IP Library Granted Patent US 11,520,937
Granted Patent B2
US 11,520,937 · App. 17/158,912 · Granted Dec 6, 2022

NVMe over fabrics authentication system

Inventors: Claudio Desanti (Santa Cruz, CA); David Lionel Black (Acton, MA)
Assignee: Dell Products L.P.
G06F21/79G06F21/31G06F21/6209G06F21/85G06F2221/2103
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,520,937
App. No.
17/158,912
Granted
Dec 6, 2022
Kind
B2
Abstract

An NVMe-oF authentication system includes an authentication verification entity coupled to an NVMe subsystem that is coupled to an NVMe host device. The NVMe subsystem transmits a first challenge to the NVMe host device and, in response, receives a first challenge reply from the NVME host device. The NVMe subsystem then generates a first authentication verification request communication that includes a first response that was provided in the first challenge reply by the NVMe host device using a first instance of a first secret that is stored in the NVMe host device, and transmits the first authentication verification request communication to the authentication verification entity. The authentication verification entity receives the first authentication verification request communication, verifies the first response using a second instance of the first secret that is stored in the authentication verification entity and, in response, transmits a first authentication verification response communication to the NVMe subsystem.

Claims (88)

1. A Non-Volatile Memory express (NVMe) over Fabrics (NVMe-oF) authentication system, comprising:

an authentication verification entity;

a Non-Volatile Memory express (NVMe) host device;

an NVMe subsystem that is coupled to the authentication verification entity and the NVMe host device, wherein the NVMe subsystem is configured to:

authenticate the authentication verification entity,

wherein the authentication verification entity is configured, subsequent to being authenticated by the NVMe subsystem, to:

transmit a first challenge to the NVMe subsystem;

receive, in response to the first challenge, a first challenge reply from the NVME subsystem that includes a first response that was provided in the first challenge reply by the NVMe subsystem using a first instance of a first secret that is stored in the NVMe subsystem;

verify the first response using a second instance of the first secret that is stored in the authentication verification entity; and

authenticate, in response to verifying the first response, the NVMe subsystem,

wherein the NVMe subsystem is configured, subsequent to being authenticated by the authentication verification entity, to:

transmit a second challenge to the NVMe host device;

receive, in response to the second challenge, a second challenge reply from the NVME host device;

generate a first authentication verification request communication that includes a second response that was provided in the second challenge reply by the NVMe host device using a first instance of a second secret that is stored in the NVMe host device; and

transmit, to the authentication verification entity, the first authentication verification request communication, and

wherein the authentication verification entity is configured to:

receive the first authentication verification request communication from the NVMe subsystem;

verify the second response using a second instance of the second secret that is stored in the authentication verification entity; and

transmit, in response to verifying the second response, a first authentication verification response communication to the NVMe subsystem.

2. The system of claim 1 , wherein the NVMe host device is configured to:

transmit a third challenge to the NVMe subsystem;

receive, in response to the third challenge, a third challenge reply from the NVME subsystem;

generate a second authentication verification request communication that includes a third response that was provided in the third challenge reply by the NVMe subsystem using a first instance of a third secret that is stored in the NVMe subsystem; and

transmit the second authentication verification request communication, and

wherein the authentication verification entity is coupled to the NVMe host device and is configured to:

receive the second authentication verification request communication from the NVMe host device;

verify the third response using a second instance of the third secret that is stored in the authentication verification entity; and

transmit, in response to verifying the third response, a second authentication verification response communication to the NVMe host device.

3. The system of claim 1 , wherein the NVMe subsystem is configured to:

receive the first authentication verification response communication from the authentication verification entity; and

enable, in response to receiving the first authentication verification response communication, storage operations by the NVMe host device via a communication channel with the NVMe host device.

4. The system of claim 1 , wherein the NVMe subsystem is configured to authenticate the authentication verification entity by:

authenticating, using an authentication verification entity identifier and an authentication verification entity public key, the authentication verification entity.

5. The system of claim 1 , wherein the authentication verification entity is configured, in response to being authenticated by the NVMe subsystem, to:

establish a secure communication channel with the NVMe subsystem.

6. The system of claim 1 , wherein the NVMe subsystem is configured to authenticate the authentication verification entity by:

performing mutual authentication operations, using an authentication verification entity/NVMe subsystem shared secret, with the authentication verification entity.

7. The system of claim 1 , wherein the NVMe host device is configured to:

authenticate the authentication verification entity,

wherein the authentication verification entity is configured, subsequent to being authenticated by the NVMe host device, to:

transmit a third challenge to the NVMe host device;

receive, in response to the third challenge, a third challenge reply from the NVME host device that includes a third response that was provided in the third challenge reply by the NVMe host device using a first instance of a third secret that is stored in the NVMe host device;

verify the third response using a second instance of the third secret that is stored in the authentication verification entity; and

authenticate, in response to verifying the third response, the NVMe host device.

8. The system of claim 7 , wherein the NVMe host device is configured to authenticate the authentication verification entity by:

authenticating, using the authentication verification entity identifier and the authentication verification entity public key, the authentication verification entity.

9. The system of claim 7 , wherein the NVMe host device is configured to authenticate the authentication verification entity by:

performing mutual authentication operations, using an authentication verification entity/NVMe host device shared secret, with the authentication verification entity.

