* cryptographic acceleration [Re: What's left over.]
@ 2002-11-02 7:09 Niels Provos
2002-11-02 8:10 ` James Morris
0 siblings, 1 reply; 4+ messages in thread
From: Niels Provos @ 2002-11-02 7:09 UTC (permalink / raw)
To: linux-kernel
While discussing various topics related to Linux and the BSDs, this
thread was mentioned.
>The question I have is whether such external hardware is even worth it
>any more for any standard crypto work. With a regular PCI bus
>fundamentally limiting throughput to something like a maximum of 66MB/s
>(copy-in and copy-out, and that's so theoretical that it's not even
The following paper
Performance Analysis of TLS Web Servers.
C. Coarfa, P. Druschel, and D. Wallach.
In Proceedings of NDSS '02, 2002.
http://www.isoc.org/isoc/conferences/ndss/01/2001/papers/dean02.pdf
analyzes the performance benefits from off-loading various crypto
operations to cryptographic hardware accelerators in comparison to
software crypto. This is in the context of web servers and TLS.
The paper concludes that hardware accelerators are useful for speeding
up public key cryptography, whereas symmetric encryption (RC4) does not
benefit from hardware acceleration very much.
For public-key cryptography, the used bus bandwidth is not significant
because data transfers are usually small.
On the other hand, there are some Ethernet cards that support inline
encryption so that not additional bus bandwidth is required to do both
public and symmetric key cryptography.
Things are slightly different for expensive symmetric encryption
algorithms like 3DES. See
A Study of the Relative Costs of Network Security Protocols
Stefan Miltchev, Sotiris Ioannidis, and Angelos D. Keromytis
http://www.cs.columbia.edu/~angelos/Papers/ipsecspeed.pdf
>Chris is write that crypto api is misdesigned if we want to use hardware
>cryptocards
Angelos Keromytis has designed an API for cryptographic services in
the kernel. The implementation provides a good abstraction.
Anyway, now you have some numbers.
Niels.
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: cryptographic acceleration [Re: What's left over.]
2002-11-02 7:09 cryptographic acceleration [Re: What's left over.] Niels Provos
@ 2002-11-02 8:10 ` James Morris
2002-11-02 16:00 ` Niels Provos
2002-11-03 18:01 ` David Dillow
0 siblings, 2 replies; 4+ messages in thread
From: James Morris @ 2002-11-02 8:10 UTC (permalink / raw)
To: Niels Provos; +Cc: linux-kernel
On Sat, 2 Nov 2002, Niels Provos wrote:
> On the other hand, there are some Ethernet cards that support inline
> encryption so that not additional bus bandwidth is required to do both
> public and symmetric key cryptography.
And this is precisely the case for which we have no detailed documentation
at this stage. Hardware which does this includes the Intel PRO/100S and
3Com 3CR990.
Any assistance from vendors in getting documentation on the crypto aspects
of cards would be highly appreciated.
- James
--
James Morris
<jmorris@intercode.com.au>
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: cryptographic acceleration [Re: What's left over.]
2002-11-02 8:10 ` James Morris
@ 2002-11-02 16:00 ` Niels Provos
2002-11-03 18:01 ` David Dillow
1 sibling, 0 replies; 4+ messages in thread
From: Niels Provos @ 2002-11-02 16:00 UTC (permalink / raw)
To: James Morris; +Cc: linux-kernel
On Sat, Nov 02, 2002 at 07:10:58PM +1100, James Morris wrote:
> And this is precisely the case for which we have no detailed documentation
> at this stage. Hardware which does this includes the Intel PRO/100S and
> 3Com 3CR990.
Intel steadfastly refuses to provide any kind of documentation about this
to open source projects. As this does not seem likely to change any time
soon, these cards won't be useful to us.
Niels.
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: cryptographic acceleration [Re: What's left over.]
2002-11-02 8:10 ` James Morris
2002-11-02 16:00 ` Niels Provos
@ 2002-11-03 18:01 ` David Dillow
1 sibling, 0 replies; 4+ messages in thread
From: David Dillow @ 2002-11-03 18:01 UTC (permalink / raw)
To: James Morris; +Cc: Niels Provos, linux-kernel
James Morris wrote:
>
> On Sat, 2 Nov 2002, Niels Provos wrote:
>
> > On the other hand, there are some Ethernet cards that support inline
> > encryption so that not additional bus bandwidth is required to do both
> > public and symmetric key cryptography.
>
> And this is precisely the case for which we have no detailed documentation
> at this stage. Hardware which does this includes the Intel PRO/100S and
> 3Com 3CR990.
Have this for 3cr990, driver coming soon. I have docs under NDA for the crypto
as well, hope to be more active getting that going as soon as I get some more
free time.
D
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2002-11-03 17:55 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2002-11-02 7:09 cryptographic acceleration [Re: What's left over.] Niels Provos
2002-11-02 8:10 ` James Morris
2002-11-02 16:00 ` Niels Provos
2002-11-03 18:01 ` David Dillow
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®