Intel® Software Guard Extensions (Intel® SGX)
Discussion board focused on hardware-based isolation and memory encryption to provide extended code protection in solutions.

Remote Attestation and IAS

SAM_R_2
初学者
1,104 次查看

Hi,

If the enclave is first launched in machine A, it sends the quote to user and user stores it. When the enclave is launched in machine B, previous quote is invalid. Is connecting to IAS necessary again in this situation?

Is it possible that Intel allows so many end users to use IAS?

Is it possible that Intel allows some other companies to do the IAS work?

-Thanks 

0 项奖励
1 解答
Surenthar_S_Intel
1,104 次查看

Hi Sam,

  • If the enclave is first launched in machine A, it sends the quote to user and user stores it. When the enclave is launched in machine B, previous quote is invalid. Is connecting to IAS necessary again in this situation?

                          Yes, connecting to IAS is necessary. when the enclave is launched in machine B, there is no “previous quote” unless the enclave has attested before.

  • Is it possible that Intel allows so many end users to use IAS?

                          Yes, Intel allows so many enclave to use IAS. Quotes are per enclave, not per user.

  • Is it possible that Intel allows some other companies to do the IAS work?

                          No, Intel doesn’t allows some other companies to do the IAS work.

Thanks and Reagrds,
Surenthar Selvaraj

在原帖中查看解决方案

0 项奖励
2 回复数
Surenthar_S_Intel
1,105 次查看

Hi Sam,

  • If the enclave is first launched in machine A, it sends the quote to user and user stores it. When the enclave is launched in machine B, previous quote is invalid. Is connecting to IAS necessary again in this situation?

                          Yes, connecting to IAS is necessary. when the enclave is launched in machine B, there is no “previous quote” unless the enclave has attested before.

  • Is it possible that Intel allows so many end users to use IAS?

                          Yes, Intel allows so many enclave to use IAS. Quotes are per enclave, not per user.

  • Is it possible that Intel allows some other companies to do the IAS work?

                          No, Intel doesn’t allows some other companies to do the IAS work.

Thanks and Reagrds,
Surenthar Selvaraj

0 项奖励
SAM_R_2
初学者
1,104 次查看

Thanks for your information

0 项奖励
回复