<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Re:The delay attack towards the trusted time in Intel® Software Guard Extensions (Intel® SGX)</title>
    <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/The-delay-attack-towards-the-trusted-time/m-p/1344150#M5064</link>
    <description>&lt;P&gt;Hello Jesus,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your answer. Further, I also have some questions:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;I am still curious about why Intel suddenly removed the Intel SGX Platform Service from Linux-based platform&amp;nbsp;&lt;SPAN&gt;beginning with Intel SGX SDK for Linux 2.9, while still retain the&amp;nbsp;Intel SGX Platform Service on&amp;nbsp;Windows platforms.&amp;nbsp;&amp;nbsp;In my understanding, this service may have nothing to do with hardware but with software (e.g., the version of the SDK).&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;What is the thinking behind the design, in which the server system does not support Intel Converged Security and Management Engine (CSME)？&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Moreover, on a Linux-based platform equipped with the 8th Gen Core-i7 CPU, If I now install the&amp;nbsp; Intel SGX SDK before Linux 2.9, can I use the trusted time and&amp;nbsp;&amp;nbsp;monotonic counter via Intel SGX's API?&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Sincerely,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;SunnySun&lt;/P&gt;</description>
    <pubDate>Wed, 15 Dec 2021 01:22:47 GMT</pubDate>
    <dc:creator>SunnySun</dc:creator>
    <dc:date>2021-12-15T01:22:47Z</dc:date>
    <item>
      <title>The delay attack towards the trusted time</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/The-delay-attack-towards-the-trusted-time/m-p/1343497#M5056</link>
      <description>&lt;P&gt;Hi Intel&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Because the request/response packets are communicated in IPC when invoking sgx_get_trusted_time,&amp;nbsp; I wonder if these packets are v&lt;SPAN&gt;ulnerable to delay attacks, i.e., the malicious OS &lt;/SPAN&gt; &lt;SPAN&gt;intercept these packets and the measured elapsed time may not correct.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Moreover, if this kind of attack exists, I also wonder to know how&lt;SPAN style="font-family: inherit;"&gt;&amp;nbsp;to mitigate this attack.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: inherit;"&gt;Best regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: inherit;"&gt;SunnySun&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Dec 2021 15:56:57 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/The-delay-attack-towards-the-trusted-time/m-p/1343497#M5056</guid>
      <dc:creator>SunnySun</dc:creator>
      <dc:date>2021-12-12T15:56:57Z</dc:date>
    </item>
    <item>
      <title>Re:The delay attack towards the trusted time</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/The-delay-attack-towards-the-trusted-time/m-p/1344058#M5061</link>
      <description>&lt;P&gt;Hello SunnySun,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I will answer your questions related to trusted time and monotonic counters in this thread and will remove the previous thread.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Support for Intel SGX Platform Services was removed from all Linux-based platforms, including client platforms, beginning with Intel SGX SDK for Linux 2.9.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Intel SGX API for monotonic counters is still part of the Intel SGX SDK for Windows and is supported on Windows 10 platforms via the Intel SGX Platform Software for Windows. The Intel SGX Platform Software for Windows is usually installed via Windows Update from the platform OEM.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The paper, &lt;A href="https://community.intel.com/legacyfs/online/drupal_files/managed/1b/a2/Intel-SGX-Platform-Services.pdf" rel="noopener noreferrer" target="_blank"&gt;Intel SGX Platform Services&lt;/A&gt;, describes in detail how the SGX SDK accesses hardware-based monotonic counters implemented in the Intel Converged Security and Management Engine (CSME), which is only available in client systems.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;quot;Intel Clear&amp;quot;;"&gt;The sgx_get_trusted_time function includes a nonce argument. According to the Intel SGX Developer Reference for Windows: "&lt;/SPAN&gt;The Enclave retrieves the time reference and the time source nonce using &lt;SPAN style="font-family: courier;"&gt;sgx_get_trusted_time&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: IntelClear-Regular;"&gt;.&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;quot;Intel Clear&amp;quot;;"&gt;" To guarantee that the time source does not change between two readings of &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; font-family: courier;"&gt;sgx_get_trusted_time&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;quot;Intel Clear&amp;quot;;"&gt;, compare the &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; font-family: courier;"&gt;nonce &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;quot;Intel Clear&amp;quot;;"&gt;from each reading - they should be the same.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Read more about protecting against replay attacks by referring to the section on the Sealed Data example in the Intel SGX Developer Reference for Windows.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;These articles may also be interesting to you:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.intel.com/content/www/us/en/support/articles/000058691/software/intel-security-products.html" rel="noopener noreferrer" target="_blank"&gt;What is the Role of the Intel® Software Guard Extensions (Intel® SGX) Platform Services Enclave (PSE) and how is it Invoked?&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.intel.ca/content/www/ca/en/support/articles/000057968/software/intel-security-products.html" rel="noopener noreferrer" target="_blank"&gt;Unable to find Alternatives to Monotonic Counter Application Programming Interfaces (APIs) in Intel® Software Guard Extensions (Intel® SGX) for Linux* to Prevent Sealing Rollback Attacks&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Sincerely,&lt;/P&gt;&lt;P&gt;Jesus G.&lt;/P&gt;&lt;P&gt;Intel Customer Support&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 14 Dec 2021 18:06:52 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/The-delay-attack-towards-the-trusted-time/m-p/1344058#M5061</guid>
