Parameter configuration method and apparatus, and device
Patent Information
- Application Number
- PCT/CN2025/085141
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-03-26
- Publication Date
- 2026-10-01
Smart Images

Figure CN2025085141_01102026_PF_FP_ABST
Abstract
Description
A parameter configuration method, apparatus and device Technical Field
[0001] This application relates to the field of communication technology, and in particular to a parameter configuration method, apparatus and device. Background Technology
[0002] Encryption technologies (such as IPsec) require encryption boards to implement encryption functions, resulting in relatively weak processing performance. Furthermore, they cannot protect all data after the Layer 2 frame header, only the data after the Layer 3 header. Therefore, a MACsec (Media Access Control Security) encryption technology is proposed.
[0003] MACsec defines a secure data communication method for local area networks. MACsec provides users with secure MAC layer data sending and receiving services, including user data encryption, data frame integrity checks, and data source authenticity verification. MACsec works in conjunction with 802.1X authentication, using a key negotiated through the MKA (MACsec Key Agreement) protocol to encrypt and perform integrity checks on authenticated user data, preventing the interface from processing messages from unauthenticated devices or tampered messages.
[0004] However, to implement MACsec, parameters need to be configured for each pair of adjacent interfaces on each device. These parameters are used for negotiation and encryption, making the deployment and maintenance of MACsec quite complex. Summary of the Invention
[0005] This application provides a parameter configuration method applied to a MACsec master device, including:
[0006] Receive a first parameter request message sent by a first MACsec slave device. The first parameter request message includes the interface identifier and MAC address of the first interface of the first MACsec slave device, and the interface identifier and MAC address of the neighbor interface of the neighbor device of the first MACsec slave device.
[0007] Receive a second parameter request message sent by the second MACsec slave device. The second parameter request message includes the interface identifier and MAC address of the second interface of the second MACsec slave device, the interface identifier and MAC address of the neighbor interface of the neighbor device of the second MACsec slave device;
[0008] If it is determined that the first interface and the second interface are successfully paired based on the first parameter request message and the second parameter request message, then the first MACsec parameter corresponding to the first MACsec slave device and the second MACsec parameter corresponding to the second MACsec slave device are obtained.
[0009] The first MACsec parameter is sent to the first MACsec slave device, and the second MACsec parameter is sent to the second MACsec slave device. The first MACsec slave device and the second MACsec slave device then perform MACsec communication based on the first MACsec parameter and the second MACsec parameter.
[0010] This application provides a parameter configuration method applicable to any MACsec slave device, including:
[0011] Obtain the interface identifier and MAC address of the neighboring interface of the neighboring device of this MACsec slave device;
[0012] Send a parameter request message to the MACsec master device. The parameter request message includes the interface identifier and MAC address of the local interface of the MACsec slave device, and the interface identifier and MAC address of the neighbor interface of the neighbor device; wherein the local interface is connected to the neighbor interface.
[0013] Receive the MACsec parameters corresponding to the local MACsec slave device sent by the MACsec master device; wherein, the MACsec parameters are obtained by the MACsec master device when it determines that the local interface and the neighbor interface are successfully paired based on the parameter request message;
[0014] Based on the MACsec parameters, perform MACsec communication with the neighboring device.
[0015] This application provides a parameter configuration device applied to a MACsec master device, comprising:
[0016] The receiving module is configured to receive a first parameter request message sent by a first MACsec slave device, the first parameter request message including the interface identifier and MAC address of the first interface of the first MACsec slave device, and the interface identifier and MAC address of the neighbor interface of the neighbor device of the first MACsec slave device; and to receive a second parameter request message sent by a second MACsec slave device, the second parameter request message including the interface identifier and MAC address of the second interface of the second MACsec slave device, and the interface identifier and MAC address of the neighbor interface of the neighbor device of the second MACsec slave device.
[0017] The acquisition module is used to acquire the first MACsec parameter corresponding to the first MACsec slave device and the second MACsec parameter corresponding to the second MACsec slave device if it is determined that the first interface and the second interface are successfully paired based on the first parameter request message and the second parameter request message.
[0018] The sending module is used to send the first MACsec parameter to the first MACsec slave device and the second MACsec parameter to the second MACsec slave device, so that the first MACsec slave device and the second MACsec slave device can perform MACsec communication based on the first MACsec parameter and the second MACsec parameter.
[0019] This application provides a parameter configuration device, applicable to any MACsec slave device, comprising:
[0020] The acquisition module is used to acquire the interface identifier and MAC address of the neighbor interface of the neighbor device of the MACsec slave device; wherein, the neighbor device is another MACsec slave device;
[0021] The sending module is used to send a parameter request message to the MACsec master device. The parameter request message includes the interface identifier and MAC address of the local interface of the MACsec slave device, and the interface identifier and MAC address of the neighbor interface of the neighbor device; wherein the local interface is connected to the neighbor interface.
[0022] The receiving module is used to receive the MACsec parameters corresponding to the local MACsec slave device sent by the MACsec master device; wherein, the MACsec parameters are obtained by the MACsec master device when it determines that the local interface and the neighbor interface are successfully paired based on the parameter request message;
[0023] A communication module is used to perform MACsec communication with the neighboring device based on the MACsec parameters.
[0024] This application provides an electronic device, including: a processor and a machine-readable storage medium, wherein the machine-readable storage medium stores machine-executable instructions that can be executed by the processor; the processor is used to execute the machine-executable instructions to implement the parameter configuration method of the above example of this application.
[0025] This application provides a computer program product, which includes a computer program that, when executed by a processor, implements the parameter configuration method described in the above example of this application.
[0026] This application provides a machine-readable storage medium storing machine-executable instructions that can be executed by a processor; wherein the processor is configured to execute the machine-executable instructions to implement the parameter configuration method of the above example of this application when the machine-executable instructions are executed.
