Apparatus and method for handling or processing higher-layer-processing data at a physical-layer-interface device

TWI933844BActive Publication Date: 2026-08-01MICROCHIP TECHNOLOGY INC
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
TW · TW
Patent Type
Patents
Current Assignee / Owner
MICROCHIP TECHNOLOGY INC
Filing Date
2021-12-03
Publication Date
2026-08-01

AI Technical Summary

Technical Problem

Implementing high-level processing at a physical layer interface device (PHY) can corrupt the timing of time-sensitive data blocks or render them too short, disrupting time-sensitive operations such as Time Sensitive Networking (TSN) and Media Access Control Security (MACsec) protocols.

Method used

The solution involves adding dummy data to time-sensitive data blocks at the PHY to match the size of high-level processing data, ensuring that the timing of the data blocks remains consistent with TSN protocols, and removing high-level processing data at the PHY without making the blocks too short, thus maintaining the integrity of the data.

Benefits of technology

This approach allows for the implementation of high-level processing at the PHY without disrupting time-sensitive operations, ensuring that data blocks adhere to the timing requirements of TSN and maintain the security protocols of MACsec, thereby enhancing the flexibility and scalability of network communications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure TWG2TB001903185_001
    Figure TWG2TB001903185_001
  • Figure TWG2TB001903185_002
    Figure TWG2TB001903185_002
  • Figure TWG2TB001903185_003
    Figure TWG2TB001903185_003
Patent Text Reader

Abstract

This invention typically relates to performing high-level processing on time-sensitive data blocks at a physical layer interface device. Some examples include logic for performing operations, including providing data blocks to the physical layer interface device. Operations may also include adding dummy data to one or more time-sensitive data blocks provided to the physical layer interface device. The size of the dummy data corresponds to the size of the high-level processed data. Other example operations may include removing high-level processed data from a first input data block. Other operations may include removing a portion of the first input data block and adding that portion to a subsequent input data block. The size of that portion corresponds to the size of integrity detection data. Other operations may include removing integrity detection data from an input data block. Related methods, systems, and apparatus are also disclosed.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] [Priority Claim] This application claims the benefit of priority date to U.S. Provisional Patent Application No. 63 / 199,058, filed December 4, 2020, entitled "Implementing HIGHER-LAYER PROCESSING ON TIME-SENSITIVE DATA BLOCKS AT A PHYSICAL-LAYER INTERFACE", the disclosure of which is incorporated herein by reference in its entirety.

[0002] This specification generally relates to high-level data processing in time-sensitive data blocks at the Physical Layer Interface (PHY). More specifically, some embodiments relate to implementing processes for adding or removing data at the PHY. More specifically, some embodiments relate to implementing processes, such that when data is added to a time-sensitive data block at the PHY, such addition does not disrupt the timing of the time-sensitive data block, but are not limited thereto. Additionally, some embodiments relate to implementing processes such that when data is removed from a data block at the PHY, the removal does not make the block too short and / or does not require the host to modify data outside the header, but are not limited thereto. [Previous Technology]

[0003] Media Access Control (MAC) security (MACsec) can be used to enhance the security of communications in Ethernet networks. MACsec may involve encrypting Ethernet frames, adding security tags (SecTags) to Ethernet frames, and adding integrity detection data (ICV) to Ethernet frames. MACsec is described in at least the following standards: IEEE Standard (Std) 802.1Q-2018, IEEE Std 802.1 AB-2016, IEEE Std 802.AS-2020, IEEE Std 802.AX-2020, IEEE Std 802.1 BA-2011, IEEE Std 802.1CB-2017, IEEE Std 802.1CM-2018, IEEE Std 802.1CMde-2020, IEEE Std 802.1Qbu-2016, IEEE Std 802.1Qbv-2015, IEEE Std 802.1Qca-2015, IEEE Std 802.1Qch-2017, IEEE Std 802.1.Qci-2017, IEEE Std 802.1Qcc-2018, IEEE Std 802.1Qcp-2018, IEEE Std 802.1Qcr-2020, IEEE Std 802.1Qcx-2020, IEEE Std 802.1AS-2011, IEEE Std 802.1Qat-2010, IEEE Std 802.1Qav2009, IEEE Std 802.1 BA-2011, IEEE Std 802.3br-2016, and IEEE Std 802.3-2018.

[0004] Time-Sensitive Networking (TSN) may include Quality of Service (QoS) techniques, which may include providing time-sensitive communication. A TSN may involve scheduling Ethernet frames at a transmitter, such that a receiver can determine timing information based on the reception of scheduled Ethernet frames. Additionally, in some embodiments, a TSN may involve interrupting a frame to transmit a higher-priority frame. TSN is described at least in IEEE Std 802.1AE. [Summary of the Invention]

[0005] This invention discloses an apparatus comprising: circuitry for providing data blocks to a physical layer interface device, the physical layer interface device including logic for performing high-level processing on the received data blocks; and a logic circuitry for: adding dummy data to one or more time-sensitive data blocks among the data blocks, the size of the dummy data corresponding to the size of high-level processed data; and providing the data blocks including the one or more time-sensitive data blocks to the physical layer interface device.

Implementation Method

[0007] In the following detailed description, reference is made to the accompanying drawings, which form a part of the description, and specific embodiments in which the present disclosure may be practiced are illustrated. These embodiments are described in sufficient detail to enable those skilled in the art to practice the present disclosure. However, other embodiments may be utilized, and structural, material, and procedural changes may be made without departing from the scope of the present disclosure.

[0008] The illustrations presented herein are not intended to represent actual views of any particular method, system, apparatus, or structure, but are merely idealized representations used to describe embodiments of the present disclosure. The drawings presented herein are not necessarily drawn to scale. Similar structures or components in the various drawings may retain the same or similar designations for the reader's convenience; however, similarity in designations does not imply that the structures or components are necessarily identical in size, composition, structure, or any other property.

[0009] The following description may include embodiments to help those skilled in the art to practice the disclosed embodiments. The use of the terms "illustrative," "by way of an embodiment," and "for example" means that the related description is explanatory, and although the scope of this disclosure is intended to cover embodiments and legal equivalents, the use of such terms is not intended to limit the scope of the embodiments disclosed to the specified components, steps, features, functions, or the like.

[0010] It will be readily understood that the components of the embodiments generally described herein and illustrated in the drawings can be configured and designed in a wide variety of different ways. Therefore, the following description of various embodiments is not intended to limit the scope of this disclosure, but merely to illustrate various embodiments. Although various forms of embodiments may be presented in the drawings, the drawings are not necessarily drawn to scale unless specifically indicated otherwise.

[0011] Furthermore, unless otherwise specified herein, the specific embodiments shown and described are merely examples and should not be considered the only way to implement this disclosure. Components, circuits, and functions may be described in block diagram form to avoid obscuring this disclosure with unnecessary details. Conversely, the specific embodiments shown and described are merely illustrative and should not be considered the only way to implement this disclosure unless otherwise specified herein. Additionally, block definitions and logical partitioning between various blocks are illustrations of specific embodiments. It will be apparent to those skilled in the art that this disclosure can be implemented by numerous other partitioning solutions. To a large extent, details regarding timing considerations and the like have been omitted, where such details are unnecessary for obtaining a complete understanding of this disclosure and are within the capabilities of those skilled in the art.

[0012] Those skilled in the art will understand that information and signals can be represented using any of a variety of different techniques and methods. For example, data, instructions, commands, information, signals, bits, and symbols that may be referenced throughout this description can be represented by voltage, current, electromagnetic waves, magnetic fields or magnetic particles, light fields or optical particles, or any combination thereof. For clarity of presentation and description, some diagrams may illustrate a signal as a single signal. Those skilled in the art will understand that a signal can represent a bus of signals, wherein the bus can have multiple bit widths, and this disclosure can be implemented on any number of data signals, including a single data signal. Those skilled in the art will understand that this disclosure covers quantum information and the transmission of qubits used to represent quantum information.

[0013] The various schematic logic blocks, modules, and circuits described in connection with the embodiments disclosed herein can be implemented or executed by logic and / or circuits including, as non-limiting examples, the following: general-purpose processors, special-purpose processors, digital signal processors (DSPs), integrated circuits (ICs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices designed to perform the functions described herein, discrete gate or transistor logic, discrete hardware components, or any combination thereof. A general-purpose processor (also referred to herein as a host processor or simply a host) can be a microprocessor, but in alternative embodiments, the processor can be any known processor, controller, microcontroller, or state machine. The processor can also be implemented as a combination of computing devices, such as a combination of a DSP and a microprocessor, a plurality of microprocessors, a combination of one or more microprocessors with a DSP core, or any other such configuration. A general-purpose computer including a processor is considered a special-purpose computer, and the general-purpose computer executes computational instructions (e.g., software code) related to the embodiments disclosed herein.

[0014] Embodiments may be described based on a program described as a flowchart, flow diagram, block diagram, or block diagram. Although a flowchart may describe operations as a sequential procedure, many such operations may be performed in another sequence, in parallel, or substantially simultaneously. Furthermore, the order of operations may be reconfigured. A program may correspond non-limitingly to a method, thread, function, procedure, subroutine, and / or subprogram. Moreover, the methods disclosed herein may be implemented in hardware, software, or both. If implemented in software, such functionality may be stored as one or more instructions or program code on or transmitted on a computer-readable medium. Computer-readable media includes both computer storage media and communication media, and communication media includes any media that facilitates the transfer of computer programs from one place to another.

[0015] Some devices can communicate with other devices across communication networks (e.g., Ethernet) or across direct connections. These devices can implement various network connectivity protocols at various components or devices. For example, a device may include components or devices that implement protocols that connect to Open Systems Interconnection (OSI) Layer 2, Data Link Layer, such as components or devices that implement the Media Access Control (MAC) protocol. In this disclosure, a component or device that implements the MAC protocol may be referred to as a "MAC". Additionally, the device may include components that implement protocols that connect to OSI Layer 1, such as components that implement protocols at the Physical Layer interface. In this disclosure, a component or device that implements protocols at the Physical Layer interface may be referred to as a "PHY" or "Physical Layer Interface Device". In this disclosure, the term "Physical Layer Interface" may refer to the interface between the PHY and the Ethernet connection. The PHY may also have an interface to the MAC; such a connection may be referred to herein as a "MAC-PHY connection".

