Intel Demos Chip to Compute with Encrypted Data
spectrum.ieee.org
spectrum.ieee.org
There are two, non-exclusive paths I'm thinking at the moment:
1. DRM: Might this enable a next level of DRM?
2. Hardware attestation: Might this enable a deeper level of hardware attestation?
It's not related to DRM or trusted computing.
A: "Intel/AMD is adding instructions to accelerate AES"
B: "Might this enable a next level of DRM? Might this enable a deeper level of hardware attestation?"
A: "wtf are you talking about? It's just instructions to make certain types of computations faster, it has nothing to do with DRM or hardware attestation."
B: "Not yet."
I'm sure in some way it probably helps DRM or hardware attestation to some extent, but not any more than say, 3nm process node helps DRM or hardware attestation by making it faster.
That said, the unfortunate reality is that the same constructs that underpin DRM are also required to build a secure system. The only difference is who controls the root of trust. As such the problems with DRM (and hardware ownership more generally) are political as opposed to technical in nature.
> We discovered a substance that boosts your innate immune system and non-specifically clears out throat infections.
> This will be good for people prone to throat infections.
> Not when it's mandated.
someone else told me they're going to spy on your windows with drones to make sure you're verifying your age to your OS, like what??? I thought we were waking up to oppression but we're just inventing fake oppression to be mad at instead of responding to real oppression.
Same here.
Can't wait to KYC myself in order to use a CPU.
It's truly amazing how modern people just blithely sacrifice their privacy and integrity for no good reason. Just to let big tech corporations more efficiently siphon money out of the market. And then they fight you passionately when you call out those companies for being unnecessarily invasive and intrusive.
The four horsemen of the infocalypse are such profoundly reliable boogeymen, we really need a huge psychological study across all modern cultures to see why they're so effective at dismantling rational thought in the general public, and how we can innoculate society against it without damaging other important social behaviors.
The reason the 'Epstein class' are able to get away with crimes is because in recent US elections the US voted to elect politicions that intentionally are not investigating those crimes and even pardoned some criminals convicted of them.
In any event, my point was all presidents who grant pardons grant them to people convicted of a crime; it’s not a recent development. But that was framed as being upsetting precedent.
https://www.criminallawlibraryblog.com/amp/preemptive-pardon...
> 9. The power of pardon conferred by the Constitution upon the President is unlimited except in cases of impeachment. It extends to every offence known to the law, and may be exercised at any time after its commission, either before legal proceedings are taken or during their pendency, or after conviction and judgment. The power is not subject to legislative control.
https://tile.loc.gov/storage-services/service/ll/usrep/usrep...
Basically you can't pardon acts that haven't happened yet, but you can pardon before any legal action has been taken on prior acts.
Now replace KYC with CCTV surveillance because thats what it really is. Complete Monetary surveillance and control to fight a boogeyman scapegoat it doesn't even actually effect.
There were so many different ways in which you were required to provide absolute proof of your identity these days that life could easily become extremely tiresome just from that factor alone, never mind the deeper existential problems of trying to function as a coherent consciousness in an epistemologically ambiguous physical universe. Just look at cash point machines, for instance. Queues of people standing around waiting to have their fingerprints read, their retinas scanned, bits of skin scraped from the nape of the neck and undergoing instant (or nearly instant-a good six or seven seconds in tedious reality) genetic analysis, then having to answer trick questions about members of their family they didn't even remember they had, and about their recorded preferences for tablecloth colours. And that was just to get a bit of spare cash for the weekend. If you were trying to raise a loan for a jetcar, sign a missile treaty or pay an entire restaurant bill things could get really trying.
Hence the Ident-i-Eeze. This encoded every single piece of information about you, your body and your life into one all-purpose machine-readable card that you could then carry around in your wallet, and therefore represented technology's greatest triumph to date over both itself and plain common sense.
We are not anymore their clients, we are just another product to sell. So, they do not design chips for us but for the benefit of other corporations.
3. Unskippable ads with data gathering at the CPU level.
I remember how thinking how fun it was! I could see unfolded before me how there would be endless ways to configure, reconfigure, optimize, etc.
I know there are a few open source chip efforts, but wondering maybe now is the time to pull the community together and organize more intentionally around that. Maybe open source chipsets won't be as fast as their corporate counterparts, but I think we are definitely at an inflection point now in society where we would need this to maintain freedom.
If anyone is working in that area, I am very interested. I am very green, but still have the old textbooks I could dust off (just don't have the ole college provided mentor graphics -- or I guess siemens now -- design tool anymore).
The future is bleak.
I think eGovernment is the main use case: not super high traffic (we're not voting every day), but very high privacy expectations.
No, but media can be watermarked in imperceptible ways, and then if all players are required to check and act on such watermarks, the gap becomes narrow enough to probably be effective.
