<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re:Intel SGX Key Management and password management in Intel® Software Guard Extensions (Intel® SGX)</title>
    <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-Key-Management-and-password-management/m-p/1328506#M4985</link>
    <description>&lt;P&gt;Hello Ziidev,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thank you for posting on the Intel® communities.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Please let me review this information internally, and kindly wait for an update. &lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Once we have more information to share, we will post it on this thread. &lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Victor G. &lt;/P&gt;&lt;P&gt;Intel Technical Support Technician&lt;/P&gt;&lt;BR /&gt;</description>
    <pubDate>Tue, 09 Nov 2021 19:03:50 GMT</pubDate>
    <dc:creator>Victor_G_Intel</dc:creator>
    <dc:date>2021-11-09T19:03:50Z</dc:date>
    <item>
      <title>Intel SGX Key Management and password management</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-Key-Management-and-password-management/m-p/1328181#M4984</link>
      <description>&lt;P&gt;&lt;SPAN class="style-scope yt-formatted-string"&gt;My question is that does how does SGX stores keys, what is the key management model for SGX? Simply, when the system shuts down, all the will be store in memory. Let's say it encrypts the data while going off then where it going to store the keys. How it is going to retrieve the data while system boots? &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="style-scope yt-formatted-string"&gt;Is it possible to use SGX on the client machine? When i was reading the about SGX I found out that SGX does not provide us context switching, then if client needs to enter a password for authentication or authorization, how we are going to do that? &lt;/SPAN&gt; &lt;SPAN class="style-scope yt-formatted-string"&gt;Please answer my questions that would be helpful.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Nov 2021 19:19:07 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-Key-Management-and-password-management/m-p/1328181#M4984</guid>
      <dc:creator>Ziidev</dc:creator>
      <dc:date>2021-11-08T19:19:07Z</dc:date>
    </item>
    <item>
      <title>Re:Intel SGX Key Management and password management</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-Key-Management-and-password-management/m-p/1328506#M4985</link>
      <description>&lt;P&gt;Hello Ziidev,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thank you for posting on the Intel® communities.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Please let me review this information internally, and kindly wait for an update. &lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Once we have more information to share, we will post it on this thread. &lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Victor G. &lt;/P&gt;&lt;P&gt;Intel Technical Support Technician&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 09 Nov 2021 19:03:50 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-Key-Management-and-password-management/m-p/1328506#M4985</guid>
      <dc:creator>Victor_G_Intel</dc:creator>
      <dc:date>2021-11-09T19:03:50Z</dc:date>
    </item>
    <item>
      <title>Re:Intel SGX Key Management and password management</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-Key-Management-and-password-management/m-p/1328537#M4986</link>
      <description>&lt;P&gt;Hello Ziidev,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thank you for your patience.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Your query will be best answered by our Intel® Software Guard Extensions (Intel® SGX) support team. We will help you to move this post to the designated team to further assist you.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Victor G.&lt;/P&gt;&lt;P&gt;Intel Technical Support Technician&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 09 Nov 2021 20:49:15 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-Key-Management-and-password-management/m-p/1328537#M4986</guid>
      <dc:creator>Victor_G_Intel</dc:creator>
      <dc:date>2021-11-09T20:49:15Z</dc:date>
    </item>
    <item>
      <title>Re:Intel SGX Key Management and password management</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-Key-Management-and-password-management/m-p/1328559#M4987</link>
      <description>&lt;P&gt;Hello Ziidev,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;This &lt;A href="https://community.intel.com/t5/Intel-Software-Guard-Extensions/Does-SGX-have-Non-Volatile-Storage/m-p/1170747" rel="noopener noreferrer" target="_blank"&gt;thread&lt;/A&gt; explains the concept of data sealing using SGX.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;It is possible to use SGX on client machines. Please explain further your scenario about "enter a password for authentication or authorization." If you want SGX to be used to store passwords, then you must write an SGX application specifically for this purpose. The operating system does not use SGX for authentication and authorization. This &lt;A href="https://www.intel.com/content/www/us/en/developer/articles/training/software-guard-extensions-tutorial-series-part-3.html" rel="noopener noreferrer" target="_blank"&gt;Password Manager using SGX&lt;/A&gt; tutorial may help although it is outdated.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Sincerely,&lt;/P&gt;&lt;P&gt;Jesus G.&lt;/P&gt;&lt;P&gt;Intel Customer Support&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 09 Nov 2021 22:40:53 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-Key-Management-and-password-management/m-p/1328559#M4987</guid>
      <dc:creator>JesusG_Intel</dc:creator>
      <dc:date>2021-11-09T22:40:53Z</dc:date>
    </item>
    <item>
      <title>Re: Intel SGX Key Management and password management</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-Key-Management-and-password-management/m-p/1328606#M4988</link>
