Intel vPro

Last updated
The current Intel vPro emblem Intel vPro (logo, 2021).svg
The current Intel vPro emblem

Intel vPro technology is an umbrella marketing term used by Intel for a large collection of computer hardware technologies, including VT-x, VT-d, Trusted Execution Technology (TXT), and Intel Active Management Technology (AMT). [1] When the vPro brand was launched (circa 2007), it was identified primarily with AMT, [2] [3] thus some journalists still consider AMT to be the essence of vPro. [4]

Contents

vPro features

Intel vPro is a brand name for a set of PC hardware features. PCs that support vPro have a vPro-enabled processor, a vPro-enabled chipset, and a vPro-enabled BIOS as their main elements. [2] [3] [5] [6] [7] [8]

A vPro PC includes:

The 12th generation of Intel Core processors introduced four distinct platforms: vPro Essentials, vPro Enterprise for Windows, vPro Enterprise for Chrome and vPro Evo Design. [21] The difference of vPro Essentials is that it does not support some features: Out-of-band KVM remote control, Wireless Intel® AMT, Fast call for help, Intel® Remote Secure Erase with Intel® SSD Pro. [22] Intel processors that support vPro Essentials are using Intel Standard Manageability (a subset of Intel AMT) [23] which supports out-of-band management and can be monitored with the "Access Monitor" feature. [24] [25]

Remote management

Intel AMT is the set of management and security features built into vPro PCs that makes it easier for a sys-admin to monitor, maintain, secure, and service PCs. [11] Intel AMT (the management technology) is sometimes mistaken for being the same as Intel vPro (the PC "platform"), because AMT is one of the most visible technologies of an Intel vPro-based PC.

Intel AMT includes:

Hardware-based management has been available in the past, but it has been limited to auto-configuration (of computers that request it) using DHCP or BOOTP for dynamic IP address allocation and disk-less workstations, as well as wake-on-LAN for remotely powering on systems. [26]

VNC-based KVM remote control

Starting with vPro with AMT 6.0, PCs with i5 or i7 processors and embedded Intel graphics, now contains an Intel proprietary embedded VNC server. You can connect out-of-band using dedicated VNC-compatible viewer technology, and have full KVM (keyboard, video, mouse) capability throughout the power cycle—including uninterrupted control of the desktop when an operating system loads. Clients such as VNC Viewer Plus from RealVNC also provide additional functionality that might make it easier to perform (and watch) certain Intel AMT operations, such as powering the computer off and on, configuring the BIOS, and mounting a remote image (IDER).

Not all i5 & i7 Processors with vPro may support KVM capability. This depends on the OEM's BIOS settings as well as if a discrete graphics card is present. Only Intel integrated HD graphics support KVM ability. [27] [ better source needed ]

Wireless communication

Intel vPro supports encrypted wired and wireless LAN wireless communication for all remote management features for PCs inside the corporate firewall. [11] Intel vPro supports encrypted communication for some remote management features for wired and wireless LAN PCs outside the corporate firewall. [11] [28]

vPro laptop wireless communication

Laptops with vPro include a gigabit network connection and support IEEE 802.11 a/g/n wireless protocols. [11] [28] [29]

AMT wireless communication

Intel vPro PCs support wireless communication to the AMT features. [11] [29]

For wireless laptops on battery power, communication with AMT features can occur when the system is awake and connected to the corporate network. This communication is available if the OS is down or management agents are missing. [11] [28]

AMT out-of-band communication and some AMT features are available for wireless or wired laptops connected to the corporate network over a host OS-based virtual private network (VPN) when laptops are awake and working properly. [11]

A wireless connection operates at two levels: the wireless network interface (WLAN) and the interface driver executing on the platform host. The network interface manages the RF communications connection.

If the user turns off the wireless transmitter/receiver using either a hardware or software switch, Intel AMT cannot use the wireless interface under any conditions until the user turns on the wireless transmitter/receiver.