See Cinavia.
Massive if. Why would I voluntarily purchase gimped hardware?
Cinavia depended on being implemented by the player itself. It's difficult to see how (for example) a smart tv could implement it for streams coming in via HDMI from a computer the user has full control of.
The only thing this scheme was ever going to catch was full blown counterfeit disks sold on a street corner to your average joe. I think that was only ever much of a thing in the developing world. Or was it just before my time?
I'm aware of what Netflix and other streaming services do. That actually makes sense.
But wait! Even that's not good enough because my (now illicit) pirate box can present the stream embedded in a webpage for the locked down device that I don't control to play back on the DRM'd TV. So I guess now we're also going to want a scheme to prevent government approved devices from establishing network connections with unapproved ones?
Keep in mind that distributors absolutely do not want to reencode video per client at the edge. IIUC they go a long way out of their way to avoid ever having to do that, with the current watermarking scheme working by randomly selecting chunks to send from two or more pre-encoded video streams.
Meanwhile AI appears poised to give us unlimited approximately free (plus a few kW hours) entertainment at least assuming it doesn't end up somehow killing us all.
In general, this solution would be expensive and targeted at data lakes, or areas where you want to run computation but not necessarily expose the data.
With regard to DRM, one key thing to remember is that it has to be cheap, and widely deployable. Part of the reason dvds were easily broken is that the algorithm chosen was inexpensive both computationally, so you can install it on as many clients as possible.
Consoles after the original Xbox (which had an epic piracy ecosystem) all had online integration. The Xbox 360 had a massive piracy scene, but it was 100% offline only. The Xbox One has had no such breaches that I am aware of.
RE: BOM - famously, with many of these examples, certain specific disc drives or mainboards were far more compromised than others.
You could play pirated games online with the 360. The piracy was at the DVD Rom firmware level, replacing the stock firmware with one that basically changed the book type of the media. (And in later versions also mimicked other security checks preformed by the console to validate the authenticity of the disk)
However the DVD firmware mod didn’t break any digital signatures. It just allowed signed code to be executed from unauthentic media, so it only allowed piracy/backups not a full jailbreak allowing unsigned code. That was more the jtag/reset glitch era. Which was more “offline only” as it was easier for MS to detect and ban your key vault from Xbox live, but because people were willing to pay for modded lobbies in games like Call of Duty (which allowed you to rank up much faster) and Xbox dying if you sneezed that them, there was a even a market for extracting the keys from dead consoles to sell to those selling modded lobbies.
You still ran a risk of getting your console hardware banned for doing the DVD firmware mod, but towards the end I believe MS threw in the towel (even after trying to embed the flash chip in the samr package as the DSP for the drive which resulted in the kamikaze hack before the drive got further exploited) because one method they tried to use to detect piracy had such tight tolerances that it caused legit customers with aging drives to be caught up in the ban wave and MS had to walk it back.
The head of Xbox security (who sadly is no longer with us, he was a good egg at heart) left Microsoft not long afterwards. Obviously stating he wanted to move on to other things, but the word around the community at the time was that he was shown the door.
Personally I don’t hold much to that story (of him being pushed), this was so late in the consoles life that it seemed like it was trying to patch the hole in the titanic after it already sunk.
I’m sure you can name benign useful things you could use it for. But it seems to me you’re blatantly overlooking the obvious flaw.
There is no getting around doing search on encrypted data reducing the level of secrecy. To have an even minutely useful search result, some information within the searched corpus must be exposed.
It raises the hurdle for those looking to surveil.
If a tree falls in the forest and no one is around to hear it, does it make a sound?
This is primarily for cloud compute I'd imagine, AI specifically. As it's generally not feasible/possible to run the state of the art models locally. Think GDPR and data sovereignty concerns, many demand privacy and can't use services without it.
2. No, anyone can run the FHE computations anywhere on any hardware if they have the evaluation key (which would also have to be present in any FHE hardware).
But when homomorphic encryption becomes efficient, perhaps governments can force companies to apply it (though they would lose their opportunity for backdooring, but E2EE is a thing too so I wouldn't worry too much).
No, this does nothing for DRM or HW attestation. The interesting thought is: not everything is a conspiracy. Yes, that’s just what a conspirator would say. But it’s also true.
There are conspiracies and abuses, for sure. That does not mean that every single annoyance is a sign of a conspiracy.
That is nice speed-up compared to generic hardware but everyone probably wants to know how much slower it is than performing same operations on plain text data? I am sure 50% penalty is acceptable, 95% is probably not.
This hardware won’t make the technique attractive for ALL computation. But, it could dramatically increase the range of applications.
However... In a world where privacy is constantly being eroded intentionally by governments and private companies, I think this will NEVER, ever reach any consumer grade hardware. My cynic could envision the technology export ban worldwide in the vein of RSA [0] .
