• FC-SP working group is working on encryption •FCSec:
– Each frame can be encrypted
– Provides authentication, integrity, anti-replay, and secrecy
– Shared key generated by the authentication exchange
– Used to establish a Security Association (SA) that provides the required cryptographic parameters
• Framework for policy management:
– Based on zone set management model – Policy Set defines the security policies for the fabric
The ANSI FC-SP working group is working on specifications for data encryption on FC networks. This model is tentatively known as FCSec (equivalent to IPSec). It allows each frame to be encrypted, providing secure authentication, message integrity and protection from man in the middle and replay attacks, and data secrecy. FCSec uses a shared key, which is generated by the authentication exchange, to establish a Security Association (SA) that provides the required cryptographic parameters.
Like IPSec, FCSec defines two modes of operation:
• Tunnel mode is used for network-to-network (SAN-to-SAN) association. It encrypts the entire frame and generates a new FC header.
• Transport mode is used for node-to-node (host-to-storage or storage- to-storage) association. It encrypts only the frame payload.