Bringing Quantum Resistance to Cisco MDS 9000 switches

0
457
Bringing Quantum Resistance to Cisco MDS 9000 switches


As safety rules tighten and quantum computing advances, organizations are prioritizing cybersecurity, making encryption more and more important. The Cisco MDS 9000 household of storage networking units affords cutting-edge encryption options, particularly via Cisco TrustSec Fibre Channel Link Encryption, making certain safe knowledge transmission throughout Fibre Channel (FC) networks.

Threats and safety rules mandate stronger safety postures

Data is among the many most essential belongings for any company, so defending knowledge from unauthorized entry and misuse is a key concern. With the emergence of hybrid work, the adoption of cloud companies, and the malicious use of AI-based instruments, cyberthreats have turn out to be extra superior and impactful. At the identical time, new privateness and safety rules are mandating that organizations obtain a greater, extra complete safety posture. As a outcome, cybersecurity is the highest precedence amongst AI deployments, in response to the Cisco 2024 AI Readiness Index, and knowledge encryption is now in excessive demand from companies of all sizes and industries.

With FC being the protocol of selection for accessing business-critical enterprise datasets, an essential side of a safety posture is to validate the identification of adjoining switches and to encrypt knowledge whereas in transit on a storage space community (SAN). These capabilities are provided on the Cisco MDS 9000 household of storage networking units utilizing Cisco TrustSec FC Link Encryption. With latest NX-OS code, a brand new cypher has been launched to face up to the brute-force calculations that may overcome present encryption requirements with quantum computing, that includes an easy configuration. Available underneath Advantage and Premier license tiers, this characteristic helps director switches, fastened configuration switches, and multiprotocol switches, benefiting each mainframe and open system environments.

Authentication is a prerequisite to encryption

Cisco MDS 9000 Series Switches implement the Fibre Channel Security Protocol (FC-SP-2 customary, ANSI INCITS 496-2012), enabling switch-to-switch and host-to-switch authentication to deal with safety challenges in enterprise materials. The Diffie-Hellman Challenge Handshake Authentication Protocol (DHCHAP) is a FC-SP protocol that gives authentication between Cisco MDS 9000 Series Switches and different units. DHCHAP combines the CHAP protocol with the Diffie-Hellman (DH) alternate, making certain that solely trusted units can be part of a cloth, thereby stopping unauthorized entry.

DHCHAP is a safe, password-based key-exchange authentication protocol supporting each switch-to-switch and host-to-switch authentication. This configuration requires setting native and peer swap passwords, with DHCHAP negotiating hash algorithms and DH teams. With NX-OS 9.4(3), SHA-1 algorithm-based authentication is default, configured on the bodily FC interface stage.

Cisco TrustSec Fibre Channel Link Encryption

The Advanced Encryption Standard (AES) is a high-security, symmetric-key block-cipher algorithm adopted globally since 2002. It helps numerous functions, together with disk encryption, VPN programs, and messaging packages. Its substitution-permutation community includes refined bit operations, with hardware-efficient execution.

Cisco TrustSec FC Link Encryption extends the Fibre Channel Security Protocol (FCSP), making certain transaction integrity and confidentiality utilizing DHCHAP for peer authentication. Encryption configuration includes defining safety associations on interfaces, setting a key and utilizing a salt for enhancing safety by differentiating encrypted textual content patterns.

Cisco TrustSec FC Link Encryption allows AES-GCM (default, encryption and authentication) or AES-GMAC (authentication solely). Key lengths supported are 128 bits for 32G units and each 128-bit and 256-bit for 64G units, providing flexibility and selection. If executed in software program, AES-128 is marginally sooner and desires much less system sources, whereas AES-256 supplies higher resilience towards brute-force assaults and elevates the answer to turn out to be quantum resistant. Cisco MDS 9000 switches leverage superior hardware-assisted AES implementation in order that each AES-128 and AES-256 execute with the identical optimum stage of efficiency.

