Intel Trusted Platforms Overview



Similar documents
Solution Recipe: Improve PC Security and Reliability with Intel Virtualization Technology

Intel Cyber Security Briefing: Trends, Solutions, and Opportunities. Matthew Rosenquist, Cyber Security Strategist, Intel Corp

Solution Recipe: Remote PC Management Made Simple with Intel vpro Technology and Intel Active Management Technology

Dell Client. Take Control of Your Environment. Powered by Intel Core 2 processor with vpro technology

Intel Management Engine BIOS Extension (Intel MEBX) User s Guide

Intel Virtualization Technology (VT) in Converged Application Platforms

HP Compaq dc7800p Business PC with Intel vpro Processor Technology and Virtual Appliances

PC Solutions That Mean Business

Intel Cyber-Security Briefing: Trends, Solutions, and Opportunities

Intel Embedded Virtualization Manager

Intel Active Management Technology Embedded Host-based Configuration in Intelligent Systems

What is a Managed Service Provider (MSP)? What is the best solution for an MSP?

Intel Identity Protection Technology Enabling improved user-friendly strong authentication in VASCO's latest generation solutions

Intel Ethernet Switch Load Balancing System Design Using Advanced Features in Intel Ethernet Switch Family

Intel Active Management Technology with System Defense Feature Quick Start Guide

vpro Prerequisites and Trade-offs for the dc7700 Business PC with Intel vpro Technology

Citrix and Intel Deliver Client Virtualization

Hybrid Virtualization The Next Generation of XenLinux

Intel Identity Protection Technology (IPT)

Realizing the Value of Intel vpro processor technology within Altiris Client Management Suite

Intel vpro. Technology-based PCs SETUP & CONFIGURATION GUIDE FOR

Intel Centrino 2 with vpro Technology and Intel Core 2 Processor with vpro Technology

ASF: Standards-based Systems Management. Providing remote access and manageability in OS-absent environments

Vendor Update Intel 49 th IDC HPC User Forum. Mike Lafferty HPC Marketing Intel Americas Corp.

Intel vpro Technology Module for Microsoft* Windows PowerShell*

Hardware + Software Solutions for The Best in Client Management & Security. Malcolm Hay Intel Technology Manager

Intel vpro Technology. How To Purchase and Install Symantec* Certificates for Intel AMT Remote Setup and Configuration

Intel Cloud Builders Guide: Cloud Design and Deployment on Intel Platforms

Intel vpro Provisioning

Q A F 0 3. ger A n A m client dell dell client manager 3.0 FAQ

Running Windows 8 on top of Android with KVM. 21 October Zhi Wang, Jun Nakajima, Jack Ren

Intel vpro Technology. Common-Use Guide. For the Kaseya IT Automation Platform* Introduction

Intel Cyber-Security Briefing: Trends, Solutions, and Opportunities. John Skinner, Director, Secure Enterprise and Cloud, Intel Americas, Inc.

新 一 代 軟 體 定 義 的 網 路 架 構 Software Defined Networking (SDN) and Network Function Virtualization (NFV)

McAfee epolicy Orchestrator * Deep Command *

How To Get A Client Side Virtualization Solution For Your Financial Services Business

Nested Virtualization

Intel Desktop Board DG965RY

Asset Tracking Inventory use case

Intel Virtualization Technology FlexMigration Application Note

Getting Ahead of Malware

A M D DA S 1. 0 For the Manageability, Virtualization and Security of Embedded Solutions

Intel Active Management Technology For Embedded Systems. Intel Embedded and Communications Group

Managing Digital Signage Over 3G Using Intel Active Management Technology (Intel AMT)

Configuring and Using AMT on TS140 and TS440

Intel Service Assurance Administrator. Product Overview

Intel vpro Technology. How To Purchase and Install Go Daddy* Certificates for Intel AMT Remote Setup and Configuration

System Image Recovery* Training Foils

with PKI Use Case Guide

Cloud based Holdfast Electronic Sports Game Platform

System Area Manager. Remote Management

A Superior Hardware Platform for Server Virtualization

Out-of-Band Management Reference

Intel Remote Configuration Certificate Utility Frequently Asked Questions

CLOUD SECURITY: Secure Your Infrastructure

Client Manageability. Out-of-Band Management with DMTF DASH. Valerie K. Kane Commercial Client Product Group, AMD

Intel Management and Security Status Application

Keep Data Secure with Intelligent Client-Side Protection for Lost or Stolen Laptops

COLO: COarse-grain LOck-stepping Virtual Machine for Non-stop Service

Proven LANDesk Solutions

Intel Identity Protection Technology with PKI (Intel IPT with PKI)

Intel Ethernet and Configuring Single Root I/O Virtualization (SR-IOV) on Microsoft* Windows* Server 2012 Hyper-V. Technical Brief v1.

