This page was machine-translated and may differ from the original. View original

Intel Unveils New Security Feature Set for 3rd-Generation Xeon Platform

Google 우선 소스Published2020.10.16 09:44
SGX, memory encryption, and firmware resilience
New security innovations, including innovative encryption accelerators



Intel unveiled a new set of security features for its upcoming 3rd generation Intel Xeon Scalable platform (Ice Lake) on the 15th.

▲ 3rd Generation Xeon Scalable Processor [Photo = Intel]

Intel is delivering its leading and certified Intel Software Guard Extensions (SGX) across the Ice Lake platform, building on its Security First Pledge. This also supports Intel Total Memory Encryption (TME), Intel Platform Firmware Resilience (PFR), and new cryptographic accelerators to harden the platform, enhance confidentiality, and ensure data integrity.

Ice Lake's security features enable Intel customers to develop solutions that improve their security posture and reduce risks related to privacy and compliance.

Technologies such as disk and network traffic encryption protect data within storage and during transmission, but data can be vulnerable to interception and tampering while in use in memory. Accordingly, 'Confidential Computing' is rapidly emerging as a method to protect data while it is being used in a trusted execution environment (TEE).

Intel SGX is the most researched, updated, and battle-ready Trusted Execution Environment (TEE) for data center confidential computing within systems. It enables application isolation within private memory regions called enclaves, protecting up to 1 terabyte of code and data in a live environment.

“Microsoft Azure was the first major public cloud to offer confidential computing, and today customers across industries like finance, healthcare, and government are using confidential computing on Azure,” said Mark Russinovich, CTO of Microsoft Azure. “Azure has confidential computing options for virtual machines, containers, machine learning, and more. We believe the next-generation Intel Xeon processors, featuring full memory encryption and cryptographic acceleration, will help customers compute more securely.”

In fact, customers in highly regulated industries, including the University of California, San Francisco (UCSF), NEC, and Magnit, have relied on Intel for security, while healthcare organizations can securely protect data, including health records, in a trusted computing environment that better preserves patient privacy.

To better protect the platform's entire memory, Ice Lake introduces a new feature called Intel TME. Intel TME ensures that all memory accessed by the Intel CPU is encrypted, including customer credentials, encryption keys, and other IP or private information on the external memory bus. Intel developed this feature to counter hardware attacks and better protect system memory.

Hardware attacks can involve removing dual in-line memory modules (DIMMs), reading them with liquid nitrogen, or installing specially designed attack hardware. Using the National Institute of Standards and Technology (NIST) Storage Encryption Standard, the encryption key, AES XTS, is generated using a hardened random number generator on the processor, not exposed to software. This allows existing software to run unmodified, while protecting memory.

Intel's design goal is to enhance security without sacrificing performance. Ice Lake introduces a new approach, along with algorithmic and software innovations, to deliver groundbreaking cryptographic performance. The first approach combines the operations of two algorithms, typically run sequentially, allowing them to run concurrently. The second approach involves processing multiple independent data buffers in parallel.

The privacy-preserving and trustworthy platform of the upcoming 3rd generation Xeon Scalable processors will enable organizations seeking to unlock the full value of their data to drive even more innovative services, usage models, and solutions.

“Data protection is essential to extracting value from data,” said Lisa Spelman, vice president and general manager of Intel’s Data Platforms Group. “With capabilities in our upcoming 3rd-Generation Xeon Scalable platform, Intel will help customers enhance the confidentiality and integrity of their data.”
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
김동우 기자