Intel Secure Guard for Application Systems

Intel has been working on security extensions to their processors to help in the overall security solution for systems. The overall concept looks promising. Fortunately, they’ve been heavily involved in building better support for this in Linux. You can follow highlights here:

Meanwhile, there are ways to conceptualize an application design that applies the extensions. Essentially abstract system primitives at the level of an application. In the process have the ability to expand or contract application boundaries. What would have been two applications are now one physical boundary. Managed runtimes do this all the time, but here you can refine the implementation in a more direct way.

In terms of the overall concepts expressed in Intel SGX, an application may be designed with features that improve resilience to compromise. The following is a rough blueprint I drafted in 2012 that is in alignment with the concepts in SGX:


