Intel is finally improving its CPU security
Taking a page from AMD, future Intel processors will offer full memory encryption to keep prying eyes away from sensitive data.
Keep up to date with the most important stories and the best deals, as picked by the PC Gamer team.
You are now subscribed
Your newsletter sign-up was successful
Want to add more newsletters?
Every Friday
GamesRadar+
Your weekly update on everything you could ever want to know about the games you already love, games we know you're going to love in the near future, and tales from the communities that surround them.
Every Thursday
GTA 6 O'clock
Our special GTA 6 newsletter, with breaking news, insider info, and rumor analysis from the award-winning GTA 6 O'clock experts.
Every Friday
Knowledge
From the creators of Edge: A weekly videogame industry newsletter with analysis from expert writers, guidance from professionals, and insight into what's on the horizon.
Every Thursday
The Setup
Hardware nerds unite, sign up to our free tech newsletter for a weekly digest of the hottest new tech, the latest gadgets on the test bench, and much more.
Every Wednesday
Switch 2 Spotlight
Sign up to our new Switch 2 newsletter, where we bring you the latest talking points on Nintendo's new console each week, bring you up to date on the news, and recommend what games to play.
Every Saturday
The Watchlist
Subscribe for a weekly digest of the movie and TV news that matters, direct to your inbox. From first-look trailers, interviews, reviews and explainers, we've got you covered.
Once a month
SFX
Get sneak previews, exclusive competitions and details of special events each month!
Intel is promising to bring full memory encryption to it processors, a revelation it made at the company's Security Day event this week. The feature is similar to what AMD already offers on its CPUs, though it won't necessarily make Intel's chips less susceptible to side-channel attacks similar to Spectre and Meltdown.
Those kinds of exploits leverage vulnerabilities in various techniques employed by processors, including out-of-order execution (OOOE), branch prediction, and speculative execution, all of which are designed to improve performance. We posted an in-depth guide on what you need to know about Meltdown and Spectre CPU exploits, and you should check it out if you haven't already.
Memory encryption can help with those kinds of attacks, but as pointed out by our friends at Tom's Hardware, researchers have warned (PDF) that it is not enough to completely thwart side-channel attacks. However, it's not without its benefits.
One way Intel protects its chips from attacks is through a feature called Software Guard eXtensions (SGX). Available in both enterprise and consumer processors, SGX is a hardware encryption technology that acts as a "secure enclave" within a memory section, but only for small amounts of data.
Arstechnica offers a thorough rundown of the technical details, but in short, SGX has some limitations—it can only run on Intel processors, developers have to design their applications to specifically leverage SGX, and developers must also choose which parts of data are marked "confidential" since they have to work with a memory limit of just 128MB.
In contrast, AMD's Secure Memory Encryption (SME) and Secure Encrypted Virtualization (SEV) features are more flexible. All system RAM can be encrypted with SME, without any special considerations imposed on application developers. And not only is AMD's implementation more flexible than SGX, the performance impact is smaller, too.
Intel is looking to rectify this with a pair of features called Total Memory Encryption (TME) and Multi-Key Total Memory Encryption (MKTME). TME and MKTME do not exist in actual CPU hardware yet, but will at some point, according to Intel.
Keep up to date with the most important stories and the best deals, as picked by the PC Gamer team.
While not specifically mentioned at the Security Day event, this is about bringing parity to AMD's processors, and perhaps even surpassing AMD's method of protecting memory. When these arrive, they will support encrypting regular memory, volatile DRAM, and persistent/non-volatile memory such as 3D Xpoint.
It's too early to tell what this will mean for consumers, and it doesn't sound like it will be available with imminent CPU launches, such as Comet Lake. It's definitely something we'll be keeping our eyes on, though.
Paul has been playing PC games and raking his knuckles on computer hardware since the Commodore 64. He does not have any tattoos, but thinks it would be cool to get one that reads LOAD"*",8,1. In his off time, he rides motorcycles and wrestles alligators (only one of those is true).


