a
APPLICATIONS
Security Coprocessor for High Speed Networking Prod-
ucts (Routers, Switches, Hubs)
Cryptographic Core for Firewalls, Hardware Encryptors,
and More
Crypto Peripheral for Implementing Secure NIC Adapt-
ers (10/100 Ethernet, Token Ring, ISDN)
Secure Modem-on-a-Chip (V.34, ADSL)
FEATURES
DES CRYPTO BLOCK
640 Mbps Sustained Performance鈥擲ingle DES
214 Mbps Sustained Performance鈥擳riple DES
Supports All Modes: ECB; CBC; 64-Bit OFB; and 1-, 8-,
64-Bit CFB. Includes Automatic Padding
Implements IPsec ESP Transforms Autonomously at
OC-3 (155 Mbps) Rates (3-DES, SHA-1)
HASH BLOCK
Hardware-Based SHA-1 and MD-5 Hashing
253 Mbps Sustained Performance鈥擲HA-1
315 Mbps Sustained Performance鈥擬D-5
Implements IPsec AH and HMAC Transforms
R
DSP
ADSP-2141L
SECURE KERNEL CONTROL
Tamper-Resistant Isolation of Cryptographic Functions
Enforces Security Perimeter Around Crypto Functions
and Crypto Storage Locations
Anticloning Protection
Secure Algorithm Download
SafeNet CGX LIBRARY
On-Chip SafeNet CGX Crypto Library with Flexible CGX
API
Includes
Chained
and
Parallel Execution
Commands
Such as Hash-and-Encrypt
Embodied as 32K Words (32K 24) Kernel Program
Mask-Programmed into On-Chip ROM
On-Chip Protected 4K 16 Security Scratchpad RAM
RANDOM NUMBER GENERATOR
Hardware-Based Nondeterministic Random Number
Generator
Generates Internal Session Keys That Are Never
Exposed Outside of the SafeNet DSP
Redundant Fail-Safe Design
Up to 1.3 Mbits of Random Data Available per Second
FUNCTIONAL BLOCK DIAGRAM
KERNEL
MODE
CONTROL
BUS_MODE
IDMA MODE
INTERRUPTS
FLAGS
IDMA
BUS
16
IDMA
INTERFACE
16
ADSP-218x
DSP CORE
16-
OR
32-BIT
BUS
PCI MODE
DMA-32
CONTROLLER
32
PCI OR
CARDBUS
INTERFACE
32
SPORT 0
SERIAL
PORTS
SPORT 1
KERNEL ROM
32K 24
PROG ROM
16K 24
DATA ROM
16K 16
TIMER
PROTECTED
KERNEL
RAM
(4K 16)
ENCRYPT
BLOCK
(DES, 3-DES)
HASH
BLOCK
(MD-5, SHA-1)
RNG
BLOCK
PUBLIC KEY
ACCELERATOR
BUS_MODE
EMI BUS
INTERRUPT
CONTROLLER
APPLICATION
REGISTERS
EXTERNAL
MEMORY
INTERFACE
32-BITS
DATA
LASER
VARIABLE
STORE
SERIAL
EEPROM
INTERFACE
BUS_SEL
26-BITS
ADDR
PF7/INT_H
RAM/ROM
SafeNet is a registered trademark of Information Resource Engineering (IRE).
REV. 0
Information furnished by Analog Devices is believed to be accurate and
reliable. However, no responsibility is assumed by Analog Devices for its
use, nor for any infringements of patents or other rights of third parties
which may result from its use. No license is granted by implication or
otherwise under any patent or patent rights of Analog Devices.
One Technology Way, P.O. Box 9106, Norwood, MA 02062-9106, U.S.A.
Tel: 781/329-4700
World Wide Web Site: http://www.analog.com
Fax: 781/326-8703
漏 Analog Devices, Inc., 2000