Shared Key Authentication for Fibre Channel Links

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The FC-SP-2 standard's certificate-based authentication for Fibre Channel links is computationally intensive and time-consuming, leading to elongated link initialization times and performance constraints in large enterprise servers with many physical ports.

Innovation Solution

A method where a shared key is generated by a key server and used for authentication across multiple links, reducing the need for repeated key retrieval and enabling efficient authentication of nodes without re-accessing the key server, thus streamlining the authentication process and reducing initialization times.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If certificate-based authentication is performed on every Fibre Channel link using the FCAP protocol, then security and authentication are ensured, but link initialization time increases and system performance deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoidlink initialization time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by performing authentication once at link establishment before any client traffic flows. The FCAP protocol authentication is executed in advance during link initialization, creating a chain of trust that can be reused across multiple links. This preliminary authentication prevents repeated computational overhead during normal operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements universality by creating a single chain of trust between two entities that can be applied across multiple Fibre Channel links. The authentication result from one link serves as a universal credential that enables secure communication on other links without repeating the full authentication process, making the authentication mechanism multi-functional across the network fabric.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If the FCAP protocol is executed on every Fibre Channel link, then mutual authentication is achieved, but the multiplier effect of CPU-intensive computations affects system initialization and normal operation

Engineering Contradiction:
Improvemutual authenticationVSAvoidsystem initialization and operation speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent performs the CPU-intensive FCAP protocol authentication in advance during link establishment rather than repeatedly during normal operation. The authentication computations are completed preliminarily, and the resulting chain of trust is cached and reused, eliminating the multiplier effect of repeated computations on system productivity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a copy of the authentication credentials (chain of trust) that can be reused across multiple links. Instead of repeating the full authentication computation on each link, the system copies and applies the previously established trust relationship, significantly reducing computational overhead while maintaining authentication integrity.

Inventive Principle:
Principle #26Copying

3Reliability

If certificate exchange and validation are performed inline on each link, then strong secure authentication is provided, but the process is computationally intensive and time-consuming

Engineering Contradiction:
Improvesecure authenticationVSAvoidcomputational intensity
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The patent performs certificate exchange and validation as a preliminary action during link establishment. The computationally intensive FCAP protocol is executed in advance, creating a chain of trust that validates both parties' identities. This preliminary computation avoids repeated high-power operations during normal link usage.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a copied version of the authentication credentials that can be reused across multiple links without repeating the full certificate validation process. The chain of trust is copied and applied to subsequent links, dramatically reducing computational intensity while maintaining the same security level.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10833860B2Shared key processing by a host to secure links
Publication Date: 2020.11.10 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10833860B2 patent drawing
  • US10833860B2 patent drawing
  • US10833860B2 patent drawing

AI summary

Authentication is performed on a plurality of links of a computing environment. One node requests generation of a shared key by a key server coupled to the one node. The one node obtains the shared key and an identifier of the shared key and sends the identifier from the one node to another node. A message encrypted with the shared key is sent from the one node to the other node via one link of the plurality of links. The one node receives via the one link an indication that the other node decrypted the encrypted message using the shared key obtained by the other node. The sending the encrypted message and the receiving the indication that the other node decrypted the encrypted message are repeated on one or more other links of the plurality of links using the shared key previously obtained.