TLS/SSL acceleration

The rapid growth of network traffic has brought about a large number of real-time encryption and packet inspection, leading to high hardware cost and rapidly increasing computational resource requirements. Moreover, in the actual usage scenarios in China, both international algorithms and national encryption algorithms will be used simultaneously for a long time. In high-performance environments, the ability to switch algorithms flexibly has become a new challenge. TLS/SSL is currently the most widely used security protocol, aiming to provide security and data integrity for internet communication.

The widespread adoption of TLS/SSL, particularly the promotion of full-site HTTPS, has brought a series of challenges for data centers.

1.High CPU usage

There are a large number of cryptographic tasks in TLS/SSL, which often occupy at least 30% of the CPU time. In cloud computing scenarios, CPU computing power, as commodity, should be allocated more to actual application scenarios to create more economic benefits.

2. Greater network latency

While TLS/SSL ensures network communication security, it also brings greater network latency, which will lead to a reduced user experience of the application.

3. Lack of dual-mode acceleration solutions

Domestic security applications are currently in the transition period from the international cryptography system to the national cryptography system. Both systems will be used together for a long time. However,mature hardware acceleration solutions are mostly provided by foreign manufacturers and lack support for the national cryptography system. Dual-mode hardware acceleration solution is a gap in the current market. In TLS/SSL practice, the industry mainly uses the open-source secure cryptographic library OpenSSL to complete the main encryption and decryption algorithms, key certificate management and SSL protocol processing.

Advantages Of MUCSE

Performance of public key algorithms (Operations per second). Testing only uses 1 Core/2 Threads. Compared with software operation efficiency, servers with built-in RSP S20 increase public key computing power by more than 20 times.

512B~4KB network packet throughput rate. The test is based on SM4-256-CBC. MUCSE® CAP,which is a hardware cryptographic acceleration platform. Provides multiple deployment methods, typical methods include chip and encryption card. The new generation of RSPS20 chip is mainly targeted at national dual-mode SSL encryption scenarios. A single chip can easily handle 25G network scenarios.

MUCSE® CAP can significantly increase the load capacity of the server's encryption tasks. Servers with built-in RSPS20 chips have increased computing power by more than 10 times in key performance such as the number of HTTPS handshakes and SSL packet throughput. Servers with built-in single-chip RSP S20 can increase the overall password computing power by more than 10 times.


Company in Wuxi:Room 1201, A3 Building,NO.777 Jianzhu Rd, Binhu District, Wuxi, China
Company in Beijing:Room 906A, Block B, Dongsheng Building, No. 8 Zhongguancun East Rd, Haidian District, Beijing,China
Company in Shenzhen:Room 1004, Jinqi Zhigu Building, Taoyuan Street, Nanshan District, Shenzhen
TEL:0510-81805885