Intel AMT Release 2.5/2.6 can send and receive management traffic via the WLAN only when the platform is in the S0 power state (the computer is on and running). It does not receive wireless traffic when the host is asleep or off. If the power state permits it, Intel AMT Release 2.5/2.6 can continue to send and receive out-of-band traffic when the platform is in an Sx state, but only via a wired LAN connection, if one exists.

Release 4.0 and later releases support wireless out-of-band manageability in Sx states, depending on the power setting and other configuration parameters.

Release 7.0 supports wireless manageability on desktop platforms.

When a wireless connection is established on a host platform, it is based on a wireless profile that sets up names, passwords and other security elements used to authenticate the platform to the wireless Access Point. The user or the IT organization defines one or more profiles using a tool such as Intel PROSet/Wireless Software. In release 2.5/6, Intel AMT must have a corresponding wireless profile to receive out-of-band traffic over the same wireless link. The network interface API allows defining one or more wireless profiles using the same parameters as the Intel PROSet/Wireless Software. See Wireless Profile Parameters. On power-up of the host, Intel AMT communicates with the wireless LAN driver on the host. When the driver and Intel AMT find matching profiles, the driver routes traffic addressed to the Intel AMT device for manageability processing. With certain limitations, Intel AMT Release 4.0/1 can send and receive out-of-band traffic without an Intel AMT configured wireless profile, as long as the host driver is active and the platform is inside the enterprise.

In release 4.2, and on release 6.0 wireless platforms, the WLAN is enabled by default both before and after configuration. That means that it is possible to configure Intel AMT over the WLAN, as long as the host WLAN driver has an active connection. Intel AMT synchronizes to the active host profile. It assumes that a configuration server configures a wireless profile that Intel AMT uses in power states other than S0.

When there is a problem with the wireless driver and the host is still powered up (in an S0 power state only), Intel AMT can continue to receive out-of-band manageability traffic directly from the wireless network interface.

For Intel AMT to work with a wireless LAN, it must share IP addresses with the host. This requires the presence of a DHCP server to allocate IP addresses and Intel AMT must be configured to use DHCP.

Encrypted communication while roaming

Intel vPro PCs support encrypted communication while roaming. [11] [29] [30]

vPro PCs version 4.0 or higher support security for mobile communications by establishing a secure tunnel for encrypted AMT communication with the managed service provider when roaming (operating on an open, wired LAN outside the corporate firewall). [11] Secure communication with AMT can be established if the laptop is powered down or the OS is disabled. [11] The AMT encrypted communication tunnel is designed to allow sys-admins to access a laptop or desktop PC at satellite offices where there is no on-site proxy server or management server appliance.

Secure communications outside the corporate firewall depend on adding a new element—a management presence server (Intel calls this a "vPro-enabled gateway")—to the network infrastructure. [11] This requires integration with network switch manufacturers, firewall vendors, and vendors who design management consoles to create infrastructure that supports encrypted roaming communication. So although encrypted roaming communication is enabled as a feature in vPro PCs version 4.0 and higher, the feature will not be fully usable until the infrastructure is in place and functional.

vPro security

vPro security technologies and methodologies are designed into the PC's chipset and other system hardware. During deployment of vPro PCs, security credentials, keys, and other critical information are stored in protected memory (not on the hard disk drive), and erased when no longer needed.

Security and privacy concerns

According to Intel, it is possible to disable AMT through the BIOS settings, however, there is apparently no way for most users to detect outside access to their PC via the vPro hardware-based technology. [31] Moreover, Sandy Bridge and future chips will have, "...the ability to remotely kill and restore a lost or stolen PC via 3G ... if that laptop has a 3G connection" [32]

On May 1, [2017] Intel published a security advisory regarding a firmware vulnerability in certain systems that utilize Intel Active Management Technology (Intel AMT), Intel Standard Manageability (Intel ISM), or Intel Small Business Technology (Intel SBT). The vulnerability is potentially very serious, and could enable a network attacker to remotely gain access to businesses PCs and workstations that use these technologies. We urge people and companies using business PCs and devices that incorporate Intel AMT, Intel ISM or Intel SBT to apply a firmware update from your equipment manufacturer when available, or to follow the steps detailed in the mitigation guide. [33] [34]

