| 数据搜索系统,热门电子元器件搜索 |
|
5812-DS01-R 数据表(PDF) 79 Page - Broadcom Corporation. |
|
|
|||||||||||||||||||||||||||||
5812-DS01-R 数据表(HTML) 79 Page - Broadcom Corporation. |
|
79 / 84 page ![]() Advance Data Sheet BCM5812 3/11/03 B roa dcom Co rpo rat ion Document 5812-DS01-405-R Alignment Restrictions Page 71 MD5 OR SHA-1 FOLLOWED BY MD5 OR SHA-1 SSL or TLS master key and connection key derivations require multiple successive hash operations, with the output of some operations feeding into the input of the next. In general, the BCM5812 should not be used with chained authentication operations where the output of one hash operation is used as input by the immediately following operation in the packet descriptor list. This applies to any of MD5 Hash, SHA-1 Hash, SSL-MAC, or TLS-HMAC followed by MD5 Hash, SHA-1 Hash, SSL-MAC, or TLS-HMAC. There are three recommendations: • Interleave an independent operation between two dependent operations. For the SSL key derivation example, perform the SHA-1 operations first, followed by the MD5 operations. If three operations are required to generate 48 bits of key material, the MD5 input would use the SHA-1 output from three operations prior. • Put the dependent operations in separate MCRs. • Assure that the output of the first operation is not the first 64 bytes input by the next operation. At an operation transition, the BCM5812 may prefetch up to 64 bytes of input while it stages completion of the previous operation. 3DES/HMAC FOLLOWED BY 3DES/HMAC The authentication function performed by 3DES/HMAC-MD5 or SHA-1 can be used for TLS key derivation with the 3DES option bit zero in the flags word in the command context. In this case, the same apply comments as under “MD5 or SHA-1 Followed by MD5 or SHA-1” on page 71. SSL-MAC OR TLS-HMAC FOLLOWED BY SSL-3DES In case of a TLS-MAC or SSL-MAC operation followed by an SSL-3DES operation, the chip starts prefetching the input data (64 bytes) for the 3DES before it writes out the hash of the first operation. The input data read of the second operation is suspended as the BCM5812 writes out the hash of the first operation. It then comes back to complete the data input read for SSL-3DES. In this case, the same suggestions as in “MD5 or SHA-1 Followed by MD5 or SHA-1” on page 71 should be applied. ALIGNMENT RESTRICTIONS Table 30 shows alignment requirements for all memory-resident data in IPsec, SSL, and TLS encryption and authentication operations. The flexibility with respect to input packet payload data allows extreme combinations to be supported. For instance, a packet with 16,000 bytes of input payload data could be described as a chain of 16,000 descriptors, with each descriptor holding one single byte. The BCM5812 handles such an extreme situation correctly from a functional standpoint, albeit with reduced performance from the huge number of descriptor fetches. For ARCFOUR encryption, data can be any length, not necessarily multiple of 32-bit words. In this case, the last word of an output data buffer may contain one, two, three, or four bytes of actual ARCFOUR data. The non-ARCFOUR data in the word could be anything and should be ignored by software. The output fragment length for the data buffer should indicate the actual ARCFOUR data length. It may not be multiple of 4 bytes. |
|
链接网址 |
| ALLDATASHEET是否为您带来帮助? [ DONATE ] |
关于 Alldatasheet | 广告服务 | 联系我们 | 隐私政策 | 数据表链接 | 链接交换 | 制造商名单 All Rights Reserved©Alldatasheet.com |
| Russian : Alldatasheetru.com | Korean : Alldatasheet.co.kr | Spanish : Alldatasheet.es | French : Alldatasheet.fr | Italian : Alldatasheetit.com Portuguese : Alldatasheetpt.com | Polish : Alldatasheet.pl | Vietnamese : Alldatasheet.vn Indian : Alldatasheet.in | Mexican : Alldatasheet.com.mx | British : Alldatasheet.co.uk | New Zealand : Alldatasheet.co.nz |
|
Family Site : ic2ic.com |
icmetro.com |