[0027] As can be seen from the above technical solutions, in this embodiment, the adjacency relationship of the MACsec slave device is reported to the MACsec master device, which then obtains the MACsec parameters of the MACsec slave device. The MACsec parameters are then centrally processed by the MACsec master device. The MACsec master device centrally manages the MACsec parameters and distributes them to the MACsec slave device to complete the configuration of the MACsec parameters. This simplifies the configuration of MACsec parameters, enables automatic deployment of MACsec parameters, and makes the deployment and maintenance of MACsec relatively simple, thus solving the problem of complex MACsec deployment. Attached Figure Description
[0028] Figure 1A is a flowchart illustrating a parameter configuration method in one embodiment of this application;
[0029] Figure 1B is a flowchart illustrating a parameter configuration method in one embodiment of this application;
[0030] Figure 2 is a network topology diagram of a MACsec network in one embodiment of this application;
[0031] Figure 3 is a flowchart illustrating a parameter configuration method in one embodiment of this application;
[0032] Figure 4A is a schematic diagram of the MACsec NLRI field in one embodiment of this application;
[0033] Figure 4B is a schematic diagram of a variable-length NLRI field in one embodiment of this application;
[0034] Figure 4C is a schematic diagram of the MACsec attribute field in one embodiment of this application;
[0035] Figure 4D is a schematic diagram of the MACsec attribute field in one embodiment of this application;
[0036] Figure 4E is a schematic diagram of the MACsec option field in one embodiment of this application;
[0037] Figure 5A is a schematic diagram of the MACsec attribute field in one embodiment of this application;
[0038] Figure 5B is a schematic diagram of the MACsec option field in one embodiment of this application;
[0039] Figure 6A is a schematic diagram of the parameter configuration device in one embodiment of this application;
[0040] Figure 6B is a schematic diagram of the parameter configuration device in one embodiment of this application;
[0041] Figure 7 is a hardware structure diagram of an electronic device according to one embodiment of this application. Detailed Implementation
[0042] This application proposes a parameter configuration method, which can be applied to MACsec master devices. Referring to Figure 1A, which is a flowchart of the method, the method may include:
[0043] Step 101: Receive a first parameter request message sent by the first MACsec slave device. The first parameter request message includes the interface identifier and MAC address of the first interface of the first MACsec slave device, and the interface identifier and MAC address of the neighbor interface of the neighbor device of the first MACsec slave device.
[0044] Step 102: Receive a second parameter request message sent by the second MACsec slave device. The second parameter request message includes the interface identifier and MAC address of the second interface of the second MACsec slave device, the interface identifier and MAC address of the neighbor interface of the neighbor device of the second MACsec slave device.
[0045] Step 103: If it is determined that the first interface and the second interface are successfully paired based on the first parameter request message and the second parameter request message, then obtain the first MACsec parameter corresponding to the first MACsec slave device and the second MACsec parameter corresponding to the second MACsec slave device.
[0046] Step 104: Send the first MACsec parameter to the first MACsec slave device and the second MACsec parameter to the second MACsec slave device. The first MACsec slave device and the second MACsec slave device then perform MACsec communication based on the first MACsec parameter and the second MACsec parameter.
[0047] This application proposes a parameter configuration method that can be applied to any MACsec slave device (e.g., the MACsec slave device can be a first MACsec slave device or a second MACsec slave device). Referring to Figure 1B, which is a flowchart of the method, the method may include:
[0048] Step 111: Obtain the interface identifier and MAC address of the neighbor interface of the neighboring device of this MACsec slave device. The neighboring device is another MACsec slave device connected to this MACsec slave device.
[0049] Step 112: Send a parameter request message to the MACsec master device. This parameter request message includes the interface identifier and MAC address of the local interface of the MACsec slave device, and the interface identifier and MAC address of the neighbor interface of the neighbor device. The local interface and the neighbor interface can be connected.
[0050] For example, if this MACsec slave device is the first MACsec slave device, then the neighboring device of this MACsec slave device can be the second MACsec slave device, the local interface is the first interface of the first MACsec slave device, and the neighboring interface is the second interface of the second MACsec slave device.
[0051] Alternatively, if this MACsec slave device is the second MACsec slave device, then the neighboring device of this MACsec slave device can be the first MACsec slave device, the local interface is the second interface of the second MACsec slave device, and the neighboring interface is the first interface of the first MACsec slave device.
[0052] Step 113: Receive the MACsec parameters corresponding to this MACsec slave device sent by the MACsec master device. For example, the MACsec parameters can be obtained by the MACsec master device when it determines that the local interface and the neighbor interface have been successfully paired based on the parameter request message.
[0053] Step 114: Perform MACsec communication with neighboring devices based on MACsec parameters.
[0054] As can be seen from the above technical solutions, in this embodiment, the adjacency relationship of the MACsec slave device is reported to the MACsec master device, which then obtains the MACsec parameters of the MACsec slave device. The MACsec parameters are then centrally processed by the MACsec master device. The MACsec master device centrally manages the MACsec parameters and distributes them to the MACsec slave device to complete the configuration of the MACsec parameters. This simplifies the configuration of MACsec parameters, enables automatic deployment of MACsec parameters, and makes the deployment and maintenance of MACsec relatively simple, thus solving the problem of complex MACsec deployment.
[0055] In one example, when the first MACsec slave device sends a first parameter request message to the MACsec master device, the first parameter request message includes first MACsec expectation information. The first MACsec expectation information indicates that the first MACsec slave device expects to perform MACsec protection on the first interface, or the first MACsec expectation information indicates that the first MACsec slave device does not expect to perform MACsec protection on the first interface.
[0056] When the second MACsec slave device sends a second parameter request message to the MACsec master device, the second parameter request message may include second MACsec expectation information. The second MACsec expectation information indicates that the second MACsec slave device expects to perform MACsec protection on the second interface, or the second MACsec expectation information indicates that the second MACsec slave device does not expect to perform MACsec protection on the second interface.
