200 Gbps Hardware Accelerated Encryption System for FPGA Network Cards

200 Gbps Hardware Accelerated Encryption System for FPGA Network Cards
复制标题

适用于 FPGA 网卡的 200 Gbps 硬件加速加密系统

DOI:
10.1145/3266444.3266446
复制
发表时间:
2018
期刊:
Proceedings of the 2018 Workshop on Attacks and Solutions in Hardware Security
影响因子:
--
通讯作者:
N. Mentens
N. Mentens
中科院分区:
--
文献类型:
--
作者:
Zdenek Martinasek;J. Hajny;D. Smekal;L. Malina;Denis Matousek;Michal Kekely;N. Mentens

文献摘要

被引文献

相似文献

给出了基于IPSec协议的200Gbps现场可编程门阵列网卡加密系统的体系结构和实现方法。据我们所知,我们的硬件加密系统是第一个能够在市场上已有的网络设备上使用经过验证的算法在安全操作模式下以200 Gbps的全链路速度加密网络流量的系统。我们的实现基于AES(高级加密标准)加密算法和GCM(伽罗瓦计数器模式)操作模式,因此它提供传输数据的加密和认证。该设计是模块化的,并且可以很容易地被其他密码替换或扩展。详细描述了该方案的体系结构、VHDL语言仿真结果以及在基于Xilinx Virtex UltraScale+芯片的NFB-200G2QL网卡上的实际实现结果。我们还介绍了加密核心与IPSec子系统的集成,从而使得到的实现可以与其他系统互操作。
We present the architecture and implementation of our encryption system designed for 200 Gbps FPGA (Field Programmable Gate Array) network cards utilizing the IPsec (IP security) protocol. To our knowledge, our hardware encryption system is the first that is able to encrypt network traffic at the full link speed of 200 Gbps using a proven algorithm in a secure mode of operation, on a network device that is already available on the market. Our implementation is based on the AES (Advanced Encryption Standard) encryption algorithm and the GCM (Galois Counter Mode) mode of operation, therefore it provides both encryption and authentication of transferred data. The design is modular and the AES can be easily substituted or extended by other ciphers. We present the full description of the architecture of our scheme, the VHDL (VHSIC Hardware Description Language) simulation results and the results of the practical implementation on the NFB-200G2QL network cards based on the Xilinx Virtex UltraScale+ chip. We also present the integration of the encryption core with the IPsec subsystem so that the resulting implementation is interoperable with other systems.