16-Security Configuration Guide

HomeSupportConfigure & DeployConfiguration GuidesH3C WX2800X&WSG1800X Configuration Guides(R5605P11)-6W10016-Security Configuration Guide
18-Crypto engine configuration
Title Size Download
18-Crypto engine configuration 44.18 KB

Configuring crypto engines

About crypto engines

Crypto engines provide encryption/decryption services for service modules, for example, the IPsec module. When a service module requires data encryption/decryption, it sends the desired data to a crypto engine. After the crypto engine completes data encryption/decryption, it sends the data back to the service module.

Enabling the GM-capable hardware crypto engine for GM algorithms

About this task

By default, the device uses software crypto engines for data encryption/decryption by GM algorithms, including SM2, SM3, and SM4 algorithms. That is, the system uses its own software algorithms for data encryption/decryption. This consumes system resources and is less efficient. When the device is installed with the GM-capable hardware crypto engine, you can configure this feature to enable the hardware crypto engine for a specific GM algorithm. Then, data encryption/decryption by that GM algorithm will not consume system resources, which improves device processing efficiency.

Procedure

1.     Enter system view.

system-view

2.     Enable the GM-capable hardware crypto engine for GM algorithms.

crypto-engine accelerator enable gm-algorithm { sm2 | sm3 | sm4 }*

By default, the GM-capable hardware crypto engine is disabled for GM algorithms.

Display and maintenance commands for crypto engines

Execute display commands in any view and reset commands in user view.

 

Task

Command

Display crypto engine information.

display crypto-engine

Display the enabling status of the GM-capable hardware crypto engine for GM algorithms.

display crypto-engine accelerator gm-algorithm status

Display crypto engine statistics.

display crypto-engine statistics [ engine-id engine-id ]

Clear crypto engine statistics.

reset crypto-engine statistics [ engine-id engine-id ]

 

  • Cloud & AI
  • InterConnect
  • Intelligent Computing
  • Intelligent Storage
  • Security
  • SMB Products
  • Intelligent Terminal Products
  • Product Support Services
  • Technical Service Solutions
All Services
  • Resource Center
  • Policy
  • Online Help
  • Technical Blogs
All Support
  • Become A Partner
  • Partner Policy & Program
  • Global Learning
  • Partner Sales Resources
  • Partner Business Management
  • Service Business
All Partners
  • Profile
  • News & Events
  • Online Exhibition Center
  • Contact Us
All About Us
新华三官网