[0016] In some cases, it may be advantageous to implement higher-level processing at components or devices typically associated with lower-level processing. For example, it may be advantageous to implement higher-layer (e.g., Layer 2) security protocols at the PHY. In this disclosure, processing associated with a layer (e.g., OSI layer) implemented at components or devices typically associated with lower layers may be referred to as "higher-level processing". As a particular non-limiting embodiment, MACsec, Internet Protocol Security (IPsec), cryptographic compilers, and encapsulation may be higher-level processing relative to the PHY.

[0017] Implementing higher-level processing at components or devices typically associated with lower-level processing allows for the advantages of scaling. Specifically, it is conventional to scale processing implemented in a System-on-a-Chip (SoC) / switch / Application-Specific Integrated Circuit (ASIC) to meet maximum expected performance. For example, an SoC / switch / ASIC can be sized to serve maximum expected performance, even if initially using a lower performance ratio or never using maximum expected performance. In contrast, processing implemented in a PHY can be scaled according to a "pay-as-you-go" model. As more ports are enabled, each port requires an additional PHY; the need for higher-level processing for each new port can be determined by supplying the appropriate PHY, and then higher-level processing capabilities can be added to the port as needed.

[0018] Alternatively, implementing higher-level processing at components or devices typically associated with lower-level processing allows for the advantages of feature upgrades. Typically, SoCs / switches / ASICs are large and complex parts of a system and are rarely easy or as frequently upgraded as the PHY. Therefore, implementing higher-level processing at the PHY allows systems that initially do not support features (e.g., MACsec) to later add those features by upgrading the PHY. Upgrading the PHY to add MACsec features to the system is a much easier way to add MACsec features compared to replacing a much larger SoC / switch / ASIC.

[0019] However, in some cases, implementing higher-level processing at components or devices typically associated with lower-level processing can lead to concurrency issues. For example, implementing protocols at different layers can alter the order in which protocols are implemented. For instance, regarding data blocks, protocols involving adding data to data blocks implemented after a time-sensitive protocol (e.g., implemented at the MAC) (e.g., at the PHY) may disrupt the timing of data blocks and compromise the performance of the time-sensitive protocol. As another example, regarding data blocks, protocols involving removing data from data blocks implemented at the PHY (e.g., MACsec) may make the data blocks too short, for example, for protocols at the receiving host.

[0020] One or more embodiments may allow a component or device to typically associate with lower-level processing to perform one or more operations of higher-level processing without violating time-sensitive protocol operations. As a particular non-limiting embodiment, one or more embodiments may allow the PHY to implement processes that add data to an output data block without violating time-sensitive operations that may occur at the MAC. As a particular non-limiting embodiment, the PHY may implement the MAC security (MACsec) protocol without violating the Time-Sensitive Networking (TSN) protocol operations occurring at the MAC. In particular, one or both of the MAC and PHY may implement one or more embodiments such that the MAC can implement TSN, and the PHY can implement MACsec without violating TSN operations at the MAC. As another particular non-limiting embodiment, one or more embodiments may allow the PHY to implement processes that remove data from an incoming data block without causing the data block to become too short. In particular, the PHY may implement MACsec and may modify the received data block such that the data frame is not too short after the SecTag and / or ICV are removed. Alternatively, data blocks can be modified without requiring the host to change the bytes outside the header of the data block.

[0021] FIG1 illustrates an exemplary environment 100 in which one or more embodiments may be operated. In particular, FIG1 illustrates devices 102 and 108, which may (e.g., directly or across communication network 122) communicate with each other. Device 102 includes circuitry and / or logic including MAC 104 and PHY 106, and device 108 includes circuitry and / or logic including MAC 110 and PHY 112.

[0022] MAC 104 and MAC 110 can perform one or more operations associated with a data link layer (e.g., OSI layer 2). For example, MAC 104 and MAC 110 can match, add, and remove MAC headers from incoming frames. MAC 104 can provide frames to PHY 106 and receive frames from that PHY, and MAC 110 can provide frames to PHY 112 and receive frames from that PHY.

[0023] PHY 106 and PHY 112 can perform one or more operations associated with a physical layer (e.g., OSI layer 1). For example, PHY 106 and PHY 112 can transmit and receive data across a connection (e.g., directly or across communication network 122) by transmitting and receiving signals at a transmission medium. Device 102 includes a MAC-PHY connection 114 and a physical layer interface 118. Device 108 includes a MAC-PHY connection 116 and a physical layer interface 120.

[0024] As an example, messages from device 102 to device 108 can be initiated at device 102. Messages can be modified by operations associated with one or more of OSI layers 7 to 2, including, for example, reformatting the message into one or more data blocks (e.g., one or more Ethernet frames). One or more data blocks can then be modified by operations at MAC 104, for example, adding a MAC header to one or more data blocks. One or more data blocks can then be provided to PHY 106 via MAC 104. One or more data blocks can then be transmitted over physical media via PHY 106. One or more data blocks can traverse communication network 122, as illustrated in FIG1, or, in the case where PHY 106 is directly connected to PHY 112, one or more data blocks can be transmitted directly from PHY 106 to PHY 112. In either case, one or more data blocks will be received at the physical media via PHY 112. The one or more data blocks can then be provided to MAC 110 via PHY 112. At MAC 110, the MAC header can be matched and removed. Subsequently, the one or more data blocks can be modified through operations associated with one or more of OSI layers 2 to 7, thereby causing a message to be received by device 108.

[0025] Figure 2 illustrates an example system 200 that may implement one or more embodiments. Specifically, system 200 includes a device 202 comprising logic and / or circuitry including a PHY 216 and a host 204. The host 204 includes logic and / or circuitry including a MAC client 208 and a MAC 206. The device 202, including MAC 206, MAC client 208, and PHY 216, may implement one or more embodiments. For example, one or more of the host 204, MAC 206, MAC client 208, and PHY 216 may implement one or more embodiments such that PHY 216 can perform one or more operations associated with higher-level processing without disrupting time-sensitive operations. As a particular non-limiting embodiment, one or more of host 204, MAC 206, and MAC client 208 may provide data blocks to PHY 216 in such a manner that when PHY 216 performs higher-level processing (e.g., operations associated with OSI layer 2 or higher, such as MACsec), the implementation of the higher-level processing does not disrupt, for example, time-sensitive operations previously implemented at host 204 (e.g., associated with TSN). As another example, one or more of host 204, MAC 206, MAC client 208, and PHY 216 may implement one or more embodiments such that PHY 216 can perform one or more operations associated with higher-level processing without causing the received data blocks to be too short. As a particular non-limiting embodiment, PHY 216 may receive modified data blocks (e.g., modified according to MACsec) at Ethernet connection 234 and provide processed data blocks (e.g., processed to remove changes) to MAC 206 in a manner that processing does not make the blocks too short.

[0026] Device 202 may be or may include any device that communicates on a communication network. For example, device 202 may be an example of device 102 or device 108 of FIG1 or a component or device thereof.

[0027] Host 204 may be or may include hardware (including, for example, circuitry and / or logic) to perform operations associated with host application 236. Host application 236 may use features of MAC 206, MAC client 208, and PHY 216 to communicate across Ethernet connection 234. Additionally, host application 236 may use features such as, but not limited to, TSN and MACsec. For example, if host application 236 is an industrial control application, host 204 may implement control software with movable actuators and valves to perform industrial operations. Industrial operations may need to be performed at specified times, thus requiring TSN to ensure commands are received at exactly the correct time. Furthermore, industrial environments may make security a concern (e.g., but not limited to, in nuclear power plants), therefore host 204 may require MACsec to protect sent commands. In some embodiments, host 204 may be a data forwarding device, such as, but not limited to, an Ethernet switch or router. In such cases, host application 236 may not exist, but host 204 may use any suitable protocol (such as, but not limited to, Ethernet switching or IP routing) to connect from one physical layer interface (not marked in FIG2) to the physical layer interface of another device (not shown in FIG2) (e.g., across Ethernet connection 234).

[0028] MAC 206 and / or MAC client 208 may perform one or more operations associated with OSI layer 2. For example, MAC 206 and / or MAC client 208 may match, add, and / or remove MAC headers. Additionally, MAC 206 and / or MAC client 208 may support frame preemption. For example, regarding data transmission (e.g., from device 202 to another device), MAC 206 and / or MAC client 208 may allow a later-received high-speed frame 230 ("e-frame 230") (e.g., received at E-MAC 226) to be transmitted before a previously received preemptible frame 228 ("P-frame 228") (e.g., received at P-MAC 224) based on the e-frame state being "high-speed". Preemption may be implemented according to IEEE 802.3 Clause 99. p-frame 228 and e-frame 230 are provided at MAC-PHY link 232 before being merged at MAC merge sublayer 214 before reaching PHY 216.

[0029] In some embodiments, the MAC client 208 may implement a timing-sensitive protocol.

[0030] For example, the MAC client 208 may implement a time-sensitive protocol (e.g., TSN). The MAC client 208 may include a TSN scheduling module 210 and a queueing module 212, which together can perform one or more operations related to TSN.

[0031] TSN scheduling module 210 can schedule data blocks (e.g., Ethernet frames).

[0032] The TSN scheduling module 210 can cause scheduled data blocks to be transmitted according to the schedule, that is, it enables the receiver to receive scheduled data blocks as expected according to the schedule. For example, scheduled data blocks can be transmitted at regular intervals. In addition, the TSN scheduling module 210 can determine whether the received data block is received according to the reception schedule.

[0033] The queue module 212 can maintain one or more data blocks in a queue. Data blocks can be maintained in the queue before being transmitted to allow higher-priority data blocks (e.g., e-frame 230) to preempt lower-priority data blocks (e.g., p-frame 228). Therefore, the higher-priority e-frame 230 can be transmitted regardless of any lower-priority p-frame 228 that may already be in the transmission process. Frame preemption allows e-frame 230 to interrupt p-frame 228 to follow the schedule.

[0034] In addition, MAC client 208 and / or MAC 206 may allow lower priority data blocks to be segmented (e.g., divided into fragments) to allow higher priority data blocks to interrupt the transmission of lower priority data blocks.

