Communication devices and methods therein for facilitating macsec communication
By transmitting MKA teardown information in MACsec communication, devices can promptly align security states and avoid service interruptions by terminating sessions and allowing unencrypted data transfer, addressing the issue of MACsec unavailability in secured MKA sessions.
Patent Information
- Application Number
- PCT/CN2024/143081
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-28
- Filing Date
- 2024-12-27
- Publication Date
- 2025-07-03
AI Technical Summary
In MACsec communication, when MACsec becomes unavailable in a secured MKA session, existing systems fail to promptly tear down the session, leading to service interruptions due to misalignment in the status of the MKA session, resulting in unencrypted traffic being sent and received by devices that have different security states.
Communication devices transmit MKA teardown information to peer devices to initiate session teardown, using parameter sets like SAK USE or Tear Down in MKPDU, enabling immediate session termination and allowing unencrypted data transfer according to the 'should-secure' policy, thereby avoiding service interruptions.
The solution allows for immediate session teardown, reducing service interruption time from potentially 6 to 18 seconds to around 20 milliseconds, ensuring seamless communication by aligning security states between devices.
Smart Images

Figure CN2024143081_03072025_PF_FP_ABST
Abstract
Description
COMMUNICATION DEVICES AND METHODS THEREIN FOR FACILITATING MACSEC COMMUNICATIONTECHNICAL FIELD
[0001] The present disclosure relates to communication technology, and more particularly, to communication devices and methods therein for facilitating Media Access Control Security (MACsec) communication.BACKGROUND
[0002] Media Access Control Security (MACsec) is an industry-standard security technology that provides secure communication for almost all types of traffic on Ethernet links. MACsec provides point-to-point (P2P) security on Ethernet links between directly-connected nodes and is capable of identifying and preventing most security threats, including denial of service, intrusion, man-in-the-middle, masquerading, passive wiretapping, and playback attacks.
[0003] MACsec is defined in Institute of Electrical and Electronics Engineers (IEEE) Standard 802.1AE-2018, Media Access Control (MAC) Security, which is incorporated herein for reference in its entirety. This standard defines, among others, Secure Channel and Secure Association:
[0004] - Secure Channel: A Secure Channel (SC) is a uni-directional point-to-point channel. This SC can only be used to apply MACsec to inbound or outbound traffic. When MACsec is enabled, a typical connectivity association using Secure Association Key (SAK) security mode includes two secure channels: one for inbound traffic, the other for outbound traffic. Each channel has an eight bytes Secure Channel Identifier (SCI) . The first six bytes match the MAC address of the egress port transmitting through that channel. The remaining two bytes are a Port Identifier used to distinguish between multiple channels from the same port.
[0005] - Secure Associations: Communication on each secure channel as a series of transient sessions is referred to as Secure Associations (SAs) . Each secure channel includes up to two SAs. In general, a channel has one SA. However, if an SA needs to be replaced, the channel must have two SAs. For example, when keys are rotated, two SAs are needed to swap from one to the other. The SA contains two critical pieces of information, which are required to encrypt and protect the frames.
[0006] · Secure Association Key (SAK) : An encrypted key derived from a pre-shared key.
[0007] · Packet Numbers (PNs) related to counters: The PNs are used for encryption, verification, and replay protection during transmission. At the transmission end of the channel, the counter records the next PN, while at the receiving end, the SA keeps tracking the next expected PN.
[0008] IEEE Standard 802.1X-2020, Port Based Network Access Control, which is incorporated herein by reference in its entirety, defines a MACsec Key Agreement (MKA) protocol. The MKA protocol allows Port Access Entities (PAEs) , each associated with a Port that is an authenticated member of a secure Connectivity Association (CA) or a potential CA, to discover other PAEs attached to the same Local Area Network (LAN) , to confirm mutual possession of a Connectivity Association Key (CAK) and hence to prove a past mutual authentication, to agree the secret keys (SAKs) used by MACsec for symmetric shared key cryptography, and to ensure that the data protected by MACsec has not been delayed.
