Enclave Page Cache

E653457

Enclave Page Cache is a protected memory region used by Intel SGX to store and manage the code and data of secure enclaves during execution.

All labels observed (3)

How this entity was disambiguated

Statements (47)

Predicate Object
instanceOf Intel SGX component
protected memory region
abbreviation EPC
accessControlledBy SGX instructions
hardware access checks
accessRestrictedTo enclave execution mode
alsoKnownAs EPC
backedBy processor memory encryption engine
belongsToCategory hardware security feature
trusted execution environment memory
capacityType platform-dependent size
contains enclave code pages
enclave data pages
enclave heap pages
enclave stack pages
enclave thread control structures
definedIn Intel SGX architecture specifications
linked to: Intel SGX
encryptedIn DRAM
introducedBy Intel SGX version 1
linked to: Intel SGX
limitedResource yes
locatedIn processor physical address space
managedBy SGX Enclave Page Cache Map
linked to: Enclave Page Cache

SGX memory management hardware
monitoredBy Enclave Page Cache Map
linked to: Enclave Page Cache
pageSize 4 KB
partOf Intel SGX memory architecture
linked to: Intel SGX
purpose manage secure enclave memory during execution
store enclave code
store enclave data
relatedTo Enclave Page Cache Map
linked to: Enclave Page Cache

enclave lifecycle management
secure context switching for enclaves
requires BIOS or firmware SGX enablement
SGX-capable processor
securityProperty confidentiality protection for enclave pages
hardware-enforced isolation from non-enclave software
integrity protection for enclave pages
protection from direct access by system management mode
protection from direct access by the operating system
protection from direct access by virtual machine monitors
supports dynamic page allocation for enclaves
page eviction to regular memory
page reloading into EPC
usedBy Intel Software Guard Extensions
linked to: Intel SGX
usedFor trusted execution environments on Intel CPUs
visibleAs reserved physical memory region
vulnerabilitySurface side-channel attacks on memory access patterns

How these facts were elicited

Referenced by (4)

Full triples — surface form annotated when it differs from this entity's canonical label.

Intel SGX memoryRegion Enclave Page Cache
Enclave Page Cache managedBy SGX Enclave Page Cache Map
linked to: Enclave Page Cache
Enclave Page Cache relatedTo Enclave Page Cache Map
linked to: Enclave Page Cache
Enclave Page Cache monitoredBy Enclave Page Cache Map
linked to: Enclave Page Cache