Intel® Software Guard Extensions (Intel® SGX)
Discussion board focused on hardware-based isolation and memory encryption to provide extended code protection in solutions.

Verifying fields within a TDX Quote

Isaac_HPE
Beginner
658 Views

I am trying to understand how to verify a quote, but there are a few fields within the Enclave Report Body structure that I am not sure what to do with, or if they are necessary to verify for a TDX attestation.

 

The fields, within Enclave Body Report, are:

CPU SVN

MRENCLAVE

ISV ProdID

With most of my concern being for the first two.  Should I be checking the CPU SVN against the PCK cert value? Is the enclave measurement reported in any collateral from Intel (I haven't found it yet if that is the case)?

 

Thanks in advance for any help or pointers,

Isaac

0 Kudos
1 Reply
Isaac_HPE
Beginner
651 Views

Sorry, ignore ISV ProdID that is already being verified! It is just the other two fields.

0 Kudos
Reply