Managing a secure association key in a connectivity association

The method for managing SAKs in MACsec devices ensures efficient resource usage by confirming all devices have switched to the new SAK before deleting the old SAK, thereby reducing data loss and resource wastage.

WO2025107232A1PCT designated stage expired Publication Date: 2025-05-30TELEFONAKTIEBOLAGET LM ERICSSON (PUBL) +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2023/133601
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-23
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

Existing MACsec devices face inefficiencies in resource management during Secure Association Key (SAK) refreshes, leading to potential data loss and wastage of hardware resources due to the storage of both old and new SAKs.

Method used

A method and device for managing SAKs in a Connectivity Association (CA) network, where a first MACsec device confirms whether all second MACsec devices in the network are using the new SAK and deletes the old SAK only after confirmation, thereby optimizing resource usage.

Benefits of technology

This approach reduces resource consumption and minimizes data loss by ensuring that the old SAK is deleted only when all devices in the network have switched to the new SAK, thus optimizing hardware resource allocation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2023133601_30052025_PF_FP_ABST
    Figure CN2023133601_30052025_PF_FP_ABST
Patent Text Reader

Abstract

A first MACsec device (110; 500; 600; 810; 812), a method (200) performed by the first MACsec device, a computer program (720) and a computer program product (710) for managing an SAK after an SAK refresh in a CA network (100) is provided. Both an old SAK and a new SAK exist in the CA network. The CA network comprises one or more second MACsec devices and the first MACsec device. The first MACsec device receives one or more frames, from the second MACsec devices, wherein the frame comprises an indication indicating that a second MACsec device of the second MACsec devices uses the new SAK or the old SAK, confirms (220) whether all of the second MACsec devices use the new SAK and deletes (230) the old SAK upon confirming that all of the one or more second MACsec devices use the new SAK.
Need to check novelty before this filing date? Find Prior Art

Description

MANAGING A SECURE ASSOCIATION KEY IN A CONNECTIVITY ASSOCIATIONTECHNICAL FIELD

[0001] The disclosure herein relates to a method for managing a Secure Association Key (SAK) , a Media Access Control (MAC) Security (MACsec) device for managing an SAK, a corresponding computer program and computer program product for the MACsec device.BACKGROUND

[0002] Media Access Control (MAC) Security (MACsec) is a network security standard that operates at the Medium Access Control (MAC) layer. MACsec defines connectionless data confidentiality and integrity for media access independent protocols. MACsec is standardized by the Institute of Electrical and Electronics Engineers (IEEE) 802.1 working group and is standardized in IEEE 802.1AE. MACsec provides point-to-point security on Ethernet links between directly-connected nodes and is capable of identifying and preventing most security threats, including denial of service, intrusion, man-in-the-middle, masquerading, passive wiretapping, and playback attacks.

[0003] Secure Association (SA) , as defined in IEEE 802.1AE, is a security relationship that provides security guarantees for frames transmitted from one member of a Connectivity Association (CA) to other members of the CA. Each SA is supported by a single secret key, or a single set of keys where the cryptographic operations used to protect one frame require more than one key. Secure Association Key (SAK) is the secret key used by an SA. A Connectivity Association (CA) is a security relationship, established and maintained by key agreement protocols, that comprises a fully connected subset of the service access points in stations attached to a single Local Area Network (LAN) , wherein the subset of service access points is to be supported by MACsec.

[0004] A pair of SAKs protects a certain amount of traffic for a certain period of time for a MACsec device. The old pair of SAKs is then replaced with a new pair of SAKs for improving the security of the SA after a certain period of time. The pair of SAKs includes an SAK in each direction, i.e., reception and transmission. The SAK for reception is used for decrypting a received MACsec frame and the SAK for transmission is used for encrypting a MACsec frame. The value of the SAK for reception and the value of the SAK for transmission may be the same or may be different. The SAK for reception and the SAK for transmission are stored in different resources in the MACsec device.

[0005] US 2019 / 0386824 A1 discloses a mechanism for providing a failover in a MACsec capable device.SUMMARY

[0006] An object of the invention is to reduce resource consumption in a Connectivity Association (CA) network comprising a Media Access Control (MAC) Security (MACsec) device.

[0007] This and other objects are met by means of different aspects of the invention, as defined by the independent claims.

[0008] According to a first aspect, a method performed by a first MACsec device for managing a Secure Association Key (SAK) after an SAK refresh in a CA network is provided. Both an old SAK and a new SAK exist in the CA network. The CA network comprises one or more second MACsec devices in addition to the first MACsec device. The method comprises receiving one or more frames, from the one or more second MACsec devices respectively, wherein the frame comprises an indication indicating that a second MACsec device of the one or more second MACsec devices uses the new SAK or the old SAK. The method comprises confirming whether all of the one or more second MACsec devices use the new SAK. The method comprises deleting the old SAK upon confirming that all of the one or more second MACsec devices use the new SAK.

[0009] According to a second aspect, a first MACsec device for managing an SAK after an SAK refresh in a CA network is provided. Both an old SAK and a new SAK exist in the CA network. The CA network comprises one or more second MACsec devices in addition to the first MACsec device. The first MACsec device is adapted to receive one or more frames, from the one or more second MACsec devices respectively, wherein the frame comprises an indication indicating that a second MACsec device of the one or more second MACsec devices uses the new SAK or the old SAK. The first MACsec device is adapted to confirm whether all of the one or more second MACsec devices use the new SAK. The first MACsec device is adapted to delete the old SAK upon confirming that all of the one or more second MACsec devices use the new SAK.

[0010] According to a third aspect, a first MACsec device for managing an SAK after an SAK refresh in a CA network is provided. The first MACsec device comprises at least one processing circuitry. The first MACsec device comprises at least one memory. The at least one memory is connected to the at least one processing circuitry. The at least one memory storing program  code that is executed by the at least one processing circuitry to perform the method according to the first aspect.

[0011] According to a fourth aspect, a computer program is provided. The computer program comprises instructions which, when executed by at least one processing circuitry of a first MACsec device causes the first MACsec device to carry out the method according to the first aspect.

[0012] According to a fifth aspect, a computer program product stored on a non-transitory computer readable medium is provided. The computer program product comprises instructions that, when executed by at least one processing circuitry of a first MACsec device, causes the first MACsec device to perform the method according to the first aspect.

[0013] Thus, advantageously, the disclosure herein increases the resource efficiency in a CA network. Hereby, it is possible for free up resources for new SAK entries in the first MACsec device. The disclosure herein advantageously improves resource efficiency in a CA network.BRIEF DESCRIPTION OF THE DRAWINGS

[0014] The above, as well as additional objects, features and advantages of the invention, will be better understood through the following illustrative and non-limiting detailed description of embodiments of the invention, with reference to the appended drawings, in which:

[0015] Fig. 1 illustrates an embodiment of a Connectivity Association (CA) network according to the invention.

[0016] Figs. 2 illustrates an embodiment according to a method of the invention.

[0017] Fig. 3 illustrates a format of a Security TAG (SecTAG) in a Media Access Control (MAC) security (MACsec) frame.

[0018] Fig. 4 illustrates a format of a TAG Control Information field and an Association Number field in a SecTAG of a MACsec frame.

[0019] Fig. 5 shows an embodiment of a network node in according to the invention.

[0020] Fig. 6 shows an embodiment of a User Equipment in according to the invention.

[0021] Fig. 7 illustrates an embodiment of a computer program product according to the invention.

[0022] Fig. 8 illustrates an embodiment of a CA network according to the invention.

