Obscura.net seems to have a simpler and more secure solution than this
Trust, a non constant, has no place in a security architecture.
Don't trust, verify.
https://www.intel.com/content/www/us/en/developer/tools/soft...
So you can verify locally and Intel's API also does the verification.
When an SGX Encalve is created, the private key to it goes within it, it can't be accessed. That's the security.
It's a good read if you look in to the tech on Intel's website.