Why would any company offer the customers real out of the box e2e encryption possibilities built into their devices.
DRM was mentioned by another user. This will not be used to enable privacy for the masses.
https://en.wikipedia.org/wiki/Export_of_cryptography_from_th...
But getting them available for customers for example say even a PCIe card or something and then that automatically encrypting everything you ever run today over an encrypted connection would be a dream.
Why not when government can just force companies to backdoor their hardware for them. That way users are secure most of the time except from the government (until the backdoor in intel's chips gets discovered anyway), and users have a false sense of security/privacy so people are more likely to share their secrets with corporations and the government gets to spy on people communicating more openly with each other.
[1] https://confer.to/blog/2025/12/confessions-to-a-data-lake/
The correct solution isn't yet another cloud service, but rather local models.
Within the enclave itself, DRAM and PCIe connections between the CPU and GPU are encrypted, but the CPU registers and the GPU onboard memory are plaintext. So the computation is happening on plaintext data, it’s just extremely difficult to access it from even the machine running the enclave.
Then, verification involves a three part approach. Disclaimer: I'm the cofounder of Tinfoil: https://tinfoil.sh/, we also run inference inside secure enclaves. So I'll explain this as we do it.
First, you open source the code that's running in the enclave, and pin a commitment to it to a transparency log (in our case, Sigstore).
Then, when a client connects to the server (that's running in the enclave), the enclave computes the measurement of its current state and returns that to the client. This process is called remote attestation.
The client then fetches the pinned measurements from Sigstore and compares it against the fetched measurements from the enclave. This guarantees that the code running in the enclave is the same as the code that was committed to publicly.
So if someone claimed they were only analyzing aggregated metrics, they could not suddenly start analyzing individual request metrics because the code would change -> hash changes -> verification fails.
> First, you open source the code that's running in the enclave, and pin a commitment to it to a transparency log (in our case, Sigstore).
This means you have reproducible builds as well? (source+build-artifacts is signed)
Also - even if there are still some risk that the link is not 100% safe, maybe it's safe to assume vendors like yourself going through all that trouble are honorable? (alternatively - they are very curious of what "paranoid" people would send through LLMs :sweatsmile:)
So we do the next best thing. We decide to trust Github and rely on Github Actions to faithfully execute the build pipeline. We also make sure to pin all images and dependencies.
There is basically no business demand beside from sellers and scholars.
> "...a mathematical transformation, sort of like the Fourier transform. It encrypts data using a quantum-computer-proof algorithm..."
I am assuming there is some deep learning at play here i.e. it is manipulating the data within the latent space. If this is true, then would the embedding process really be considered "encryption"? You could argue it is security through obscurity (in the sense that the latent space basis is arbitrary/learned), but it feels like two different things to me.
The crux of HE is that it provides a _homomorphism_: you map from the space of plaintext to the space of cipher texts, but the mapping preserves arithmetic properties such as addition and multiplication. To be clear - this means that the server can add and multiply the cipher texts, but the plaintext result of that operation is still irreversible without the private key. To the server, it looks like random noise.
I don't think it's helpful to think about this as connected to deep learning or embedding spaces. An excellent resource I'd recommend is Jeremy Kun's guide: https://www.jeremykun.com/2024/05/04/fhe-overview/
When you have giant corporations like Intel being able to label their smaller competition's technology as "software cheats", then it becomes an incredibly toxic environment. If anyone were to do it to Intel, they would be sued for libel and slander and other anti-competitive tactics.
However, I shouldn't be surprised. The industry normalizes this type of discourse. At the same time, the same giant corporations will preach about AI safety and claim you can only trust them with it.
That being said, this is a great innovation by Intel. I was impressed at their technology and the thorough discussion about how this type of computing is related to GPU's and CPU's. It's especially interesting given the emergence of computational memory applications.
The PC market was made shitty enough this year, that Mid/High class Mac Pro/laptops are actually often a better value deal now (if and only if your use-case is covered software wise.)
Intel does plan on a RTX + amd64 SoC soon, but still pooched the memory interface with a 30 year old mailbox kludge. Intel probably wont survive this choice without bailouts. =3
Judging by Nvidia's current valuation, that's a parenthetical worth ~4 trillion dollars. Apple isn't muscling AMD or Nvidia out of the datacenter anytime soon, and they're basically feeding Intel Foundry customers by dominating TSMC fab capacity. Apple's contribution to the chip shortage is so bad that even they have considered using Intel Foundry Services: https://www.macrumors.com/2025/11/28/intel-rumored-to-supply...
It's been 7 years of Apple Silicon and the macOS market share really hasn't shifted much. The Year Of Apple Silicon For People Whose Use-Case Is Covered Software Wise was 2019; the majority of remaining customers aren't showing any interest.
