Title: Initiator (I1)
1Initiator (I1)
Initiator (I2)
Initiator (I3)
I_T nexus B
Service Delivery Subsystem
I_T nexus C
I_T nexus A
Target
Set of Data Encryption Parameters (one or
more) --- At least one one for ALL I_T NEXUS or
LOCAL a) the SCSI initiator device port name
otherwise, the SCSI initiator device port
identifier b) SCSI target port through which the
data encryption parameters were
established ab)I_T nexus c) key scope d)
encryption mode e) decryption mode f) key g)
supplemental decryption keys h) algorithm
index i) key instance counter j) CKOD k)
CKORL l) CKORP m) U-KAD n) A-KAD o) M-KAD p)
nonce q) raw decryption mode disable where
supported and r) check external encryption mode
where supported.
Saved Information per I_T nexus a) data
encryption scope b) lock c) key instance
counter value at lock d) key instance counter
value assigned to the last key established by a
Set Data Encryption page for this I_T nexus with
a scope value of LOCAL and the SDK bit is set to
zero and e) registered for encryption unit
attentions state.
Saved Information per I_T nexus a) data
encryption scope b) lock c) key instance
counter value at lock d) key instance counter
value assigned to the last key established by a
Set Data Encryption page for this I_T nexus with
a scope value of LOCAL and the SDK bit is set to
zero and e) registered for encryption unit
attentions state.
Set of Data Encryption Parameters (one or
more) --- Optionally one for each additional
LOCAL a) the SCSI initiator device port name
otherwise, the SCSI initiator device port
identifier b) SCSI target port through which the
data encryption parameters were
established ab)I_T nexus c) key scope d)
encryption mode e) decryption mode f) key g)
supplemental decryption keys h) algorithm
index i) key instance counter j) CKOD k)
CKORL l) CKORP m) U-KAD n) A-KAD o) M-KAD p)
nonce q) raw decryption mode disable where
supported and r) check external encryption mode
where supported.
Saved Information per I_T nexus a) data
encryption scope b) lock c) key instance
counter value at lock d) key instance counter
value assigned to the last key established by a
Set Data Encryption page for this I_T nexus with
a scope value of LOCAL and the SDK bit is set to
zero and e) registered for encryption unit
attentions state.
2AT POR
Initiator (I1)
Initiator (I2)
Initiator (I3)
I_T nexus B
Service Delivery Subsystem
I_T nexus C
I_T nexus A
Target
Saved Information per I_T nexus a) data
encryption scope b) lock c) key instance
counter value at lock d) key instance counter
value assigned to the last key established by a
Set Data Encryption page for this I_T nexus with
a scope value of LOCAL and the SDK bit is set to
zero and e) registered for encryption unit
attentions state.
Set of Data Encryption Parameters (one or
more) --- assume only one supported by device
server a) the SCSI initiator device port name
otherwise, the SCSI initiator device port
identifier b) SCSI target port through which the
data encryption parameters were
established ab)I_T nexus (NULL) c) key
scopeALL I_T NEXUS d) encryption
modeDISABLE e) decryption modeDISABLE f)
keyNULL g) supplemental decryption
keysNULL h) algorithm indexNULL i) key
instance counter0 j) CKOD0 k) CKORL0 l)
CKORP0 m) U-KADNULL n) A-KADNULL o)
M-KADNULL p) nonceNULL q) raw decryption mode
disable0 r) check external encryption mode0
Saved Information per I_T nexus a) data
encryption scope b) lock c) key instance
counter value at lock d) key instance counter
value assigned to the last key established by a
Set Data Encryption page for this I_T nexus with
a scope value of LOCAL and the SDK bit is set to
zero and e) registered for encryption unit
attentions state.
