US2008095367A1PendingUtilityA1

Methods and apparatus for confidentiality protection for fibre channel common transport

Assignee: CISCO TECH INCPriority: Mar 19, 2004Filed: Dec 18, 2007Published: Apr 24, 2008
Est. expiryMar 19, 2024(expired)· nominal 20-yr term from priority
H04L 63/126H04L 63/0435H04L 63/123H04L 63/061
52
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Methods and apparatus are provided for improving message-based security in a Fibre Channel network. More specifically, the present invention relates to methods and apparatus for providing confidentiality for Fibre Channel control messages encapsulated within Common Transport Information Units. Control messages transported with the Fibre Channel Common Transport protocol, and passed between Fibre Channel network entities, can be encrypted providing confidentiality combined with data origin authentication, integrity and anti-replay protection provided by existing Fibre Channel security mechanisms.

Claims

exact text as granted — not AI-modified
1 . A method comprising: 
 identifying network traffic having a source corresponding to a first network entity in a network and a destination corresponding to a second network entity in the network;    determining if the network traffic corresponds to selectors of a first entry in a security database, wherein the determining includes comparing a class of traffic of the network traffic against a class of traffic identified in the first entry;    assigning a security association identified to the network traffic; and    creating a second entry in the security database, the second entry including the security association identification and encryption information, wherein the encryption information is to be used to encrypt a first portion of the network traffic.    
   
   
       2 . The method of  claim 1 , further comprising transmitting the network traffic to the second network entity.  
   
   
       3 . The method of  claim 1 , wherein the network is a Fibre Channel network.  
   
   
       4 . The method of  claim 1 , wherein the determining includes comparing the source of the network traffic against a source identified in the first entry.  
   
   
       5 . The method of  claim 1 , wherein the determining includes comparing the destination of the network traffic against a destination identified in the first entry.  
   
   
       6 . The method of  claim 1 , wherein a payload of the network traffic is padded prior to encrypting the first portion of the network traffic.  
   
   
       7 . An apparatus comprising: 
 means for identifying network traffic having a source corresponding to a first network entity in a network and a destination corresponding to a second network entity in the network;    means for determining if the network traffic corresponds to selectors of a first entry in a security database, wherein the determining includes comparing a class of traffic of the network traffic against a class of traffic identified in the first entry;    means for assigning a security association identified to the network traffic; and    means for creating a second entry in the security database, the second entry including the security association identification and encryption information, wherein the encryption information is to be used to encrypt a first portion of the network traffic.    
   
   
       8 . The apparatus of  claim 7 , further comprising means for transmitting the network traffic to the second network entity.  
   
   
       9 . The apparatus of  claim 7 , wherein the network is a Fibre Channel network.  
   
   
       10 . The apparatus of  claim 7 , wherein the means for determining includes means for comparing the source of the network traffic against a source identified in the first entry.  
   
   
       11 . The apparatus of  claim 7 , wherein the means for determining includes means for comparing the destination of the network traffic against a destination identified in the first entry.  
   
   
       12 . The apparatus of  claim 7 , further comprising means for padding the network traffic prior to encrypting the first portion of the network traffic.  
   
   
       13 . A network device comprising: 
 one or more ports; and    at least one processor configured to perform the following steps: 
 identifying network traffic having a source corresponding to a first network entity in a network and a destination corresponding to a second network entity in the network;  
 determining if the network traffic corresponds to selectors of a first entry in a security database, wherein the determining includes comparing a class of traffic of the network traffic against a class of traffic identified in the first entry;  
 assigning a security association identified to the network traffic; and  
 creating a second entry in the security database, the second entry including the security association identification and encryption information, wherein the encryption information is to be used to encrypt a first portion of the network traffic.  
   
   
   
       14 . The network device of  claim 13 , wherein the one or more processors are further configured to transmit the network traffic to the second network entity.  
   
   
       15 . The network device of  claim 13 , wherein the network is a Fibre Channel network.  
   
   
       16 . The network device of  claim 13 , wherein the determining includes comparing the source of the network traffic against a source identified in the first entry.  
   
   
       17 . The network device of  claim 13 , wherein the determining includes comparing the destination of the network traffic against a destination identified in the first entry.  
   
   
       18 . The network device of  claim 13 , wherein the one or more processors are further configured to pad a payload of the network traffic prior to encrypting the first portion of the network traffic.

Join the waitlist — get patent alerts

Track US2008095367A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.