Intel® Software Guard Extensions (Intel® SGX)
Discussion board focused on hardware-based isolation and memory encryption to provide extended code protection in solutions.

Can enclave refuse to be evicted from EPC?


I m now researching on the SGX, especially the eviction of EPC.

I think it is hard to completely trust the main memory under the untrusted OS environment.

Actually, if the EPC is evicted by untrusted OS, it will be stored in system memory.

And although it has confidentiality, integrity verification scheme, But what happens if malware undiscriminatingly remove that Enclave Page on system memory?

Isn't it dangerous? Then, is there other way to protects enclave from being evicted?

0 Kudos
0 Replies