Fibre Channel Key Server Authentication for Link Initialization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The FC-SP-2 standard's certificate-based authentication for Fibre Channel links is computationally intensive and time-consuming, leading to elongated link initialization times and system performance constraints, especially in large enterprise environments with numerous Fibre Channel physical ports and dynamic switched fabrics.

Innovation Solution

A computer program product facilitates authentication by obtaining a shared key from a key server and using it to encrypt messages across multiple links, allowing nodes to authenticate without repeatedly obtaining the shared key, thereby reducing processing time and increasing system performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If certificate-based authentication is performed on every Fibre Channel link using the FCAP protocol, then security and authentication reliability are improved, but link initialization time and system performance deteriorate

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidlink initialization time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs certificate validation and key exchange operations in advance during link initialization, before client traffic flows begin. By completing the computationally intensive FCAP authentication protocol beforehand, the system prepares encryption keys and authentication credentials proactively, so that subsequent data transmission can proceed without repeated authentication delays.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates and distributes copies of authentication credentials and encryption keys to multiple nodes in the Fibre Channel network. Instead of requiring each node to perform independent certificate validation, the system generates authentication credentials once and replicates them across the network, significantly reducing the computational burden and time required for link initialization while maintaining authentication reliability.

Inventive Principle:
Principle #26Copying

2Reliability

If the FCAP protocol is executed on every Fibre Channel link, then authentication security is improved, but system performance and processing throughput deteriorate

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the computationally intensive certificate validation and key exchange operations from the regular data transmission path. By separating the authentication phase from the data transfer phase, the system performs security verification independently during link initialization, allowing subsequent client traffic to flow without being burdened by repeated authentication computations, thus maintaining security while improving overall system performance.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent merges the authentication credential distribution with the link initialization process. By combining the FCAP protocol execution with the establishment of the Fibre Channel link, the system accomplishes both authentication and link setup in a single integrated operation, rather than performing separate authentication handshakes for each data transfer, thereby improving productivity without compromising security.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11025413B2Securing a storage network using key server authentication
Publication Date: 2021.06.01 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11025413B2 patent drawing
  • US11025413B2 patent drawing
  • US11025413B2 patent drawing

AI summary

Authentication is performed on a plurality of links coupling one node of the computing environment and another node of the computing environment. The performing authentication includes obtaining by the one node a shared key from a key server coupled to the one node and another node of the computing environment. A message encrypted with the shared key is sent from the one node to the other node via one link of the plurality of links. An indication that the other node decrypted the message using the shared key obtained by the other node is received from the other node via the one link. The sending and the receiving are repeated on one or more other links of the plurality of links using the shared key previously obtained.