IP Library Granted Patent US 7,089,587
Granted Patent B2
US 7,089,587 · App. 10/116,523 · Granted Aug 8, 2006

ISCSI target offload administrator

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,089,587
App. No.
10/116,523
Granted
Aug 8, 2006
Kind
B2
Abstract

A method, system and apparatus for negotiating parameters for an IPSec connection between a requesting client and an iSCSI system using a computer system other than an iSCSI system are provided. By design, the iSCSI system monitors TCP (Transmission Control protocol) port 500 for secure requests. When a request enters port 500 , the iSCSI system transmits all information received on port 500 to a computer system better suited to handle IPSec parameter negotiations. After the computer system has negotiated the parameters, the parameters are passed to the iSCSI system for a secure data transaction to ensue.

Claims (31)

1. A method of transacting data over a secure network connection between an iSCSI system and a client system, the iSCSI system including a host system and an SCSI machine, the method comprising the steps of:

receiving from said client system, by said iCSCI machine, a request for a secure connection to transact the data;

forwarding, by said iSCSI machine, said request to said host system, said host system being used for negotiating parameters of the secure connection with the client system; and

passing, by said host system, the negotiated parameters of the secure connection to the iSCSI machine such that the iSCSI machine and the client system can transact data over the secure connection without further help from the host system.

2. The method of claim 1 wherein one of the parameters is an encryption/decryption key.

3. The method of claim 2 wherein the iSCSI includes a network adapter, the network adapter using the encryption/decryption key for encrypting/decrypting the data.

4. The method of claim 3 wherein the request for the secure connection is received at TCP (Transmission Control Protocol) port 500 .

5. The method of claim 4 wherein the request for the secure connection is a login request.

6. A computer program product on a computer readable medium for transacting data over a secure network connection between an iSCSI system and a client system, the iSCSI system including a host system and an iSCSI machine, the computer program product comprising:

code means for receiving from said client system, by said iCSCI machine, a request for a secure connection to transact the data;

code means for forwarding, by said iSCSI machine, said request to said host system, said host system being used for negotiating parameters of the secure connection with the client system; and

code means for passing, by said host system, the negotiated parameters of the secure connection to the iSCSI machine such that the iSCSI machine and the client system can transact data over the secure connection without further help from the host system.

7. The computer program product of claim 6 wherein one of the parameters is an encryption/decryption key.

8. The computer program product of claim 7 wherein the iSCSI includes a network adapter, the network adapter using the encryption/decryption key for encrypting/decrypting the data.

9. The computer program product of claim 8 wherein the request for the secure connection is received at TCP (Transmission Control Protocol) port 500 .

10. The computer program product of claim 9 wherein the request for the secure connection is a login request.

11. An apparatus for transacting data over a secure network connection with a client system, the apparatus including a host system and an iSCSI machine, the apparatus comprising:

means for receiving from said client system, by said iCSCI machine, a request for a secure connection to transact the data;

means for forwarding, by said iSCSI machine, said request to said host system, said host system being used for negotiating parameters of the secure connection with the client system; and

means for passing, by said host system, the negotiated parameters of the secure connection to the iSCSI machine such that the iSCSI machine and the client system can transact data over the secure connection without further help from the host system.

12. The apparatus of claim 11 wherein one of the parameters is an encryption/decryption key.

13. The apparatus of claim 12 wherein the iSCSI includes a network adapter, the network adapter using the encryption/decryption key for encrypting/decrypting the data.

14. The apparatus of claim 13 wherein the request for the secure connection is received at TCP (Transmission Control Protocol) port 500 .

15. The apparatus of claim 14 wherein the request for the secure connection is a login request.

16. An iSCSI system for transacting data over a secure network connection with a client system, the iSCSI system including a host system and an iSCSI machine, the iSCSI system comprising:

at least one storage system for storing code data; and

at least one processor for processing the code data to receive from said client system, by said iCSCI machine, a request for a secure connection to transact the data, to forward, by said iSCSI machine, said request to said host system, said host system being used for negotiating parameters of the secure connection with the client system, and to pass, by said host system, the negotiated parameters of the secure connection to the iSCSI machine such that the iSCSI machine and the client system can transact data over the secure connection without further help from the host system.

17. The computer system of claim 16 wherein one of the parameters is an encryption/decryption key.

18. The computer system of claim 17 wherein the iSCSI includes a network adapter, the network adapter using the encryption/decryption key for encrypting/decrypting the data.

19. The computer system of claim 18 wherein the request for the secure connection is received at TCP (Transmission Control Protocol) port 500 .

20. The computer system of claim 19 wherein the request for the secure connection is a login request.

Assignments (4)
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 37900/0720 Recorded Jul 13, 2018
From: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
To: MELLANOX TECHNOLOGIES, LTD.
Reel/Frame 046542/0792 →
PATENT SECURITY AGREEMENT Recorded Feb 24, 2016
From: MELLANOX TECHNOLOGIES, LTD.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 037900/0720 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 2, 2013
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: MELLANOX TECHNOLOGIES, LTD.
Reel/Frame 030128/0885 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 4, 2002
From: ALLEN, JAMES P.; CONKLIN, WILLIAM CHRISTOPHER; JAIN, VINIT; MULLEN, SHAWN PATRICK; SHARMA, RAKESH; SHARMA, SATYA PRAKESH
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 012773/0724 →