      <description>&lt;P&gt;Hi JesusG_intel,&lt;/P&gt;
&lt;P&gt;Our situation is different. We would like to run SGX on both server and client systems. But we faces issues on client side. Our application requires that when application is running, it requests a password from user and then seal it and send it to the server.&lt;/P&gt;
&lt;P&gt;But as far as I know,&amp;nbsp; we can only enter password in insecure zone not directly into the enclave. And if the system is compromised then keylogging or any other type of attack is possible. How we can make sure the user who is running the system or opened this application is a valid user?&lt;/P&gt;
&lt;P&gt;Thank you for your consideration,&lt;/P&gt;
&lt;P&gt;Best Regards,&lt;/P&gt;
&lt;P&gt;Ziidev&lt;/P&gt;</description>
      <pubDate>Wed, 10 Nov 2021 01:51:23 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-Key-Management-and-password-management/m-p/1328606#M4988</guid>
      <dc:creator>Ziidev</dc:creator>
      <dc:date>2021-11-10T01:51:23Z</dc:date>
    </item>
    <item>
      <title>Re: Re:Intel SGX Key Management and password management</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-Key-Management-and-password-management/m-p/1328607#M4989</link>
      <description>&lt;P&gt;Please let me know how to move this post to Intel SGX forum. I would be happy.&lt;/P&gt;
&lt;P&gt;Best Regards,&lt;/P&gt;
&lt;P&gt;Ziidev&lt;/P&gt;</description>
      <pubDate>Wed, 10 Nov 2021 01:53:45 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-Key-Management-and-password-management/m-p/1328607#M4989</guid>
      <dc:creator>Ziidev</dc:creator>
      <dc:date>2021-11-10T01:53:45Z</dc:date>
    </item>
    <item>
      <title>Re:Intel SGX Key Management and password management</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-Key-Management-and-password-management/m-p/1328885#M4990</link>
      <description>&lt;P&gt;Hello Ziidev,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;While your question seems simple, it requires a complex answer. Therefore, I will point you to further resources for your reference.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;SGX does not prevent a system from being compromised. That is why in the SGX security model, SGX does not trust system software - it assumes the OS has been compromised!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This paper, &lt;A href="https://arxiv.org/abs/1701.01061" rel="noopener noreferrer" target="_blank"&gt;SGXIO: Generic Trusted I/O Path for Intel SGX&lt;/A&gt;, provides the guidance you seek: "SGXIO surpasses traditional use cases in cloud computing and makes SGX technology usable for protecting user-centric, local applications against kernel-level keyloggers and likewise"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This article &lt;A href="https://www.intel.com/content/www/us/en/developer/articles/technical/intel-sgx-and-side-channels.html" rel="noopener noreferrer" target="_blank"&gt;SGX and Side-Channel Attacks&lt;/A&gt; addresses SGX's position on side-channel attacks. The article has an outdated link to the SGX Developer Guide, but this is the correct link: &lt;A href="https://download.01.org/intel-sgx/latest/linux-latest/docs/Intel_SGX_Developer_Guide.pdf" rel="noopener noreferrer" target="_blank"&gt;Intel SGX Developer Guide&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The section on &lt;I&gt;Protection from Side-Channel Attacks&lt;/I&gt; is on page 51 of the SGX Developer Guide.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Be sure to read more details about the SGX security model in the SGX workshop tutorial at the International Symposium on Computer Architecture in 2015, the slides for which can be found her&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;quot;Intel Clear&amp;quot;;"&gt;e&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.intel.com/content/dam/develop/external/us/en/documents/332680-001-720907.pdf" rel="noopener noreferrer" target="_blank" style="font-size: 12px;"&gt;[slides 109-121]&lt;/A&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;quot;Intel Clear&amp;quot;;"&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sincerely,&lt;/P&gt;&lt;P&gt;Jesus G.&lt;/P&gt;&lt;P&gt;Intel Customer Support&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 10 Nov 2021 20:24:51 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-Key-Management-and-password-management/m-p/1328885#M4990</guid>
      <dc:creator>JesusG_Intel</dc:creator>
      <dc:date>2021-11-10T20:24:51Z</dc:date>
    </item>
    <item>
      <title>Re: Re:Intel SGX Key Management and password management</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-Key-Management-and-password-management/m-p/1329772#M4993</link>
      <description>&lt;P&gt;Hi JesusG_Intel,&lt;/P&gt;
&lt;P&gt;I read this paper. It is a very good good paper. Now I am sure that SGX does not provide I/O key security. So we have to follow this paper for further guideline.&lt;/P&gt;
&lt;P&gt;Thanks you for kind reply.&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Ziidev&lt;/P&gt;</description>
      <pubDate>Sat, 13 Nov 2021 17:04:13 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-Key-Management-and-password-management/m-p/1329772#M4993</guid>
      <dc:creator>Ziidev</dc:creator>
      <dc:date>2021-11-13T17:04:13Z</dc:date>
    </item>
    <item>
      <title>Re:Intel SGX Key Management and password management</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-Key-Management-and-password-management/m-p/1330272#M4994</link>
      <description>&lt;P&gt;&lt;B&gt;This thread has been marked as answered and Intel will no longer monitor this thread. If you want a response from Intel in a follow-up question, please open a new thread.&lt;/B&gt;&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 15 Nov 2021 23:05:35 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-Key-Management-and-password-management/m-p/1330272#M4994</guid>
      <dc:creator>JesusG_Intel</dc:creator>
      <dc:date>2021-11-15T23:05:35Z</dc:date>
    </item>
  </channel>
</rss>

