- C 92.1%
- C++ 6%
- M4 0.9%
- Shell 0.5%
- Dockerfile 0.3%
- Other 0.2%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
|
|
||
| .github | ||
| debian | ||
| dockerfiles | ||
| docs | ||
| fips | ||
| kpt | ||
| test | ||
| test_bssl | ||
| .gitignore | ||
| .gitmodules | ||
| atomic-ops.h | ||
| autogen.sh | ||
| configure.ac | ||
| driver_install.sh | ||
| e_qat.c | ||
| e_qat.h | ||
| fips_install.sh | ||
| intkat.sh | ||
| LICENSE | ||
| LICENSE.BORINGSSL | ||
| LICENSE.OPENSSL | ||
| LICENSE.PLOCK | ||
| Makefile.am | ||
| plock.c | ||
| plock.h | ||
| qae_mem_utils.h | ||
| qat.ec | ||
| qat.txt | ||
| qat_bssl.c | ||
| qat_bssl.h | ||
| qat_bssl_err.c | ||
| qat_bssl_err.h | ||
| qat_common.h | ||
| qat_constant_time.h | ||
| qat_err.c | ||
| qat_err.h | ||
| qat_events.c | ||
| qat_events.h | ||
| qat_evp.c | ||
| qat_evp.h | ||
| qat_fips.c | ||
| qat_fips.h | ||
| qat_fork.c | ||
| qat_fork.h | ||
| qat_hw_asym_common.c | ||
| qat_hw_asym_common.h | ||
| qat_hw_callback.c | ||
| qat_hw_callback.h | ||
| qat_hw_ccm.c | ||
| qat_hw_ccm.h | ||
| qat_hw_chachapoly.c | ||
| qat_hw_chachapoly.h | ||
| qat_hw_ciphers.c | ||
| qat_hw_ciphers.h | ||
| qat_hw_dh.c | ||
| qat_hw_dh.h | ||
| qat_hw_dsa.c | ||
| qat_hw_dsa.h | ||
| qat_hw_ec.c | ||
| qat_hw_ec.h | ||
| qat_hw_ecx.c | ||
| qat_hw_gcm.c | ||
| qat_hw_gcm.h | ||
| qat_hw_hkdf.c | ||
| qat_hw_hkdf.h | ||
| qat_hw_init.c | ||
| qat_hw_kpt.c | ||
| qat_hw_kpt.h | ||
| qat_hw_polling.c | ||
| qat_hw_polling.h | ||
| qat_hw_prf.c | ||
| qat_hw_prf.h | ||
| qat_hw_rsa.c | ||
| qat_hw_rsa.h | ||
| qat_hw_sha3.c | ||
| qat_hw_sha3.h | ||
| qat_hw_sm2.c | ||
| qat_hw_sm2.h | ||
| qat_hw_sm3.c | ||
| qat_hw_sm3.h | ||
| qat_hw_sm4_cbc.c | ||
| qat_hw_sm4_cbc.h | ||
| qat_hw_usdm_inf.c | ||
| qat_hw_usdm_inf.h | ||
| qat_prov_aes_ccm.c | ||
| qat_prov_aes_ccm.h | ||
| qat_prov_bio.c | ||
| qat_prov_bio.h | ||
| qat_prov_capabilities.c | ||
| qat_prov_cbc.c | ||
| qat_prov_cbc.h | ||
| qat_prov_chachapoly.c | ||
| qat_prov_chachapoly.h | ||
| qat_prov_ciphers.c | ||
| qat_prov_ciphers.h | ||
| qat_prov_cmvp.c | ||
| qat_prov_cmvp.h | ||
| qat_prov_dh.c | ||
| qat_prov_dh.h | ||
| qat_prov_dsa.c | ||
| qat_prov_dsa.h | ||
| qat_prov_ec.h | ||
| qat_prov_ecdh.c | ||
| qat_prov_ecdsa.c | ||
| qat_prov_ecx.h | ||
| qat_prov_exch_ecx.c | ||
| qat_prov_hkdf.c | ||
| qat_prov_hkdf.h | ||
| qat_prov_hkdf_packet.c | ||
| qat_prov_hkdf_packet.h | ||
| qat_prov_init.c | ||
| qat_prov_kem_ml_kem.c | ||
| qat_prov_kmgmt_dh.c | ||
| qat_prov_kmgmt_dsa.c | ||
| qat_prov_kmgmt_ec.c | ||
| qat_prov_kmgmt_ec_utils.c | ||
| qat_prov_kmgmt_ec_utils.h | ||
| qat_prov_kmgmt_ecx.c | ||
| qat_prov_kmgmt_ml_dsa.c | ||
| qat_prov_kmgmt_ml_kem.c | ||
| qat_prov_kmgmt_rsa.c | ||
| qat_prov_kmgmt_rsa_utils.c | ||
| qat_prov_kmgmt_rsa_utils.h | ||
