743844-015.pdf - 第42页
• Providing of architectural definition for platform manufacturer Boot P olicy . • Enforcing manufacturer provided Boot P olicy using Intel architectural components. Benefits of this protection are that Boot Guard can he…

Perform Carry-Less Multiplication Quad Word Instruction
The processor supports the carry-less multiplication instruction, ie, Perform Carry-Less
Multiplication Quad Word Instruction (PCLMULQDQ). PCLMULQDQ is a Single
Instruction Multiple Data (SIMD) instruction that computes the 128-bit carry-less
multiplication of two 64-bit operands without generating and propagating carries.
Carry-less multiplication is an essential processing component of several cryptographic
systems and standards. Hence, accelerating carry-less multiplication can significantly
contribute to achieving high-speed secure computing and communication.
PCLMULQDQ specifications and functional descriptions are included in the Intel
®
64
Architectures Software Developer’s Manual, Volume 2. Available at:
http://www.intel.com/products/processor/manuals
Intel
®
Secure Key
The processor supports Intel
®
Secure Key (formerly known as Digital Random Number
Generator or DRNG), a software visible random number generation mechanism
supported by a high-quality entropy source. This capability is available to
programmers through the RDRAND instruction. The resultant random number
generation capability is designed to comply with existing industry standards in this
regard (ANSI X9.82 and NIST SP 800-90).
Some possible usages of the RDRAND instruction include cryptographic key generation
as used in a variety of applications, including communication, digital signatures,
secure storage, etc.
RDRAND specifications and functional descriptions are included in the Intel
®
64
Architectures Software Developer’s Manual, Volume 2. Available at:
http://www.intel.com/products/processor/manuals
Execute Disable Bit
The Execute Disable Bit allows memory to be marked as non-executable when
combined with a supporting operating system. If code attempts to run in non-
executable memory, the processor raises an error to the operating system. This
feature can prevent some classes of viruses or worms that exploit buffer overrun
vulnerabilities and can, thus, help improve the overall security of the system.
Boot Guard Technology
Boot Guard technology is a part of boot integrity protection technology. Boot Guard
can help protect the platform boot integrity by preventing the execution of
unauthorized boot blocks. With Boot Guard, platform manufacturers can create boot
policies such that invocation of an unauthorized (or untrusted) boot block will trigger
the platform protection per the manufacturer's defined policy.
With verification based in the hardware, Boot Guard extends the trust boundary of the
platform boot process down to the hardware level.
Boot Guard accomplishes this by:
• Providing of hardware-based Static Root of Trust for Measurement (S-RTM) and
the Root of Trust for Verification (RTV) using Intel architectural components.
2.3.3
2.3.4
2.3.5
2.3.6
R
Technologies—Intel
®
Core
™
, Xeon
™
6300 And Xeon
™
E 2400 Processors
13
th
Generation Intel
®
Core
™
, Intel
®
Core
™
14
th
Generation, Intel
®
Core
™
Processor (Series 1) and (Series 2), Intel
®
Xeon
™
E
2400 Processor and Intel
®
Xeon
™
6300 Processor
May 2025 Datasheet, Volume 1 of 2
Doc. No.: 743844, Rev.: 015 41