Many vPro features, including AMT, are implemented in the Intel Management Engine (ME), a distinct processor in the chipset running MINIX 3, which has been found to have numerous security vulnerabilities. Unlike for AMT, there is generally no official, documented way to disable the Management Engine (ME); it is always on unless it is not enabled at all by the OEM. [35] [36]

Security features

Intel vPro supports industry-standard methodologies and protocols, as well as other vendors' security features: [6] [11] [13] [37]

Intel Boot Guard

Intel Boot Guard is a processor feature that prevents the computer from running firmware (UEFI) images not released by the system manufacturer (OEM or ODM). When turned on, the processors verifies a digital signature contained in the firmware image before executing it, using the public key of the keypair, the OEM/ODM public key is fused into the system's Platform Controller Hub (PCH) [lower-alpha 1] by the system manufacturer (not by Intel). As a result, Intel Boot Guard, when activated, makes it impossible for end users to install replacement firmware (such as Coreboot) or modded BIOS. [40] [41]

Intel Boot Guard was first released in Haswell processors in June 2013.

Technologies and methodologies

Intel vPro uses several industry-standard security technologies and methodologies to secure the remote vPro communication channel. These technologies and methodologies also improve security for accessing the PC's critical system data, BIOS settings, Intel AMT management features, and other sensitive features or data; and protect security credentials and other critical information during deployment (setup and configuration of Intel AMT) and vPro use. [11] [42]

vPro hardware requirements

The first release of Intel vPro was built with an Intel Core 2 Duo processor. [6] The current versions of Intel vPro are built into systems with 10 nm Intel 10th Generation Core i5 & i7 processors.

PCs with Intel vPro require specific chipsets. Intel vPro releases are usually identified by their AMT version. [6] [11]

Laptop PC requirements

Laptops with Intel vPro require:

Note that AMT release 2.5 for wired/wireless laptops and AMT release 3.0 for desktop PCs are concurrent releases.

Desktop PC requirements

Desktop PCs with vPro (called "Intel Core 2 with vPro technology") require:

Note that AMT release 2.5 for wired/wireless laptops and AMT release 3.0 for desktop PCs are concurrent releases.

vPro, AMT, Core i relationships

There are numerous Intel brands. However, the key differences between vPro (an umbrella marketing term), AMT (a technology under the vPro brand), Intel Core i5 and Intel Core i7 (a branding of a package of technologies), and Core i5 and Core i7 (a processor) are as follows:

The Core i7, the first model of the i series was launched in 2008, and the less-powerful i5 and i3 models were introduced in 2009 and 2010, respectively. The microarchitecture of the Core i series was code-named Nehalem, and the second generation of the line was code-named Sandy Bridge.

Intel Centrino 2 was a branding of a package of technologies that included Wi-Fi and, originally, the Intel Core 2 Duo. [5] The Intel Centrino 2 brand was applied to mobile PCs, such as laptops and other small devices. Core 2 and Centrino 2 have evolved to use Intel's latest 45-nm manufacturing processes, have multi-core processing, and are designed for multithreading.

Intel vPro is a brand name for a set of Intel technology features that can be built into the hardware of the laptop or desktop PC. [11] The set of technologies are targeted at businesses, not consumers. A PC with the vPro brand often includes Intel AMT, Intel Virtualization Technology (Intel VT), Intel Trusted Execution Technology (Intel TXT), a gigabit network connection, and so on. There may be a PC with a Core 2 processor, without vPro features built in. However, vPro features require a PC with at least a Core 2 processor. The technologies of current versions of vPro are built into PCs with some versions of Core 2 Duo or Core 2 Quad processors (45 nm), and more recently with some versions of Core i5 and Core i7 processors.

