743844-015.pdf - 第40页

• Enable SMM code execution r ange checking • Select whether SMM Save State is to be written to legacy SMRAM or to MSRs • Determine if a thread is going to be delayed entering SMM • Determine if a thread is blocked from …

100%1 / 224
The guest paging structure managed by the guest OS specifies the ordinary
translation of a guest linear address to the guest physical address and attributes that
the guest ring-0 software has programmed, whereas HLAT specifies the alternate
translation of the guest linear address to guest physical address and attributes that
the Secure Kernel and VMM seek to enforce. A logical processor uses HLAT to translate
guest linear addresses only when those guest linear addresses are used to access
memory (both for code fetch and data load/store) and the guest linear addresses
match the PLR programmed by the VMM/Secure Kernel.
HLAT specifications and functional descriptions are included in the Intel
®
Architecture
Instruction Set Extensions Programming Reference. Available at:
https://software.intel.com/en-us/download/intel-architecture-instruction-set-
extensions-programming-reference
Security Technologies
Intel
®
Trusted Execution Technology
Intel
®
Trusted Execution Technology (Intel
®
TXT) defines platform-level
enhancements that provide the building blocks for creating trusted platforms.
The Intel
®
TXT platform helps to provide the authenticity of the controlling
environment such that those wishing to rely on the platform can make an appropriate
trust decision. The Intel
®
TXT platform determines the identity of the controlling
environment by accurately measuring and verifying the controlling software.
Another aspect of the trust decision is the ability of the platform to resist attempts to
change the controlling environment. The Intel
®
TXT platform will resist attempts by
software processes to change the controlling environment or bypass the bounds set by
the controlling environment.
Intel
®
TXT is a set of extensions designed to provide a measured and controlled
launch of system software that will then establish a protected environment for itself
and any additional software that it may execute.
These extensions enhance two areas:
The launching of the Measured Launched Environment (MLE).
The protection of the MLE from potential corruption.
The enhanced platform provides these launch and control interfaces using Safer Mode
Extensions (SMX).
The SMX interface includes the following functions:
Measured/Verified launch of the MLE.
Mechanisms to ensure the above measurement is protected and stored in a secure
location.
Protection mechanisms that allow the MLE to control attempts to modify itself.
The processor also offers additional enhancements to System Management Mode
(SMM) architecture for enhanced security and performance. The processor provides
new MSRs to:
Enable a second SMM range
2.3
2.3.1
R
Technologies—Intel
®
Core
, Xeon
6300 And Xeon
E 2400 Processors
13
th
Generation Intel
®
Core
, Intel
®
Core
14
th
Generation, Intel
®
Core
Processor (Series 1) and (Series 2), Intel
®
Xeon
E
2400 Processor and Intel
®
Xeon
6300 Processor
May 2025 Datasheet, Volume 1 of 2
Doc. No.: 743844, Rev.: 015 39
Enable SMM code execution range checking
Select whether SMM Save State is to be written to legacy SMRAM or to MSRs
Determine if a thread is going to be delayed entering SMM
Determine if a thread is blocked from entering SMM
Targeted SMI, enable/disable threads from responding to SMIs, both VLWs, and
IPI
For the above features, BIOS should test the associated capability bit before
attempting to access any of the above registers. The capability bits are discussed in
the register description.
For more information, refer to the Intel
®
Trusted Execution Technology Measured
Launched Environment Programming Guide at:
http://www.intel.com/content/www/us/en/software-developers/intel-txt-software-
development-guide.html.
NOTE
Intel
®
TXT Technology may not be available on all SKUs.
Intel
®
Advanced Encryption Standard New Instructions
The processor supports Intel
®
Advanced Encryption Standard New Instructions (Intel
®
AES-NI) that are a set of Single Instruction Multiple Data (SIMD) instructions that
enable fast and secure data encryption and decryption based on the Advanced
Encryption Standard (AES). Intel
®
AES-NI is valuable for a wide range of
cryptographic applications, such as applications that perform bulk encryption/
decryption, authentication, random number generation, and authenticated encryption.
AES is broadly accepted as the standard for both government and industrial
applications and is widely deployed in various protocols.
