Intel® Core™ Processor (Series 3)
Formerly known as Wildcat Lake, Datasheet, Volume 1 of 2
| ID | Date | Version | Classification |
|---|---|---|---|
| 913965 | 05/19/2026 | 001 | Public |
Intel® Total Storage Encryption (Intel® TSE)
Intel® Total Storage Encryption provides a security measure for a PCIe-NVMe device by encrypting the data in the device using the Intel inline encryption.
The Intel® Total Storage Encryption, which is enabled over
The Intel® Total Storage Encryption encrypts the data using the AES XTS algorithm with a 256-bit data encryption key and 256-bit tweak key when the data is written to the storage from system memory and decrypted when read from the storage to the system memory.
The software can wrap the 256-bit keys using Platform Bind Key BLOB (PBNDKB) instruction and get the key handle wrapped by a platform-specific wrapping key. Once the software obtains the handle, the software can delete the original keys from memory. The software can also program the 256-bit keys using either the key handles or plaintext keys through the Platform Config (PCONFIG) instruction.
The Intel® Total Storage Encryption driver
- Intel® TSE is currently a vPRO only feature and should be enabled on any NVMe attached to the platform PCIe port, including PCH ports.
- Intel® TSE works with PCIe NVMe storage devices off CPU and PCH Root Ports.
- Intel® TSE works with one PCIe NVMe storage device (regardless of Processor/PCH).