[0023] All the figures are schematic, not necessarily to scale, and generally only show parts which are necessary in order to elucidate the invention, wherein other parts may be omitted or merely suggested.DETAILED DESCRIPTION

[0024] The invention will now be described more fully hereinafter with reference to the accompanying drawings, in which certain embodiments of the invention are shown. This invention may, however, be embodied in many different forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided by way of example so that this disclosure will be thorough and complete, and will fully convey the scope of the invention to those skilled in the art.

[0025] Generally, all terms used herein are to be interpreted according to their ordinary meaning in the relevant technical field, unless a different meaning is clearly given and / or is implied from the context in which it is used. All references to a / an / the element, apparatus, component, means, step, etc. are to be interpreted openly as referring to at least one instance of the element, apparatus, component, means, step, etc., unless explicitly stated otherwise. The steps of any methods disclosed herein do not have to be performed in the exact order disclosed, unless a step is explicitly described as following or preceding another step and / or where it is implicit that a step must follow or precede another step. Any feature of any of the embodiments disclosed herein may be applied to any other embodiment, wherever appropriate. Likewise, any advantage of any of the embodiments may apply to any other embodiments, and vice versa. Other objectives, features and advantages of the enclosed embodiments will be apparent from the following description.

[0026] A Media Access Control (MAC) Security (MACsec) device requires a regular refresh of a Secure Association Key (SAK) . Each time an SAK is refreshed, i.e., an old pair of SAK is replaced with a new pair of SAK (hereafter, referred to as an old SAK and a new SAK, respectively) , the MACsec device stores both the new SAK and the old SAK. The old SAK is stored in the MACsec device even though it may not be used again in the future for encryption or decryption of frames. This storing of the old SAK is a waste of hardware resources in the MACsec device.

[0027] Known systems provide deletion of the old SAK at or after a fixed time, such as 3 seconds, but this approach is not optimal. Time-based SAK deletion is not appropriate because it is hard to quantify how long the MACsec device has to wait before deleting / purging an old SAK. Also, a time for deletion of an old SAK is affected by many factors such as network size, network latency and traffic load. These factors may also be changing dynamically in a communication network (e.g. a CA network) , thus the consequences of premature / ill-timed deletion of the old SAK is not appropriate. Premature deletion of the old SAK may lead to data loss, which directly affects key performance indicators of the communication network such as  Quality of Experience (QoE) , Quality of Service (QoS) and Grade of Service (GoS) . The data loss because of premature SAK deletion occurs since the old SAK might still be required to decrypt incoming traffic. In an example, if throughput of a MACsec device is 40 Gb / s, the premature deletion of the old SAK may create a data loss of 40 Gb for each second.

[0028] After SAK refreshing, the new SAK is used by the MACsec device for encryption and / or decryption purposes but the old SAK is stored for at least a period of time. The purpose of the storing the key for the period of time is to prevent data loss during a key refresh, i.e., key switching from the old SAK to the new SAK. Each node in a Connectivity Association (CA) may not be able to switch to a new encryption key (e.g. the new SAK) at the same time. Therefore, the old encryption key (e.g. the old SAK) is still used for encryption in some devices in the CA. Storing the old decryption key (e.g. the old SAK) ensures a smooth service flow and moreover, restricts data loss.

[0029] After switching to the new SAK, the old SAK is not used for encryption purposes nor decryption purposes. That is, after switching to the new SAK, the old SAK can be deleted for encryption or decryption purposes. As mentioned before, time-based SAK deletion is not appropriate because it is hard to quantify how long the MACsec device has to wait before deleting an old SAK. If the old SAK is deleted earlier than required, huge data may occur due to the reason for example that the traffic cannot be decrypted based on the old SAK, which leads to a reduced customer experience (e.g. reduced QoS, reduced QoE, reduced GoS) . If the old SAK is deleted later than required, it leads to a waste of hardware resources which may already be constrained. SAK resources in the MACsec device are often constrained even though throughput of MACsec may be in the order of GB / s. MACsec operations (e.g. encryption, decryption) are thus performed by a hardware chip or a Field Programmable Gate Array (FPGA) which may be capable of handling the throughput of MACsec.

[0030] An example of a hardware chip is Broadcom hardware chip which can only support 1024 SAK entries at a maximum. In a MACsec over Virtual Local Area Network (VLAN) scenario, 4096 SAK entries may be needed. Thus, even though MACsec over VLAN requires a space for 4096 SAK entries, only 1024 SAK entries may be supported by the hardware chip. If SAK resources (e.g. SAK entries such as the new SAK and the old SAK) are managed properly, hardware resource wastage may be minimized.

[0031] The disclosure herein provides a means to reduce hardware resource wastage. The disclosure herein further provides a means to minimize data loss while reducing hardware resource usage.

[0032] Present disclosure provides a first MACsec device for managing an SAK after an SAK refresh in a CA network. Both an old SAK and a new SAK exist in the CA network. The CA network comprises one or more second MACsec devices in addition to the first MACsec device. The first MACsec device adapted to receive one or more frames, from the one or more second MACsec devices respectively. The frame comprises an indication indicating that a second MACsec device of the one or more second MACsec devices uses the new SAK or the old SAK. The first MACsec device adapted to confirm whether all of the one or more second MACsec devices uses the new SAK. The first MACsec device adapted to delete the old SAK upon confirming that all of the one or more second MACsec devices uses the new SAK.

[0033] Fig. 1 illustrates a CA network 100 according to an embodiment of the invention. The CA network includes a single CA. The CA network 100 comprises a first MACsec device 110 and one or more second MACsec devices 120. The CA network comprises a CA. The CA is a security relationship, established and maintained by key agreement protocols, that comprises a fully connected subset of the service access points in stations attached to a single LAN that are to be supported by MACsec. In an example, the one or more second MACsec devices 120 may be a second MACsec device 120a, a second MACsec device 120b and a second MACsec device 120c. The collective term for any other MACsec device, other than the first MACsec device 110, is the second MACsec device 120. Examples of the first MACsec device 110 and / or the second MACsec device 120 have been provided in relation to the description corresponding to Figs. 5 and 6.

[0034] The current SAK refreshing mechanism as defined by Institute of Electrical and Electronics Engineers (IEEE) 802.1AE and IEEE 802.1X is described herein to differentiate the invention from the prior art. In an example, consider that the second MACsec device 120a is a MACsec Key Agreement (MKA) protocol Key server node, and that the first MACsec device 110 and the second MACsec device 120b is an MKA Key client node.

[0035] In an example, the second MACsec device 120a distributed a new SAK to each of the first MACsec device 110 and the second MACsec device 120b. After receiving the new SAK, each of the first MACsec device 110 and the second MACsec device 120b, send a message to all other devices in the CA network 100 (e.g. the first MACsec device 110 sends the message to each of the second MACsec devices 120a, 120b and 120c; the second MACsec device 120b sends the message to each of the first MACsec device 110 and the second MACsec devices 120a and 120c) . The message comprises an indication of a confirmation that the new SAK has been installed in each of the first MACsec device 110 and the second MACsec device 120b. The message is sent as a Distributed SAK parameter set and / or an SAK in USE parameter set  in MACsec Key Agreement Protocol Data Unit (MKPDU) and sent as a control plane message. The second MACsec device 120a (i.e., the MKA Key server node) does not send a confirmation indication like the first MACsec device 110 and the second MACsec device 120b (i.e., MKA Key client nodes which receive the key from the MKA Key server node) . Additionally, each MKA Key client node is aware of which MKA Key client node (s) is / are connected to it. Each MKA Key client node also maintains a record of which SAK is being used by each of the MKA Key client node (s) which is / are connected to it. The MKA key server node comprises functionality of an MKA key server. The MKA key client node comprises functionality of an MKA key client.

