aka SEM
works by repurpusing one of the physical address bits as a marker for whether memory acccess is plaintext or encrypted.
no key management necessary, is all done transparently by the on chip mem controller.
See https://www.amd.com/system/files/TechDocs/24593.pdf, page 275 (or on-page page number 220), chapter 7.10.
For the cpuid stuff see https://www.amd.com/system/files/TechDocs/24594.pdf, page 671, chapter E.4.17.