Granite River Labs, GRL
Reese Li
The COVID-19 pandemic disrupted the global labor market and disrupted traditional work patterns, and in the process normalized concepts of "remote work" and "hybrid work". Exploring new ways to keep productivity levels high in this evolving labor landscape by providing the software and hardware capabilities is therefore one hurdle that management must overcome to keep remote and hybrid workforces sustainable.
The Intel vPro® goes as far back as 2006, when Intel astutely anticipated the evolving business needs. A platform ahead of its time, the Intel vPro® supports business and IT needs through four key pillars: Performance, Security, Manageability, and Stability. By 2011, the platform was already fully deployed on Intel client computers, laying the foundation for remote work requirements to be met.
Intel vPro® enabled remote device repairs and efficient management of PC fleets by providing out-of-band (OOB) management through Intel® Active Management Technology (AMT). Fast forward to last year's release of the 12th generation Alder Lake processors paired with the Intel vPro® platform, and we witness the emergence of a hybrid architecture that further amplifies computer performance and productivity.
The hybrid architecture of Intel's 12th generation processor, Alder Lake, balances performance and power consumption/heat between the Performance Cores (P-Cores) and Efficient Cores (E-Cores). This enables users to engage in multitasking and use IT applications with greater flexibility.
When combined with computers designed with the Intel vPro platform, Alder Lake processors integrate Intel Wi-Fi 6/6E and Thunderbolt™ 4 technologies. In addition to enhancing responsiveness for cloud and collaboration applications, Thunderbolt™ 4 technology enables the extension of multiple 4K displays and peripheral devices, as well as laptop charging. For remote workers, this helps create a clutter-free work environment that is conducive for multitasking.
Intel has developed a diverse range of processors to address different needs, including power optimization, graphics performance, memory, and form factor. These processors offer a wide array of choices for both enterprises and individual users. Let's take a closer look at Intel's 13th generation processor, Raptor Lake, as an illustrative example for mobile devices. Certain processors within this lineup provide support for Intel vPro® design. For more information and details about other processors and their compatibility with Intel vPro®, please visit the Intel website.
Table 1: Overview of Intel® Active Management Technology
Intel AMT is a feature of Intel vPro® that operates independently of the operating system, providing a wide range of built-in functionalities and add-on modules for management and security applications. Its presence allows IT personnel to discover, repair, and protect networked computing assets. Even when a computer is in a powered-off state, as long as it remains connected to a power source and network, IT personnel can still access Intel AMT and perform remote management and operations.
Intel AMT uses four pre-defined IANA network ports to transmit and receiver data:
In Intel AMT applications, data transmission and reception take place through ports 16992/16994 when no security certificate (Transport Layer Security, TLS) is configured. If a security certificate is configured, ports 16993/16995 are used. The presence of a security certificate does not impact valid network traffic. In other words, the traffic for data transmission and reception remains the same for ports 16992 and 16993. The distinction lies in the fact that data transmission via port 16993 requires a security certificate negotiation. This same principle applies to ports 16994/16995, but these ports employ a proprietary binary protocol that requires special software for usage.
Figure 1: OS accepts all data traffic except ports 16992 to 16995 (source: Active Platform Management Demystified: Unleashing the Power of Intel VPro® Technology)
After Intel AMT is configured, two ports will be opened and ready to receive connection instructions from the management console. Transmission Control Protocol (TCP) connections can be established on these two ports at any time. Before accepting commands from the management console, Intel AMT performs identity authentication and authorization using either HTTP-Digest or Kerberos. The authorization phase determines which entity acts as the management console and whether it has the necessary permissions to carry out operations. This authentication and authorization process ensures the security of data transmission and safeguards against potential external attacks by third parties.
Here is a brief overview of the Intel AMT authentication and authorization process, using TLS configuration as an example:
So, what are the remote operations that authorized IT administrators can perform with Intel AMT? Here are a few examples of common operations:
For more information and additional applications, please refer to the Intel® Active Management Technology website.
In the Thunderbolt™ 3/4 Host Functional Compliance Test Specification 1.4 released by Intel, a new test item for 3.5.6 vPro® (AMT) was introduced. This test item is designed for devices that support Intel vPro® and use Ethernet over Thunderbolt™, a feature that enables the use of Intel AMT via a Thunderbolt™ cable.
To enable Intel AMT through the Thunderbolt™ interface, it is necessary for the laptop hardware to support the Intel vPro® platform. Additionally, a Thunderbolt™ 4 dock that supports vPro® (AMT) is required. The following instructions will guide you on how to leverage the Intel vPro® platform for remote software and hardware maintenance through a Thunderbolt™ cable.
Figure 2: Schematic diagram of vPro® (AMT) test environment setup
Figure 3: Intel AMT interface on TBT Host1, displaying the configured local IP address
Figure 4: Intel AMT interface on Host2, showing the options for Remote Control
As the first certification lab in the world qualified by Intel, GRL provides comprehensive testing services for Thunderbolt™, including electrical validation and functional validation testing on system, dock, monitor, and more. Our team possesses extensive testing experience, in-depth domain knowledge, and robust industry connections, positioning us to deliver unparalleled support to our customers.
Author
Reese Li, Test Engineer of GRL
Reese is a GRL Thunderbolt Certification Test Engineer. He is acquainted with test specifications and principles of Thunderbolt and assists customers in solving challenging test problems and attaining certification.