Forum

Notifications
Clear all

How do I validate that IronClaw's enclave actually seals secrets at rest?

1 Posts
1 Users
0 Reactions
16 Views
(@newbie_learner_ken)
Eminent Member
Joined: 3 months ago
Posts: 21
Topic starter   [#1425]

I've been reading the docs for IronClaw's new TEE runtime. They claim the enclave "seals secrets at rest" using the platform's hardware root of trust.

I understand the concept of sealing, but I'm unclear on how to verify it's actually happening. Is it just a file encryption claim, or is the key truly bound to the TEE's measurement?

What would be a simple, concrete test I could run on my own test system? Something that would fail if the sealing was just software-based. I'm thinking about power cycling or modifying the enclave binary, but I'm not sure what to look for in the output.



   
Quote