Channel Key Loading via Local Key Manager for Fibre Channel
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The FC-SP-2 standard's certificate-based authentication in Fibre Channel environments is computationally intensive and time-consuming, leading to elongated link initialization times and system constraints, especially in large enterprise servers with numerous Fibre Channel ports.
Innovation Solution
Implementing a method for channel key loading of a host bus adapter (HBA) based on a secure key exchange (SKE) authentication response, where a local key manager (LKM) executes on the initiator node, performs state checks, and extracts an encryption algorithm identifier from the authentication response message to establish secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If certificate-based authentication (FCAP/IKE protocol) is used for Fibre Channel links, then security and authentication strength are improved, but link initialization time increases and system performance deteriorates
Solution Approach 1:
The patent performs authentication and key exchange operations in advance before actual data transmission begins. The HBA completes the IKE protocol and receives encryption keys prior to initiating client workloads, so that when data flow starts, authentication is already complete. This preliminary action eliminates the delay that would otherwise occur during data transmission and significantly reduces the impact on link initialization time.
Solution Approach 2:
The patent divides the authentication process into distinct phases: a preliminary authentication phase where the HBA completes IKE protocol and obtains keys, and a subsequent data transmission phase. By segmenting the initialization process and completing security setup before workload execution, the system separates security operations from business logic, reducing the impact on overall system initialization time.
2Reliability
If IKE protocol with certificate-based authentication is implemented, then secure communication is achieved, but CPU intensive mathematical computations increase system resource consumption
Solution Approach 1:
The HBA performs all CPU-intensive IKE protocol computations and mathematical operations during the preliminary authentication phase before data transmission begins. By completing these computationally heavy tasks in advance, the system avoids consuming excessive CPU resources during actual data processing operations, thereby reducing overall system resource consumption while maintaining secure authentication.
3Reliability
If FCAP protocol is executed on every Fibre Channel link, then link-by-link authentication is achieved, but system initialization time increases
Solution Approach 1:
The patent implements preliminary authentication where the HBA completes the IKE protocol and obtains encryption keys before initiating client workloads. This ensures that when data transmission begins, authentication is already complete, thereby maintaining link-by-link security authentication while significantly reducing the impact on system initialization speed and improving overall productivity.
Data Source
AI summary
Aspects of the invention include channel key loading of a host bus adapter (HBA) based on a secure key exchange (SKE) authentication response by a responder node of a computing environment. A non-limiting example computer-implemented method includes receiving an authentication response message at an initiator channel on an initiator node from a responder channel on a responder node to establish a secure communication, the receiving at a local key manager (LKM) executing on the initiator node. A state check can be performed based on a security association of the initiator node and the responder node. An identifier of a selected encryption algorithm can be extracted from the authentication response message. The initiator channel can request to communicate with the responder channel based at least in part on a successful state check and the selected encryption algorithm.