[0035] Additionally, MAC 206 and MAC client 208 can receive and / or process data frames received from PHY 216 and provide the data frames to host 204 and / or host application 236. MAC 206 and MAC client 208 can process data frames according to TSN. For example, MAC 206 can verify frame fragments (or frames) and / or reassemble verified frame fragments. Furthermore, once e-frames 230 are received, MAC client 208 can provide such e-frames. Alternatively, MAC client 208 can hold received p-frames 228 at queue module 212 so that host application 236 can access p-frames as needed.

[0036] MAC 206 may, for example, provide data blocks (including, for example, scheduled and / or segmented data blocks) to PHY 216 at MAC-PHY link 232 (which may be, for example, but not limited to, a serial or parallel bus). PHY 216 may receive and transmit data blocks at the physical medium. For example, protocol sublayer 222 may transmit data blocks, such as transmitting one or more bits at a time at the physical medium, for example, as charge on a line or antenna. Additionally, PHY 216 may receive and provide data blocks to MAC 206 at the physical medium.

[0037] Additionally, PHY 216 may include a higher-level processing module 218. The higher-level processing module 218 may implement higher-level processing (e.g., processing associated with any of OSI layers 2 to 7). For example, PHY 216 may implement MACsec. For example, higher-level processing module 218 may include a MACsec module 220 that can implement MACsec. Higher-level processing may involve adding data to a data block before transmitting the data block and removing data from the data block upon receiving the data block.

[0038] The host 204 and / or PHY 216 of device 202 may implement one or more embodiments such that when PHY 216 performs higher-level processing (e.g., MACsec) on output data blocks, the higher-level processing does not disrupt time-sensitive operations (e.g., TSN) performed at MAC 206. Alternatively, PHY 216 may implement one or more embodiments such that higher-level processing (e.g., MACsec) on incoming data blocks does not cause the incoming data blocks to be too short.

[0039] Figures 3A, 4A, and 5A illustrate examples of the timing of transmitting an exemplary data block at a MAC (e.g., MAC 206 of Figure 2) according to one or more embodiments. The data blocks of Figures 3A, 4A, and 5A may be provided by the transmitter's MAC to the transmitter's PHY at a MAC-PHY connection (e.g., MAC-PHY connection 232 of Figure 2). Figures 3B, 4B, and 5B illustrate examples of the timing of transmitting an exemplary data block at a PHY (e.g., PHY 216 of Figure 2) according to one or more embodiments. The transmitted data blocks of Figures 3B, 4B, and 5B may be the transmitted data blocks of Figures 3A, 4A, and 5A after higher-level processing is performed at the transmitter's PHY. The outgoing data blocks of Figures 3B, 4B, and 5B may be ready to be output by the transmitter's PHY at an Ethernet connection (e.g., Ethernet connection 234 in Figure 2). The outgoing data blocks of Figures 3B, 4B, and / or 5B can be received by a system implementing MACsec and TSN at any suitable component or device. For example, the receiver of the outgoing data blocks of Figures 3B, 4B, and / or 5B can implement MACsec at the PHY or MAC.

[0040] In this disclosure, timing diagrams (e.g., as illustrated in Figures 3A to 8B) depict data blocks ordered from the first on the right to the last on the left. Data blocks can be transmitted at a certain data rate. Therefore, the size of a data block (e.g., in bytes) and timing can be correlated by the data rate. Furthermore, in this disclosure, the description of timing can be correlated with the number of seconds and / or bytes. For example, one time period can be described as several bytes following another time period. Data blocks and / or portions thereof are not drawn to scale.

[0041] FIG3A illustrates an example of timing for data blocks transmitted after implementing a time-sensitive scheduling function (e.g., TSN) (e.g., at the MAC) according to one or more embodiments. FIG3B illustrates an example of timing for corresponding output data blocks after implementing higher-level processing associated with a higher-level protocol (e.g., MACsec) at the PHY, for example. In particular, FIG3A illustrates an adjusted timing 302 according to one or more embodiments, which is the timing for data blocks transmitted after implementing TSN at the MAC (and is also expected to be adjusted due to the subsequent application of MACsec operation at the PHY). FIG3B illustrates output frame timing 304, which is the timing for data blocks, for example, after implementing MACsec at the PHY.

[0042] The adjusted timing 302 includes data blocks: frame F1_1, frame F2_1 and frame F3_1. Each of the data blocks includes a preamble, an Ethernet header, a payload (untagged) and a frame check sequence (FCS).

[0043] Output frame timing 304 includes data blocks: frames F1s, F2s, and F3s. Each of the data blocks in output frame timing 304 corresponds to a data block in adjusted timing 302. In particular, the data blocks in output frame timing 304 may be data blocks in adjusted timing 302 after MACsec implementation. MACsec implementation may include encrypting at least a portion of one or more data blocks (e.g., payload), adding a security tag (SecTag) to one or more data blocks, and / or adding integrity detection data (ICV) to one or more data blocks. MACsec implementation may allow authentication (e.g., by adding ICV) and / or confidentiality (e.g., via encryption). For example, frame F1s may be frame F1_1 after MACsec implementation, i.e., including SecTag 308 and ICV 310.

[0044] According to one or more embodiments, each of the data blocks in the adjusted timing 302 is separated by an extended interframe gap (IFG) (e.g., extended IFG 306). Extended IFG 306 may be longer than a standard IFG, such as standard IFG 312. Extended IFG 306 may be longer than standard IFG 312 by a duration related to the data added to the data block via MACsec. Specifically, extended IFG 306 may be longer than standard IFG 312 by a duration (or number of bytes) corresponding to the size of SecTag 308 and ICV 310. As a particular non-limiting embodiment, standard IFG 312 may be 12 bytes long, SecTag 308 may be 16 bytes long, and ICV 310 may be 16 bytes long; therefore, extended IFG 306 may be 44 bytes long.

[0045] For example, in the embodiment illustrated in FIG3B, frame F1s is 112 bytes long (i.e., the original frame F1_1 has 80 bytes plus 16 bytes of SecTag 308 and 16 bytes of ICV 310) and standard IFG 312 is 12 bytes long. Frame F2s starts at T2, which is T1 (the time when frame F1s starts) plus 124 bytes (i.e., the 112 bytes of frame F1s and the 12 bytes used for standard IFG 312). Furthermore, in the embodiment illustrated in Figure 3A, where frame F1_1 is 80 bytes long and the extended IFG 306 is 44 bytes long, F2_l starts at T2, which is T1 plus 124 bytes (i.e., the 80 bytes of frame F1_1 plus the 44 bytes of extended IFG 306). Similarly, in both Figures 3A and 3B, T3 (the start time of frames F3_1 and F3s) is 368 bytes after T1. Therefore, the adjusted timing 302 in Figure 3A ensures that implementing MACsec at the PHY (e.g., as illustrated in Figure 3B) does not compromise the time sensitivity of the data block.

[0046] In some cases, the extended IFG 306 may have a longer duration (or number of bytes) than the standard IFG 312, which is longer than the corresponding sizes of SecTag 308 and ICV 310. For example, in some cases, not all frames in a series of frames can be encrypted, and / or some frames in a frame string can be encrypted using different encryption methods. In such cases, it may be appropriate for the extended IFG to correspond entirely to the largest SecTag and ICV of the series of frames and the size of the standard IFG 312.

[0047] Because the adjusted timing 302 includes an extended IFG 306 (instead of the standard IFG 312), the adjusted timing 302 allows the timing of the output frame timing 304 to be based on the TSN after implementing MACsec (specifically, adding SecTag 308 to ICV 310). Specifically, based on the TSN, the receiver can expect data blocks to begin at specific times (e.g., T1, T2, and T3). The adjusted timing 302 (specifically, the extension of IFG 306 compared to the standard IFG 312) allows the data blocks of the output frame timing 304 (i.e., after implementing MACsec) to begin at specific times (e.g., T1, T2, and T3). Therefore, one or more embodiments may allow the implementation of higher-level protocols (e.g., MACsec) (e.g., at the PHY) after implementing time-sensitive protocols (e.g., TSN) (e.g., at the MAC) without compromising the time-sensitive nature of the data blocks.

[0048] To implement the embodiment described with respect to FIG3A, the MAC (e.g., MAC 206 of FIG2) may include an extended IFG 306 of a specific duration. In particular, the MAC may include an extended IFG 306 having a duration corresponding to the standard IFG 312 plus the size of the bytes to be added at the PHY according to a higher-level protocol (e.g., MACsec). Alternatively, in some cases, the MAC may include an additional extended IFG (not shown) with a duration greater than the standard IFG 312 plus the size of the bytes to be added at the PHY by higher-level processing.

[0049] Figure 4A illustrates an example of timing for data blocks transmitted at the MAC after the implementation of a timing agreement, according to one or more embodiments.

[0050] Figure 4B illustrates an example of the timing of the corresponding output data block after higher-level processing associated with a higher-level protocol (e.g., MACsec) is implemented at the PHY. Specifically, Figure 4A illustrates adjusted timing 402, which is the timing of a data block transmitted at the MAC after implementing TSN according to one or more embodiments. Figure 4B illustrates output frame timing 404, which is the timing of a data block, for example, after implementing MACsec at the PHY.

[0051] The adjusted timing 402 includes data blocks: frame F1_2, frame F2_2 and frame F3_2. Each of the data blocks includes a preamble, an Ethernet header, a payload (untagged) and an FCS.

[0052] Output frame timing 404 includes data blocks: frames F1s, F2s, and F3s. Each of the data blocks in output frame timing 404 corresponds to a data block in adjusted timing 402. In particular, the data block in output frame timing 404 may be a data block in adjusted timing 402 after MACsec implementation. MACsec implementation may include encrypting at least a portion of one or more data blocks (e.g., payload), adding a SecTag to one or more data blocks, and / or adding an ICV to one or more data blocks. For example, frame F1s may be frame F1_2 after MACsec implementation, i.e., including SecTag 410 and ICV 412.

[0053] According to one or more embodiments, each of the data blocks in the adjusted timing 402 includes a dummy SecTag 406 and a dummy ICV 408. The size of the dummy SecTag 406 may correspond to the size of the SecTag 410, and the size of the dummy ICV 408 may correspond to the size of the ICV 412. As a particular non-limiting embodiment, the SecTag 410 may be 16 bytes long, therefore the dummy SecTag 406 may be 16 bytes long. Similarly, the ICV 412 may be 16 bytes long, and the dummy ICV 408 may be 16 bytes long. When MACsec is implemented (e.g., at the PHY), the dummy SecTag 406 and the dummy ICV 408 may be overwritten by the SecTag 410 and ICV 412, respectively.

