DocumentCode :
3018051
Title :
Security Enhancement in InfiniBand Architecture
Author :
Lee, Manhee ; Kim, Eun Jung ; Yousif, Mazin
Author_Institution :
Dept. of Comput. Sci., Texas A&M Univ., College Station, TX, USA
fYear :
2005
fDate :
04-08 April 2005
Abstract :
The InfiniBand™ Architecture (IBA) is a new promising I/O communication standard positioned for building clusters and System Area Networks (SANs). However, the IBA specification has left out security resulting in potential security vulnerabilities, which could be exploited with moderate effort. In this paper, we view these vulnerabilities from three classical security aspects: availability, confidentiality, and authentication. For better availability of IBA, we recommend that a switch be able to enforce partitioning for data packets for which we propose an efficient implementation method using trap messages. For confidentiality, we encrypt only secret keys to minimize performance degradation. The most serious vulnerability in IBA is authentication since IBA authenticates packets solely by checking the existence of plaintext keys in the packet. In this paper, we propose a new authentication mechanism that treats the Invariant CRC (ICRC) field as an Authentication Tag, which is compatible with current IBA specification. When analyzing the performance of our authentication approach along with other authentication algorithms, we observe that our approach dramatically enhances IBA´s authentication capability without hampering IBA performance benefit. Furthermore, simulation results indicate that our methods enhance security in IBA with marginal performance overhead.
Keywords :
authorisation; cryptography; message authentication; packet switching; parallel architectures; performance evaluation; telecommunication standards; workstation clusters; InfiniBand architecture; data packets; invariant CRC field; message authentication; security vulnerabilities; system area networks; Authentication; Availability; Buildings; Communication standards; Communication system security; Cryptography; Data security; Degradation; Packet switching; Switches;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Parallel and Distributed Processing Symposium, 2005. Proceedings. 19th IEEE International
Print_ISBN :
0-7695-2312-9
Type :
conf
DOI :
10.1109/IPDPS.2005.396
Filename :
1419931
Link To Document :
بازگشت