IBM System z cryptographic hardware features
The IBM® System z196 used in this scenario was equipped with two cryptographic hardware features.
- CP Assist for Cryptographic Function (CPACF) is a feature on the processor unit (cryptographic feature code 3863). It accelerates symmetric cryptographic functions (DES, 3DES, AES). The Secure Sockets Layer (SSL) protocol uses symmetric cipher encryption/decryption operations during the network data transmission after the SSL connection has been established. CPACF also supports SHA hash functions (SHA-1, SHA-256). The available WAS and IHS cipher suites involve symmetric ciphers as well as hash functions.
- The Crypto Express® (CEX)
feature complements the System
z® cryptographic features. Crypto Express3 (CEX3) provides
improved performance for asymmetric operations. It supports clear
key and secure key modes. The feature is capable of offloading and
accelerating RSA ciphers. RSA ciphers are basic parts of SSL cipher
suites and are used in the SSL handshake process when initiating a
SSL connection. RSA is a common algorithm used in public key cryptography.
The RSA cipher is the most CPU-intensive operation whenever a network
connection is secured using SSL.
An adapter on a Crypto Express feature can be either defined as a cryptographic coprocessor (CEX3C) or as a cryptographic accelerator (CEX3A). Both types are considered in the cryptographic setup discussed in this paper.
Note: Terminology: An IBM System z cryptographic feature
has a feature code because it is an orderable entity. For Crypto Express (CEX) the functional
entity is called an adapter. A Crypto Express3 (CEX3) feature
contains two CEX adapters. CPACF is also considered as a feature,
because it is an orderable (non-priced) entity and has a feature code.