[0009] MKA provides a secure multipoint-to-multipoint transport between the members of the same CA, suitable for conveying information that is constant, or refreshed or acknowledged by the MKA applications that make use of that transport. The CAK is used to authenticate each protocol data unit (MACsec Key Protocol Data Unit, or MKPDU) transmitted, providing proof of its transmission by a CA member, and each station includes its own randomly chosen identifier and a message number in the MKPDU. By transmitting MKPDUs that contain the identifiers and recent message numbers of the other participants, each member proves that it is in current possession of the CAK and is actively participating in the protocol, thus demonstrating the ‘liveness’ of the MKPDU and distinguishing it from MKPDUs that could have been captured by an attacker and played or replayed later -with the aim of disrupting the protocol or of influencing its outcome. MKPDUs are transmitted at regular intervals of MKA Hello Time or MKA Bounded Hello Time (if a bounded receive delay is to be guaranteed) , when data to be transported changes as specified in Clause 9 of IEEE Standard 802.1X-2020, and as specified by the PAE Controlled Port state machine (CP) state machine (setting the state machine variable newInfo, as specified in Clause 12 of IEEE Standard 802.1X-2020) .SUMMARY
[0010] According to Clause 9.14 of IEEE Standard 802.1X-2020, an MKA participant shall be deleted as a result of any of the following:
[0011] h) The CAK lifetime (if specified) has expired.
[0012] i) The CAK was derived from an Extensible Authentication Protocol (EAP) exchange, but has not resulted in the recognition of a Live Peer with an acceptable MACsec Capability within a period MKA Life Time (see Table 9-3 of IEEE Standard 802.1X-2020, which summarizes each MKA participant’s use of timers and their timeout values) .
[0013] An MKA participant may be deleted as a result of any of the following:
[0014] j) The last key server to distribute a key using that CAK is no longer in the participant’s Live Peer List but is (as identified by its SCI) on the Live Peer List of another participant that is using the same Common Port.
[0015] k) The number of participants would otherwise exceed the number that can be supported by the system.
[0016] The MKA Life Time is defined as 6 seconds. In most of implementations, the life time is configurable value from 6 seconds to 18 seconds. The MKA protocol keeps the participant liveness according to configured life time. Ifthe participant does not receive any MKA packets from its peer within the life time, the participant may remove the established secure session.
[0017] The MACsec supports a “should-secure” policy to allow unencrypted traffic if MKA session not Secured. During the MKA negotiation, a communication device (e.g., router) tries to establish an MKA session.
[0018] · If the MKA session is not established, traffic is transmitted in clear text without the MACsec encryption and decryption.
[0019] · If the MKA session is established successfully, traffic is transmitted with MACsec encryption and decryption.
[0020] Figs. 1A and 1B each show an exemplary scenario ofP2P MACsec communication between Router A and Router B. Initially, as shown in Fig. 1A, after successful MKA negotiation, traffic is transmitted with MACsec encryption and decryption between Router A and Router B. Then, as shown in Fig. 1B, MACsec is disabled at Router B, and Router B stops sending MKA to Router A. According to the ‘should-secure’ policy, Router B start sending unencrypted traffic to Router A. At Router A, the MKA session remains until its life time expires. During the period after the MACsec is disabled at Router B and before the life time expires at Router A, Router A still sends encrypted traffic to Router B, but Router B could not decrypt the traffic as its MACsec is disabled. On the other hand, during this period, Router A fails to decrypt traffic from Router B, as it is in fact unencrypted. This will result in service interruption.
[0021] It is an object of the present disclosure to provide communication devices and methods therein, capable of solving or mitigating the above problem.
[0022] According to a first aspect of the present disclosure, a method in a first communication device is provided. The method includes transmitting, to a second communication device in response to MACsec becoming unavailable in a secured MKA session, MKA teardown information indicating that the first communication device is to tear down the MKA session with the second communication device. The method further includes: receiving unencrypted data from the second communication device.
[0023] In an embodiment, the MKA teardown information may be carried in an SAK USE parameter set or a Tear Down parameter set in an MKPDU.
[0024] In an embodiment, the Tear Down parameter set may include an Advanced Encryption Standard (AES) Key Wrap of an SAK associated with the MKA session.
[0025] In an embodiment, the method may further include tearing down the MKA session and transmitting unencrypted data to the second communication device.
[0026] In an embodiment, the operation of tearing down the MKA session may include deleting MKA participants of the MKA session that are associated with the first communication device and the second communication device respectively, and deleting an SAK associated with the MKA session.
[0027] In an embodiment, the MACsec becoming unavailable may include the MACsec being disabled at the first communication device.
[0028] According to a second aspect of the present disclosure, a method in a second communication device is provided. The method includes receiving, from a first communication device, MKA teardown information indicating that the first communication device is to tear down a MKA session with the second communication device. The method further includes transmitting unencrypted data to the first communication device.
