SafeXcel 2141 - High-Throughput Security Processor
The SafeXcel-2141 is a highly integrated "security system on a chip" incorporating a sophisticated,
general purpose DSP core, several high-performance cryptographic function blocks and PCI, External Memory and Serial EEPROM interfaces.
Overview
The SafeNet SafeXcel-2141 is the first product in a family of embedded encryption solutions. Based on the field-proven
SafeXcel IP, the SafeXcel-2141 integrates into networking and telecommunications equipment to enable high-throughput
and high-security VPNs.
With sustainable throughput of Triple DES IPSec transforms at OC-3 (155 Mbps) rates, the SafeXcel- 2141 offers high
performance at a very reasonable price point. The on-chip SafeNet CGX Library of cryptographic functions simplifies
security system development for the OEM designer. In addition, the DSP core of the SafeXcel-2141 is fully user programmable,
affording a high level of flexibility in customizing and differentiating the final security system.
The SafeXcel-2141 is an enabling technology for the Internet, allowing OEMs to develop the high-throughput and highly
secure networking and telecommunications products required for applications such as eCommerce and extranets.
SafeNet and Analog Devices (ADI) teamed up to create this new class of security system-on-a-chip. Only the combination
of SafeNet's patent-pending SecureIP Technology™ and ADl's IC design expertise could have come up with the
industry's first DSP-based solution for secure communications.
Safe at High Speeds
The SafeXcel-2141 architecture segregates security functions in a kernel separate from standard processing functions.
This hardware approach provides an unprecedented level of security for commercial applications. The on-chip bus is
automatically isolated to prevent access to sensitive information such as keys.
Fast Development
Developing and implementing embedded security systems is a complex process. The SafeXcel-2141 simplifies this process
by incorporating in a single chip the accelerated performance of critical security algorithms and high-level security
functions using the SafeNet CGX Library. The library executes on a high-performance, user-programmable general purpose
DSP Core. Designers concentrate on integrating security into their system in the best and most cost-effective manner,
instead of focusing on the development of complex security algorithms or combining these algorithms into industry-standard
implementations like IPSec. All of that essential security work is done for the designer by the SafeXcel-2141.
Enabling a High-Throughput VPN
When VPNs replace private leased lines for connecting branch offices, remote users and corporate LANs, significant cost
savings are realized. However, if the VPN is neither fast enough nor secure enough to satisfy the corporate user, it will
not be successful. The SafeXcel-2141 enables OEM equipment manufacturers to design and develop equipment for VPNs with
very high throughput of encrypted and authenticated data, and quickly set up security associations required to establish
an exchange of encrypted data. VPNs based on the SafeXcel-2141 are fast, safe and secure.
Data security is a functional imperative in our information-based society. The SafeXcel-2141 is an enabling technology
for emerging Internet applications such as eCommerce, Extranet, Broadband, and voice-over-IP.
SafeNet SafeXcel IP
With broad market acceptance through both the end user and OEM VPN markets, SafeNet
SafeXcel IP is one of the leading security industry standards. Industry
leaders such as Cisco Systems, RSA Security, Texas Instruments, Samsung, Nokia, and Nortel Networks rely on it for
their embedded VPN solutions.
SafeNet SafeXcel IP provides the building blocks for security implementations that enable organizations to use the
Internet and other shared networks for private communications. Providing a suite of VPN products, SafeNet offers a
broad range of complete VPN solutions for intranet, extranet, and remote access applications and are all built on the
time and field-tested SafeXcel IP.
Key Features
High Throughput
- 3-DES at 214 Mbps
- DES at 640 Mbps
- MD5 at 315 Mbps
- SHA-l at 253 Mbps
IPSec Transforms
- Triple-DES, SHA-1 at OC-3 rates (155 Mbps)
Strong Security
- Unencrypted keys never leave the SafeXcel, nor do they reside in unprotected memory
- Facilitates certification to FIPS 140-1
- Security functions isolated by DSP-controlled protection circuitry
Fast Development Time
- SafeNet CGX Toolkit and Library of Cryptographic functions embedded on-chip
- ADSP-218X DSP Core is user programmable
Specifications
- Lock rate: 40 MHz
- Voltage: 3.3 V
- Temperature: 0-70° C
- Package: 208-1ead Metric Quad
- Flat Pack
Support of Standards
The SafeXcel-2141 supports many standards used to implement secure systems:
- IPSec - ISAKMP/Oakley negotiations in all modes, IPSec transforms per IETF RFC 2401 through 2412
- FIPS-140-1 - Strict U.S. Federal security standard
- X9.17 - International banking key management guideline