How we built Enclaves: Resolving clock drift in Nitro Enclaves
Blog post from Evervault
Evervault has been using AWS Nitro Enclaves for nearly three years and encountered unexpected clock drift issues that were not documented, leading to significant time discrepancies over time, which affected operations relying on precise timing. Initially, the clock drift was unnoticed because the encryption engine within Enclaves handled non-time-sensitive tasks and was frequently patched. However, during beta testing, users began experiencing errors related to certificate validation and token issuance due to inaccurate enclave time. An investigation revealed that the clock drift was proportional to the load on the enclave and that the clock was not synchronized after startup. As an interim solution, Evervault periodically restarted enclaves and later implemented a method to sync enclave time with the hypervisor clock, reducing drift to microseconds. To achieve more accuracy, Evervault plans to employ Cloudflare NTS for time synchronization from a trusted NTP server.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.