SafeXcel™-1141 Security Co-Processor
Highly integrated VPN security co-processor optimized for very cost-sensitive designs
The SafeXcel-1141 security co-processor is designed specifically to accelerate IPSec and incorporates security engines for the following operations:
• Public Key operations
• Random Number Generation operations
The SafeXcel-1141 implements security features in hardware unavailable with any other chip solution in its price range, including:
• ESP and AH header insertion and validation, including SPI and replay counter processing
• Full AH 'mutable bit' processing, including IPv4 option and IPv6 extension headers
• HMAC ICV validation on inbound packets
• Automatic IV generation and insertion
With the SafeXcel-1141, host processors can off-load not only VPN packet transforms, but also cryptographic computations needed for key management handshaking (i.e. IKE) - which can seriously affect system performance. The public key processor in the SafeXcel-1141 typically provides more than 10 times the performance of a 32-bit RISC processor.
Cost-Effective Acceleration
The SafeXcel-1141 provides the optimum price-performance point for low-to mid-range systems. By accelerating only the critical and processor-intensive security functions, it provides an excellent value proposition.
Efficient Security Processing
The SafeXcel-1141 truly offloads the host processor, freeing it to execute its networking functions and leaving room for future feature growth. The system integration features in the SafeXcel-1141 were carefully designed to remove performance bottlenecks. By performing virtually all of the security protocol steps on-chip, multiple bus movements are avoided and operations may be pipelined to minimize latency.
AuthenTec also offers a Software Driver Developer's Kit (DDK) containing:
• Generic platform independent Driver Libraries, header & make files, test code, test applications and example drivers for x86/Linux 2.6.x platforms
• Extensive documentation set
• The DDK facilitates the software developer in easy porting to other platforms and software development
• The DDK supports integration with AuthenTec QuickSec toolkits
Specifications
Random Number Generator • Hardware-based nondeterministic Random Number Generator (RNG)
• Can internally generate session keys, IV's, nonce's, cookies, public & private keys, etc.
• Up to 1 Mbit of random data per second
DMA Block • 4-Channel, 32-bit DMA controller Supports DMA between Host bus interface and all internal registers and memories
PCI Interface • 32-bit 3.3V/5V tolerant bus interface
• 33MHz bus speed
• PCI v2.2 Compliant
• Bus Master and Target capability
Host Co-processor Interface • Can be interfaced with virtually any General-purpose processor, RISC processor, or Network Processor.
• "Glueless" interface to Motorola MPC-860, MPC-8260 and Virata Expansion Interface
• 16-bit or 32-bit interfaces up to 50MHz
• Supports DMA burst transfers up to 32-bytes
• Supports big or little endian architectures
Electrical • Core Power: 2.5V ±10%
• I/O Power: 3.3V ±10%
• PCI Voltages: 3.3V or 5V
• Core Clock Speed: 33 MHz
• Power Consumption: 0.35W typical
Package • 128 pin Plastic TQFP
• RoHS-compliant package