Fibre Channel Link Authentication via Preliminary Key Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The FC-SP-2 standard's certificate-based authentication for Fibre Channel links is computationally intensive and time-consuming, leading to elongated link initialization times and performance constraints in large enterprise servers with many physical ports, due to the need for repeated key exchanges and mathematical computations.

Innovation Solution

A method is introduced where a shared key is obtained from a key server and used to encrypt messages containing encryption keys and parameters, allowing for secure authentication without repeated key requests, reducing processing time and improving system performance by establishing a secure path between nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If certificate-based authentication is performed on every Fibre Channel link, then security is improved, but link initialization time increases and system performance deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoidlink initialization time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs certificate-based authentication in advance during link initialization, before client traffic flows begin. The FCAP protocol executes the computationally intensive certificate validation and key exchange during the link setup phase, so that subsequent data transmission can proceed without repeated authentication overhead. This preliminary action ensures security is established upfront while minimizing impact on ongoing performance.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent establishes encryption keys and security parameters during link initialization through the FCAP protocol, so that these authentication credentials are ready before client workloads commence. The IKE protocol performs mathematical computations and key material generation in advance, allowing the links to be security-configured before carrying production traffic, thus separating the authentication burden from the data transmission phase.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If certificate-based authentication is performed on every Fibre Channel link, then authentication security is improved, but system performance and productivity deteriorate due to repeated key exchanges

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent performs the computationally intensive certificate-based authentication and key exchange operations during link initialization, before client traffic flows. The FCAP and IKE protocols execute their mathematical computations and cryptographic operations during this setup phase, establishing security credentials in advance. This allows subsequent data transmission to proceed at full speed without repeated authentication overhead, thus preserving system productivity while maintaining strong security.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If FCAP protocol is performed before client traffic flows, then link security is established, but link initialization times are elongated

Engineering Contradiction:
Improvelink securityVSAvoidlink initialization time
Core Design Contradiction:
ReliabilityVSDuration of action of moving object

Solution Approach 1:

The patent executes the FCAP protocol and performs certificate-based authentication during the link initialization phase, before any client traffic flows begin. By completing the security setup, key exchange, and credential validation during this preliminary window, the system establishes robust link security upfront. The elongated initialization time is accepted as a one-time cost to enable secure subsequent high-speed data transmission without repeated authentication interruptions.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If IKE protocol mathematical computations are performed in large enterprise servers with many physical ports, then authentication security is improved, but the multiplier effect causes system initialization constraints

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem initialization complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs the IKE protocol's mathematical computations and key generation during link initialization for each physical port, establishing security credentials in advance. While the multiplier effect of many ports does increase initialization complexity, this preliminary action approach concentrates the computational burden during setup rather than during ongoing operations. Once initialized, each link can transmit data without repeated computational overhead, thus managing system complexity while maintaining strong authentication security across multiple ports.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11563588B2Securing a path at a selected node
Publication Date: 2023.01.24 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11563588B2 patent drawing
  • US11563588B2 patent drawing
  • US11563588B2 patent drawing

AI summary

A path is secured from one node to another node of the computing environment. The one node obtains a first encryption key and a second encryption key. A shared key is obtained by the one node from a key server, and the shared key is used to encrypt a message. The encrypted message includes the first encryption key and the second encryption key. The encrypted message and an identifier of the shared key is sent from the one node to the other node, and a response message is received by the one node. The response message at least provides an indication that the other node received the encrypted message and obtained the shared key.