<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, in Intel® Software Guard Extensions (Intel® SGX)</title>
    <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/A-security-concern-about-SGX/m-p/1094434#M934</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P style="word-wrap: break-word; font-size: 12px;"&gt;Section 5 of our&amp;nbsp;&lt;A href="https://software.intel.com/en-us/articles/innovative-instructions-and-software-model-for-isolated-execution" style="cursor: pointer;"&gt;whitepaper&amp;nbsp;&lt;/A&gt;explains the process for building an enclave. Whilst a Ring0 component&amp;nbsp;executes the instructions, the HW architecture is responsible for the security of the enclave. The measurement created by the HW during this process is inaccessible to the Ring0 component.&lt;/P&gt;

&lt;P style="word-wrap: break-word; font-size: 12px;"&gt;At the end of the build process you have an enclave with a measurement and&amp;nbsp;it then uses the attestation process to allow a verifier to determine that the enclave was built as it required and then to deploy a secret to the enclave.&lt;/P&gt;

&lt;P style="word-wrap: break-word; font-size: 12px;"&gt;Keys used to keep the secret local are also bound to the measurement of the enclave.&lt;/P&gt;

&lt;P style="word-wrap: break-word; font-size: 12px;"&gt;-Surenthar&lt;/P&gt;</description>
    <pubDate>Tue, 22 Nov 2016 11:00:01 GMT</pubDate>
    <dc:creator>Surenthar_S_Intel</dc:creator>
    <dc:date>2016-11-22T11:00:01Z</dc:date>
    <item>
      <title>A security concern about SGX</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/A-security-concern-about-SGX/m-p/1094433#M933</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;As I know, a SGX enclave memory will be encrypted until it is loaded into CPU.&lt;/P&gt;

&lt;P&gt;The memory will be decrypted by memory controller, it means that the secret message will be loaded into CPU cache as a plaintext, right?&lt;/P&gt;

&lt;P&gt;If a malicious software or malicious enclave try to flush or desctroy the whole cache line, How does SGX protect the secret in the cache?&lt;/P&gt;

&lt;P&gt;Is there any document introduce the details about SGX instruction behavior inside CPU?&lt;/P&gt;

&lt;P&gt;&amp;nbsp;&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2016 08:27:20 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/A-security-concern-about-SGX/m-p/1094433#M933</guid>
      <dc:creator>Changzheng_W_Intel</dc:creator>
      <dc:date>2016-11-22T08:27:20Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/A-security-concern-about-SGX/m-p/1094434#M934</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P style="word-wrap: break-word; font-size: 12px;"&gt;Section 5 of our&amp;nbsp;&lt;A href="https://software.intel.com/en-us/articles/innovative-instructions-and-software-model-for-isolated-execution" style="cursor: pointer;"&gt;whitepaper&amp;nbsp;&lt;/A&gt;explains the process for building an enclave. Whilst a Ring0 component&amp;nbsp;executes the instructions, the HW architecture is responsible for the security of the enclave. The measurement created by the HW during this process is inaccessible to the Ring0 component.&lt;/P&gt;

&lt;P style="word-wrap: break-word; font-size: 12px;"&gt;At the end of the build process you have an enclave with a measurement and&amp;nbsp;it then uses the attestation process to allow a verifier to determine that the enclave was built as it required and then to deploy a secret to the enclave.&lt;/P&gt;

&lt;P style="word-wrap: break-word; font-size: 12px;"&gt;Keys used to keep the secret local are also bound to the measurement of the enclave.&lt;/P&gt;

&lt;P style="word-wrap: break-word; font-size: 12px;"&gt;-Surenthar&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2016 11:00:01 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/A-security-concern-about-SGX/m-p/1094434#M934</guid>
      <dc:creator>Surenthar_S_Intel</dc:creator>
      <dc:date>2016-11-22T11:00:01Z</dc:date>
    </item>
  </channel>
</rss>

