性能和安全是网络安全设备设计的两个主要问题,在网络设备中通过IPSec 来提供安 全功能已成为一种迫切需要。本文针对IPSec 中的SPDB 和SADB 数据库查找和维护造成的性能瓶颈问题,提出了一种由CAM 和SRAM 分别完成查找和读取的查表流水线方案,该方案可将数据库维护对数据处理的影响降到最低限度。 关键词:IPSec TCAM 包分类 An Research on TCAM-based IPSec Lookup Solution KE Xiang-dong HUANG Jian-hua (National Digital Switching System Engineering & Technological R&D Center, ZhengZhou, 450002) Abstract: High performance and security is main aims of network security equipment design, so implementing IPSec to provide security function is an urgent demand. This paper proposes an novel memory architecture based on CAM and SRAM to address the performance weakness of the SPDB and SADB searching operation. This solution can minimize the impact on data path processing when updating the databases. Keywords: IPSec TCAM IP Classification