Two separate teams of academic researchers have published papers describing flaws in Intel’s Software Guard Extensions. SGX enhances application security by letting developers partition sensitive information into enclaves with hardware-assisted enhanced security protection. The aim is to protect application code and data from disclosure or modification. The recently uncovered flaws can prevent SGX from achieving its goal by compromising long-term storage, and by allowing attackers to control data leakage.
New Flaws in Intel’s CPU Software Guard Extensions Revealed
Posted by: Richard Adhikari June 11, 2020 10:46 AMTwo separate teams of academic researchers have published papers describing flaws in Intel’s Software Guard Extensions. SGX enhances application security by letting developers partition sensitive information into enclaves with hardware-assisted enhanced security protection. The aim is to protect application code and data from disclosure or modification. The recently uncovered flaws can prevent SGX from achieving its goal by compromising long-term storage, and by allowing attackers to control data leakage.