3 ms·
> One might argue that it is not always true that the adversary can program different keys into the NVM on a training device, for instance, when one-time progra
by _nhynes 5y ago
> One might argue that it is not always true that the adversary can program different keys into the NVM on a training device, for instance, when one-time programmable (OTP) memories like e-fuses or ROMs are used. We admit that such keys cannot be extracted using our approach.
The SGX remote attestation key is burnt into the chip during manufacture and isn’t programmable.
- no_time 5y agoExtracting a single SGX private key is less desirable but nonetheless practical even if the hardware gets destroyed in the process. You could load the extracted key into an emulator and do your computing that way. It just does not scale unfortunately. Decrypting the firmware of ME or AMD PSP this way could totally work though.