<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Using SGX and UUID to avoid Sybil attacks in Intel® Software Guard Extensions (Intel® SGX)</title>
    <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Using-SGX-and-UUID-to-avoid-Sybil-attacks/m-p/1134870#M2012</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;We're working on a project where we have a problem of one user pretending to be many users, just by installing our software many times on the same computer (Sybil attack).&lt;/P&gt;

&lt;P&gt;Is it possible to mitigate it using SGX and UUID? What we had in mind is the software creates an enclave, and then sends our server the UUID of the processor running it. That way, we can identify that the user runs two processes of our software on the same computer.&lt;BR /&gt;
	&lt;BR /&gt;
	We're aware that there may be privacy issues with such an approach, but so far we want just to know if such a thing is possible at all.&lt;/P&gt;

&lt;P&gt;Is there a limitation for enclaves to send UUID through the network? Or can it be easily manipulated by the user? Our software is open source.&lt;/P&gt;</description>
    <pubDate>Wed, 26 Sep 2018 10:21:06 GMT</pubDate>
    <dc:creator>Ron__Eyal</dc:creator>
    <dc:date>2018-09-26T10:21:06Z</dc:date>
    <item>
      <title>Using SGX and UUID to avoid Sybil attacks</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Using-SGX-and-UUID-to-avoid-Sybil-attacks/m-p/1134870#M2012</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;We're working on a project where we have a problem of one user pretending to be many users, just by installing our software many times on the same computer (Sybil attack).&lt;/P&gt;

&lt;P&gt;Is it possible to mitigate it using SGX and UUID? What we had in mind is the software creates an enclave, and then sends our server the UUID of the processor running it. That way, we can identify that the user runs two processes of our software on the same computer.&lt;BR /&gt;
	&lt;BR /&gt;
	We're aware that there may be privacy issues with such an approach, but so far we want just to know if such a thing is possible at all.&lt;/P&gt;

&lt;P&gt;Is there a limitation for enclaves to send UUID through the network? Or can it be easily manipulated by the user? Our software is open source.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Sep 2018 10:21:06 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Using-SGX-and-UUID-to-avoid-Sybil-attacks/m-p/1134870#M2012</guid>
      <dc:creator>Ron__Eyal</dc:creator>
      <dc:date>2018-09-26T10:21:06Z</dc:date>
    </item>
    <item>
      <title>You don't have a processor</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Using-SGX-and-UUID-to-avoid-Sybil-attacks/m-p/1134871#M2013</link>
      <description>&lt;P&gt;What you can do is use remote attestation with Linkable mode, which would enable you to assess whether the same machine is authenticating to your server.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Sep 2018 21:25:00 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Using-SGX-and-UUID-to-avoid-Sybil-attacks/m-p/1134871#M2013</guid>
      <dc:creator>Yan_M_1</dc:creator>
      <dc:date>2018-09-26T21:25:00Z</dc:date>
    </item>
  </channel>
</rss>

