Claims
- 1. A method of authenticating a Fibre Channel over TCP/IP connection between a first device and a second device in which a first connection is established and authenticated and a second connection is subsequently established and a nonce is sent from the first device to the second device over the second connection and the nonce is returned from the second device to the first device over the first, authenticated connection, compared to the nonce sent by the first device to the second device and an acceptance is sent over the first, authenticated connection from the first device to the second device if the nonce sent is the same as the nonce received wherein the improvement comprises:
returning the nonce received by the second device to the first device over the first, authenticated connection using Switch Fabric Internal Link Services; and, sending the acceptance over the first, authenticated connection from the first device to the second device using Switch Fabric Internal Link Services.
- 2. A method of authenticating a Fibre Channel over TCP/IP connection between a first device and a second device which comprises:
establishing a first Fibre Channel over TCP/IP connection between the first device and the second device; authenticating the first connection; establishing a second Fibre Channel over TCP/IP connection between the first device and the second device; sending a nonce from the first device to the second device over the second connection; returning the nonce received by the second device to the first device over the first connection using Switch Fabric Internal Link Services; comparing the nonce sent to the nonce returned; and, sending an acceptance over the first, authenticated connection from the first device to the second device using Switch Fabric Internal Link Services if the nonce sent is the same as the nonce received.
- 3. A method as recited in claim 2 wherein authenticating the first connection is accomplished by means of the Fibre Channel Switch Link Authentication Protocol.
- 4. A method as recited in claim 2 wherein sending an acceptance comprises sending a Switch Accept switch internal link service command.
- 5. A method as recited in claim 2 further comprising sending a rejection over the first, authenticated connection from the first device to the second device using Switch Fabric Internal Link Services if the nonce sent is not the same as the nonce received.
- 6. A method as recited in claim 5 wherein sending a rejection comprises sending a Switch Internal Link Service Reject command.
- 7. A method as recited in claim 5 further comprising sending a reason code from the first device to the second device using Switch Fabric Internal Link Services.
- 8. A method as recited in claim 7 further comprising sending a reason code explanation from the first device to the second device using Switch Fabric Internal Link Services.
- 9. A method as recited in claim 2 further comprising sending a rejection over the first, authenticated connection from the first device to the second device using Switch Fabric Internal Link Services if a nonce was not sent by the first device to the second device.
- 10. A Fibre Channel switch comprising a processor and a medium storing instructions for causing the processor to:
establish a first Fibre Channel over TCP/IP connection between the switch and a second switch; authenticate the first connection; establish a second Fibre Channel over TCP/IP connection between the switch and the second switch; send a nonce to the second switch over the second connection; receive the nonce returned by the second switch over the first connection using Switch Fabric Internal Link Services; compare the nonce sent to the nonce returned; and, send an acceptance over the first, authenticated connection to the second switch using Switch Fabric Internal Link Services if the nonce sent is the same as the nonce received.
- 11. A switch as recited in claim 10 further comprising stored instructions for causing the processor to send a rejection over the first, authenticated connection to the second switch using Switch Fabric Internal Link Services if the nonce sent is not the same as the nonce received.
- 12. A switch as recited in claim 11 further comprising stored instructions for causing the processor to send a reason code over the first, authenticated connection to the second switch using Switch Fabric Internal Link Services if the nonce sent is not the same as the nonce received.
- 13. A switch as recited in claim 12 further comprising stored instructions for causing the processor to send a reason code explanation over the first, authenticated connection to the second switch using Switch Fabric Internal Link Services if the nonce sent is not the same as the nonce received.
- 14. A Fibre Channel device comprising a processor and a medium storing instructions for causing the processor to:
establish a first Fibre Channel over TCP/IP connection between the device and a second Fibre Channel device; authenticate the first connection; establish a second Fibre Channel over TCP/IP connection between the device and the second Fibre Channel device; send a nonce to the second Fibre Channel device over the second connection; receive the nonce returned by the second Fibre Channel device over the first connection using Switch Fabric Internal Link Services; compare the nonce sent to the nonce returned; and, send an acceptance over the first, authenticated connection to the second Fibre Channel device using Switch Fabric Internal Link Services if the nonce sent is the same as the nonce received.
- 15. A Fibre Channel device as recited in claim 14 further comprising stored instructions for causing the processor to send a rejection over the first, authenticated connection to the second Fibre Channel device using Switch Fabric Internal Link Services if the nonce sent is not the same as the nonce received.
- 16. A Fibre Channel device as recited in claim 15 further comprising stored instructions for causing the processor to send a reason code over the first, authenticated connection to the second Fibre Channel device using Switch Fabric Internal Link Services if the nonce sent is not the same as the nonce received.
- 17. A Fibre Channel device as recited in claim 16 further comprising stored instructions for causing the processor to send a reason code explanation over the first, authenticated connection to the second Fibre Channel device using Switch Fabric Internal Link Services if the nonce sent is not the same as the nonce received.
- 18. A Fibre Channel device comprising a processor and a medium storing instructions for causing the processor to:
communicate with a second Fibre Channel device using a first Fibre Channel over a TCP/IP connection between the device and the second Fibre Channel device; respond to a request to authenticate the first connection; establish a second Fibre Channel over TCP/IP connection between the device and the second Fibre Channel device; receive a nonce from the second Fibre Channel device transmitted via the second connection; return the nonce received from the second Fibre Channel device over the first connection using Switch Fabric Internal Link Services; and, receive a signal over the first connection from the second Fibre Channel device using Switch Fabric Internal Link Services indicating whether the nonce returned was the same as the nonce sent by the second Fibre Channel device.
CROSS-REFERENCE TO RELATED APPLICATIONS
[0001] This application claims the benefit of U.S. Provisional Application No. 60/432,289 filed Dec. 10, 2002.
Provisional Applications (1)
|
Number |
Date |
Country |
|
60432289 |
Dec 2002 |
US |