[0057] The MACsec master device acquires the first MACsec parameters corresponding to the first MACsec slave device and the second MACsec parameters corresponding to the second MACsec slave device. This can include: if the first MACsec expectation information indicates that the first MACsec slave device expects to perform MACsec protection on the first interface, and the second MACsec expectation information indicates that the second MACsec slave device expects to perform MACsec protection on the second interface, then the first MACsec parameters corresponding to the first MACsec slave device are acquired, and the second MACsec parameters corresponding to the second MACsec slave device are also acquired. Alternatively, if the first MACsec expectation information indicates that the first MACsec slave device does not expect to perform MACsec protection on the first interface, and / or the second MACsec expectation information indicates that the second MACsec slave device does not expect to perform MACsec protection on the second interface, then the parameter configuration process ends, and the MACsec master device prohibits the acquisition of the MACsec parameters corresponding to the MACsec slave device.
[0058] In one example, there are two types of MACsec parameters. The first type of parameter allows two MACsec slave devices to use the same parameter value, while the second type of parameter allows two MACsec slave devices to use the same or different parameter values.
[0059] The MACsec master device obtains the first MACsec parameters corresponding to the first MACsec slave device and the second MACsec parameters corresponding to the second MACsec slave device, which may include: for each first type of parameter, obtaining a reference parameter value for that first type of parameter; wherein the reference parameter value is selected from a set of parameter values, or the reference parameter value is a default parameter value. For each second type of parameter, obtaining the first parameter value and the second parameter value for that second type of parameter, the first parameter value and the second parameter value may be the same or different; wherein the first parameter value is selected from a set of parameter values, or the first parameter value is a default parameter value; the second parameter value is selected from a set of parameter values, or the second parameter value is a default parameter value.
[0060] Obtain the first MACsec parameter, which includes a reference parameter value for each first type of parameter and a first parameter value for each second type of parameter; obtain the second MACsec parameter, which includes a reference parameter value for each first type of parameter and a second parameter value for each second type of parameter.
[0061] In one example, sending a first MACsec parameter to a first MACsec slave device and a second MACsec parameter to a second MACsec slave device may include: sending a first parameter response message to the first MACsec slave device, the first parameter response message including the interface identifier and MAC address of the first interface of the first MACsec slave device, the interface identifier and MAC address of the second interface of the second MACsec slave device, and the first MACsec parameter; and sending a second parameter response message to the second MACsec slave device, the second parameter response message including the interface identifier and MAC address of the second interface of the second MACsec slave device, the interface identifier and MAC address of the first interface of the first MACsec slave device, and the second MACsec parameter.
[0062] In one example, the first parameter request message and the second parameter request message include a first BGP update message, which includes a first NLRI field and a first MACsec attribute field. The first NLRI field includes an address family identifier and a variable-length NLRI field. The address family identifier indicates that the first NLRI field carries MACsec information, and the variable-length NLRI field includes an interface identifier and a MAC address. The first MACsec attribute field includes MACsec expectation information. The first parameter response message and the second parameter response message include a second BGP update message, which includes a second NLRI field and a second MACsec attribute field. The second NLRI field includes an address family identifier and a variable-length NLRI field. The address family identifier indicates that the second NLRI field carries MACsec information, and the variable-length NLRI field includes an interface identifier and a MAC address. The second MACsec attribute field includes MACsec parameters.
[0063] The parameter configuration method of this application embodiment will be described below in conjunction with specific application scenarios.
[0064] All devices are divided into MACsec master devices and MACsec slave devices. There can be one MACsec master device and at least two MACsec slave devices. For ease of description, we will use two MACsec slave devices as an example, and refer to them as the first MACsec slave device and the second MACsec slave device. When there are more MACsec slave devices, the parameter configuration process for the MACsec slave devices is similar.
[0065] For example, a Route Reflector (RR) can be used as a MACsec master device, or any other type of network device can be used as a MACsec master device; there are no restrictions on this. Similarly, network devices (such as routers and switches) can be used as MACsec slave devices, or any other type of network device can be used as a MACsec slave device, as long as the MACsec slave device has traffic forwarding requirements.
[0066] Referring to Figure 2, which is a network topology diagram of a MACsec network, network device C acts as the MACsec master device, and network devices A and B act as MACsec slave devices. For example, network device A can act as the first MACsec slave device and network device B as the second MACsec slave device, or network device A can act as the second MACsec slave device and network device B as the first MACsec slave device.
[0067] In Figure 2, interface a1 of network device A (such as the first MACsec slave device) and interface b1 of network device B (such as the second MACsec slave device) are connected. Interface a1 can be referred to as the first interface of the first MACsec slave device, and interface b1 can be referred to as the second interface of the second MACsec slave device.
[0068] In one example, a MACsec master device can establish BGP (Border Gateway Protocol) neighbors with each MACsec slave device, and MACsec slave devices can establish LLDP (Link Layer Discovery Protocol) neighbors with each other.
[0069] In Figure 2, network device C establishes a BGP neighbor relationship with network device A, network device C establishes a BGP neighbor relationship with network device B, and network device A establishes an LLDP neighbor relationship with network device B.
[0070] For example, LLDP provides a link layer discovery method that enables devices from different vendors to discover each other and exchange information in the network. LLDP encapsulates the information of the local device (such as main capabilities, management address, device identifier, interface identifier, etc.) in LLDPDU (Link Layer Discovery Protocol Data Unit) and publishes it to directly connected neighbors. The neighbors then save this information after receiving it.
[0071] In the above application scenario, this application proposes a parameter configuration method. Referring to Figure 3, which is a flowchart of the parameter configuration method, the parameter configuration method may include:
[0072] Step 301: The first MACsec slave device obtains the interface identifier and MAC address of the neighbor interface of the neighbor device. The neighbor device is the second MACsec slave device connected to the first MACsec slave device.
[0073] The second MACsec slave device obtains the interface identifier and MAC address of the neighbor interface of the neighbor device. The neighbor device is the first MACsec slave device connected to the second MACsec slave device.
