Security
DeTEE Security
Technical security aspects of the DeTEE Cloud platform.
In order to provide the most secure and reliable Virtual Machines and Containers, DeTEE is relying on a few key technologies and techniques:
- Intel SGX (Software Guard Extensions);
- AMD SEV (Secure Encrypted Virtualization);
- Intel SGX DCAP (Data Center Attestation Primitives);
- mRATLS (Mutual Remote Attestation Transport Layer Security);
- hRATLS (Hybrid Remote Attestation Transport Layer Security);
- Sealing (Technique of saving sensitive information to the untrusted disk).
Note
In case of a zero day vulnerability in the specific hardware, DeTEE allows you to use different hardware providers so you can easy migrate to a different hardware.
Refer to this link to see the list of current vulnerabilities and mitigations for Intel SGX. TODO: add the link to a list of AMD vulnerabilities