Binary Code Retrofitting and Hardening Using SGX
Shuai Wang, Wenhao Wang, Qinkun Bao, Pei Wang, Xiaofeng Wang, Dinghao Wu · 2017
Trusted Execution Environment (TEE) is designed to deliver a safe execution environment for software systems. Intel Software Guard Extensions (SGX) provides isolated memory regions (i.e., SGX enclaves) to protect code and data from adversaries in the untrusted world. While existing research has proposed techniques to execute entire executable files inside enclave instances by providing rich sets of OS facilities, one notable limitation of these techniques is the unavoidably large size of Trusted Computing Base (TCB), which can potentially break the principle of least privilege.