2 ms·
The TPM is an TCG standard (also ISO/IEC 11889), and specifies commands that support a lot of use cases. The Secure Enclave from Apple is something simpler and
by als0 3y ago
The TPM is an TCG standard (also ISO/IEC 11889), and specifies commands that support a lot of use cases. The Secure Enclave from Apple is something simpler and more restrictive, that is tailored only for Apple's use cases.
- jiveturkey 3y agosimpler? hardly. high level overview: https://support.apple.com/guide/security/secure-enclave-sec59b0b31ff/web https://support.apple.com/guide/security/secure-enclave-sec5... low level overiew: https://www.blackhat.com/docs/us-16/materials/us-16-Mandt-Demystifying-The-Secure-Enclave-Processor.pdf https://www.blackhat.com/docs/us-16/materials/us-16-Mandt-De... AFAIK, and it's hard to find the info since I don't have it handy, so I don't want to devote the searching time, but bringing it back on-topic, all disk i/o has to go through the secure enclave for encryption and decryption. i believe this is better documented on mac than iphone. the data storage is always encrypted since T2. If filevault is enabled, then the user's password gets mixed in with the T2 hardware keys. Because those keys can never leave T2, all disk i/o necessarily goes through it. This is vastly different than how TPM operates.
- als0 3y agoCounterpoint: https://trustedcomputinggroup.org/wp-content/uploads/TCG_TPM2_r1p59_Part3_Commands_pub.pdf https://trustedcomputinggroup.org/wp-content/uploads/TCG_TPM...