Local Key Manager Secure Key Exchange for Fibre Channel
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The FC-SP-2 standard's certificate-based authentication for Fibre Channel links is computationally intensive and time-consuming, leading to elongated link initialization times and system constraints, especially in large enterprise environments with numerous Fibre Channel physical ports and dynamic switched fabrics.
Innovation Solution
A secure key exchange (SKE) initialization request is generated by a local key manager (LKM) between initiator and responder nodes, creating a security association and using shared keys for secure communication, reducing the need for frequent authentication and minimizing computational overhead.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If certificate-based authentication (FCAP protocol) is used for secure communication, then security strength is improved, but link initialization time is elongated and system performance is constrained
Solution Approach 1:
The patent applies preliminary action by pre-establishing security associations and performing authentication setup before actual data transmission begins. The FCAP protocol executes certificate validation and key exchange during link initialization phase, so that when client traffic flows start, the secure communication channel is already established and authenticated, eliminating the need for repeated authentication during data transfer.
Solution Approach 2:
The patent extracts the computationally intensive certificate-based authentication process from the data transmission path and isolates it to the link initialization phase only. By separating authentication setup from ongoing data transfer operations, the heavy computational burden of FCAP protocol is confined to initial link establishment, allowing subsequent data communication to proceed without repeated authentication overhead.
2Reliability
If certificate-based authentication is performed on every Fibre Channel link, then authentication security is improved, but CPU computational load increases significantly
Solution Approach 1:
The patent performs certificate-based authentication in advance during link initialization before any client traffic flows. The FCAP protocol completes all computationally intensive operations including certificate validation, signature verification, and key exchange during the setup phase, so that CPU-intensive operations are not repeated during subsequent data transmission, reducing overall computational load.
Solution Approach 2:
The patent implements periodic authentication only at link initialization events rather than continuously during data transfer. The FCAP protocol is executed periodically at discrete initialization moments, and once authentication is established, the security association remains valid for the duration of the link, eliminating the need for continuous CPU-intensive authentication operations.
3Reliability
If FCAP protocol is executed before client traffic flows, then secure communication is established, but system productivity is reduced
Solution Approach 1:
The patent executes the FCAP protocol in advance during link initialization to establish secure communication channels before client traffic flows begin. By completing authentication and key exchange beforehand, the system ensures that when data transfer starts, the secure pathway is already ready, preventing interruptions during productive data transmission phases.
Solution Approach 2:
The patent segments the system initialization process into distinct phases: first executing the computationally intensive FCAP authentication protocol during link initialization, then transitioning to high-speed data transfer phase. This segmentation allows the heavy authentication workload to be isolated to setup phase, while productivity-critical data transfer operations can proceed at full speed without authentication overhead.
Data Source
AI summary
Aspects of the invention include receiving a request from an initiator channel on an initiator node to initiate a secure communication with a responder channel on a responder node. The receiving is at a local key manager (LKM) executing on the initiator node. A security association is created at the LKM between the initiator node and the responder node. An identifier of a shared key assigned for communication between the initiator node and the responder node is obtained, and a message requesting initialization of the secure communication between the initiator channel and the responder channel is built. The message includes the identifier of the shared key. The message is sent to the initiator channel.


