ISA-L_crypto is a collection of optimized low-level functions targeting storage applications. ISA-L_crypto includes:
Multi-buffer hashes - run multiple hash jobs together on one core for much better throughput than single-buffer versions.
Multi-hash - Get the performance of multi-buffer hashing with a single-buffer interface. Specification ref : Multi-Hash white paper
Multi-hash + murmur - run both together.
AES - block ciphers
Rolling hash - Hash input in a window which moves through the input
Also see:
x86_64:
aarch64:
RISC-V 64:
other:
To build and install the library with autotools it is usually sufficient to run:
./autogen.sh
./configure
make
sudo make install
To use a standard makefile run:
make -f Makefile.unx
On Windows use nmake to build dll and static lib:
nmake -f Makefile.nmake
Refer to cmake/README.md file.
Other targets include:
make check : create and run testsmake tests : create additional unit testsmake perfs : create included performance testsmake ex : build examplesmake doc : build API manualImportant: If using the -flto (Link Time Optimization) compilation flag,
it is recommended to pass the -fno-strict-aliasing flag to avoid
potential test failures.
Legacy or to be avoided algorithms listed in the table below are implemented in the library in order to support legacy applications. Please use corresponding alternative algorithms instead.
+----------------------------------------------------+
| # | Algorithm | Recommendation | Alternative |
|---+----------------+----------------+--------------|
| 1 | MD5 integrity | Legacy | SHA256 |
|---+----------------+----------------+--------------|
| 2 | SHA1 integrity | Avoid | SHA256 |
+----------------------------------------------------+
Intel(R) Intelligent Storage Acceleration for Crypto Library depends on C library and it is recommended to use its latest version.
Applications using the Intel(R) Intelligent Storage Acceleration for Crypto Library rely on Operating System to provide process isolation. As the result, it is recommended to use latest Operating System patches and security updates.
The library does not fulfill technical requirements to achieve Cryptographic Module (CMVP) certification as a standalone component. It is fit for Cryptographic Algorithm validation and certification (CAVP) and it can be part of CMVP as one of the components.
ACVP test application located in tests directory is to support CAVP process. It implements validation of the following algorithms:
Note: the acvp-app requires libacvp 2.0+ to be built.
Note: all sizes in bits
+--------------------------------------------------------------------------------------------+
| Algorithm | Standard | Parameters |
|---------------------+-----------+----------------------------------------------------------|
| AES-CBC | SP800-38A | Key size: 128, 192, 256 |
| | | Direction: encrypt and decrypt |
|---------------------+-----------+----------------------------------------------------------|
| AES-GCM | SP800-38D | Key size: 128, 256 |
| | | Direction: encrypt and decrypt |
| | | ivLen: 96 |
| | | tagLen: 64, 96, 128 |
| | | payloadLen: [min = 0, max = 65536, increment = 8] |
| | | aadLen: 128, 256 |
|---------------------+-----------+----------------------------------------------------------|
| AES-XTS | SP800-38E | Key size: 128, 256 |
| | | Direction: encrypt and decrypt |
| | | payloadLen: [min = 4160, max = 32832, increment = 8] |
|---------------------+-----------+----------------------------------------------------------|
| SHA1 (SHA-1) | FIPS180-4 | messageLength: [min = 0, max = 65536, increment = 8] |
|---------------------+-----------+----------------------------------------------------------|
| SHA256 (SHA2-256) | FIPS180-4 | messageLength: [min = 0, max = 65536, increment = 8] |
|---------------------+-----------+----------------------------------------------------------|
| SHA512 (SHA2-512) | FIPS180-4 | messageLength: [min = 0, max = 65536, increment = 8] |
+--------------------------------------------------------------------------------------------+
For more details, please look at FIPS.md document.
The Windows OS has an insecure predefined search order and set of defaults when trying to locate a resource. If the resource location is not specified by the software, an attacker need only place a malicious version in one of the locations Windows will search, and it will be loaded instead. Although this weakness can occur with any resource, it is especially common with DLL files.
Applications using libisal_crypto DLL library may need to apply one of the solutions to prevent from DLL injection attack.
