HMAC-SHA-512 Hardware Implementation for IPSec
Nguyễn Trường Sơn, Keisuke Iwai, Takakazu Kurokawa · ITC-CSCC :International Technical Conference on Circuits Systems, Computers and Communications · 2003
Message authentication plays an important role in network communication security confirming that the received messages come from the correct source and have not been altered. In general, a key authentication scheme uses a Message Authentication Code (MAC). The technique with a hash function to produce a MAC is referred to as an HMAC. This paper presents a hardware implementation of Keyed-Hash Message Authentication Code for IPSec using FPGA (Field Programmable Gate Array). The hash function SHA-512 is chosen to strengthen the security level. High speed architecture using parallel counters (PCs) and carry save adders (CSAs) in computation part of additions is proposed. Its analysis results are also given. The implementation results show that data throughput of our design became 681 Mbps, which is 23.4% faster than normal adders without PCs nor CSAs, with a slight increase of hardware resources of approximately 0.6%. This fact indicates the ability of our design to provide a hardware system for practical implementation of IPSec authentication.