Intel® ISA Extensions
Use hardware-based isolation and memory encryption to provide more code protection in your solutions.
This community is designed for sharing of public information. Please do not share Intel or third-party confidential information here.
1058 Discussions

How to enable MPK in Intel Xeon Gold processors?


I would like to use Intel MPK (memory protection keys) feature.

According to a paper: ERIM: Secure, Efficient In-process Isolation with Protection Keys (MPK), I buy a server with Intel Xeon Gold 6142 2.6GHz CPU. But I found there is no PKU feature in my server. (I run cat /proc/cpuinfo | grep pku and found nothing).

So, how to enable MPK in Intel Xeon Gold processors?

20190814221230 (1).jpg

0 Kudos
1 Reply
Black Belt

This may depend on your Linux kernel revision.   According to initial support was first added in the 3.19 kernel, while suggests that support is not complete until the 4.9 kernel.

The "cpuid" program available at does a good job of parsing the output of the CPUID instruction.  On my Xeon Gold 6152, the cpuid program reports that the MPX and PKU features are supported, and the kernel (CentOS 7.6, 3.10.0-957.5.1.el7.x86_64) reports the "mpx" and "pku" extensions have been pack-ported to this kernel.