Intel AMT is part of the Intel Management Engine that is built into PCs with the Intel vPro brand. Intel AMT is a set of remote management and security hardware features that let a sys-admin with AMT security privileges access system information and perform specific remote operations on the PC. [6] These operations include remote power up/down (via wake on LAN), remote / redirected boot (via integrated device electronics redirect, or IDE-R), console redirection (via serial over LAN), and other remote management and security features.

See also

Notes

  1. In some Intel CPUs, PCH and the processor are integrated into the same package. [39]

Related Research Articles

<span class="mw-page-title-main">Centrino</span> Brand name by Intel

Centrino is a brand name of Intel Corporation which represents its Wi-Fi and WiMAX wireless computer networking adapters. Previously the same brand name was used by the company as a platform-marketing initiative. The change of the meaning of the brand name occurred on January 7, 2010. The Centrino was replaced by the Ultrabook.

<span class="mw-page-title-main">Alienware</span> American computer hardware subsidiary of Dell Inc.

Alienware Corporation is an American computer hardware subsidiary brand of Dell. Their product range is dedicated to gaming computers and can be identified by their alien-themed designs. Alienware was founded in 1996 by Nelson Gonzalez and Alex Aguila. The development of the company is also associated with Frank Azor, Arthur Lewis, Joe Balerdi, and Michael S. Dell. The company's corporate headquarters is located in The Hammocks, Miami, Florida.

<span class="mw-page-title-main">Dell XPS</span> Line of high performance computers manufactured by Dell

Dell XPS is a line of consumer-oriented laptop and desktop computer series manufactured by Dell since 1993.

<span class="mw-page-title-main">Dell Latitude</span> Line of business-oriented laptop computers by Dell

Dell Latitude is a line of laptop computers manufactured and sold by American company Dell Technologies. It is a business-oriented line, aimed at corporate enterprises, healthcare, government, and education markets; unlike the Inspiron and XPS series, which are aimed at individual customers, and the Vostro series, which is aimed at smaller businesses.

<span class="mw-page-title-main">Intel Core 2</span> Processor family by Intel

Intel Core 2 was a processor family encompassing a range of Intel's mainstream 64-bit x86-64 single-, dual-, and quad-core microprocessors based on the Core microarchitecture. The single- and dual-core models are single-die, whereas the quad-core models comprise two dies, each containing two cores, packaged in a multi-chip module. The Core 2 range was the last flagship range of Intel desktop processors to use a front-side bus (FSB).

<span class="mw-page-title-main">Sandy Bridge</span> Intel processor microarchitecture

Sandy Bridge is the codename for Intel's 32 nm microarchitecture used in the second generation of the Intel Core processors. The Sandy Bridge microarchitecture is the successor to Nehalem and Westmere microarchitecture. Intel demonstrated an A1 stepping Sandy Bridge processor in 2009 during Intel Developer Forum (IDF), and released first products based on the architecture in January 2011 under the Core brand.

<span class="mw-page-title-main">Intel Active Management Technology</span> Out-of-band management platform by Intel

Intel Active Management Technology (AMT) is hardware and firmware for remote out-of-band management of select business computers, running on the Intel Management Engine, a microprocessor subsystem not exposed to the user, intended for monitoring, maintenance, updating, and repairing systems. Out-of-band (OOB) or hardware-based management is different from software-based management and software management agents.

<span class="mw-page-title-main">Dell Vostro</span> Line of laptop and desktop computers by Dell

Dell Vostro is a line of business-oriented laptop and desktop computers manufactured by Dell aimed at small to medium range businesses. From 2013–2015, the line was temporarily discontinued on some Dell websites but continued to be offered in other markets, such as Malaysia and India.

<span class="mw-page-title-main">Haswell (microarchitecture)</span> Intel processor microarchitecture

Haswell is the codename for a processor microarchitecture developed by Intel as the "fourth-generation core" successor to the Ivy Bridge. Intel officially announced CPUs based on this microarchitecture on June 4, 2013, at Computex Taipei 2013, while a working Haswell chip was demonstrated at the 2011 Intel Developer Forum. With Haswell, which uses a 22 nm process, Intel also introduced low-power processors designed for convertible or "hybrid" ultrabooks, designated by the "U" suffix.