• Providing of architectural definition for platform manufacturer Boot Policy.
• Enforcing manufacturer provided Boot Policy using Intel architectural components.
Benefits of this protection are that Boot Guard can help maintain platform integrity by
preventing re-purposing of the manufacturer’s hardware to run an unauthorized
software stack.
NOTE
Boot Guard availability may vary between the different SKUs.
Intel
®
Supervisor Mode Execution Protection
Intel
®
Supervisor Mode Execution Protection (Intel
®
SMEP) is a mechanism that
provides the next level of system protection by blocking malicious software attacks
from user mode code when the system is running in the highest privilege level. This
technology helps to protect from virus attacks and unwanted code from harming the
system. For more information, refer to Intel
®
64 Architectures Software Developer’s
Manual, Volume 3 at:
http://www.intel.com/products/processor/manuals
Intel
®
Supervisor Mode Access Protection
Intel
®
Supervisor Mode Access Protection (Intel
®
SMAP) is a mechanism that provides
next level of system protection by blocking a malicious user from tricking the
operating system into branching off user data. This technology shuts down very
popular attack vectors against operating systems.
For more information, refer to the Intel
®
64 Architectures Software Developer’s
Manual, Volume 3:
http://www.intel.com/products/processor/manuals
Intel
®
Secure Hash Algorithm Extensions
The Intel
®
Secure Hash Algorithm Extensions (Intel
®
SHA Extensions) is one of the
most commonly employed cryptographic algorithms. Primary usages of SHA include
data integrity, message authentication, digital signatures, and data de-duplication. As
the pervasive use of security solutions continues to grow, SHA can be seen in more
applications now than ever. The Intel
®
SHA Extensions are designed to improve the
performance of these compute-intensive algorithms on Intel
®
architecture-based
processors.
The Intel
®
SHA Extensions are a family of seven instructions based on the Intel
®
Streaming SIMD Extensions (Intel
®
SSE) that are used together to accelerate the
performance of processing SHA-1 and SHA-256 on Intel architecture-based
processors. Given the growing importance of SHA in our everyday computing devices,
the new instructions are designed to provide a needed boost of performance to
hashing a single buffer of data. The performance benefits will not only help improve
responsiveness and lower power consumption for a given application, but they may
also enable developers to adopt SHA in new applications to protect data while
delivering to their user experience goals. The instructions are defined in a way that
simplifies their mapping into the algorithm processing flow of most software libraries,
thus enabling easier development.
2.3.7
2.3.8
2.3.9
R
Intel
®
Core
™
, Xeon
™
6300 And Xeon
™
E 2400 Processors—Technologies
13
th
Generation Intel
®
Core
™
, Intel
®
Core
™
14
th
Generation, Intel
®
Core
™
Processor (Series 1) and (Series 2), Intel
®
Xeon
™
E
2400 Processor and Intel
®
Xeon
™
6300 Processor
Datasheet, Volume 1 of 2 May 2025
42 Doc. No.: 743844, Rev.: 015

More information on Intel
®
SHA can be found at:
http://software.intel.com/en-us/artTGLes/intel-sha-extensions
User Mode Instruction Prevention
User Mode Instruction Prevention (UMIP) provides additional hardening capability to
the OS kernel by allowing certain instructions to execute only in supervisor mode
(Ring 0).
If the OS opt-in to use UMIP, the following instruction are enforced to run in supervisor
mode:
• SGDT - Store the GDTR register value
• SIDT - Store the IDTR register value
• SLDT - Store the LDTR register value
• SMSW - Store Machine Status Word
• STR - Store the TR register value
An attempt at such execution in user mode causes a general protection exception
(#GP).
UMIP specifications and functional descriptions are included in the Intel
®
64
Architectures Software Developer’s Manual, Volume 3. Available at:
http://www.intel.com/products/processor/manuals
Read Processor ID
A companion instruction that returns the current logical processor's ID and provides a
faster alternative to using the RDTSCP instruction.
Read Processor ID (RDPID) specifications and functional descriptions are included in
the Intel
®
64 Architectures Software Developer’s Manual, Volume 2. Available at:
http://www.intel.com/products/processor/manuals
Intel
®
Total Memory Encryption - Multi-Key
This technology encrypts the platform's entire memory with multiple encryption keys.
Intel
®
Total Memory Encryption (Intel
®
TME), when enabled via BIOS configuration,
ensures that all memory accessed from the Intel processor is encrypted.
Intel TME encrypts memory accesses using the AES XTS algorithm with 128-bit keys.
The global encryption key used for memory encryption is generated using a hardened
random number generator in the processor and is not exposed to software.
Software (OS/VMM) manages the use of keys and can use each of the available keys
for encrypting any page of the memory. Thus, Intel
®
Total Memory Encryption - Multi-
key (Intel
®
TME-MK) allows page granular encryption of memory. By default Intel
TME-MK uses the Intel TME encryption key unless explicitly specified by software.
2.3.10
2.3.11
2.3.12
R
Technologies—Intel
®
Core
™
, Xeon
™
6300 And Xeon
™
E 2400 Processors
13
th
Generation Intel
®
Core
™
, Intel
®
Core
™
14
th
Generation, Intel
®
Core
™
Processor (Series 1) and (Series 2), Intel
®
Xeon
™
E
2400 Processor and Intel
®
Xeon
™
6300 Processor
May 2025 Datasheet, Volume 1 of 2
Doc. No.: 743844, Rev.: 015 43