[0029] In an embodiment, the MKA teardown information may be carried in an SAK USE parameter set or a Tear Down parameter set in an MKPDU.
[0030] In an embodiment, the Tear Down parameter set may include an AES Key Wrap of an SAK associated with the MKA session.
[0031] In an embodiment, the method may further include: verifying the MKA teardown information based on the AES Key Wrap of the SAK. The unencrypted data may be transmitted in response to the MKA teardown information being successfully verified.
[0032] In an embodiment, the first communication device may act as a Key Server and the second communication device acts as a client. The method may further include tearing down the MKA session in response to the MKA teardown information.
[0033] In an embodiment, the first communication device may act as a client and the second communication device may act as a Key Server. The method may further include tearing down the MKA session in response to the MKA teardown information, when there is no further live client in the MKA session, or deleting MKA participants of the MKA session that are associated with the first communication device and the second communication device respectively in response to the MKA teardown information, when there is at least one further live client in the MKA session.
[0034] In an embodiment, the operation of tearing down the MKA session may include deleting MKA participants of the MKA session that are associated with the first communication device and the second communication device respectively; and deleting an SAK associated with the MKA session.
[0035] In an embodiment, the method may further include, subsequent to receiving the MKA teardown information, receiving unencrypted data from the first communication device.
[0036] According to a third aspect of the present disclosure, a first communication device is provided. The first communication device includes a communication interface, a processor, and a memory. The memory contains instructions executable by the processor whereby the first communication device is operative to perform the method according to the above first aspect.
[0037] According to a fourth aspect of the present disclosure, a computer-readable storage medium is provided. The computer-readable storage medium has computer-readable instructions stored thereon. The computer-readable instructions, when executed by a processor of a first communication device, configure the first communication device to perform the method according to the above first aspect.
[0038] According to a fifth aspect of the present disclosure, a second communication device is provided. The second communication device includes a communication interface, a processor, and a memory. The memory contains instructions executable by the processor whereby the second communication device is operative to perform the method according to the above second aspect.
[0039] According to a sixth aspect of the present disclosure, a computer-readable storage medium is provided. The computer-readable storage medium has computer-readable instructions stored thereon. The computer-readable instructions, when executed by a processor of a second communication device, configure the second communication device to perform the method according to the above second aspect.
[0040] With the embodiments of the present disclosure, when MACsec becomes unavailable at a communication device in a secured MKA session, a communication device can transmit, to its peer device, MKA teardown information indicating that the communication device is to tear down the MKA session with the peer device. In this case, the MKA session can be torn down between the two devices, without having to wait for expiration of MKA lift time. Accordingly, unencrypted traffic may be communicated between the two devices according to the should-secure policy, and service interruption due to misalignment between the two devices with regard to the status of the MKA session can be avoided.BRIEF DESCRIPTION OF THE DRAWINGS
[0041] The above and other objects, features and advantages will be more apparent from the following description of embodiments with reference to the figures, in which:
[0042] Figs. 1A and 1B are schematic diagrams each showing an exemplary scenario of P2P MACsec communication;
[0043] Fig. 2 is a flowchart illustrating a method in a first communication device according to an embodiment of the present disclosure;
[0044] Fig. 3 is a schematic diagram showing an MKPDU format;
[0045] Fig. 4 is a schematic diagram showing a format of an SAK USE parameter set according to an embodiment of the present disclosure;
[0046] Fig. 5 is a schematic diagram showing a format of a Tear Down parameter set according to an embodiment of the present disclosure;
[0047] Fig. 6 is a flowchart illustrating a method in a second communication device according to an embodiment of the present disclosure;
[0048] Fig. 7 is a sequence diagram showing an example of a process of MKA session teardown;
[0049] Fig. 8 is a block diagram of a first communication device according to an embodiment of the present disclosure; and
[0050] Fig. 9 is a block diagram of a second communication device according to an embodiment of the present disclosure.DETAILED DESCRIPTION
[0051] References in the specification to "one embodiment, " "an embodiment, " "an example embodiment, " and the like indicate that the embodiment described may include a particular feature, structure, or characteristic, but it is not necessary that every embodiment includes the particular feature, structure, or characteristic. Moreover, such phrases are not necessarily referring to the same embodiment. Further, when a particular feature, structure, or characteristic is described in connection with an embodiment, it is submitted that it is within the knowledge of one skilled in the art to affect such feature, structure, or characteristic in connection with other embodiments whether or not explicitly described.
