3 ms·
Enclaves (e.g. SGX) get you there without the need for fancy math. And you get to maintain normal computation (i.e. x86). Enclaves have the downside of being a
by strstr 8y ago
Enclaves (e.g. SGX) get you there without the need for fancy math. And you get to maintain normal computation (i.e. x86).
Enclaves have the downside of being a bit of a pain to use. But hell, FHE isn’t any easier.
- taejo 8y agoWith SGX you don't have to trust the cloud provider, but you still have to trust Intel. Of course, you're probably trusting Intel anyway, so this is perhaps just a theoretical concern.
- pgeorgi 8y agoWith homomorphic encryption, you have to trust Intel to build CPUs that calculate correctly. Except for FDIV style bugs (which are pretty rare, and it's telling that FDIV, from the mid-90s is the go-to example), they mostly managed to maintain that trust. With SGX you have to trust Intel to build CPUs that isolate securely. Meltdown, Spectre (multiple variants), bugs in Intel TXT and ME, and that's only some of the headline issues from the last 4 years.
- tzs 8y ago...and if there are bugs, with SGX they could expose your secrets. With homomorphic encryption they should just turn your results into detectable garbage on your end, I'd expect.
- tdullien 8y agoIt is somewhat doubtful, though, that SGX achieves what it was supposed to achieve. While you get full-RAM encryption & integrity, the trouble is that CPUs tend to only work-as-defined for a narrow range of environmental parameters. In all likelihood, a malicious cloud provider can take a CPU out of spec, at which point pretty much all security guarantees go out of the window...
- strstr 8y agoMy understanding was that if you take the CPU out of spec (e.g. voltage) while in an enclave, you’ll get MCEs and the CPU either nukes your enclave or forcibly reboots (idr which). That said you can still shave it down and start FIBing if you have the $$$.