Intel® Software Guard Extensions (Intel® SGX)
Use hardware-based isolation and memory encryption to provide more code protection in your solutions.

Remote Attestation and IAS

SAM_R_2
Beginner
324 Views

Hi,

If the enclave is first launched in machine A, it sends the quote to user and user stores it. When the enclave is launched in machine B, previous quote is invalid. Is connecting to IAS necessary again in this situation?

Is it possible that Intel allows so many end users to use IAS?

Is it possible that Intel allows some other companies to do the IAS work?

-Thanks 

0 Kudos
1 Solution
Surenthar_S_Intel
324 Views

Hi Sam,

  • If the enclave is first launched in machine A, it sends the quote to user and user stores it. When the enclave is launched in machine B, previous quote is invalid. Is connecting to IAS necessary again in this situation?

                          Yes, connecting to IAS is necessary. when the enclave is launched in machine B, there is no “previous quote” unless the enclave has attested before.

  • Is it possible that Intel allows so many end users to use IAS?

                          Yes, Intel allows so many enclave to use IAS. Quotes are per enclave, not per user.

  • Is it possible that Intel allows some other companies to do the IAS work?

                          No, Intel doesn’t allows some other companies to do the IAS work.

Thanks and Reagrds,
Surenthar Selvaraj

View solution in original post

2 Replies
Surenthar_S_Intel
325 Views

Hi Sam,

  • If the enclave is first launched in machine A, it sends the quote to user and user stores it. When the enclave is launched in machine B, previous quote is invalid. Is connecting to IAS necessary again in this situation?

                          Yes, connecting to IAS is necessary. when the enclave is launched in machine B, there is no “previous quote” unless the enclave has attested before.

  • Is it possible that Intel allows so many end users to use IAS?

                          Yes, Intel allows so many enclave to use IAS. Quotes are per enclave, not per user.

  • Is it possible that Intel allows some other companies to do the IAS work?

                          No, Intel doesn’t allows some other companies to do the IAS work.

Thanks and Reagrds,
Surenthar Selvaraj

SAM_R_2
Beginner
324 Views

Thanks for your information

Reply