Indeed, but a local LLM finishing in 3 days instead of 1 on a $40k GPU changes the economic decision priority for some.
Apple sales grew "21.3% year-over-year as of the second quarter of 2025", but also sales flattened as supply chain pricing shocks from "AI"/tariffs hit late last year.
"Judging by Nvidia's current valuation" is a bad bet with current circular investment conditions.
We shall see, but as EOL drivers and OS rot hits legacy NVIDIA hardware... people are going to have to find some compromise in the next 2 years. Even AMD 9850X3D currently cost less than 64G of low end PC ddr5 memory.
Odd times for sure =3
Apple’s Mac market share of the PC market went from 6.6% to 9% (https://www.cultofmac.com/news/mac-shipments-2025-apple) so that’s nothing to balk at. The MacBook Neo might grow that even more as maybe it converts low end buyers into locked in users in the ecosystem and then they move on to more Mac’s.
Apples only issue is its walled garden ecosystem eliminates most small/medium software studio content. In a way, the FOSS projects have greatly increased the MacOS software options available, and the recent Steam port is very promising.
Win11 has caused a massive shift in users to posix like systems. This will only improve most of the ecosystem. =3
5000 * 0 is still 0.
I joke, but i think relative numbers like this are very misleading as FHE is starting from such an absurdly slow place.
Still, this is pretty cool and there are probably niche applications that become possible with this, but i think this is a small enough speed up that it is still very niche.
If computation can happen directly on encrypted data, does that reduce the need for trusted environments like SGX/TEE, or does it mostly complement them?
If you need to trust the encryption and trust the hardware itself, it may not be suitable for your environment/ threat model.
Are we reading the same article? It's talking about homorphic encryption, ie. doing mathematical operations on already encrypted data, without being aware of its cleartext contents. It's not related to SGX or other trusted computing technologies.
"We believe that just like the internet went from zero encryption with HTTP to encrypting data in transit with HTTPS, the next natural step will be to use FHE to enable end-to-end encryption by default in every application, something we call HTTPZ"
That's my point, this sounds like a way to create a backdoor for at-rest data.
I get the feeling honestly it seems more expensive and more effort to backdoor it..
I encrypt some data and keep the key. I send the encrypted data to you (probably some cloud provider). I tell you to do some operations on the data. I don't tell you the key or what the data is or what the operations mean. You send the results back to me. I use the key to decrypt them.
You have helped me with my compute task, but the data you have is totally meaningless without the key, and only I have the key.
It's hard to believe that it's possible to make encryption where this can do useful work, but it is.
First you encrypt the data. Then you send it to hardware to compute, get result back and decrypt it.
The textbook example application of FHE is phone book search. The server "multiply" the whole phonebook database file with your encrypted query, and sends back the whole database file to you every time regardless of queries. When you decrypt the file with the key used to encrypt the query, the database is all corrupt and garbled except for the rows matching the query, thereby causing the search to have practically occurred. The only information that exists in the clear are query and the size of entire database.
Sounds fantastically energy-efficient, no? That's the problem with FHE, not risks of backdooring.
So here's my question: Could FHE hardware be used to extremely quickly and reliably secure something like a database connection?
I looked through Gemini, and it says the following:
"Zama are building libraries that use FHE accelerators to allow "Confidential Smart Contracts" or private AI queries. You could send a highly sensitive health query to an AI, and the AI hardware would process it and send the answer back without the AI company ever knowing what you asked."
Which is why I ask. Because if you have a backdoor into the hardware, as either a corporation or a government, then you can get access to those "very sensitive and fully secured communications".
They also discuss a crypto / smart contracts use case, and advertise " securing L1 or L2".
After nearly 3 decades of critical technology systems architecture and management involving ongoing industry audits my experience and age knows why my hair has lost some of its color. Much of that lost color comes from security management of third party systems, yes the old dreaded dependencies. Elimination of those third parties is key for one's cyber sanity and hair color yet with technology still in its infancy some cannot distinguish the forest from the trees.
Nothing remains the same as progress moves forward correcting for past mistakes while learning what works and does not along that journey, technology platforms are no exception. Analogously early automobiles lacked safety features as well such as windshield wipers and seatbelts so has the passage of time proved their addition to be valued? Few people today truly understand how things work as nearly all just want the instant fix "pill" to alleviate their issues however this approach cannot work with security. True security is designed in from the foundation and such secure platforms go unseen yet we have an endless list of victims from those insecure systems which have "bolted on" security after the fact. This security change and more is coming to system designs as the entire world is now fully aware of cyber security, or in this case, the lack of it.
Time, the young fail to consider it up until a single moment in their life, while the old reflect on where theirs went. After the reflection of one's time however change becomes obvious.
What you cannot see matters most!