Browse > Article
http://dx.doi.org/10.13089/JKIISC.2014.24.6.1065

Accelerated VPN Encryption using AES-NI  

Jeong, Jin-Pyo (Sungkyungkwan University)
Hwang, Jun-Ho (Hansei University)
Han, Keun-Hee (Korea University)
Kim, Seok-Woo (Hansei University)
Abstract
Considering the safety of the data and performance, it can be said that the performance of the AES algorithm in a symmetric key-based encryption is the best in the IPSec-based VPN. When using the AES algorithm in IPSec-based VPN even with the expensive hardware encryption card such as OCTEON Card series of Cavium Networks, the Performance of VPN works less than half of the firewall using the same hardware. In 2008, Intel announced a set of 7 AES-NI instructions in order to improve the performance of the AES algorithm on the Intel CPU. In this paper, we verify how much the performance IPSec-based VPN can be improved when using seven sets of AES-NI instruction of the Intel CPU.
Keywords
VPN; IPSec; AES; AES-NI;
Citations & Related Records
연도 인용수 순위
  • Reference
1 Kahraman Akdemir, "Breakthrough AES Performance with Intel AES New Instructions," White Paper, 2010.
2 Adrian Hoban, "Using Intel AES-New Instructions and PCLMULQDQ to Significantly Improve IPSec Performance on Linux," White Paper, 324238-001, Aug. 2010.
3 Vinodh Gopal, "Optimized Galois- Counter-Mode Implementation on Intel Architecture Processors," Aug. 2010
4 "Intel Advanced Encryption Standard New Instructions(AES-NI) Ecosystem March 2013 Update http://www.intel.com/content/dam/www/public/us/en/documents/specification-updates/aes-ni-ecosystem-update.pdf
5 Oracle Solaris, x86 Intel AES-NI Optimization, http://docs.oracle.com/cd/E19253-01/821-2301/gjxnz/
6 Hyunjin Ahn and Choi Wanseong, "Performance comparison of ARIA-CCM and ARIA-GCM in ARM9", "Kookmin University, KISA," "KICS" 108-109
7 strong swan User Documentation Ipsec.conf, http://wiki.strongswan.org/projects/strongswan/wiki/IKEv2CipherSuites