4 ms·
> Why don't AMD and Intel want to monetise their management features? They do, most machines don't have remote management firmware and chipset features install
by qb45 9y ago
> Why don't AMD and Intel want to monetise their management features?
They do, most machines don't have remote management firmware and chipset features installed.
As for why the ME is present on all hardware - it would be a shame if your consumer CPU couldn't securely decode super-4K-full-ultra-HD videos, right?
Besides DRM, I think the ME is also used for SGX.
Intel(R) Software Guard Extensions (Intel(R) SGX) is an Intel technology for application developers seeking to protect select code and data from disclosure or modification.
Maybe Intel wants to create some "ecosystem" of software utilizing SGX (because vendor lock in) and for that they want as large hardware base as possible. That's just a guess, I haven't read Intel docs and IDK if any off-the-shelf SGX software exists yet, but I have seen similar ideas in some AMD PSP PDFs.
edit:
FWIW, Intel Wikivertisement on SGX:
The introduction of SGX has a large impact on the security industry. It shifts how security is being achieved and lowers the attack surface area of projects. One example of SGX used in security was a demo application from wolfSSL using it for cryptography algorithms. One example of a secure service built using SGX is Fortanix's key management service. This entire cloud based service is built using SGX servers and designed to provide privacy from cloud provider. An additional example is Numecent using SGX to protect the DRM that is used to authorize application execution with their Cloudpaging application delivery products.
The last one seems like something that could benefit from SGX on end-user devices: https://www.numecent.com/cloudpaging/ https://www.numecent.com/cloudpaging/
- wahern 9y agoAFAIU SGX has nothing to do with the ME. It's entirely in the CPU and MMU. SGX is more like ARM's TrustZone, except it can be utilized by multiple, independent pieces of unprivileged code. SGX is pretty slick. The only real problem is that 1) Intel has done a horrible job of educating developers, 2) Intel's PKI scheme for remotely verifying authenticity of an enclave (e.g. for DRM schemes) requires huge on-going license payments to Intel, and 3) they don't seem keen on rolling it out across their entire processor line-up. All three cases have been and will continue to be serious impediments to uptake because of the confusion they create. Those impediments are likely to keep SGX niche and underutilized.
- qb45 9y agoThanks, it seems you are right. I thought that the ME plays some role in SGX setup but I can't find a single source for that now. Apparently it's all done with special instructions implemented in microcode.