logo
Casa Casi

FCIA’s FC-SP-3: A Standard Ready for the Quantum-Computing World

Certificazione
Cina Beijing Qianxing Jietong Technology Co., Ltd. Certificazioni
Cina Beijing Qianxing Jietong Technology Co., Ltd. Certificazioni
Rassegne del cliente
Il personale di vendita della tecnologia il Co., srl di Pechino Qianxing Jietong è molto professionale e paziente. Possono fornire rapidamente le citazioni. La qualità e l'imballaggio dei prodotti sono inoltre molto buoni. La nostra cooperazione è molto regolare.

—— LLC del》 di Festfing DV del 《

Quando stavo cercando urgentemente il CPU di Intel e lo SSD di Toshiba, sabbioso dalla tecnologia il Co., srl di Pechino Qianxing Jietong mi ha dato molto aiuto e mi ha ottenuto i prodotti che ho avuto bisogno di rapidamente. Realmente la apprezzo.

—— Kitty Yen

Sabbioso della tecnologia il Co., srl di Pechino Qianxing Jietong è un rappresentante molto attento, che può ricordarmi degli errori di configurazione a tempo in cui compro un server. Gli ingegneri sono inoltre molto professionali e possono realizzare rapidamente il processo difficile.

—— Strelkin Mikhail Vladimirovich

Siamo molto soddisfatti della nostra esperienza di lavoro con Beijing Qianxing Jietong. La qualità del prodotto è eccellente e la consegna è sempre puntuale. Il loro team di vendita è professionale, paziente e molto disponibile con tutte le nostre domande. Apprezziamo molto il loro supporto e non vediamo l'ora di una partnership a lungo termine. Altamente raccomandato!

—— Ahmad Navid

Qualità: “Grande esperienza con il mio fornitore. Il MikroTik RB3011 era già usato, ma era in ottime condizioni e tutto funzionava perfettamente.e tutte le mie preoccupazioni sono state affrontate rapidamente- Un fornitore molto affidabile.

—— Geran Colesio

Sono ora online in chat

FCIA’s FC-SP-3: A Standard Ready for the Quantum-Computing World

September 22, 2026

The first pass only trimmed prose. I'll restructure it so tabular content becomes tables and the remaining text gets tighter — this cuts the word count well below the 15% target.


ultimo caso aziendale circa FCIA’s FC-SP-3: A Standard Ready for the Quantum-Computing World  0


FC-SP-3: Securing Fibre Channel for the Post-Quantum Era


In enterprise IT, most security upgrades happen after a breach. The INCITS FC-SP-3 standard is different: it responds proactively to regulatory and cryptographic deadlines already shaping infrastructure planning. The NSA's CNSA 2.0 gives National Security Systems a demanding migration path, while the EU's NIS2 and DORA have folded encryption policies into active compliance programs. Quantum computing adds urgency — not because a cryptanalytically relevant quantum computer is imminent, but because "harvest now, decrypt later" attacks expose long-lived data today.


Timing matters because Fibre Channel carries the data enterprises can least afford to lose. It remains the primary infrastructure for mission-critical storage in finance, healthcare, government, utilities and other regulated sectors. It is physically and logically isolated from Ethernet, cannot be routed from Ethernet networks, and gains further protection from fabric zoning and device masking. With over 160 million ports shipped and more than 35 million still operational, this installed base is exactly why FC-SP-3 matters: it does not require replacing SANs, but provides a standards-based way to secure existing fabrics.


Key Takeaways


Takeaway What it means
The standard beats the deadlines Completed by INCITS T11 in 2026, FC-SP-3 meets CNSA 2.0, NIS2 and DORA requirements years ahead of the 2030/2031 dates
Subtract first, then add quantum resistance Legacy crypto (3DES, MD5, SHA-1, sub-2048-bit DH) removed; ML-KEM-1024 and ML-DSA-87 added; spec cut from 288 to 152 pages
Encryption without the infrastructure tax Autonomous in-flight encryption generates keys in the HBA and runs at line rate — no key server, no switch changes, no host CPU load
The array keeps its superpowers Transport-layer encryption preserves compression, deduplication and ransomware detection that app-level encryption defeats
Compliance rides the refresh cycle Rolling rollout on the normal 3–5 year refresh delivers a fully encrypted, quantum-resistant SAN by 2030 as a byproduct of procurement


Encryption Is on a Deadline


Traditional storage architectures rely on implicit trust, yet sophisticated attacks at this layer can compromise large data volumes. Supply chain attacks — exemplified by the 2019–2021 advisory from CISA — have shown that insider threats exploiting compromised components are becoming more common. In response, US President Biden issued Executive Order 14028 (May 12, 2021), requiring encryption for federal data at rest and in transit. This forced agencies to adopt the original CNSA Suite (CNSA 1.0), which defined approved algorithms but did not anticipate quantum threats. CNSA 2.0 now prepares those standards for quantum computing, retiring vulnerable algorithms and introducing quantum-resistant ones on a phased schedule.


