SafeXcel™-172 PCI Card
Cost-effective security PCI Card designed for mid-range VPN appliance market
The plug-in SafeXcel 172-PCI Card provides leading-edge IPsec acceleration features and comprehensive algorithms including DES, 3DES, AES, SHA-1, MD5, HMAC, Public-Key Acceleration, True Random Number Generation.
With this accelerator, host system applications are no longer burdened by processor-intensive crypto applications that can seriously affect system performance. Thus the host processor receives more free cycles for its main tasks and additional features and tasks.
Providing unmatched performance at a very attractive price, the SafeXcel 171-PCI Card delivers complete IPsec processing, including full header and trailer handling for ESP and AH. It also provides acceleration for IKE handshaking, including the very processor-intensive public key computations.
AuthenTec offers a Software Driver Developer's Kit (DDK) containing:
• Generic platform independent Driver Libraries, header & make files, test code, test applications and example drivers for x86/Linux 2.6.x platforms
• Extensive documentation set
• The DDK facilitates the software developer in easy porting to other platforms and software development
• The DDK supports integration with AuthenTec QuickSec toolkits
Applications
• Broadband access devices (xDSL, Cable Modem, NIC)
• SOHO router
• Set-top box / Internet appliances
• Wireless (Bluetooth, 802.11x, 2.5G/3G)
Specifications
Environment
• Operating Temperature: 0 – 70°C
• Storage Temperature: 0 – 85°C
• Operating Humidity: 10 – 90% RH
Electrical
• PCI Voltage: 5V ±10%
• PCI Bus Signaling: 3.3V or 5V
• Power Consumption: 1W typical
Mechanical
• Standard PCI ‘short’ card
• 17.5 cm x 10.7 cm
• 6.875” x 4.2”
• Also available: PCI mini card
• 12 cm x 5.1 cm
• 4.75” x 2”
Features & Benefits
IPsec Throughput
- 290 Mbps sustained ESP (AES, MD5, 1500 byte packets)
- 260 Mbps sustained ESP (3-DES, SHA-1, 1500 byte packets)
- 90 Mbps sustained ESP (3-DES, SHA-1, 64 byte packets)
Symmetric Encryption Block
- 1056 Mbps Single-DES
- 352 Mbps Triple-DES
- 845 Mbps AES
- Supports all modes: ECB; CBC; OFB; 1, 8, 64-bit CFB(DES), 128-bit CFB(AES)
Multi-mode Padding support
- Implements IPsec ESP transforms
Hash Block
• Hardware-based MD-5 and SHA-1
• 520 Mbps MD-5
• 417 Mbps SHA-1
• Implements IPsec AH and HMAC
• Includes mutable bit handler for AH, including IPv4 option and IPv6 extension headers
Public Key Accelerator
• Accelerator for math-intensive public key operations up to 2048-bit modulus size
• Diffie-Hellman negotiate: 5.1ms (1024-bit modulus, 180 exponent)
• RSA 1024-bit sign: 8.4ms
• RSA 1024-bit verify: .85ms
• DSA Sign: 8.9ms, DSA Verify: 20.5ms
Protocol Support
• Full IPsec transforms including ESP, AH and bundled header/trailer processing
• Basic Encrypt, Decrypt, Hash and HMAC operations
• Random Number Generator
• Hardware-based Non-deterministic
Random Number Generator
• Can generate session keys, IV’s, public and private key seeds, etc.
• Up to 1 Mbit of Random Data per sec.
CGX Library
• Advanced cryptographic library, with Integrated Key Management support Targeted to Host processor
• Symmetric Algorithms
- DES/3DES (hardware accelerated)
- AES Rijndael
- ARC4, ARC5
Hash Algorithms
- SHA-1 (hardware accelerated)
- MD5 (hardware accelerated)
- RIPEMD-128
- RIPEMD-160
Compression Algorithm
• Deflate Protocol Support
• IPsec ESP & AH (hardware accelerated)
• IPsec IKE (hardware accelerated)
• IPcomp
• SSL, WTLS
PCI Interface
• 32-bit 3.3V or 5V bus interface
• 66 MHz max bus speed
• PCI v2.2 Compliant
• Bus Master and Target Capability