- Marquer comme nouveau
- Marquer
- S'abonner
- Sourdine
- S'abonner au fil RSS
- Surligner
- Imprimer
- Signaler un contenu inapproprié
I had an argument with my friend who says BIOS is also a part of TCB for an application using SGX and his point is as follows:
SGX support detection is indicated in CPUID EBX bit 02, but its availability to applications requires BIOS support and opt-in enabling which is not reflected in CPUID bits. So if your BIOS is corrupt or compromised, you could never be able to detect SGX and use SGX feature.
Does he make sense? because I remember reading it somewhere that SGX TCB is the only CPU.
- Marquer comme nouveau
- Marquer
- S'abonner
- Sourdine
- S'abonner au fil RSS
- Surligner
- Imprimer
- Signaler un contenu inapproprié
A compromised BIOS could disable SGX on a platform. But that's a DoS attack, which SGX has no way to prevent.
However, the BIOS is outside an enclave TCB. A running enclave doesn't "use" the BIOS.
Lien copié
- Marquer comme nouveau
- Marquer
- S'abonner
- Sourdine
- S'abonner au fil RSS
- Surligner
- Imprimer
- Signaler un contenu inapproprié
A compromised BIOS could disable SGX on a platform. But that's a DoS attack, which SGX has no way to prevent.
However, the BIOS is outside an enclave TCB. A running enclave doesn't "use" the BIOS.

- S'abonner au fil RSS
- Marquer le sujet comme nouveau
- Marquer le sujet comme lu
- Placer ce Sujet en tête de liste pour l'utilisateur actuel
- Marquer
- S'abonner
- Page imprimable