<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is not memory protection in debug mode? in Intel Confidential Computing</title>
    <link>https://community.intel.com/t5/Intel-Confidential-Computing/Is-not-memory-protection-in-debug-mode/m-p/1152059#M2604</link>
    <description>&lt;P&gt;Hello, I'm Tae Un Kang.&lt;/P&gt;

&lt;P&gt;I downloaded the "Intel Software Guard Extensions SDK for Windows* OS(Developer References)" document from the intel homepage and read it.&lt;BR /&gt;
	(https://software.intel.com/en-us/sgx-sdk/documentation)&lt;/P&gt;

&lt;P&gt;Looking at page 17 of the document, it appears that debug mode does not support memory protection.&lt;/P&gt;

&lt;P&gt;The following is mentioned on page 17.&lt;/P&gt;

&lt;P&gt;***&lt;BR /&gt;
	&lt;STRONG&gt;The code/data memory inside an enclave launched in debug mode is accessible by the debugger or other software outside of the enclave. Thus, it does not have the same memory access protection as an enclave launched in non-debug mode.&lt;/STRONG&gt;&lt;BR /&gt;
	***&lt;/P&gt;

&lt;P&gt;Also, If you look at "two approaches to x86 memory encryption", it seems that Intel SGX's memory protection does not work in Debug mode.&lt;BR /&gt;
	(https://lwn.net/Articles/686808)&lt;/P&gt;

&lt;P&gt;The following is a part of "two approaches to x86 memory encryption".&lt;/P&gt;

&lt;P&gt;***&lt;BR /&gt;
	&lt;STRONG&gt;Instead, enclaves can only run in the "debug mode," where it's possible to read and manipulate data inside the enclave from the rest of the system. That, obviously, detracts from the utility of the feature. It's not entirely clear why this limitation is in place.&lt;/STRONG&gt;&lt;BR /&gt;
	***&lt;/P&gt;

&lt;P&gt;&lt;BR /&gt;
	My question is as follows.&lt;/P&gt;

&lt;P&gt;1. Is it necessary to compile in Release mode to use the memory protection feature of Intel SGX?&lt;/P&gt;

&lt;P&gt;2. Do I need a Commercial License to compile in Release mode?&lt;/P&gt;

&lt;P&gt;3. If Memory is not protected in debug mode, what other functions are available in Intel SGX?&lt;/P&gt;

&lt;P&gt;&amp;nbsp;&lt;/P&gt;

&lt;P&gt;Thank you&lt;/P&gt;</description>
    <pubDate>Sun, 05 Nov 2017 05:27:28 GMT</pubDate>
    <dc:creator>tae_un_k_</dc:creator>
    <dc:date>2017-11-05T05:27:28Z</dc:date>
    <item>
      <title>Is not memory protection in debug mode?</title>
      <link>https://community.intel.com/t5/Intel-Confidential-Computing/Is-not-memory-protection-in-debug-mode/m-p/1152059#M2604</link>
      <description>&lt;P&gt;Hello, I'm Tae Un Kang.&lt;/P&gt;

&lt;P&gt;I downloaded the "Intel Software Guard Extensions SDK for Windows* OS(Developer References)" document from the intel homepage and read it.&lt;BR /&gt;
	(https://software.intel.com/en-us/sgx-sdk/documentation)&lt;/P&gt;

&lt;P&gt;Looking at page 17 of the document, it appears that debug mode does not support memory protection.&lt;/P&gt;

&lt;P&gt;The following is mentioned on page 17.&lt;/P&gt;

&lt;P&gt;***&lt;BR /&gt;
	&lt;STRONG&gt;The code/data memory inside an enclave launched in debug mode is accessible by the debugger or other software outside of the enclave. Thus, it does not have the same memory access protection as an enclave launched in non-debug mode.&lt;/STRONG&gt;&lt;BR /&gt;
	***&lt;/P&gt;

&lt;P&gt;Also, If you look at "two approaches to x86 memory encryption", it seems that Intel SGX's memory protection does not work in Debug mode.&lt;BR /&gt;
	(https://lwn.net/Articles/686808)&lt;/P&gt;

&lt;P&gt;The following is a part of "two approaches to x86 memory encryption".&lt;/P&gt;

&lt;P&gt;***&lt;BR /&gt;
	&lt;STRONG&gt;Instead, enclaves can only run in the "debug mode," where it's possible to read and manipulate data inside the enclave from the rest of the system. That, obviously, detracts from the utility of the feature. It's not entirely clear why this limitation is in place.&lt;/STRONG&gt;&lt;BR /&gt;
	***&lt;/P&gt;

&lt;P&gt;&lt;BR /&gt;
	My question is as follows.&lt;/P&gt;

&lt;P&gt;1. Is it necessary to compile in Release mode to use the memory protection feature of Intel SGX?&lt;/P&gt;

&lt;P&gt;2. Do I need a Commercial License to compile in Release mode?&lt;/P&gt;

&lt;P&gt;3. If Memory is not protected in debug mode, what other functions are available in Intel SGX?&lt;/P&gt;

&lt;P&gt;&amp;nbsp;&lt;/P&gt;

&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Sun, 05 Nov 2017 05:27:28 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Confidential-Computing/Is-not-memory-protection-in-debug-mode/m-p/1152059#M2604</guid>
      <dc:creator>tae_un_k_</dc:creator>
      <dc:date>2017-11-05T05:27:28Z</dc:date>
    </item>
    <item>
      <title>Hi.</title>
      <link>https://community.intel.com/t5/Intel-Confidential-Computing/Is-not-memory-protection-in-debug-mode/m-p/1152060#M2605</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;

&lt;P&gt;Answering your questions below:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
	&lt;P&gt;&lt;SPAN style="font-size: 12px;"&gt;1. Is it necessary to compile in Release mode to use the memory protection feature of Intel SGX?&lt;/SPAN&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;&lt;SPAN style="font-size: 12px;"&gt;No. You can compile your enclave in Pre-Release mode and still use the memory protection feature.&lt;/SPAN&gt;&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
	&lt;P&gt;&lt;SPAN style="font-size: 12px;"&gt;2. Do I need a Commercial License to compile in Release mode?&lt;/SPAN&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;&lt;SPAN style="font-size: 12px;"&gt;Yes.&lt;/SPAN&gt;&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
	&lt;P&gt;&lt;SPAN style="font-size: 12px;"&gt;3. If Memory is not protected in debug mode, what other functions are available in Intel SGX?&lt;/SPAN&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;&lt;SPAN style="font-size: 12px;"&gt;Everything that is part of the SDK can be used in debug mode. That is, you can still use all the functionalities of the SDK but data will not be protected by HW.&lt;/SPAN&gt;&lt;/P&gt;

&lt;P&gt;&lt;SPAN style="font-size: 12px;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;

&lt;P&gt;&lt;SPAN style="font-size: 12px;"&gt;Rodolfo&lt;/SPAN&gt;&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
	&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Sun, 05 Nov 2017 14:00:03 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Confidential-Computing/Is-not-memory-protection-in-debug-mode/m-p/1152060#M2605</guid>
      <dc:creator>Rodolfo_S_</dc:creator>
      <dc:date>2017-11-05T14:00:03Z</dc:date>
    </item>
  </channel>
</rss>