      <dc:creator>JesusG_Intel</dc:creator>
      <dc:date>2021-12-14T18:06:52Z</dc:date>
    </item>
    <item>
      <title>Re: Re:The delay attack towards the trusted time</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/The-delay-attack-towards-the-trusted-time/m-p/1344150#M5064</link>
      <description>&lt;P&gt;Hello Jesus,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your answer. Further, I also have some questions:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;I am still curious about why Intel suddenly removed the Intel SGX Platform Service from Linux-based platform&amp;nbsp;&lt;SPAN&gt;beginning with Intel SGX SDK for Linux 2.9, while still retain the&amp;nbsp;Intel SGX Platform Service on&amp;nbsp;Windows platforms.&amp;nbsp;&amp;nbsp;In my understanding, this service may have nothing to do with hardware but with software (e.g., the version of the SDK).&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;What is the thinking behind the design, in which the server system does not support Intel Converged Security and Management Engine (CSME)？&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Moreover, on a Linux-based platform equipped with the 8th Gen Core-i7 CPU, If I now install the&amp;nbsp; Intel SGX SDK before Linux 2.9, can I use the trusted time and&amp;nbsp;&amp;nbsp;monotonic counter via Intel SGX's API?&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Sincerely,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;SunnySun&lt;/P&gt;</description>
      <pubDate>Wed, 15 Dec 2021 01:22:47 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/The-delay-attack-towards-the-trusted-time/m-p/1344150#M5064</guid>
      <dc:creator>SunnySun</dc:creator>
      <dc:date>2021-12-15T01:22:47Z</dc:date>
    </item>
    <item>
      <title>Re: Re:The delay attack towards the trusted time</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/The-delay-attack-towards-the-trusted-time/m-p/1344155#M5065</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello Jesus,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I would like to add more to the Question 2 in my last reply.&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI class="sub_section_element_selectors"&gt;&lt;SPAN class="sub_section_element_selectors"&gt;What is the thinking behind the design, in which the server system does not support Intel Converged Security and Management Engine (CSME)？In the future, w&lt;SPAN&gt;ill Intel consider supporting CSME, trusted time, monotonic counters in SGX for server platforms in the future.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="sub_section_element_selectors"&gt;&lt;SPAN class="sub_section_element_selectors"&gt;Sincerely,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="sub_section_element_selectors"&gt;SunnySun&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Dec 2021 01:38:52 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/The-delay-attack-towards-the-trusted-time/m-p/1344155#M5065</guid>
      <dc:creator>SunnySun</dc:creator>
      <dc:date>2021-12-15T01:38:52Z</dc:date>
    </item>
    <item>
      <title>Re:The delay attack towards the trusted time</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/The-delay-attack-towards-the-trusted-time/m-p/1344443#M5068</link>
      <description>&lt;P&gt;Hello SunnySun,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10pt;"&gt;OEMs must accept a license to support Platform Services. OEMs can accept this license on their Windows systems because the OS is pre-installed at the factory. However, due to how Linux is distributed and installed, the OEMs could not accept that license for Linux installations.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10pt;"&gt;Intel server products use Intel Server Platform Services for manageability. Servers and clients have different manageability needs that are addressed by different technologies.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10pt;"&gt;Intel does not recommend installing older versions of SGX software. As this is security software, you should always install the most recent version to get all the latest security and bug fixes. Also, you would need the Linux ME drivers, which Intel does not provide.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10pt;"&gt;We cannot comment on future roadmaps.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Sincerely,&lt;/P&gt;&lt;P&gt;Jesus G.&lt;/P&gt;&lt;P&gt;Intel Customer Support&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 15 Dec 2021 23:23:09 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/The-delay-attack-towards-the-trusted-time/m-p/1344443#M5068</guid>
      <dc:creator>JesusG_Intel</dc:creator>
      <dc:date>2021-12-15T23:23:09Z</dc:date>
    </item>
    <item>
      <title>Re:The delay attack towards the trusted time</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/The-delay-attack-towards-the-trusted-time/m-p/1345061#M5072</link>
      <description>&lt;P&gt;&lt;B&gt;This thread has been marked as answered and Intel will no longer monitor this thread. If you want a response from Intel in a follow-up question, please open a new thread.&lt;/B&gt;&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 17 Dec 2021 22:53:56 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/The-delay-attack-towards-the-trusted-time/m-p/1345061#M5072</guid>
      <dc:creator>JesusG_Intel</dc:creator>
      <dc:date>2021-12-17T22:53:56Z</dc:date>
    </item>
  </channel>
</rss>

