Methods and apparatus for confidentiality protection for fibre channel common transport
Abstract
Methods and apparatus are provided for improving message-based security in a Fibre Channel network. More specifically, the present invention relates to methods and apparatus for providing confidentiality for Fibre Channel control messages encapsulated within Common Transport Information Units. Control messages transported with the Fibre Channel Common Transport protocol, and passed between Fibre Channel network entities, can be encrypted providing confidentiality combined with data origin authentication, integrity and anti-replay protection provided by existing Fibre Channel security mechanisms.
Claims
exact text as granted — not AI-modified1 . A method comprising:
identifying network traffic having a source corresponding to a first network entity in a network and a destination corresponding to a second network entity in the network; determining if the network traffic corresponds to selectors of a first entry in a security database, wherein the determining includes comparing a class of traffic of the network traffic against a class of traffic identified in the first entry; assigning a security association identified to the network traffic; and creating a second entry in the security database, the second entry including the security association identification and encryption information, wherein the encryption information is to be used to encrypt a first portion of the network traffic.
2 . The method of claim 1 , further comprising transmitting the network traffic to the second network entity.
3 . The method of claim 1 , wherein the network is a Fibre Channel network.
4 . The method of claim 1 , wherein the determining includes comparing the source of the network traffic against a source identified in the first entry.
5 . The method of claim 1 , wherein the determining includes comparing the destination of the network traffic against a destination identified in the first entry.
6 . The method of claim 1 , wherein a payload of the network traffic is padded prior to encrypting the first portion of the network traffic.
7 . An apparatus comprising:
means for identifying network traffic having a source corresponding to a first network entity in a network and a destination corresponding to a second network entity in the network; means for determining if the network traffic corresponds to selectors of a first entry in a security database, wherein the determining includes comparing a class of traffic of the network traffic against a class of traffic identified in the first entry; means for assigning a security association identified to the network traffic; and means for creating a second entry in the security database, the second entry including the security association identification and encryption information, wherein the encryption information is to be used to encrypt a first portion of the network traffic.
8 . The apparatus of claim 7 , further comprising means for transmitting the network traffic to the second network entity.
9 . The apparatus of claim 7 , wherein the network is a Fibre Channel network.
10 . The apparatus of claim 7 , wherein the means for determining includes means for comparing the source of the network traffic against a source identified in the first entry.
11 . The apparatus of claim 7 , wherein the means for determining includes means for comparing the destination of the network traffic against a destination identified in the first entry.
12 . The apparatus of claim 7 , further comprising means for padding the network traffic prior to encrypting the first portion of the network traffic.
13 . A network device comprising:
one or more ports; and at least one processor configured to perform the following steps:
identifying network traffic having a source corresponding to a first network entity in a network and a destination corresponding to a second network entity in the network;
determining if the network traffic corresponds to selectors of a first entry in a security database, wherein the determining includes comparing a class of traffic of the network traffic against a class of traffic identified in the first entry;
assigning a security association identified to the network traffic; and
creating a second entry in the security database, the second entry including the security association identification and encryption information, wherein the encryption information is to be used to encrypt a first portion of the network traffic.
14 . The network device of claim 13 , wherein the one or more processors are further configured to transmit the network traffic to the second network entity.
15 . The network device of claim 13 , wherein the network is a Fibre Channel network.
16 . The network device of claim 13 , wherein the determining includes comparing the source of the network traffic against a source identified in the first entry.
17 . The network device of claim 13 , wherein the determining includes comparing the destination of the network traffic against a destination identified in the first entry.
18 . The network device of claim 13 , wherein the one or more processors are further configured to pad a payload of the network traffic prior to encrypting the first portion of the network traffic.Join the waitlist — get patent alerts
Track US2008095367A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.