Upgraded to OpenSSL 1.1.1m. Provided RA-TLS (Remote Attestation based Transport Layer Security) APIs and Samples. Supported PKRU (Protection Key rights Register) in Enclave. Added APIs of SHA384 and VerifyReport2 to support TDX. Enhanced QPL (Quote Provider Library) to support caching Intel PCK (Provisioning Certificate Key) certificate chain in local memory, or retrieving Intel PCK cert chain from local HTTP/S address. Upgraded Intel ECDSA Quote Verification Enclave to integrate SgxSSL/OpenSSL version 1.1.1m. Introduced Intel ID enclave for QE identity generation. Fixed bugs. Signed-off-by: Li, Xun <xun.li@intel.com>
Intel(R) EPID SDK
The Intel(R) Enhanced Privacy ID Software Development Kit
Intel(R) EPID SDK enables adding Intel(R) EPID support to applications and platforms.
Intel(R) EPID is a cryptographic protocol which enables the remote authentication of a trusted platform whilst preserving the user's privacy.
-
For a given public key there are many (e.g., millions) of private keys. The key holders form a group.
-
Any key holder may sign against the one public key.
-
No one can tell which private key signed the data. This is the privacy property.
You can use Intel(R) EPID as a foundational building block for a multitude of security solutions.
Prerequisites
What's New in This Release
See CHANGELOG.md.
Documentation
See doc/index.html to browse the html documentation.
License
See LICENSE.txt.
Math Primitives
The source code used for math primitives in the Intel(R) EPID SDK is a subset of the Intel(R) IPP Cryptography library (version 2017 Update 2) written in pure C and not optimized for performance. For higher performance, you can use the commercial version of the IPP Cryptography library, which is available at https://software.intel.com/articles/download-ipp-cryptography-libraries.
More information on the optimized versions of Intel(R) IPP Cryptography library, including mitigations for a potential side-channel issue are available at https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00060&languageid=en-fr.