You can read up on Lotus2 and how it is structured if you want to learn more. But basically there is a security chip in every cart that when called, will generate a random password, this password is checked by the system. Think of it as a two-step verification process similar to google authenticator. This is different than the basic encryption and decryption of files, which is handled by the system itself and is independent of the cart or data.I don't think this is accurate. If it were, we'd likely already see XCI files from Switch 2 games. It would also mean that Nintendo didn't implement any type of full disk encryption. My understanding is that the card reader handles the full disk encryption on the cart and the Switch handles the decryption of the game (XCI) files.
What we know with certainty is that Nintendo does not implement any security handshake between the cart and the system S1 and S2 (when playing S1 games). The system thinks that the cart is legit and gives it a green light to play. MigFlash is just a loader not a decryption device. The reason why we do not see any XCI files from S2 games is that most likely, we do not know enough about the file protocol that Nintendo is using for the cart (Lotus3) and or files themselves (which may be organized differently than previous .XCI). Simply there is a lot we don't know.











