Shared Key Authentication for Fibre Channel Link Initialization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The FC-SP-2 standard's certificate-based authentication for Fibre Channel links is computationally intensive and time-consuming, leading to elongated link initialization times and system performance constraints in large enterprise environments with many endpoints.

Innovation Solution

A method where nodes obtain a shared key from a key server and use it to authenticate multiple links without repeated key retrieval, establishing a chain of trust to reduce processing time and increase system performance by minimizing key server access during link initialization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If certificate-based authentication (FCAP/IKE protocol) is used for Fibre Channel links, then security and authentication strength are improved, but link initialization time increases and system performance deteriorates

Engineering Contradiction:
Improveauthentication strengthVSAvoidlink initialization time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs authentication and key exchange actions in advance before link initialization. Nodes obtain shared keys from a key server prior to establishing Fibre Channel links, so that when links are initialized, authentication can occur rapidly without repeated key retrieval operations. This preliminary authentication setup eliminates the time-consuming certificate validation and key exchange processes during normal link initialization.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If repeated key retrieval and certificate validation are performed for each link, then authentication reliability is maintained, but processing time increases and system performance is constrained

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent establishes a universal authentication mechanism where a single shared key obtained from the key server serves multiple Fibre Channel links simultaneously. Instead of performing separate authentication operations for each link, the system uses the universally obtained shared key to authenticate all links, thereby maintaining authentication reliability while significantly improving system performance by eliminating redundant processing.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges multiple authentication operations into a single operation. Rather than retrieving keys and validating certificates separately for each link, the system combines these operations into one preliminary authentication step where the shared key is obtained and then reused across all links. This merging of operations reduces processing time and enhances system productivity.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11038671B2Shared key processing by a storage device to secure links
Publication Date: 2021.06.15 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11038671B2 patent drawing
  • US11038671B2 patent drawing
  • US11038671B2 patent drawing

AI summary

Authentication is performed on a plurality of links to be used to couple one node of the computing environment and another node of the computing environment. The performing authentication includes obtaining, by the other node from the one node via one link of the plurality of links, an identifier of a shared key maintained by a key server. The other node uses the identifier to obtain the shared key from the key server. An indication that the other node decrypted a message received from the one node using the shared key is sent from the other node via the one link. The sending the indication on one or more other links of the plurality of links is repeated for subsequent messages decrypted by the other node using the shared key previously obtained.