KiviCrypt-AES-GMAC

Encryption and Decryption IP Core

Cost-efficient licensing model

Low license fees based on one-time fee and free evaluation licenses make IP cores accessible even for projects with limited budgets.

Fast availability and direct support

Evaluation packages and documentation are available via download, with rapid responsive web support to keep your project moving.

Easy integration

AXI4-Lite interface, platform-agnostic C source code HAL, API and software driver and clear documentation enable fast integration into hardware–software co-design flows.

European technology

Developed in Germany, with predictable availability giving design teams transparency, control, and long-term planning security.

Experienced IP core providers

KiviCore’s employees bring more than 20 years of experience in IP core design and licensing of IP cores.

KiviHash-AES-GMAC overview

The KiviHash-AES-GMAC IP core generates and verifies authentication tags using Galois Message Authentication Code (GMAC), as specified in NIST SP 800-38D. GMAC is derived from AES-GCM and provides data integrity and authenticity without encrypting the data. It is suited to systems that need to authenticate messages or data streams while keeping their contents in plaintext.
The core supports AES keys of 128, 192 and 256 bits, a 96-bit IV, and tag lengths from 32 to 128 bits. It accepts either a pre-expanded key or performs key expansion internally by default. Its fully synchronous architecture is designed for integration into FPGA and ASIC systems.

Key features

  • NIST SP 800-38D compliant
  • Key size: 128, 192, 256 bits
  • IV length: 96 bits
  • Tag lengths: 128, 120, 112, 104, 96, 64, 32 bits
  • GMAC generate and verify
  • Works with pre-expanded key or internal key expansion (default)
  • Fast design
  • AXI Stream data I/O
  • Optional with DMA engine
  • Optional AMBA® AXI4-Lite
  • Fully synchronous design
  • Area and speed optimized for LUT4 FPGAs
  • No internal block RAM needed
  • Optional HAL and software driver (C-code, platform independent)
  • Support for Linux, RTOS and bare-metal software
  • For any FPGA and ASIC
Variants Description
KiviHash-AES-GMAC-Fast

Optimized for high processing throughput, suitable for designs that require increased performance while maintaining efficient use of resources.

Applications

KiviHash-AES-GMAC can authenticate data where encryption is unnecessary or handled separately:

  • Communication protocols: Authenticate packets or messages sent over a data link.
  • Firmware and configuration data: Verify integrity and authenticity before processing.
  • FPGA and SoC data paths: Detect unauthorized changes to data transferred between system components.

Test and verification

  • NIST ACVP test vectors for AES-GCM block cipher mode
  • Extended verification through simulation
  • FPGA integration and implementation tests
  • Unity tests for driver and whole IP Core

Technical documentation & evaluation package

Register for the Evaluation Portal to access evaluation packages, technical documentation and integration resources.

Licensing

Licensing and deliverables

License type Purpose Scope Fee Deliverables
Product License Manufacture of products intended for commercial distribution. Valid for single-instance implementation/synthesis into one device (e.g., one type of SoC, or FPGA) for a specific project or product definition. Multiple instantiations refer to the physical realization of one IP core multiple times in one device. One-time fee 
  • SystemVerilog RTL source code or targeted FPGA netlis
  • Testbenches
  • Integration examples
  • Simulation and synthesis scripts
  • Optional Software HAL & driver source code
  • Optional Software example for Linux and bare-metal
  • Documentation
Evaluation License Usability and evaluation for upcoming design  Valid for single-instance implementation/synthesis into one device (SoC, or FPGA) for a specific upcoming design project. Free, no license fee
  • Netlist format, time-bombed
  • Testbenches
  • Integration examples
  • Software HAL & driver source code
  • Software example source code
  • Documentation
Support and maintenance
  • Maintenance and updates of IP core included

  • Rapid bug fix cycles
  • Documentation and integration examples included
  • Web based support with response times of 8 hours (Mo to Fri)

 

FPGA implementation results

AMD (Xilinx) implementation results

 

 

KiviHash-AES-GMAC

Device
LUTs

max. Frequency (MHz)

max. Throughput (Gbps)

Spartan 7

15690

140.3

18.0

Kintex 7

15710

210.7

27.0

Zynq US+ MPSoC

15713

322.4

41.3

Versal AI Cores Series

16726

349.4

44.8

 

 

Efinix implementation results

 

 
 KiviHash-AES-GMAC
Device
XLR

max. Frequency (MHz)

max. Throughput (Gbps)

Titanium

22256

257.8

33.0

Topaz

22256

141.6

18.1

Trion

22407

64.4

8.3

 

Microchip implementation results
 
KiviHash-AES-GMAC
Device
LUT4

max. Frequency (MHz)

max. Throughput (Gbps)
PolarFire SoC 14356 126.2 15.8
PolarFire 14356 126.2 15.8
Igloo2 63312 80.2 10.3
RTG4

63586

61.5

7.9

SmartFusion 2

63312

80.2

10.3