Industry-leading efficiency and throughput

The Cisco 64G FC switching module supplies excessive encryption capabilities, supporting eight ports at 64G speeds every, attaining 512G mixture encrypted throughput per module. This industry-leading efficiency outcomes from superior ASIC design, dealing with encryption with no efficiency penalty. The store-and-forward structure ensures unchanged latency between encrypted and non-encrypted configurations, making MDS 9000 SAN switches distinctive in sustaining effectivity with the very best stage of safety. Fixed configuration and multiservice switches leverage the identical capabilities, however the variety of encrypted ports is determined by the swap mannequin. For instance, on Cisco MDS 9124V there are 4 ports that may be encrypted, on Cisco MDS 9148V there are eight, and on Cisco MDS 9396V there are 16.

Port independence and repair availability

In real-world deployments, port independence is essential for sustaining connectivity throughout disruptions. Cisco MDS 9000 Series Switches excel on this, with an optimized ASIC structure and body path separation making certain no affect on different encrypted ports throughout occasions like port errdisable or cable/SFP pull. This functionality enhances service availability considerably.

Fabric switches like Cisco MDS 9124V, 9148V, and 9396V assist a number of encrypted ports with out lowering the entire variety of usable ports, in contrast to competing merchandise. This functionality ensures constant useful resource allocation no matter encryption standing.

Distance assist and SAN analytics compatibility

Enabling encryption on MDS 9000 Series units doesn’t have an effect on supported distances, preserving buffer credit and permitting unaltered long-distance operations. Users can preserve the identical distance capabilities with encryption, eliminating design constraints throughout safety planning.

Cisco SAN Analytics supplies deep visitors visibility and is the {industry} benchmark. It might be totally relevant to encrypted visitors, sustaining assurance and insights with out compromising visibility. The superior structure of the Cisco MDS 9000 Series ensures that it’s at all times potential to examine headers, in order that SAN Analytics might be utilized to encrypted visitors coming into the swap or leaving it.

Key size, rekeying, and quantum resistance

AES-GCM helps 128- and 256-bit keys. Key choice on 64G units affords flexibility, with handbook periodic rekeying obtainable as a further safety measure. AES-256 is favored for quantum resistance and safety towards the rising threats posed by quantum computer systems, together with Grover’s algorithm. The enhanced TrustSec functionality on MDS 9000 is taken into account safe no less than till 2050, as per ETSI GR QSC 006 V1.1.1, future-proofing safety efforts.

Comprehensive safety suite

The Cisco MDS 9000 Series affords intensive safety features, each intrinsic and configurable. Intrinsic options embody Secure Boot and Anti-counterfeit know-how, whereas configurable choices embody VSANs, laborious zoning, port safety, cloth binding, safe syslog logging, safe erase, Transport Layer Security (TLS) 1.3, Simple Network Management Protocol Version 3 (SNMPv3), Secure Shell Version 2 (SSHv2), amongst others. These options assist enterprise continuity and catastrophe restoration throughout knowledge facilities, providing encryption on FC and FC over IP (FCIP) Inter-Switch Links (ISLs) via TrustSec and IPsec know-how, respectively (Figure 1).

Flow chart displaying link layer security and hybrid SAN extensions using TrustSec and IPsec technologies, including specs for TrustSec and IPsec.
Figure 1. MDS 9000 encryption, masking enterprise continuity and catastrophe restoration wants

Conclusion

Cisco MDS 9000 switches ship unmatched encryption for SANs, distinguished by superior ASIC design, superior {hardware} structure, and complicated software program management. TrustSec FC Link Encryption is important for securely interconnecting SAN materials throughout knowledge facilities utilizing FC hyperlinks. With Cisco MDS 9000 64G units, you’ll be able to lengthen SANs securely, enhancing the safety posture in preparation for quantum computing with out compromise.

 

Additional sources:
Cisco MDS 9000 Series Security Configuration Guide
Cisco Storage Area Networking
Storage networking merchandise
What is a storage space community (SAN)?

Share:

LEAVE A REPLY

Please enter your comment!
Please enter your name here