Fibre Channel Target Authentication for iSCSI Initiators
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional storage area network authentication mechanisms lead to inefficiencies due to multiple entities performing authentication, resulting in administrative complexities and inefficiencies, even with centralized password management services like RADIUS servers.
Innovation Solution
The solution involves aggregating authentication information at fibre channel targets, where an iSCSI initiator performs an authentication exchange with a fibre channel target through a fibre channel switch, eliminating the need for password maintenance at multiple entities and allowing fibre channel end devices to authenticate initiators, thereby simplifying password management and reducing administrative burdens.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication is performed at multiple entities (fibre channel switches and targets), then security coverage is improved, but administrative complexity increases
Solution Approach 1:
The patent merges authentication functionality into the fibre channel target device, combining what were previously separate authentication functions at switches and targets into a unified target-based authentication mechanism. This reduces administrative complexity while maintaining security coverage, as the target becomes the central authentication authority for both iSCSI initiators and fibre channel hosts.
2Reliability
If password information is maintained at fibre channel switches, then authentication capability is provided, but password management complexity increases
Solution Approach 1:
The patent extracts password information management from fibre channel switches and relocates it to fibre channel targets. This extraction simplifies password management by consolidating authentication credentials at the target level, eliminating the need for administrators to manage passwords across multiple switch devices while preserving authentication capability.
3Reliability
If authentication exchanges occur at multiple entities, then security is enhanced, but processing time increases
Solution Approach 1:
The patent implements preliminary authentication actions at the fibre channel target before actual data transfers begin. By performing authentication exchanges upfront at a centralized location (the target), the system establishes security credentials once rather than repeatedly at multiple entities during subsequent operations, reducing overall authentication time while maintaining security.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Methods and apparatus are provided for authenticating an iSCSI initiator connected to a fibre channel storage area network. An iSCSI initiator performs an authentication exchange with a fibre channel target such as a fibre channel host or disk array through one or more fibre channel switches. Authentication information such as password information no longer is required at fibre channel switches and can instead be aggregated at fibre channel targets.