OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Crypto hw acceleration for openssl

From: Oliver Fromme (ollilurza.secnetix.de)
Date: Sun Apr 23 2006 - 14:16:13 CDT


Winston Tsai <wtsaihifn.com> wrote:
> I got roughly the same performance results when I use the openssl speed
> test with and without a hifn 7956 cryto card
> [...]
> Then I ran:
> Openssl speed des-cbc
> [...]
> My understanding is that openssl will detect the presence of an
> accelerator card and use it (via \dev\crypto) instead of the crypto
> library.
> Did I miss something here?

I don't know if the openssl speed test picks up the crypto-
dev hardware automatically. But ssh/scp definitely does.

I have run several tests on my VIA C3 Nehemiah+RNG+ACE,
which accelerates AES encryption. When the padlock(4)
module is loaded (it contains the Nehemiah ACE support),
ssh/scp performance is roughly doubled. It's quite
noticeable when transfering large files.

Best regards
   Oliver

PS: I can provide some benchmark numbers if interested.

--
Oliver Fromme, secnetix GmbH & Co. KG, Marktplatz 29, 85567 Grafing
Dienstleistungen mit Schwerpunkt FreeBSD: http://www.secnetix.de/bsd
Any opinions expressed in this message may be personal to the author
and may not necessarily reflect the opinions of secnetix in any way.

"The scanf() function is a large and complex beast that often does
something almost but not quite entirely unlike what you desired."
        -- Chris Torek
_______________________________________________
freebsd-securityfreebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribefreebsd.org"