Date: 26-Nov-2009   URL: www.sun.com/products/networking/sslaccel/suncryptoaccel6000/features.xml

Sun Crypto Accelerator 6000 PCIe Card

Features and Benefits

Security is mandatory in today's business environment. The Sun Crypto Accelerator 6000 PCIe Adapter improves both network security and bottom lines without adding undue complexity and without draining system performance, resources, or budget. Software Version 1.1 adds additional features and benefits to customers at no additional costs.


Key Benefits

  • Support for Red Hat 5 and SUSE 10 Linux distributions
  • Accelerates SSL cryptographic functions, as well as bulk encryption (including IPSec packets)
  • SSL session establishment rate: Up to 13,000 RSA operations per second
  • Tamper-resistant/evident centralized key and certificate storage
  • Designed to meet FIPS 140-2 Level 3 certification requirements

Software 1.1 Features

 

 


Centralized Key Management

This newest release offers the ability to provide an enterprise wide, Sun Crypto Accelerator 6000 PCIs Card 6000- based keystore. With a centralized repository, users have access, from any server with this card, to the same keystore and associated objects. This reduces management overhead and can improve availability.


Multiple Keystore Support

Users are now able to create multiple keystore instances on a single card. This capability not only allows users to leverage virtualized environments such as zones and domains but also is useful for single host environments with diverse user needs. Allowing different user populations to manage their own keystore provides additional flexibility and security.


Firmware Based ECC

ECC can provide higher levels of security than RSA with smaller keys. Because of this, it requires significantly less CPU processing than RSA for equivalent or better security. Adding ECC support to Sun's Crypto Card allows users to keep sensitive ECC keys in the FIPS 140-2 certified HSM. The Sun Crypto Accelerator 6000 1.1 software supports the ECC/ ECDSA /ECDH mechanisms and all of the NIST approved elliptic curves.


Firmware Based SHA-512

Support for multi-part SHA-512 hashing is secure enhancement Working with the SUN Key Management Station (KMS). The feature provides user secure keyed hash of the KMS database.


Improved Keystore Backup

This newest release provides backup operation not only to the master key but also everything needed to restore the keystore. Likewise the restore includes the backup key and object database.


Improved Auditing

The Sun Crypto Card now aslo supports a separately maintained audit to improve usability and traceability. The user is given flexibility to control the verbosity of the logged audit events.

 
 
Copyright 2004-2009 Sun Microsystems, Inc.