
White Paper: The All New 2010 Intel® Core™ vPro™ Processor Family: Intelligence that Adapts to Your Needs
Virtualization can be achieved entirely with software — but this approach has traditionally had several challenges, including too much overhead, poor performance, and unenforced isolation (a security issue).
Intel VT includes hardware enhancements that shift much of the burden of
Improving isolation and security
Intel VT includes hardware enhancements that virtualize memory, the CPU, and directed I/O. These features provide a significant level of hardware enforcement for the VMM’s memory manager, and significantly improve isolation of the virtual environment. In turn, this helps improve security for critical processes and sensitive data.
Establishing a trusted execution environment
One of the persistent challenges of virtualization is ensuring the integrity of the VMM. Intel TXT addresses this important security issue using a
as expected. The process allows the VMM to be verified earlier than with current software protection mechanisms (such as virus detection software).
Intel TXT also protects secrets (security credentials) during power transitions. With Intel TXT, during OS and application launch, passwords and keys are stored in protected memory. When the PC is rebooted, Intel TXT detects that secrets are still stored in memory, removes the secrets, then allows a normal boot process. (Secrets are not removed by Intel TXT after a normal protected partition
Table 5. Virtualization support in laptop and desktop PCs.
have not traditionally been protected before the OS and security applications are launched, are now protected even after improper
Intel TXT is available in the latest laptop and desktop PCs with a new Intel Core vPro processor.
Intel® VT is compatible with other technologiesStandard memory, storage, and graphics cards work with Intel VT.5 The latest laptop and desktop PCs with a new Intel Core vPro processor can also run most
PCs with
•Flexibility. Support both traditional and alternative compute models on a single standardized PC build.
•Legacy support. Run legacy applications seamlessly in a user environment, and still maintain high security in a separate virtual environment through the use of Intel VT and Intel TXT.
•
•Productivity. Provide local execution for laptop PCs who are off the network, while streaming applications or OSs to other users who are network connected.
•Performance. Great user experience with local,
•Leading ISV support from Citrix, VMWare, Microsoft, and Symantec.
Advanced technology | Offers | All new 2010 Intel® Core™ vPro™ processor family |
Intel® VT9 | Traditional client virtualization, which isolates and supports | Yes |
| multiple OSs on a single PC |
|
|
|
|
Intel® VT for Directed I/O | Virtualization of I/O hardware | Yes |
|
|
|
Support for virtual containers | Temporary virtual machines (“containers”) that support virtual | Yes |
| user environments and isolate streamed OS and applications |
|
|
|
|
Intel® TXT19 | Trusted launch of the VMM and protection of secrets | Yes |
| during proper or improper shutdown |
|
|
|
|
21