[0074] Referring to Figure 2, the first interface (e.g., interface a1) of the first MACsec slave device (e.g., network device A) and the second interface (e.g., interface b1) of the second MACsec slave device (e.g., network device B) are connected, and the first MACsec slave device and the second MACsec slave device establish an LLDP neighbor relationship. Based on this, the first MACsec slave device can obtain the LLDP neighbor information of the second MACsec slave device, and the LLDP neighbor information may include the interface identifier of the second interface of the second MACsec slave device and the MAC address of the second interface. Similarly, the second MACsec slave device can obtain the LLDP neighbor information of the first MACsec slave device, and the LLDP neighbor information may include the interface identifier of the first interface of the first MACsec slave device and the MAC address of the first interface.
[0075] Step 302: The first MACsec slave device sends a first parameter request message to the MACsec master device, and the MACsec master device receives the first parameter request message sent by the first MACsec slave device.
[0076] In one example, the first parameter request message may include the interface identifier and MAC address of the first interface (i.e., the local interface) of the first MACsec slave device, the interface identifier and MAC address of the neighbor interface of the neighbor device of the first MACsec slave device, and the neighbor interface of the neighbor device is connected to the first interface. For example, the neighbor interface of the neighbor device may be the second interface of the second MACsec slave device.
[0077] For example, as shown in Figure 2, the first parameter request message may include physical link neighbor relationships obtained based on LLDP, and the physical link neighbor relationships may include, but are not limited to: the interface identifier (e.g., 1 / 0 / 1) and MAC address (e.g., 1-1-1) of interface a1 of network device A, the interface identifier (e.g., 2 / 0 / 1) and MAC address (e.g., 2-2-2) of interface b1 of network device B, and interface b1 is connected to interface a1.
[0078] In one example, when the first MACsec slave device sends a first parameter request message to the MACsec master device, the first parameter request message includes first MACsec expectation information, which indicates whether the first MACsec slave device expects MACsec protection. The first MACsec expectation information indicates that the first MACsec slave device expects MACsec protection for the first interface, or it indicates that the first MACsec slave device does not expect MACsec protection for the first interface.
[0079] In one example, the first MACsec slave device determines whether the first interface has the MACsec desire function enabled. If the first interface has the MACsec desire function enabled, it means that MACsec protection is desired. Therefore, the first MACsec slave device sends a first parameter request message to the MACsec master device, and the first MACsec desire information indicates that the first MACsec slave device desires MACsec protection for the first interface.
[0080] If the MACsec desire function is not enabled on the first interface, it means that MACsec protection is not desired. Therefore, the first MACsec slave device does not send the first parameter request message to the MACsec master device.
[0081] In one example, when the first MACsec slave device sends a first parameter request message to the MACsec master device, it can also encrypt the first parameter request message and send the encrypted first parameter request message to the MACsec master device. For example, it can use SSL (Secure Sockets Layer) encryption or IPsec (IP Security) encryption. For instance, SSL is a security protocol that provides secure connections for TCP-based application layer protocols (such as BGP and HTTP). IPsec is a Layer 3 tunneling encryption protocol that provides high-quality, cryptographically-based security guarantees for data.
[0082] In one example, the first parameter request message can include a BGP update message, that is, a BGP update message as the first parameter request message. Of course, other protocol messages of BGP type can also be used as the first parameter request message, or other protocol messages of non-BGP type can be used as the first parameter request message. There are no restrictions on this. The BGP update message will be used as an example for explanation.
[0083] BGP update messages may include an NLRI (Network Layer Reachability Information) field and a MACsec attribute field. The NLRI field may include an address family identifier and a variable-length NLRI field. The address family identifier indicates that the NLRI field carries MACsec information. The variable-length NLRI field may include an interface identifier and a MAC address, such as the interface identifier and MAC address of the first interface of a first MACsec slave device, or the interface identifier and MAC address of the second interface of a second MACsec slave device. The MACsec attribute field may include first MACsec expectation information, indicating that the first MACsec slave device expects MACsec protection for the first interface.
[0084] For example, for BGP update messages, a new NLRI field can be defined, called the MACsec NLRI field, as shown in Figure 4A. The MACsec NLRI field can include an AFI (Address Family Identifier) field, a SAFI (Subsequent Address Family Identifier) field, an NLRI length field, and a variable-length NLRI field. The AFI and SAFI fields represent address family identifiers, indicating that the NLRI field carries MACsec information. For example, the AFI field can be an unused AFI value representing the MACsec address family and can be 2 bytes. The SAFI field can be any value representing the MACsec and can be 1 byte; other values in the SAFI field are reserved. The NLRI length field indicates the length of the MACsec NLRI field and can be 1 byte.
[0085] For example, regarding variable-length NLRI fields, see Figure 4B, which is a schematic diagram of a variable-length NLRI field. A variable-length NLRI field can include a length field (e.g., 2 bytes), a node ID field (e.g., 4 bytes), a local interface ID field (e.g., 9 bytes), a local interface MAC field (e.g., 6 bytes), a neighbor interface ID field (e.g., 9 bytes), and a neighbor interface MAC field (e.g., 6 bytes). Variable-length NLRI fields are not limited to the above fields.
[0086] The length field indicates the length of the variable-length NLRI field. The node identifier field is the Router ID configured in the local BGP, which can be the IP address of the first MACsec slave device, such as 1.1.1.1. The local interface identifier field is the interface ID of the local interface with MACsec desire enabled, which can be the interface identifier of the first interface of the first MACsec slave device, such as 1 / 0 / 1. The local interface MAC field is the MAC address of the local interface with MACsec desire enabled, which can be the MAC address of the first interface of the first MACsec slave device, such as 1-1-1. The neighbor interface identifier field is the neighbor interface ID discovered by the first interface using LLDP, which can be the interface identifier of the second interface of the second MACsec slave device, such as 2 / 0 / 1. The neighbor interface MAC field is the neighbor interface MAC address discovered by the first interface using LLDP, which can be the MAC address of the second interface of the second MACsec slave device, such as 2-2-2. For the local interface identifier field and the neighbor interface identifier field, the ASCII values of English letters and forward slashes in the interface identifier can also be converted to binary representation.
