> generate a key that’s stored in this fortress.
It refers to the private key that is resident inside SecureEnclave. (During manufacturing)
See further. Dont just read one or two lines.
“The attacker can’t steal the private key from the device because the TPM / Secure Enclave will not release it. That is the core protection here,” Scott Helme, a researcher and founder of Report URI who blogged about the new protections on Tuesday, told Ars. “The attacker can steal the cookie, but they can’t answer a DBSC challenge by signing it with the private key, which is still safe on your device.”
Read https://support.apple.com/en-gb/guide/security/sec59b0b31ff/...