Intel
®
AES-NI consists of six Intel
®
SSE instructions. Four instructions, AESENC,
AESENCLAST, AESDEC, and AESDELAST facilitate high-performance AES encryption
and decryption. The other two, AESIMC and AESKEYGENASSIST, support the AES key
expansion procedure. Together, these instructions provide full hardware for supporting
AES; offering security, high performance, and a great deal of flexibility.
This generation of the processor has increased the performance of the Intel
®
AES-NI
significantly compared to previous products.
The Intel
®
AES-NI specifications and functional descriptions are included in the Intel
®
64 Architectures Software Developer’s Manual, Volume 2. Available at:
http://www.intel.com/products/processor/manuals
NOTE
Intel
®
AES-NI Technology may not be available on all SKUs.
2.3.2
R
Intel
®
Core
, Xeon
6300 And Xeon
E 2400 Processors—Technologies
13
th
Generation Intel
®
Core
, Intel
®
Core
14
th
Generation, Intel
®
Core
Processor (Series 1) and (Series 2), Intel
®
Xeon
E
2400 Processor and Intel
®
Xeon
6300 Processor
Datasheet, Volume 1 of 2 May 2025
40 Doc. No.: 743844, Rev.: 015
Perform Carry-Less Multiplication Quad Word Instruction
The processor supports the carry-less multiplication instruction, ie, Perform Carry-Less
Multiplication Quad Word Instruction (PCLMULQDQ). PCLMULQDQ is a Single
Instruction Multiple Data (SIMD) instruction that computes the 128-bit carry-less
multiplication of two 64-bit operands without generating and propagating carries.
Carry-less multiplication is an essential processing component of several cryptographic
systems and standards. Hence, accelerating carry-less multiplication can significantly
contribute to achieving high-speed secure computing and communication.
PCLMULQDQ specifications and functional descriptions are included in the Intel
®
64
Architectures Software Developer’s Manual, Volume 2. Available at:
http://www.intel.com/products/processor/manuals
Intel
®
Secure Key
The processor supports Intel
®
Secure Key (formerly known as Digital Random Number
Generator or DRNG), a software visible random number generation mechanism
supported by a high-quality entropy source. This capability is available to
programmers through the RDRAND instruction. The resultant random number
generation capability is designed to comply with existing industry standards in this
regard (ANSI X9.82 and NIST SP 800-90).
Some possible usages of the RDRAND instruction include cryptographic key generation
as used in a variety of applications, including communication, digital signatures,
secure storage, etc.
RDRAND specifications and functional descriptions are included in the Intel
®
64
Architectures Software Developer’s Manual, Volume 2. Available at:
http://www.intel.com/products/processor/manuals
Execute Disable Bit
The Execute Disable Bit allows memory to be marked as non-executable when
combined with a supporting operating system. If code attempts to run in non-
executable memory, the processor raises an error to the operating system. This
feature can prevent some classes of viruses or worms that exploit buffer overrun
vulnerabilities and can, thus, help improve the overall security of the system.
Boot Guard Technology
Boot Guard technology is a part of boot integrity protection technology. Boot Guard
can help protect the platform boot integrity by preventing the execution of
unauthorized boot blocks. With Boot Guard, platform manufacturers can create boot
policies such that invocation of an unauthorized (or untrusted) boot block will trigger
the platform protection per the manufacturer's defined policy.
With verification based in the hardware, Boot Guard extends the trust boundary of the
platform boot process down to the hardware level.
Boot Guard accomplishes this by:
Providing of hardware-based Static Root of Trust for Measurement (S-RTM) and
the Root of Trust for Verification (RTV) using Intel architectural components.
2.3.3
2.3.4
2.3.5
2.3.6
R
Technologies—Intel
®
Core
, Xeon
6300 And Xeon
E 2400 Processors
13
th
Generation Intel
®
Core
, Intel
®
Core
14
th
Generation, Intel
®
Core
Processor (Series 1) and (Series 2), Intel
®
Xeon
E
2400 Processor and Intel
®
Xeon
6300 Processor
May 2025 Datasheet, Volume 1 of 2
Doc. No.: 743844, Rev.: 015 41