Alex Ionescu wrote a paper [1] on Win10 and SGX.
> It’s important to realize that for now, only Intel has
> the required key to allow an enclave to be launched
> without knowing the required CPU-specific enclave key,
> and no other (even signed) enclaves can be launched
> without it. Once Intel releases a permissive loader, or
> if Intel ME vulnerabilities are found to extract the key,
> then the real abuse will begin.
>
> Indeed, one area of further research is the Intel SGX
> Driver that was released for recent Intel SGX-enabled
> Dell Laptops, which contains a le.signed.dll file that is
> the Intel Launch Enclave. Additionally, it contains
> Intel’s EINITTOKEN that can be used to launch such
> enclaves, as well as a service and set of APIs which
> appear to make it possible to launch additional enclaves.
> Windows 10, on its own, does not seem to ship or support
> its own Intel-signed Launch Enclave.
[1] http://www.alex-ionescu.com/Enclave%20Support%20In%20Windows...