Intel
Ukuhlasela kuyingozi kuphela kumongo wokukhohlisa ngezibalo kuma-SGX enclaves, ngoba kudinga amalungelo ezimpande ohlelweni ukuze kwenziwe. Esimweni esilula, umhlaseli angakwazi ukuzuza ukuhlanekezelwa kolwazi olucutshungulwe ku-enclave, kodwa ezimweni eziyinkimbinkimbi kakhulu, ithuba lokudala kabusha okhiye abayimfihlo abagcinwe ku-enclave esetshenziselwa ukubethela usebenzisa i-RSA-CRT kanye ne-AES-NI algorithms ayikho. ngaphandle. Indlela yokusebenza ingase isetshenziselwe ukukhiqiza amaphutha kuma-algorithms alungile ekuqaleni ukuze kuvuse ubungozi lapho usebenza ngenkumbulo, isibonelo, ukuhlela ukufinyelela endaweni engaphandle komngcele webhafa enikeziwe.
Ikhodi ye-prototype yokwenza ukuhlasela
Ingqikithi yendlela iwukudala izimo zokuvela kokonakala kwedatha okungalindelekile ngesikhathi sokubala ku-SGX, lapho ukusetshenziswa kokubethela kanye nokuqinisekiswa kwememori ku-enclave kungavikeli. Ukwethula ukuhlanekezela, kuvele ukuthi bekungenzeka ukusebenzisa ukuxhumana kwesoftware okujwayelekile ukulawula imvamisa namandla kagesi, okuvamise ukusetshenziselwa ukunciphisa ukusetshenziswa kwamandla ngesikhathi sokungenzi lutho kwesistimu nokwenza kusebenze ukusebenza okuphezulu ngesikhathi sokusebenza kanzima. Imvamisa nezici ze-voltage zidlula yonke i-chip, okuhlanganisa nomthelela wekhompuyutha endaweni engayodwa.
Ngokushintsha i-voltage, ungakha izimo lapho ukushaja kunganele ukuvuselela iseli yememori ngaphakathi kwe-CPU, futhi inani layo liyashintsha. Umehluko oyinhloko ekuhlaselweni
Uma leli nani elishintshiwe lisetshenziswa enqubweni yokuphindaphinda yenqubo yokubethela, okukhiphayo kuyenqatshwa ngombhalo we-cipher ongalungile. Njengoba inamandla okuxhumana nesibambi ku-SGX ukuze ibethele idatha yayo, umhlaseli angakwazi, okubangela ukwehluleka, aqongelele izibalo mayelana nezinguquko kumbhalo wemfihlo ophumayo futhi, emizuzwini embalwa, abuyisele inani lokhiye ogcinwe ku-enclave. Umbhalo wokokuqala ofakiwe kanye nombhalo olungile ophumayo uyaziwa, ukhiye awushintshi, futhi okukhiphayo kwe-ciphertext engalungile kubonisa ukuthi ingxenye ethile ihlanekezelwe enaluni eliphambene.
Ngemva kokuhlaziya amapheya wamanani we-ciphertexts elungile neyonakele eqoqwe ngesikhathi sokwehluleka okuhlukahlukene, kusetshenziswa izindlela zokuhlaziya ukwehluleka okuhlukile (i-DFA,
Amamodeli ahlukahlukene ama-Intel processors athintwa inkinga, okuhlanganisa ama-Intel Core CPU ane-6
Isizukulwane se-10, kanye nesizukulwane sesihlanu nesithupha sika-Xeon E3, isizukulwane sokuqala nesesibili se-Intel Xeon Scalable, Xeon D,
U-Xeon W no-Xeon E.
Ake sikukhumbuze ukuthi ubuchwepheshe be-SGX (
Source: opennet.ru