Vendor: Algotronix Ltd. Category: MACsec

Multiple SecY IEEE 802.1ae MACSEC IP Core for 40Gbit Ethernet

Ethernet is a ubiquitous, efficient and cost-effective transport mechanism for unified communication of voice, data and video ove…

Overview

Ethernet is a ubiquitous, efficient and cost-effective transport mechanism for unified communication of voice, data and video over a shared medium, but it was not designed with secure networks in mind and is not inherently secure. MACSEC can be applied to any Ethernet network and as well as its use in commercial networks is eminently well suited to overlay an additional layer of security to military and governmental communications systems. MACSEC also provides an exciting opportunity to add standards based security to Ethernet connected embedded systems.

The concept of the MACsec scheme is that nodes on a network form a set of trusted entities. Each node can receive both encrypted or plaintext messages, and the system policy can dictate how each is handled. Unlike protocols such as IPsec which are end-to-end and session based, the MACSEC decrypts and verifies each packet at every node. Packets that require routing to other trusted nodes in the system are then encrypted and forwarded.

The MACSEC core is a high performance pipelined implementation of IEEE standard 802.1ae. The core is built on Algotronix' pipelined implementation of the AES-GCM encryption algorithm which itself builds on our G3 AES core. This version of the core supports multiple 'virtual' MACSec SecYs on a single hardware encryptor which allows for a Multi-Access LAN as specified in section 11-8 of the standard. Each SecY has a single secure channel for transmit so unless multiple SecYs are supported an end point would use the same key to send packets to all the end-points it wished to communicate with. For example, if it wished to communicate with endpoints A and B then B would have access to the key used to encrypt messages for A. Multiple SecYs provide more control of security - for example a separate SecY could be used for node A and node B after and node B would no longer be provided with the key to decrypt messages intended for node A.

The Algotronix MACSEC core is supplied with a VHDL testbench which generates a sequence of test packets and compares the responses of the IP core to the output generated by a behavioral model of MACSEC. It is supplied as VHDL source code and can be configured using a number of VHDL generic parameters to select only those features which are required in order to conserve area. The core can also be supplied in Verilog on request. The MACSEC core provides both transmit and receive channels. The core is an easy to use fully synchronous design with a single clock and separate flow control on the transmit and receive channels. The core has been designed for efficiency in modern FPGAs and makes full use of FPGA specific features such as dual port memory blocks.

Key features

  • Complies with IEEE 802.1ae standard
  • Based on the Algotronix AES-GCM-1G product
  • Supports 128 bit keys as standard, with 256 bit key option available
  • Targets all modern FPGA families from Xilinx, Altera, Microsemi and Lattice
  • Supplied as VHDL or Verilog source code to allow customers to conduct their own code review
  • Supplied with comprehensive test bench containing a behavioral model of MACSec developed by Algotronix

Specifications

Identity

Part Number
MACSEC-1G
Vendor
Algotronix Ltd.
Type
Silicon IP

Files

Note: some files may require an NDA depending on provider policy.

Provider

HQ: United Kingdom

Learn more about MACsec IP core

Enhancing Ethernet Security with MACsec

Ethernet was originally designed for high-speed data transfer and interoperability between devices. However, traditional Ethernet does not provide built-in mechanisms for securing data traffic, such as encryption or authenticity protection. This is where MACsec comes into the picture.

O-RAN Fronthaul Security using MACsec

With 5G being deployed for time-sensitive applications, security is becoming an important consideration. At the same time, Open Radio Access Networks (RAN) are gaining more interest from mobile carriers and governments. Yet, Open RAN networks have serious security challenges, especially in the RAN fronthaul where there are strict timing requirements. This paper proposes MACsec as an efficient data link layer security solution that can assist in meeting these challenges.

Frequently asked questions about MACsec IP cores

What is Multiple SecY IEEE 802.1ae MACSEC IP Core for 40Gbit Ethernet?

Multiple SecY IEEE 802.1ae MACSEC IP Core for 40Gbit Ethernet is a MACsec IP core from Algotronix Ltd. listed on Semi IP Hub.

How should engineers evaluate this MACsec?

Engineers should review the overview, key features, supported foundries and nodes, maturity, deliverables, and provider information before shortlisting this MACsec IP.

Can this semiconductor IP be compared with similar products?

Yes. Buyers can compare this product with similar semiconductor IP cores or IP families based on category, provider, process options, and structured technical specifications.

×
Semiconductor IP