Intel Matrix Storage Console

Intel Data Direct I/O Technology (Intel DDIO): A Primer >

Intel Desktop Board D975XBX2

Intel Cloud Builder Guide: Cloud Design and Deployment on Intel Platforms

LANDesk White Paper. LANDesk Management Suite for Lenovo Secure Managed Client

Windows Server Virtualization & The Windows Hypervisor

Intel System Event Log (SEL) Viewer Utility

COLO: COarse-grain LOck-stepping Virtual Machine for Non-stop Service. Eddie Dong, Tao Hong, Xiaowei Yang

Life With Big Data and the Internet of Things

Intel Desktop Board DQ35JO

Intel Network Builders: Lanner and Intel Building the Best Network Security Platforms

Windows 7 XP Mode for HP Business PCs

Intel Data Center Manager. Data center IT agility and control

How to Configure Intel X520 Ethernet Server Adapter Based Virtual Functions on Citrix* XenServer 6.0*

Intel Desktop Board D945GCPE Specification Update

Intel Media SDK Library Distribution and Dispatching Process

Intel RAID Volume Recovery Procedures

Isaku Yamahata CloudOpen Japan May 22, 2014

Intel Desktop Board DG41WV

Intel Desktop Board D925XECV2 Specification Update

Accelerating High-Speed Networking with Intel I/O Acceleration Technology

SyAM Software* Server Monitor Local/Central* on a Microsoft* Windows* Operating System

Intel Cloud Builder Guide to Cloud Design and Deployment on Intel Xeon Processor-based Platforms

HP Client Manager 6.2

Intel Desktop Board D945GCPE

Enabling Deskside Manageability and Productivity. The CompuCom EUC Workbench Powered by Intel vpro Technology

How to Configure Intel Ethernet Converged Network Adapter-Enabled Virtual Functions on VMware* ESXi* 5.1

Intel Virtualization Technology Overview Yu Ke

Intel Desktop Board DG41BI

Intel Server Board S3420GPRX Intel Server System SR1630GPRX Intel Server System SR1630HGPRX

Intel Desktop Board DG43RK

Creating Overlay Networks Using Intel Ethernet Converged Network Adapters

Transcription:

Intel Trusted Platforms Overview Greg Clifton Intel Customer Solutions Group Director, DoD & Intelligence 2006 Intel Corporation

Legal Disclaimer INFORMATION IN THIS DOCUMENT IS PROVIDED IN CONNECTION WITH INTEL PRODUCTS. NO LICENSE, EXPRESS OR IMPLIED, BY ESTOPPEL OR OTHERWISE, TO ANY INTELLECTUAL PROPERTY RIGHTS IS GRANTED BY THIS DOCUMENT. EXCEPT AS PROVIDED IN INTEL S S TERMS AND CONDITIONS OF SALE FOR SUCH PRODUCTS, INTEL ASSUMES NO LIABILITY WHATSOEVER, AND INTEL DISCLAIMS ANY EXPRESS OR IMPLIED WARRANTY, RELATING TO SALE AND/OR USE OF INTEL PRODUCTS INCLUDING LIABILITY OR WARRANTIES RELATING TO FITNESS FOR A PARTICULAR PURPOSE, MERCHANTABILITY, OR INFRINGEMENT OF ANY PATENT, COPYRIGHT OR OTHER INTELLECTUAL PROPERTY RIGHT. INTEL PRODUCTS ARE NOT INTENDED ED FOR USE IN MEDICAL, LIFE SAVING, OR LIFE SUSTAINING APPLICATIONS. Intel may make changes to specifications and product descriptions s at any time, without notice. All products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. Intel, processors, chipsets, and desktop boards may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request. Intel and the Intel logo are trademarks or registered trademarks of Intel Corporation or its subsidiaries in the United States and other countries. *Other names and brands may be claimed as the property of others. Copyright 2006 Intel Corporation. Intel and the Intel logo are trademarks or registered trademarks of Intel Corporation or its subsidiaries in the United States and other countries. 2