Saved Information per I_T nexus a) data
encryption scopePUBLIC b) lockFALSE c) key
instance counter value at lockNULL d) key
instance counter value assigned to the last key
established by a Set Data Encryption page for
this I_T nexus with a scope value of LOCAL and
the SDK bit is set to zeroNULL e) registered
for encryption unit attentions stateFALSE
3Initiator (I1)
Initiator (I2)
Initiator (I3)
I_T nexus B
Service Delivery Subsystem
I_T nexus C
Set Data Encryption page a) SCOPELOCAL b)
LOCKTRUE c) CEEM00b d) RDMC00b e)
SDKFALSE f) ENCRYPTION MODEENCRYPT g)
DECRYPTION MODEDECRYPT h) algorithm index8001
0014h (AES-GCM w/16byte MAC) or NULL if more than
one supported i) KEY FORMAT00h j) CKODTRUE k)
CKORLTRUE l) CKORPTRUE m) U-KADNULL n)
A-KADxyz o) M-KADNULL p) nonceNULL q)
KEY123456789ABCDEFh
I_T nexus A
Target
Saved Information I_T nexus C a) data
encryption scopePUBLIC b) lockFALSE c) key
instance counter value at lockNULL d) key
instance counter value assigned to the last key
established by a Set Data Encryption page for
this I_T nexus with a scope value of LOCAL and
the SDK bit is set to zeroNULL e) registered
for encryption unit attentions stateFALSE
Set of Data Encryption Parameters (one or
more) --- assume only one supported by device
server a) the SCSI initiator device port name
otherwise, the SCSI initiator device port
identifier b) SCSI target port through which the
data encryption parameters were
established ab)I_T nexus (I_T nexus A) c)
key scopeLOCAL d) encryption modeENCRYPT e)
decryption modeDECRYPT f) key123456789ABCDEF g
) supplemental decryption keysNULL h) algorithm
index8001 0014h (AES-GCM w/16byte MAC) or NULL
if more than one supported i) key instance
counter1 j) CKODTRUE k) CKORLTRUE l)
CKORPTRUE m) U-KADNULL n) A-KADxyz o)
M-KADNULL p) nonceNULL q) raw decryption mode
disableFALSE r) check external encryption
modeFALSE
Saved Information I_T nexus B a) data
encryption scopePUBLIC b) lockFALSE c) key
instance counter value at lockNULL d) key
instance counter value assigned to the last key
established by a Set Data Encryption page for
this I_T nexus with a scope value of LOCAL and
the SDK bit is set to zeroNULL e) registered
for encryption unit attentions stateFALSE
Saved Information I_T nexus A a) data
encryption scopeLOCAL b) lockTRUE c) key
instance counter value at lock1 d) key instance
counter value assigned to the last key
established by a Set Data Encryption page for
this I_T nexus with a scope value of LOCAL and
the SDK bit is set to zero1 e) registered for
encryption unit attentions stateTRUE
4Initiator (I1)
Initiator (I2)
Initiator (I3)
I_T nexus B
Service Delivery Subsystem
I_T nexus C
I_T nexus A
Target
Saved Information I_T nexus C a) data
encryption scopePUBLIC b) lockFALSE c) key
instance counter value at lockNULL d) key
instance counter value assigned to the last key
established by a Set Data Encryption page for
this I_T nexus with a scope value of LOCAL and
the SDK bit is set to zeroNULL e) registered
for encryption unit attentions stateFALSE
Set of Data Encryption Parameters (one or
more) --- assume only one supported by device
server a) the SCSI initiator device port name
otherwise, the SCSI initiator device port
identifier b) SCSI target port through which the
data encryption parameters were
established ab)I_T nexus (I_T nexus B) c)
key scopeALL I_T NEXUS d) encryption
modeENCRYPT e) decryption modeDECRYPT f)
keyA5A5A5A5A5A5h g) supplemental decryption
keysNULL h) algorithm index8001 0014h
(AES-GCM w/16byte MAC) or NULL if more than one
supported i) key instance counter2 j)
CKODTRUE k) CKORLTRUE l) CKORPTRUE m)
U-KADNULL n) A-KAD123456789 o) M-KADNULL p)
nonceNULL q) raw decryption mode
disableFALSE r) check external encryption
modeFALSE
Saved Information I_T nexus B a) data
encryption scopeALL I_T NEXUS b) lockTRUE c)
key instance counter value at lock2 d) key
instance counter value assigned to the last key
established by a Set Data Encryption page for
this I_T nexus with a scope value of LOCAL and
the SDK bit is set to zeroNULL e) registered
for encryption unit attentions stateTRUE
Set Data Encryption page a) SCOPEALL I_T
NEXUS b) LOCKTRUE c) CEEM00b d)
RDMC00b e) SDKFALSE f) ENCRYPTION
MODEENCRYPT g) DECRYPTION MODEDECRYPT h)
algorithm index8001 0014h (AES-GCM w/16byte
MAC) or NULL if more than one supported i) KEY
FORMAT00h j) CKODTRUE k) CKORLTRUE l)
CKORPTRUE m) U-KADNULL n) A-KAD123456789 o)
M-KADNULL p) nonceNULL q) KEYA5A5A5A5A5A5h
Saved Information I_T nexus A a) data
encryption scopeLOCAL b) lockTRUE c) key
instance counter value at lock1 d) key instance
counter value assigned to the last key
established by a Set Data Encryption page for
this I_T nexus with a scope value of LOCAL and
the SDK bit is set to zero1 e) registered for
encryption unit attentions stateTRUE