Intel QuickAssist Technology (QAT) OpenSSL Engine is an OpenSSL Plug-In Engine that provides cryptographic acceleration for both hardware and optimized software using Intel QuickAssist Technology enabled Intel platforms.
sudo vim /etc/default/grubGRUB_CMDLINE_LINUX to add intel_iommu=on vfio-pci.ids=8086:4941 (SPR)sudo update-grubUpdate the kernel: grubby --update-kernel=/boot/vmlinuz-$(uname -r) --remove-args="intel_iommu=on" --args="intel_iommu=off vfio-pci.ids=8086:4941"
Reboot the system
Ensure VT-d and SRIOV are enabled in the host. The steps can be referred from the link [Configuring the host operating system with SR-IOV IOMMU](https://intel.github.io/quickassist/AppNotes/Containers/setup.html#configuring-the-host-operating-s…
sh for i in `(lspci -D -d :4940 || lspci -D -d :4942) | awk '{print $1}'`; do echo 16 | sudo tee /sys/bus/pci/devices/$i/sriov_numvfs; done sh systemctl stop qat
sh systemctl stop qat_service
sh systemctl disable qat_service sh for i in `lspci -D -d :4940 | awk '{print $1}'`; do echo down > /sys/bus/pci/devices/$i/qat/state; done sh for i in `lspci -D -d :4940 | awk '{print $1}'`; do echo "sym;asym" > /sys/bus/pci/devices/$i/qat/cfg_services; done sh for i in `lspci -D -d :4940 | awk '{print $1}'`; do echo up > /sys/bus/pci/devices/$i/qat/state; done sh for i in `lspci -D -d :4940 | awk '{print $1}'`; do cat /sys/bus/pci/devices/$i/qat/state; done sh getent group qat | cut -d ':' -f 3 sh chown root:qat /dev/vfio/*
sh chmod 660 /dev/vfio/* To run the Docker image, use the following command:
docker run -it --cap-add=IPC_LOCK --security-opt seccomp=unconfined --security-opt apparmor=unconfined $(for i in `ls /dev/vfio/*`; do echo --device $i; done) --cpuset-cpus <n cores> --env QAT_POLICY=1 --ulimit memlock=50000000:50000000 intel/intel-qat-engine:<tag_number> openssl speed -provider qatprovider -provider default -elapsed -async_jobs 72 -multi <n> <algo>
Note: n is the number of processes.
docker run -it --cap-add=IPC_LOCK --security-opt seccomp=unconfined --security-opt apparmor=unconfined $(for i in `ls /dev/vfio/*`; do echo --device $i; done) --cpuset-cpus 0-63 --env QAT_POLICY=1 --ulimit memlock=524288000:524288000 intel/intel-qat-engine:<tag_number> openssl speed -provider qatprovider -provider default -elapsed -async_jobs 72 -multi 64 rsa2048
version: 3.5.7
built on: Thu Jul 23 03:54:54 2026 UTC
options: bn(64,64)
compiler: gcc -fPIC -pthread -m64 -Wa,--noexecstack -Wall -O3 -DOPENSSL_USE_NODELETE -DL_ENDIAN -DOPENSSL_PIC -DOPENSSL_BUILDING_OPENSSL -DNDEBUG
CPUINFO: OPENSSL_ia32cap=0x7ffef3ffffebffff:0xfb417ffef3bfbfff:0x40601d30ffdd4432:0x00000001000e4000:0x0007000100000000
sign verify encrypt decrypt sign/s verify/s encr./s decr./s
rsa 2048 bits 0.000074s 0.000005s 0.000009s 0.000160s 13540.1 203929.3 106579.3 6238.6
keygen encaps decaps keygens/s encaps/s decaps/s
rsa2048 0.055922s 0.000016s 0.000251s 17.9 61781.2 3988.2
keygen signs verify keygens/s sign/s verify/s
rsa2048 0.055110s 0.000074s 0.000005s 18.1 13430.4 201675.5
Intel, Intel Atom, and Xeon are trademarks of Intel Corporation in the U.S. and/or other countries.
*Other names and brands may be claimed as the property of others.
Copyright © 2026, Intel Corporation. All rights reserved.
Content type
Image
Digest
sha256:012874ed2…
Size
216.1 MB
Last updated
2 months ago
docker pull intel/intel-qat-engine:2.2.0Pulls:
7
Sep 14 to Sep 20