<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Key persistence and sharing in IntelSGX in Intel® Software Guard Extensions (Intel® SGX)</title>
    <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Key-persistence-and-sharing-in-IntelSGX/m-p/1504743#M5811</link>
    <description>&lt;DIV class=""&gt;We are developing a product build on top of Intel SGX hosted on Azure, we are facing some challenges when it comes to data persistence. We have two requirements:&lt;/DIV&gt;&lt;OL class=""&gt;&lt;LI&gt;The ability to store a persistent secret key, between restarts&lt;/LI&gt;&lt;LI&gt;The ability to share this key with other enclaves (provided these are signed by the same entity, aka Applied Blockchain), we'll refer to this as forward key sharing.&lt;/LI&gt;&lt;/OL&gt;&lt;DIV class=""&gt;Our infrastructure is deployed and managed on kubernetes on Azure and as such the concern over network destruction poses a great concern. We've implemented in-house solution to the persistence problem, wherein all enclaves can provision each other assuming they have the same MRENCLAVE, removing the single point of failure. Forward key sharing is harder to achieve due to microcode updates that prevent the enclave from "recognizing" a newer enclave. Before we dive deeper. We would like to know if Azure has any solutions for Persisting data between microcode updates to Intel TEEs.&lt;/DIV&gt;</description>
    <pubDate>Fri, 14 Jul 2023 09:30:48 GMT</pubDate>
    <dc:creator>nolasco_napoleao</dc:creator>
    <dc:date>2023-07-14T09:30:48Z</dc:date>
    <item>
      <title>Key persistence and sharing in IntelSGX</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Key-persistence-and-sharing-in-IntelSGX/m-p/1504743#M5811</link>
      <description>&lt;DIV class=""&gt;We are developing a product build on top of Intel SGX hosted on Azure, we are facing some challenges when it comes to data persistence. We have two requirements:&lt;/DIV&gt;&lt;OL class=""&gt;&lt;LI&gt;The ability to store a persistent secret key, between restarts&lt;/LI&gt;&lt;LI&gt;The ability to share this key with other enclaves (provided these are signed by the same entity, aka Applied Blockchain), we'll refer to this as forward key sharing.&lt;/LI&gt;&lt;/OL&gt;&lt;DIV class=""&gt;Our infrastructure is deployed and managed on kubernetes on Azure and as such the concern over network destruction poses a great concern. We've implemented in-house solution to the persistence problem, wherein all enclaves can provision each other assuming they have the same MRENCLAVE, removing the single point of failure. Forward key sharing is harder to achieve due to microcode updates that prevent the enclave from "recognizing" a newer enclave. Before we dive deeper. We would like to know if Azure has any solutions for Persisting data between microcode updates to Intel TEEs.&lt;/DIV&gt;</description>
      <pubDate>Fri, 14 Jul 2023 09:30:48 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Key-persistence-and-sharing-in-IntelSGX/m-p/1504743#M5811</guid>
      <dc:creator>nolasco_napoleao</dc:creator>
      <dc:date>2023-07-14T09:30:48Z</dc:date>
    </item>
    <item>
      <title>Re:Key persistence and sharing in IntelSGX</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Key-persistence-and-sharing-in-IntelSGX/m-p/1504969#M5812</link>
      <description>&lt;P&gt;Hi Nolasco_napoleao,&lt;/P&gt;&lt;P&gt;Thank you for reaching out to Intel Customer Support.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm checking this out and will get back to you soon.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Zulkifli&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 14 Jul 2023 21:19:17 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Key-persistence-and-sharing-in-IntelSGX/m-p/1504969#M5812</guid>
      <dc:creator>Zulkifli_Intel</dc:creator>
      <dc:date>2023-07-14T21:19:17Z</dc:date>
    </item>
    <item>
      <title>Re:Key persistence and sharing in IntelSGX</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Key-persistence-and-sharing-in-IntelSGX/m-p/1508386#M5824</link>
      <description>&lt;P&gt;Hi Nolasco_napoleao,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry for the delay in reply. You don't need to worry about sealing and microcode updates in Azure, Microsoft ensures that key blobs from past TCB levels are saved before and restored after a microcode update (aka TCB-Recovery), so anything sealed before the upgrade will be able to be unsealed after.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please contact&amp;nbsp;&lt;A href="https://azure.microsoft.com/en-us/support/options/" rel="noopener noreferrer" target="_blank"&gt;Azure support&lt;/A&gt;&amp;nbsp;for further help on using Intel® SGX on Azure.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Sincerely,&lt;/P&gt;&lt;P&gt;Zulkifli&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 26 Jul 2023 13:30:37 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Key-persistence-and-sharing-in-IntelSGX/m-p/1508386#M5824</guid>
      <dc:creator>Zulkifli_Intel</dc:creator>
      <dc:date>2023-07-26T13:30:37Z</dc:date>
    </item>
    <item>
      <title>Re:Key persistence and sharing in IntelSGX</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Key-persistence-and-sharing-in-IntelSGX/m-p/1511248#M5834</link>
      <description>&lt;P&gt;This thread will no longer be monitored since we have provided a solution. If you need any additional information from Intel, please submit a new question.&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 04 Aug 2023 16:40:00 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Key-persistence-and-sharing-in-IntelSGX/m-p/1511248#M5834</guid>
      <dc:creator>Zulkifli_Intel</dc:creator>
      <dc:date>2023-08-04T16:40:00Z</dc:date>
    </item>
  </channel>
</rss>