[0054] Because the adjusted timing 402 includes dummy SecTag 406 and dummy ICV 408, the adjusted output timing 400 allows the timing of the output frame timing 404 to be based on TSN after MACsec is implemented. Specifically, based on TSN, the receiver can expect data blocks to start at specific times (e.g., T1, T2, and T3). The adjusted timing 402 (specifically, including dummy SecTag 406 and dummy ICV 408) allows the data blocks of the output frame timing 404 (i.e., after MACsec is implemented) to start at specific times (e.g., T1, T2, and T3). Therefore, one or more embodiments may allow the implementation of higher-level protocols (e.g., MACsec) at the PHY after the implementation of time-sensitive protocols (e.g., TSN) (e.g., at the MAC) without compromising the time-sensitive nature of the data blocks.

[0055] For example, in the embodiment illustrated in FIG4B, frame F1s is 112 bytes long (i.e., 80 bytes of frame F1_1 plus 16 bytes of SecTag 410 and 16 bytes of ICV 412) and the standard IFG is 12 bytes long. Frame F2s starts at T2, which is T1 (the time when frame F1s starts) plus 124 bytes (i.e., 112 bytes of frame F1s and 12 bytes for the standard IFG). Furthermore, in the embodiment illustrated in Figure 4A, frame F1_2 is 112 bytes long (i.e., the original frame's 80 bytes plus the 16 bytes of dummy SecTag 406 and the 16 bytes of dummy ICV 408) and the standard IFG is 12 bytes long. F2_2 starts at T2, which is T1 plus 124 bytes (i.e., frame F1_2's 112 bytes plus the standard IFG's 12 bytes). Similarly, in both Figures 4A and 4B, T3 (the start time of frames F3_2 and F3s) is 368 bytes after T1. Therefore, the adjusted timing 402 in Figure 4A ensures that implementing MACsec at the PHY (e.g., as illustrated in Figure 4B) does not compromise the time sensitivity of the data block.

[0056] To implement the embodiment described with respect to FIG4A, a MAC client (e.g., MAC client 208 of FIG2), a queue module (e.g., queue module 212 of FIG2), or a host application (e.g., host application 236 of FIG2) may include dummy data of a specific size in the data block. In particular, the MAC client, queue module, and / or host application may include dummy data in the data block with a size corresponding to the size of bytes added at the PHY according to higher-level processing to be associated with higher-level protocols (e.g., MACsec). Alternatively, the PHY may overwrite the dummy data with additional data instead of adding additional data.

[0057] Figure 5A illustrates an example of timing for data blocks transmitted at the MAC after the implementation of a timing agreement, according to one or more embodiments.

[0058] FIG5B illustrates an example of the timing of the corresponding output data block after higher-level processing associated with a higher-level protocol (e.g., MACsec) is implemented at the PHY. Specifically, FIG5A illustrates adjusted timing 502, which is the timing of a data block transmitted after implementing TSN at the MAC according to one or more embodiments. FIG5B illustrates output frame timing 504, which is the timing of a data block, for example, after implementing MACsec at the PHY.

[0059] The adjusted timing 502 includes data blocks: frame F1_3, frame F2_3 and frame F3_3. Each of the data blocks includes a preamble, an Ethernet header, a payload (untagged) and an FCS.

[0060] Output frame timing 504 includes data blocks: frame F1s, frame F2s, and frame F3s. Each of the data blocks in output frame timing 504 corresponds to a data block in adjusted timing 502. In particular, the data block in output frame timing 504 may be a data block in adjusted timing 502 after MACsec implementation. MACsec implementation may include encrypting at least a portion of one or more data blocks (e.g., payload), adding a SecTag to one or more data blocks, and / or adding an ICV to one or more data blocks. For example, frame F1s may be frame F1_3 after MACsec implementation, i.e., including SecTag 512 and ICV 514.

[0061] According to one or more embodiments, similar to that described with respect to FIG4A, each of the data blocks in the adjusted timing 502 includes a dummy SecTag 506. The size of the dummy SecTag 506 may correspond to the size of some (e.g., SecTag 512) of bytes to be added at the PHY according to higher-level processing associated with a higher-level protocol (e.g., MACsec). As a particular non-limiting embodiment, SecTag 512 may be 16 bytes long, and therefore the dummy SecTag 506 may be 16 bytes long.

[0062] Additionally, according to one or more embodiments, similar to that described with respect to FIG3A, each of the frames in the adjusted timing 502 is separated by an extended IFG 508. The extended IFG 508 may be longer than the standard IFG 510 by a duration corresponding to (or in some cases greater than) the size of some (e.g., ICV 514) of bytes to be added at the PHY according to higher-level processing associated with a higher-level protocol (e.g., MACsec). As a particular non-limiting embodiment, the standard IFG 510 may be 12 bytes long and the ICV 514 may be 16 bytes long, and therefore the extended IFG 508 may be 28 bytes long (or longer).

[0063] Because the adjusted timing 502 includes an extended IFG 508 (instead of the standard IFG 510) and a dummy SecTag 506, the adjusted timing 502 ensures that after MACsec is implemented (specifically, by adding SecTag 512 to ICV 514), the timing of the output frame timing 504 is based on the TSN. Specifically, based on the TSN, the receiver can expect data blocks to begin at specific times (e.g., T1, T2, and T3). The adjusted timing 502 (specifically, the extended IFG 508 compared to the standard IFG 510, and including the dummy SecTag 506) ensures that the data blocks of the output frame timing 504 (i.e., after MACsec is implemented) begin at specific times (e.g., T1, T2, and T3). Therefore, one or more embodiments may allow high-level processing associated with higher-level protocols (e.g., MACsec) to be performed at the PHY after implementing a time-sensitive protocol (e.g., TSN) (e.g., at the MAC) without compromising the time-sensitive nature of the data block.

[0064] For example, in the embodiment illustrated in FIG5B, frame F1s is 112 bytes long (i.e., 80 bytes of frame F1_1 plus 16 bytes of SecTag 512 and 16 bytes of ICV 514) and standard IFG 510 is 12 bytes long. Frame F2s starts at T2, which is T1 (the time when frame F1s starts) plus 124 bytes (i.e., 112 bytes of frame F1s and 12 bytes for standard IFG 510). Furthermore, in the embodiment illustrated in Figure 5A, frame F1_3 is 96 bytes long (i.e., the 80 bytes of frame F1_1 plus the 16 bytes of the dummy SecTag 506) and the extended IFG 508 is 28 bytes long (i.e., the size of the standard IFG 510 plus the size of the ICV 514). F2_3 starts at T2, which is T1 plus 124 bytes (i.e., the 96 bytes of frame F1_3 plus the 28 bytes of the extended IFG 508). Similarly, in both Figures 5A and 5B, T3 (the start time of frames F3_3 and F3s) is 368 bytes after T1. Therefore, the adjusted timing 502 in Figure 5A ensures that implementing MACsec at the PHY (e.g., as illustrated in Figure 5B) does not compromise the time sensitivity of the data block.

[0065] To implement the embodiment described with respect to FIG. 5A, the MAC (e.g., MAC 206) may include an IFG of a specific duration. Specifically, the MAC may include an IFG having a duration corresponding to a standard IFG plus the size of some (e.g., ICV 514) of bytes to be added to the PHY according to a higher-level protocol (e.g., MACsec). Additionally, to implement the embodiment described with respect to FIG. 5A, the MAC client (e.g., MAC client 208), the queue module (e.g., queue module 212), or the host application (e.g., host application 236) may include dummy data of a specific size in the frame. Specifically, the MAC client, the queue module, and / or the host application may include dummy data in the frame with a size corresponding to some (e.g., SecTag 512) of bytes to be added to the PHY according to a higher-level protocol (e.g., MACsec). Alternatively, the PHY may overwrite the dummy data with additional data instead of adding additional data.

[0066] Figures 6A, 7A, and 8A illustrate examples of the timing of an exemplary incoming data block received at a PHY (e.g., PHY 216 of Figure 2) according to one or more embodiments. For example, the incoming data blocks of Figures 6A, 7A, and 8A may be received by the receiver's PHY at an Ethernet connection. Figures 6B, 7B, and 8B illustrate examples of the timing of an exemplary incoming data block provided to a MAC (e.g., MAC 206 of Figure 2) according to one or more embodiments. The incoming data blocks of Figures 6B, 7B, and 8B may be, for example, the data blocks at Figures 6A, 7A, and 8A after processing at the PHY. For example, the incoming data blocks of Figures 6B, 7B, and 8B may be provided by the receiver's PHY to the receiver's MAC at a MAC-PHY connection. The incoming data blocks in Figures 6A, 7A, and / or 8A may have been transmitted by the system implementing MACsec and TSN at any suitable component or device. For example, the transmitter of the incoming data blocks in Figures 6A, 7A, and / or 8A may have implemented MACsec at the PHY or MAC.

[0067] FIG6A illustrates an example of timing for data blocks (e.g., received at the PHY), which include data associated with higher-level processing connected to a higher-level protocol (e.g., MACsec). FIG6B illustrates an example of timing for corresponding data blocks (e.g., provided to the MAC) according to one or more embodiments. In particular, FIG6A illustrates input frame segment timing 602, which is the timing of a frame segment received at the PHY. FIG6B illustrates an adjusted frame segment timing 604 according to one or more embodiments, which is the timing of a corresponding frame segment provided by the PHY to the MAC.

[0068] Input frame segment timing 602 includes data blocks: a first segment, zero or more intermediate segments, and a final segment. In FIG. 6A, three frame segments are illustrated for descriptive purposes. In other embodiments, input frame segment timing 602 may include any number (zero or greater than zero) intermediate frame segments. Each of the illustrated data blocks of input frame segment timing 602 may be a segment of a single preemptible frame labeled as a P frame, for example, a single preemptible frame has been segmented according to a segmentation protocol (e.g., frame preemption that may be included in TSN). Each of the data blocks of input frame segment timing 602 includes an Ethernet header and respective payload portions (i.e., the beginning of the payload, the middle of the payload, and the end of the payload, respectively). Each of the data blocks also includes an m-packet cyclic redundancy check (mCRC) in addition to the final data block. The final data block includes a frame check sequence (FCS). The first segment of input frame segment timing 602 includes SecTag 606, and the last segment of input frame segment timing 602 includes ICV 608. SecTag 606 and ICV 608 may have been added to the frame segment according to the MACsec protocol implemented at the transmitter.

