<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I will try to rephrase this: in Intel® Software Guard Extensions (Intel® SGX)</title>
    <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Provide-remote-attestation-to-external-user/m-p/1106807#M1212</link>
    <description>&lt;P&gt;I will try to rephrase this: Can a user (other than the ISV who has the private signing key) obtain a remote attestation&amp;nbsp;&lt;SPAN style="font-size: 1em;"&gt;from (or with the help of) the ISV but without the ISV being able to tamper with this attestation?&lt;/SPAN&gt;&lt;/P&gt;

&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 08 Jun 2017 16:24:33 GMT</pubDate>
    <dc:creator>David_B_1</dc:creator>
    <dc:date>2017-06-08T16:24:33Z</dc:date>
    <item>
      <title>Provide remote attestation to external user</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Provide-remote-attestation-to-external-user/m-p/1106804#M1209</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;In case external users (other than the enclave developer who has signed the enclave with his private key) &amp;nbsp;need to share data with the application enclave, is it possible for these users to get a certified measurement &amp;nbsp;of the application enclave&amp;nbsp;&lt;SPAN style="font-size: 13.008px;"&gt;(e.g. from the quoting enclave)&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="font-size: 1em;"&gt;without the enclave developer being able to tamper with this measurement?&lt;/SPAN&gt;&lt;/P&gt;

&lt;P&gt;In other words, can the enclave developer prove to an external user that it is safe the share his data with the enclave?&lt;/P&gt;

&lt;P&gt;Thanks, David&lt;/P&gt;</description>
      <pubDate>Mon, 15 May 2017 13:43:57 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Provide-remote-attestation-to-external-user/m-p/1106804#M1209</guid>
      <dc:creator>David_B_1</dc:creator>
      <dc:date>2017-05-15T13:43:57Z</dc:date>
    </item>
    <item>
      <title>May want to check this out:</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Provide-remote-attestation-to-external-user/m-p/1106805#M1210</link>
      <description>&lt;P&gt;May want to check this out:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://software.intel.com/en-us/articles/intel-software-guard-extensions-remote-attestation-end-to-end-example" target="_blank"&gt;https://software.intel.com/en-us/articles/intel-software-guard-extensions-remote-attestation-end-to-end-example&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 May 2017 13:25:46 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Provide-remote-attestation-to-external-user/m-p/1106805#M1210</guid>
      <dc:creator>AArya2</dc:creator>
      <dc:date>2017-05-16T13:25:46Z</dc:date>
    </item>
    <item>
      <title>Thanks Arya,</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Provide-remote-attestation-to-external-user/m-p/1106806#M1211</link>
      <description>&lt;P&gt;Thanks Arya,&lt;/P&gt;

&lt;P&gt;However, I don't think it answers my question. What I would like to know is if it is possible for an enclave to provide (with ISV's agreement) a remote attestation to an external user that is not the ISV (i.e. not the enclave developper who signed the enclave).&lt;/P&gt;

&lt;P&gt;&amp;nbsp;&lt;/P&gt;

&lt;P&gt;Maybe something like the figure below:&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="IAS_ExtUsr.png"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/9542iFAA8B3087901A250/image-size/large?v=v2&amp;amp;px=999&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="IAS_ExtUsr.png" alt="IAS_ExtUsr.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 May 2017 15:55:58 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Provide-remote-attestation-to-external-user/m-p/1106806#M1211</guid>
      <dc:creator>David_B_1</dc:creator>
      <dc:date>2017-05-16T15:55:58Z</dc:date>
    </item>
    <item>
      <title>I will try to rephrase this:</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Provide-remote-attestation-to-external-user/m-p/1106807#M1212</link>
      <description>&lt;P&gt;I will try to rephrase this: Can a user (other than the ISV who has the private signing key) obtain a remote attestation&amp;nbsp;&lt;SPAN style="font-size: 1em;"&gt;from (or with the help of) the ISV but without the ISV being able to tamper with this attestation?&lt;/SPAN&gt;&lt;/P&gt;

&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2017 16:24:33 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Provide-remote-attestation-to-external-user/m-p/1106807#M1212</guid>
      <dc:creator>David_B_1</dc:creator>
      <dc:date>2017-06-08T16:24:33Z</dc:date>
    </item>
    <item>
      <title>Hi, David.</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Provide-remote-attestation-to-external-user/m-p/1106808#M1213</link>
      <description>&lt;P&gt;Hi, David.&lt;/P&gt;

&lt;P&gt;This is absolutely possible. The private signing key is not needed in the process of producing a quote once the enclave application is already running. The quote is signed with the EPID key, and not with the private signing key.&lt;/P&gt;

&lt;P&gt;Best regards,&lt;BR /&gt;
	Rodolfo&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2017 19:02:16 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Provide-remote-attestation-to-external-user/m-p/1106808#M1213</guid>
      <dc:creator>Rodolfo_S_</dc:creator>
      <dc:date>2017-06-16T19:02:16Z</dc:date>
    </item>
    <item>
      <title>Thanks Rodolfo, this was very</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Provide-remote-attestation-to-external-user/m-p/1106809#M1214</link>
      <description>&lt;P&gt;Thanks Rodolfo, this was very helpful!&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2017 09:12:35 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Provide-remote-attestation-to-external-user/m-p/1106809#M1214</guid>
      <dc:creator>David_B_1</dc:creator>
      <dc:date>2017-06-19T09:12:35Z</dc:date>
    </item>
    <item>
      <title>About this issue,I still have</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Provide-remote-attestation-to-external-user/m-p/1106810#M1215</link>
      <description>&lt;P&gt;About this issue,I still have a question.&lt;/P&gt;

&lt;P&gt;EPID (key) seems to prove the ISV identity。but how to prove the code run in the enclave is the one expected , by comparing the "&lt;SPAN style="color: rgb(96, 96, 96); font-size: 13.008px;"&gt;MRENCLAVE" measurement value&amp;nbsp;&lt;/SPAN&gt;?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2017 10:07:15 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Provide-remote-attestation-to-external-user/m-p/1106810#M1215</guid>
      <dc:creator>yu_b_1</dc:creator>
      <dc:date>2017-07-27T10:07:15Z</dc:date>
    </item>
  </channel>
</rss>