[0052] It shall be understood that although the terms "first" and "second" etc. may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, a first element could be termed a second element, and similarly, a second element could be termed a first element, without departing from the scope of example embodiments. As used herein, the term "and / or" includes any and all combinations of one or more of the associated listed terms.
[0053] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of example embodiments. As used herein, the singular forms "a" , "an" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms "comprises" , "comprising" , "has" , "having" , "includes" and / or "including" , when used herein, specify the presence of stated features, elements, and / or components etc., but do not preclude the presence or addition of one or more other features, elements, components and / or combinations thereof.
[0054] In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skills in the art to which this disclosure belongs.
[0055] Fig. 2 is a flowchart illustrating a method 200 according to an embodiment of the present disclosure. The method 200 can be performed by a first communication device, which may be e.g., a router or any appropriate device supporting the MKA protocol. The first communication device may act as a Key server or a client.
[0056] At block 210, the first communication device transmits, to a second communication device in response to MACsec becoming unavailable in a secured MKA session, MKA teardown information indicating that the first communication device is to tear down the MKA session with the second communication device. It may be the case when an administrator of the first communication device manually disables MACsec at the first communication device while the first communication device is having the MKA session in the Secured status with the second communication device.
[0057] In an example, the MKA teardown information may be carried in an SAK USE parameter set in an MKPDU.
[0058] Fig. 3 shows an MKPDU format defined in IEEE Standard 802.1X-2020. Some parameter sets are defined in IEEE Standard 802.1X-2020:
[0059] 1. BASIC_PARAMETER_SET = 0
[0060] 2. LIVE_PEER_LIST = 1
[0061] 3. POTENTIAL_PEER_LIST = 2
[0062] 4. SAK_USE=3
[0063] 5. DISTRIBUTED_SAK = 4
[0064] 6. DISTRIBUTED_CAK = 5
[0065] 7. KMD = 6
[0066] 8. ANNOUNCEMENT = 7
[0067] 9. ICV_INDICATOR = 255.
[0068] Fig. 4 shows a format of the SAK USE parameter set according to an embodiment of the present disclosure. The “X” bit in the SAK USE parameter set can be used as the MKA teardown information. For example, the “X” bit being set to “1” may indicate that the first communication device is to tear down the MKA session with the second communication device.
[0069] For further details of the MKPDU format and the SAK USE parameter set, reference can be made to IEEE Standard 802.1X-2020.
[0070] In another example, a new parameter set, referred to as “Tear Down” parameter set, can be defined. Fig. 5 shows a format of the Tear Down parameter set according to an embodiment of the present disclosure. A new parameter set type, e.g., 200, can be used. As shown, two “Tear-Down” bits in the parameter set can be used as the MKA teardown information. For example, the “Tear-Down” bits being set to “11” may indicate that the first communication device is to tear down the MKA session with the second communication device.
[0071] Here, the Tear Down parameter set may include an AES Key Wrap of an SAK associated with the MKA session. According to IEEE Standard 802.1X-2020, each distributed SAK shall be protected by AES Key Wrap, as specified by The Internet Engineering Task Force (IETF) Request For Comments (RFC) 3394, which is incorporated herein by reference in its entirety. The AES Key Wrap default Initial Value (IV) defined in RFC 3394 shall be used. On receiving the Tear Down parameter set, a participant shall always verify the current SAK using the AES algorithm specified in the Basic parameter set. This can prevent the unauthorized denial of service attacks.
[0072] In an example, e.g., after the block 210, the first communication device may tear down the MKA session and transmit unencrypted data to the second communication device. Here, the operation of tearing down the MKA session may include deleting MKA participants of the MKA session that are associated with the first communication device and the second communication device respectively, and deleting an SAK associated with the MKA session.
[0073] At block 220, the first communication device receives unencrypted data from the second communication device. The unencrypted data is transmitted by the second communication device in response to receiving the MKA teardown information.
[0074] Fig. 6 is a flowchart illustrating a method 600 according to an embodiment of the present disclosure. The method 600 can be performed by a second communication device, which may be e.g., a router or any appropriate device supporting the MKA protocol.
[0075] At block 610, the second communication device receives, from a first communication device, MKA teardown information indicating that the first communication device is to tear down a MKA session with the second communication device.
