3 ms·
The Secure Enclave in the T1 and all iPhones since the 5s has a unique key in the AES engine's silicon, that cannot be read even from the Secure Enclave's firmw
by thisacctforreal 8y ago
The Secure Enclave in the T1 and all iPhones since the 5s has a unique key in the AES engine's silicon, that cannot be read even from the Secure Enclave's firmware.
This key is "tangled" with user-supplied keys for per-device access to data.
I assume the T2 offers this same feature.
See UID in the glossary (page 80) or under Hardware security features (page 12) of the iOS 11 Security Guide
https://www.apple.com/business/docs/iOS_Security_Guide.pdf https://www.apple.com/business/docs/iOS_Security_Guide.pdf