Logo image
High-Throughput Scalable Architecture of the IPSec Processor
Thesis

High-Throughput Scalable Architecture of the IPSec Processor

Feng-Chi Lu
Masters, 國立清華大學, 資訊工程學系
2007

Abstract

網路協定安全 效能 可調整 架構 IPSec Throughput scalable architecture
With the rapid growth of applications in Internet and wireless communication, the security for transmitting nformation on public network has become a fundamental issue. The Internet Protocol Security (IPSec) standard is developed by the Internet Engineering Task Force (IETF) to provide the security services at the IP layer. IPSec implemented by software is not sufficient to handle the enormous traffic generated by modern network applications. In this thesis, we propose the scalable architecture for IPSec. It provides encryption and authentication services. The cryptographic algorithms supported in our design are AES-ECB, AES-CBC, AES-CTR, AES-CCM, HMAC-MD5 and HMAC-SHA-1. The proposed architecture can process multiple packets in parallel using our IPSec processing hardware. For high throughput requirement, the architecture of multi-IPSec processing block can achieve more than 20 Gbps throughput. The proposed architecture is platform based and scalable, which provides tradeoff between performance and cost for a wide range of network applications. In addition, a performance evaluation method is provided for the proposed architecture. According to this evaluation model, we can choose the suitable architecture to implement for different requirements in network security. If the requirements of confidentiality and authentication are imbalance, the evaluation model can provide different parameters to maximize the overall throughput.

Metrics

1 Record Views

Details

Logo image