Management and security. It started as just management, and then it added security as demand for that service grew. There are very real needs that it fills, though it doesn't need to sacrifice end-user control:
Management: Imagine you manage and support 10,000 desktops and laptops. Remote access is essential (otherwise you'd effectively pay something like 2/3 of your support staff to cover time spent walking around), but typical remote access depends on an available processor, memory, OS, etc. For the many cases where those components aren't all available (something failed, OS is being updated, need to disable a component to diagnose it, etc.), you need out-of-band remote access, such as what Intel ME provides. It's a high-value service for corporate IT.
Security: You need an out-of-band machine to perform crypto functions, to protect the crypto functions against in-band attacks (e.g., in the OS, BIOS, applications ...). The out-of-band machine can then be used to verify the integrity of BIOS, OS, and other important things. It's also useful for DRM. If you're in corporate IT, you suddenly have a way to provide reasonable security guarantees across your 10,000 computers, a huge step forward.
If you are in corporate IT, or if you're a vendor wanting to enforce, protect, or hide your media or other proprietary bits, end-user control is undesirable. Obviously, that could be optional for owners of the computers who have other needs, but somehow it never works out that way ...
EDIT If you really want to learn about it, save your time and go to the source:
Platform Embedded Security Technology Revealed: Safeguarding the Future of Computing with Intel Embedded Security and Management Engine by Xiaoyu Ruan, a security researcher with the Platform Engineering Group at Intel
Management: Imagine you manage and support 10,000 desktops and laptops. Remote access is essential (otherwise you'd effectively pay something like 2/3 of your support staff to cover time spent walking around), but typical remote access depends on an available processor, memory, OS, etc. For the many cases where those components aren't all available (something failed, OS is being updated, need to disable a component to diagnose it, etc.), you need out-of-band remote access, such as what Intel ME provides. It's a high-value service for corporate IT.
Security: You need an out-of-band machine to perform crypto functions, to protect the crypto functions against in-band attacks (e.g., in the OS, BIOS, applications ...). The out-of-band machine can then be used to verify the integrity of BIOS, OS, and other important things. It's also useful for DRM. If you're in corporate IT, you suddenly have a way to provide reasonable security guarantees across your 10,000 computers, a huge step forward.
If you are in corporate IT, or if you're a vendor wanting to enforce, protect, or hide your media or other proprietary bits, end-user control is undesirable. Obviously, that could be optional for owners of the computers who have other needs, but somehow it never works out that way ...
EDIT If you really want to learn about it, save your time and go to the source:
Platform Embedded Security Technology Revealed: Safeguarding the Future of Computing with Intel Embedded Security and Management Engine by Xiaoyu Ruan, a security researcher with the Platform Engineering Group at Intel