c4

Revised:  January 25, 2005.



Revised:  February 22, 2005.



2c12



6c16



0c20



4c24



6c26



8c28



91,192d190

Maximum


Not applicable.


22a321
4964 |A| PCI Cryptographic Coprocessor

32c431



39c438



43c442



47c446



52c451



56c455



60a460,462

Physical Specifications


Not applicable.


62c464

Physical Specifications


Operating Environment



65c467

Operating Environment


Limitations



68c470

Limitations


Hardware Requirements



71,474c473

Hardware Requirements


Not applicable.

Software Requirements


Software Requirements



80c479



04c503



11c510



15c514



19c518



24,525c523,524

No Charge Specify Codes



No Charge Specify Codes



03,604c602,603

Special Feature Codes -- Chargeable



Special Feature Codes -- Chargeable



36a636
  • (#4964) - PCI Cryptographic Coprocessor

    213a3214

    (No Longer Available as of February 8, 2005)


    285a3287,3364

    (#4964) PCI Cryptographic Coprocessor


    The IBM PCI Cryptographic Coprocessor is a 2/3 length PCI adapter
    combining hardware and software designed to provide high performance
    hardware engines for secure internet transactions such as data exchange,
    verifying electronic signatures, bulk data encryption and decryption.
    Cryptographic processes are performed within a tamper resistant
    enclosure on the adapter that is designed to meet FIPS PUB 140-1
    standard for commercial cryptographic devices at Level 3.

    Security functions supported by the adapter includes:


    • Data Encryption Standard (DES) (56 and 40 bit keys) encryption and
      decryption, with pre- and post-padding; the coprocessor uses both
      electronic and codebook (ECB) and cipher block chain (CBC) modes of
      encryption.
    • Message Authentication (MAC) and financial PIN processing
    • Triple DES encryption and decryption of general data
    • RSA key-pair generation
    • RSA signature generation and signature verification
    • Secure Hashing Algorithm (SHA-1) in hardware
    • Hardware random number generation
    • Protected data storage and retrieval
    • Other non-cryptographic security utilities can be carried out
      using the onboard processor

    IBM offers software to enable your use of the Coprocessors. Two
    different approaches to cryptographic functions are offered for
    download from:


    http://www.ibm.com/security/cryptocards


    • PKCS #11 Version 2.01, an implementation of the industry-standard
      API
    • IBM Common Cryptographic Architecture (CCA), featuring support of
      special interest to the finance industry.

    Under custom contract, IBM also offers toolkits that you can employ
    to develop extensions to the CCA offering and to develop your own
    application to exploit the secure computing environment and
    cryptographic
    hardware. For more information on custom contracts, refer:


    http://www.ibm.com/security/cryptocards.

    For additional information on the IBM PCI Cryptographic Coprocessor,
    refer to the following World Wide Web page:


    Limitations:


    • The IBM PCI Cryptographic Coprocessor Adapter is a field only
      installed device in order to meet restrictive shipping requirements.

    Note: This adapter may have AIX 5.1 support limitations. Go to the
    following URL to view the latest AIX 5.1 support limitation statements:


    http://www.ibm.com/servers/aix/os/adapters/51.html



    • Attributes provided: Data encryption via PCI bus to host
    • Attributes required: 1 PCI slot
    • For 7040-61D: (#4964)

      • Minimum required: 0
      • Maximum allowed: 8 (Initial order maximum: 8 )
      • OS level required: AIX V5.1 or higher.
        For Linux informaion, refer to:
        http://www.ibm.com/servers/eservers/pseries/hardware/
        factsfeatures.html
         


      • Initial Order/MES/Both/Supported: Both
      • CSU: No
      • Return parts MES: No

      Note: Maximum of 4 adapter per FC# 6563 planar



    722c3801
  • Maximum allowed: 1 (Initial order maximum: 1 )
  • Maximum allowed: 4 (Initial order maximum: 4 )

    272,5273c5351,5352

    Feature Exchanges



    Feature Exchanges



    279c5358



    291c5370



    301c5380



    309c5388