Intel Sftware Guard Extensins Platfrm Sftware fr Windws* OS Release Ntes Installatin Guide and Release Ntes 24 May 2016 Revisin: 1.6 Cntents: Intrductin What's New System Requirements Installatin Ntes Knwn Issues and Limitatins Disclaimer and Legal Infrmatin Intel Sftware Guard Extensins Platfrm Sftware fr Windws* OS Release Ntes 1
1 Intrductin This dcument prvides system requirements, installatin instructins, limitatins and legal infrmatin fr Intel Sftware Guard Extensins (Intel SGX) platfrm sftware (PSW). Prduct Cntents Intel Sftware Guard Extensins PSW package includes the fllwing sftware cmpnents: Ingredient Binary Versin String Intel SGX Windws* 7/8.1/10 driver (64 bit nly) 1.6.80.31049 Intel SGX Runtime System Library 1.6.100.32132 Intel SGX Applicatin Enclaves 1.6.101.32775 Intel SGX Applicatin Enclave Service (AESM) 1.6.101.32869 2 What's New Intel Sftware Guard Extensins PSW includes the fllwing changes in this versin Apply the fllwing updates fr the Intel SGX PSW installer: Install prductin architecture enclave (AE) and supprt flexible prvisining in prductin envirnment Install prductin the platfrm cnfiguratin data (PCD) file Install in Windws* 10 RTM when Hyper-V* is enabled even thugh yu cannt lad an enclave in this setting Use Intel SGX Prductin Platfrm Prvisining Service backend server by default Bug fix fr the pwer management supprt Supprt fr manual prxy set-up in Windws10* Netwrk and internet setting Supprt t query platfrm prvisining status Intel Sftware Guard Extensins Platfrm Sftware fr Windws* OS Release Ntes 2
Supprt t query platfrm service status Supprt t query enclave launch whitelist file 3 System Requirements Hardware Requirements The 6th Generatin Intel Cre Prcessr (Intel micrarchitecture cde name Skylake) A platfrm that uses Intel micrarchitecture cde name Kabylake prcessr with H0 stepping Firmware Requirements The 6th Generatin Intel Cre Prcessr (Intel micrarchitecture cde name Skylake) BIOS RC 0.7 r newer if the system is using an Intel reference BIOS. The latest versin f Intel micrarchitecture cde name Kabylake mbile platfrm Sftware Requirements Supprted perating systems fr the Intel SGX PSW installer: Micrsft Windws* 7/8.1/10/Threshld2/Redstne1 64-bit versin. Nte: Intel SGX PSW des nt supprt Micrsft Windws* 32-bit perating system. If yu need t use Intel SGX platfrm service, install the fllwing prduct: Full set f Intel Management Engine (ME) sftware cmpnents 11.5.0.1000 r newer Nte: T install full set f Intel Management Engine (ME) sftware cmpnents, yu need t install with SetupMe.exe instead f MEISetup.exe (HECI driver nly). 4 Installatin Ntes Befre installing Intel SGX PSW, enable Intel SGX in BIOS. Fr example, if the system is using an Intel reference BIOS, yu may cnfigure the BIOS ptins accrding t the fllwing steps: Intel Sftware Guard Extensins Platfrm Sftware fr Windws* OS Release Ntes 3
G t Intel Advanced Menu -> CPU Cnfiguratin -> SW Guard Extensins (SGX). Set SW Guard Extensins (SGX) as Enabled r Sftware Cntrlled. If yu set Sftware Cntrlled fr the SW Guard Extensins (SGX) ptin, yu need t enable Intel SGX using Intel SGX Enabling Functins after installing Intel SGX PSW. See Intel SGX SDK User s Guide fr Windws* OS fr mre details. If yu set Enabled fr the SW Guard Extensins (SGX) ptin, yu may need t cnfigure Intel Advanced Menu -> CPU Cnfiguratin -> PRMRR. Yu can set it t 32MB, 64MB r 128MB. The default ptin is 128MB. This step maybe nly applicable t Intel reference BIOS and may be nt applicable t OEM BIOS. Yu need administratr privilege t run the installer. Frm an Administratr cmmand prmpt, run the fllwing: msiexec /i SGX_PSW.msi T frce Intel SGX PSW installatin with administrative accunt, use the fllwing cmmand: msiexec /i SGX_PSW.msi FORCE_INSTALL=1 Silent/unattended installatins can be dne by adding the /qn r /quiet switch: msiexec /i SGX_PSW.msi /qn Once installed, yu can see Intel Sftware Guard Extensins Platfrm Sftware in the Cntrl Panel\Prgrams\Prgrams and Features