I'm more interested by the fact that it apparently didn't work this way before Tahoe.
What happen though is the ability to encrypt the data with secure enclave, store it on our own. When migrating, we decrypt with secure enclave, get back original data and re-encryp on the new device.