| qat_prov_prf.c | ||
| qat_prov_prf.h | ||
| qat_prov_rsa.c | ||
| qat_prov_rsa.h | ||
| qat_prov_rsa_enc_dec.c | ||
| qat_prov_sha2.c | ||
| qat_prov_sha3.c | ||
| qat_prov_sign_ml_dsa.c | ||
| qat_prov_sign_rsa.c | ||
| qat_prov_sign_sm2.c | ||
| qat_prov_sign_sm2.h | ||
| qat_prov_sm3.c | ||
| qat_prov_sm4_cbc.c | ||
| qat_prov_sm4_cbc.h | ||
| qat_prov_sm4_ccm.c | ||
| qat_prov_sm4_ccm.h | ||
| qat_prov_sm4_gcm.c | ||
| qat_prov_sm4_gcm.h | ||
| qat_provider.cnf | ||
| qat_provider.h | ||
| qat_rsa_ciphertext.c | ||
| qat_rsa_ciphertext.h | ||
| qat_self_test_data.inc | ||
| qat_self_test_kats.c | ||
| qat_self_test_tls_prf.c | ||
| qat_sw_ec.c | ||
| qat_sw_ec.h | ||
| qat_sw_ecx.c | ||
| qat_sw_ecx.h | ||
| qat_sw_freelist.c | ||
| qat_sw_freelist.h | ||
| qat_sw_gcm.c | ||
| qat_sw_gcm.h | ||
| qat_sw_init.c | ||
| qat_sw_ipsec_inf.c | ||
| qat_sw_ml_dsa.c | ||
| qat_sw_ml_dsa.h | ||
| qat_sw_ml_kem.c | ||
| qat_sw_ml_kem.h | ||
| qat_sw_polling.c | ||
| qat_sw_polling.h | ||
| qat_sw_queue.c | ||
| qat_sw_queue.h | ||
| qat_sw_request.h | ||
| qat_sw_rsa.c | ||
| qat_sw_rsa.h | ||
| qat_sw_sha2.c | ||
| qat_sw_sha2.h | ||
| qat_sw_sm2.c | ||
| qat_sw_sm2.h | ||
| qat_sw_sm3.c | ||
| qat_sw_sm3.h | ||
| qat_sw_sm4_cbc.c | ||
| qat_sw_sm4_cbc.h | ||
| qat_sw_sm4_ccm.c | ||
| qat_sw_sm4_ccm.h | ||
| qat_sw_sm4_gcm.c | ||
| qat_sw_sm4_gcm.h | ||
| qat_utils.c | ||
| qat_utils.h | ||
| qatengine-oot.spec | ||
| qatengine.spec | ||
| README.md | ||
| SECURITY.md | ||
| test.am | ||
| testapp.sh | ||
| update_config.sh | ||
Intel® QuickAssist Technology (QAT) Engine and QAT Provider for OpenSSL
This project provides QAT Engine (qatengine) and QAT Provider (qatprovider)
integrations for OpenSSL. Cryptographic operations can be accelerated through
QAT hardware (QAT_HW) or Intel CPU instruction-set optimized software
libraries (QAT_SW). A co-existence build enables both acceleration paths.
The image below illustrates the high-level software architecture of the QAT Engine and QAT Provider interfaces.
Applications such as NGINX and HAProxy are common applications
which interfaces to crypto libraries like OpenSSL* and its fork like
Tongsuo(BabaSSL)*, BoringSSL*, etc. OpenSSL* is a toolkit for TLS/SSL protocols and
has developed a modular system to plug in device-specific Engines and Providers.
Depending on the particular use case, the QAT Provider or QAT Engine can be configured
to accelerate operations using QAT Hardware, QAT Software, or both, depending on
the platform, to meet your specific acceleration needs. This project supports
QAT Engine (qatengine) through the OpenSSL ENGINE interface (up to OpenSSL 3.x;
not supported in OpenSSL 4.0 and later) and QAT Provider (qatprovider) through
the OpenSSL Provider interface (recommended for OpenSSL 3.x and later).