Intel Active Management Technology (AMT) is hardware-based technology built into PCs with Intel vPro technology. AMT is designed to help sys-admins remotely manage and secure PCs out-of-band when PC power is off, the operating system (OS) is unavailable, software management agents are missing, or hardware has failed.

<span class="mw-page-title-main">Intel Core</span> Line of CPUs by Intel

Intel Core is a line of multi-core central processing units (CPUs) for midrange, embedded, workstation, high-end and enthusiast computer markets marketed by Intel Corporation. These processors displaced the existing mid- to high-end Pentium processors at the time of their introduction, moving the Pentium to the entry level. Identical or more capable versions of Core processors are also sold as Xeon processors for the server and workstation markets.

<span class="mw-page-title-main">Skylake (microarchitecture)</span> CPU microarchitecture by Intel

Skylake is Intel's codename for its sixth generation Core microprocessor family that was launched on August 5, 2015, succeeding the Broadwell microarchitecture. Skylake is a microarchitecture redesign using the same 14 nm manufacturing process technology as its predecessor, serving as a tock in Intel's tick–tock manufacturing and design model. According to Intel, the redesign brings greater CPU and GPU performance and reduced power consumption. Skylake CPUs share their microarchitecture with Kaby Lake, Coffee Lake, Whiskey Lake, and Comet Lake CPUs.

Founded by Alex Vasilevsky, Virtual Computer was a venture-backed software company in the Boston area that produces desktop virtualization products, which combine centralized management with local execution on a hypervisor running on PCs. By running the workload on the PC, Virtual Computer enables companies to have centralized management without servers, storage, and networking required for server-hosted VDI.

<span class="mw-page-title-main">Broadwell (microarchitecture)</span> Fifth generation of Intel Core processors

Broadwell is the fifth generation of the Intel Core processor. It is Intel's codename for the 14 nanometer die shrink of its Haswell microarchitecture. It is a "tick" in Intel's tick–tock principle as the next step in semiconductor fabrication. Like some of the previous tick-tock iterations, Broadwell did not completely replace the full range of CPUs from the previous microarchitecture (Haswell), as there were no low-end desktop CPUs based on Broadwell.

<span class="mw-page-title-main">LGA 1151</span> Intel microprocessor compatible socket

LGA 1151, also known as Socket H4, is a type of zero insertion force flip-chip land grid array (LGA) socket for Intel desktop processors which comes in two distinct versions: the first revision which supports both Intel's Skylake and Kaby Lake CPUs, and the second revision which supports Coffee Lake CPUs exclusively.

<span class="mw-page-title-main">Intel Management Engine</span> Autonomous computer subsystem

The Intel Management Engine (ME), also known as the Intel Manageability Engine, is an autonomous subsystem that has been incorporated in virtually all of Intel's processor chipsets since 2008. It is located in the Platform Controller Hub of modern Intel motherboards.

<span class="mw-page-title-main">Coffee Lake</span> Eighth-generation Intel Core microprocessor family

Coffee Lake is Intel's codename for its eighth-generation Core microprocessor family, announced on September 25, 2017. It is manufactured using Intel's second 14 nm process node refinement. Desktop Coffee Lake processors introduced i5 and i7 CPUs featuring six cores and Core i3 CPUs with four cores and no hyperthreading.

Comet Lake is Intel's codename for its 10th generation Core processors. They are manufactured using Intel's third 14 nm Skylake process revision, succeeding the Whiskey Lake U-series mobile processor and Coffee Lake desktop processor families. Intel announced low-power mobile Comet Lake-U CPUs on August 21, 2019, H-series mobile CPUs on April 2, 2020, desktop Comet Lake-S CPUs April 30, 2020, and Xeon W-1200 series workstation CPUs on May 13, 2020. Comet Lake processors and Ice Lake 10 nm processors are together branded as the Intel "10th Generation Core" family. Intel officially launched Comet Lake-Refresh CPUs on the same day as 11th Gen Core Rocket Lake launch. The low-power mobile Comet Lake-U Core and Celeron 5205U CPUs were discontinued on July 7, 2021.

