IP Library Granted Patent US 12,425,219
Granted Patent B2
US 12,425,219 · App. 18/459,253 · Granted Sep 23, 2025

Generating a secure key exchange authentication request using a security parameter index transform

Inventors: Richard Mark Sczepczenski (Hyde Park, NY); Daniel Hughes (Poughkeepsie, NY); Alol Antony Crasta (Poughkeepsie, NY)
Assignee: International Business Machines Corporation
H04L9/321H04L9/0819
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,425,219
App. No.
18/459,253
Granted
Sep 23, 2025
Kind
B2
Abstract

Embodiments of the present disclosure provide systems and methods for generating a secure key exchange (SKE) Authentication Request using a Security Parameter Index (SPI) Transform to provide secure data transfer in a computing environment. A disclosed method comprises receiving an SKE SA Initialization Response message at a local key manager (LKM) executing on an initiator node to initiate a secure communication between an initiator channel on the initiator node and a responder channel on a responder node. The LKM creates an SPI based on an SPI Transform using an SA Index and SPI Transform values, and the LKM builds the SKE Authentication Request message, which comprises the SPI, a set of cryptographic keys, and a list of encryption algorithms supported by the initiator channel. The LKM sends the SKE Authentication Request message to the responder channel on the responder node using the initiator channel.

Claims (38)

1. A method comprising:

receiving, from a responder channel on a responder node, a Secure Key Exchange (SKE) Security Association (SA) Initialization Response message at a local key manager (LKM) executing on an initiator node to initiate a secure communication between an initiator channel on the initiator node and the responder channel;

obtaining a selected Security Parameter Index (SPI) Transform, an SA Index, and SPI Transform values;

creating an SPI based on the SPI Transform using the SA Index and the SPI Transform values;

building an SKE Authentication Request message based on the SKE SA Initialization Response message and the SPI, wherein the SKE Authentication Request message comprises the SPI, a set of cryptographic keys, and a list of encryption algorithms; and

transmitting the SKE Authentication Request message from the LKM to the responder channel on the responder node using the initiator channel.

2. The method of claim 1 , wherein obtaining the SA Index and the SPI Transform values further comprises registering the initiator channel with the LKM executing on the initiator node, and wherein the initiator channel selects the SPI Transform and provides the SPI Transform values, and the LKM registers the selected SPI Transform and the SPI Transform values.

3. The method of claim 2 , further comprises using a random number generator to generate the SPI Transform values, at the initiator channel on the initiator node, wherein the SPI Transform values comprise a random SPI base, a random SPI shift, or a SPI mask.

4. The method of claim 1 , wherein obtaining the selected SPI Transform, the SA Index and the SPI Transform values further comprises sending, via the initiator channel, the SA Index as part of a Start LKM message to the LKM.

5. The method of claim 1 , further comprises creating, at the LKM executing on the initiator node, an SA between the initiator node and the responder node pair responsive to receiving an Start LKM message.

6. The method of claim 5 , wherein obtaining the selected SPI Transform, the SA Index and SPI Transform values, creating the SPI, and building the SKE SA Initialization Request message are performed responsive to receiving the Start LKM message.

7. The method of claim 1 , further comprises deriving the set of cryptographic keys, and building the list of encryption algorithms based on the Initialization Response message.

8. The method of claim 1 , further comprises performing state and verification checks of the received SKE SA Initialization Response message based on an SA between the initiator node and the responder node pair.

9. The method of claim 1 , wherein receiving the SKE SA Initialization Response message at the LKM executing on the initiator node further comprises receiving the SKE SA Initialization Response message from the responder channel on the responder node at the initiator channel, and transmitting the SKE Authentication Response message to the LKM with an SA Index message providing the SA Index by the initiator channel.

10. The method of claim 1 , wherein creating the SPI based on the SPI Transform using the SA Index and the SPI Transform values further comprises computing two or more transformations, each transformation comprising a combination of two or more of a SPI mask, a SPI shift, a generated random number, a transformation result, or a SPI base, and the SA Index.

11. A system, comprising:

a processor; and

a memory, wherein the memory includes a computer program product configured to perform operations for generating a secure key exchange (SKE) Authentication Request using a Security Parameter Index (SPI) Transform, the operations comprising:

receiving, from a responder channel on a responder node, a SKE SA Initialization Response message at a local key manager (LKM) executing on an initiator node to initiate a secure communication between an initiator channel on the initiator node and the responder channel;

obtaining, a selected SPI Transform, an SA Index, and Security Parameter Index (SPI) Transform values;

creating an SPI based on the SPI Transform using the SA Index and the SPI Transform value;

building an SKE Authentication Request message based on the SKE SA Initialization Response message and the SPI, wherein the SKE Authentication Request message comprises the SPI, a set of cryptographic keys, and a list of encryption algorithms; and

transmitting the SKE Authentication Request message from the LKM to the responder channel on the responder node using the initiator channel.

12. The system of claim 11 , wherein obtaining the selected SPI Transform, the SA Index and the SPI Transform values further comprises sending, via the initiator channel, the SA Index as part of a Start LKM message to the LKM on the initiator node.

13. The system of claim 11 , wherein creating the SPI based on the SPI Transform using the SA Index and the SPI Transform values further comprises computing two or more transformations, each transformation comprising a combination of two or more of a SPI mask, a SPI shift, a generated random number, a transformation result, or a SPI base, and the SA Index.

14. The system of claim 11 , wherein obtaining the SA Index and the SPI Transform values further comprises registering the initiator channel with the LKM executing on the initiator node, and wherein the initiator channel selects the SPI Transform and provides the SPI Transform values, and the LKM registers the selected SPI Transform and the SPI Transform values.

