Intel celebrates security of Ice Lake Xeon processors, so far impervious to any threat due to their unavailability
(2020/10/14)
- Reference: 1602703585
- News link: https://www.theregister.co.uk/2020/10/14/intel_ice_lake_xeon_security/
- Source link:
Intel on Wednesday talked up a set of security features planned for its promised third-generation Xeon Scalable Processors, code-named Ice Lake, which are supposed to show up before the end of the year.
The chip biz said it's "doubling down on its Security First Pledge," as if some sort of quantitative measurement of security could be calculated and weighed against prior security commitments.
The suggested twofold security inflation takes the form of adding features like Software Guard Extensions (SGX), Total Memory Encryption (TME), Platform Firmware Resilience (PFR), and cryptographic acceleration to the Ice Lake line.
"With a focus on encrypting and protecting data at rest, in transit and in use, Ice Lake helps our customers move beyond encrypted data to encrypted computing," said Lisa Spelman, corporate VP in Intel's Data Platform Group and general manager of the Xeon and Memory Group, in [1]a video presentation .
SGX consists of security-oriented instructions and features, baked into Intel silicon, that allow applications to run code in private memory areas called secure enclaves that cannot, in theory, be accessed by the operating system, hypervisor, and any other software. The idea is that you can run secret, sensitive stuff in an enclave, such as DRM decryption, without being snooped on.
Intel screams Tiger Lake is 'world's best processor' (then quietly into its sleeve: for thin Windows, ChromeOS laptops) [2]READ MORE
Spelman said SGX is "the most researched, updated, and battle-tested trusted execution encouragement available for the data center today," and helps support confidential computing on platforms like Microsoft Azure, Alibaba Cloud, and IBM Cloud Data Guard.
SGX is indeed researched and often thereafter updated when infosec types find holes, as [3]has [4]happened [5]several [6]times in recent years and may yet again. But perhaps it's enough that Intel is paying attention and fixing flaws as they're found.
TME
PFR
PRF relies on an FPGA as the platform root of trust, which validates firmware components before firmware code gets run. It can protect components like the BIOS flash, BMC Flash, SPI descriptor, Intel Management Engine, and power supply firmware, according to the manufacturer.
And the various cryptographic improvements touted refer to techniques for parallelizing normally sequential algorithms and data buffer processing – having these operations run at the same time is, as might be expected, faster than running them one after another.
Intel's Ice Lake Xeons are also protected by an additional layer of security known as not actually being available to you and I right now. But that's unlikely to last much longer. Almost suffice to say, rival AMD's Epyc server processors have similar security features, such as RAM encryption and encrypted virtual machine memory. ®
Get our [9]Tech Resources
[1] https://newsroom.intel.com/news-releases/intel-xeon-scalable-platform-built-most-sensitive-workloads/
[2] https://www.theregister.com/2020/09/02/intel_evo_processor/
[3] https://www.theregister.com/2020/06/10/intel_patches_sgx_again/
[4] https://www.theregister.com/2019/02/12/intel_sgx_hacked/
[5] https://www.theregister.com/2019/12/05/membuster_secure_enclave/
[6] https://www.theregister.com/2019/12/10/intel_sgx_youve_been_plunderstruck/
[7] https://software.intel.com/sites/default/files/managed/a5/16/Multi-Key-Total-Memory-Encryption-Spec.pdf
[8] https://www.intel.com/content/dam/www/public/us/en/documents/solution-briefs/firmware-resilience-blocks-solution-brief.pdf
[9] https://whitepapers.theregister.com/
The chip biz said it's "doubling down on its Security First Pledge," as if some sort of quantitative measurement of security could be calculated and weighed against prior security commitments.
The suggested twofold security inflation takes the form of adding features like Software Guard Extensions (SGX), Total Memory Encryption (TME), Platform Firmware Resilience (PFR), and cryptographic acceleration to the Ice Lake line.
"With a focus on encrypting and protecting data at rest, in transit and in use, Ice Lake helps our customers move beyond encrypted data to encrypted computing," said Lisa Spelman, corporate VP in Intel's Data Platform Group and general manager of the Xeon and Memory Group, in [1]a video presentation .
SGX consists of security-oriented instructions and features, baked into Intel silicon, that allow applications to run code in private memory areas called secure enclaves that cannot, in theory, be accessed by the operating system, hypervisor, and any other software. The idea is that you can run secret, sensitive stuff in an enclave, such as DRM decryption, without being snooped on.
