IP Library › Granted Patent US 11,652,616
Granted Patent B2
US 11,652,616 · App. 16/801,280 · Granted May 16, 2023

Initializing a local key manager for providing secure data transfer in a computing environment

Inventors: Mooheng Zee (Dutchess, NY); Richard Mark Sczepczenski (Hyde Park, NY); John R. Flanagan (Chapel Hill, NC); Christopher J. Colonna (Ossining, NY)
Assignee: International Business Machines Corporation
H04L9/083G06F13/4068G06F21/606H04L9/3215H04L9/3268H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,652,616
App. No.
16/801,280
Granted
May 16, 2023
Kind
B2
Abstract

Aspects of the invention include initializing a local key manager (LKM) on a node of a computing environment. The node includes a plurality of channels. The LKM is configured to provide a secure data transfer between the node and an other node of the computing environment. A connection is established, by the LKM, between the LKM and an external key manager (EKM) that stores a shared key for the node and the other node. In response to establishing the connection, the LKM registers security capabilities of the plurality of channels. The security capabilities are used by the LKM to provide the secure data transfer between the node and the other node.

Claims (45)

1. A computer program product for facilitating processing in a computing environment, the computer program product comprising:

a computer readable storage medium readable by one or more processing circuits and storing instructions for performing operations comprising:

initializing a local key manager (LKM) on a node of the computing environment, the node comprising a plurality of channels;

establishing, by the LKM, a connection between the LKM and an external key manager (EKM) that stores a shared key for use by the node and an other node of the computing environment to provide a secure data transfer between the node and the other node;

in response to establishing the connection:

obtaining, by the LKM, the shared key from the EKM; and

registering, by the LKM, security capabilities of the plurality of channels, the security capabilities comprising one or more encryption algorithms supported by the channels, and

transmitting, by the LKM, an initialization request message to the other node, the initialization request message including an identifier of the shared key, a nonce and a security parameter index, wherein the initialization request message is not encrypted,

wherein the other node obtains the shared key from the EKM in response to the initialization request message

wherein communication between the node and the other node via the connection is protected using key created based on the shared key, a nonce and a security parameter index.

2. The computer program product of claim 1 , wherein the node is a host computer and the LKM executes in a logical partition of the host computer.

3. The computer program product of claim 1 , wherein the establishing a connection comprises initiating a request to the EKM for the connection, the request comprising an authentication certificate assigned to the node.

4. The computer program product of claim 3 , wherein the connection is established based at least in response to the EKM recognizing the authentication certificate.

5. The computer program product of claim 3 , wherein the request is a key management interoperability protocol (KMIP) message that is sent via a transport layer security (TLS) session to the EKM.

6. The computer program product of claim 1 , wherein the node is a host computer or a storage array.

7. The computer program product of claim 1 , wherein the other node is a host computer or a storage array.

8. The computer program product of claim 1 , wherein the channel is a host bus adapter (HBA).

9. The computer program product of claim 1 , wherein the LKM is further configured to provide a secure data transfer between two of the plurality of channels on the node.

10. A computer-implemented method of facilitating processing within a computing environment, the computer-implemented method comprising:

initializing a local key manager (LKM) on a node of the computing environment, the node comprising a plurality of channels;

establishing, by the LKM a connection between the LKM and an external key manager (EKM) that stores a shared key used by the node and an other node of the computing environment to provide a secure data transfer between the node and the other node;

in response to establishing the connection:

obtaining, by the LKM, the shared key from the EKM; and

registering, by the LKM, security capabilities of the plurality of channels, the security capabilities comprising one or more encryption algorithms supported by the channels, and

transmitting, by the LKM, an initialization request message to the other node, the initialization request message including an identifier of the shared key, a nonce and a security parameter index, wherein the initialization request message is not encrypted,

wherein the other node obtains the shared key from the EKM in response to the initialization request message

wherein communication between the node and the other node via the connection is protected using key created based on the shared key, a nonce and a security parameter index.

11. The computer-implemented method of claim 10 , wherein the node is a host computer and the LKM executes in a logical partition of the host computer.

12. The computer-implemented method of claim 10 , wherein the establishing a connection comprises initiating a request to the EKM for the connection, the request comprising an authentication certificate assigned to the node.

13. The computer-implemented method of claim 12 , wherein the request is a key management interoperability protocol (KMIP) message that is sent via a transport layer security (TLS) session to the EKM.

14. The computer-implemented method of claim 10 , wherein the node is a host computer or a storage array.

15. The computer-implemented method of claim 10 , wherein the channel is a host bus adapter (HBA).

16. A computer system for facilitating processing within a computing environment, the computer system comprising:

a node; and

a plurality of channels coupled to the node, wherein the computer system is configured to perform operations comprising:

initializing a local key manager (LKM) on the node, the node comprising a plurality of channels;

establishing, by the LKM a connection between the LKM and an external key manager (EKM) that stores a shared key used by the node and an other node of the computing environment to provide a secure data transfer between the node and the other node; and

in response to establishing the connection:

obtaining, by the LKM, the shared key from the EKM; and

registering, by the LKM, security capabilities of the plurality of channels, the security capabilities comprising one or more encryption algorithms supported by the channels, and

transmitting, by the LKM, an initialization request message to the other node, the initialization request message including an identifier of the shared key, a nonce and a security parameter index, wherein the initialization request message is not encrypted,

wherein the other node obtains the shared key from the EKM in response to the initialization request message

wherein communication between the node and the other node via the connection is protected using key created based on the shared key, a nonce and a security parameter index.

17. The computer system of claim 16 , wherein the node is a host computer and the LKM executes in a logical partition of the host computer.

18. The computer system of claim 16 , wherein the establishing a connection comprises initiating a request to the EKM for the connection, the request comprising an authentication certificate assigned to the node.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 26, 2020
From: ZEE, MOOHENG; SCZEPCZENSKI, RICHARD MARK; FLANAGAN, JOHN R.; COLONNA, CHRISTOPHER J.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 051931/0101 →
Continuity (1)
Related Publication 20210266147A1 · Aug 26, 2021
Cited By (10)
US 12,216,946 US 12,425,219 US 12,476,797 US 12,500,875 US 12,506,606 US 12,634,213 US 12,634,350 US 12,699,639 US 12,712,727 US 12,726,365