[0069] The adjusted frame segment timing 604 includes data blocks: a first segment, zero or more intermediate segments, and a final segment. In FIG. 6B, three frame segments are illustrated for descriptive purposes. In other embodiments, the adjusted frame segment timing 604 may include any number (zero or greater than zero) of intermediate frame segments. Each of the data blocks in the adjusted frame segment timing 604 corresponds to a data block in the input frame segment timing 602. In particular, the data block in the adjusted frame segment timing 604 may be a data block in the input frame segment timing 602 after MACsec is performed at the receiver. Performing MACsec at the receiver may include decrypting at least a portion of one or more data blocks (e.g., payload), removing SecTag 606 from the first data block of one or more data blocks, and / or removing ICV 608 from the final data block of one or more data blocks. Additionally, MACsec implementation may include security checks, including frame authentication based on ICV 608. For example, the first segment of the adjusted frame segment timing 604 may be the first segment of the input frame segment timing 602 after decryption and removal of SecTag 606.

[0070] In some embodiments, the PHY may remove SecTag 606 and ICV 608 to implement the MACsec protocol. In some cases, removing SecTag 606 and / or ICV 608 from a data block may result in a data block that is too short. For example, there may be constraints on the length of a frame segment (e.g., a constraint requiring the frame segment to be 64 bytes or longer), and after removing ICV 608, the last frame segment may not meet that constraint.

[0071] According to one or more embodiments, dummy data may be added to one or more frame segments (e.g., at the PHY) to ensure that the frame segment is not too short. For example, at the PHY, dummy SecTag 610 may be added to the first frame segment of the adjusted frame segment timing 604, and dummy ICV 612 may be added to the last segment of the adjusted frame segment timing 604. The size of dummy SecTag 610 may correspond to the size of SecTag 606, and the size of dummy ICV 612 may correspond to the size of ICV 608. As a particular non-limiting embodiment, dummy SecTag 610 may be 16 bytes long, and therefore SecTag 606 may be 16 bytes long. Similarly, dummy ICV 612 may be 16 bytes long, and therefore ICV 608 may be 16 bytes long.

[0072] FIG7A illustrates an example of timing for data blocks (e.g., received at the PHY), which include data associated with higher-level processing connected to a higher-level protocol (e.g., MACsec). FIG7B illustrates an example of timing for corresponding data blocks (e.g., provided to the MAC) according to one or more embodiments. In particular, FIG7A illustrates input frame segment timing 702, which is the timing of a frame segment received at the PHY. FIG7B illustrates adjusted frame segment timing 704 according to one or more embodiments, which is the timing of a corresponding frame segment provided by the PHY to the MAC.

[0073] Input frame segment timing 702 includes data blocks: a first segment, zero or more intermediate segments, and a final segment. In FIG. 7A, three frame segments are illustrated for descriptive purposes. In other embodiments, input frame segment timing 702 may include any number (zero or greater than zero) intermediate frame segments. Each of the illustrated data blocks in input frame segment timing 702 may be a segment of a single preemptible frame, for example, a single preemptible frame has been segmented according to a segmentation protocol (e.g., which may be included in TSN). Each of the data blocks in input frame segment timing 702 includes an Ethernet header and respective payload portions (i.e., the beginning of the payload, the middle of the payload, and the end of the payload, respectively). Each of the data blocks also includes an m-packet cyclic redundancy check (mCRC) in addition to the final data block. The final data block includes a frame check sequence (FCS). The first segment of the input frame segment timing 702 includes SecTag 706, and the last segment of the input frame segment timing 702 includes ICV 708. SecTag 706 and ICV 708 may have been added to the frame segment according to the MACsec protocol implemented at the transmitter.

[0074] The adjusted frame segment timing 704 includes data blocks: a first segment, zero or more intermediate segments, and a final segment. In FIG. 7B, three frame segments are illustrated for descriptive purposes. In other embodiments, the adjusted frame segment timing 704 may include any number (zero or greater than zero) of intermediate frame segments. Each of the data blocks in the adjusted frame segment timing 704 corresponds to a data block in the input frame segment timing 702. In particular, the data block in the adjusted frame segment timing 704 may be a data block in the input frame segment timing 702 after MACsec is performed at the receiver. Performing MACsec at the receiver may include decrypting at least a portion of one or more data blocks (e.g., payload), removing the SecTag from the first data block of one or more data blocks, and / or removing the ICV from the final data block of one or more data blocks. For example, the first segment of the adjusted frame segment timing 704 can be the first segment of the input frame segment timing 702 after decryption and removal of SecTag 706.

[0075] According to one or more embodiments, dummy data may be added to one or more frame segments (e.g., at the PHY) to ensure that the frame segment is not too short. For example, at the PHY, dummy SecTag 710 and dummy ICV 712 may be added to the first frame segment of the adjusted frame segment timing 704. In some embodiments, dummy SecTag 710 may occupy a position in the first frame segment previously occupied by SecTag 706, for example, dummy SecTag 710 may replace SecTag 706 in the first frame segment of the adjusted frame segment timing 704. The size of dummy SecTag 710 may correspond to the size of SecTag 706, and the size of dummy ICV 712 may correspond to the size of ICV 708. As a specific non-limiting embodiment, SecTag 706 may be 16-byte long, and therefore, dummy SecTag 710 may be 16-byte long. Similarly, ICV 708 may be 16-byte long, and therefore, dummy ICV 712 may be 16-byte long.

[0076] Additionally, portions from previous segments can be taken from each frame segment (except the last frame segment) and added to subsequent frame segments. For example, in the case of zero intermediate frame segments, a portion of the first frame segment can be taken from the first frame segment and added to the last frame segment as the previous segment portion 716. As another embodiment, in the case of one or more intermediate frame segments, a portion can be taken from the first frame segment and added to the second frame segment as the previous segment portion 714, a portion can be taken from the second frame segment and added to the third frame segment as the previous segment portion 714, and so on, until a portion is taken from the penultimate frame segment and added to the last frame segment as the previous segment portion 716. The size of this portion can correspond to the size of the ICV 708. As a particular non-limiting embodiment, the ICV 708 can be 16 bytes long, and the sizes of the previous segment portion 714 and the previous segment portion 716 can each be 16 bytes long.

[0077] Adding the previous segment 716 to the last frame segment ensures that the last frame segment is not too short. Adding the dummy ICV 712 and the dummy SecTag 710 to the first frame segment ensures that the first frame segment is not too short. Each of the first to penultimate frame segments has had a portion removed and a portion of equal size added. Therefore, the first to penultimate frame segments can maintain their size.

[0078] Alternatively or concurrently, the preceding segment portions 714 and 716 (and the dummy SecTag 710 and dummy ICV 712) may be added close to or before the respective frames (e.g., close to the header). Some hosts may not be able to remove the ICV from the end of the frame. Alternatively or concurrently, for other hosts, removing the ICV from the end of the frame may be costly (in terms of time or power). By adding the preceding segment portion 716 close to or before the last frame segment, the frame segment timing 704 can be adjusted to ensure that the last frame segment is not too short, without having to add data (to be removed by the host) to the end of the frame (e.g., without having to add the dummy ICV to the end of the last segment).

[0079] Figure 8A illustrates an example of the timing of data blocks (e.g., received at the PHY), which include data associated with higher-level protocols (e.g., MACsec).

[0080] FIG8B illustrates an example of timing for a corresponding data block (e.g., provided to a MAC) according to one or more embodiments. In particular, FIG8A illustrates input frame segment timing 802, which is the timing of a frame segment received at the PHY. FIG8B illustrates an adjusted frame segment timing 804 according to one or more embodiments, which is the timing of a corresponding frame segment provided by the PHY to the MAC.

[0081] Input frame segment timing 802 includes data blocks: a first segment, zero or more intermediate segments, and a final segment. In FIG8A, three frame segments are illustrated for descriptive purposes. In other embodiments, input frame segment timing 802 may include any number (zero or greater than zero) intermediate frame segments. Each of the illustrated data blocks in input frame segment timing 802 may be a segment of a single preemptible frame, for example, a single preemptible frame has been segmented according to a segmentation protocol (e.g., which may be included in a TSN). Each of the data blocks in input frame segment timing 802 includes an Ethernet header and respective payload portions (i.e., the beginning of the payload, the middle of the payload, and the end of the payload, respectively). Each of the data blocks also includes an m-packet cyclic redundancy check (mCRC) in addition to the final data block. The final data block includes a frame check sequence (FCS). The first segment of the frame includes SecTag 806, and the last segment of the frame includes ICV 808. SecTag 806 and ICV 808 may have been added to the frame segments according to the MACsec protocol implemented at the transmitter.

[0082] The adjusted frame segment timing 804 includes data blocks: a first segment, zero or more intermediate segments, and a final segment. In FIG8B, three frame segments are illustrated for descriptive purposes. In other embodiments, the adjusted frame segment timing 804 may include any number (zero or greater than zero) of intermediate frame segments. Each of the data blocks in the adjusted frame segment timing 804 corresponds to a data block in the input frame segment timing 802. In particular, the data block in the adjusted frame segment timing 804 may be a data block in the input frame segment timing 802 after MACsec is performed at the receiver. Performing MACsec at the receiver may include decrypting at least a portion of one or more data blocks (e.g., payload), removing the SecTag from the first data block of one or more data blocks, and / or removing the ICV from the final data block of one or more data blocks. For example, the first segment of the adjusted frame segment timing 804 can be the first segment of the input frame segment timing 802 after decryption and removal of SecTag 806.

[0083] Similar to that described with respect to FIG7A, a portion may be taken from each frame segment (except for the last frame segment) and added to subsequent frame segments as a previous segment portion, for example, previous segment portion 810 and previous segment portion 812. The size of this portion may correspond to the size of ICV 808. As a particular non-limiting embodiment, ICV 808 may be 16-bit long, and the size of previous segment portion 810 and previous segment portion 812 may be 16-bit long.

