobile device. The security architecture of iOS and the SEP combined with the relatively wide deployment of iPhones makes for a great number of use cases.
- yyzhero 9y agoThe secure enclave uses secp256r1 while blockchain typically use secp256k1. Since private keys can't be imported, blockchain devs still require software interface until one or the others adopts the scheme.
- bluesign 9y agoI think use case for blockchain will be private key derived from a key stored in secured enclave. Which is not the ideal case of course.
- DennisP 9y agoAh, too bad. Ethereum is supposed to be adding signature abstraction, so you can use whatever signature scheme you want; maybe using secp256r1 with phones would be a good application of that.
- onetom 9y agohttps://www.trustedkey.com https://www.trustedkey.com actually uses the Enclave and also the equivalent component (Secure Element) in Android phones. Both of these modules use the secp256r1 curve at least, so the signature verification algo which runs on the blockchain can be the same for both types of devices. (You can find some more details on this topic here: http://blog.enuma.io/update/2016/11/01/a-tale-of-two-curves-hardware-signing-for-ethereum.html http://blog.enuma.io/update/2016/11/01/a-tale-of-two-curves-...) Since the Byzantium fork there are some precompiles available for curve operations. Using those for the r1 curve signature verification in EVM code brought down the gas cost to practical levels.
- onetom 9y agoWas it https://www.trustedkey.com https://www.trustedkey.com ?
- userbinator 9y agoThat sounds like what's essentially a TPM.
- MertsA 9y agoIt's a bit more than a TPM, since it's running the Secure Enclave firmware on it. It's like a mix between a TPM and Intel ME.