PBKDF2-HMAC Key Derivation
Password to key — an RFC 8018 hardware engine
Security IP
Overview
The security of a self-encrypting drive begins with how safely a key is derived from a password. PBKDF2 is the key-stretching standard that repeats the HMAC operation many times over, deliberately raising the cost of a brute-force attack.
The IP runs PBKDF2-HMAC-SHA-256 (SHA-512 optional) in hardware with no software involvement. Its main uses inside a storage controller are KEK (key encryption key) generation, host authentication and data-encryption key preparation, following RFC 8018, RFC 2104 and FIPS 180-4.
Implementation has been verified on an Intel/Altera Arria II GX FPGA.
| Standards | RFC 8018 (PBKDF2) · RFC 2104 (HMAC) · FIPS 180-4 (SHA-2) |
|---|---|
| Algorithm | PBKDF2-HMAC-SHA-256 (SHA-512 option) |
| Use | KEK generation · host authentication · data-encryption key preparation |
| Implementation | Verified on FPGA (Intel/Altera Arria II GX) |
Architecture
Architecture
Deliverables
Included with a licence
- Synthesisable Verilog RTL and integration wrappers
- Cycle-accurate reference model and equivalence checker
- Full-chain testbench (clean / correct / UE / pad vectors)
- Datasheet, manual and integration guide (released under NDA)
Verification toolchains: Intel/Altera (Quartus) · AMD/Xilinx (Vivado) · ASIC — process-portable RTL
Engagement
How we engage
01
IP licence
Licence the verified IP as it stands. Synthesisable RTL, the verification environment and an integration guide come with it.
02
Custom development
The IP is modified or extended to your requirement. Because we design from the interface layer up, unusual requirements can be accommodated.
03
Co-development & national programmes
Joint silicon and firmware development against platform requirements, including participation in national R&D programmes. Scope and terms are agreed case by case.
More IP
Other IP in the portfolio
Controller
SSD Controller
1.44MB to 16TB from a single controller
Interface IP
SATA 6Gbps Link / Transport
Domestic SATA Gen3 interface IP
ECC
156-bit BCH ECC
Parametric BCH codec, t = 8 … 156
ECC
QC-LDPC Error Correction
Soft-decision error correction for 3D NAND TLC / QLC
Security IP
AES-128/256 Encryption
Combined encrypt/decrypt engine with DMA streaming