US 11,991,273 B2
Storage device key management for encrypted host data
Jacob L. Sheppard, Corona De Tucson, AZ (US); Igor Popov, Tucson, AZ (US); Roger G. Hathorn, Tucson, AZ (US); and Bernhard Laubli, Green Valley, AZ (US)
Assigned to INTERNATIONAL BUSINESS MACHINES CORPORATION, Armonk, NY (US)
Filed by INTERNATIONAL BUSINESS MACHINES CORPORATION, Armonk, NY (US)
Filed on Sep. 4, 2018, as Appl. No. 16/121,076.
Prior Publication US 2020/0076585 A1, Mar. 5, 2020
Int. Cl. H04L 9/08 (2006.01)
CPC H04L 9/0838 (2013.01) [H04L 9/083 (2013.01); H04L 9/0891 (2013.01); H04L 9/0894 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A system for facilitating processing within a computing environment, said system comprising:
a memory; and
a node coupled to the memory, wherein the system is configured to perform a method, said method comprising:
obtaining, by the node, an authentication message from another node of the computing environment, the authentication message including a unique identifier of a shared key to be used in cryptographic operations, the shared key specifically generated for a selected node pair that includes the one node and the other node;
obtaining, by the node, the shared key from a key server coupled to the node and the other node, the obtaining comprising using the unique identifier of the shared key included in the authentication message to obtain the shared key from the key server;
using the shared key obtained from the key server in one or more cryptographic operations to, at least, authenticate a link between the node and the other node; and
using the shared key to authenticate one or more other links between the node and the other node, the shared key being a same shared key used to authenticate the link between the node and the other node, the shared key used to authenticate the one or more other links between the node and the other node being retrieved from an internal key store of the node,
wherein the shared key is used to authenticate a plurality of links between the selected node pair, the plurality of links including the link and the one or more other links between the node and the other node.