QuickSec Toolkit for SAN
SafeNet QuickSec™ Toolkit for SAN is ideal for Storage Area Network
developers who need to integrate advanced security functionality into
storage systems and devices as they standardize on IP and iSCSI.
Overview
SafeNet QuickSec Toolkit for SAN contains an easily integrated security
functionality for SAN developers and is licensed in source code format
so OEMs can quickly integrate IPSec technology to their target environment.
Additionally, SafeNet's experienced technical support team and professional
services group stand ready to help SAN developers requiring security expertise.
iSCSI - The Internet SCSI Standard for transferring
SCSI storage protocol commands and data blocks using IP networks. iSCSI
does not provide any security features as such, but IETF mandates the
use of encryption with protocols such as IPSec.
IPSec - Internet Engineering Task Force (IETF) has endorsed
vendor independent network layer protocol for implementing end-to-end
security. IPSec is an application and media independent layer for bringing
security to heterogeneous networks.
Internet Key Exchange (IKE) - IKE is the Session management
and authentication protocol of choice for IPSec data layer. SafeNet's
IKE implementation is among the first to introduce support for the latest
IETF standards.
X.509 PKI Client Functionality - X.509 Public Key Infrastructures
provide a scalable solution for managing IPSec networks with thousands
of Network Attached Storage (NAS) devices and peer nodes.
Features
- IPSec stack for embedded environments
- IPSec functionality based on IPSec and related IETF standards
- Deterministic memory usage with minimum run-time memory allocation
- Cross-platform portability based on clearly identified porting layers
- ANSI C source code product
- IPSec functionality including data plane and control plane components
Control Plane:
- IKE (Internet Key Exchange) protocol for session establishment and
authentication
- X.509 Certificate validation engine
- Management & configuration API for dynamic run-time Security Policy
configuration
Data Plane:
- IP flow-oriented packet lookup
- Software implementation of IPSec transforms and necessary cryptography
- Integration to host TCP/IP stack via separate porting layer
- Well-defined model for offloading performance critical processing
path to NPUs
- Slow path processing for IP fragments