- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is there a guide or a demo showing the steps for enabling TME in BIOS and then evaluating whether the DRAM is encrypted correctly?
https://www.intel.com/content/www/us/en/architecture-and-technology/vpro/hardware-shield/total-memory-encrpytion.html
The following picture shows that when 'Total Memory Encryption Bypass' is disabled, it indicates that TME is enabled. Is right?
Link Copied
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The TME Bypass feature is used to allow non-trusted software (ie. standard, non-confidential VMs that aren't utilizing Intel TDX) to automatically bypass the memory encryption flows in the memory subsystem/controller. You can read a bit more about it at this link: Performance Considerations: Intel® Trust Domain Extensions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you very much for your response. Our application scenario is as follows:
- User A will deploy their Intel server (which supports Intel TME) in User B's local area network data center.
- User A will deploy an application developed by A (such as a web service) on the server, and User A will deploy their data and code on the Intel server in B's data center.
- User A will only provide B with an HTTPS interface, and User A will independently maintain the Intel server, with only A having login access.
- Based on the above description, A wishes to use the Intel TME mechanism to encrypt memory to defend against physical attacks (such as cold boot attacks and memory dump attacks) from B's data center (e.g., by B's data center personnel).
- A wants to enable TME directly in the BIOS (without needing TDX or TME-MK), so that A does not need to make any modifications to the system software (Linux kernel) or application software.
Therefore, the question in this scenario is that we only need Intel TME, so Intel TME bypass must be configured as disabled to ensure the security of A's data, correct?

- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page