Intel® Software Guard Extensions (Intel® SGX)
Use hardware-based isolation and memory encryption to provide more code protection in your solutions.

Can SGX enclaves run at VMX root mode (or VMM)?

Bronze_me
Novice
249 Views

Hello,

Is it possible to run SGX enclaves at VMX root ring 3? As we know, Intel VMX root mode has ring0-3, so can we run a SGX enclave at VMX-root mode's ring3 and install the Intel SGX Driver at VMX-root mode's ring0?

 

That is, Can we run SGX enclaves correctly inside the VMM (or Hypervisor)

This question is inspired by one statement in the Intel SDM file: "Intel SGX functionality (including SGX1 and SGX2) can be made available to software running in either VMX root operation or VMX non-root operation", but there seems no additional description about running SGX enclave in VMX root mode.

Thanks.

0 Kudos
0 Replies
Reply