Initiator I 1 Initiator I 2 Initiator I

  • Slides: 4
Download presentation
Initiator (I 1) Initiator (I 2) Initiator (I 3) I_T nexus B Service Delivery

Initiator (I 1) Initiator (I 2) Initiator (I 3) I_T nexus B Service Delivery Subsystem I_T nexus C I_T nexus A Target Set of Data Encryption Parameters (one or more): --- At least one; one for ALL I_T NEXUS or LOCAL a) the SCSI initiator device port name; otherwise, the Set SCSI of Data Encryption initiator device Parameters port identifier; (one or more): --- Optionally one port for each additional LOCAL b) SCSI target through which the data encryption a) the parameters SCSI initiator weredevice established; port name; otherwise, the SCSI a&b)=I_T initiator device nexus port identifier; b) SCSI c) key target scope; port through which the data encryption parameters d) encryption were established; mode; a&b)=I_T e) decryption nexus mode; f) key; c) key scope; g) supplemental d) encryption mode; decryption keys; h) algorithm index; e) decryption mode; f) key; i) key instance counter; g) supplemental j) CKOD; decryption keys; h) algorithm k) CKORL; index; i) key l) CKORP; instance counter; j) CKOD; m) U-KAD; k) CKORL; n) A-KAD; l) CKORP; o) M-KAD; m) U-KAD; p) nonce; n) A-KAD; q) raw decryption mode disable where supported; and o) M-KAD; r) check external encryption mode where supported. p) nonce; q) raw decryption mode disable where supported; and r) check external encryption mode where supported. Saved Information per I_T nexus: a) data encryption scope; Saved Information per I_T nexus: b) lock; c) key instance counter value at lock; a) data encryption scope; Saved I_T nexus: d)Information key instanceper counter value assigned to the last b) lock; key established by a Set Data Encryption page for c) key instance counter value at lock; a) data this encryption I_T nexusscope; with a scope value of LOCAL and d) key instance counter value assigned to the last b) lock; the SDK bit is set to zero; and key established by a Set Data Encryption page for c) keye)instance registered counter for encryption value at lock; unit attentions state. this I_T nexus with a scope value of LOCAL and d) key instance counter value assigned to the last the SDK bit is set to zero; and key established by a Set Data Encryption page for e) registered for encryption unit attentions state. this I_T nexus with a scope value of LOCAL and the SDK bit is set to zero; and e) registered for encryption unit attentions state.

Initiator (I 1) Initiator (I 2) Initiator (I 3) AT POR I_T nexus B

Initiator (I 1) Initiator (I 2) Initiator (I 3) AT POR I_T nexus B Service Delivery Subsystem I_T nexus C I_T nexus A Target Set of Data Encryption Parameters (one or more): --- assume only one supported by device server a) the SCSI initiator device port name; otherwise, the SCSI initiator device port identifier; b) SCSI target port through which the data encryption parameters were established; a&b)=I_T nexus (==NULL) c) key scope==ALL I_T NEXUS d) encryption mode==DISABLE e) decryption mode==DISABLE f) key==NULL g) supplemental decryption keys==NULL h) algorithm index==NULL i) key instance counter==0 j) CKOD==0 k) CKORL==0 l) CKORP==0 m) U-KAD==NULL n) A-KAD==NULL o) M-KAD==NULL p) nonce==NULL q) raw decryption mode disable==0 r) check external encryption mode==0 Saved Information per I_T nexus: a) data encryption scope; Saved Information per I_T nexus: b) lock; c) key instance counter value at lock; a) data encryption scope; Saved I_T nexus: d)Information key instanceper counter value assigned to the last b) lock; key established by a Set Data Encryption page for c) key instance counter value at lock; a) data this encryption I_T nexusscope==PUBLIC with a scope value of LOCAL and d) key instance counter value assigned to the last b) lock==FALSE the SDK bit is set to zero; and key established by a Set Data Encryption page for c) keye)instance registered counter for encryption value at lock==NULL unit attentions state. this I_T nexus with a scope value of LOCAL and d) key instance counter value assigned to the last the SDK bit is set to zero; and key established by a Set Data Encryption page for e) registered for encryption unit attentions state. this I_T nexus with a scope value of LOCAL and the SDK bit is set to zero==NULL e) registered for encryption unit attentions state==FALSE

