Virtual Event Today: Threat Detection & Incident Response Summit - Login Now
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Protection

Intel Unveils New Security Tech in Upcoming Ice Lake CPU

Intel on Wednesday announced the new security technologies that will be present in the company’s upcoming 3rd generation Xeon Scalable processor, code-named “Ice Lake.”

Intel told SecurityWeek that it’s aiming to make initial production shipments of the first 10nm-based Xeon Scalable product at the end of the year.

Intel on Wednesday announced the new security technologies that will be present in the company’s upcoming 3rd generation Xeon Scalable processor, code-named “Ice Lake.”

Intel told SecurityWeek that it’s aiming to make initial production shipments of the first 10nm-based Xeon Scalable product at the end of the year.

The company says Ice Lake will include its SGX trusted execution environment, as well as several new features for memory encryption, firmware resilience, and cryptographic performance acceleration. Intel says these features should address concerns related to data integrity and confidentiality.New security features in Intel Ice Lake processors

“Protecting data is essential to extracting value from it, and with the capabilities in the upcoming 3rd Gen Xeon Scalable platform, we will help our customers solve their toughest data challenges while improving data confidentiality and integrity. This extends our long history of partnering across the ecosystem to drive security innovations,” said Lisa Spelman, corporate VP of the Data Platform Group and GM of the Xeon and Memory Group at Intel.

One of the new security features introduced with Ice Lake processors is named Total Memory Encryption (TME), which ensures that all memory accessed from the CPU is encrypted. This includes encryption keys, user credentials, and other sensitive information on the external memory bus.

The feature uses the AES XTS standard and the encryption key is generated by a hardened random number generator in the processor. TME, Intel says, can provide better protection against attacks that involve custom-built hardware or removing the RAM sticks.

As for cryptographic acceleration, Intel says it has introduced two new innovations that should help reduce the performance impact caused by better security.

Advertisement. Scroll to continue reading.

“The first is a technique to stitch together the operations of two algorithms that typically run in combination yet sequentially, allowing them to execute simultaneously. The second is a method to process multiple independent data buffers in parallel,” the company explained.

Finally, the Intel Platform Firmware Resilience (PFR) feature in Ice Lake processors is designed to protect systems against firmware attacks by detecting and addressing them before any damage is caused. Protected components include the BIOS and BMC flash, Management Engine, SPI Descriptor, and even the power supply firmware.

Microsoft believes the new processors can be very useful for its Azure confidential computing offering.

“Azure has confidential computing options for virtual machines, containers, machine learning, and more. We believe the next-generation Intel Xeon processors with Intel SGX featuring full memory encryption and cryptographic acceleration will help our customers unlock even more confidential computing scenarios,” said Mark Russinovich, chief technology officer at Microsoft Azure.

Related: Intel Improves Hardware Shield in New 10th Gen Core vPro Processors

Related: CacheOut/L1DES: New Speculative Execution Attack Affecting Intel CPUs

Related: New Security Tech in Intel CPUs Protects Systems Against Malware Attacks

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

People on the Move

Tim Byrd has been appointed Chief Information Security Officer at First Citizens Bank.

IRONSCALES has named Steve McKenzie as Chief Operating Officer.

Silvio Pappalardo has joined AuthMind as Chief Revenue Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.