[0036] The second MACsec device 120a (i.e., the MKA Key server node) distributes the new SAK in a message corresponding to "Distributed SAK parameter set and SAK in USE parameter set in MKPDU" . The message received by the first MACsec device 110 and the second MACsec device 120b (i.e., MKA Key client nodes) and sent by the first MACsec device 110 and the second MACsec device 120b (i.e., MKA Key client nodes) are different "Distributed SAK parameter set and SAK in USE parameter set in MKPDU" messages. The second MACsec device 120a (i.e., MKA Key server node) receives a confirmation from each of the all the devices in the CA network 100. After receiving the message comprising confirmation of the installation of the new SAK from all other devices in the CA network 100, the second MACsec device 120a (i.e., the MKA Key server node) validates that the new SAK is ready at each of the other devices (e.g. the first MACsec device 110 and the second MACsec device 120b) . After the validation, the second MACsec device 120a (i.e. the MKA Key server node) switches to the new SAK in a sending direction for encryption and retains the old SAK. At this stage, the second MACsec device 120a (i.e., the MKA Key server) may decrypt traffic which has been encrypted by the new SAK and decrypt traffic which has been encrypted by the old SAK simultaneously. Furthermore, each of the other devices (e.g. the first MACsec device 110 and the second MACsec device 120b) in the CA network 100, after receiving a confirmation message about installation of the new SAK in each of the other devices, may also switch to the new SAKs but still retain the old SAKs. While the example herein describes the second MACsec device 120a as the MKA Key server node and the first MACsec device 110 and the second MACsec device 120b as the MKA Key client nodes, the skilled person will understand that these roles are interchangeable in any permutation (e.g. the first MACsec device 110 as the MKA Key server node, the second MACsec devices 120a, 120b as the MKA Key client nodes; the second MACsec device 120b as the MKA Key server node, the first MACsec device 110 and the MACsec device 120c as the MKA Key client nodes; the second  MACsec device 120b as the MKA Key server node, the first MACsec device 110 and the MACsec device 120a as the MKA Key client nodes) .

[0037] A Secure Connection (SC) is a security relationship used to provide security guarantees for frames transmitted from one member (e.g. the first MACsec device 110) of a CA network to the others (e.g. the second MACsec device 120) . An SC is supported by a sequence of Secure Associations (SAs) , thus allowing the periodic use of fresh keys without terminating the relationship.

[0038] Fig. 2 illustrates a method 200 according to an embodiment of the invention. The method 200 is performed by a first MACsec device 110 in a CA network 100 as described in relation to the description corresponding to Fig. 1. The method 200 is performed by the first MACsec device 110 for managing a SAK after an SAK refresh in a CA network. Both an old SAK and a new SAK exist in the CA network. Further, the CA network comprises one or more second MACsec devices 120 (e.g. the second MACsec device 120a, the second MACsec device 120b, the second MACsec device 120c) in addition to the first MACsec device 110.

[0039] The method 200 comprises receiving 210 one or more frames, from the one or more second MACsec devices 120 respectively, wherein a frame of the frames comprises an indication indicating that a second MACsec device (e.g. the second MACsec device 120a) of the one or more second MACsec devices 120 uses the new SAK or the old SAK. In an example, the frame is a MACsec frame.

[0040] The method 200 comprises confirming 220 whether all (e.g. the second MACsec device 120a, the second MACsec device 120b, the second MACsec device 120c) of the one or more second MACsec devices 120 uses the new SAK. The confirming 220 operation is performed by the indication received in the frame from each of the one or more second MACsec devices 120. The operation of confirming 220 corresponds to identifying or checking whether all (e.g. the second MACsec device 120a, the second MACsec device 120b, the second MACsec device 120c) of the one or more second MACsec devices 120 use the new SAK.

[0041] The method 200 comprises deleting 230 the old SAK upon confirming that all (e.g. the second MACsec device 120a and the second MACsec device 120b, the second MACsec device 120c) of the one or more second MACsec devices 120 use the new SAK. The deletion 230 is performed based on the confirmation 220. The deletion of the old SAK taking place in the first MACsec device 110. The operation of deleting 230 corresponds to purging or removing the old SAK upon receiving a confirmation of usage of the new SAK in the received frame from each of the one or more second MACsec devices 120.

[0042] In some embodiments, the indication comprises a Security Channel Identifier (SCI) and an Association Number (AN) . The SCI indicates an identity of a second MACsec device (e.g. the second MACsec device 120a) of the one or more second MACsec devices 120. The AN indicates whether the second MACsec device (e.g. the second MACsec device 120a) uses the new SAK or the old SAK. In some embodiments, the received frame indicates that an End Station (ES) bit is set to 0 and a Secure Channel (SC) bit is set to 1 in a header of the received frame. In some embodiments, the indication (e.g. the AN field and the SCI field) is included in a MAC Security TAG (SecTAG) of the received frame. Reference is drawn to Figs. 3 and 4 to understand the SecTAG and to define the positions of the SCI field and the AN field in the SecTAG. Additionally, an SCI is unique for each node (e.g. the first MACsec device 110, the second MACsec device 120a) in the CA network 100. Further, an AN is different for each SAK in the CA network 100. Thus, by parsing a combination of the two fields (the SCI and the AN) , it may be possible to decipher which SAK is being used by the one or more second MACsec devices 120 (e.g., the old SAK; or the new SAK) .

[0043] In some embodiments, the indication comprises a source MAC address and an Association Number (AN) . The AN indicates whether a second MACsec device (e.g. the second MACsec device 120a) of the one or more second MACsec devices 120 uses the new SAK or the old SAK. The source MAC address indicates an identity of the second MACsec device (e.g. the second MACsec device 120a) . In some embodiments, the received frame indicates that an ES bit is set to 1 and an SC bit is set to 0 in a header of the received frame. In some embodiments, the AN is included in a MAC SecTAG of the received frame. The source MAC address is a Source Address of the received frame. Reference is drawn to Figs. 3 and 4 to show an embodiment of the SecTAG and the position of the AN field in the SecTAG. Additionally, a source MAC address is unique for each node (e.g. the first MACsec device 110, the second MACsec device 120a) in the CA network 100. Further, an AN is different for each SAK in the CA network 100. Thus, by parsing a combination of the two fields (the source MAC address and the AN) , it may be possible to decipher which SAK (e.g., the old SAK; or the new SAK) is being used by which of the one or more second MACsec devices 120.

[0044] Fig. 3 illustrates an embodiment of a format of MAC SecTAG in a MACsec frame. The MAC SecTAG is 12 octets long (i.e., 12*8 bits = 96 bits) . The MAC SecTAG includes i) a MACsec EtherType field as defined in section 9.4 of IEEE 802.1AE, ii) a TAG Control Information (TCI) field as defined in section 9.5 of IEEE 802.1AE, iii) an AN field as defined in section 9.6 of IEEE 802.1AE and as described in relation to Fig. 2, iv) a Short Length (SL) field as defined in section 9.7 of IEEE 802.1AE, v) a Packet Number (PN) field as defined in  section 9.8 of IEEE 802.1AE and vi) an optionally encoded SCI field as defined in section 9.9 of IEEE 802.1AE and as described in relation to Figs. 2.

[0045] Fig. 4 illustrates a format the TCI field and the AN field as described in relation to Figs. 2 and 3.

[0046] The TCI field and the AN field together are defined in 1 octet of the MAC SecTAG. The TCI field comprises bits 8 through 3 of octet 3 (Section 9.5 of IEEE 802.1AE) of the SecTAG. The AN field is encoded as an integer in bits 1 and 2 of octet 3 of the SecTAG (Section 9.5 of IEEE 802.1AE) and the AN field identifies up to four different SAs within the context of an SC.

[0047] If an SCI field (sections 9.9 and 7.1.2 of IEEE 802.1AE) is explicitly encoded in the MAC SecTAG, bit 6 (the SC bit) of the TCI shall be set. The SC bit shall be clear if an SCI is not present in the SecTAG.