QAT Provider (qatprovider) is built by default. Pass --enable-qat_engine at build time to opt into the
legacy OpenSSL ENGINE interface instead. See
QAT Provider Interface for details.
Provider-First Quick Start
For OpenSSL 3.x and later, use QAT Provider (qatprovider) as the default interface.
cd /path/to/openssl_install/bin
./openssl list -providers -provider qatprovider -provider default
./openssl speed -provider qatprovider -provider default -elapsed -async_jobs 8 rsa2048
Use QAT Engine (qatengine) only when a legacy ENGINE-based integration is required.
Naming Conventions
qatprovideris the OpenSSL Provider module name (documented as QAT Provider).qatengineis the legacy OpenSSL ENGINE module name (documented as QAT Engine).- OpenSSL ENGINE refers to the legacy OpenSSL interface itself, not the project.
QAT_HWandQAT_SWdescribe acceleration paths, independent of whether the interface is Provider or Engine.
Features
Supported features are described here.
Limitations and Known Issues
Limitations and known issues are described here.
Requirements
Installation Instructions
Installation instructions, including build steps for the QAT Engine
(qatengine) and QAT Provider (qatprovider) interfaces across QAT_HW,
QAT_SW, and co-existence configurations, are described here.
Testing
Verify QAT Provider and QAT Engine loading
Verify QAT Provider loading
QAT Provider (qatprovider) is the default and recommended interface for OpenSSL 3.x and later.
Run the following to verify qatprovider is loaded correctly. Always load the default provider
alongside qatprovider to ensure complete algorithm coverage.
cd /path/to/openssl_install/bin
./openssl list -providers -provider qatprovider -provider default
Expected output will list qatprovider with its name, version and loaded status.
Note: Always activate the
defaultprovider alongsideqatprovider— either via-provider defaulton the command line or by adding it to youropenssl.cnf. See QAT Provider Interface for details.
Verify QAT Engine loading
Use the --enable-qat_engine flag to build the legacy QAT Engine. Run the following
command to verify that the QAT Engine is loaded correctly. This command should not be
used to determine QAT Engine capabilities, as it does not display all the algorithms
supported by the QAT Engine.
cd /path/to/openssl_install/bin
./openssl engine -t -c -v qatengine
qat_hw target output will be:
(qatengine) Reference implementation of QAT crypto engine(qat_hw) <qatengine version>
[RSA, DSA, DH, AES-128-CBC-HMAC-SHA1, AES-128-CBC-HMAC-SHA256,
AES-256-CBC-HMAC-SHA1, AES-256-CBC-HMAC-SHA256, TLS1-PRF, HKDF, X25519, X448]
[ available ]
ENABLE_EXTERNAL_POLLING, POLL, SET_INSTANCE_FOR_THREAD,
GET_NUM_OP_RETRIES, SET_MAX_RETRY_COUNT, SET_INTERNAL_POLL_INTERVAL,
GET_EXTERNAL_POLLING_FD, ENABLE_EVENT_DRIVEN_POLLING_MODE,
GET_NUM_CRYPTO_INSTANCES, DISABLE_EVENT_DRIVEN_POLLING_MODE,
SET_EPOLL_TIMEOUT, SET_CRYPTO_SMALL_PACKET_OFFLOAD_THRESHOLD,
ENABLE_INLINE_POLLING, ENABLE_HEURISTIC_POLLING,
GET_NUM_REQUESTS_IN_FLIGHT, INIT_ENGINE, SET_CONFIGURATION_SECTION_NAME,
ENABLE_SW_FALLBACK, HEARTBEAT_POLL, DISABLE_QAT_OFFLOAD
qat_sw target output will be:
(qatengine) Reference implementation of QAT crypto engine(qat_sw) <qatengine version>
[RSA, id-aes128-GCM, id-aes192-GCM, id-aes256-GCM, X25519]
[ available ]
ENABLE_EXTERNAL_POLLING, POLL, ENABLE_HEURISTIC_POLLING,
GET_NUM_REQUESTS_IN_FLIGHT, INIT_ENGINE
Detailed information about the engine specific messages is available here.
Also ./openssl engine -t -c -vvvv qatengine gives brief description about each ctrl command.
