SafeXcel™-182 High-performance Security PCI-X Card
Highly integrated, 1.4 Gigabit/sec class high-speed network security card targeted to VPN applications in mid- to high-range network devices and appliances
With the SafeXcel 182-PCI Card accelerator card, system applications are relieved of the burden of processor-intensive crypto applications, which can drain system performance. This gives the host processor more free cycles to perform its main tasks, leaving room for additional features and tasks.
The SafeXcel 182-PCI Card delivers complete IPsec processing, including full header and trailer handling for ESP and AH, and provides acceleration for IKE handshaking, including the very processor-intensive public key computations.
Designed for the VPN Appliance Market and Optimized for IPsec
With the acceleration of VPN performance in mid-to high-end network devices and appliances as a design focus, the SafeXcel 182-PCI Card provides powerful and efficient IPsec processing. By accelerating only the critical and processor-intensive security functions, it delivers high security and robust performance at the best price in the industry. The SafeXcel 182-PCI Card also accelerates the algorithms used to implement SSL VPNs, allowing vendors to create multi-functional security appliances with a single security co-processor.
Efficient Data, Control, and Management Architecture
The SafeXcel 182-PCI Card incorporates separate interfaces for data, control and security association (SA) database access, enabling fast packet processing, highly efficient control and SA management systems. It also incorporates convenient and common hardware interfaces, supporting PCI-X, SPI-3 (optional) and S/DRAM memory interface capabilities to ensure easy integration with the widest variety of network and host processors, such as IBM NP4GS3, Intel IXP 2400, and Agere APP5xx.
AuthenTec offers a Software Driver Developer's Kit (DDK) containing:
• Generic platform independent Driver Libraries, header & make files, test code, test applications and
example drivers for x86/Linux 2.6.x platforms
• Extensive documentation set
• The DDK facilitates the software developer in easy porting to other platforms and software development
• The DDK supports integration with AuthenTec QuickSec toolkits
Applications
• Crypto Engine for Internetworking Devices
• Routers & Switches
• VPN Gateways
• Firewalls
• Server IPsec or SSL accelerator
• iSCSI Storage Security
• Workstation Security Module
IPsec Performance
Sustained ESP: PCI-X (data) + EMI(SA): AES and SHA-1
• 1.4 Gbps (1500-byte pkts)
• 900 Mbps (350-byte pkts)
• 500 Mbps (64-byte pkts)
3DES and SHA-1
• 1.3 Gbps (1500-byte pkts)
• 820 Mbps (350-byte pkts)
• 450 Mbps (64-byte pkts)
MPPE Performance (ARC4, 1500 byte packets)
• 1.3 Gbps sustained Stateless PCI-X
Crypto Block
• 2.8 Gbps Single-DES
• 2.2 Gbps Triple-DES
• 2.8 Gbps AES (256-bit key)
• 2.5 Gbps ARC4
• Supports modes: ECB; CBC
• Multi-mode Padding support
Hash Block
• 2.9 Gbps MD-5
• 2.9 Gbps SHA-1
• Implements IPsec AH and HMAC
• Includes mutable bit handler for AH,including IPv4 option and IPv6 extension headers
Public Key Accelerator
• Accelerator for math-intensive public key operations up to 2048-bit modulus.
• Diffie-Hellman negotiate: 2100 ops/sec (1024-bit modulus, 180 exponent)
• RSA 1024-bit sign: 1400 ops/sec
• RSA 1024-bit verify: 3900 ops/sec
• DSA Sign 160-bit exp: 1440 ops/sec
• DSA Verify 160-bit exp: 720 ops/sec
Protocol Support
• Full IPsec transforms including ESP, AH and bundled header/trailer processing
• Basic Encrypt, Decrypt, Hash and HMAC operations
Random Number Generator
• Hardware-based, Non-deterministic Random Number Generator
• Used to internally generate session keys, IV's nonce's, cookies, public & private keys, etc.
PCI-X/PCI Interface
• 32/64-bit 3.3V bus, 5V tolerant
• PCI: 33 or 66 MHz bus speeds
• PCI-X: 66 or 100 MHz bus speeds
• Up to 6.4 Gbps burst throughput
• PCI-X v1.0 compliant
• PCI v2.2 compliant
• Bus Master and Target capability
SPI-3 Interface (optional)
• Level 3 support
• 100 MHz max bus speed
• Two independent 32-bit interfaces: 1 RX; 1 TX
• Used for packet descriptor and packet data transport (In & Out)
• 3.2 Gbps burst transfers per direction.
On-board Memory
• SDRAM
• 8 MBytes (16 MBytes optional)
Electrical
• PCI Voltage: 3.3V / 5V ±10%
• PCI Bus Signaling: 3.3V (5V tolerant)
• Power Consumption: 5.5W Max
• Dynamic power reduction by programming lower clock speeds
Mechanical
• Universal PCI form factor (short card)
• 17.5 cm x 10.7 cm (6.875" x 4.2")
QuickSec IPsec Toolkit (license required)
• Dynamic addressing and config.
• L2TP
• IKE Configuration
• Legacy authentication
• XAUTH
• RADIUS client
• NAT (Network Address Translation)
• Application layer gateways
• NATT (NAT Traversal)
• Enables IPsec connectivity over NATed networks
• TCP/IP Firewall
• Application layer Gateways for common applications
CGX Library (license required)
• Advanced cryptographic library, with Integrated Key Management support
• Targeted to Host processor
• Symmetric Algorithms
• DES/3DES (HW accelerated)
• AES Rijndael (HW accelerated)
• ARC4 (HW accelerated)
• RC5
• Hash Algorithms
• SHA-1 (HW accelerated)
• MD5 (HW accelerated)
• RIPEMD-128
• RIPEMD-160
• Compression Algorithm
• Deflate
• Protocol Support
• IPsec ESP, AH (HW accelerated)
• IPsec IKE (HW accelerated)
• IPcomp
• SSL/TLS, WTLS