Intel Platforms Business Desktop Digital Home Mobility Server Built-in in Manageability Proactive Security Energy Efficient Performance Performance Energy Efficient Connectivity Ease of Use Performance Battery Life Uncompromised Connectivity Innovative Form Factor Effective Virtualization Optimized Power & Thermals Reliable Data Intensive Computing Agenda: It is an imperfect world Building the foundation in 2006 The 2007 Weybridge Platform Solving the problems with Intel vpro technology Conclusions Energy Efficient Performance 3

Today s s Challenges Managing and Securing modern business clients is more challenging than ever Zero day malicious exploits create scenarios that patching alone can t t resolve Layered security improves platform protection capabilities Optimized platform architecture removes bottlenecks, but also introduces complexity Damaged software or hardware can impair the ability to remotely repair a client Client PCs are not manageable when they need it most, i.e. HW or SW problem or turned off. 1.Desk Desk-side side visits & manual processes drive disproportionate share of IT costs Intel IT: ~10-15% 15% of help desk calls require desk-side side visit, but drive ~50% of help desk costs 2. Security threats increasing, time to respond decreasing but protections vulnerable to attack or user tampering Time to exploit = 3 days; Time to vendor patch = 42 days single technology solves all of these problems!! 4

Intel s s Platform Solution Utilize a set of technologies that work together to: Enable innovative solutions to solve these problems Create a new framework for a rich layered security architecture 5

Evolving Intel vpro in 2007 Weybridge Intel Core TM 2 Duo Wolfdale CPU Bearlake Support Family Chipsets Intel Trusted Execution Technology Windows Vista* Premium Logo Intel Active Management Technology 3.0 2007 Weybridge Platform esata*, Expanded USB*, Intel Rapid Recovery Technology Enhanced Virtualization (VTd) *Other names and brands may be claimed as the property of others 6 Low Power Reduced Chipset & Platform Power te: Certain features may be available only on particular SKUs

Intel Virtualization Technology Traditional Virtualization Virtual Appliance Model Virtual Machine 1 Virtual Machine 2 Virtual Machine 3 App App App App App App User OS 1 User OS 2 User OS 3 User Environment App App App User OS Virtual Appliance App Embedded OS Heavyweight Virtual Virtual Machine Machine Monitor Monitor Hardware Hardware Platform Platform Full OS Partitions Full OS capability Multiple applications Full HW suite available Generally virtualized devices Maximum features and capability agility Lightweight VMM Hardware Hardware Platform Platform Virtual Appliance Partitions Generally headless Fixed/specific function Low OS profile Minimal management cost Minimal platform resource utilization Minimal true/virtual HW mapped OS state/power independent Make Virtualization Applicable to Mainstream 7

VT-d d Direct I/O Overview Virtual Machines Physical driver Virtual Machine Monitor (VMM) DMA Remap Assigned IO Devices Phys Mem Software remapping for CPU based memory access Bearlake Family Chipsets (VT-d a chipset technology) 8 (VT-x a CPU technology)

VT-d d : DMA based Protection and Remapping for Virtual Appliances Capability Partition Host OS and Apps Virtual Device Driver Virtual Machine Monitor (VMM) Host HW I/O devices assigned to host OS Virtual Appliance Appliance Stack I/O Virtualization Physical Device Driver I/O devices assigned to service OS VT-d enables Flexible memory management by VMM Un-modified device drivers to run in both partitions Contain DMA errors across partitions Allows enforcement of independent security policies for each partition 9

Intel Trusted Execution Technology Introduced on Weybridge for Increased Security Codename LT extends Intel VT capabilities of partitions and isolation to increase security using Measured launch and a chain of trust to generate a secure partition Trusted Platform Module (TPM) for Secure Storage of measurements and Signed reporting VM 1 App App User OS App VM 0 Firewall App Mgmt App Service OS Lightweight VMM Platform Hardware 10

Intel Active Management Technology Overview Provides Built-in in Manageability and Proactive Security for networked computing resources Enables maintenance and repair of systems using out-of of- band (OOB) management capabilities even if the system is powered off or the OS is down Helps secure networks by: Proactively blocking incoming threats Reactively containing the spread of threats Ensuring critical software agents are present Keeping installed software versions up to date Enabling popular third-party management consoles and security applications in use today 1 Intel Active Management Technology requires the platform to have an Intel AMT-enabled chipset, network hardware and software, connection with a power source, and a network connection. 11

