Presentation: The Security Challenges & Issues From SGX Practice

Track: Security: Attacking and Defending

Location: Bayview AB

Day of week:

Slides: Download Slides

Level: Intermediate - Advanced

Persona: Architect, Backend Developer, CTO/CIO/Leadership, Developer

Abstract

Intel® Software Guard Extensions (Intel® SGX) provides a trusted execution environment with hardware root of trust, brings powerful capability to build secure applications to solve data security problems. However applying SGX technology correctly and writing secure code are still a challenge.

In this talk, we want to present challenges and issues we saw with applying SGX to protect sensitive data in product. We will broadly discuss open problems including how to write ecall functions correctly, how to avoid potential side channel attack, what are the architecture issues when we apply secure AI with Intel® SGX.

Speaker: Xiaoning Li

Chief Security Architect @Alibaba Cloud

Xiaoning Li is Chief Security Architect at Alibaba Cloud. Previously he was a security researcher and architect at Intel Labs. Focused on analyzing/detecting/preventing 0 day/malware with existing/new processor features. For the past 10+ years, his work has been focusing on both hardware/software security system co-design and advanced threat research. Xiaoning holds 20+ grant/filling patents in security areas including processor/system security and has published more than 20+ conference/invited talks including BlackHat, CanSecWest, ShmooCon, Source etc.

Find Xiaoning Li at