IBM System z cryptographic hardware features

The IBM® System z196 used in this scenario was equipped with two cryptographic hardware features.

  • CP Assist for Cryptographic Function (CPACF) is a feature on the processor unit (cryptographic feature code 3863). It accelerates symmetric cryptographic functions (DES, 3DES, AES). The Secure Sockets Layer (SSL) protocol uses symmetric cipher encryption/decryption operations during the network data transmission after the SSL connection has been established. CPACF also supports SHA hash functions (SHA-1, SHA-256). The available WAS and IHS cipher suites involve symmetric ciphers as well as hash functions.
  • The Crypto Express® (CEX) feature complements the System z® cryptographic features. Crypto Express3 (CEX3) provides improved performance for asymmetric operations. It supports clear key and secure key modes. The feature is capable of offloading and accelerating RSA ciphers. RSA ciphers are basic parts of SSL cipher suites and are used in the SSL handshake process when initiating a SSL connection. RSA is a common algorithm used in public key cryptography. The RSA cipher is the most CPU-intensive operation whenever a network connection is secured using SSL.

    An adapter on a Crypto Express feature can be either defined as a cryptographic coprocessor (CEX3C) or as a cryptographic accelerator (CEX3A). Both types are considered in the cryptographic setup discussed in this paper.

Note: Terminology: An IBM System z cryptographic feature has a feature code because it is an orderable entity. For Crypto Express (CEX) the functional entity is called an adapter. A Crypto Express3 (CEX3) feature contains two CEX adapters. CPACF is also considered as a feature, because it is an orderable (non-priced) entity and has a feature code.