CNSA 2.0 enforcement timeline


Deadline Requirement
After Dec 31, 2025 First enforcement phase begins
Jan 1, 2027 New National Security System installations must be fully CNSA 2.0 compliant
Dec 31, 2030 Decommissioning of non-compliant systems complete
Dec 31, 2031 All National Security Systems use CNSA 2.0 exclusively


The US is not alone. The EU's DORA applies to financial institutions, mandating strict reporting, risk management and security testing; NIS2 requires member states to share threat intelligence and counter supply chain attacks. Both demand strong in-flight and at-rest encryption, which FC-SP-3 advances.


Q-Day and Harvest Now, Decrypt Later


"HNDL" attacks capture encrypted traffic today to decrypt it once a powerful quantum computer exists. Current algorithms resist brute-force on conventional hardware, but a Cryptanalytically Relevant Quantum Computer (CRQC) could break RSA and ECC. To blunt a potential Q-Day attack, the NSA mandates CNSA 2.0 compliance by Dec 31, 2031 — ahead of expected CRQC availability — using post-quantum algorithms built on problems intractable even for quantum machines.


Two Decades of Fibre Channel Security


FC-SP-3 is the third generation of over twenty years of work by INCITS's T11 committee. An earlier standard (approved 2002, published 2007) established zoning and segmentation controls; FC-SP-2 (2012) added authentication and encryption, evolving through amendments in 2015 and 2023; FC-SP-3 was approved as a project in 2022 and completed recently. This is a scheduled modernization of a mature framework, not a bolt-on response — developed openly by the vendors who build the equipment, chaired by Roger Hathorn (IBM), edited by David Peterson and James Smart (Broadcom), with contributors from Broadcom, Cisco, Dell, HPE, IBM, Marvell, NetApp and Viavi. Companies that compete for every SAN socket agreed on how encryption across those sockets should work.


What FC-SP-3 Changes


The headline change is subtraction — removing the legacy cryptography FC-SP-2 still carried.


Removed vs. added cryptography


Removed (legacy) Added (CNSA 2.0-aligned)
3DES, AES-CTR ML-KEM-1024 (key establishment, NIST FIPS 203)
MD5, SHA-1, RSA-SHA-1 ML-DSA-87 (digital signatures, NIST FIPS 204)
DH-CHAP groups below 2048 bits ECDSA at 384 and 512 bits
AES key lengths under 256 bits (GCM/CBC) SHA-2-based PRFs
RADIUS usage AES-GCM required for security association management
CT authentication; FC-PAP and FC-EAP protocols


Hiding the payload encryption method forces attackers to test a broad range of algorithms at high cost, while ML-KEM effectively counters interception. The structural change is equally consequential: FC-SP-2's tiered compliance model — whose lowest tier (Auth-A) forced vendors to support obsolete MD5 and 2048-bit DH merely to remain compliant — is replaced by interoperability profiles (Annex A). A compliant implementation supports the profiles matching its target environment; decisions on requirements rest with bodies like NIST and the NSA, not the transport standard. Annex D covers backward compatibility with FC-SP-2, so mixed fabrics have a documented path rather than a cliff. Audit Mode eases the transition by preserving access first, applying the strictest measures only when both endpoints are capable.


Putting FC-SP-3 on a Live SAN


FC-SP-3 defines the tools and negotiation behavior; how they are applied on a running fabric comes down to two vendor-neutral, compliant models.


Deployment models compared


Aspect Key server model Autonomous in-flight encryption
Key source External key manager (KMIP) Generated inside the HBA
Infrastructure Key servers + network paths + operational discipline None required
Best fit Mainframe / high-compliance shops already running KMIP Fabric-wide rollout on existing gear
Switch changes None None
Fallback Auto-negotiates, falls back when a peer lacks support


In-flight encryption runs in dedicated silicon at full line rate — no throughput penalty, no host CPU load. Because encryption happens at the transport layer, data still arrives at the array in usable form, preserving compression, deduplication and compression-ratio anomaly detection (a key ransomware signal) that application-level encryption destroys. It fits defense-in-depth: link encryption plus full-disk or array-level encryption at rest, anchored by zero-trust endpoints — a silicon root of trust, SPDM mutual attestation between CPU and HBA, and cryptographically signed drivers. Audit Mode lets administrators preview which links would encrypt before enforcement, turning a disruptive cutover into an incremental, verifiable process. Autonomous in-flight encryption already ships in FC-SP-3-capable HBAs; any compliant endpoint can participate, and most storage OEMs add it through 2026.


