Fibre Channel Target Authentication for iSCSI Initiators

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional storage area network authentication mechanisms lead to inefficiencies due to multiple entities performing authentication, resulting in administrative complexities and inefficiencies, even with centralized password management services like RADIUS servers.

Innovation Solution

The solution involves aggregating authentication information at fibre channel targets, where an iSCSI initiator performs an authentication exchange with a fibre channel target through a fibre channel switch, eliminating the need for password maintenance at multiple entities and allowing fibre channel end devices to authenticate initiators, thereby simplifying password management and reducing administrative burdens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication is performed at multiple entities (fibre channel switches and targets), then security coverage is improved, but administrative complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidadministrative complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges authentication functionality into the fibre channel target device, combining what were previously separate authentication functions at switches and targets into a unified target-based authentication mechanism. This reduces administrative complexity while maintaining security coverage, as the target becomes the central authentication authority for both iSCSI initiators and fibre channel hosts.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If password information is maintained at fibre channel switches, then authentication capability is provided, but password management complexity increases

Engineering Contradiction:
Improveauthentication capabilityVSAvoidpassword management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts password information management from fibre channel switches and relocates it to fibre channel targets. This extraction simplifies password management by consolidating authentication credentials at the target level, eliminating the need for administrators to manage passwords across multiple switch devices while preserving authentication capability.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If authentication exchanges occur at multiple entities, then security is enhanced, but processing time increases

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary authentication actions at the fibre channel target before actual data transfers begin. By performing authentication exchanges upfront at a centralized location (the target), the system establishes security credentials once rather than repeatedly at multiple entities during subsequent operations, reducing overall authentication time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP1864441B1Iscsi and fibre channel authentication
Publication Date: 2019.11.06 CISCO TECHNOLOGY INC
  • EP1864441B1 patent drawingFigure 1
  • EP1864441B1 patent drawingFigure 2
  • EP1864441B1 patent drawingFigure 3

AI summary

Methods and apparatus are provided for authenticating an iSCSI initiator connected to a fibre channel storage area network. An iSCSI initiator performs an authentication exchange with a fibre channel target such as a fibre channel host or disk array through one or more fibre channel switches. Authentication information such as password information no longer is required at fibre channel switches and can instead be aggregated at fibre channel targets.