Intel® Software Guard Extensions (Intel® SGX)
Use hardware-based isolation and memory encryption to provide more code protection in your solutions.

SGX Host application multiple enclave

ciraci__nicolo
Beginner
390 Views

Hi,

can an application have two separate enclaves? Each running their code in separate concurrent threads? Furthermore, can this two enclave share a variable or the only communication way is LocalAttestation/Seal Data?

 

 

0 Kudos
2 Replies
Rodolfo_S_
New Contributor III
390 Views

Hi,

for the first two questions, the answer is yes. As for the last one, this would go against the purpose of SGX, which is to provide enclaves that are completely isolated from anything else. Therefore, no.

Regards,

Rodolfo

Hoang_N_Intel
Employee
390 Views

Running multiple enclaves in an application is definitely available but please remember that Enclave resource is limited and there is performance implication.

If you want to share a secret between two enclaves, you need to build a secure channel between them. A common technique is s leverage Diffie Hellman key exchange protocol to build one.

Reply