Intel Management Engine

From coreboot
Revision as of 17:58, 13 August 2014 by GNUtoo (talk | contribs) (→‎Where)
Jump to navigation Jump to search

The wiki is being retired!

Documentation is now handled by the same processes we use for code: Add something to the Documentation/ directory in the coreboot repo, and it will be rendered to Contributions welcome!

Uses of the Management Engine

The management engine(Often abreviated ME) is a CPU which permits Out of band management of the computer.

Freedom and security issues

  • The code that is running inside the management engine is proprietary and signed
  • The management engine CPU has access to a lot of things, see "ME physical capabilities" for more details.


Board Firmware Microarchitecture Chipset ME location ME physical capabilities ME restrictions
Lenovo x201 AMT Nehalem Ibex Peak Inside the PCH
  • Has access to the memory
  • Controls the computer's original networking adapters
  • The ME firmware is signed.
Packard Bell EasyNote LM85 (MS2290)
Samsung Series 5 550 Chromebook me.bin Sandy Bridge Inside the PCH
  • The ME firmware is signed.
Samsung Series 3 Chromebox
Lenovo t520 AMT

Why there is no replacement for it yet

Firmware signature

RAM reagion is locked

See also