Shared Key Authentication for Fibre Channel Links
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The FC-SP-2 standard's certificate-based authentication for Fibre Channel links is computationally intensive and time-consuming, leading to elongated link initialization times and performance constraints in large enterprise servers with many physical ports.
Innovation Solution
A method where a shared key is generated by a key server and used for authentication across multiple links, reducing the need for repeated key retrieval and enabling efficient authentication of nodes without re-accessing the key server, thus streamlining the authentication process and reducing initialization times.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If certificate-based authentication is performed on every Fibre Channel link using the FCAP protocol, then security and authentication are ensured, but link initialization time increases and system performance deteriorates
Solution Approach 1:
The patent applies preliminary action by performing authentication once at link establishment before any client traffic flows. The FCAP protocol authentication is executed in advance during link initialization, creating a chain of trust that can be reused across multiple links. This preliminary authentication prevents repeated computational overhead during normal operation.
Solution Approach 2:
The patent implements universality by creating a single chain of trust between two entities that can be applied across multiple Fibre Channel links. The authentication result from one link serves as a universal credential that enables secure communication on other links without repeating the full authentication process, making the authentication mechanism multi-functional across the network fabric.
2Reliability
If the FCAP protocol is executed on every Fibre Channel link, then mutual authentication is achieved, but the multiplier effect of CPU-intensive computations affects system initialization and normal operation
Solution Approach 1:
The patent performs the CPU-intensive FCAP protocol authentication in advance during link establishment rather than repeatedly during normal operation. The authentication computations are completed preliminarily, and the resulting chain of trust is cached and reused, eliminating the multiplier effect of repeated computations on system productivity.
Solution Approach 2:
The patent creates a copy of the authentication credentials (chain of trust) that can be reused across multiple links. Instead of repeating the full authentication computation on each link, the system copies and applies the previously established trust relationship, significantly reducing computational overhead while maintaining authentication integrity.
3Reliability
If certificate exchange and validation are performed inline on each link, then strong secure authentication is provided, but the process is computationally intensive and time-consuming
Solution Approach 1:
The patent performs certificate exchange and validation as a preliminary action during link establishment. The computationally intensive FCAP protocol is executed in advance, creating a chain of trust that validates both parties' identities. This preliminary computation avoids repeated high-power operations during normal link usage.
Solution Approach 2:
The patent creates a copied version of the authentication credentials that can be reused across multiple links without repeating the full certificate validation process. The chain of trust is copied and applied to subsequent links, dramatically reducing computational intensity while maintaining the same security level.
Data Source
AI summary
Authentication is performed on a plurality of links of a computing environment. One node requests generation of a shared key by a key server coupled to the one node. The one node obtains the shared key and an identifier of the shared key and sends the identifier from the one node to another node. A message encrypted with the shared key is sent from the one node to the other node via one link of the plurality of links. The one node receives via the one link an indication that the other node decrypted the encrypted message using the shared key obtained by the other node. The sending the encrypted message and the receiving the indication that the other node decrypted the encrypted message are repeated on one or more other links of the plurality of links using the shared key previously obtained.


