8 ms·
I must be missing something, but how does one bootstrap an enclave securely? A malicious VM can emulate the new SGX mode, but lift the restriction of not being
by RDeckard 13y ago
I must be missing something, but how does one bootstrap an enclave securely? A malicious VM can emulate the new SGX mode, but lift the restriction of not being able to access the enclave's memory.
- anologwintermut 13y agoTXT handles this with a TPM that stores a key and has hardware to check that the proper instructions executed and signs an attestation to that fact with its key. SGX doesn't need a TPM. Does it possibly have similar hardware on die?
- sweis 13y agoSGX adds the ability to attest and seal individual enclaves, with a root attestation key in the CPU die: https://docs.google.com/file/d/0B_wHUJwViKDaSUV6aUcxR0dPejg/edit https://docs.google.com/file/d/0B_wHUJwViKDaSUV6aUcxR0dPejg/... This key has some similarities to a TPM EK / AIK, but rather than PCRs for the measurements they have a cryptographic log of the enclave.