Next: Evaluation
Up: OpenBSD Cryptographic Framework
Previous: OpenBSD Cryptographic Framework
Although the cryptographic
framework does not directly take advantage of ethernet cards that
support IPsec processing offloading (since they are not
general-purpose cryptographic accelerators), we extended the IPsec
stack to use them. Unfortunately, at the time of writing this paper,
driver support for these cards was not completed and thus we could not
measure their performance. The cards of this type we are familiar with
are 100Mbps full-duplex, and it seems reasonable (given our results
with dedicated cryptographic processors) to assume that they can
achieve that performance. Unfortunately, at the time this paper was
written, we did not have enough information to write a device driver
that could take advantage of such features.
Stefan Miltchev
4/17/2002