Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add an Interaction model without a Verifier #1

Open
ericvoit opened this issue Dec 6, 2021 · 0 comments
Open

Add an Interaction model without a Verifier #1

ericvoit opened this issue Dec 6, 2021 · 0 comments

Comments

@ericvoit
Copy link
Collaborator

ericvoit commented Dec 6, 2021

In April, Vinnie asked for an interaction model which doesn't require a Verifier. This is for things like SGX where the provable identity of the MRSIGNER is sufficient to the Relying Party. The specific comment was: The question then is whether we need some form of time interval tracking between Verifiers A & B. I believe it to be useful to understand the delta in time between the creation of the original Attestation Results, and their receipt on the Relying Party. The one time I can think of when this might not be necessary is when the Relying Party trusts that the Attester cannot be meaningfully changed from the outside over time. (E.g., a specific MRENCLAVE can expose no changing Evidence to Verifier A over time, and this MRENCLAVE is trusted to be unable to mimic another MRENCLAVE or replay Attestation Evidence about another MRENCLAVE.) In such a case, nonce#2 from figure 1 can be safely dropped. I will propose text to this effect into the draft.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant