3 ms·
> Intel actually had a similar tech without the RAM encryption some time ago, called TXT. Given that RAM encryption is literally the core function of SEV, any
by theevilsharpie 6y ago
> Intel actually had a similar tech without the RAM encryption some time ago, called TXT.
Given that RAM encryption is literally the core function of SEV, any functionality that lacks it is by definition dissimilar.
- thu2111 6y agoTXT had RAM protection, as in, other software or hardware devices couldn't read the protected memory areas. RAM encryption itself is primarily about stopping bus sniffing or cold boot attacks. Useful, but by no means the only kind of protection you need. Especially because combining encryption with authentication is very hard. It is easy to forget that encryption doesn't stop someone flipping bits and you can corrupt the plaintext in ways useful to an attacker by doing so, hence the rise of AES/GCM. But I don't think SEV uses AEAD? But the core technology is basically the same concept. You get a protected memory space (to some degree of protection), you can derive keys linked to the loaded code hash, and you can do remote attestation to set up a Diffie-Hellman handshake with the remote protected domain. All that stuff is identical between TXT and SEV.