QuickSec Toolkit for SAN
SafeNet QuickSec™ Toolkit for SAN is ideal for Storage Area Network developers
who need to integrate advanced security functionality into storage systems and devices
as they standardize on IP and iSCSI.
Overview
SafeNet QuickSec Toolkit for SAN contains an easily integrated security functionality
for SAN developers and is licensed in source code format so OEMs can quickly integrate
IPSec technology to their target environment. Additionally, SafeNet's experienced
technical support team and professional services group stand ready to help SAN developers
requiring security expertise.
iSCSI - The Internet SCSI Standard for transferring SCSI storage
protocol commands and data blocks using IP networks. iSCSI does not provide any
security features as such, but IETF mandates the use of encryption with protocols
such as IPSec.
IPSec - Internet Engineering Task Force (IETF) has endorsed vendor
independent network layer protocol for implementing end-to-end security. IPSec is
an application and media independent layer for bringing security to heterogeneous
networks.
Internet Key Exchange (IKE) - IKE is the Session management and
authentication protocol of choice for IPSec data layer. SafeNet's IKE implementation
is among the first to introduce support for the latest IETF standards.
X.509 PKI Client Functionality - X.509 Public Key Infrastructures
provide a scalable solution for managing IPSec networks with thousands of Network
Attached Storage (NAS) devices and peer nodes.
Features
- IPSec stack for embedded environments
- IPSec functionality based on IPSec and related IETF standards
- Deterministic memory usage with minimum run-time memory allocation
- Cross-platform portability based on clearly identified porting layers
- ANSI C source code product
- IPSec functionality including data plane and control plane components
Control Plane:
- IKE (Internet Key Exchange) protocol for session establishment and authentication
- X.509 Certificate validation engine
- Management & configuration API for dynamic run-time Security Policy configuration
Data Plane:
- IP flow-oriented packet lookup
- Software implementation of IPSec transforms and necessary cryptography
- Integration to host TCP/IP stack via separate porting layer
- Well-defined model for offloading performance critical processing path to NPUs
- Slow path processing for IP fragments