[0048] If the SC bit in the TCI is set, the SCI (sections 7.1.2 and 8.2.1 of IEEE 802.1AE) is encoded in octets 9 through 16 of the SecTAG. Furthermore, the SCI facilitates identification of the SA where the CA network comprises three or more SCs and the SCI facilitates Network management identification of the MAC Security Entity (SecY) that has transmitted the frame. A SecY may be the first MACsec device 110 and / or the one or more second MACsec devices 120. Octets 9 through 14 of the SecTAG encode the System Identifier component of the SCI. Octets 9 through 14 comprise the six octets of a MAC address uniquely associated with a transmitting SecY such as the one or more second MACsec devices 120a, 120b and 120c. The octet values 9 through 14 and their sequence conform to the Canonical Format specified by IEEE Standard 802. Octets 15 and 16 of the SecTAG encode the Port Identifier component of the SCI, as an integer.

[0049] Fig. 5 shows a network node 500 in accordance with some embodiments. As used herein, network node refers to equipment capable, configured, arranged and / or operable to communicate directly or indirectly with a UE and / or with other network nodes or equipment, in a telecommunication network. Examples of network nodes include, but are not limited to, routers, access points (APs) (e.g., radio access points) , base stations (BSs) (e.g., radio base stations, Node Bs, evolved Node Bs (eNBs) and NR NodeBs (gNBs) ) , RAN nodes, O-RAN nodes or components of an O-RAN node (e.g., O-RU, O-DU, O-CU) or any future new generation (including 6G) related network node. In an example, the network node 500 comprises the first MACsec device 110 and / or the one or more second MACsec devices 120. The network node 500 is configured to perform the operations according to any of the methods  disclosed herein in relation to the first MACsec device 110, including the method shown in Fig. 2.

[0050] Base stations may be categorized based on the amount of coverage they provide (or, stated differently, their transmit power level) and so, depending on the provided amount of coverage, may be referred to as femto base stations, pico base stations, micro base stations, or macro base stations. A base station may be a relay node or a relay donor node controlling a relay. A network node may also include one or more (or all) parts of a distributed radio base station such as centralized digital units, distributed units (e.g., in an O-RAN access node) and / or remote radio units (RRUs) , sometimes referred to as Remote Radio Heads (RRHs) . Such remote radio units may or may not be integrated with an antenna as an antenna integrated radio. Parts of a distributed radio base station may also be referred to as nodes in a distributed antenna system (DAS) .

[0051] Other examples of network nodes include multiple transmission point (multi-TRP) 5G access nodes, multi-standard radio (MSR) equipment such as MSR BSs, network controllers such as radio network controllers (RNCs) or base station controllers (BSCs) , base transceiver stations (BTSs) , transmission points, transmission nodes, multi-cell / multicast coordination entities (MCEs) , Operation and Maintenance (O&M) nodes, Operations Support System (OSS) nodes, Self-Organizing Network (SON) nodes, positioning nodes (e.g., Evolved Serving Mobile Location Centers (E-SMLCs) ) , and / or Minimization of Drive Tests (MDTs) .

[0052] The network node 500 includes a processing circuitry 502, a memory 504, a communication interface 506, and a power source 508. The network node 500 may be composed of multiple physically separate components (e.g., a NodeB component and a RNC component, or a BTS component and a BSC component, etc. ) , which may each have their own respective components. In certain scenarios in which the network node 500 comprises multiple separate components (e.g., BTS and BSC components) , one or more of the separate components may be shared among several network nodes. For example, a single RNC may control multiple NodeBs. In such a scenario, each unique NodeB and RNC pair, may in some instances be considered a single separate network node. In some embodiments, the network node 500 may be configured to support multiple radio access technologies (RATs) . In such embodiments, some components may be duplicated (e.g., separate memory 504 for different RATs) and some components may be reused (e.g., a same antenna 510 may be shared by different RATs) . The network node 500 may also include multiple sets of the various illustrated components for different wireless technologies integrated into network node 500, for example GSM, WCDMA, LTE, NR, WiFi, Zigbee, Z-wave, LoRaWAN, Radio Frequency  Identification (RFID) or Bluetooth wireless technologies. These wireless technologies may be integrated into the same or different chip or set of chips and other components within network node 500.

[0053] The processing circuitry 502 may comprise a combination of one or more of a microprocessor, controller, microcontroller, central processing unit, digital signal processor, application-specific integrated circuit, field programmable gate array, or any other suitable computing device, resource, or combination of hardware, software and / or encoded logic operable to provide, either alone or in conjunction with other network node 500 components, such as the memory 504, to provide network node 500 functionality.

[0054] In some embodiments, the processing circuitry 502 includes a system on a chip (SOC) . In some embodiments, the processing circuitry 502 includes one or more of radio frequency (RF) transceiver circuitry 512 and baseband processing circuitry 514. In some embodiments, the radio frequency (RF) transceiver circuitry 512 and the baseband processing circuitry 514 may be on separate chips (or sets of chips) , boards, or units, such as radio units and digital units. In alternative embodiments, part or all of RF transceiver circuitry 512 and baseband processing circuitry 514 may be on the same chip or set of chips, boards, or units.

[0055] The memory 504 may comprise any form of volatile or non-volatile computer-readable memory including, without limitation, persistent storage, solid-state memory, remotely mounted memory, magnetic media, optical media, random access memory (RAM) , read-only memory (ROM) , mass storage media (for example, a hard disk) , removable storage media (for example, a flash drive, a Compact Disk (CD) or a Digital Video Disk (DVD) ) , and / or any other volatile or non-volatile, non-transitory device-readable and / or computer-executable memory devices that store information, data, and / or instructions that may be used by the processing circuitry 502. The memory 504 may store any suitable instructions, data, or information, including a computer program, software, an application including one or more of logic, rules, code, tables, and / or other instructions capable of being executed by the processing circuitry 502 and utilized by the network node 500. The memory 504 may be used to store any calculations made by the processing circuitry 502 and / or any data received via the communication interface 506. In some embodiments, the processing circuitry 502 and memory 504 is integrated.

[0056] The communication interface 506 is used in wired or wireless communication of signaling and / or data between a network node, access network, and / or UE. As illustrated, the communication interface 506 comprises port (s)  / terminal (s) 516 to transmit and receive data, for example to and from a network over a wired connection. The communication interface 506  also includes radio front-end circuitry 518 that may be coupled to, or in certain embodiments a part of, the antenna 510. Radio front-end circuitry 518 comprises filters 520 and amplifiers 522. The radio front-end circuitry 518 may be connected to an antenna 510 and processing circuitry 502. The radio front-end circuitry may be configured to condition signals communicated between antenna 510 and processing circuitry 502. The radio front-end circuitry 518 may receive digital data that is to be sent out to other network nodes or UEs via a wireless connection. The radio front-end circuitry 518 may convert the digital data into a radio signal having the appropriate channel and bandwidth parameters using a combination of filters 520 and / or amplifiers 522. The radio signal may then be transmitted via the antenna 510. Similarly, when receiving data, the antenna 510 may collect radio signals which are then converted into digital data by the radio front-end circuitry 518. The digital data may be passed to the processing circuitry 502. In other embodiments, the communication interface may comprise different components and / or different combinations of components.

[0057] In certain alternative embodiments, the network node 500 does not include separate radio front-end circuitry 518, instead, the processing circuitry 502 includes radio front-end circuitry and is connected to the antenna 510. Similarly, in some embodiments, all or some of the RF transceiver circuitry 512 is part of the communication interface 506. In still other embodiments, the communication interface 506 includes one or more ports or terminals 516, the radio front-end circuitry 518, and the RF transceiver circuitry 512, as part of a radio unit (not shown) , and the communication interface 506 communicates with the baseband processing circuitry 514, which is part of a digital unit (not shown) .