Initiator (I 1) Initiator (I 2) Initiator (I 3) I_T nexus B Service Delivery

Initiator (I 1) Initiator (I 2) Initiator (I 3) I_T nexus B Service Delivery Subsystem I_T nexus C I_T nexus A Target Set of Data Encryption Parameters (one or more): --- assume only one supported by device server a) the SCSI initiator device port name; otherwise, the SCSI initiator device port identifier; b) SCSI target port through which the data encryption parameters were established; a&b)=I_T nexus (==I_T nexus A) c) key scope==LOCAL d) encryption mode==ENCRYPT e) decryption mode==DECRYPT f) key==123456789 ABCDEF g) supplemental decryption keys==NULL h) algorithm index==8001 0014 h (AES-GCM w/16 byte MAC) or NULL if more than one supported i) key instance counter==1 j) CKOD==TRUE k) CKORL==TRUE l) CKORP==TRUE m) U-KAD==NULL n) A-KAD==xyz o) M-KAD==NULL p) nonce==NULL q) raw decryption mode disable==FALSE r) check external encryption mode==FALSE Set Data Encryption page a) SCOPE==LOCAL; b) LOCK==TRUE; c) CEEM==00 b d) RDMC==00 b e) SDK==FALSE Saved Information I_T nexus C: f) ENCRYPTION MODE==ENCRYPT g) DECRYPTION MODE==DECRYPT a) data encryption scope==PUBLIC Saved Information I_T nexus B: h) algorithm index==8001 0014 h (AES-GCM w/16 byte b) lock==FALSE MAC) or NULL more than one supported c) keyifinstance counter value at lock==NULL a) data encryption scope==PUBLIC i) KEY FORMAT==00 h d) key instance counter value assigned to the last b) lock==FALSE j) CKOD==TRUE key established by a Set Data Encryption page for c) key instance counter value at lock==NULL k) CKORL==TRUE this I_T nexus with a scope value of LOCAL and d) key instance counter value assigned to the last l) CKORP==TRUE the SDK bit is set to zero==NULL key established by a Set Data Encryption page for m) U-KAD==NULL e) registered for encryption unit attentions this I_T nexus with a scope value of LOCAL and n) A-KAD==xyz state==FALSE the SDK bit is set to zero==NULL o) M-KAD==NULL e) registered for encryption unit attentions p) nonce==NULL state==FALSE q) KEY==123456789 ABCDEFh Saved Information I_T nexus A: a) data encryption scope==LOCAL b) lock==TRUE c) key instance counter value at lock==1 d) key instance counter value assigned to the last key established by a Set Data Encryption page for this I_T nexus with a scope value of LOCAL and the SDK bit is set to zero==1 e) registered for encryption unit attentions state==TRUE

Initiator (I 1) Initiator (I 2) Initiator (I 3) I_T nexus B Service Delivery

Initiator (I 1) Initiator (I 2) Initiator (I 3) I_T nexus B Service Delivery Subsystem I_T nexus C I_T nexus A Target Set of Data Encryption Parameters (one or more): --- assume only one supported by device server a) the SCSI initiator device port name; otherwise, the SCSI initiator device port identifier; b) SCSI target port through which the data encryption parameters were established; a&b)=I_T nexus (==I_T nexus B) c) key scope==ALL I_T NEXUS d) encryption mode==ENCRYPT e) decryption mode==DECRYPT f) key==A 5 A 5 A 5 h g) supplemental decryption keys==NULL h) algorithm index==8001 0014 h (AES-GCM w/16 byte MAC) or NULL if more than one supported i) key instance counter==2 j) CKOD==TRUE k) CKORL==TRUE l) CKORP==TRUE m) U-KAD==NULL n) A-KAD==123456789 o) M-KAD==NULL p) nonce==NULL q) raw decryption mode disable==FALSE r) check external encryption mode==FALSE Saved Information I_T nexus C: a) data encryption scope==PUBLIC Saved Information I_T nexus B: b) lock==FALSE c) key instance counter value at lock==NULL a) data encryption scope==ALL I_T NEXUS d) key instance counter value assigned to the last b) lock==TRUE key established by a Set Data Encryption page for c) key instance counter value at lock==2 this I_T nexus with a scope value of LOCAL and d) key instance counter value assigned to the last Set Data Encryption page the SDK bit is set to zero==NULL key established by a Set Data Encryption page for a) SCOPE==ALL I_T NEXUS; e) registered for encryption unit attentions this I_T nexus with a scope value of LOCAL and state==FALSE b) LOCK==TRUE; the SDK bit is set to zero==NULL c) CEEM==00 b e) registered for encryption unit attentions d) RDMC==00 b state==TRUE e) SDK==FALSE f) ENCRYPTION MODE==ENCRYPT g) DECRYPTION MODE==DECRYPT Saved Information nexus A: h) algorithm index==8001 0014 h (AES-GCMI_T w/16 byte MAC) or NULL if more than one supported i) KEY FORMAT==00 h a) data encryption scope==LOCAL j) CKOD==TRUE b) lock==TRUE k) CKORL==TRUE c) key instance counter value at lock==1 l) CKORP==TRUE d) key instance counter value assigned to the last m) U-KAD==NULL key established by a Set Data Encryption page for n) A-KAD==123456789 this I_T nexus with a scope value of LOCAL and o) M-KAD==NULL the SDK bit is set to zero==1 p) nonce==NULL e) registered for encryption unit attentions q) KEY==A 5 A 5 A 5 h state==TRUE