<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How do we enable Intel TME (Total Memory Encryption) and evaluate its effectiveness?&amp;quot; in Intel® Software Guard Extensions (Intel® SGX)</title>
    <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/How-do-we-enable-Intel-TME-Total-Memory-Encryption-and-evaluate/m-p/1652660#M6287</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Is there a guide or a demo showing the steps for enabling TME in BIOS and then evaluating whether the DRAM is encrypted correctly?&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.intel.com/content/www/us/en/architecture-and-technology/vpro/hardware-shield/total-memory-encrpytion.html" target="_blank"&gt;https://www.intel.com/content/www/us/en/architecture-and-technology/vpro/hardware-shield/total-memory-encrpytion.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The following picture shows that when 'Total Memory Encryption Bypass' is disabled, it indicates that TME is enabled. Is right?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="da313c6a-6c47-471a-b1e5-d8da60a10e9f.png" style="width: 999px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/61406i1E55C96254184485/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="da313c6a-6c47-471a-b1e5-d8da60a10e9f.png" alt="da313c6a-6c47-471a-b1e5-d8da60a10e9f.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 27 Dec 2024 10:54:35 GMT</pubDate>
    <dc:creator>Bronze_me</dc:creator>
    <dc:date>2024-12-27T10:54:35Z</dc:date>
    <item>
      <title>How do we enable Intel TME (Total Memory Encryption) and evaluate its effectiveness?"</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/How-do-we-enable-Intel-TME-Total-Memory-Encryption-and-evaluate/m-p/1652660#M6287</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Is there a guide or a demo showing the steps for enabling TME in BIOS and then evaluating whether the DRAM is encrypted correctly?&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.intel.com/content/www/us/en/architecture-and-technology/vpro/hardware-shield/total-memory-encrpytion.html" target="_blank"&gt;https://www.intel.com/content/www/us/en/architecture-and-technology/vpro/hardware-shield/total-memory-encrpytion.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The following picture shows that when 'Total Memory Encryption Bypass' is disabled, it indicates that TME is enabled. Is right?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="da313c6a-6c47-471a-b1e5-d8da60a10e9f.png" style="width: 999px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/61406i1E55C96254184485/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="da313c6a-6c47-471a-b1e5-d8da60a10e9f.png" alt="da313c6a-6c47-471a-b1e5-d8da60a10e9f.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Dec 2024 10:54:35 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/How-do-we-enable-Intel-TME-Total-Memory-Encryption-and-evaluate/m-p/1652660#M6287</guid>
      <dc:creator>Bronze_me</dc:creator>
      <dc:date>2024-12-27T10:54:35Z</dc:date>
    </item>
    <item>
      <title>Re: How do we enable Intel TME (Total Memory Encryption) and evaluate its effectiveness?"</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/How-do-we-enable-Intel-TME-Total-Memory-Encryption-and-evaluate/m-p/1654731#M6292</link>
      <description>&lt;P&gt;The TME Bypass feature is used to allow non-trusted software (ie. standard, non-confidential VMs that aren't utilizing Intel TDX) to automatically bypass the memory encryption flows in the memory subsystem/controller.&amp;nbsp; You can read a bit more about it at this link:&amp;nbsp;&amp;nbsp;&lt;A href="https://www.intel.com/content/www/us/en/developer/articles/technical/trust-domain-extensions-on-4th-gen-xeon-processors.html" target="_blank"&gt;Performance Considerations: Intel® Trust Domain Extensions&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 15:14:55 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/How-do-we-enable-Intel-TME-Total-Memory-Encryption-and-evaluate/m-p/1654731#M6292</guid>
      <dc:creator>Scott_R_Intel</dc:creator>
      <dc:date>2025-01-06T15:14:55Z</dc:date>
    </item>
    <item>
      <title>Re: How do we enable Intel TME (Total Memory Encryption) and evaluate its effectiveness?"</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/How-do-we-enable-Intel-TME-Total-Memory-Encryption-and-evaluate/m-p/1655670#M6295</link>
      <description>&lt;P&gt;Thank you very much for your response. Our application scenario is as follows:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;User A will deploy their Intel server (which supports Intel TME) in User B's local area network data center.&lt;/LI&gt;&lt;LI&gt;User A will deploy an application developed by A (such as a web service) on the server, and User A will deploy their data and code on the Intel server in B's data center.&lt;/LI&gt;&lt;LI&gt;User A will only provide B with an HTTPS interface, and User A will independently maintain the Intel server, with only A having login access.&lt;/LI&gt;&lt;LI&gt;Based on the above description, A wishes to use the Intel TME mechanism to encrypt memory to defend against physical attacks (such as cold boot attacks and memory dump attacks) from B's data center (e.g., by B's data center personnel).&lt;/LI&gt;&lt;LI&gt;A wants to enable TME directly in the BIOS (without needing TDX or TME-MK), so that A does not need to make any modifications to the system software (Linux kernel) or application software.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Therefore, the question in this scenario is that we only need Intel TME, so Intel TME bypass must be configured as disabled to ensure the security of A's data, correct?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2025 09:38:49 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/How-do-we-enable-Intel-TME-Total-Memory-Encryption-and-evaluate/m-p/1655670#M6295</guid>
      <dc:creator>Bronze_me</dc:creator>
      <dc:date>2025-01-09T09:38:49Z</dc:date>
    </item>
  </channel>
</rss>

