Commsdesign Home Register About Commsdesign Feedback Online Opportunities SpecSearch GlobalSpec




















eLibrary

EE TIMES NETWORK
 Online Editions
 EE TIMES
 EE TIMES ASIA
 EE TIMES CHINA
 EE TIMES FRANCE
 EE TIMES GERMANY
 EE TIMES INDIA
 EE TIMES JAPAN
 EE TIMES KOREA
 EE TIMES TAIWAN
 EE TIMES UK

 EE TIMES EUROPE
 ANALOG EUROPE
 AUTOMOTIVE DL EUROPE

 POWER DL EUROPE

 Web Sites
 • Audio DesignLine
 • Automotive DesignLine
 • Career Center
 • CommsDesign
 • Microwave
    Engineering
 • Deepchip.com
 • Design & Reuse
 • Digital Home DesignLine
 • DSP DesignLine
 • EDA DesignLine
 • Embedded.com
 • Elektronik i Norden
 • Green SupplyLine
 • Industrial Control
    DesignLine
 • Planet Analog
 • Mobile Handset
    DesignLine
 • Power Management
    DesignLine
 • Programmable Logic
    DesignLine
 • RF DesignLine
 • The RF Edge
 • Techonline
 • Video | Imaging
    DesignLine
 • Wireless Net
    DesignLine

ELECTRONICS GROUP SITES

 • eeProductCenter
 • Electronics Supply &
    Manufacturing
 • Conferences
    and Events
 • Electronics Supply &
    Manufacturing--China
 • Electronics Express
 • Webinars


06 July 2009



How much SSL is enough?

By Linley Gwennap
Courtesy of EE Times
Apr 08, 2002
Print This Story Send As Email Reprints
 
GWENNAP_LINLEYThey say you can never be too rich or too thin. But can a chip have too much performance? That's the hot debate in the security-processor world.

Startups Cavium, ChipSign and Layer N have announced chips that deliver 10,000 to 100,000 Secure Sockets Layer handshakes per second. To put that in perspective, the fastest chip available for most of last year, Broadcom's 5820, handles only 800. Market leaders Broadcom and Hifn (and most other security-processor vendors) scoff at the newcomers for offering far more performance than anyone can use.

One or more SSL handshakes are generated any time your Web browser goes into secure mode and the little lock symbol appears. Security processors are used in Web servers and front-end equipment to process the complex SSL computations much faster than a general-purpose CPU can.

Hifn points out that a typical SSL session transfers at least three Web pages of perhaps 28 kbytes each. Thus, a Gigabit Ethernet channel dedicated to SSL would max out at fewer than 1,500 sessions/s.

Layer N counters that a security processor must handle peak loads. For a short period, a chip could receive mostly session setups, not requests from existing sessions. In this period, a Gigabit Ethernet channel could request 100,000 SSL handshakes/s.

Even if the security chip can handle so many SSL operations, the bottleneck shifts to the TCP protocol, where several Pentium 4 processors would be needed just for 10,000 connections/s. This is a critical problem for Cavium and ChipSign, but Layer N's chip includes a TCP offload engine to break this bottleneck.

Hifn's ultimate argument is that no work load comes close to generating 100,000 SSL handshakes/s. This would be equivalent to all of Amazon's Christmas 2001 customers making their purchases during the same five minutes. Most Web site operators are looking for no more than 2,000 handshakes/s.

Layer N admits this is the case today. But with new technology cutting the cost of securing an SSL transaction by orders of magnitude, Web site operators may move to securing entire sites, greatly increasing the demand for SSL handshakes.

All parties in this debate are guilty of selling what they have and bashing what they don't. But these aggressive startups must wait for a paradigm shift to build demand for their muscular technology.

Linley Gwennap is Founder and Principal Analyst of the Linley Group (www.linleygroup.com/npu).




EE Times TechCareers
Search Jobs

Enter Keyword(s):


Function:


State:
  

Post Your Resume
-----------------
Employers Area
Most Recent Posts
Boeing seeking Embedded Software Engineer 5 in Huntington Beach, CA

SEL seeking Lead DSP Engineer in Pullman, WA

SEL seeking Power Systems Instructor in Pullman, WA

Rutland Regional Medical seeking Server Engineer in Rutland, VT

Osram Sylvania seeking Mechanical Design Engineer in Danvers, MA

More career-related news, resources and job postings for technology professionals

Related Products
  • Micrel's first high brightness LED driver debuts
  • Thin integrated optical proximity sensor targets mobile applications
  • IDT samples programmable clocks for wide range of applications
  • UART series features USB 2.0 compliant bus interface
  • TI 'C674x/L13x DSP quartet address connectivity, efficiency and ease of development

    eeProductCenter



    Home  |  Register  |  About  |  Feedback  |  Contact   |  Site Map
    All materials on this site Copyright © 2009 TechInsights, a Division of United Business Media LLC All rights reserved.
    Privacy Statement ¦ Terms of Service