Storage Port Audit Mode for Seamless Encryption Transition

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In Fibre Channel environments, existing security protocols do not adequately manage the transition from plaintext to encrypted data communication, particularly in heterogeneous settings where not all devices support security, leading to potential loss of connectivity and I/O errors when enabling security.

Innovation Solution

The implementation of an audit mode indicator allows I/O operations to continue in plaintext while initiating security associations, transitioning to encrypted data exchange, ensuring seamless connectivity and preventing I/O errors by allowing a grace period for queued plaintext data to be flushed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security protocols are enabled in Fibre Channel environments, then data security is improved, but connectivity is lost and I/O errors occur due to incompatible devices

Engineering Contradiction:
Improvedata securityVSAvoidconnectivity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically adjusts security enforcement based on the audit mode indicator state. When audit mode is enabled, the storage port allows plaintext I/O operations even if security association negotiation fails, effectively making the security enforcement flexible rather than rigid. This resolves the contradiction by allowing the system to adapt its security behavior based on operational context.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary security association negotiation while maintaining the capability to fall back to plaintext operation. The audit mode indicator is set in advance to permit plaintext I/O, allowing the system to attempt security establishment without risking connectivity loss. This preliminary action approach ensures that security is attempted first, but connectivity is preserved as a backup.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If encryption is enabled on an operational path, then data security is improved, but I/O operations are disrupted during the transition from plaintext to encrypted communication

Engineering Contradiction:
Improvedata securityVSAvoidI/O operation continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system maintains continuous I/O operation throughout the security transition by allowing plaintext operations to continue when audit mode is enabled. The storage port processes I/O requests without interruption during security association establishment, ensuring that useful action (data transfer) continues uninterrupted while security is being enhanced in the background.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The audit mode indicator acts as an intermediary mechanism that mediates between security requirements and operational continuity. It allows the system to transition from plaintext to encrypted communication by permitting plaintext operations during the transition period, thus bridging the gap between security enhancement and operational continuity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If security association negotiation is performed, then encrypted communication is achieved, but device complexity increases due to additional protocols and key management

Engineering Contradiction:
Improveencrypted communicationVSAvoidsecurity protocol implementation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements security associations as temporary, context-specific security contexts rather than permanent configurations. Each security association is established for a specific operational path and can be independently managed without affecting other paths. This allows security to be implemented where needed without requiring complex system-wide security infrastructure.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS11188658B2Concurrent enablement of encryption on an operational path at a storage port
Publication Date: 2021.11.30 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11188658B2 patent drawing
  • US11188658B2 patent drawing
  • US11188658B2 patent drawing

AI summary

A storage port is enabled for security. The storage port performs Input/Output (I/O) in plaintext on a path between the storage port and a host port, in response to determining that an audit mode indicator has been enabled to allow I/O even if authentication or security association negotiation between the storage port and the host port cannot be completed successfully. Concurrently with performing of I/O in plaintext on the path, the storage port enables encryption of data for I/O on the path.