[PATCH v6 0/4] introduce IPsec Service in virtio-crypto
Srujana Challa <[email protected]>
| Newsgroups | dev.linux.lists.virtio-comment |
|---|---|
| Message-ID | <[email protected]> |
This series enhances virtio-crypto by adding support for IPsec services. These patches aim to extend the capabilities of virtio-crypto, enabling it to handle IPsec operations efficiently. In addition to standard crypto processing, the IPsec protocol processing is also offloaded to the Crypto device as lookaside operation. It utilizes new virtio basic facilities, including capability and resource objects. Below is a summary of the changes introduced: Patch1: This patch introduces the foundational support for IPsec services within the virtio-crypto framework, outlining the necessary capabilities for IPsec operations. Patch2: This patch adds resource objects required for programming IPsec Security Associations (SAs) for both encryption and decryption processes. Patch3: This patch includes new opcodes specific to IPsec operations, facilitating the handling of IPsec data requests within the virtio-crypto driver. Patch4: This patch specifies the requirements for both the device and the driver to support IPsec operations. These enhancements are for providing support for IPsec within the virtio-crypto device/driver, improving security and performance for virtualized environments. We believe these additions will significantly benefit users who rely on virtio-crypto for secure data transmission. v2: - Addressed the review comments from Matias. v3: - Addressed the review comments from Parav Pandit. v4: - Introduced COPY_DF, ECN and SA LIFETIME to the SA options. - Introduced SA lifetime to the SA resource object data structure. - Set cipher and auth key arrays to fixed sizes. v5: - Addressed minor review comments from Parav Pandit. v6: - The esn field has been removed from the IPsec SA resource object. Srujana Challa (4): virtio-crypto: Add IPsec service operation and Capabilities virtio-crypto: Add resource objects for IPsec outbound and inbound SAs virtio-crypto: Add new IPsec opcodes to data request virtio-crypto: Add device and driver requirements for IPsec operation device-types/crypto/description.tex | 510 ++++++++++++++++++++- device-types/crypto/device-conformance.tex | 1 + device-types/crypto/driver-conformance.tex | 1 + introduction.tex | 12 + 4 files changed, 519 insertions(+), 5 deletions(-) -- 2.25.1