
2/28/2020 · Derek Chamorro, Brian Bassett, provided by our Performance team
What this post added
This post introduces Cloudflare's exploration and implementation of AMD's Secure Memory Encryption (SME) on EPYC processors. This feature provides hardware-level encryption for data in RAM, addressing physical server theft and memory snooping vulnerabilities. The post details the components of SME, its transparent mode (TSME), and performance testing results, demonstrating a minimal performance impact. This adds a new layer of hardware-assisted security to protect data in use, complementing existing encryption strategies.