list. The Intel SGX PSW installer des nt uninstall the Intel SGX device driver after the uninstallatin f the platfrm sftware. Subsequent installatins f the Intel SGX PSW update the driver t newer versins nly (n dwngrade is allwed). T use Intel SGX platfrm service, yu need t install full set f Intel Management Engine (ME) sftware cmpnents which includes Intel Dynamic Applicatin Lader(DAL) Hst Interface Service. If yu install Intel ME driver nly, Intel SGX platfrm service is nt available. Default Installatin Flders The default tp-level installatin flder fr this prduct is: C:\Prgram Files\Intel\IntelSGXPSW Intel Sftware Guard Extensins Platfrm Sftware fr Windws* OS Release Ntes 4
5 Knwn Issues and Limitatins Intel Sftware Guard Extensins nly supprts integrated Windws authenticatin prxy scheme. The Basic and the Digest authenticated prxy schemes are nt supprted. OEM must nt pst Intel SGX PSW fr end-users t dwnlad. Any Intel SGX PSW upgrade fr end-users is thrugh SGX applicatins prvided by ISV nly. Yu cannt install Intel SGX PSW by duble-clicking the Intel SGX PSW installer MSI file. T avid this issue, use ne f the fllwing appraches: Run the Intel SGX PSW installer as an administratr Run the installer frm within a cmmand cnsle which was started by run as administratr Intel SGX platfrm service fails fr DAL cmmunicatin failure if yu repeatedly use the service ver 40 hurs. If yu have installed Intel SGX PSW 1.6.100.32132, and yu upgrade Intel SGX PSW t versin 1.6.101.32869 thrugh the Upgrade ptin f Intel SGX PSW installer, Intel SGX PSW des nt cmmunicate with Intel SGX Prduct Platfrm Prvisining Service backend server. T avid this issue, uninstall Intel SGX PSW 1.6.100.32132, then install Intel SGX PSW 1.6.101.32869. 6 Disclaimer and Legal Infrmatin N license (express r implied, by estppel r therwise) t any intellectual prperty rights is granted by this dcument. Intel disclaims all express and implied warranties, including withut limitatin, the implied warranties f merchantability, fitness fr a particular purpse, and nn-infringement, as well as any warranty arising frm curse f perfrmance, curse f dealing, r usage in trade. This dcument cntains infrmatin n prducts, services and/r prcesses in develpment. All infrmatin prvided here is subject t change withut ntice. Cntact yur Intel representative t btain the latest frecast, schedule, specificatins and radmaps. The prducts and services described may cntain defects r errrs knwn as errata which may cause deviatins frm published specificatins. Current characterized errata are available n request. Intel technlgies features and benefits depend n system cnfiguratin and may require enabled hardware, sftware r service activatin. Learn mre at Intel.cm, r frm the OEM r retailer. Intel Sftware Guard Extensins Platfrm Sftware fr Windws* OS Release Ntes 5
Cpies f dcuments which have an rder number and are referenced in this dcument may be btained by calling 1-800-548-4725 r by visiting www.intel.cm/design/literature.htm. Intel, the Intel lg, Xen, and Xen Phi are trademarks f Intel Crpratin in the U.S. and/r ther cuntries. Optimizatin Ntice Intel's cmpilers may r may nt ptimize t the same degree fr nn-intel micrprcessrs fr ptimizatins that are nt unique t Intel micrprcessrs. These ptimizatins include SSE2, SSE3, and SSSE3 instructin sets and ther ptimizatins. Intel des nt guarantee the availability, functinality, r effectiveness f any ptimizatin n micrprcessrs nt manufactured by Intel. Micrprcessr-dependent ptimizatins in this prduct are intended fr use with Intel micrprcessrs. Certain ptimizatins nt specific t Intel micrarchitecture are reserved fr Intel micrprcessrs. Please refer t the applicable prduct User and Reference Guides fr mre infrmatin regarding the specific instructin sets cvered by this ntice. Ntice revisin #20110804 * Other names and brands may be claimed as the prperty f thers. 2016 Intel Crpratin. Intel Sftware Guard Extensins Platfrm Sftware fr Windws* OS Release Ntes 6