[0087] In one example, for the MACsec attribute field of a BGP update message, the MACsec attribute field can be placed before or after the MACsec NLRI field. See Figure 4C for a schematic diagram of the MACsec attribute field. The MACsec attribute field can include a type field (e.g., 2 bytes), a length field (e.g., 2 bytes), and a value field (e.g., variable length).
[0088] The type field can indicate the type of the MACsec attribute field. For example, when the type field is 0, it means that the MACsec attribute field is sent by the MACsec slave device, and when the type field is 1, it means that the MACsec attribute field is sent by the MACsec master device. Therefore, when the first MACsec slave device sends the first parameter request message to the MACsec master device, the type field is 0.
[0089] The length field can represent the length of the MACsec attribute field. The value field can represent the value of the MACsec attribute field. For example, the value field of the MACsec attribute field can be a MACsec option field. See Figure 4D, which is a schematic diagram of a MACsec attribute field. A MACsec attribute field can include a type field, a length field, and a MACsec option field (e.g., 1 byte). For example, the MACsec option field includes first MACsec expectation information, which indicates that the first MACsec slave device expects MACsec protection for the first interface.
[0090] Referring to Figure 4E, which illustrates the MACsec option field, the MACsec option field can include a MACsec Desire Option field (e.g., 1 bit) and a Reserve field (e.g., 7 bits). The value of the MACsec Desire Option field is 0 or 1 (binary), where 0 indicates that MACsec protection is not desired and 1 indicates that MACsec protection is desired. When the first MACsec slave device sends a first parameter request message to the MACsec master device, the value of the MACsec Desire Option field is 1.
[0091] Step 303: The second MACsec slave device sends a second parameter request message to the MACsec master device, and the MACsec master device receives the second parameter request message sent by the second MACsec slave device.
[0092] In one example, the second parameter request message may include the interface identifier and MAC address of the second interface (i.e., the local interface) of the second MACsec slave device, the interface identifier and MAC address of the neighbor interface of the neighbor device of the second MACsec slave device, and the neighbor interface of the neighbor device is connected to the second interface. For example, the neighbor interface of the neighbor device may be the first interface of the first MACsec slave device.
[0093] For example, as shown in Figure 2, the second parameter request message may include the interface identifier (e.g., 2 / 0 / 1) and MAC address (e.g., 2-2-2) of interface b1 of network device B, and the interface identifier (e.g., 1 / 0 / 1) and MAC address (e.g., 1-1-1) of interface a1 of network device A, with interface a1 connected to interface b1.
[0094] In one example, when the second MACsec slave device sends a second parameter request message to the MACsec master device, the second parameter request message includes second MACsec expectation information. This second MACsec expectation information indicates whether the second MACsec slave device expects MACsec protection. Alternatively, it may indicate that the second MACsec slave device expects MACsec protection for the second interface, or that it does not expect MACsec protection for the second interface.
[0095] In one example, the second parameter request message may include a BGP update message. The BGP update message may include an NLRI field and a MACsec attribute field. The NLRI field includes an address family identifier and a variable-length NLRI field. The address family identifier indicates that the NLRI field carries MACsec information. The variable-length NLRI field may include an interface identifier and a MAC address, such as the interface identifier and MAC address of the second interface of the second MACsec slave device, or the interface identifier and MAC address of the first interface of the first MACsec slave device. The MACsec attribute field may include second MACsec expectation information, indicating that the second MACsec slave device expects MACsec protection for the second interface.
[0096] In one example, step 303 is similar to step 302, and will not be repeated here.
[0097] Step 304: If it is determined that the first interface and the second interface are successfully paired based on the first parameter request message and the second parameter request message, the MACsec master device generates a MACsec pairing table. This MACsec pairing table is used to record the interface identifiers of the successfully paired first interface and the second interface, and the MAC address of the second interface.
[0098] In one example, the MACsec master device can obtain the interface identifier and MAC address of the first interface of the first MACsec slave device, and the interface identifier and MAC address of the neighbor interface of the neighbor device of the first MACsec slave device, from the first parameter request message. The MACsec master device can obtain the interface identifier and MAC address of the second interface of the second MACsec slave device, and the interface identifier and MAC address of the neighbor interface of the neighbor device of the second MACsec slave device, from the second parameter request message.
[0099] If the interface identifier of the neighbor interface of the first MACsec slave device's neighbor device is the same as the interface identifier of the second interface of the second MACsec slave device, the MAC address of the neighbor interface of the first MACsec slave device's neighbor device is the same as the MAC address of the second interface of the second MACsec slave device, the interface identifier of the neighbor interface of the second MACsec slave device's neighbor device is the same as the interface identifier of the first interface of the first MACsec slave device, and the MAC address of the neighbor interface of the second MACsec slave device's neighbor device is the same as the MAC address of the first interface of the first MACsec slave device, then the MACsec master device determines that the first interface and the second interface are successfully paired and generates a MACsec pairing table. Otherwise, the MACsec master device determines that the first interface and the second interface have failed to pair and does not generate a MACsec pairing table.
[0100] The MACsec pairing table may include the interface identifier and MAC address of the first interface of the first MACsec slave device, and the interface identifier and MAC address of the second interface of the second MACsec slave device. See Table 1 for an example of a MACsec pairing table. There are no restrictions on this MACsec pairing table.
[0101] Table 1
[0102] Step 305: The MACsec master device obtains the first MACsec expectation information from the first parameter request message, obtains the second MACsec expectation information from the second parameter request message, and adds the first MACsec expectation information and the second MACsec expectation information to the MACsec pairing table.
[0103] For example, the first MACsec expectation information indicates that the first MACsec slave device expects to perform MACsec protection on the first interface, or the first MACsec expectation information indicates that the first MACsec slave device does not expect to perform MACsec protection on the first interface. Similarly, the second MACsec expectation information indicates that the second MACsec slave device expects to perform MACsec protection on the second interface, or the second MACsec expectation information indicates that the second MACsec slave device does not expect to perform MACsec protection on the second interface.
[0104] See Table 2 for an example of the updated MACsec pairing table. In Table 2, MACsec Desire is set to "Yes," indicating that MACsec protection is desired for either the first or second interface.
