3 ms·
How does a software running under SGX know that it is in a "real" processor enclave, and not in an enclave emulated around it which allows the emulator to actua
by giomasce 8y ago
How does a software running under SGX know that it is in a "real" processor enclave, and not in an enclave emulated around it which allows the emulator to actually peek inside and know what the software is doing? Virtual machines are already a thing, and if the virtual machine emulates the SGX interface it can very well support the extraction of memory encryption keys too...
- taejo 8y agoYou're right, of course, that the software can't know, since any test it did could simply be emulated to return the right result. But anyone that software talks to outside of the emulation can know. IIRC (I last looked at SGX a few years ago, and have moved out of cryptography subsequently) the processor has keypair with the corresponding certificate signed by Intel. The code running inside SGX can then create and distribute a public key with a certificate proving (if you trust Intel) not only that the keypair was generated inside SGX, but also which code has access to it, and a server can encrypt data using that key, and only that code will be able to decrypt it.