Vendor: IP Cores, Inc. Category: IPsec / TLS

IPsec Security Processor

Core implements the IPsec and SSL/TLS security standard at high data rates that require the cryptographic processing acceleration.

Overview

Core implements the IPsec and SSL/TLS security standard at high data rates that require the cryptographic processing acceleration. The ISP1-128 core is tuned for applications with the data rates of 10-100 Gbps in advanced ASIC geometries.

The design is fully synchronous and available in both source and netlist form.

Key features

  • Support for IPv4 and IPv6 packets
  • Support for the IPsec ESP and AH protocols:
    • Insertion / removal of headers and trailers; internal padding
    • Transport and tunnel modes of operation
    • Integrity Check Value (ICV) insertion and validation
    • Transport and Tunnel Adjacency (AH+ESP combination) support
  • Support for IPsec ESP encryption algorithms per RFC 4835:
    • NULL
    • AES-CBC (128- and 256-bit keys)
    • TripleDES-CBC
  • Support for IPsec ESP (and AH for –AH option) authentication algorithms per RFC 4835:
    • HMAC-SHA1-96
    • AES-XCBC-MAC-96
  • Optional support for SSL 2.0, 3.0 and TLS 1.0. 1.1, and 1.2 (-SSL option). Capable of supporting simultaneous SSL/TLS and IPsec data flows. SSL/TLS cipher support includes:
    • Block ciphers with hash-based authentication
    • AEAD ciphers
  • Support for SSL / TLS block ciphers:
    • RC4
    • TripleDES-CBC
    • AES-CBC (128-, 192- and 256-bit keys)
    • AES-GCM (128- and 256-bit) (-GCM option)
  • Support for SSL / TLS hashes:
    • MD5  SHA-1
    • SHA-256
    • SHA-384
    • SHA-512
  • Additional cryptographic algorithms available upon request
  • Built-in cryptographically secure pseudorandom number generator
  • Replay protection
  • Scalable high performance. Scaling is achieved through adjustable number of encryption engines inside and configurable throughput of the connection parameters memory .
  • FIFO-like interface with flexible bit width; simple integration into the datapath.
  • Dedicated encryption and decryption configurations, duplex option with shared connection context memory available.
  • Support for Galois Counter Mode Encryption and authentication (GCM), Galois Message Authentication (GMAC)
  • Flow-through design
  • Built-in connection parameters database and lookup engine
  • OpenSSL integration (integration with other packages upon request)
  • Optional statistics block
  • No segmentation/reassembly support in the IPsec transport mode

Specifications

Identity

Part Number
ISP1-128
Vendor
IP Cores, Inc.
Type
Silicon IP

Files

Note: some files may require an NDA depending on provider policy.

Provider

Learn more about IPsec / TLS IP core

Bringing IPsec into the Quantum Safe Era

Over the next five years, all security protocols and public key cryptography will undergo a comprehensive overhaul to ensure quantum safety. This represents the most significant change in these domains since the advent of public key cryptography.

How to design secure SoCs, Part V: Data Protection and Encryption

In today’s connected world, where data is a crucial asset in SoCs, Part V of our series explores how to protect and encrypt data, whether at rest, in transit, or in use building on our earlier blog posts of the series: Essential security features for digital designers, key management, secure boot, and runtime integrity.

Frequently asked questions about IPsec / TLS IP cores

What is IPsec Security Processor?

IPsec Security Processor is a IPsec / TLS IP core from IP Cores, Inc. listed on Semi IP Hub.

How should engineers evaluate this IPsec / TLS?

Engineers should review the overview, key features, supported foundries and nodes, maturity, deliverables, and provider information before shortlisting this IPsec / TLS IP.

Can this semiconductor IP be compared with similar products?

Yes. Buyers can compare this product with similar semiconductor IP cores or IP families based on category, provider, process options, and structured technical specifications.

×
Semiconductor IP