10. An Information Handling System (IHS), comprising:

a processing system; and

a memory system that is coupled to the processing system and that includes instructions that, when executed by the processing system, cause the processing system to provide an authentication verification engine that is configured, subsequent to being authenticated by a Non-Volatile Memory express (NVMe) subsystem, to:

transmit a first challenge to the NVMe subsystem;

receive, in response to the first challenge, a first challenge reply from the NVME subsystem that includes a first response that was provided in the first challenge reply by the NVMe subsystem using a first instance of a first secret that is stored in the NVMe subsystem;

verify the first response using a second instance of the first secret that is stored in the IHS; and

authenticate, in response to verifying the first response, the NVMe subsystem,

wherein the authentication verification entity is configured, subsequent to authenticating the NVMe subsystem, to:

receive, from the NVMe subsystem, a first authentication verification request communication that includes a second response that was provided to the NVMe subsystem in a second challenge reply by an NVMe host device using a first instance of a second secret that is stored in the NVMe host device;

verify the second response using a second instance of the second secret that is stored in the IHS; and

transmit, in response to verifying the second response, a first authentication verification response communication to the NVMe subsystem.

11. The IHS of claim 10 , wherein the authentication verification engine is configured to:

receive, from the NVMe host device, a second authentication verification request communication that includes a third response that was provided to the NVMe host device in a third challenge reply by the NVMe subsystem using a first instance of a third secret that is stored in the NVMe subsystem;

verify the third response using a second instance of the third secret that is stored in the IHS; and

transmit, in response to verifying the third response, a second authentication verification response communication to the NVMe host device.

12. The IHS of claim 10 , wherein the authentication verification engine is configured to be authenticated by the NVMe subsystem by:

authenticating, using an authentication verification entity identifier and an authentication verification entity public key, with the NVMe subsystem.

13. The IHS of claim 10 , wherein the authentication verification engine is configured to be authenticated by the NVMe subsystem by:

performing, using an authentication verification entity/NVMe subsystem shared secret, mutual authentication operations with the NVMe subsystem.

14. The IHS of claim 10 , wherein the authentication verification engine is configured to:

establish, in response to being authenticated by the NVMe subsystem, a secure communication channel with the NVMe subsystem.

15. A method for performing Non-Volatile Memory express (NVMe) over Fabrics authentication, comprising:

transmitting, by the authentication verification entity in response to being authenticated by a Non-Volatile Memory express (NVMe) subsystem, a first challenge to the NVMe subsystem;

receiving, by the authentication verification entity in response to the first challenge, a first challenge reply from the NVME subsystem that includes a first response that was provided in the first challenge reply by the NVMe subsystem using a first instance of a first secret that is stored in the NVMe subsystem;

verifying, by the authentication verification entity, the first response using a second instance of the first secret that is stored in the authentication verification entity;

authenticating, by the authentication verification entity in response to verifying the first response, the NVMe subsystem;

receiving, by the authentication verification entity from the NVMe subsystem subsequent to authenticating the NVMe subsystem, a first authentication verification request communication that includes a second response that was provided to the NVMe subsystem in a second challenge reply by an NVMe host device using a first instance of a second secret that is stored in the NVMe host device;

verifying, by the authentication verification entity, the second response using a second instance of the second secret that is stored in the authentication verification entity; and

transmitting, by the authentication verification entity in response to verifying the second response, a first authentication verification response communication to the NVMe subsystem.

16. The method of claim 15 , further comprising:

receiving, by the authentication verification entity from the NVMe host device, a third authentication verification request communication that includes a third response that was provided to the NVMe host device in a third challenge reply by the NVMe subsystem using a first instance of a third secret that is stored in the NVMe subsystem;

verifying, by the authentication verification entity, the third response using a second instance of the third secret that is stored in the authentication verification entity; and

transmitting, by the authentication verification entity in response to verifying the third response, a second authentication verification response communication to the NVMe host device.

17. The method of claim 16 , wherein the first authentication verification response communication and the second authentication verification response communication indicate to the NVMe subsystem and the NVMe host device to continue communications.

18. The method of claim 15 , further comprising:

authenticating, by the NVME subsystem using an authentication verification entity identifier and an authentication verification entity public key, the authentication verification entity.

19. The method of claim 15 , further comprising:

establishing, by the authentication verification entity with the NVMe subsystem in response to being authenticated by the NVMe subsystem, a secure communications channel.

20. The method of claim 15 , further comprising:

authenticating, by the NVMe subsystem using an authentication verification entity/NVMe subsystem shared secret, the authentication verification entity by performing mutual authentication operations with the authentication verification entity.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (055479/0342) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0460 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (055479/0051) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0663 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056136/0752) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0771 →
RELEASE OF SECURITY INTEREST AT REEL 055408 FRAME 0697 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0553 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056136/0752 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 055479/0051 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 055479/0342 →
SECURITY AGREEMENT Recorded Feb 25, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 055408/0697 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 26, 2021
From: DESANTI, CLAUDIO; BLACK, DAVID LIONEL
To: DELL PRODUCTS L.P.
Reel/Frame 055038/0844 →
Continuity (2)
Provisional Application 63064509 · Aug 12, 2020
Related Publication 20220050933A1 · Feb 17, 2022