[0076] Here, the MKA teardown information may be carried in an SAK USE parameter set or a Tear Down parameter set in an MKPDU. For details, reference can be made to the above description given in connection with the method 200 and Figs. 4 and 5.
[0077] In an example, the Tear Down parameter set may include an AES Key Wrap of an SAK associated with the MKA session. For details, reference can be made to the above description given in connection with the method 200 and Fig. 5. Accordingly, the second communication device may verify the MKA teardown information based on the AES Key Wrap of the SAK.
[0078] In an example, the first communication device may act as a Key Server and the second communication device may act as a client. In this case, the second communication device may tear down the MKA session in response to the MKA teardown information. Here, the operation of tearing down the MKA session may include deleting MKA participants of the MKA session that are associated with the first communication device and the second communication device respectively, and deleting an SAK associated with the MKA session.
[0079] In another example, the first communication device may act as a client and the second communication device may act as a Key Server. In this case, when there is no further live client in the MKA session, the second communication device may tear down the MKA session in response to the MKA teardown information. Here, the operation of tearing down the MKA session may include deleting MKA participants of the MKA session that are associated with the first communication device and the second communication device respectively, and deleting an SAK associated with the MKA session. When there is at least one further live client in the MKA session, the second communication device may delete MKA participants of the MKA session that are associated with the first communication device and the second communication device respectively in response to the MKA teardown information (i.e., without deleting the SAK associated with the MKA session as it will be used between the Key Server and the live client (s) ) . In this context, a participant is “live” when demonstrating its “liveness” by transmitting MKPDUs regularly within MKA life time and thus being recognized by another participant as a Live Peer.
[0080] At block 620, the second communication device transmits unencrypted data to the first communication device. In an example, the unencrypted data may be transmitted in response to the MKA teardown information being successfully verified.
[0081] Additionally, after receiving the MKA teardown information, the second communication device may receive unencrypted data from the first communication device.
[0082] The above methods 200 and 600 will be further explained below with reference to Fig. 7, which shows an example of a process of MKA session teardown between Device A and Device B.
[0083] As shown, at Step 1, Device A and Device B perform MKA session negotiation with each other. At Step 2, after successful negotiation, an MKA session is established between Device A and Device B, and the MKA session is in a Secured status. At Step 3, Device A and Device B send encrypted data to each other.
[0084] At Step 4, MACsec is disabled at Device B, and Device B starts to tear down the MKA session (e.g., by deleting Device A and Device B from MKA participants of the MKA session and deleting an SAK associated with the MKA session) . At this time, at Step 5, Device B sends MKA Teardown information (referring to e.g., Fig. 4 or 5) to Device A, informing Device A that Device B is to tear down the MKA session. Device A may verify the MKA Teardown information e.g., based on an AES Key Wrap of an SAK (referring to e.g., Fig. 5) . At Step 6, Device A may either tear down the MKA session (e.g., by deleting Device A and Device B from MKA participants of the MKA session and deleting an SAK associated with the MKA session) ifDevice A is a client (in this case Device B is a Key Server) or ifDevice A is a Key Server and there is no further live client (other than Device B) in the MKA session, or simply delete Device A and Device B from MKA participants of the MKA session ifDevice A is a Key Server and there is at least one further live client (other than Device B) in the MKA session.
[0085] At Step 7, there is no Secured MKA session between Device A and Device B, or the MKA session between Device A and Device B becomes Unsecured. At Step 8, Device A and Device B send encrypted data to each other.
[0086] The transmission and handling of the MKA Teardown information may take around 20 milliseconds, while the MKA life time could take 6 to 18 seconds to expire. With the introduction of the MKA Teardown information, the service interruption time and / or traffic loss can be significantly reduced according to the present disclosure.
[0087] Fig. 8 is a block diagram of a first communication device 800 according to an embodiment of the present disclosure.
[0088] The first communication device 800 includes a communication interface 810, a processor 820 and a memory 830.
[0089] The memory 830 may contain instructions executable by the processor 820 whereby the first communication device 800 is operative to perform the actions, e.g., of the procedure described earlier in conjunction with Fig. 2. Particularly, the memory 830 may contain instructions executable by the processor 820 whereby the first communication device 800 is operative to: transmit, to a second communication device in response to MACsec becoming unavailable in a secured MKA session, MKA teardown information indicating that the first communication device is to tear down the MKA session with the second communication device; and receive unencrypted data from the second communication device.