Intel screams Tiger Lake is 'world's best processor' (then quietly into its sleeve: for thin Windows, ChromeOS laptops) [2]READ MORE
Spelman said SGX is "the most researched, updated, and battle-tested trusted execution encouragement available for the data center today," and helps support confidential computing on platforms like Microsoft Azure, Alibaba Cloud, and IBM Cloud Data Guard.
SGX is indeed researched and often thereafter updated when infosec types find holes, as [3]has [4]happened [5]several [6]times in recent years and may yet again. But perhaps it's enough that Intel is paying attention and fixing flaws as they're found.
TME
[7]PDF
, as Intel tells it, is just what the name suggests: a way to encrypt all data going in and out of external memory from the processor chipset using AES-XTS cryptography with 128-bit keys. Chipzilla says it created this feature to defend against hardware attacks, "such as removing and reading the dual in-line memory module (DIMM) after spraying it with liquid nitrogen or installing purpose-built attack hardware." In other words, if you rip the RAM out of a server and preserve its contents, it'll be encrypted anyway.PFR
[8]PDF
meanwhile refers to various measures put in place to prevent server firmware from being altered or tampered with, from the point of production through deployment in a data center or a similar environment.PRF relies on an FPGA as the platform root of trust, which validates firmware components before firmware code gets run. It can protect components like the BIOS flash, BMC Flash, SPI descriptor, Intel Management Engine, and power supply firmware, according to the manufacturer.
And the various cryptographic improvements touted refer to techniques for parallelizing normally sequential algorithms and data buffer processing – having these operations run at the same time is, as might be expected, faster than running them one after another.
Intel's Ice Lake Xeons are also protected by an additional layer of security known as not actually being available to you and I right now. But that's unlikely to last much longer. Almost suffice to say, rival AMD's Epyc server processors have similar security features, such as RAM encryption and encrypted virtual machine memory. ®
Get our [9]Tech Resources
[1] https://newsroom.intel.com/news-releases/intel-xeon-scalable-platform-built-most-sensitive-workloads/
[2] https://www.theregister.com/2020/09/02/intel_evo_processor/
[3] https://www.theregister.com/2020/06/10/intel_patches_sgx_again/
[4] https://www.theregister.com/2019/02/12/intel_sgx_hacked/
[5] https://www.theregister.com/2019/12/05/membuster_secure_enclave/
[6] https://www.theregister.com/2019/12/10/intel_sgx_youve_been_plunderstruck/
[7] https://software.intel.com/sites/default/files/managed/a5/16/Multi-Key-Total-Memory-Encryption-Spec.pdf
[8] https://www.intel.com/content/dam/www/public/us/en/documents/solution-briefs/firmware-resilience-blocks-solution-brief.pdf
[9] https://whitepapers.theregister.com/
Funniest headline in weeks!
Dvon of Edzore
To paraphrase The Elon, "The most secure processor is no processor." Though it still won't protect against ransomware and "This is the Finance Director. Have our bank wire 21.7 million to this account for our new branch."
Thanks, it's the one with "Mechanical Interlockings for Dummies" in the pocket.
I like the ideas...
...Behind encrypted RAM and all that. I will admit that I am skeptical (and maybe even more cynical, if possible) about Intel's claims. It's not just Intel either. I think I am developing a full blown case of hardware vulnerability paranoia.
This is due to the fact that as time goes by it is inevitable that more of what we used to do in software will be done in hardware. I spent decades watching people roll their eyes when I told them that reducing their software footprint was the fastest and cheapest way to reduce the attack surface of their organization. Maybe, just maybe, had they actually been paying me for advice instead of just "Making IT Work" they would have listened. After I have been gone from those companies for decades I look back and in my minds eye I can those eyes rolling again when some PFY says "You are going to ransom? You know that will only make things worse, right?"
My point is that I want to be able to choose which features I get in my CPU now. For 25 years I have able to apt-get my way to a (mostly?) stable and secure system. Now it's time for some new commands, like "Intel-put --cores=32 --L2=2M --L3=128M --AVX=128 --hidden-backdoors=-1" and have them spit out my desired hardware. It would not be cheap but it would go a long way towards rebuilding the trust that was lost.
Maybe, just maybe, in the future everyone will be able to design a custom CPU in fifteen minutes.