💾 Archived View for gemini.bortzmeyer.org › fosdem › event-11444.gmi captured on 2023-03-21 at 00:56:08. Gemini links have been rewritten to link to archived content
⬅️ Previous capture (2021-12-17)
-=-=-=-=-=-=-
Dmitrii Kuvaiskii
Type devroom
Running unmodified applications in SGX enclaves
Starts on day 1 (2021-02-06) at 10:55 (Brussels time, UTC+1) in room Hardware trusted (duration 00:25)
Matrix room #hardware trusted:fosdem.org
Graphene is a lightweight library OS, designed to run a single Linux application in an isolated environment. Currently, Graphene runs on Linux and Intel SGX enclaves on Linux platforms. With Intel SGX support, Graphene can secure a critical application in a hardware-encrypted memory region and protect the application from a malicious system stack with minimal porting effort.
This talk will discuss the design, implementation, features, lessons learned, and the current status of the project. The talk will highlight some of the technical challenges of enabling unmodified applications in restricted secure environments such as Intel SGX enclaves.