SafeNet, The Foundation of Information Security
 
 
Language: English English Japanese Chinese Chinese Spanish Portuguese
sample image
Blank
Email this page Print this page Feedback
   SafeXcel IP Security Packet Engine
Blank
Innovations in information security.
Blank

SafeXcel IP Security Packet Engine

Silicon-proven Intellectual Property (IP) for accelerating IPSec, SSL/TLS/DTLS, SRTP and MACsec

Features

IPSec

  • IPSec packet transforms
  • Support for latest RFC's (RFC-4302, 4303 and 4308), incl. ESN
  • IPv4 and IPv6 support
  • Header and trailer processing
  • Mutable-bit handling
  • 1Gbit/s (ESP,AES, SHA-1,1500-byte packets)

SSL / TLS/DTLS

  • SSL, TLS and DTLS single pass packet transforms with full header processing
  • One-pass hash-then-encrypt inbound transforms
  • 1Gbit/s (AES, SHA-1, 1500-byte packets)

SRTP

  • SRTP packet transforms
  • ROC removal and TAG generation and insertion
  • Variable offset of header length per packet
  • 1 Gbit/s (AES-ICM, SHA-1, 1500-byte packets)

MACsec

  • Header insertion and removal
  • Integrity only or integrity+confidentiality mode
  • 1.8Gbit/s (AES-GCM, 1500-byte packets)

Basic cryptographic operations

  • (Triple-)DES: ECB, CBC, OFB, CFB modes
  • AES: ECB, CBC, ICM, CTR modes.
  • ARC4: stateful and stateless modes
  • HMAC (Basic, IPSec, TLS, SRTP), MAC (SSL), GMAC (IPSec) and AES-XCBC (IPSec)
  • AES-GCM (MACsec, IPSec)
  • AES-CCM (WLAN, IPSec
  • SHA-1, SHA-2 (224, 256, 384 and 512-bit)
  • MD5

Public-Key Accelerator

  • Supporting RSA, DSA, DH and ECC
  • Modulus sizes up to 4k
  • RSA 1024-bit sign (CRT): 5.6 ms
  • Local memory for storage of operands and results
  • Interrupt output

True Random Number Generator

  • Non-deterministic noise source
  • Generation of keys, IVs, cookies and nonces
  • ANSI X9.17 Annex C / ANSI X9.31 Annex A post-processing

Pseudo-Random Number Generator

  • Generation of IVs for DES, Triple-DES, and AES
  • ANSI X9.17 Annex C / ANSI X9.31 Annex A post-processing