[0084] Adding the previous segment portion 812 to the final frame segment ensures that the final frame segment is not too short. Each of the second to penultimate frame segments has had a portion removed and an equal-sized portion added. Therefore, the second to penultimate frame segments maintain their size. To ensure that the first frame segment is not too short, another device or network can be configured to segment it to ensure that the first segment is not too short after the SecTag is removed. For example, a transmitter segmenting the frame can be instructed not to send a first segment smaller than a certain size.

[0085] Alternatively or concurrently, the preceding segment portion 810 and preceding segment portion 812 may be added near or before the respective frame (e.g., near the header). Some hosts may not be able to remove the ICV from the end of the frame. Alternatively or concurrently, removing the ICV from the end of the frame may be costly (in terms of time or power) for other hosts. By adding the preceding segment portion 812 near or before the last frame segment, the frame segment timing 804 can be adjusted to ensure that the last frame segment is not too short, without having to add data (to be removed by the host) to the end of the frame (e.g., without having to add the dummy ICV to the end of the last segment).

[0086] FIG9 is a flowchart of an exemplary method 900 according to one or more embodiments. In some embodiments, at least a portion of method 900 may be performed by means of a device or system such as device 102 or device 108 of FIG1, device 202 of FIG2, host 204 of FIG2, MAC client 208 of FIG2, MAC 206 of FIG2, circuit system 1300 of FIG13, or another device or system. Although illustrated as discrete blocks, various blocks may be divided into additional blocks, combined into fewer blocks, or eliminated, depending on the implementation.

[0087] At block 902, a data block can be provided to a physical layer interface device (e.g., a PHY). For example, MAC 206 of FIG2 can send a data block (e.g., an Ethernet frame for transmission) to PHY 216 of FIG2 via MAC-PHY link 232 of FIG2.

[0088] At block 904, dummy data can be added to one or more time-sensitive data blocks being provided to the physical layer interface device. The size of the dummy data may correspond to the size of the higher-level processed data (e.g., SecTag and / or ICV). Adjusted timing 402 of Figure 4A is an example of a data block including dummy data that may have been added, for example, at block 904 (e.g., dummy SecTag 406 and dummy ICV 408 of Figure 4A). Adjusted timing 502 is another example of a data block including dummy data that may have been added, for example, at block 904 (e.g., dummy SecTag 506 of Figure 5A).

[0089] In some embodiments, the higher-level processing data corresponding to the size of the dummy data may be associated with one or more of the following: media access control security, Internet Protocol security, cryptographic compilers, and encapsulation. In some embodiments, the time sensitivity of the data block may be associated with a time-sensitive networking connection or another synchronization or instant protocol. In some embodiments, the data block may be or may include one or more Ethernet frames and / or Ethernet frame fragments.

[0090] In some embodiments, the higher-layer processing data may be or may include security tags and / or integrity detection data. The size of the security tag may be a first number of bytes. The size of the integrity detection data may be a second number of bytes. The size of the dummy data may be the sum of the first number of bytes and the second number of bytes. In some cases, the size of the dummy data may be greater than the sum of the first number of bytes and the second number of bytes.

[0091] FIG10 is a flowchart of another exemplary method 1000 according to one or more embodiments. In some embodiments, at least a portion of method 1000 may be performed by means or systems such as device 102 or device 108 of FIG1, device 202 of FIG2, host 204 of FIG2, MAC client 208 of FIG2, MAC 206 of FIG2, circuit system 1300 of FIG13, or another means or system. Although illustrated as discrete blocks, various blocks may be divided into additional blocks, combined into fewer blocks, or eliminated, depending on the implementation.

[0092] At block 1002, a data block can be provided to a physical layer interface device (e.g., a PHY). For example, MAC 206 of FIG2 can send a data block (e.g., an Ethernet frame for transmission) to PHY 216 of FIG2 via MAC-PHY link 232 of FIG2.

[0093] At block 1004, dummy data can be added to one or more time-sensitive data blocks being provided to the physical layer interface device. The size of the dummy data may correspond to the size of higher-level processed data (e.g., SecTag and / or ICV). Timing 502 is an example of a data block that may include dummy data (e.g., dummy SecTag 506 in FIG. 5A) that may have been added, for example, at block 1004.

[0094] In some embodiments, the higher-level processing data corresponding to the size of the dummy data may be or may include a security tag. For example, the size of the higher-level processing data may be a first number of bytes. The size of the dummy data may be a first number of bytes.

[0095] At block 1006, which may be selected as appropriate, the data block may be output from the physical layer interface device, for example, to a link. For example, a data block provided to the physical layer interface device (e.g., a data block with added dummy data) may be output.

[0096] At block 1008, which may be selected as appropriate, when providing a data block to the physical layer interface device, there may be a delay of a predetermined duration when providing each of one or more time-sensitive data blocks. For example, the data block provider may wait for a predetermined duration before providing each of one or more time-sensitive data blocks. The adjusted timing 502 of Figure 5A is an example of a data frame that includes a delay of a predetermined duration between the provision of each data block (extended IFG 508 of Figure 5A).

[0097] In some embodiments, the size of the integrity detection data may be a first number of bytes. The predetermined duration of block 1008 may correspond to the transmission time associated with the first number of bytes.

[0098] FIG11 is a flowchart of yet another exemplary method 1100 according to one or more embodiments. In some embodiments, at least a portion of method 1100 may be performed by means or systems such as device 102 or device 108 of FIG1, device 202 of FIG2, PHY 216 of FIG2, circuit system 1300 of FIG13, or another means or system. Although illustrated as discrete blocks, various blocks may be divided into additional blocks, combined into fewer blocks, or eliminated, depending on the implementation.

[0099] At block 1102, while receiving a data block, higher-layer processing data can be removed from the first input data block. For example, PHY 216 in Figure 2 can receive a data block from Ethernet connection 234 in Figure 2. While receiving the data block, PHY 216 can remove higher-layer processing data from the first input data block, that is, data associated with the higher-layer protocol. Input frame segment timing 702 in Figure 7A is an example of a data block that can be received at block 1102. In addition, adjusted frame segment timing 704 in Figure 7B is an example of a data block including the first data block after removing SecTag 706 (an example of higher-layer processing data) in Figure 7A at block 1102, which can be provided from PHY 216 in Figure 2 to MAC 206. Similarly, the input frame segment timing 802 of Figure 8A is an example of a data block that can be received at block 1102. Additionally, the adjusted frame segment timing 804 of Figure 8B includes, for example, an example of a data block including a first data block after removing SecTag 806 of Figure 8A (an example of higher-level data processing) at block 1102.

[0100] In some embodiments, the higher-layer processing data removed at block 1102 may be or may include data related to one or more of the following: Media Access Control security, Internet Protocol security, cryptographic compilers, and encapsulation. In some embodiments, the data block received in method 1100 may be time-sensitive. The time sensitivity of the received data block may be related to a time-sensitive network connection. In some embodiments, the data block received in method 1100 may be or may include an Ethernet frame fragment. In some embodiments, the higher-layer processing data removed at block 1102 may be or may include a security tag.

[0101] At block 1104, while receiving a data block, a portion of the first input data block can be removed. Furthermore, at block 1104, this portion can be added to a subsequent input data block. The size of this portion can correspond to the size of the integrity detection data. Adjusted frame segment timing 704 is an example of a data block in which a portion of the first data block has been removed and added to a subsequent data block, namely, the previous segment portion 714 of FIG. 7B. Adjusted frame segment timing 804 is an example of a data block in which a portion of the first data block has been removed and added to a subsequent data block, namely, the previous segment portion 810 of FIG. 8B.

[0102] At block 1106, while receiving a data block, integrity detection data from the input data block can be removed. In some embodiments, the size of the integrity detection data may be a first number of bytes. The size of this portion is a first number of bytes. Adjusted frame segment timing 704 is an example of a data block in which integrity detection data (e.g., ICV 708 of FIG. 7A) has been removed, for example, from the output data block (e.g., from the last data block) at block 1106. Adjusted frame segment timing 804 includes another example of a data block in which integrity detection data (e.g., ICV 808 of FIG. 8A) has been removed, for example, from the input data block (e.g., from the last data block) at block 1106.

[0103] In some cases, such as when there are only two input data blocks, the subsequent data block may be the last data block. In such cases, removing integrity detection data from the input data block (at block 1106) may remove integrity detection data from the subsequent input data block.

[0104] In other cases, such as when there are more than two input data blocks, method 1100 may additionally include removing a corresponding portion from each of the input data blocks and adding the corresponding portion to one of the input data blocks immediately following it or to the input data block itself. Furthermore, at block 1106, integrity detection data may be removed from the last block of the input data blocks.

[0105] FIG12 is a flowchart of yet another exemplary method 1200 according to one or more embodiments. In some embodiments, at least a portion of method 1200 may be performed by means or systems such as device 102 or device 108 of FIG1, device 202 of FIG2, PHY 216 of FIG2, circuit system 1300 of FIG13, or another means or system. Although illustrated as discrete blocks, various blocks may be divided into additional blocks, combined into fewer blocks, or eliminated, depending on the implementation.

[0106] At block 1202, while receiving a data block, higher-layer processing data can be removed from the first input data block. For example, PHY 216 in Figure 2 can receive a data block from Ethernet connection 234 in Figure 2. While receiving the data block, PHY 216 can remove higher-layer processing data from the first input data block. The input frame segment timing 702 in Figure 7A is an example of a data block that can be received at block 1202. In addition, the adjusted frame segment timing 704 in Figure 7B is an example of a data block including the first data block after removing SecTag 706 (an example of higher-layer processing data) in Figure 7A at block 1202.

[0107] At block 1204, which can be selected as appropriate, dummy data can be inserted into the first input data block while receiving the data block. The size of the dummy data can correspond to the size of the higher-level processing data (e.g., SECtag) and the size of the integrity detection data (e.g., ICV). The adjusted frame segment timing 704 of FIG7B is an example of a data block including a first data block with the inserted dummy data blocks (e.g., dummy SecTag 710 and dummy ICV 712 of FIG7B).

[0108] At block 1206, while receiving a data block, a portion of the first input data block can be removed. Furthermore, at block 1206, this portion can be added to a subsequent input data block. The size of this portion can correspond to the size of the integrity detection data. The adjusted frame segment timing 704 is an example of a data block in which a portion of the first data block has been removed and added to a subsequent data block, namely, the previous segment portion 714 of Figure 7B.