Two solutions are available:
C
58.9%
Assembly
39.0%
ISA-L_crypto is a collection of optimized low-level functions targeting storage applications. ISA-L_crypto includes:
Multi-buffer hashes - run multiple hash jobs together on one core for much better throughput than single-buffer versions.
Multi-hash - Get the performance of multi-buffer hashing with a single-buffer interface. Specification ref : Multi-Hash white paper
Multi-hash + murmur - run both together.
AES - block ciphers
Rolling hash - Hash input in a window which moves through the input
Also see:
x86_64:
aarch64:
RISC-V 64:
other:
To build and install the library with autotools it is usually sufficient to run:
./autogen.sh
./configure
make
sudo make install
To use a standard makefile run:
make -f Makefile.unx
On Windows use nmake to build dll and static lib:
nmake -f Makefile.nmake
Refer to cmake/README.md file.
Other targets include:
make check : create and run testsmake tests : create additional unit testsmake perfs : create included performance testsmake ex : build examplesmake doc : build API manualImportant: If using the -flto (Link Time Optimization) compilation flag,
it is recommended to pass the -fno-strict-aliasing flag to avoid
potential test failures.
Legacy or to be avoided algorithms listed in the table below are implemented in the library in order to support legacy applications. Please use corresponding alternative algorithms instead.
+----------------------------------------------------+
| # | Algorithm | Recommendation | Alternative |
|---+----------------+----------------+--------------|
| 1 | MD5 integrity | Legacy | SHA256 |
|---+----------------+----------------+--------------|
| 2 | SHA1 integrity | Avoid | SHA256 |
+----------------------------------------------------+
Intel(R) Intelligent Storage Acceleration for Crypto Library depends on C library and it is recommended to use its latest version.
Applications using the Intel(R) Intelligent Storage Acceleration for Crypto Library rely on Operating System to provide process isolation. As the result, it is recommended to use latest Operating System patches and security updates.
The library does not fulfill technical requirements to achieve Cryptographic Module (CMVP) certification as a standalone component. It is fit for Cryptographic Algorithm validation and certification (CAVP) and it can be part of CMVP as one of the components.
ACVP test application located in tests directory is to support CAVP process. It implements validation of the following algorithms:
Note: the acvp-app requires libacvp 2.0+ to be built.
Note: all sizes in bits
+--------------------------------------------------------------------------------------------+
| Algorithm | Standard | Parameters |
|---------------------+-----------+----------------------------------------------------------|
| AES-CBC | SP800-38A | Key size: 128, 192, 256 |
| | | Direction: encrypt and decrypt |
|---------------------+-----------+----------------------------------------------------------|
| AES-GCM | SP800-38D | Key size: 128, 256 |
| | | Direction: encrypt and decrypt |
| | | ivLen: 96 |
| | | tagLen: 64, 96, 128 |
| | | payloadLen: [min = 0, max = 65536, increment = 8] |
| | | aadLen: 128, 256 |
|---------------------+-----------+----------------------------------------------------------|
| AES-XTS | SP800-38E | Key size: 128, 256 |
| | | Direction: encrypt and decrypt |
| | | payloadLen: [min = 4160, max = 32832, increment = 8] |
|---------------------+-----------+----------------------------------------------------------|
| SHA1 (SHA-1) | FIPS180-4 | messageLength: [min = 0, max = 65536, increment = 8] |
|---------------------+-----------+----------------------------------------------------------|
| SHA256 (SHA2-256) | FIPS180-4 | messageLength: [min = 0, max = 65536, increment = 8] |
|---------------------+-----------+----------------------------------------------------------|
| SHA512 (SHA2-512) | FIPS180-4 | messageLength: [min = 0, max = 65536, increment = 8] |
+--------------------------------------------------------------------------------------------+
For more details, please look at FIPS.md document.
The Windows OS has an insecure predefined search order and set of defaults when trying to locate a resource. If the resource location is not specified by the software, an attacker need only place a malicious version in one of the locations Windows will search, and it will be loaded instead. Although this weakness can occur with any resource, it is especially common with DLL files.
Applications using libisal_crypto DLL library may need to apply one of the solutions to prevent from DLL injection attack.
Two solutions are available:
C
58.9%
Assembly
39.0%