[0058] The antenna 510 may include one or more antennas, or antenna arrays, configured to transmit and / or receive wireless signals. The antenna 510 may be coupled to the radio front-end circuitry 518 and may be any type of antenna capable of transmitting and receiving data and / or signals wirelessly. In certain embodiments, the antenna 510 is separate from the network node 500 and connectable to the network node 500 through an interface or port.

[0059] The antenna 510, communication interface 506, and / or the processing circuitry 502 may be configured to perform any receiving operations and / or certain obtaining operations described herein as being performed by the network node. Any information, data and / or signals may be received from a UE, another network node and / or any other network equipment. Similarly, the antenna 510, the communication interface 506, and / or the processing circuitry 502 may be configured to perform any transmitting operations described herein as being performed by the network node. Any information, data and / or signals may be transmitted to a UE, another network node and / or any other network equipment.

[0060] The power source 508 provides power to the various components of network node 500 in a form suitable for the respective components (e.g., at a voltage and current level needed for each respective component) . The power source 508 may further comprise, or be coupled to, power management circuitry to supply the components of the network node 500 with power for performing the functionality described herein. For example, the network node 500 may be connectable to an external power source (e.g., the power grid, an electricity outlet) via an input circuitry or interface such as an electrical cable, whereby the external power source supplies power to power circuitry of the power source 508. As a further example, the power source 508 may comprise a source of power in the form of a battery or battery pack which is connected to, or integrated in, power circuitry. The battery may provide backup power should the external power source fail.

[0061] Embodiments of the network node 500 may include additional components beyond those shown in Fig. 5 for providing certain aspects of the network node’s functionality, including any of the functionality described herein and / or any functionality necessary to support the subject matter described herein. For example, the network node 500 may include user interface equipment to allow input of information into the network node 500 and to allow output of information from the network node 500. This may allow a user to perform diagnostic, maintenance, repair, and other administrative functions for the network node 500.

[0062] Fig. 6 shows a UE 600 in accordance with some embodiments. As used herein, a UE refers to a device capable, configured, arranged and / or operable to communicate wirelessly with network nodes and / or other UEs. Examples of a UE include, but are not limited to, a smart phone, mobile phone, cell phone, voice over IP (VoIP) phone, wireless local loop phone, desktop computer, personal digital assistant (PDA) , wireless cameras, gaming console or device, music storage device, playback appliance, wearable terminal device, wireless endpoint, mobile station, tablet, laptop, laptop-embedded equipment (LEE) , laptop-mounted equipment (LME) , smart device, wireless customer-premise equipment (CPE) , vehicle, vehicle-mounted or vehicle embedded / integrated wireless device, etc. Other examples include any UE identified by the 3rd Generation Partnership Project (3GPP) , including a narrow band IoT (NB-IoT) UE, a machine type communication (MTC) UE, and / or an enhanced MTC (eMTC) UE. In an example, the UE 600 comprises the first MACsec device 110 and / or the one or more second MACsec devices 120. The UE 600 is configured to perform the operations according to any of the methods disclosed herein in relation to the first MACsec device 110, including the method shown in Fig. 2.

[0063] A UE may support device-to-device (D2D) communication, for example by implementing a 3GPP standard for sidelink communication, Dedicated Short-Range Communication (DSRC) , vehicle-to-vehicle (V2V) , vehicle-to-infrastructure (V2I) , or vehicle-to-everything (V2X) . In other examples, a UE may not necessarily have a user in the sense of a human user who owns and / or operates the relevant device. Instead, a UE may represent a device that is intended for sale to, or operation by, a human user but which may not, or which may not initially, be associated with a specific human user (e.g., a smart sprinkler controller) . Alternatively, a UE may represent a device that is not intended for sale to, or operation by, an end user but which may be associated with or operated for the benefit of a user (e.g., a smart power meter) .

[0064] The UE 600 includes processing circuitry 602 that is operatively coupled via a bus 604 to an input / output interface 606, a power source 608, a memory 610, a communication interface 612, and / or any other component, or any combination thereof. Certain UEs may utilize all or a subset of the components shown in Fig. 6. The level of integration between the components may vary from one UE to another UE. Further, certain UEs may contain multiple instances of a component, such as multiple processors, memories, transceivers, transmitters, receivers, etc.

[0065] The processing circuitry 602 is configured to process instructions and data and may be configured to implement any sequential state machine operative to execute instructions stored as machine-readable computer programs in the memory 610. The processing circuitry 602 may be implemented as one or more hardware-implemented state machines (e.g., in discrete logic, field-programmable gate arrays (FPGAs) , application specific integrated circuits (ASICs) , etc. ) ; programmable logic together with appropriate firmware; one or more stored computer programs, general-purpose processors, such as a microprocessor or digital signal processor (DSP) , together with appropriate software; or any combination of the above. For example, the processing circuitry 602 may include multiple central processing units (CPUs) .

[0066] In the example, the input / output interface 606 may be configured to provide an interface or interfaces to an input device, output device, or one or more input and / or output devices. Examples of an output device include a speaker, a sound card, a video card, a display, a monitor, a printer, an actuator, an emitter, a smartcard, another output device, or any combination thereof. An input device may allow a user to capture information into the UE 600. Examples of an input device include a touch-sensitive or presence-sensitive display, a camera (e.g., a digital camera, a digital video camera, a web camera, etc. ) , a microphone, a sensor, a mouse, a trackball, a directional pad, a trackpad, a scroll wheel, a smartcard, and the like. The presence-sensitive display may include a capacitive or resistive touch sensor to sense input from a user. A sensor  may be, for instance, an accelerometer, a gyroscope, a tilt sensor, a force sensor, a magnetometer, an optical sensor, a proximity sensor, a biometric sensor, etc., or any combination thereof. An output device may use the same type of interface port as an input device. For example, a Universal Serial Bus (USB) port may be used to provide an input device and an output device.

[0067] In some embodiments, the power source 608 is structured as a battery or battery pack. Other types of power sources, such as an external power source (e.g., an electricity outlet) , photovoltaic device, or power cell, may be used. The power source 608 may further include power circuitry for delivering power from the power source 608 itself, and / or an external power source, to the various parts of the UE 600 via input circuitry or an interface such as an electrical power cable. Delivering power may be, for example, for charging of the power source 608. Power circuitry may perform any formatting, converting, or other modification to the power from the power source 608 to make the power suitable for the respective components of the UE 600 to which power is supplied.

[0068] The memory 610 may be or be configured to include memory such as random access memory (RAM) , read-only memory (ROM) , programmable read-only memory (PROM) , erasable programmable read-only memory (EPROM) , electrically erasable programmable read-only memory (EEPROM) , magnetic disks, optical disks, hard disks, removable cartridges, flash drives, and so forth. In one example, the memory 610 includes one or more application programs 614, such as an operating system, web browser application, a widget, gadget engine, or other application, and corresponding data 616. The memory 610 may store, for use by the UE 600, any of a variety of various operating systems or combinations of operating systems.

[0069] The memory 610 may be configured to include a number of physical drive units, such as redundant array of independent disks (RAID) , flash memory, USB flash drive, external hard disk drive, thumb drive, pen drive, key drive, high-density digital versatile disc (HD-DVD) optical disc drive, internal hard disk drive, Blu-Ray optical disc drive, holographic digital data storage (HDDS) optical disc drive, external mini-dual in-line memory module (DIMM) , synchronous dynamic random access memory (SDRAM) , external micro-DIMM SDRAM, smartcard memory such as tamper resistant module in the form of a universal integrated circuit card (UICC) including one or more subscriber identity modules (SIMs) , such as a USIM and / or ISIM, other memory, or any combination thereof. The UICC may for example be an embedded UICC (eUICC) , integrated UICC (iUICC) or a removable UICC commonly known as ‘SIM card. ’ The memory 610 may allow the UE 600 to access instructions, application programs and the like, stored on transitory or non-transitory memory media, to off-load data, or to upload  data. An article of manufacture, such as one utilizing a communication system may be tangibly embodied as or in the memory 610, which may be or comprise a device-readable storage medium.

