Vendor: CAST Category: Symmetric Crypto

AES-GCM Authenticated Encrypt/Decrypt Engine

The AES-GCM encryption IP core implements Rijndael encoding and decoding in compliance with the NIST Encryption Standard.

Overview

The AES-GCM encryption IP core implements Rijndael encoding and decoding in compliance with the NIST Advanced Encryption Standard. It processes 128-bit blocks, and is programmable for 128-, 192-, and 256-bit key lengths. 

Four architectural versions are available to suit system requirements. The Standard version (AES-GCM-S) is more compact, using a 32-bit datapath and requiring 44/52/60 clock cycles for each data block (128/192/256-bit cipher key, respectively). The Fast version (AES-GCM-F) achieves higher throughput using a 128-bit datapath and requiring 11/13/15 clock cycles for each data block depending on key size.

For applications where throughput is critical there are two additional versions. The High Throughput AES-GCM-X can process 128 bits/cycle and the Higher Throughput AES-GCM-X2 can process 256 bits/cycle respectively independent of the key size.

GCM stands for Galois Counter. GCM is a generic authenticate-and-encrypt block cipher mode. A Galois Field (GF) multiplier/accumulator is utilized to generate an authentication tag while CTR (Counter) mode is used to encrypt.  

Key features

  • Encrypts and decrypts using the AES Rijndael Block Cipher Algorithm 
  • NIST-Validated
  • Implemented according to the National Institute of Standards and Technology (NIST) Special Publication 800-38D
  • Processes 128-bit data in 32-bit blocks
  • Employs user-programmable key size of 128, 192, or 256 bits
  • Any size IV length
  • Easy integration & implementation
    • Works with a pre-expanded key or can integrate the optional key expansion function
    • Fully synchronous, uses only the rising clock-edge, single-clock domain, no false or multicycle timing paths, scan-ready, LINT-clean, reusable design
    • Simple input and output interface, optionally bridged to AMBA™ interfaces or integrated with a DMA engine.
  • Available in VHDL or Verilog source code format, or as a targeted FPGA
  •  

Block Diagram

Specifications

Identity

Part Number
AES-GCM
Vendor
CAST
Type
Silicon IP

Security

Crypto Algorithm
AES

Files

Note: some files may require an NDA depending on provider policy.

Provider

HQ: USA

Learn more about Symmetric Crypto IP core

From Classical CAN and CAN FD to CAN XL: Functional Safety and Security for Next-Generation In-Vehicle Communication

This article reviews the functional-safety attributes of Classical CAN and CAN FD, then explains how CAN XL preserves and extends them. It also discusses higher-layer safety protocols, fault-tolerant CAN XL controller implementations, and CANsec, the CAN XL security extension inspired by the MACsec model. Finally, it highlights how the CAST CAN XL controller IP and CANsec acceleration IP can support the efficient deployment of safety- and security-capable in-vehicle networks.

CANsec: Security for the Third Generation of the CAN Bus

CANsec is a resource-efficient solution for securing the CAN bus against the most common cyber security threats on software-defined vehicles. Here we show that the encryption and authentication of CAN XL frames are possible without latencies or loss...

Frequently asked questions about Symmetric Cryptography IP cores

What is AES-GCM Authenticated Encrypt/Decrypt Engine?

AES-GCM Authenticated Encrypt/Decrypt Engine is a Symmetric Crypto IP core from CAST listed on Semi IP Hub.

How should engineers evaluate this Symmetric Crypto?

Engineers should review the overview, key features, supported foundries and nodes, maturity, deliverables, and provider information before shortlisting this Symmetric Crypto IP.

Can this semiconductor IP be compared with similar products?

Yes. Buyers can compare this product with similar semiconductor IP cores or IP families based on category, provider, process options, and structured technical specifications.

×
Semiconductor IP