[0105] Table 2
[0106] Step 306: If the first MACsec expectation information indicates that the first MACsec slave device expects to perform MACsec protection on the first interface, and the second MACsec expectation information indicates that the second MACsec slave device expects to perform MACsec protection on the second interface, then the MACsec master device obtains the first MACsec parameter corresponding to the first MACsec slave device and the second MACsec parameter corresponding to the second MACsec slave device.
[0107] In one example, to implement MACsec communication, multiple types of MACsec parameters need to be configured, and among all types of MACsec parameters, there are first-type and second-type parameters. The first-type parameter allows two MACsec slave devices to use the same parameter value, while the second-type parameter allows two MACsec slave devices to use the same or different parameter values.
[0108] For example, all MACsec parameters contain a first type of parameter A (such as first type of parameter A1, first type of parameter A2, ...) and a second type of parameter B (such as second type of parameter B1, second type of parameter B2, ...).
[0109] For each first-class parameter, the MACsec master device can obtain a reference parameter value for that first-class parameter. The reference parameter value can be selected from the set of parameter values, or it can be a pre-configured parameter value (such as a user-configured parameter value), or it can be a default parameter value.
[0110] For example, for parameter A1 of the first type (the implementation process for other parameters of the first type is similar), a set of parameter values can be pre-configured for parameter A1. This set of parameter values can include multiple parameter values for parameter A1. The MACsec master device can select a parameter value from this set of parameter values as the reference parameter value for parameter A1. For example, it can randomly select a parameter value as the reference parameter value for parameter A1, or it can use a certain strategy to select a parameter value (such as prioritizing the minimum value, prioritizing the maximum value, etc.) as the reference parameter value for parameter A1. There are no restrictions on this selection method.
[0111] For example, for the first type of parameter A1, the user can pre-configure a reference parameter value for the first type of parameter A1. In this way, the parameter value configured by the user can be used as the reference parameter value for the first type of parameter A1.
[0112] For example, for parameter A1 of type 1, the default parameter value (i.e., the default parameter value) can be used as the reference parameter value for parameter A1 of type 1. For example, if no reference parameter value is selected from the parameter value set, and the user has not pre-configured a reference parameter value, it means that the reference parameter value for parameter A1 of type 1 is the default value. Therefore, the default parameter value (i.e., the fixed parameter value) is used as the reference parameter value for parameter A1 of type 1.
[0113] The above are just examples of obtaining reference parameter values for the first type of parameter, and there are no restrictions on the method of obtaining them.
[0114] For each second-type parameter, the MACsec master device can obtain the first parameter value and the second parameter value. The first parameter value and the second parameter value can be the same or different. The first parameter value can be selected from a set of parameter values, or it can be a pre-configured parameter value (such as a user-configured parameter value), or it can be a default parameter value. The second parameter value can also be selected from a set of parameter values, or it can be a pre-configured parameter value (such as a user-configured parameter value), or it can be a default parameter value.
[0115] For example, for the second type of parameter B1 (the implementation process for other second type parameters is similar), a set of parameter values can be pre-configured for B1. This set of parameter values can include multiple parameter values for B1. The MACsec master device can select a parameter value from this set as the first parameter value of B1, such as randomly selecting a parameter value or using a certain strategy (e.g., prioritizing the minimum value, prioritizing the maximum value, etc.). Similarly, the MACsec master device can select a parameter value from this set as the second parameter value of B1, such as randomly selecting a parameter value or using a certain strategy (e.g., prioritizing the minimum value, prioritizing the maximum value, etc.).
[0116] When selecting the first and second parameter values for the second type of parameter B1, the same parameter value can be used as the first and second parameter values, or different parameter values can be used as the first and second parameter values.
[0117] For example, regarding parameter B1 of the second type, the user can pre-configure a first parameter value for parameter B1, and the user can also pre-configure a second parameter value for parameter B1. In this way, the user-configured parameter values can be used as the first and second parameter values for parameter B1. When configuring the first and second parameter values for parameter B1, the same parameter value can be configured as both the first and second parameter values, or different parameter values can be configured as both the first and second parameter values.
[0118] For example, regarding parameter B1 of the second type, a default parameter value (i.e., the default parameter value) can be used as the first parameter value of parameter B1, and a default parameter value (i.e., the default parameter value) can be used as the second parameter value of parameter B1. For instance, if neither the first nor the second parameter value is selected from the parameter value set, and the user has not pre-configured either the first or the second parameter value, then the parameter value of parameter B1 is the default value. Therefore, the default parameter value (i.e., the fixed parameter value) is used as both the first and second parameter values of parameter B1. For example, the same default parameter value can be used as both the first and second parameter values, or different default parameter values can be used as both the first and second parameter values.
[0119] The above are just examples of obtaining the parameter values of the second type of parameter, and there are no restrictions on the method of obtaining them.
[0120] In one example, the MACsec master device acquires first MACsec parameters and second MACsec parameters based on the reference parameter value of each first-type parameter and the first and second parameter values of each second-type parameter. The first MACsec parameters may include the reference parameter value of each first-type parameter and the first parameter value of each second-type parameter. The second MACsec parameters may include the reference parameter value of each first-type parameter and the second parameter value of each second-type parameter. For example, the first MACsec parameters may include the reference parameter value of first-type parameter A1, the reference parameter value of first-type parameter A2, ..., the first parameter value of second-type parameter B1, the first parameter value of second-type parameter B2, ... Furthermore, the second MACsec parameters may include the reference parameter value of first-type parameter A1, the reference parameter value of first-type parameter A2, ..., the second parameter value of second-type parameter B1, the second parameter value of second-type parameter B2, ...
[0121] In one example, after obtaining the first MACsec parameter and the second MACsec parameter, the first MACsec parameter and the second MACsec parameter can also be added to the MACsec pairing table.
[0122] See Table 3 for an example of the updated MACsec pairing table.
[0123] Table 3
[0124] For the first type of parameter A1, the first MACsec slave device and the second MACsec slave device use the same parameter value a1. For the second type of parameter B1, the first MACsec slave device uses parameter value b11, and the second MACsec slave device uses parameter value b12, where parameter value b12 may be the same as or different from parameter value b11.
[0125] In one example, the first MACsec parameter and the second MACsec parameter include, but are not limited to, at least one of the following parameter values: Connection association key name, which is a first-type parameter, and both the first and second MACsec parameters include the same connection association key name; Pre-shared key, which is a first-type parameter, and both the first and second MACsec parameters include the same pre-shared key; Session timeout, which is a second-type parameter, and both the first and second MACsec parameters include the same session timeout, or include different session timeouts; MACsec replay protection window size, which is a second-type parameter, and both the first and second MACsec parameters include the same MACsec replay protection window size, or include different MACsec replay protection window sizes; and MACsec encryption offset, which is a first-type parameter, and both the first and second MACsec parameters include the same MACsec encryption offset.
[0126] The MACsec cipher suite option can be a second-class parameter, where the first and second MACsec parameters include the same or different MACsec cipher suite options. The secure channel identifier option can be a first-class parameter, where the first and second MACsec parameters include the same secure channel identifier option. The shared key option can be a first-class parameter, where the first and second MACsec parameters include the same shared key option. The replay protection option can be a second-class parameter, where the first and second MACsec parameters include the same or different replay protection option. The verification mode option can be a second-class parameter, where the first and second MACsec parameters include the same or different verification mode options. The maintenance mode option can be a second-class parameter, where the first and second MACsec parameters include the same or different maintenance mode options.
[0127] For example, see Table 4, which shows an example of the updated MACsec pairing table.
[0128] Table 4
[0129] Step 307: The MACsec master device sends the first MACsec parameter to the first MACsec slave device, and the first MACsec slave device receives the first MACsec parameter sent by the MACsec master device.
[0130] In one example, a MACsec master device can send a first parameter response message to a first MACsec slave device. This first parameter response message may include the interface identifier and MAC address of the first interface of the first MACsec slave device, the interface identifier and MAC address of the second interface of the second MACsec slave device, and the first MACsec parameters. The MACsec master device can obtain this information from the MACsec pairing table.
[0131] In one example, when a MACsec master device sends a first parameter response message to a first MACsec slave device, it can also encrypt the first parameter response message and send the encrypted first parameter response message to the first MACsec slave device. For example, the first parameter response message can be encrypted using SSL encryption or IPsec encryption.
[0132] In one example, the first parameter response message can include a BGP update message, that is, a BGP update message as the first parameter response message. Of course, other protocol messages of BGP type can also be used as the first parameter response message, or other protocol messages of non-BGP type can be used as the first parameter response message. There are no restrictions on this. The BGP update message will be used as an example for explanation.
[0133] BGP update messages may include an NLRI field and a MACsec attribute field. The NLRI field may include an address family identifier and a variable-length NLRI field. The address family identifier indicates that the NLRI field carries MACsec information. The variable-length NLRI field includes an interface identifier and a MAC address, such as the interface identifier and MAC address of the first interface of a first MACsec slave device, or the interface identifier and MAC address of the second interface of a second MACsec slave device. Additionally, the MACsec attribute field may include a first MACsec parameter.
[0134] For example, the NLRI field can be a MACsec NLRI field. The content of the MACsec NLRI field is the same as that of the MACsec NLRI field in the first parameter request message, as described in step 302.
[0135] In one example, for the MACsec attribute field of a BGP update message, the MACsec attribute field can be placed before or after the MACsec NLRI field. See Figure 5A for a schematic diagram of the MACsec attribute field. The MACsec attribute field can include, but is not limited to, the following fields:
[0136] The Type field (e.g., 2 bytes) indicates the type of the MACsec attribute field. For example, a value of 0 indicates that the MACsec attribute field was sent by a MACsec slave device, and a value of 1 indicates that the MACsec attribute field was sent by a MACsec master device. Therefore, when a MACsec master device sends a first parameter response message to the first MACsec slave device, the Type field is set to 1. The Length field (e.g., 2 bytes) indicates the length of the MACsec attribute field. The MACsec Option field (e.g., 2 bytes) carries some parameter values; see the following section for details on the MACsec Option field.
[0137] In addition to the type field, length field, and MACsec option field, the MACsec attribute field can also relate to fields related to the first MACsec parameter, specifically the following first MACsec parameter:
[0138] The Connection Association Key Name field carries the connection association key name, also known as the CKN Name (Connectivity Association Key Name) or Shared key CKN Name. For example, the connection association key name field can be 32 bytes or 64 bytes; there is no restriction on this.
[0139] The connection association key name is used to uniquely identify the pre-shared CAK (Connectivity Association Key) to distinguish different security association groups. For example, during MACsec parameter-based session negotiation, the negotiation message carries the connection association key name. Only when the first MACsec slave device and the second MACsec slave device use the same connection association key name can they be identified as the same CA (Connectivity Association). If the first MACsec slave device and the second MACsec slave device use different connection association key names, they cannot be identified as the same CA, and the session negotiation process terminates. Here, a CA is a set of two or more members using the same key and key algorithm suite.
[0140] Configure the same connection association key name 1 on the first interface of the first MACsec slave device and the second interface of the second MACsec slave device. The other interfaces of the first MACsec slave device cannot be configured with this connection association key name 1, but can only be configured with other connection association key names. The other interfaces of the second MACsec slave device cannot be configured with this connection association key name 1, but can only be configured with other connection association key names.
[0141] The pre-shared key field carries the pre-shared key, also known as the MACsec MKA CAK. The MKA protocol is part of MACsec and is used to discover MACsec peers and negotiate the necessary security keys to protect the link. The CAK is the key used by the CA participants. MACsec MKA CAK is simply referred to as the pre-shared key. For example, the pre-shared key field can be 64 bytes or 117 bytes.
[0142] The pre-shared key can be used as the root key. The pre-shared key is used to generate the session key, that is, to derive the session key. The session key can be a SAK (Security Association Key). The SAK is derived from the pre-shared key according to the algorithm and is used to encrypt data transmitted between secure channels.