References

  1. "Intel vPro Technology Reference Guide (Updated for Intel AMT 8)" (PDF). Intel. August 16, 2012. Archived from the original (PDF) on 2015-03-20. Retrieved 2014-09-14.
  2. 1 2 "Remote Pc Management with Intel's vPro". Tom's Hardware Guide. 26 April 2007. Retrieved 2007-11-21.
  3. 1 2 "A new dawn for remote management? A first glimpse at Intel's vPro platform". ars technica. 6 February 2007. Retrieved 2007-11-07.
  4. "Intel vPro: Three Generations Of Remote Management". Tom's Hardware. 26 September 2011.
  5. 1 2 "Intel Centrino 2 Explained". CNET. Archived from the original on 2012-11-05. Retrieved 2008-07-15.
  6. 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 "Architecture Guide: Intel Active Management Technology". Intel. 2008-06-26. Archived from the original on 2012-07-22. Retrieved 2008-08-12.
  7. 1 2 3 "Intel vPro Chipset Lures MSPs, System Builders". ChannelWeb. 27 August 2007.
  8. 1 2 3 "Intel Mostly Launches Centrino 2 Notebook Platform". ChannelWeb. 15 July 2008.
  9. admin (30 March 2015). "Business Client - Overview". software.intel.com.
  10. S, Ganesh T. "Intel Expands Compute Stick Family with Cherry Trail and Core M Models". www.anandtech.com.
  11. 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 "Intel Active Management Technology (Intel AMT) Start Here Guide" (PDF). Intel. Retrieved 2013-03-18.
  12. "Intel Centrino 2 with vPro Technology". Intel. Archived from the original on 2008-03-15. Retrieved 2008-06-30.
  13. 1 2 3 4 5 6 "New Intel vPro Processor Technology Fortifies Security for Business PCs (news release)". Intel. Archived from the original on 2007-09-12. Retrieved 2007-08-07.
  14. 1 2 "Intel Trusted Execution Technology" (PDF). Intel. 2007. Retrieved 2008-07-15.
  15. 1 2 "Intel Trusted Execution Technology: A Primer". Intel. 2007-12-10. Archived from the original on 2008-09-24. Retrieved 2008-08-17.
  16. 1 2 "Intel Software Network, engineer / developers forum". Intel. Archived from the original on 2011-08-13. Retrieved 2008-08-09.
  17. 1 2 "Cisco Security Solutions with Intel Centrino Pro and Intel vPro Processor Technology" (PDF). Intel. 2007.
  18. Processor without vPro having Intel VT support: "Intel® Core™ i7-1165G7 Processor".
  19. "The Benefits of Intel Centrino with vPro Technology in the Enterprise" (PDF). Wipro Technologies. 1 September 2007. Archived from the original (PDF) on 21 December 2008.
  20. "Execute Disable Bit and Enterprise Security". Intel. Retrieved 2008-08-10.
  21. "Intel 12th gen vPro branches into four distinct platforms across Windows and Chrome, Control Flow Enforcement now coming to desktops for the first time".
  22. "What Are the Differences between Intel® vPro™ Essentials and Intel® vPro™ Enterprise?".
  23. "Intel expands the scope of vPro processors with the 12th-gen lineup".
  24. "About Intel AMT > Support for Other Intel Platforms".
  25. "Intel AMT Features > Access Monitor".
  26. "A new dawn for remote management? A first glimpse at Intel's vPro platform". ars technica. 6 February 2007. Retrieved 2007-07-26.
  27. "Intel® Active Management Technology SDK".
  28. 1 2 3 "Understanding Intel AMT over wired vs. wireless (video)". Intel. Archived from the original on March 26, 2008. Retrieved 2008-08-14.
