850 karma · joined July 26, 2012
Importantly, a user who does not fully trust the machine administrator can still maintain integrity and confidentiality over their computation.
SGX memory encryption keys are ephemeral, they are generated at boot, and they do not need to be owned by anyone to be useful, on the contrary!
Code running in an SGX enclave is measured and absolutely known at enclave launch. The fact that enclave memory is encrypted for confidentiality is unrelated.
I don’t understand why you think trusting the hyper visor is helping anything. You are still open to this attack, and to all side channel attacks as soon as you run any untrusted code.
The scheme you suggest, which isn’t typically how TrustZone is used, gives zero integrity and confidentiality guarantees for applications. I don’t know if it’s “the right way” for some threat model, but for the most typical TEE use cases which are trying to establish strong integrity and confidentiality guarantees in the presence of an untrusted host, it’s absolutely not right nor useful.
I am baffled that a serious effort at producing papers that are understandable and implementable is dismissed as a “social phenomenon”. Deliberately obscure papers are bad, sloppy science, not a clever signaling mechanism.
As pointed out elsewhere in the conversation and indeed in revised editions of the Paxos paper, it does not even break new ground and is equivalent to the earlier view management protocol.