18-Security Configuration Guide

HomeSupportRoutersSR6602-I[IE] SeriesConfigure & DeployConfiguration GuidesH3C SR6602-I[IE] AI-Powered ICT Converged Gateways Configuration Guides(V9)-R9119-6W10018-Security Configuration Guide
04-Crypto engine configuration
Title Size Download
04-Crypto engine configuration 42.75 KB

Configuring crypto engines

About crypto engines

Crypto engines encrypt and decrypt data for service modules.

Crypto engine types

Crypto engines include the following types:

·     Hardware crypto engines—A hardware crypto engine is a coprocessor integrated on a CPU or hardware crypto card. Hardware crypto engines can accelerate encryption/decryption speed, which improves device processing efficiency. You can enable or disable hardware crypto engines globally as needed. By default, hardware crypto engines are enabled.

·     Software crypto engines—A software crypto engine is a set of software encryption algorithms. The device uses software crypto engines to encrypt and decrypt data for service modules. They are always enabled. You cannot enable or disable software crypto engines.

Crypto engine processing mechanism

If you disable hardware crypto engines, the device uses only software crypto engines for data encryption/decryption. If you enable hardware crypto engines, the device preferentially uses hardware crypto engines. If the device does not support hardware crypto engines, or if the hardware crypto engines do not support the required encryption algorithm, the device uses software crypto engines for data encryption/decryption.

Crypto engines provide encryption/decryption services for service modules, for example, the IPsec module. When a service module requires data encryption/decryption, it sends the desired data to a crypto engine. After the crypto engine completes data encryption/decryption, it sends the data back to the service module.

Verifying and maintaining crypto engines

Displaying crypto engine information

To display crypto engine information, execute the following command in any view:

display crypto-engine

Displaying and clearing crypto engine statistics

To display crypto engine statistics, execute the following command in any view:

display crypto-engine statistics [ engine-id engine-id slot slot-number ]

To clear crypto engine statistics, execute the following command in user view:

reset crypto-engine statistics [ engine-id engine-id slot slot-number ]

 

  • Cloud & AI
  • InterConnect
  • Intelligent Computing
  • Intelligent Storage
  • Security
  • SMB Products
  • Intelligent Terminal Products
  • Product Support Services
  • Technical Service Solutions
All Services
  • Resource Center
  • Policy
  • Online Help
  • Technical Blogs
All Support
  • Become A Partner
  • Partner Policy & Program
  • Global Learning
  • Partner Sales Resources
  • Partner Business Management
  • Service Business
All Partners
  • Profile
  • News & Events
  • Online Exhibition Center
  • Contact Us
All About Us
新华三官网