Random Number Generation for Security
Securing Memory at EPYC Scale

Securing Memory at EPYC Scale

2/28/2020 · Derek Chamorro, Brian Bassett, provided by our Performance team

What this post added

This post introduces Cloudflare's exploration and implementation of AMD's Secure Memory Encryption (SME) on EPYC processors. This feature provides hardware-level encryption for data in RAM, addressing physical server theft and memory snooping vulnerabilities. The post details the components of SME, its transparent mode (TSME), and performance testing results, demonstrating a minimal performance impact. This adds a new layer of hardware-assisted security to protect data in use, complementing existing encryption strategies.

Read the original post ↗