Fibre Channel Security via Entity Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Fibre channel networks lack comprehensive security measures, particularly for authentication, confidentiality, and anti-replay protection, leaving them vulnerable to attacks like spoofing and hijacking, especially when new entities are introduced into the fabric and beyond immediate neighboring nodes.

Innovation Solution

Implementing node-based and message-based security mechanisms, including entity-to-entity authentication and key exchange services within initialization messages, and using per-message authentication and encryption to secure frames passed between fibre channel network entities, ensuring continuous security across the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical security is used to secure all fibre channel network entities, then security is improved, but feasibility deteriorates because it is not always possible to locate every entity in a secured environment

Engineering Contradiction:
ImprovesecurityVSAvoidfeasibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent divides security into two layers: physical security for critical entities and logical/security protocol-based protection for all entities. This segmentation allows feasible implementation by applying strict physical security only where necessary while using authentication protocols universally.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces authentication messages and security protocols as intermediaries between network entities. These messages carry authentication data that verifies entity identities without requiring physical security for all entities, thus bridging the gap between security requirements and operational feasibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security checks are performed only by directly neighboring nodes, then device complexity is reduced, but security deteriorates because more distant nodes cannot perform checking and the fabric remains vulnerable to attacks

Engineering Contradiction:
ImprovesecurityVSAvoidsecurity check scope
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes authentication capability universal by enabling all nodes in the fabric to verify authentication messages, not just neighboring nodes. Each node can independently check authentication data in messages, providing comprehensive security coverage without significantly increasing individual device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent performs authentication checks preliminarily by including authentication data in initialization messages before normal operations begin. This preliminary authentication establishes trust relationships in advance, allowing all nodes to verify identities before communication starts, thus enhancing security without requiring continuous complex checking.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If once the link is established no further security is provided, then device complexity is reduced, but security deteriorates because the fabric is still vulnerable to spoofing, hijacking, or impersonation attacks

Engineering Contradiction:
ImprovesecurityVSAvoidcontinuous security provision
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements continuous security by incorporating authentication verification into ongoing communication processes. Security is not a one-time event but a continuous process where authentication data is verified throughout the communication lifecycle, preventing spoofing and hijacking attacks while maintaining manageable complexity through standardized protocols.

Inventive Principle:
Principle #20Continuity of useful action

4Reliability

If per-message authentication and encryption are implemented, then security is improved, but device complexity and processing overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidsecurity mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies partial authentication and encryption to only those messages that require enhanced security, rather than uniformly applying full security measures to all communications. This selective approach provides necessary security protection while avoiding unnecessary complexity and overhead for less sensitive communications.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS7965843B1Methods and apparatus for security over fibre channel
Publication Date: 2011.06.21 CISCO TECHNOLOGY INC
  • US7965843B1 patent drawing
  • US7965843B1 patent drawing
  • US7965843B1 patent drawing

AI summary

Methods and apparatus are provided for improving both node-based and message-based security in a fibre channel network. Entity to entity authentication and key exchange services can be included in existing initialization messages used for introducing fibre channel network entities into a fibre channel fabric, or with specific messages exchanged over an already initialized communication channel. Both per-message authentication and encryption mechanisms can be activated using the authentication and key exchange services. Messages passed between fibre channel network entities can be encrypted and authenticated using information provided during the authentication sequence. Security services such as per-message authentication, confidentiality, integrity protection, and anti-replay protection can be implemented.