Intel AMT 06 Architecture Overview Discover Enhanced non-volatile memory storage Out of Band access Heal Provisioning & remote control Hardware Diagnostics Protect System Defense: Filtering features Capability to allow, disallow, rate-limit packets based on 5-tuple 5 IP Protocol Filter Filters programmed by remote console Filtering in hardware for LAN Agent Presence info info Operating Help System Desk Server Corporate Network Intel PRO/1000 LAN Operating System* Operating System* SW Agents Intel Q965 Express Chipset Core 2 Duo (G)MCH ICH8-DO DDR2* DDR2* FLASH Management Console 12

Intel Active Management Technology Major Intel AMT Components OOB Communication, Management Engine, nvolatile Memory Operating System SW Diagnostics/Agents/Applications Network Driver Management Engine Driver System Defense Management Engine FLASH BIOS LAN Controller ME Services NV Memory Intel AMT Firmware Intel AMT Private OOB Comms Filter TCP/IP SOAP TLS Confidentiality HTTP Authorization Intel AMT Public PHY HW Sensors & AFSC = Out-of-band; Active even when System is turned off or OS is down = In Band Go 13

Intel Active Management Technology Usage Cases Remote Asset Inventory Hardware and Software Inventory Remote Diagnostics and Repair Encrypted, Remote Power-on and Update Agent Presence Checking Hardware-based Isolation and Recovery 14

Intel AMT Core Attributes Advantage over S/W Solutions OS and HDD-Independent Runs outside the context of the OS Works the same way regardless of the installed OS Immune from OS configuration issues Highly-Available OOB Remote Management Provides remote management capabilities in all system power and health states Runs on auxiliary and battery power (mobile) Wired and wireless network support (2007) Tamper-Resistance Intel AMT agent bound to the PC and configured by IT Resistant to end-user modify/disable Network and Host I/F Security 15

Intel AMT Capabilities Intel AMT Capabilities Advantage over H/W (WoL & ASF) Solutions Capabilities OOB Mgt (Any OS/power state) Remote Control Event Alerting 3 rd Party n-volatile Storage Event Logging Remote Reboot Asset Information Remote BIOS Update Secure Communications Connection Protocol Layer 4 Stack Firmware Updates Utility System Defense / Agent Presence System Defense /NOC Filters WoL Booting Only Remote Boot Only ne Registered packet 16 ASF 2.0 Boot/reboot and alerts Remote Boot/Reboot w/boot options Yes (1 Client, no filtering) Yes (PXE) Simple authentication - no encryption RMCP UDP Intel AMT Boot/reboot, alerts, event log, and remote control, redirection Remote boot/reboot w/ boot options, Serial Over LAN, IDE redirection Yes (Broadcast to 16 clients, filter only desired events) Yes Yes, including filters Yes (PXE or IDE- Redirect) Yes Yes SSL 3.1/TLS encryption, HTTP Digest/Negotiate authentication SOAP/HTTP (web browser access) TCP (preferred routing protocol) Yes Yes Yes

Conclusion Solving yesterday s s problems with enhancements to yesterday s s solutions is not sufficient to address the challenges of tomorrow We are well underway to redefining the PC Radical new hardware that enables distinct technologies that work together being launched in 2006 and 2007 New class of solutions that solve problems in new ways are starting to emerge Barriers to innovation are being cleared for ISVs This is just the beginning new innovations to come for the 2008 platform and beyond stay tuned 17

18

Intel Virtualization Technology Mode Transitions VM entry (VMLAUNCH/VMRESUME) Transition VMM Guest Enters VMX non-root operation Loads Guest state and Exit criteria from VMCS VM exit (VMEXIT) Transition Guest VMM Enters VMX root operation Saves Guest state in VMCS Loads VMM state from VMCS May be triggered by many causes E.g. Accessing CPU MSRs VM 0 App App... Guest OS 0... VM n VM exit VM entry App App... Guest OS n VMM Platform HW Intel and the Intel logo are trademarks or registered trademarks of Intel Corporation or its subsidiaries in the United States and other countries. 19

Intel Virtualization Technology Operation with VMCS VM 1 VM 2 VM n VMX n-root Ring 3 Ring 3 Operation Ring 0 Ring 0... Ring 3 Ring 0 VMEXIT VMCS 1 VMCS 2 VMCS n IA-32 Operation VMX Root Operation VMLAUNCH Ring 3 Ring 0 VMRESUME 20