  29. 1 2 3 "New Intel-Based Laptops Advance All Facets of Notebook PCs". Intel. Archived from the original on 2008-07-17. Retrieved 2008-07-15.
  30. "Intel Active Management Technology Setup and Configuration Service, Version 5.0" (PDF). Intel. Archived from the original (PDF) on 2008-09-04. Retrieved 2008-08-04.(see CIRA configuration discussion)
  31. Hodgin, Rick C. (2008-09-24). "Big Brother potentially exists right now in our PCs, compliments of Intel's vPro". TG Daily. Archived from the original on 2009-10-27. Retrieved 2014-02-26.
  32. Hachman, Mark (2010-09-14). "Intel's 'Sandy Bridge' Chip to Include vPro Business Features". PC Magazine. quoting Jeff Marek, director of business client engineering for Intel.
  33. "Intel® AMT Critical Firmware Vulnerability". Intel.
  34. "Report claims Intel CPUs contain enormous security flaw - ExtremeTech". www.extremetech.com.
  35. "Positive Technologies Blog: Disabling Intel ME 11 via undocumented mode". Archived from the original on 2017-08-28. Retrieved 2017-08-30.
  36. "Intel Patches Major Flaws in the Intel Management Engine". Extreme Tech.
  37. "Intel vPro Technology". Intel. Retrieved 2008-07-14.
  38. "How To Enable BitLocker With Intel PTT and No TPM For Better Security". Legit Reviews. 2019-05-08. Retrieved 2020-09-11.
  39. Smith, Ryan (August 11, 2014). "Intel Broadwell Architecture Preview: A Glimpse into Core M". AnandTech . Retrieved February 25, 2015.
  40. Hoffman, Chris (February 13, 2015). "How Intel and PC makers prevent you from modifying your laptop's firmware". PC World . Retrieved February 25, 2015.
  41. Garrett, Matthew (February 16, 2015). "Intel Boot Guard, Coreboot and user freedom". mjg59.dreamwidth.org. Retrieved February 25, 2015.
  42. "Intel Active Management Technology Setup and Configuration Service Installation and User Manual" (PDF). Intel. Archived from the original (PDF) on 2010-08-21. Retrieved 2008-07-14.
  43. "Advanced Encryption Standard (AES) Instructions Set". Intel. Archived from the original on 2008-09-24. Retrieved 2008-08-05.
  44. 1 2 "Hardening Measures Built into Intel Active Management Technology". Intel. 2007-12-10. Archived from the original on 2008-03-20. Retrieved 2008-08-01.
  45. "Intel vPro Technology FAQ". Intel. Archived from the original on March 15, 2008. Retrieved 2008-07-12.
  46. "4th Generation Intel Core i7 Processors". Ark.intel.com. Retrieved 2014-02-26.
  47. "4th Generation Intel Core i5 Processors". Ark.intel.com. Retrieved 2014-02-26.
  48. 1 2 "ARK | Intel QM87 Chipset (Intel DH82QM87 PCH)". Ark.intel.com. Retrieved 2014-02-26.
  49. "ARK | Processor Feature Filter". Ark.intel.com. Retrieved 2014-02-26.
  50. "ARK | Processor Feature Filter". Ark.intel.com. Retrieved 2014-02-26.
  51. "New Intel Centrino Atom Processor Technology Ushers in 'Best Internet Experience in Your Pocket'". Intel. 2008-04-02. Archived from the original on 2008-04-17. Retrieved 2008-08-07.
  52. 1 2 "Intel Centrino Pro and Intel vPro Processor Technology" (PDF). Intel. 2007. Retrieved 2008-08-07.
  53. "Gelsinger Speaks To Intel And High-Tech Industry's Rapid Technology Cadence". Intel. 2007-09-18. Archived from the original on 2008-04-17. Retrieved 2008-08-16.