[0070] The processing circuitry 602 may be configured to communicate with an access network or other network using the communication interface 612. The communication interface 612 may comprise one or more communication subsystems and may include or be communicatively coupled to an antenna 622. The communication interface 612 may include one or more transceivers used to communicate, such as by communicating with one or more remote transceivers of another device capable of wireless communication (e.g., another UE or a network node in an access network) . Each transceiver may include a transmitter 618 and / or a receiver 620 appropriate to provide network communications (e.g., optical, electrical, frequency allocations, and so forth) . Moreover, the transmitter 618 and receiver 620 may be coupled to one or more antennas (e.g., antenna 622) and may share circuit components, software or firmware, or alternatively be implemented separately.

[0071] In the illustrated embodiment, communication functions of the communication interface 612 may include cellular communication, Wi-Fi communication, LPWAN communication, data communication, voice communication, multimedia communication, short-range communications such as Bluetooth, near-field communication, location-based communication such as the use of the global positioning system (GPS) to determine a location, another like communication function, or any combination thereof. Communications may be implemented in according to one or more communication protocols and / or standards, such as IEEE 802.11, Code Division Multiplexing Access (CDMA) , Wideband Code Division Multiple Access (WCDMA) , GSM, LTE, New Radio (NR) , 6G, UMTS, WiMax, Ethernet, transmission control protocol / internet protocol (TCP / IP) , synchronous optical networking (SONET) , Asynchronous Transfer Mode (ATM) , QUIC, Hypertext Transfer Protocol (HTTP) , and so forth.

[0072] Regardless of the type of sensor, a UE may provide an output of data captured by its sensors, through its communication interface 612, via a wireless connection to a network node. Data captured by sensors of a UE can be communicated through a wireless connection to a network node via another UE. The output may be periodic (e.g., once every 15 minutes if it reports the sensed temperature) , random (e.g., to even out the load from reporting from several sensors) , in response to a triggering event (e.g., when moisture is detected an alert is sent) , in response to a request (e.g., a user initiated request) , or a continuous stream (e.g., a live video feed of a patient) .

[0073] As another example, a UE comprises an actuator, a motor, or a switch, related to a communication interface configured to receive wireless input from a network node via a wireless connection. In response to the received wireless input the states of the actuator, the motor, or the switch may change. For example, the UE may comprise a motor that adjusts the control surfaces or rotors of a drone in flight according to the received input or to a robotic arm performing a medical procedure according to the received input.

[0074] A UE, when in the form of an IoT device, may be a device for use in one or more application domains, these domains comprising, but not limited to, city wearable technology, extended industrial application and healthcare. Non-limiting examples of such an IoT device are a device which is or which is embedded in: a connected refrigerator or freezer, a TV, a connected lighting device, an electricity meter, a robot vacuum cleaner, a voice controlled smart speaker, a home security camera, a motion detector, a thermostat, a smoke detector, a door / window sensor, a flood / moisture sensor, an electrical door lock, a connected doorbell, an air conditioning system like a heat pump, an autonomous vehicle, a surveillance system, a weather monitoring device, a vehicle parking monitoring device, an electric vehicle charging station, a smart watch, a fitness tracker, a head-mounted display for Augmented Reality (AR) or Virtual Reality (VR) , a wearable for tactile augmentation or sensory enhancement, a water sprinkler, an animal-or item-tracking device, a sensor for monitoring a plant or animal, an industrial robot, an Unmanned Aerial Vehicle (UAV) , and any kind of medical device, like a heart rate monitor or a remote controlled surgical robot, and any other 6G devices. A UE in the form of an IoT device comprises circuitry and / or software in dependence of the intended application of the IoT device in addition to other components as described in relation to the UE 600 shown in Fig. 6.

[0075] As yet another specific example, in an IoT scenario, a UE may represent a machine or other device that performs monitoring and / or measurements, and transmits the results of such monitoring and / or measurements to another UE and / or a network node. The UE may in this case be an M2M device, which may in a 3GPP context be referred to as an MTC device. As one particular example, the UE may implement the 3GPP NB-IoT standard. In other scenarios, a UE may represent a vehicle, such as a car, a bus, a truck, a ship and an airplane, or other equipment that is capable of monitoring and / or reporting on its operational status or other functions associated with its operation.

[0076] In practice, any number of UEs may be used together with respect to a single use case. For example, a first UE might be or be integrated in a drone and provide the drone’s speed information (obtained through a speed sensor) to a second UE that is a remote controller  operating the drone. When the user makes changes from the remote controller, the first UE may adjust the throttle on the drone (e.g. by controlling an actuator) to increase or decrease the drone’s speed. The first and / or the second UE can also include more than one of the functionalities described above. For example, a UE might comprise the sensor and the actuator, and handle communication of data for both the speed sensor and the actuators.

[0077] Although the computing devices described herein (e.g., UEs, network nodes, hosts) may include the illustrated combination of hardware components, other embodiments may comprise computing devices with different combinations of components. It is to be understood that these computing devices may comprise any suitable combination of hardware and / or software needed to perform the tasks, features, functions and methods disclosed herein. Determining, calculating, obtaining or similar operations described herein may be performed by processing circuitry, which may process information by, for example, converting the obtained information into other information, comparing the obtained information or converted information to information stored in the network node, and / or performing one or more operations based on the obtained information or converted information, and as a result of said processing making a determination. Moreover, while components are depicted as single boxes located within a larger box, or nested within multiple boxes, in practice, computing devices may comprise multiple different physical components that make up a single illustrated component, and functionality may be partitioned between separate components. For example, a communication interface may be configured to include any of the components described herein, and / or the functionality of the components may be partitioned between the processing circuitry and the communication interface. In another example, non-computationally intensive functions of any of such components may be implemented in software or firmware and computationally intensive functions may be implemented in hardware.

[0078] In certain embodiments, some or all of the functionality described herein may be provided by processing circuitry executing instructions stored on in memory, which in certain embodiments may be a computer program product in the form of a non-transitory computer-readable storage medium. In alternative embodiments, some or all of the functionality may be provided by the processing circuitry without executing instructions stored on a separate or discrete device-readable storage medium, such as in a hard-wired manner. In any of those particular embodiments, whether executing instructions stored on a non-transitory computer-readable storage medium or not, the processing circuitry can be configured to perform the described functionality. The benefits provided by such functionality are not limited to the  processing circuitry alone or to other components of the computing device, but are enjoyed by the computing device as a whole, and / or by end users and a wireless network generally.

[0079] Fig. 7 illustrates an embodiment of a computer program product 710 according to the invention. The computer program product 710 of the first MACsec device 110 and / or the one or more second MACsec devices 120 includes a computer readable storage medium (storage or recording medium) storing a computer program 720 comprising computer readable instructions. The computer readable medium of the first MACsec device 110 and / or the one or more second MACsec devices 120, may be a non-transitory computer readable medium, such as, magnetic media (e.g., a hard disk) , optical media, memory devices (e.g., random access memory, flash memory) , and the like. In some embodiments, the computer readable instructions of the computer program 720 are configured such that when executed by processing circuitry 502 and / or the processing circuitry 602, the computer readable instructions cause the first MACsec device 110 and / or the one or more second MACsec devices 120 to perform steps described herein (e.g., method 200) . In other embodiments, the first MACsec device 110 and / or the one or more second MACsec devices 120 may be configured / operable to perform steps described herein without the need for code. That is, for example, the processing circuity 502 and / or the processing circuitry 602 may consist merely of one or more ASICs. Hence, the features of the embodiments described herein may be implemented in hardware and / or software.

