Fibre Channel Node Authentication Path Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The FC-SP-2 standard's certificate-based authentication for Fibre Channel links is computationally intensive and time-consuming, leading to elongated link initialization times and performance constraints in large enterprise servers with many physical ports, due to the need for repeated key exchanges and central processing unit-intensive mathematical computations.
Innovation Solution
A method is introduced where a node obtains a shared key from a key server, uses it to decrypt an encrypted message, and sends a response message with a security parameters index to another node, establishing a secure path without repeated key retrieval, reducing processing time and improving system performance by minimizing certificate exchange and validation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If certificate-based authentication (FCAP/IKE protocol) is used for Fibre Channel links, then security and authentication strength are improved, but link initialization time increases and system performance deteriorates
Solution Approach 1:
The patent applies preliminary action by performing certificate validation and key exchange operations before the actual Fibre Channel link initialization. The authentication protocol prepares and validates certificates in advance, so that when the link needs to be initialized, the authentication is already complete or can be completed much faster, thereby reducing link initialization time while maintaining strong security.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism that mediates between the certificate-based security requirements and the performance requirements. This intermediary layer handles the computationally intensive certificate validation and key exchange operations separately from the main data transmission path, allowing secure authentication without blocking the Fibre Channel link initialization process.
2Reliability
If repeated key exchanges are performed for each Fibre Channel link, then authentication security is maintained, but processing time increases and system performance decreases
Solution Approach 1:
The patent applies universality by creating a single authentication context that serves multiple Fibre Channel links. Once authentication is performed for a node, the same authenticated context can be reused across multiple links, eliminating the need for repeated key exchanges. This multi-functional authentication approach maintains security while dramatically improving system performance by avoiding redundant computations.
Solution Approach 2:
The patent discards the need for repeated key exchange operations by recovering and reusing authentication results. Instead of performing full key exchanges for each link, the system recovers the authentication state from previous operations and reuses it, thereby maintaining security without the processing overhead of repeated exchanges.
3Reliability
If intensive mathematical computations are performed for authentication, then authentication strength is improved, but CPU resource consumption increases and system initialization is constrained
Solution Approach 1:
The patent performs the intensive mathematical computations for certificate validation and key generation in advance, during system initialization or setup phases. By completing these computationally heavy operations beforehand, the system avoids consuming excessive CPU resources during normal operation and link initialization, while still maintaining strong authentication strength.
Solution Approach 2:
The patent implements self-service by having the authentication system handle its own computational requirements efficiently. The system uses hardware acceleration capabilities and optimized algorithms to perform cryptographic operations with minimal CPU intervention, allowing strong authentication without excessive resource consumption during normal operation.
Data Source
AI summary
A path for a node of a computing environment is secured. The securing includes obtaining, by the node, a message that includes an identifier of a shared key and an encrypted message. The node obtains the shared key from a key server and uses it to decrypt the encrypted message to obtain an encryption key and one or more parameters. A security parameters index to be associated with the encryption key and the one or more parameters is obtained. The node sends a response message to another node, the response message including the security parameters index.


