SafeXcel 2141 - High-Throughput Security Processor
The SafeXcel-2141 is a highly integrated "security system on a chip" incorporating
a sophisticated, general purpose DSP core, several high-performance cryptographic
function blocks and PCI, External Memory and Serial EEPROM interfaces.
Overview
The SafeNet SafeXcel-2141 is the first product in a family of embedded encryption
solutions. Based on the field-proven SafeXcel IP, the SafeXcel-2141 integrates into
networking and telecommunications equipment to enable high-throughput and high-security
VPNs.
With sustainable throughput of Triple DES IPSec transforms at OC-3 (155 Mbps) rates,
the SafeXcel- 2141 offers high performance at a very reasonable price point. The
on-chip SafeNet CGX Library of cryptographic functions simplifies security system
development for the OEM designer. In addition, the DSP core of the SafeXcel-2141
is fully user programmable, affording a high level of flexibility in customizing
and differentiating the final security system.
The SafeXcel-2141 is an enabling technology for the Internet, allowing OEMs to develop
the high-throughput and highly secure networking and telecommunications products
required for applications such as eCommerce and extranets.
SafeNet and Analog Devices (ADI) teamed up to create this new class of security
system-on-a-chip. Only the combination of SafeNet's patent-pending SecureIP Technology™
and ADl's IC design expertise could have come up with the industry's first DSP-based
solution for secure communications.
Safe at High Speeds
The SafeXcel-2141 architecture segregates security functions in a kernel separate
from standard processing functions. This hardware approach provides an unprecedented
level of security for commercial applications. The on-chip bus is automatically
isolated to prevent access to sensitive information such as keys.
Fast Development
Developing and implementing embedded security systems is a complex process. The
SafeXcel-2141 simplifies this process by incorporating in a single chip the accelerated
performance of critical security algorithms and high-level security functions using
the SafeNet CGX Library. The library executes on a high-performance, user-programmable
general purpose DSP Core. Designers concentrate on integrating security into their
system in the best and most cost-effective manner, instead of focusing on the development
of complex security algorithms or combining these algorithms into industry-standard
implementations like IPSec. All of that essential security work is done for the
designer by the SafeXcel-2141.
Enabling a High-Throughput VPN
When VPNs replace private leased lines for connecting branch offices, remote users
and corporate LANs, significant cost savings are realized. However, if the VPN is
neither fast enough nor secure enough to satisfy the corporate user, it will not
be successful. The SafeXcel-2141 enables OEM equipment manufacturers to design and
develop equipment for VPNs with very high throughput of encrypted and authenticated
data, and quickly set up security associations required to establish an exchange
of encrypted data. VPNs based on the SafeXcel-2141 are fast, safe and secure.
Data security is a functional imperative in our information-based society. The SafeXcel-2141
is an enabling technology for emerging Internet applications such as eCommerce,
Extranet, Broadband, and voice-over-IP.
SafeNet SafeXcel IP
With broad market acceptance through both the end user and OEM VPN markets, SafeNet
SafeXcel IP is one of the leading security
industry standards. Industry leaders such as Cisco Systems, RSA Security, Texas
Instruments, Samsung, Nokia, and Nortel Networks rely on it for their embedded VPN
solutions.
SafeNet SafeXcel IP provides the building blocks for security implementations that
enable organizations to use the Internet and other shared networks for private communications.
Providing a suite of VPN products, SafeNet offers a broad range of complete VPN
solutions for intranet, extranet, and remote access applications and are all built
on the time and field-tested SafeXcel IP.
Key Features
High Throughput
- 3-DES at 214 Mbps
- DES at 640 Mbps
- MD5 at 315 Mbps
- SHA-l at 253 Mbps
IPSec Transforms
- Triple-DES, SHA-1 at OC-3 rates (155 Mbps)
Strong Security
- Unencrypted keys never leave the SafeXcel, nor do they reside in unprotected memory
- Facilitates certification to FIPS 140-1
- Security functions isolated by DSP-controlled protection circuitry
Fast Development Time
- SafeNet CGX Toolkit and Library of Cryptographic functions embedded on-chip
- ADSP-218X DSP Core is user programmable
Specifications
- Lock rate: 40 MHz
- Voltage: 3.3 V
- Temperature: 0-70° C
- Package: 208-1ead Metric Quad
- Flat Pack
Support of Standards
The SafeXcel-2141 supports many standards used to implement secure systems:
- IPSec - ISAKMP/Oakley negotiations in all modes, IPSec transforms
per IETF RFC 2401 through 2412
- FIPS-140-1 - Strict U.S. Federal security standard
- X9.17 - International banking key management guideline