[0080] The computer program code mentioned above may also be provided, for instance in the form of a data carrier carrying computer program code for performing the embodiments herein when being loaded into the hardware. One such carrier may be in the form of a CD ROM disc. It is however feasible with other data carriers such as a memory stick. The computer program code may furthermore be provided as pure program code on the first MACsec device 110 and / or the one or more second MACsec devices 120, and downloaded to the hardware at production, and / or during software updates.

[0081] Fig. 8 shows an example of the CA network 100 in accordance with some embodiments.

[0082] In the example, the CA network 100 includes a telecommunication network 802 that includes an access network 804, such as a radio access network (RAN) , and a core network 806, which includes one or more core network nodes 808. The access network 804 includes one or more access network nodes, such as network nodes 810a and 810b (one or more of which may be generally referred to as network nodes 810) , or any other similar 3rd Generation Partnership Project (3GPP) access nodes or non-3GPP access points. Moreover, as will be appreciated by those of skill in the art, a network node is not necessarily limited to an  implementation in which a radio portion and a baseband portion are supplied and integrated by a single vendor. Thus, it will be understood that network nodes include disaggregated implementations or portions thereof. For example, in some embodiments, the telecommunication network 802 includes one or more Open-RAN (ORAN) network nodes. An ORAN network node is a node in the telecommunication network 802 that supports an ORAN specification (e.g., a specification published by the O-RAN Alliance, or any similar organization) and may operate alone or together with other nodes to implement one or more functionalities of any node in the telecommunication network 802, including one or more network nodes 810 and / or core network nodes 808. The network nodes 810 facilitate direct or indirect connection of user equipment (UE) , such as by connecting UEs 812a, 812b, 812c, and 812d (one or more of which may be generally referred to as UEs 812) to the core network 806 over one or more wireless connections. The CA network 100 may comprise the CA network 100. In some embodiments, the UEs 812 may comprise the first MACsec device 110 and / or the one or more second MACsec devices 120. In some embodiments, the network nodes 810 may comprise the first MACsec device 110 and / or the one or more second MACsec devices 120. In some embodiments, the first MACsec device 110 and / or the one or more second MACsec devices are separated from the UE 812 or the network nodes 810.

[0083] Examples of an ORAN network node include an open radio unit (O-RU) , an open distributed unit (O-DU) , an open central unit (O-CU) , including an O-CU control plane (O-CU-CP) or an O-CU user plane (O-CU-UP) , a RAN intelligent controller (near-real time or non-real time) hosting software or software plug-ins, such as a near-real time control application (e.g., xApp) or a non-real time control application (e.g., rApp) , or any combination thereof (the adjective “open” designating support of an ORAN specification) . The network node may support a specification by, for example, supporting an interface defined by the ORAN specification, such as an A1, F1, W1, E1, E2, X2, Xn interface, an open fronthaul user plane interface, or an open fronthaul management plane interface. Moreover, an ORAN access node may be a logical node in a physical node. Furthermore, an ORAN network node may be implemented in a virtualization environment (described further below) in which one or more network functions are virtualized. For example, the virtualization environment may include an O-Cloud computing platform orchestrated by a Service Management and Orchestration Framework via an O-2 interface defined by the O-RAN Alliance or comparable technologies.

[0084] Example wireless communications over a wireless connection include transmitting and / or receiving wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for conveying information without the use of wires, cables,  or other material conductors. Moreover, in different embodiments, the CA network 100 may include any number of wired or wireless networks, network nodes, UEs, and / or any other components or systems that may facilitate or participate in the communication of data and / or signals whether via wired or wireless connections. The CA network 100 may include and / or interface with any type of communication, telecommunication, data, cellular, radio network, and / or other similar type of system.

[0085] The UEs 812 may be any of a wide variety of communication devices, including wireless devices arranged, configured, and / or operable to communicate wirelessly with the network nodes 810 and other communication devices. Similarly, the network nodes 810 are arranged, capable, configured, and / or operable to communicate directly or indirectly with the UEs 812 and / or with other network nodes or equipment in the telecommunication network 802 to enable and / or provide network access, such as wireless network access, and / or to perform other functions, such as administration in the telecommunication network 802.

[0086] In the depicted example, the core network 806 connects the network nodes 810 to one or more hosts, such as host 816. These connections may be direct or indirect via one or more intermediary networks or devices. In other examples, network nodes may be directly coupled to hosts. The core network 806 includes one more core network nodes (e.g., core network node 808) that are structured with hardware and software components. Features of these components may be substantially similar to those described with respect to the UEs, network nodes, and / or hosts, such that the descriptions thereof are generally applicable to the corresponding components of the core network node 808. Example core network nodes include functions of one or more of a Mobile Switching Center (MSC) , Mobility Management Entity (MME) , Home Subscriber Server (HSS) , Access and Mobility Management Function (AMF) , Session Management Function (SMF) , Authentication Server Function (AUSF) , Subscription Identifier De-concealing function (SIDF) , Unified Data Management (UDM) , Security Edge Protection Proxy (SEPP) , Network Exposure Function (NEF) , and / or a User Plane Function (UPF) .

[0087] The host 816 may be under the ownership or control of a service provider other than an operator or provider of the access network 804 and / or the telecommunication network 802, and may be operated by the service provider or on behalf of the service provider. The host 816 may host a variety of applications to provide one or more service. Examples of such applications include live and pre-recorded audio / video content, data collection services such as retrieving and compiling data on various ambient conditions detected by a plurality of UEs, analytics functionality, social media, functions for controlling or otherwise interacting with remote  devices, functions for an alarm and surveillance center, or any other such function performed by a server.

[0088] As a whole, the CA network 100 of Fig. 8 enables connectivity between the UEs, network nodes, and hosts. In that sense, the CA network 100 may be configured to operate according to predefined rules or procedures, such as specific standards that include, but are not limited to: Global System for Mobile Communications (GSM) ; Universal Mobile Telecommunications System (UMTS) ; Long Term Evolution (LTE) , and / or other suitable 2G, 3G, 4G, 5G, 6G standards, or any applicable future generation standard (e.g., 6G) ; wireless local area network (WLAN) standards, such as the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standards (WiFi) ; and / or any other appropriate wireless communication standard, such as the Worldwide Interoperability for Microwave Access (WiMax) , Bluetooth, Z-Wave, Near Field Communication (NFC) ZigBee, LiFi, and / or any low-power wide-area network (LPWAN) standards such as LoRa and Sigfox.

[0089] In some examples, the telecommunication network 802 is a cellular network that implements 3GPP standardized features. Accordingly, the telecommunications network 802 may support network slicing to provide different logical networks to different devices that are connected to the telecommunication network 802. For example, the telecommunications network 802 may provide Ultra Reliable Low Latency Communication (URLLC) services to some UEs, while providing Enhanced Mobile Broadband (eMBB) services to other UEs, and / or Massive Machine Type Communication (mMTC)  / Massive IoT services to yet further UEs.

[0090] In some examples, the UEs 812 are configured to transmit and / or receive information without direct human interaction. For instance, a UE may be designed to transmit information to the access network 804 on a predetermined schedule, when triggered by an internal or external event, or in response to requests from the access network 804. Additionally, a UE may be configured for operating in single-or multi-RAT or multi-standard mode. For example, a UE may operate with any one or combination of Wi-Fi, NR (New Radio) and LTE, i.e. being configured for multi-radio dual connectivity (MR-DC) , such as E-UTRAN (Evolved-UMTS Terrestrial Radio Access Network) New Radio –Dual Connectivity (EN-DC) .