[0090] In an embodiment, the MKA teardown information may be carried in an SAK USE parameter set or a Tear Down parameter set in an MKPDU.
[0091] In an embodiment, the Tear Down parameter set may include an AES Key Wrap of an SAK associated with the MKA session.
[0092] In an embodiment, the memory 830 may further contain instructions executable by the processor 820 whereby the first communication device 800 is operative to tear down the MKA session and transmit unencrypted data to the second communication device.
[0093] In an embodiment, the operation of tearing down the MKA session may include deleting MKA participants of the MKA session that are associated with the first communication device and the second communication device respectively, and deleting an SAK associated with the MKA session.
[0094] In an embodiment, the MACsec becoming unavailable may include the MACsec being disabled at the first communication device.
[0095] Fig. 9 is a block diagram of a second communication device 900 according to an embodiment of the present disclosure.
[0096] The second communication device 900 includes a communication interface 910, a processor 920 and a memory 930.
[0097] The memory 930 may contain instructions executable by the processor 920 whereby the second communication device 900 is operative to perform the actions, e.g., of the procedure described earlier in conjunction with Fig. 6. Particularly, the memory 930 may contain instructions executable by the processor 920 whereby the second communication device 900 is operative to: receive, from a first communication device, MKA teardown information indicating that the first communication device is to tear down a MKA session with the second communication device; and transmit unencrypted data to the first communication device.
[0098] In an embodiment, the MKA teardown information may be carried in an SAK USE parameter set or a Tear Down parameter set in an MKPDU.
[0099] In an embodiment, the Tear Down parameter set may include an AES Key Wrap of an SAK associated with the MKA session.
[0100] In an embodiment, the memory 930 may further contain instructions executable by the processor 920 whereby the second communication device 900 is operative to: verify the MKA teardown information based on the AES Key Wrap of the SAK. The unencrypted data may be transmitted in response to the MKA teardown information being successfully verified.
[0101] In an embodiment, the first communication device may act as a Key Server and the second communication device acts as a client. The memory 930 may further contain instructions executable by the processor 920 whereby the second communication device 900 is operative to: tear down the MKA session in response to the MKA teardown information.
[0102] In an embodiment, the first communication device may act as a client and the second communication device may act as a Key Server. The memory 930 may further contain instructions executable by the processor 920 whereby the second communication device 900 is operative to: tear down the MKA session in response to the MKA teardown information, when there is no further live client in the MKA session, or delete MKA participants of the MKA session that are associated with the first communication device and the second communication device respectively in response to the MKA teardown information, when there is at least one further live client in the MKA session.
[0103] In an embodiment, the operation of tearing down the MKA session may include deleting MKA participants of the MKA session that are associated with the first communication device and the second communication device respectively; and deleting an SAK associated with the MKA session.
[0104] In an embodiment, the memory 930 may further contain instructions executable by the processor 920 whereby the second communication device 900 is operative to: subsequent to receiving the MKA teardown information, receive unencrypted data from the first communication device.
[0105] The present disclosure also provides at least one computer program product in the form of a non-volatile or volatile memory, e.g., a non-transitory computer readable storage medium, an Electrically Erasable Programmable Read-Only Memory (EEPROM) , a flash memory and a hard drive. The computer program product includes a computer program. The computer program includes: code / computer readable instructions, which when executed by the processor 820 causes the first communication device 800 to perform the actions, e.g., of the procedure described earlier in conjunction with Fig. 2; or code / computer readable instructions, which when executed by the processor 920 causes the second communication device 900 to perform the actions, e.g., of the procedure described earlier in conjunction with Fig. 6.
[0106] The computer program product may be configured as a computer program code structured in computer program modules. The computer program modules could essentially perform the actions of the flow illustrated in Fig. 2 or 6.
[0107] The processor may be a single CPU (Central Processing Unit) , but could also comprise two or more processing units. For example, the processor may include general purpose microprocessors; instruction set processors and / or related chips sets and / or special purpose microprocessors such as Application Specific Integrated Circuits (ASICs) . The processor may also comprise board memory for caching purposes. The computer program may be carried in a computer program product connected to the processor. The computer program product may comprise a non-transitory computer readable storage medium on which the computer program is stored. For example, the computer program product may be a flash memory, a Random Access Memory (RAM) , a Read-Only Memory (ROM) , or an EEPROM, and the computer program modules described above could in alternative embodiments be distributed on different computer program products in the form of memories.
