Title :
Hardware Acceleration of OpenSSL Cryptographic Functions for High-Performance Internet Security
Author :
Khalil-Hani, Mohamed ; Nambiar, Vishnu P. ; Marsono, M.N.
Author_Institution :
Fac. of Electr. Eng., Univ. Teknol. Malaysia, Skudai, Malaysia
Abstract :
The transport layer security (TLS) protocol is currently the predominant method of implementing Internet security. This paper proposes an FPGA-based embedded system integrating hardware that accelerates the cryptographic algorithms used in the SSL/TLS protocol. OpenSSL, an open source implementation of the SLL v3 and TLS v1 protocol, is deployed in the proposed embedded system powered with a Nios-2 embedded soft-core processor. Nios2-Linux RTOS is applied, which serves to provide Ethernet connectivity, multitasking, and support for the OpenSSL library. Key cipher functions used in SSL-driven connections, which include AES-256 symmetric encryption, SHA-2 hashing, RSA-2048 publickey cryptography, are accelerated in hardware. The embedded cryptosystem is prototyped completely on an Altera Stratix II FPGA development board. Experimental results show significant improvements in performance of the SSL transactions when the proposed embedded cryptosystem is deployed in the networking system.
Keywords :
Internet; Linux; computer network security; cryptographic protocols; embedded systems; field programmable gate arrays; microprocessor chips; public domain software; public key cryptography; transport protocols; AES-256 symmetric encryption; Altera Stratix II FPGA development board; Ethernet connectivity; FPGA-based embedded system; Nios-2 embedded soft-core processor; Nios2-Linux RTOS; OpenSSL cryptographic functions; OpenSSL library; RSA-2048 publickey cryptography; SHA-2 hashing; SLL v3 protocol; SSL-TLS protocol; TLS v1 protocol; embedded cryptosystem; field programmable gate arrays; hardware acceleration; high-performance Internet security; key cipher functions; networking system; secure socket layer protocol; transport layer security protocol; Acceleration; Cryptographic protocols; Cryptography; Embedded system; Ethernet networks; Hardware; Internet; Multitasking; Power system security; Transport protocols; Network Security; OpenSSL; cryptographic algorithms; embedded system; hardware acceleration;
Conference_Titel :
Intelligent Systems, Modelling and Simulation (ISMS), 2010 International Conference on
Conference_Location :
Liverpool
Print_ISBN :
978-1-4244-5984-1
DOI :
10.1109/ISMS.2010.89