[0091] In the example, the hub 814 communicates with the access network 804 to facilitate indirect communication between one or more UEs (e.g., UE 812c and / or 812d) and network nodes (e.g., network node 810b) . In some examples, the hub 814 may be a controller, router, content source and analytics, or any of the other communication devices described herein regarding UEs. For example, the hub 814 may be a broadband router enabling access to the core network 806 for the UEs. As another example, the hub 814 may be a controller that sends  commands or instructions to one or more actuators in the UEs. Commands or instructions may be received from the UEs, network nodes 810, or by executable code, script, process, or other instructions in the hub 814. As another example, the hub 814 may be a data collector that acts as temporary storage for UE data and, in some embodiments, may perform analysis or other processing of the data. As another example, the hub 814 may be a content source. For example, for a UE that is a VR headset, display, loudspeaker or other media delivery device, the hub 814 may retrieve VR assets, video, audio, or other media or data related to sensory information via a network node, which the hub 814 then provides to the UE either directly, after performing local processing, and / or after adding additional local content. In still another example, the hub 814 acts as a proxy server or orchestrator for the UEs, in particular if one or more of the UEs are low energy IoT devices.

[0092] The hub 814 may have a constant / persistent or intermittent connection to the network node 810b. The hub 814 may also allow for a different communication scheme and / or schedule between the hub 814 and UEs (e.g., UE 812c and / or 812d) , and between the hub 814 and the core network 806. In other examples, the hub 814 is connected to the core network 806 and / or one or more UEs via a wired connection. Moreover, the hub 814 may be configured to connect to an M2M service provider over the access network 804 and / or to another UE over a direct connection. In some scenarios, UEs may establish a wireless connection with the network nodes 810 while still connected via the hub 814 via a wired or wireless connection. In some embodiments, the hub 814 may be a dedicated hub –that is, a hub whose primary function is to route communications to / from the UEs from / to the network node 810b. In other embodiments, the hub 814 may be a non-dedicated hub –that is, a device which is capable of operating to route communications between the UEs and network node 810b, but which is additionally capable of operating as a communication start and / or end point for certain data channels.

Claims

1.A method (200) performed by a first Media Access Control, MAC, Security, MACsec, device (110; 500; 600; 810; 812) for managing a Secure Association Key, SAK, after an SAK refresh in a connectivity association, CA, network (100) wherein both an old SAK and a new SAK exist in the CA network, and wherein the CA network (100) comprises one or more second MACsec devices (120; 500; 600; 810; 812) in addition to the first MACsec device, the method comprising:receiving (210) one or more frames, from the one or more second MACsec devices respectively, wherein the frame comprises an indication indicating that a second MACsec device of the one or more second MACsec devices uses the new SAK or the old SAK;confirming (220) whether all of the one or more second MACsec devices use the new SAK; anddeleting (230) the old SAK upon confirming that all of the one or more second MACsec devices use the new SAK.2.The method according to claim 1, wherein the CA network comprises two or more second MACsec devices (120; 500; 600; 810; 812) in addition to the first MACsec device.3.The method according to claim 1 or 2, wherein the indication comprises a Security Channel Identifier, SCI, and an Association Number, AN, and wherein the SCI indicates an identity of a second MACsec device of the one or more second MACsec devices, and the AN indicates whether the second MACsec device uses the new SAK or the old SAK.4.The method according to claim 3, wherein the received frame indicates that an End Station, ES, bit is set to 0 and a Secure Channel, SC, bit is set to 1 in a header of the received frame.5.The method according to any of claims 1 to 4, wherein the indication is included in a MAC Security TAG, SecTAG, of the received frame.6.The method according to claim 1, wherein the indication comprises a source MAC address and an Association Number, AN, wherein the AN indicates whether a second MACsec device  of the one or more second MACsec devices uses the new SAK or the old SAK and the source MAC address indicates an identity of the second MACsec device.7.The method according to claim 6, wherein the received frame indicates that an End Station, ES, bit is set to 1 and a Secure Channel, SC, bit is set to 0 in a header of the received frame.8.The method according to any of claims 6 or 7, wherein the AN is included in a MAC Security TAG, SecTAG, of the received frame and the source MAC address is a Source Address of the received frame.9.The method according to any of claims 1 to 8, wherein the frame is a MACsec frame.10.A first Media Access Control, MAC, Security, MACsec, device (110; 500; 600; 810; 812) for managing a Secure Association Key, SAK, after an SAK refresh in a connectivity association, CA, network (100) wherein both an old SAK and a new SAK exist in the CA network, and wherein the CA network (100) comprises one or more second MACsec devices (120; 500; 600; 810; 812) in addition to the first MACsec device, the first MACsec device adapted to:receive (210) one or more frames, from the one or more second MACsec devices respectively, wherein the frame comprises an indication indicating that a second MACsec device of the one or more second MACsec devices uses the new SAK or the old SAK;confirm (220) whether all of the one or more second MACsec devices use the new SAK; anddelete (230) the old SAK upon confirming that all of the one or more second MACsec devices use the new SAK.11.The first MACsec device according to claim 10, wherein the CA network comprises two or more second MACsec devices (120; 500; 600; 810; 812) in addition to the first MACsec device.12.The first MACsec device according to claim 10 or 11, wherein the indication comprises a Security Channel Identifier, SCI, and an Association Number, AN, and wherein the SCI indicates an identity of a second MACsec device of the one or more second MACsec devices, and the AN indicates whether the second MACsec device uses the new SAK or the old SAK.13.The first MACsec device according to claim 12, wherein the received frame indicates that an End Station, ES, bit is set to 0 and a Secure Channel, SC, bit is set to 1 in a header of the received frame.14.The first MACsec device according to any of claims 10 to 13, wherein the indication is included in a MAC Security TAG, SecTAG, of the received frame.15.The first MACsec device according to claim 10, wherein the indication comprises a source MAC address and an Association Number, AN, wherein the AN indicates whether a second MACsec device of the one or more second MACsec devices uses the new SAK or the old SAK and the source MAC address indicates an identity of the second MACsec device.16.The first MACsec device according to claim 15, wherein the received frame indicates that an End Station, ES, bit is set to 1 and a Secure Channel, SC, bit is set to 0 in a header of the received frame.17.The first MACsec device according to any of claims 15 or 16, wherein the AN is included in a MAC Security TAG, SecTAG, of the received frame and the source MAC address is a Source Address of the received frame.18.The first MACsec device according to any of claims 10 to 17, wherein the frame is a MACsec frame.19.The first MACsec device according to any of claims 10 to 18, wherein the first MACsec device or a second MACsec device of the one or more second MACsec devices is either a MACsec Key Agreement (MKA) protocol Key server node or an MKA Key client node.20.A first MACsec device (110; 500; 600; 810; 812) in a Connectivity Association, CA, network (100) , the first MACsec device comprising:at least one processing circuitry (502) ; andat least one memory (504) connected to the at least one processing circuitry (502) and storing program code that is executed by the at least one processing circuitry to perform the method according to any one of claims 1 to 9.21.A computer program (720) comprising instructions which, when executed by at least one processing circuitry (502; 602) of:a first MACsec device (110; 500; 600; 810; 812) , causes the first MACsec device to carry out the method according to any one of claims 1 to 9.22.A computer program product (710) stored on a non-transitory computer readable medium and comprising instructions that, when executed by at least one processing circuitry (502; 602) of:a first MACsec device (110; 500; 600; 810; 812) , causes the first MACsec device to perform the method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • MACsec (Multi-Access Computer security) key updating method and equipment

    CN103209072A