[0109] At block 1208, while receiving a data block, integrity detection data from the input data block can be removed. The frame segment timing 704 is an example of a data block in which integrity detection data (e.g., ICV 708 in FIG7A) has been removed, for example, from the output data block (e.g., from the last data block) at block 1208.

[0110] In some cases, such as when there are only two input data blocks, the subsequent data block may be the last data block. In such cases, removing integrity detection data from the input data block (at block 1208) may remove integrity detection data from the subsequent input data block.

[0111] In other cases, such as when there are more than two input data blocks, method 1200 may additionally include removing a corresponding portion from each of the input data blocks and adding the corresponding portion to one of the input data blocks immediately following it or to the input data block itself. Furthermore, at block 1208, integrity detection data may be removed from the last block of the input data blocks.

[0112] Figure 13 is a block diagram of circuit system 1300. In some embodiments, the circuit system can be used to implement various functions, operations, actions, procedures, and / or methods disclosed herein. Circuit system 1300 includes one or more processors 1302 (sometimes referred to herein as "processor 1302") operatively coupled to one or more devices, such as, but not limited to, data storage devices (sometimes referred to herein as "memory 1304"). Memory 1304 includes machine-executable code 1306 stored thereon (e.g., stored on computer-readable memory), and processor 1302 includes logic circuit system 1308. Machine-executable code 1306 includes information describing functional elements that can be implemented (e.g., executed) by logic circuit system 1308. Logic circuit system 1308 implements (e.g., executes) the functional elements described by machine-executable code 1306. When executing the functional elements described by machine executable code 1306, the circuit system 1300 should be considered as dedicated hardware for implementing the functional elements disclosed herein. In some embodiments, the processor 1302 may execute the functional elements described by machine executable code 1306 sequentially, simultaneously (e.g., on one or more different hardware platforms), or in one or more parallel program streams.

[0113] When implemented by the logic circuit system 1308 of the processor 1302, the machine-executable code 1306 adapts the processor 1302 to perform the operations of the embodiments disclosed herein. For example, the machine-executable code 1306 may adapt the processor 1302 to perform at least some or all of the methods 900 of FIG. 9, 1000 of FIG. 10, 1100 of FIG. 11, and 1200 of FIG. 12. As another embodiment, the machine-executable code 1306 may adapt the processor 1302 to perform at least some or all of the operations discussed for the apparatus 102 or 108 of FIG. 1, and more specifically for, but not limited to, one or more of the MAC 104, PHY 106, MAC 110, and / or PHY 112 of FIG. 1. As another embodiment, machine executable code 1306 can adapt processor 1302 to perform at least some or all of the operations described for the device 202 of FIG2 and more specifically for, but not limited to, the host 204, MAC 206, MAC client 208, TSN scheduling module 210, queue module 212, MAC merging sublayer 214, PHY 216, higher layer processing module 218 and / or MACsec module 220 of FIG2.

[0114] Processor 1302 may include a general-purpose processor, a special-purpose processor, a central processing unit (CPU), a microcontroller, a programmable logic controller (PLC), a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic, discrete hardware components, other programmable devices, or any combination thereof designed to perform the functions disclosed herein. A general-purpose computer including a processor is considered a special-purpose computer, and the general-purpose computer executes computational instructions (e.g., software code) related to the embodiments disclosed herein. It should be noted that a general-purpose processor (also referred to herein as a host processor or simply a host) may be a microprocessor, but in alternative embodiments, processor 1302 may include any known processor, controller, microcontroller, or state machine. Processor 1302 may also be implemented as a combination of computing devices, such as a combination of a DSP and a microprocessor, a plurality of microprocessors, a combination of one or more microprocessors with a DSP core, or any other such configuration.

[0115] In some embodiments, the memory 1304 includes volatile data storage (e.g., random access memory (RAM)) and non-volatile data storage (e.g., flash memory, hard disk drive, solid-state drive, erasable programmable read-only memory (EPROM), etc.). In some embodiments, the processor 1302 and the memory 1304 may be implemented in a single device (e.g., a semiconductor device product, a system-on-a-chip (SOC), etc.). In some embodiments, the processor 1302 and the memory 1304 may be implemented in a separate device.

[0116] In some embodiments, the machine-executable code 1306 may include computer-readable instructions (e.g., software code, firmware code). As a non-limiting embodiment, the computer-readable instructions may be stored in storage 1304, directly accessed by processor 1302, and executed by processor 1302 using at least logic circuit system 1308. Also as a non-limiting embodiment, the computer-readable instructions may be stored on storage 1304, transferred to a memory device (not shown) for execution, and executed by processor 1302 using at least logic circuit system 1308. Therefore, in some embodiments, logic circuit system 1308 includes electrically constructible logic circuit system 1308.

[0117] In some embodiments, machine-executable code 1306 may describe hardware (e.g., a circuit system) to be implemented in logic circuit system 1308 to perform functional elements. This hardware may be described at any of a variety of abstraction levels, from low-level transistor layout to high-level description languages. At high abstraction levels, hardware description languages ​​(HDLs) may be used, such as, but not limited to, the Institute of Electrical and Electronics Engineers (IEEE) Standard Hardware Description Language (HDL). As a non-limiting embodiment, VERILOG™, SYSTEMVERILOG™, or VLSI Hardware Description Language (VHDL™) may be used.

[0118] The HDL description can be converted to a description at any of a number of other abstraction levels as needed. As a non-limiting embodiment, a higher-level description can be converted to a logic-level description, such as Register Transfer Language (RTL), Gate Level (GL) description, Placement Level description, or Mask Level description. As a non-limiting embodiment, micro-operations to be performed by the hardware logic circuitry (e.g., but not limited to, gates, flip-flops, registers) of the logic circuitry system 1308 can be described in RTL and subsequently converted to a GL description by a synthesis tool, and the GL description can be converted to a placement-level description corresponding to the physical layout of integrated circuitry of a programmable logic device, discrete gate or transistor logic, discrete hardware components, or combinations thereof by a placement and routing tool. Therefore, in some embodiments, the machine-executable code 1306 may include HDL, RTL, GL descriptions, mask-level descriptions, other hardware descriptions, or any combination thereof.

[0119] In embodiments where the machine executable code 1306 includes a hardware description (at any level of abstraction), the system (not shown, but including memory 1304) may be configured to implement the hardware description described by the machine executable code 1306. As a non-limiting embodiment, the processor 1302 may include programmable logic devices (e.g., an FPGA or a PLC), and the logic circuit system 1308 may be electrically controlled to implement a circuit system corresponding to the hardware description in the logic circuit system 1308. Also as a non-limiting embodiment, the logic circuit system 1308 may include hard-wired logic manufactured by a manufacturing system (not shown, but including memory 1304) according to the hardware description of the machine executable code 1306.

[0120] Regardless of whether the machine executable code 1306 includes computer-readable instructions or hardware description, the logic circuit system 1308 executes the functional elements described by the machine executable code 1306 when implementing the functional elements of the machine executable code 1306. It should be noted that although the hardware description may not directly describe the functional elements, it indirectly describes the functional elements that the hardware elements described by the hardware description can execute.

[0121] As used in this disclosure, the terms "module" or "component" may refer to a specific hardware implementation for performing the actions of a module or component, and / or a software object or software convention that can be stored on and / or executed by the general-purpose hardware of a computing system (e.g., computer-readable media, processing device, etc.). In some embodiments, the different components, modules, engines, and services described in this disclosure may be implemented as objects or programs that execute on a computing system (e.g., as separate threads). Although some of the systems and methods described in this disclosure are generally described as being implemented in software (stored on and / or executed by general-purpose hardware), specific hardware implementations or combinations of software and specific hardware implementations are also possible and covered.

[0122] As used in this disclosure, the term "combination" in relation to a plurality of elements can include a combination of all elements or any of a variety of different sub-combinations of some of those elements. For example, the phrase "A, B, C, D or a combination thereof" can refer to any one of A, B, C or D; a combination of each of A, B, C and D; and any sub-combination of A, B, C or D, such as A, B and C; A, B and D; A, C and D; B, C and D; A and B; A and C; A and D; B and C; B and D; or C and D.

[0123] The terms used in this disclosure and especially in the appended claims (e.g., the subject of the appended claims) are generally intended to be "open" terms (e.g., the term "including" should be interpreted as "including but not limited to", the term "having" should be interpreted as "at least having", the term "includes" should be interpreted as "including but not limited to", etc.).

[0124] Furthermore, if a certain number of introduced claims are intended, this intent will be explicitly stated in the claims, and this intent will not exist without such a statement. For example, to aid understanding, the appended claims may contain the use of the introductory phrases "at least one" and "one or more" to describe the technical solution. However, the use of such phrases should not be construed as implying that the introduction of the indefinite article "a (a or an)" to the claim description limits any particular claim containing such introduced claim description to only one embodiment of that description, even when the same claim includes the introductory phrases "one or more" or "at least one" and indefinite articles such as "a (a or an)" (e.g., "a (a and / or an)" should be interpreted as meaning "at least one" or "one or more"); this also applies to the use of definite articles used to introduce the claim description.

[0125] Furthermore, even if a specific number of the introduced claims are explicitly stated, those skilled in the art will recognize that such statements should generally be interpreted as meaning at least the number stated (e.g., the unmodified statement "two statements" without other modifiers means at least two statements or two or more statements). In addition, when using rules such as "at least one of A, B, and C" or "one or more of A, B, and C," this construction is generally intended to include A alone, B alone, C alone, A and B together, A and C together, B and C together, or A, B, and C together, etc.

[0126] Furthermore, any separate words or phrases presenting two or more alternative terms, whether in this specification, the claims, or the drawings, should be understood to encompass the possibility of including one of such terms, any one of such terms, or both of such terms. For example, the phrase "A or B" should be understood to include the possibility of "A" or "B" or "A and B".

[0127] Additional non-limiting embodiments of this disclosure may include:

[0128] Example 1: An apparatus comprising: circuitry for providing data blocks to a physical layer interface device, the physical layer interface device including logic for performing high-level processing on the received data blocks; and a logic circuitry for: adding dummy data to one or more time-sensitive data blocks in the data blocks, the size of the dummy data corresponding to the size of the high-level processed data; and providing the data blocks including the one or more time-sensitive data blocks to the physical layer interface device.

