Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Confusion in the DCAP process #1013

Open
aghia98 opened this issue Feb 19, 2024 · 0 comments
Open

Confusion in the DCAP process #1013

aghia98 opened this issue Feb 19, 2024 · 0 comments

Comments

@aghia98
Copy link

aghia98 commented Feb 19, 2024

Hi,
I am reading the Intel's documentation and third party papers to undrstand the DCAP protocol and I am bit confused in some steps.

  1. What is the difference between the attestation key (AK) and the provisioning certification key (PCK) ? The former is used to sign enclave quotes while the second is used to sign QE Reports and authenticate the former...Why not only the PCK is used then ?
  2. What is the difference between a quote and a QE report ?
  3. To check the enclave, Intel provides quote verification enclave (QvE)... Why do we need an enclave to check the quotes since the protocol exposes the certification chain and anyone can check it ?

thank you in advance

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant