<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is it possible to revoke some enclave's permission to execute? in Intel® Software Guard Extensions (Intel® SGX)</title>
    <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Is-it-possible-to-revoke-some-enclave-s-permission-to-execute/m-p/1124678#M1680</link>
    <description>&lt;P&gt;The developer may be want to prevent old version enclaves executing. However the old enclaves together with old SIGSTRUCT and TOKEN &amp;nbsp;have been delivered.&lt;/P&gt;</description>
    <pubDate>Fri, 13 May 2016 03:11:49 GMT</pubDate>
    <dc:creator>gu_j_1</dc:creator>
    <dc:date>2016-05-13T03:11:49Z</dc:date>
    <item>
      <title>Is it possible to revoke some enclave's permission to execute?</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Is-it-possible-to-revoke-some-enclave-s-permission-to-execute/m-p/1124678#M1680</link>
      <description>&lt;P&gt;The developer may be want to prevent old version enclaves executing. However the old enclaves together with old SIGSTRUCT and TOKEN &amp;nbsp;have been delivered.&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2016 03:11:49 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Is-it-possible-to-revoke-some-enclave-s-permission-to-execute/m-p/1124678#M1680</guid>
      <dc:creator>gu_j_1</dc:creator>
      <dc:date>2016-05-13T03:11:49Z</dc:date>
    </item>
    <item>
      <title>Hi Gu,</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Is-it-possible-to-revoke-some-enclave-s-permission-to-execute/m-p/1124679#M1681</link>
      <description>&lt;P&gt;Hi Gu,&lt;/P&gt;

&lt;P&gt;Is your application using Remote Attestation? If so, you can revoke an enclave's ability to attest via several methods.The Service Provider can update the ISVSVN or ISVPRODID and subsequently fail attestation requests. The ISV can also ask to place the signature on the Signature Revocation List (SigRL). Please refer to the following article for more information:&amp;nbsp;&lt;A href="https://software.intel.com/en-us/blogs/2016/03/09/intel-sgx-epid-provisioning-and-attestation-services" target="_blank"&gt;https://software.intel.com/en-us/blogs/2016/03/09/intel-sgx-epid-provisioning-and-attestation-services&lt;/A&gt;.&lt;/P&gt;

&lt;P&gt;If your application is not using attestation, there is no way to prevent the enclave from executing without changing the underlying Trusted Compute Base on the local platform.&lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2016 18:19:00 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Is-it-possible-to-revoke-some-enclave-s-permission-to-execute/m-p/1124679#M1681</guid>
      <dc:creator>Alexander_B_Intel</dc:creator>
      <dc:date>2016-05-17T18:19:00Z</dc:date>
    </item>
    <item>
      <title>Quote:Alexander B. (Intel)</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Is-it-possible-to-revoke-some-enclave-s-permission-to-execute/m-p/1124680#M1682</link>
      <description>&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE&gt;Alexander B. (Intel) wrote:&lt;BR /&gt;&lt;P&gt;&lt;/P&gt;

&lt;P&gt;Hi &lt;GS class="GINGER_SOFTWARE_mark" ginger_software_uiphraseguid="b8aef6a7-fd85-415e-b9ac-666424e4d24c" id="888dbe38-60c2-4faf-adbf-01626e2459ca"&gt;Gu&lt;/GS&gt;,&lt;/P&gt;

&lt;P&gt;Is your application using Remote Attestation? If so, you can revoke an enclave's ability to attest via several methods&lt;GS class="GINGER_SOFTWARE_mark" ginger_software_uiphraseguid="69740e59-832b-4116-86e7-1a50e5c7dda3" id="ab1696c1-5f39-40c8-927c-3031debdb2fb"&gt;.&lt;/GS&gt;The Service Provider can update the ISVSVN or ISVPRODID and subsequently fail attestation requests. The ISV can also ask to place the signature on the Signature Revocation List (SigRL). Please refer to the following article for more information:&amp;nbsp;&lt;A href="https://software.intel.com/en-us/blogs/2016/03/09/intel-sgx-epid-provisioning-and-attestation-services"&gt;https://software.intel.com/en-us/blogs/2016/03/09/intel-sgx-epid-provisioning-and-attestation-services&lt;/A&gt;.&lt;/P&gt;

&lt;P&gt;If your application is not using attestation, there is no way to prevent the enclave from executing without changing the underlying Trusted &lt;GS class="GINGER_SOFTWARE_mark" ginger_software_uiphraseguid="ad511208-14c0-40d6-ac8c-daebcdd5fef7" id="0ed38005-e7ab-4e5a-a375-136ad1732e2e"&gt;Compute&lt;/GS&gt; Base on the local platform.&lt;/P&gt;

&lt;P&gt;[/&lt;GS class="GINGER_SOFTWARE_mark" ginger_software_uiphraseguid="b3fe4c2e-2b51-4ab1-80d4-18b6fb774c15" id="57b97b53-7a12-463b-a2f9-d47fc6c9b63a"&gt;quote&lt;/GS&gt;]&lt;/P&gt;

&lt;P&gt;Does the attestation usually take place at the launch time of enclave? If so, does it mean &lt;GS class="GINGER_SOFTWARE_mark" ginger_software_uiphraseguid="b9fcb3e1-b1b3-42ca-9c16-77ab262f339b" id="c5c74410-ceaa-4644-ab14-cb5159c3bc78"&gt;remote entity&lt;/GS&gt; cannot stop the execution of old version enclaves which have already run?&lt;/P&gt;

&lt;P&gt;&lt;SPAN style="font-size: 1em; line-height: 1.5;"&gt;Thanks!&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Wed, 18 May 2016 01:01:50 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Is-it-possible-to-revoke-some-enclave-s-permission-to-execute/m-p/1124680#M1682</guid>
      <dc:creator>gu_j_1</dc:creator>
      <dc:date>2016-05-18T01:01:50Z</dc:date>
    </item>
    <item>
      <title>Quote:gu j. wrote:</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Is-it-possible-to-revoke-some-enclave-s-permission-to-execute/m-p/1124681#M1683</link>
      <description>&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE&gt;gu j. wrote:&lt;BR /&gt;&lt;P&gt;&lt;/P&gt;

&lt;BLOCKQUOTE class="quote-msg quote-nest-1 odd"&gt;
	&lt;DIV class="quote-author"&gt;&lt;SPAN style="font-size: 1em; line-height: 1.5;"&gt;Does the attestation usually take place at the launch time of enclave? If so, does it mean remote entity cannot stop the execution of old version enclaves which have already run?&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;

&lt;P&gt;Attestation can happen at any time when an enclave asks the remote entity to provision secrets to it. The remote entity cannot stop the execution of the enclave, but it &lt;STRONG&gt;can &lt;/STRONG&gt;fail the enclave attestation and refuse to provision it with any new secrets.&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2016 16:44:00 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Is-it-possible-to-revoke-some-enclave-s-permission-to-execute/m-p/1124681#M1683</guid>
      <dc:creator>Alexander_B_Intel</dc:creator>
      <dc:date>2016-05-18T16:44:00Z</dc:date>
    </item>
  </channel>
</rss>