[0108] The disclosure has been described above with reference to embodiments thereof. It should be understood that various modifications, alternations and additions can be made by those skilled in the art without departing from the spirits and scope of the disclosure. Therefore, the scope of the disclosure is not limited to the above particular embodiments but only defined by the claims as attached.
Claims
1.A method (200) in a first communication device, comprising:transmitting (210) , to a second communication device in response to Media Access Control Security, MACsec, becoming unavailable in a secured MACsec Key Agreement, MKA, session, MKA teardown information indicating that the first communication device is to tear down the MKA session with the second communication device; andreceiving (220) unencrypted data from the second communication device.2.The method (200) of claim 1, wherein the MKA teardown information is carried in a Secure Association Key, SAK, USE parameter set or a Tear Down parameter set in a MACsec Key Protocol Data Unit, MKPDU.3.The method (200) of claim 2, wherein the Tear Down parameter set comprises an Advanced Encryption Standard, AES, Key Wrap of an SAK associated with the MKA session.4.The method (200) of any of claims 1-3, further comprising:tearing down the MKA session; andtransmitting unencrypted data to the second communication device.5.The method (200) of claim 4, wherein said tearing down the MKA session comprises:deleting MKA participants of the MKA session that are associated with the first communication device and the second communication device respectively; anddeleting an SAK associated with the MKA session.6.The method (200) of any of claims 1-5, wherein the MACsec becoming unavailable comprises the MACsec being disabled at the first communication device.7.A method (600) in a second communication device, comprising:receiving (610) , from a first communication device, Media Access Control Security ‘MACsec’ Key Agreement, MKA, teardown information indicating that the first communication device is to tear down a MKA session with the second communication device; andtransmitting (620) unencrypted data to the first communication device.8.The method (600) of claim 7, wherein the MKA teardown information is carried in a Secure Association Key, SAK, USE parameter set or a Tear Down parameter set in a MACsec Key Protocol Data Unit, MKPDU.9.The method (600) of claim 8, wherein the Tear Down parameter set comprises an Advanced Encryption Standard, AES, Key Wrap of an SAK associated with the MKA session.10.The method (600) of claim 9, further comprising:verifying the MKA teardown information based on the AES Key Wrap of the SAK,wherein the unencrypted data is transmitted in response to the MKA teardown information being successfully verified.11.The method (600) of any of claims 7-10, wherein the first communication device acts as a Key Server and the second communication device acts as a client, and wherein the method (600) further comprises:tearing down the MKA session in response to the MKA teardown information.12.The method (600) of any of claims 7-10, wherein the first communication device acts as a client and the second communication device acts as a Key Server, and wherein the method (600) further comprises:tearing down the MKA session in response to the MKA teardown information, when there is no further live client in the MKA session; ordeleting MKA participants of the MKA session that are associated with the first communication device and the second communication device respectively in response to the MKA teardown information, when there is at least one further live client in the MKA session.13.The method (600) of claim 11 or 12, wherein said tearing down the MKA session comprises:deleting MKA participants of the MKA session that are associated with the first communication device and the second communication device respectively; anddeleting an SAK associated with the MKA session.14.The method (600) of any of claims 7-13, further comprising, subsequent to receiving the MKA teardown information:receiving unencrypted data from the first communication device.15.A first communication device (800) , comprising a communication interface (810) , a processor (820) , and a memory (830) , the memory (830) comprising instructions executable by the processor (820) whereby the first communication device (800) is operative to perform the method according to any of claims 1-6.16.A computer-readable storage medium having computer-readable instructions stored thereon, the computer-readable instructions, when executed by a processor of a first communication device, configure the first communication device to perform the method according to any of claims 1-6.17.A second communication device (900) , comprising a communication interface (910) , a processor (920) , and a memory (930) , the memory (930) comprising instructions executable by the processor (920) whereby the second communication device (900) is operative to perform the method according to any of claims 7-14.18.A computer-readable storage medium having computer-readable instructions stored thereon, the computer-readable instructions, when executed by a processor of a second communication device, configure the second communication device to perform the method according to any of claims 7-14.
Citation Information
Patent Citations
Fast heartbeat liveness between packet processing engines using media access control security (macsec) communication
US20190116183A1
Failover in a media access control security capabale device
US20190386824A1
Pausing a media access control security (macsec) key agreement (MKA) protocol of an MKA session using a fast heartbeat session
US20230079217A1