Supermicro X13DEG-PVC User Manual page 105

Table of Contents

Advertisement

Chapter 4: UEFI BIOS
SGX Package Info In-Band Access
Setting this feature to Enabled is required before the BIOS provides software with the key
blobs, which are generated for each CPU package. The options are Disabled and Enabled.
SGX PRM Size (Available when "SW Guard Extensions (SGX)" is set to Enabled)
Use this feature to set the Processor Reserved Memory Range Register (PRMRR) size. The
options are 256M, 512M, 1G, 2G, 4G, and 8G.
SGX QoS (Available when "SW Guard Extensions (SGX)" is set to Enabled)
Use this feature to enable Intel SGX Quality of Service (QoS) support. QoS can enhance
network performance by prioritizing network traffic. The options are Disabled and Enabled.
Select Owner EPOCH Input type (Available when "SW Guard Extensions (SGX)" is
set to Enabled)
Owner EPOCH is used as a parameter to allow you to add personal entropy into the key
derivation process. A correct Owner EPOCH is required to have access to personal data
previously sealed by other platform users. There are two Owner EPOCH modes. One is New
Random Owner EPOCH , and the other is manually entered by the user. Each EPOCH is
64-bit. The options are Change to New Random Owner EPOCHs and Manual User Defined
Owner EPOCHs.
Note: Changing the Owner EPOCH value will lose the data in enclaves.
Software Guard Extensions Epoch 0 (Available when "SW Guard Extensions (SGX)"
is set to Enabled and "Select Owner EPOCH input type" is set to Manual User
Defined Owner EPOCHs)
Use this feature to enter the EPOCH value. The default is 0.
Software Guard Extensions Epoch 1 (Available when "SW Guard Extensions (SGX)"
is set to Enabled and "Select Owner EPOCH input type" is set to Manual User
Defined Owner EPOCHs)
Use this feature to enter the EPOCH value. The default is 0.
SGXLEPUBKEYHASHx Write Enable (Available when "SW Guard Extensions (SGX)"
is set to Enabled)
Use this feature to enable writes to SGXLEPUBKEYHASH[3..0] from OS/SW. The options
are Disabled and Enabled. Only those CPUs that support Intel SGX Flexible Launch Control
(FLC) feature have SGXLEPUBKEYHASH, which contains the hash of the public key for the
SGX Launch Enclave (LE) to be signed with.
SGXLEPUBKEYHASH0 (Available when both "SW Guard Extensions (SGX)" and
"SGXLEPUBKEYHASHx Write Enable" are set to Enabled)
Use this feature to enter the bytes 0-7 of SGX Launch Enclave Public Key Hash.
105

Advertisement

Table of Contents
loading

Table of Contents