Intel® Software Guard Extensions (Intel® SGX)
Discussion board focused on hardware-based isolation and memory encryption to provide extended code protection in solutions.
1554 Discussions

Platform Ownership Endorsements: tool for platform-identity extraction

Benny_Intel
Moderator
76 Views

An important step in Intel's Platform Ownership Endorsements flow is to extract platform identities and to generate signed POE structures. Last week, Intel released the first version of the Intel® Platform Ownership Endorsement Generator (Intel® POE Generator), supporting the platform identity extraction:

  • Extracts Platform Instance IDs (PIID) from Platform Manifests (Base16 format), PCK Certificates (PEM format), and SGX/TD Quotes
  • Extracts Processor Registration IDs (PRID) from Platform Manifests (Base16 format)
  • Emits results as JSON, with a versioned schema (see poe-gen-tool/schemas/extract-output.schema.json)

While this is the first release of the tool, it’s version name matches the current Intel® Data Center Attestation Primitives (Intel® DCAP) release. In future Intel DCAP releases, the Intel® POE Generator  will additionally be packaged as DEB & RPM and distributed together with the other Intel DCAP packages.

Labels (3)
0 Replies
Reply