<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is attestation meant to be end-user verifiable? in Intel® Software Guard Extensions (Intel® SGX)</title>
    <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Is-attestation-meant-to-be-end-user-verifiable/m-p/1156408#M2748</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've read the documentation and whitepaper on the SGX Attestation and it looks to me that it's more like a thing that myself (owner and runner of the code) can use to make sure my HW nor enclave had been tampered with, rather than being used as a way for my clients to be sure I'm not doing "evil" things (like running a different code than I should -- assuming it's public).&lt;/P&gt;&lt;P&gt;I like how SGX aids on preventing the code's memory from snooping. Is there any way for my end-user, assuming my code is public, to be able to build that same code,&amp;nbsp;and somehow (hashing?) verify that it's the same code that's running on the enclave?&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
    <pubDate>Tue, 03 Sep 2019 20:08:02 GMT</pubDate>
    <dc:creator>Seidl__Jan</dc:creator>
    <dc:date>2019-09-03T20:08:02Z</dc:date>
    <item>
      <title>Is attestation meant to be end-user verifiable?</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Is-attestation-meant-to-be-end-user-verifiable/m-p/1156408#M2748</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've read the documentation and whitepaper on the SGX Attestation and it looks to me that it's more like a thing that myself (owner and runner of the code) can use to make sure my HW nor enclave had been tampered with, rather than being used as a way for my clients to be sure I'm not doing "evil" things (like running a different code than I should -- assuming it's public).&lt;/P&gt;&lt;P&gt;I like how SGX aids on preventing the code's memory from snooping. Is there any way for my end-user, assuming my code is public, to be able to build that same code,&amp;nbsp;and somehow (hashing?) verify that it's the same code that's running on the enclave?&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2019 20:08:02 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Is-attestation-meant-to-be-end-user-verifiable/m-p/1156408#M2748</guid>
      <dc:creator>Seidl__Jan</dc:creator>
      <dc:date>2019-09-03T20:08:02Z</dc:date>
    </item>
  </channel>
</rss>