Test using OpenSSL* speed utility
Test using OpenSSL* speed utility
QAT Provider (-provider qatprovider -provider default)
cd /path/to/openssl_install/bin
qat_hw
* RSA 2K Sign/Verify
taskset -c 1 ./openssl speed -provider qatprovider -provider default -elapsed -async_jobs 72 rsa2048
* ECDH P-256 Compute Key
taskset -c 1 ./openssl speed -provider qatprovider -provider default -elapsed -async_jobs 72 ecdhp256
* ECDSA P-256 Sign/Verify
taskset -c 1 ./openssl speed -provider qatprovider -provider default -elapsed -async_jobs 72 ecdsap256
* AES-256-GCM
taskset -c 1 ./openssl speed -provider qatprovider -provider default -elapsed -async_jobs 72 -evp aes-256-gcm
qat_sw
* RSA 2K Sign/Verify
taskset -c 1 ./openssl speed -provider qatprovider -provider default -elapsed -async_jobs 8 rsa2048
* ECDH X25519 Compute Key
taskset -c 1 ./openssl speed -provider qatprovider -provider default -elapsed -async_jobs 8 ecdhx25519
* ECDSA P-256 Sign/Verify
taskset -c 1 ./openssl speed -provider qatprovider -provider default -elapsed -async_jobs 8 ecdsap256
* AES-256-GCM
taskset -c 1 ./openssl speed -provider qatprovider -provider default -elapsed -evp aes-256-gcm
QAT Engine (-engine qatengine)
cd /path/to/openssl_install/bin
qat_hw
* RSA 2K Sign/Verify
taskset -c 1 ./openssl speed -engine qatengine -elapsed -async_jobs 72 rsa2048
* ECDH Compute Key
taskset -c 1 ./openssl speed -engine qatengine -elapsed -async_jobs 72 ecdhp256
* ECDSA Sign/Verify
taskset -c 1 ./openssl speed -engine qatengine -elapsed -async_jobs 72 ecdsap256
* AES-128-CBC-HMAC-SHA256
taskset -c 1 ./openssl speed -engine qatengine -elapsed -async_jobs 72 -evp aes-128-cbc-hmac-sha256
qat_sw
* RSA 2K Sign/Verify
taskset -c 1 ./openssl speed -engine qatengine -elapsed -async_jobs 8 rsa2048
* ECDH X25519 Compute Key
taskset -c 1 ./openssl speed -engine qatengine -elapsed -async_jobs 8 ecdhx25519
* ECDH P-256 Compute Key
taskset -c 1 ./openssl speed -engine qatengine -elapsed -async_jobs 8 ecdhp256
* ECDSA P-256 Sign/Verify
taskset -c 1 ./openssl speed -engine qatengine -elapsed -async_jobs 8 ecdsap256
* ECDH P-384 Sign/Verify
taskset -c 1 ./openssl speed -engine qatengine -elapsed -async_jobs 8 ecdhp384
* ECDSA P-384 Sign/Verify
taskset -c 1 ./openssl speed -engine qatengine -elapsed -async_jobs 8 ecdsap384
* AES-128-GCM
taskset -c 1 ./openssl speed -engine qatengine -elapsed -evp aes-128-gcm
Note: Run the test without -engine qatengine or -provider qatprovider for each algorithm to
compare against OpenSSL* software. This covers key algorithms; additional algorithms can be tested
by changing the algo parameter. Additional provider test commands are described in
docs/qat_provider.md.
Test using inbuilt testapp utility
Test using inbuilt testapp utility
Note: The
testapputility supports QAT Engine (qatengine) & QAT Provider interfaces.
cd /path/to/qat_engine or /path/to/qat_provider
make test
./testapp.sh <QAT_HW|QAT_SW> <provider|engine>
Examples:
./testapp.sh QAT_HW provider
./testapp.sh QAT_SW provider
./testapp.sh QAT_HW engine
./testapp.sh QAT_SW engine
The testapp.sh script will run the corresponding functional tests supported
by QAT_HW and QAT_SW. Please note that the QAT Engine should be built with
that support for the tests.
Additional information for testapp tests available with the help option
./testapp -help
Application integration & Case studies
Guidance on integrating an application directly with the QAT Provider, including external and heuristic polling, is described here.
Links to additional content are available here.
Troubleshooting
Troubleshooting information is available here.
Licensing
Legal
Intel, Intel Atom, and Xeon are trademarks of Intel Corporation in the U.S. and/or other countries.
*Other names and brands may be claimed as the property of others.
Copyright © 2016-2026, Intel Corporation. All rights reserved.