Thread (91 messages) 91 messages, 11 authors, 2018-12-13

RE: [RFC v2 00/13] Multi-Key Total Memory Encryption API (MKTME)

From: Huang, Kai <hidden>
Date: 2018-12-12 23:24:25
Also in: keyrings, linux-mm

I strongly suspect that, on L1TF-vulnerable CPUs, MKTME provides no
protection whatsoever.  It sounds like MKTME is implemented in the
memory controller -- as far as the rest of the CPU and the cache hierarchy
are concerned, the MKTME key selction bits are just part of the physical
address.  So an attack like L1TF that leaks a cacheline that's selected by
physical address will leak the cleartext if the key selection bits are set
correctly.
Right. MKTME doesn't prevent cache based attack. Data in cache is in clear.

Thanks,
-Kai
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help