Contact Us
Overview

SmartDV’s IPsec Verification IP is a comprehensive solution for verifying the Internet Protocol Security suite, the industry-standard framework for providing authentication, integrity, and confidentiality for IP layer traffic across IPv4 and IPv6 networks. Fully compliant with RFC 4301 for the IPsec security architecture, RFC 4302 for the Authentication Header protocol, RFC 4303 for the Encapsulating Security Payload protocol, and RFC 7296 for IKEv2 Internet Key Exchange, it supports complete verification of IPsec endpoint functionality across tunnel and transport modes, covering Security Policy Database and Security Association Database management, ESP and AH protocol processing, IKEv2 key exchange and Security Association negotiation, and all recommended cryptographic algorithms per RFC 8221 and RFC 8247.

SmartDV’s IPsec VIP supports UVM, SystemVerilog, and Verilog, and integrates seamlessly into diverse verification environments. It is simulator-independent and compatible with all leading EDA simulators, providing flexibility across simulation platforms.

With comprehensive AES-GCM, AES-CBC, and HMAC-SHA algorithm coverage, Perfect Forward Secrecy, NAT traversal, anti-replay protection, extended sequence numbers, built-in functional coverage, and a complete test suite, SmartDV’s IPsec VIP enables verification teams to thoroughly validate IPsec security implementations for VPN gateways, firewalls, network processors, data center interconnects, and security-critical embedded networking applications.

IPsec VIP
Key Features
  • Full IPsec Tunnel and Transport Mode Support – Provides complete IPsec endpoint verification across tunnel mode for site-to-site and gateway-to-gateway configurations encapsulating entire original IP packets, and transport mode for host-to-host configurations protecting only the payload, supporting both IPv4 and IPv6 traffic.
  • ESP Protocol Support – Supports Encapsulating Security Payload per RFC 4303 covering encryption with separate integrity protection using AES-CBC with HMAC-SHA-256/384/512, AEAD encryption with built-in integrity using AES-GCM-128 and AES-GCM-256, ESP in both tunnel and transport modes, anti-replay protection via sequence numbers, and NULL encryption for authentication-only operation.
  • AH Protocol Support – Supports Authentication Header per RFC 4302 covering packet authentication and integrity verification across tunnel and transport modes, HMAC-SHA-256/384/512 authentication algorithms, and anti-replay protection, providing complete AH protocol layer verification for designs requiring header-level integrity.
  • IKEv2 Key Exchange and SA Management – Supports Internet Key Exchange version 2 per RFC 7296 covering IKE_SA_INIT and IKE_AUTH exchange phases, Security Association negotiation and establishment, Pre-Shared Key and certificate-based authentication, Diffie-Hellman key exchange with Perfect Forward Secrecy, NAT traversal over UDP 4500, Dead Peer Detection, and Child SA creation and rekeying.
  • Security Policy and Association Database Support – Supports Security Policy Database for traffic selector-based policy enforcement covering PROTECT, BYPASS, and DISCARD actions, Security Association Database for active SA parameter management, and Peer Authorization Database for IKE peer authentication data, providing complete IPsec policy plane verification.
  • Cryptographic Algorithm Coverage – Supports all RFC 8221 and RFC 8247 mandatory and recommended algorithm suites including AES-GCM-128/256 for AEAD encryption, AES-CBC-128/256 for encryption, HMAC-SHA-256/384/512 for integrity, SHA-256/384/512 for PRF functions, and ECDH Diffie-Hellman groups for key exchange with extended sequence number support per RFC 4304.
  • Complete Verification Infrastructure – Provides built-in functional coverage analysis, constraints randomization, and callbacks for user access to monitor-observed data across all IPsec protocol conditions covering both normal operation and error injection scenarios.
Compliance and Compatibility
  • Fully compliant with RFC 4301 (IPsec Security Architecture)
  • Fully compliant with RFC 4302 (Authentication Header) and RFC 4303 (Encapsulating Security Payload)
  • Fully compliant with RFC 7296 (IKEv2 Internet Key Exchange)
  • Cryptographic algorithm support per RFC 8221 and RFC 8247
  • Supports IPv4 and IPv6 traffic in both tunnel and transport modes
  • Compatible with UVM, OVM, VMM, SystemVerilog, and Verilog verification environments
  • Compatible with all major EDA simulators including Synopsys VCS, Cadence Xcelium, Siemens Questa, Aldec Riviera-PRO, and Verilator