Channel Key Loading via Local Key Manager for Fibre Channel

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The FC-SP-2 standard's certificate-based authentication in Fibre Channel environments is computationally intensive and time-consuming, leading to elongated link initialization times and system constraints, especially in large enterprise servers with numerous Fibre Channel ports.

Innovation Solution

Implementing a method for channel key loading of a host bus adapter (HBA) based on a secure key exchange (SKE) authentication response, where a local key manager (LKM) executes on the initiator node, performs state checks, and extracts an encryption algorithm identifier from the authentication response message to establish secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If certificate-based authentication (FCAP/IKE protocol) is used for Fibre Channel links, then security and authentication strength are improved, but link initialization time increases and system performance deteriorates

Engineering Contradiction:
Improveauthentication strengthVSAvoidlink initialization time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs authentication and key exchange operations in advance before actual data transmission begins. The HBA completes the IKE protocol and receives encryption keys prior to initiating client workloads, so that when data flow starts, authentication is already complete. This preliminary action eliminates the delay that would otherwise occur during data transmission and significantly reduces the impact on link initialization time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent divides the authentication process into distinct phases: a preliminary authentication phase where the HBA completes IKE protocol and obtains keys, and a subsequent data transmission phase. By segmenting the initialization process and completing security setup before workload execution, the system separates security operations from business logic, reducing the impact on overall system initialization time.

Inventive Principle:
Principle #1Segmentation

2Reliability

If IKE protocol with certificate-based authentication is implemented, then secure communication is achieved, but CPU intensive mathematical computations increase system resource consumption

Engineering Contradiction:
Improvesecure authenticationVSAvoidCPU resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The HBA performs all CPU-intensive IKE protocol computations and mathematical operations during the preliminary authentication phase before data transmission begins. By completing these computationally heavy tasks in advance, the system avoids consuming excessive CPU resources during actual data processing operations, thereby reducing overall system resource consumption while maintaining secure authentication.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If FCAP protocol is executed on every Fibre Channel link, then link-by-link authentication is achieved, but system initialization time increases

Engineering Contradiction:
Improvelink authenticationVSAvoidsystem initialization speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary authentication where the HBA completes the IKE protocol and obtains encryption keys before initiating client workloads. This ensures that when data transmission begins, authentication is already complete, thereby maintaining link-by-link security authentication while significantly reducing the impact on system initialization speed and improving overall productivity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11824974B2Channel key loading in a computing environment
Publication Date: 2023.11.21 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11824974B2 patent drawing
  • US11824974B2 patent drawing
  • US11824974B2 patent drawing

AI summary

Aspects of the invention include channel key loading of a host bus adapter (HBA) based on a secure key exchange (SKE) authentication response by a responder node of a computing environment. A non-limiting example computer-implemented method includes receiving an authentication response message at an initiator channel on an initiator node from a responder channel on a responder node to establish a secure communication, the receiving at a local key manager (LKM) executing on the initiator node. A state check can be performed based on a security association of the initiator node and the responder node. An identifier of a selected encryption algorithm can be extracted from the authentication response message. The initiator channel can request to communicate with the responder channel based at least in part on a successful state check and the selected encryption algorithm.