[0] https://www.kernel.org/doc/html/v4.17/crypto/userspace-if.ht...
[0] https://www.kernel.org/doc/html/v4.17/crypto/userspace-if.ht...
SME/MKTME add hardware support for this.
Transparent disk encryption, not a problem since devices have filesystems which can implement encryption at that layer.
Note: inside the enclave there is a performance loss but that's due to MAC checks. If you just want encryption without integrity against tampering you don't need that.
https://en.wikichip.org/wiki/x86/sme
https://www.kernel.org/doc/Documentation/x86/amd-memory-encr...
From the quick description it sounds like this provides a way of encrypting, per memory page, based on a symmetric key that is backed by some level of hardware encryption. It was not clear (in a quick read) how or where to specify the key by which an individual page is encrypted. That would be a critical component of comprehension with respect to identifying if this could be used to encipher individual processes and further isolate memory. It sounds like it might be possible to establish per-process memory isolation, which is probably the best level of security possible without resorting to entirely isolated hardware.
Additionally a per-process key does not help against spectre style attacks where you would trick the process into speculating on protected memory.
https://info.varnish-software.com/blog/introducing-varnish-t...
Ah, so we'll just have to trust you that it's doing anything at all, then.
> https://news.ycombinator.com/newsguidelines.html
Forgive me but can we not be skeptical of claims made about a commercial product?
It's also not helpful to post such a clichéd dismissal of what someone else says or their work. That's in the site guidelines too.