Fibre Channel Node Authentication Path Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The FC-SP-2 standard's certificate-based authentication for Fibre Channel links is computationally intensive and time-consuming, leading to elongated link initialization times and performance constraints in large enterprise servers with many physical ports, due to the need for repeated key exchanges and central processing unit-intensive mathematical computations.

Innovation Solution

A method is introduced where a node obtains a shared key from a key server, uses it to decrypt an encrypted message, and sends a response message with a security parameters index to another node, establishing a secure path without repeated key retrieval, reducing processing time and improving system performance by minimizing certificate exchange and validation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If certificate-based authentication (FCAP/IKE protocol) is used for Fibre Channel links, then security and authentication strength are improved, but link initialization time increases and system performance deteriorates

Engineering Contradiction:
Improveauthentication strengthVSAvoidlink initialization time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by performing certificate validation and key exchange operations before the actual Fibre Channel link initialization. The authentication protocol prepares and validates certificates in advance, so that when the link needs to be initialized, the authentication is already complete or can be completed much faster, thereby reducing link initialization time while maintaining strong security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication mechanism that mediates between the certificate-based security requirements and the performance requirements. This intermediary layer handles the computationally intensive certificate validation and key exchange operations separately from the main data transmission path, allowing secure authentication without blocking the Fibre Channel link initialization process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If repeated key exchanges are performed for each Fibre Channel link, then authentication security is maintained, but processing time increases and system performance decreases

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies universality by creating a single authentication context that serves multiple Fibre Channel links. Once authentication is performed for a node, the same authenticated context can be reused across multiple links, eliminating the need for repeated key exchanges. This multi-functional authentication approach maintains security while dramatically improving system performance by avoiding redundant computations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent discards the need for repeated key exchange operations by recovering and reusing authentication results. Instead of performing full key exchanges for each link, the system recovers the authentication state from previous operations and reuses it, thereby maintaining security without the processing overhead of repeated exchanges.

Inventive Principle:
Principle #34Discarding and recovering

3Reliability

If intensive mathematical computations are performed for authentication, then authentication strength is improved, but CPU resource consumption increases and system initialization is constrained

Engineering Contradiction:
Improveauthentication strengthVSAvoidCPU resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by stationary object

Solution Approach 1:

The patent performs the intensive mathematical computations for certificate validation and key generation in advance, during system initialization or setup phases. By completing these computationally heavy operations beforehand, the system avoids consuming excessive CPU resources during normal operation and link initialization, while still maintaining strong authentication strength.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements self-service by having the authentication system handle its own computational requirements efficiently. The system uses hardware acceleration capabilities and optimized algorithms to perform cryptographic operations with minimal CPU intervention, allowing strong authentication without excessive resource consumption during normal operation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11522681B2Securing a path at a node
Publication Date: 2022.12.06 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11522681B2 patent drawing
  • US11522681B2 patent drawing
  • US11522681B2 patent drawing

AI summary

A path for a node of a computing environment is secured. The securing includes obtaining, by the node, a message that includes an identifier of a shared key and an encrypted message. The node obtains the shared key from a key server and uses it to decrypt the encrypted message to obtain an encryption key and one or more parameters. A security parameters index to be associated with the encryption key and the one or more parameters is obtained. The node sends a response message to another node, the response message including the security parameters index.