14-12-2017 дата публикации
Номер: US20170359214A1
Принадлежит:
An Internet Protocol Security (IPSec) acceleration method, an apparatus, and a system, where the method includes generating, by an Internet Key Exchange (IKE) device, an IKE link establishment session packet according to an IPSec configuration parameter and a security policy in a security policy database (SPD), sending, by the IKE device, the IKE link establishment session packet to a peer device, establishing a security association (SA) with the peer device, and sending, by the IKE module, the SA to a data forwarding device. The IKE device and the data forwarding device are discrete devices. In this way, the IKE device and the data forwarding device can be deployed in different devices in order to increase the IPSec speed. 1. An Internet Protocol Security (IPSec) acceleration method , comprising:generating, by an Internet Key Exchange (IKE) device, an IKE link establishment session packet according to an IPSec configuration parameter and a security policy in a security policy database (SPD);sending, by the IKE device, the IKE link establishment session packet to a peer device;establishing, by the IKE device, a security association (SA) with the peer device; andsending, by the IKE device, the SA to a data forwarding device, andwherein the IKE device and the data forwarding device are discrete devices.2. The method according to claim 1 , wherein the IKE device is deployed on a field-programmable gate array (FPGA) chip of an accelerator card claim 1 , and wherein generating the IKE link establishment session packet comprises:processing concurrently, by the IKE device using a Montgomery algorithm according to the IPSec configuration parameter and the security policy that is in the SPD, modular multiplication required for IKE session link establishment;generating, by the IKE device, a googol;calculating, by the IKE device, a Diffie-Hellman key value; andgenerating, by the IKE device, the IKE link establishment session packet.3. The method according to claim 1 , wherein ...
Подробнее