What In-Flight Encryption Protects Against


FC links leave the room where they originate, crossing conduits, risers and campus runs. An attacker with physical access to fiber does not need to cut it; passive monitoring can read traffic without any alert. Inside the building, an insider with patch-panel access can record traffic, and diagnostic tools can capture frames into service logs. In-flight encryption closes all these paths at once: anything captured between two FC-SP-3 endpoints — from bent fiber, a patch panel or a log file — is ciphertext with no key available at the point of capture. Encrypting at the transport layer protects data in transit while keeping it usable at the array, which is why it is preferred over application-level encryption.


The Road to a Fully Encrypted SAN


The FCIA roadmap runs on refresh-cycle math: servers and storage turn over every three to five years, so nearly every fabric replaces its endpoints at least once before the 2030/2031 deadlines. Every major server vendor already ships FC-SP-3-capable adapters, and most storage OEMs add compliant connectivity through 2026. Encryption-capable endpoints negotiate automatically and coexist with legacy gear; Audit Mode verifies readiness before enforcement. No forklift event is needed. An organization that refreshes on its normal cadence and specifies FC-SP-3 as it goes arrives at 2030 with a fully encrypted, quantum-resistant SAN as a byproduct of routine procurement.


ultimo caso aziendale circa FCIA’s FC-SP-3: A Standard Ready for the Quantum-Computing World  1


Conclusion


FC-SP-3 is not a flashy standard — and that is its virtue. It removes cryptography that should have been retired years ago, adds the NIST post-quantum algorithms regulators require, and replaces a flawed compliance model with interoperability profiles. It lands years ahead of the mandates it satisfies, inside refresh cycles enterprises were already planning. The hard parts have been engineered away: no switch changes, no extra security infrastructure, no host CPU penalty, and an Audit Mode that makes rollout observable before enforcement.


The caveat is that a standard is a toolset, not a deployment. Nothing encrypts itself: organizations must inventory their HBAs and storage, specify FC-SP-3 in upcoming purchases, and enable security as capable endpoints populate the fabric. For finance, healthcare, utilities and government, that work has a deadline whether or not anyone schedules it — HNDL means data stolen today is already exposed to the quantum computers of the next decade. FC-SP-3 closes the gap by making security a procurement detail rather than a project, keeping Fibre Channel what it has been for two decades: the fabric regulated industries trust with the data they can least afford to lose.


Glossary


Term Definition
3DES Triple DES; legacy block cipher removed in FC-SP-3
AES-GCM/CBC/CTR AES modes; GCM required for security association management, CTR removed, keys under 256 bits dropped
CNSA 2.0 NSA's quantum-resistant algorithm suite and deadlines for US National Security Systems
CRQC Cryptanalytically Relevant Quantum Computer, powerful enough to break current public-key crypto
CT authentication Auth of FC Common Transport traffic to fabric services; removed in FC-SP-3
DH-CHAP Fibre Channel auth protocol pairing CHAP with Diffie-Hellman; groups below 2048 bits dropped
DORA Digital Operational Resilience Act, EU regulation for financial-sector ICT risk
ECC/ECDSA Elliptic Curve crypto/signatures; kept at 384 and 512 bits alongside ML-DSA
FC-PAP/FC-EAP Legacy FC-SP-2 auth protocols removed in FC-SP-3
FCIA Fibre Channel Industry Association
HBA Host bus adapter, the FC interface card in servers/storage
HNDL Harvest now, decrypt later
INCITS/T11 Standards body and its FC technical committee that develops FC-SP-3
KMIP Key Management Interoperability Protocol
MD5/SHA-1/SHA-2 Hash functions; MD5 and SHA-1 removed, SHA-2 replaces them
ML-DSA-87 Post-quantum signature algorithm (FIPS 204), added in FC-SP-3
ML-KEM-1024 Post-quantum key establishment (FIPS 203), added in FC-SP-3
NIS2 EU Network and Information Security Directive 2
PQC Post-quantum cryptography
PRF Pseudorandom function; SHA-2-based PRFs required
Q-Day Point at which a CRQC breaks current public-key crypto
RADIUS Network auth protocol; use removed from FC-SP-3
RSA Public-key algorithm a CRQC could break; RSA-SHA-1 removed
SPDM Security Protocol and Data Model, for CPU/HBA attestation



Beijing Qianxing Jietong Technology Co., Ltd.
Sandy Yang/Global Strategy Director
WhatsApp / WeChat: +86 13426366826
Email: yangyd@qianxingdata.com
Website: www.qianxingdata.com/www.storagesserver.com
Business Focus:
ICT Product Distribution/System Integration & Services/Infrastructure Solutions
With 20+ years of IT distribution experience, we partner with leading global brands to deliver reliable products and professional services.
“Using Technology to Build an Intelligent World”Your Trusted ICT Product Service Provider!


Dettagli di contatto
Beijing Qianxing Jietong Technology Co., Ltd.

Persona di contatto: Ms. Sandy Yang

Telefono: 13426366826

Invia la tua richiesta direttamente a noi (0 / 3000)