Intel® Server Board M50CYP2SB Family Technical Product Specification
103
12.4
Intel® Total Memory Encryption (Intel® TME)
To better protect computer system memory, the 3
rd
Gen Intel® Xeon® Scalable processor has a security
feature called Intel® Total Memory Encryption (Intel® TME). This feature is supported on the Intel® Server
Board M50CYP2SB family. Intel® TME helps ensure that all memory accessed from the Intel® processors is
encrypted, including customer credentials, encryption keys, and other IP or personal information on the
external memory bus. Intel® TME is also available for multi-tenant server platforms, called Intel® Total
Memory Encryption
–
Multi-Tenant (Intel® TME-MT).
Intel developed this feature to provide greater protection for system memory against hardware attacks, such
as removing and reading the dual in-line memory module (DIMM) after spraying it with liquid nitrogen or
installing purpose-built attack hardware. Using the National Institute of Standards and Technology (NIST)
storage encryption standard AES XTS, an encryption key is generated using a hardened random number
generator in the processor without exposure to software. This situation allows existing software to run
unmodified while better protecting memory.
Intel® TME can be enabled directly in the server BIOS and is compatible with Intel® Software Guard
Extensions application enclave solutions.
Intel® TME has the following characteristics:
•
Encrypts
the entire memory using a NIST standard “storage
-
class” algorithm for encryption: AES
-XTS
•
Transparent to software
, it encrypts data before writing to server memory and then decrypts on read.
•
Easy enablement
that requires no operating system or application enabling and is applicable to all
operating systems.
To enable/disable Intel® TME, access the BIOS Setup menu by pressing
<F2>
key during POST. Navigate to
the following menu:
Advanced >
Processor Configuration
Important Note:
When either Intel® TME or Intel® TME-MT is enabled, a subset of memory RAS features and
Intel® Optane™
persistent memory 200 series (if installed) will be disabled. See
For more information on Intel® TME, see the
BIOS Setup Utility User Guide for the Intel® Server Boards
D50TNP, M50CYP, and D40AMP Families
and the
BIOS Firmware External Product Specification (EPS) for the
Intel® Server Boards D50TNP, M50CYP, and D40AMP Families.
12.5
Intel
®
Software Guard Extensions (Intel
®
SGX)
Intel® Software Guard Extensions (Intel® SGX) is a set of instructions that increases the security of application
code and data, giving them more protection from disclosure or modification. Developers can partition
sensitive information into enclaves that are areas of execution in memory with more security protection.
Intel® SGX Helps protect selected code and data from disclosure or modification. Intel® SGX helps partition
applications into enclaves in memory that increase security. Enclaves have hardware-assisted confidentiality
and integrity-added protections to help prevent access from processes at higher privilege levels. Through
attestation services, a relying party can receive some verification on the identity of an application enclave
before launch.
Содержание M50CYP2SB Series
Страница 2: ...2 This page intentionally left blank...