[0129] Example 2: The device as in Example 1, wherein the high-level processing data is associated with one or more of the following: media access control security, Internet Protocol security, a cryptographic compiler, and an encapsulation.

[0130] Example 3: The device as in either Example 1 or 2, wherein the time sensitivity of the data blocks is related to the time-sensitive network connection.

[0131] Example 4: The device as described in any of Examples 1 to 3, wherein the data blocks include one or more of Ethernet frames and Ethernet frame segments.

[0132] Example 5: The device as described in any of Examples 1 to 4, wherein: the high-layer processing data includes a security tag and integrity detection data; the size of the security tag is a first number of bytes; the size of the integrity detection data is a second number of bytes; and the size of the dummy data is the sum of the first number of bytes and the second number of bytes.

[0133] Example 6: The device of any of Examples 1 to 5 includes: the physical layer interface device includes logic for performing high-level processing on the received data blocks.

[0134] Example 7: A method comprising: providing a data block to a physical layer interface device, the physical layer interface device including logic for performing high-level processing on the received data block; and adding dummy data to one or more time-sensitive data blocks being provided to the physical layer interface device, the size of the dummy data corresponding to the size of the high-level processed data.

[0135] Example 8: The method of Example 7 includes outputting the data blocks at the physical layer interface device.

[0136] Example 9: The method of any of Examples 7 and 8, comprising providing the data blocks to the physical layer interface device while waiting for a predetermined duration to provide each of one or more time-sensitive data blocks.

[0137] Example 10: The method of any one of Examples 7 to 9, wherein: the high-level processing data includes a security tag; the size of the high-level processing data is a first number of bytes; and the size of the dummy data is the first number of bytes.

[0138] Example 11: The method of any of Examples 7 to 10, wherein: one of the integrity detection data is a first number of bytes; and the predetermined duration corresponds to a transmission time related to the first number of bytes.

[0139] Example 12: An apparatus comprising: a physical layer interface means for: receiving a data block; removing high-level processing data from a first input data block; removing a portion of the first input data block and adding the portion to a subsequent input data block, wherein a size of the portion corresponds to a size of integrity detection data; and removing the integrity detection data from an input data block.

[0140] Example 13: The device as in Example 12, wherein the high-level processing data includes data relating to one or more of the following: media access control security, Internet Protocol security, a cryptographic compiler, and an encapsulation.

[0141] Example 14: The device as in any of Examples 12 and 13, wherein the received data blocks are time-sensitive and the time sensitivity of the received data blocks is related to the time-sensitive network connection.

[0142] Example 15: The device of any of Examples 12 to 14, wherein the data blocks include Ethernet frame segments.

[0143] Example 16: The device as described in any of Examples 12 to 15, wherein the high-level processing data includes a security tag.

[0144] Example 17: A device as described in any of Examples 12 to 16, wherein: the size of the integrity detection data is a first number of bytes; and the size of the portion is the first number of bytes.

[0145] Example 18: A method comprising: receiving a data block; removing high-level processing data from a first input data block; removing a portion of the first input data block and adding the portion to a subsequent input data block, wherein a size of the portion corresponds to a size of integrity detection data; and removing the integrity detection data from an input data block.

[0146] Example 19: The method of Example 18, wherein removing the integrity detection data from the input data block includes removing the integrity detection data from the subsequent input data block.

[0147] Example 20: The method of any of Examples 18 and 19 includes: removing a corresponding portion from each of a plurality of input data blocks, and adding a separate corresponding portion to a subsequent input data block of the plurality of input data blocks, wherein one of the corresponding portions corresponds to the size of the integrity detection data.

[0148] Example 21: The method of any of Examples 18 to 20 includes inserting dummy data into the first input data block while receiving the data blocks, wherein one size of the dummy data corresponds to the sum of one size of the higher-level processing data and one size of the integrity detection data.

[0149] Although this disclosure has described certain illustrated embodiments herein, those skilled in the art will recognize and understand that the invention is not limited thereto. In fact, many additions, deletions, and modifications can be made to the illustrated and described embodiments and their legal equivalents without departing from the scope of the invention as claimed below. Furthermore, features from one embodiment may be combined with features from another embodiment while still being covered within the scope of the invention as contemplated by the inventors. [Simplified Explanation of the Diagram]

[0006] Although this disclosure concludes with a patent claim specifically pointing out and explicitly asserting particular embodiments, various features and advantages of embodiments within the scope of this disclosure may be more readily identified from the following description when read in conjunction with the accompanying drawings, in which: FIG1 illustrates an exemplary environment in which one or more embodiments may be operated. FIG2 illustrates an exemplary system in which one or more embodiments may be implemented. FIG3A illustrates an example of the timing of transmitting an exemplary data block at the MAC according to one or more embodiments. FIG3B illustrates an example of the timing of transmitting an exemplary data block at the PHY according to one or more embodiments. FIG4A illustrates another example of the timing of transmitting a data block at the MAC according to one or more embodiments. FIG4B illustrates another example of the timing of transmitting a data block at the PHY according to one or more embodiments. FIG5A illustrates yet another example of the timing of transmitting a data block at the MAC according to one or more embodiments. Figure 5B illustrates another example of the timing for transmitting a data block in preparation for output at the PHY according to one or more embodiments. Figure 6A illustrates an example of the timing for transmitting a data block in a receiving manner at the PHY according to one or more embodiments. Figure 6B illustrates an example of the timing for transmitting a data block in a providing-to-MAC manner according to one or more embodiments. Figure 7A illustrates another example of the timing for transmitting a data block in a receiving manner at the PHY according to one or more embodiments. Figure 7B illustrates another example of the timing for transmitting a data block in a providing-to-MAC manner according to one or more embodiments. Figure 8A illustrates yet another example of the timing for transmitting a data block in a receiving manner at the PHY according to one or more embodiments. Figure 8B illustrates yet another example of the timing for transmitting a data block in a providing-to-MAC manner according to one or more embodiments. Figure 9 is a flowchart of an example method according to one or more embodiments. Figure 10 is a flowchart of another example method according to one or more embodiments. Figure 11 is a flowchart of yet another exemplary method according to one or more embodiments. Figure 12 is a flowchart of yet another exemplary method according to one or more embodiments. Figure 13 is a block diagram of a circuit system according to one or more embodiments that can be used to implement various functions, operations, actions, procedures and / or methods.

Claims

1. An apparatus for handling high-level processing data in time-sensitive data blocks on a physical layer interface device, comprising: circuitry for providing data blocks to a physical layer interface device, the physical layer interface device including logic for performing high-level processing on the received data blocks; and a logic circuitry for: adding dummy data to one or more time-sensitive data blocks, the size of the dummy data corresponding to a size of high-level processing data; and providing the data blocks including the one or more time-sensitive data blocks to the physical layer interface device, wherein... The time sensitivity of one or more time-sensitive data blocks is related to time-sensitive network connectivity.

2. The equipment as requested in item 1, wherein, The high-level data processing relates to one or more of the following: media access control security, Internet protocol security, a cryptographic compiler, and encapsulation.

3. The equipment as requested in item 1, wherein, These data blocks contain one or more of Ethernet frames and Ethernet frame segments.

4. The equipment as requested in item 1, wherein, The high-level processing data includes a security tag and integrity detection data; the size of the security tag is a first number of bytes; the size of the integrity detection data is a second number of bytes; and the size of the dummy data is the sum of the first number of bytes and the second number of bytes.

5. The device as claimed in claim 1, comprising: the entity layer interface device including logic for performing high-level processing on the received data blocks.

6. A method for handling high-level processing data in a time-sensitive data block on a physical layer interface device, comprising: providing a data block to a physical layer interface device, the physical layer interface device including logic for performing high-level processing on the received data block; and adding dummy data to one or more time-sensitive data blocks being provided to the physical layer interface device, wherein a size of the dummy data corresponds to a size of the high-level processing data, wherein... The time sensitivity of one or more time-sensitive data blocks is related to time-sensitive network connectivity.

7. The method of request item 6 includes outputting the data blocks at the physical layer interface device.

8. The method of claim 6, which includes providing the data blocks to the physical layer interface device while waiting for a predetermined duration to provide each of the one or more time-sensitive data blocks.

9. As in request item 8, wherein, The high-level processed data includes a security tag; the size of the high-level processed data is a first number of bytes; and the size of the dummy data is the first number of bytes.

10. As in request item 8, wherein, One of the integrity detection data sizes is a first number of bytes; and the predetermined duration corresponds to a transmission time associated with the first number of bytes.

11. An apparatus for processing high-level processing data in an input data block on a solid layer interface device, comprising: a solid layer interface device for: receiving a data block; removing high-level processing data from a first input data block; removing a portion of the first input data block and adding the portion to a subsequent input data block, wherein a size of the portion corresponds to a size of integrity detection data; and removing the integrity detection data from an input data block.

12. The equipment as requested in item 11, wherein, The high-level processing data includes information relating to one or more of the following: media access control security, Internet protocol security, a cryptographic compiler, and encapsulation.

13. The equipment as requested in item 11, wherein, The received data blocks are time-sensitive, and the time sensitivity of the received data blocks is related to time-sensitive network connectivity.

14. The equipment as requested in item 11, wherein, These data blocks contain Ethernet frame fragments.

15. The equipment as requested in item 11, wherein, The high-level data processing includes a security label.

16. The equipment as requested in item 11, wherein, The size of the integrity detection data is a first number of bytes; and the size of the portion is the first number of bytes.

17. A method for processing high-level processing data in an input data block in a physical layer interface device, comprising: receiving the data block; removing high-level processing data from a first input data block; removing a portion of the first input data block and adding the portion to a subsequent input data block, wherein a size of the portion corresponds to a size of integrity detection data; and removing the integrity detection data from an input data block.

18. As in request item 17, wherein, Removing the integrity detection data from the input data block includes removing the integrity detection data from the subsequent input data block.

19. The method of claim 17, comprising: removing a corresponding portion from each of a plurality of input data blocks, and adding a separate corresponding portion to a subsequent input data block of the plurality of input data blocks, wherein one of the corresponding portions corresponds to the size of the integrity detection data.

20. The method of claim 17, comprising inserting dummy data into the first input data block while receiving the data blocks, wherein one size of the dummy data corresponds to the sum of one size of the higher-level processing data and one size of the integrity detection data.