15. The system of claim 14 , further comprises using a random number generator to generate the SPI Transform values, at the initiator channel on the initiator node, wherein the SPI Transform values comprise a random SPI base, a random SPI shift, or a SPI mask.

16. A computer program product for generating a secure key exchange (SKE) Authentication Request using a Security Parameter Index (SPI) Transform, the computer program product comprising:

a computer-readable storage medium having computer-readable program code embodied therewith, the computer-readable program code executable by one or more computer processors to perform an operation comprising:

receiving, from the responder channel on a responder node, a SKE SA Initialization Response message at a local key manager (LKM) executing on an initiator node to initiate a secure communication between an initiator channel on the initiator node and the responder channel;

obtaining, a selected SPI Transform, an SA Index, and Security Parameter Index (SPI) Transform values;

creating an SPI based on the SPI Transform using the SA Index and the SPI Transform value;

building an SKE Authentication Request message based on the SKE SA Initialization Response message and the SPI, wherein the SKE Authentication Request message comprises the SPI, a set of cryptographic keys, and a list of encryption algorithms; and

transmitting the SKE Authentication Request message from the LKM to the responder channel on the responder node using the initiator channel.

17. The computer program product of claim 16 , wherein obtaining the selected SPI Transform, the SA Index and the SPI Transform values further comprises sending, via the initiator channel, the SA Index as part of a Start LKM message to the LKM on the initiator node.

18. The computer program product of claim 16 , wherein creating the SPI based on the SPI Transform using the SA Index and the SPI Transform values further comprises computing two or more transformations; wherein each transformation comprising a combination of two or more of a SPI mask, a SPI shift, a generated random number, a transformation result, or a SPI base, and the SA Index.

19. The computer program product of claim 16 , wherein obtaining the SA Index and the SPI Transform values further comprises registering the initiator channel with the LKM executing on the initiator node, and wherein the initiator channel selects the SPI Transform and provides the SPI Transform values, and the LKM registers the selected SPI Transform and the SPI Transform values.

20. The computer program product of claim 19 , further comprises using a random number generator to generate the SPI Transform values, at the initiator channel on the initiator node, wherein the SPI Transform values comprise a random SPI base, a random SPI shift, and a SPI mask.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2023
From: SCZEPCZENSKI, RICHARD MARK; HUGHES, DANIEL; CRASTA, ALOL ANTONY
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 064768/0828 →
Continuity (1)
Related Publication 20250080348A1 · Mar 6, 2025
References Cited (32)
US 7434045B1 · Enderwick et al. · 2008 [cited by applicant]
US 11038698B2 · Driever et al. · 2021 [cited by applicant]
US 11080336B2 · Van Dusen · 2021 [cited by examiner]
US 11184160B2 · Zee et al. · 2021 [cited by applicant]
US 11310036B2 · Sczepczenski et al. · 2022 [cited by applicant]
US 11405215B2 · Sczepczenski · 2022 [cited by examiner]
US 11489821B2 · Zee et al. · 2022 [cited by applicant]
US 11502834B2 · Zee et al. · 2022 [cited by applicant]
US 11546137B2 · Sczepczenski et al. · 2023 [cited by applicant]
US 11563588B2 · Driever et al. · 2023 [cited by applicant]
US 11652616B2 · Zee et al. · 2023 [cited by applicant]
US 20110296186A1 · Wong et al. · 2011 [cited by applicant]
US 20130290721A1 · Khalil et al. · 2013 [cited by applicant]
US 20150101029A1 · Maino et al. · 2015 [cited by applicant]
US 20190190710A1 · Chopra · 2019 [cited by examiner]
US 20210075627A1 · Hathorn et al. · 2021 [cited by applicant]
US 20210091943A1 · Hathorn et al. · 2021 [cited by applicant]
US 20210266147A1 · Zee et al. · 2021 [cited by applicant]
US 20210266177A1 · Sczepczenski et al. · 2021 [cited by applicant]
US 20210266304A1 · Zee · 2021 [cited by examiner]
US 20210273799A1 · Kampati et al. · 2021 [cited by applicant]
US 20210273928A1 · Kampati et al. · 2021 [cited by applicant]
US 20220021687A1 · Bhattacharya et al. · 2022 [cited by applicant]
US 20220263811A1 · Kampati et al. · 2022 [cited by applicant]
US 20230327871A1 · Ganjikunta et al. · 2023 [cited by applicant]
US 20250080330A1 · Sczepczenski et al. · 2025 [cited by applicant]
US 20250080343A1 · Sczepczenski et al. · 2025 [cited by applicant]
CN 102447616B · 2016 [cited by applicant]
“List of IBM Patents or Patent Applications Treated as Related,” for U.S. Appl. No. 18/459,253, filed Aug. 31, 2023. [cited by applicant]
International Searching Authority, International Search Report and Written Opinion for PCT Application No. PCT/EP2024/069059, dated Aug. 19, 2024. [cited by applicant]
INCITS: “Fibre Channel Generic Services—4 (FC-GS-4) Rev 7.9”, Feb. 11, 2004 (Feb. 11, 2004), XP002606595, Retrieved from the Internet <URL:http://www.t10.org/ftp/t11/document.04/04-031v1.pdf> [retrieved on Oct. 10, 2010… [cited by applicant]
“Robert Snively”, “Fibre Channel Security Protocols”, INCITS working draft proposed American National Standard for Information Technology, Jan. 31, 2004, 182 pages. [cited by applicant]