Intel® Software Guard Extensions (Intel® SGX)
Discussion board focused on hardware-based isolation and memory encryption to provide extended code protection in solutions.

Remote Attestation and IAS

SAM_R_2
Beginner
631 Views

Hi,

If the enclave is first launched in machine A, it sends the quote to user and user stores it. When the enclave is launched in machine B, previous quote is invalid. Is connecting to IAS necessary again in this situation?

Is it possible that Intel allows so many end users to use IAS?

Is it possible that Intel allows some other companies to do the IAS work?

-Thanks 

0 Kudos
1 Solution
Surenthar_S_Intel
631 Views

Hi Sam,

  • If the enclave is first launched in machine A, it sends the quote to user and user stores it. When the enclave is launched in machine B, previous quote is invalid. Is connecting to IAS necessary again in this situation?

                          Yes, connecting to IAS is necessary. when the enclave is launched in machine B, there is no “previous quote” unless the enclave has attested before.

  • Is it possible that Intel allows so many end users to use IAS?

                          Yes, Intel allows so many enclave to use IAS. Quotes are per enclave, not per user.

  • Is it possible that Intel allows some other companies to do the IAS work?

                          No, Intel doesn’t allows some other companies to do the IAS work.

Thanks and Reagrds,
Surenthar Selvaraj

View solution in original post

0 Kudos
2 Replies
Surenthar_S_Intel
632 Views

Hi Sam,

  • If the enclave is first launched in machine A, it sends the quote to user and user stores it. When the enclave is launched in machine B, previous quote is invalid. Is connecting to IAS necessary again in this situation?

                          Yes, connecting to IAS is necessary. when the enclave is launched in machine B, there is no “previous quote” unless the enclave has attested before.

  • Is it possible that Intel allows so many end users to use IAS?

                          Yes, Intel allows so many enclave to use IAS. Quotes are per enclave, not per user.

  • Is it possible that Intel allows some other companies to do the IAS work?

                          No, Intel doesn’t allows some other companies to do the IAS work.

Thanks and Reagrds,
Surenthar Selvaraj

0 Kudos
SAM_R_2
Beginner
631 Views

Thanks for your information

0 Kudos
Reply