Bài viết
FPGA-Based inline encryption bridge using AES-XTS for storage systems
- Trần Văn Khánh (VN)
- Phan Văn Kỷ (VN)
- Vũ Văn Việt (VN)
Tóm tắt
Bài báo này trình bày một hệ thống mã hóa AES-256 XTS phần cứng được triển khai trên FPGA, cung cấp một cầu nối inline hoàn chỉnh giữa bộ điều khiển lưu trữ và thiết bị lưu trữ. Khác với các công trình trước chỉ tập trung tối ưu lõi AES, thiết kế này tích hợp lõi vào giao thức SATA đầy đủ và đánh giá hiệu năng đầu-cuối trên đường truyền lưu trữ. Lõi XTS-AES dạng pipeline cho phép mã hóa theo sector với tốc độ cao và thời gian thực, đồng thời gần như không ảnh hưởng đến hiệu năng. Việc triển khai trên FPGA mang lại khả năng linh hoạt về kích thước khóa và chế độ mã hóa, hỗ trợ cập nhật thuật toán thông qua tái cấu hình từng phần và mở rộng cho các hệ thống lưu trữ khác, bao gồm cả các hệ thống lưu trữ kết nối mạng NAS. Các đóng góp chính là: (i) đề xuất kiến trúc mã hóa inline dựa trên FPGA với lõi AES-XTS tích hợp đầy đủ vào giao thức SATA; (ii) triển khai và đánh giá hiệu năng mã hóa trên hệ thống lưu trữ thực tế, chứng minh tính khả thi và minh bạch trong các tác vụ thời gian thực.
Lượt tải theo tháng
Di chuột vào cột để xem số lượt tải.
Cách trích dẫn
Trần Văn Khánh, Phan Văn Kỷ, Vũ Văn Việt (2025). FPGA-Based inline encryption bridge using AES-XTS for storage systems. Tạp chí Khoa học và Công nghệ trong lĩnh vực An toàn thông tin, 3(26), 5-17. https://doi.org/10.54654/isj.v2i25.1141
Tiểu sử tác giả
Trần Văn Khánh
Tài liệu tham khảo
- 1.C. Laird, “Taking a Hard-Line Approach to Encryption”, IEEE Computer Society, vol. 40, 2007, pp. 13-15.
- 2.Dumitru, L. Alexandru, Eftimie, Sergiu, Fostea, Dan, “An FPGA-based cloud storage gateway”, Naval Academy Publishing House, 2016.
- 3.FIPS PUB 197, “Advanced Encryption Standard (AES),” National Institute of Standards and Technology (NIST), Nov. 2001.
- 4.G. Saggese, A. Mazzeo, N. Mazzocca, A. G. M. Strollo, “An FPGA-based performance analysis of the unrolling, tiling, and pipelining of the AES algorithm” Field Programmable Logic and Application, 2003, pp. 292-302.
- 5.IEEE Std 1619-2007, “IEEE Standard for Cryptographic Protection of Data on Block-Oriented Storage Devices”.
- 6.L. Demir, M. Thiery, V. Roca, J. L. Roch, J. M. Tenkes, “Improving dm-crypt performance for XTS-AES mode through extended requests: first results”, HAL open science, 2016.
- 7.Yi Wang, A. Kumar, Yajun Ha, “FPGA-based high throughput XTS-AES encryption/decryption for storage area network”, IEEE, 2014.
- 8.Martin, L., “XTS: A Mode of AES for Encrypting Hard Disks”, Security & Privacy, IEEE, vol.8, no.3, pp.68-69, May-June 2010.
- 9.M. A. Alomari, K. Samsudin, A. R. Ramli, “A Study on Encryption Algorithms and Modes for Disk Encryption”, IEEE, 2009.
- 10.Ahmed, Shakil, Naseem, Muhammad, “Efficient AES-XTS Pipelined Implementation on FPGA”, Sir Syed University Research Journal of Engineering & Technology, Vol. 4, No. 1, 2014 pp. 1–6.
- 11.Tran, Sy Nam, Luong, The Dung, Nguyen Van Long, “A High Throughput, Low Latency 105Gbps Four-Pipeline Stage AES”, Journal of Science and Technology on Information Security, Vol. 58, No. 1.CS (21), 2024, pp. 21–35.
- 12.M. M. Mansour, M. M. Al-Qutayri, and A. Al-Ali, “A high-speed FPGA implementation of the AES algorithm,” in Proc. Int. Conf. on Electronics, Circuits and Systems (ICECS), pp. 1404–1407, 2005.
- 13.M. Saqib, F. Anwar, and A. A. Khan, “FPGA-based implementation and performance analysis of XTS-AES encryption for data storage security,” International Journal of Computer Applications, vol. 179, no. 42, 2018, pp. 1–7.
- 14.S. Ahmed, K. Samsudin, A. R. Ramli, F. Z. Rokhani, “Effective Implementation of XTS-AES on FPGA”, IEEE, 2011.
- 15.S. Ahmed, M. Nassem, “Efficient XTS-AES pipelined Implementation on FPGA”, IEEE, 2014.
- 16.SATA-IP Bridge reference design, https://dgway.com/products/IP/SATA-IP/dg_sata_ip_refdesign_bridge_kt7_en/
- 17.SATA-IP Device reference design, https://dgway.com/products/IP/SATA-IP/dg_sata_ip_refdesign_device_kt7_en/
- 18.SATA-IP Host reference design on 7-Series, https://dgway.com/products/IP/SATA-IP/dg_sata_ip_refdesign_host_7series_en/
- 19.SAT- IP Transport & Link Layer, https://dgway.com/products/IP/SATA-IP/dg_sata_ip_data_sheet_7series_en/
- 20.S. An, S. C. Seo, “Designing a new XTS-AES parallel optimization implementation technique for fast file encryption”, IEEE, 2022.
- 21.Khanh, T. V., Tu, N. V., & Ho, T. P. . (2022). Some issues about upgrading and developing high-speed local IP network encryption devices. Journal of Science and Technology on Information Security, 1(15), 46-55. https://doi.org/10.54654/isj.v1i15.838.
- 22.Ky, P. V., Cuong, V. T., & Phuc, L. H. (2021). Solution for Cryptographic Intervention in PCI-Express Data Transmission on FPGA Board. Journal of Science and Technology on Information Security, 2(12), 59-68. https://doi.org/10.54654/isj.v2i12.108.
Bài viết liên quan
- Giải pháp bảo mật đầu cuối cho điện thoại di động
- Một Giải Pháp Bảo Mật Dữ Liệu PCI-Express Sử Dụng Công Nghệ FPGA
- Một giải pháp quản lý kết nối mật cho IPSec trên FPGA
- Some issues about upgrading and developing high-speed local IP network encryption devices
- Some issues about upgrading and developing high-speed local IP network encryption devices
- Xây dựng bộ thư viện người dùng cho card tăng tốc mã hóa qua giao tiếp PCIe