IPsec Engine
The IPsec Engine implements RFC4301 and other relevant RFCs, providing confidentiality, connectionless data integrity, data-origi…
Overview
The IPsec Engine implements RFC4301 and other relevant RFCs, providing confidentiality, connectionless data integrity, data-origin authentication and replay protection on OSI layer 3.
The scalable architecture provides low-latency, line rate acceleration of packet encapsulation, encryption and replay protection. Its modular design not only gives the ability to choose between different cryptographic algorithms, but also provides fine-grained control on classification features, packet formats, and more. Integration with a wide range of performance or area-optimized cryptographic IP cores allows unrivalled trade-off possibilities between throughput, area and latency.
Implementation aspects
At its very core, the IPsec Engine is completely technology-agnostic and can be integrated in a wide range of FPGA and ASIC technologies. On FPGA, the engine can use vendor-specific optimizations to reach very high throughput goals.
Key features
- Can aggregate several 10, 40 or 100 GbE link
- UDP encapsulation
- Compliant with RFC 4106, 4301, 4303, 7634
- Byte lifetime counters
- Supports AES-GCM-128/256
- Generic interface to TCAM
- 32 to 1024 bits datapath
- Supports IPv4 and IPv6
- ESP encapsulation/decapsulation
- 5-tuple classification
- Bypass mode
- Data interface: AMBA 4 AXI-Stream
- ASIC and FPGA
- Control interface: AMBA 4 APB
Block Diagram
Benefits
- Scalable architecture
- Low-latency
Applications
- Cloud computing
- Data center
- Edge router
- Edge networking for IoT data aggregation
What’s Included?
- Netlist or RTL
- Scripts for synthesis & STA
- Self-checking TestBench based on FIPS vectors
- Documentation
Specifications
Identity
Files
Note: some files may require an NDA depending on provider policy.
Provider
Learn more about IPsec / TLS IP core
Why nonce reuse can break AES-GCM security in embedded systems
AES in embedded systems: Understanding the most important AES modes
Embedded Security explained: Cryptographic Hash Functions
ML-KEM explained: Quantum-safe Key Exchange for secure embedded Hardware
How to design secure SoCs, Part V: Data Protection and Encryption
Frequently asked questions about IPsec / TLS IP cores
What is IPsec Engine?
IPsec Engine is a IPsec / TLS IP core from Secure-IC listed on Semi IP Hub.
How should engineers evaluate this IPsec / TLS?
Engineers should review the overview, key features, supported foundries and nodes, maturity, deliverables, and provider information before shortlisting this IPsec / TLS IP.
Can this semiconductor IP be compared with similar products?
Yes. Buyers can compare this product with similar semiconductor IP cores or IP families based on category, provider, process options, and structured technical specifications.