Intel is locking down its upcoming third-generation Xeon Scalable processors with a bevy of security enhancements designed to extend data protections down to the machine's bones.

Intel's Ice Lake-based Xeon chips, slated for release later this year, will benefit from secure enclaves, full memory encryption, firmware protections, and enhanced cryptographic performance, according to the chipmaker.

“Protecting data is essential to extracting value from it, and with the capabilities in the upcoming third-gen Xeon Scalable platform, we will help our customers solve their toughest data challenges while improving data confidentiality and integrity," Lisa Spelman, VP of Intel's Data Platform Group, said in a statement.

Integrated security has become increasingly important in the wake of the Meltdown and Spectre vulnerabilities which allowed unauthorized access to memory registers.

Learning from prior exploits, the upcoming scalable chips promise to be Intel's most heavily armored to date.

While Software Guard Extensions (SGX) is nothing new to the Xeon line — they have been available on Xeon E processors for some time — this is the first time the technology is being extended to Intel's full data center line up.

SGX enables application isolation in private memory regions, called enclaves. Ice Lake-based Xeon chips will feature "up to one terabyte of available protected enclave space in order to accommodate the huge workloads that we tend to see in data center operations," Anil Rao, VP of architecture for Intel's data platform group, said in a statement.

SGX will also include capabilities for predicted offload, enabling FPGAs and GPUs to take advantage of these protections as well, Rao added.

Freeze This!

Additionally, Intel's Ice Lake-based Xeons will benefit from new memory protections that will prevent advanced hardware exploits, according to the vendor.

Intel Total Memory Encryption (TME) will ensure all memory accessed by the CPU is encrypted. This means all customer credentials, encryption keys, and other personal information will be safe from attacks, the chipmaker said.

This framework will effectively eliminate the possibility of cold-boot exploits, which involve freezing the memory in order to preserve data, such as encryption keys, even after it has been removed from the machine, according to Intel.

Faster Encryption and Firmware Protections

In addition to freeze proofing its CPUs, Intel is introducing new cryptographic instruction sets to reduce the performance overheads when encryption is turned on.

Customers will no longer have to choose between performance and security, according to Intel.

Finally, Intel's third-generation Scalable chips will add Platform Firmware Resilience (PFR) to protect against and detect indirect attempts to breach the system through compromised firmware.

PFR can prevent exploits via BIOS, flash, a serial peripheral interface descriptor, Intel Management Engine, and power supply firmware, according to the company.

Confidential Computing Opportunity

Microsoft Azure was one of the first cloud providers to adopt SGX-equipped processors from Intel to enable "confidential compute" for customers in highly regulated industries.

"We believe the next generation of Intel Xeon processors with Intel SGX featuring full memory encryption and cryptographic acceleration will help our customers unlock even more confidential computing scenarios," said Mark Russinovich, CTO of Microsoft Azure, in a statement.

Health care providers could conceivably use the technology to better protect patient privacy, while other industries might use it to safeguard intellectual property, according to Intel.