<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Intel SGX root key in Intel® Software Guard Extensions (Intel® SGX)</title>
    <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-root-key/m-p/1400788#M5397</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;The root key is a component of the Root CA Cert and can be extracted from it.&amp;nbsp; We have hard coded links now in the API Docs to the Root CA Certs just above where &lt;A href="https://api.portal.trustedservices.intel.com/documentation#pcs-certificate-v3" target="_blank"&gt;this&lt;/A&gt; link lands you.&lt;/P&gt;
&lt;P&gt;Look for:&lt;/P&gt;
&lt;P&gt;“Download the Provisioning Certification Root CA Certificate for API v3 here:&lt;BR /&gt;&lt;A href="https://certificates.trustedservices.intel.com/Intel_SGX_Provisioning_Certification_RootCA.cer" target="_blank"&gt;DER&lt;/A&gt; &lt;A href="https://certificates.trustedservices.intel.com/Intel_SGX_Provisioning_Certification_RootCA.pem" target="_blank"&gt;PEM&lt;/A&gt; (fingerprint: 8bd31eb1d63ce37382c0ffaa0d8200a3011ad6ff)”&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this is helpful&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sincerely,&lt;/P&gt;
&lt;P&gt;Sahira&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 15 Jul 2022 21:43:10 GMT</pubDate>
    <dc:creator>Sahira_Intel</dc:creator>
    <dc:date>2022-07-15T21:43:10Z</dc:date>
    <item>
      <title>Intel SGX root key</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-root-key/m-p/1397309#M5377</link>
      <description>&lt;P&gt;I am building an App that uses Intel SGX to sign a certain type of activities the app performs. Within a Secure Enclave I generate a statement X of the Kind "Operation A was performed with results B". Next, I generate a one-time key Y to sign this statement. The key X itself is a part of an SGX quote, i.e., is signed with the chain of keys (K1, K2, ...) provided by SGX technology. This chain terminates at the so called Intel SGX Root Key (R).&lt;/P&gt;
&lt;PRE&gt;R -&amp;gt; K1 -&amp;gt; K2 -&amp;gt; ... -&amp;gt; Y -&amp;gt; X ("operation = A ; result = B")
&lt;/PRE&gt;
&lt;P&gt;I want to store statement X somewhere else such that 1 year later anyone would be able to verify that indeed an operation A was performed with result B.&lt;A href="https://tommypetrussia.com/" target="_self"&gt;&amp;nbsp;&lt;/A&gt;In this case, the verifier would unwind the chain of trust starting from the Intel SGX Root Key (R) until they reach my one-time key Y, and finally verify the statement X.&lt;/P&gt;
&lt;P&gt;The question is, where do I get the key R from?&lt;/P&gt;
&lt;P&gt;When we deal with this type of cryptographic schemes, the ultimate key to trust is somewhere in the public, e.g., on one of the main pages of Intel's website. However, it is kind of challenging to find it. Any idea where one could obtain it from?&lt;/P&gt;</description>
      <pubDate>Sat, 02 Jul 2022 09:10:32 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-root-key/m-p/1397309#M5377</guid>
      <dc:creator>RealArssal</dc:creator>
      <dc:date>2022-07-02T09:10:32Z</dc:date>
    </item>
    <item>
      <title>Re: Intel SGX root key</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-root-key/m-p/1400788#M5397</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;The root key is a component of the Root CA Cert and can be extracted from it.&amp;nbsp; We have hard coded links now in the API Docs to the Root CA Certs just above where &lt;A href="https://api.portal.trustedservices.intel.com/documentation#pcs-certificate-v3" target="_blank"&gt;this&lt;/A&gt; link lands you.&lt;/P&gt;
&lt;P&gt;Look for:&lt;/P&gt;
&lt;P&gt;“Download the Provisioning Certification Root CA Certificate for API v3 here:&lt;BR /&gt;&lt;A href="https://certificates.trustedservices.intel.com/Intel_SGX_Provisioning_Certification_RootCA.cer" target="_blank"&gt;DER&lt;/A&gt; &lt;A href="https://certificates.trustedservices.intel.com/Intel_SGX_Provisioning_Certification_RootCA.pem" target="_blank"&gt;PEM&lt;/A&gt; (fingerprint: 8bd31eb1d63ce37382c0ffaa0d8200a3011ad6ff)”&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this is helpful&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sincerely,&lt;/P&gt;
&lt;P&gt;Sahira&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2022 21:43:10 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-root-key/m-p/1400788#M5397</guid>
      <dc:creator>Sahira_Intel</dc:creator>
      <dc:date>2022-07-15T21:43:10Z</dc:date>
    </item>
  </channel>
</rss>