[0143] For example, the session key is used to encrypt data packets between the first MACsec slave device and the second MACsec slave device. The first MACsec slave device encrypts the data packet using the session key and sends the encrypted data packet to the second MACsec slave device. The second MACsec slave device encrypts the data packet using the session key and sends the encrypted data packet to the first MACsec slave device.
[0144] During MACsec parameter-based session negotiation, the first MACsec slave device generates key derivation parameters (such as a nonce) using a pre-shared key, and carries these parameters in the negotiation message. The second MACsec slave device verifies the legitimacy of the first MACsec slave device using the pre-shared key and the key derivation parameters. If legitimate, the session negotiation process continues; otherwise, it terminates.
[0145] For example, during session negotiation based on MACsec parameters, the pre-shared key used by the first MACsec slave device and the second MACsec slave device is directly configured. To ensure that the session between the first MACsec slave device and the second MACsec slave device can be established normally, the same pre-shared key is configured on the first interface of the first MACsec slave device and the second interface of the second MACsec slave device.
[0146] When generating a session key based on a pre-shared key (i.e., key derivation), the AES-Key Wrap algorithm can be used to generate the session key by combining the pre-shared key and a random number, and there are no restrictions on this process.
[0147] To address the security requirements of pre-shared keys, they can be securely distributed offline, and their length must meet the requirements of the cryptographic suite, such as being 256 bits long.
[0148] The session timeout field is used to carry the session timeout period, namely MKA Timer MKA-life (MKA session timeout period). The session timeout field can be 2 bytes.
[0149] The session timeout period is used to control the lifespan of a session. After a session timeout is determined based on the session timeout period, a renegotiation is triggered, which means that the session negotiation process based on the MACsec parameter is re-executed.
[0150] During MACsec parameter-based session negotiation, the negotiation message carries the session timeout (the session timeout can also be called the exchange timeout, such as 60s). Based on this, the first MACsec slave device can use the smaller value of the session timeout as the target session timeout, and the second MACsec slave device can also use the smaller value of the session timeout as the target session timeout.
[0151] During data packet transmission between the first MACsec slave device and the second MACsec slave device, if the first MACsec slave device does not receive a data packet from the second MACsec slave device within the target session timeout period, the session is deemed to have timed out, the current session key is terminated, and renegotiation begins. Similarly, if the second MACsec slave device does not receive a data packet from the first MACsec slave device within the target session timeout period, the session is deemed to have timed out, the current session key is terminated, and renegotiation begins.
[0152] The MACsec replay protection window size field is used to store the size of the MACsec replay protection window, also known as the Replay Window. The MACsec replay protection window size field can be 4 bytes.
[0153] The MACsec replay protection window size is used to prevent attackers from replaying old packets, and this is achieved by maintaining a PN (Packet Number) window. The MACsec replay protection window size is used to discard replayed data packets between the first MACsec slave device and the second MACsec slave device.
[0154] For example, the first MACsec slave device can determine the PN window range based on the MACsec replay protection window size. If the MACsec replay protection window size is 64 and the PN window range is 37-100, then if the data packet is not within the PN window range, such as if the sequence number of the data packet is less than the lower limit of the PN window range, the first MACsec slave device will discard the data packet and will no longer forward the data packet.
[0155] During session negotiation based on MACsec parameters, the negotiation message may include the MACsec replay protection window size, which represents the maximum allowed PN interval. The first MACsec slave device informs the second MACsec slave device of its own MACsec replay protection window size via the negotiation message, but determines the PN window range based on this first MACsec slave device's MACsec replay protection window size. The second MACsec slave device informs the first MACsec slave device of its own MACsec replay protection window size via the negotiation message.
[0156] When the MACsec replay protection window size is 0, it means that out-of-order or duplicate data packets are not allowed to be received. The MACsec replay protection window size is only effective when the replay protection function is enabled.
[0157] The MACsec encryption offset field is used to carry the MACsec encryption offset, which can be called MACsec Confidentiality-Offset or MACsec Encryption Offset. The MACsec encryption offset field can be 1 byte.
[0158] The MACsec encryption offset indicates the starting encryption position of data packets between the first and second MACsec slave devices, and supports flexible encapsulation formats (such as whether VLAN tags are encrypted). For example, if the MACsec encryption offset is 16, it means that encryption starts from the 16th byte of the data packet. The value of the MACsec encryption offset can include 0 (decimal), 30 (decimal), and 50 (decimal), etc., and the unit effective on the MACsec slave device is bytes.
[0159] During MACsec parameter-based session negotiation, the negotiation message carries the MACsec encryption offset. If the first MACsec slave device and the second MACsec slave device use the same MACsec encryption offset, the session negotiation process continues. If the first MACsec slave device and the second MACsec slave device use different MACsec encryption offsets, the negotiation fails and the session negotiation process terminates.
[0160] In one example, when MACsec uses the GCM-AES-128 or GCM-AES-XPN-128 encryption suite, the connection key name and pre-shared key can be required to be 32 characters long. Based on this, for connection key names shorter than 32 characters, zeros can be added to the end to reach 32 characters. For connection key names longer than 32 characters, the first 32 characters can be used. Similarly, for pre-shared keys shorter than 32 characters, zeros can be added to the end to reach 32 characters. For pre-shared keys longer than 32 characters, the first 32 characters can be used.
[0161] Furthermore, for the GCM-AES-128 cipher suite, the MACsec encryption offset can be any value. For the GCM-AES-XPN-128 cipher suite, the MACsec encryption offset can be 0.
[0162] In one example, when MACsec uses the GCM-AES-256 or GCM-AES-XPN-256 encryption suite, the connection association key name and pre-shared key can be required to be 64 characters long. Based on this, for connection association key names shorter than 64 characters, zeros can be added to the end to reach 64 characters. For connection association key names longer than 64 characters, the first 64 characters can be retrieved. Similarly, for pre-shared keys shorter than 64 characters, zeros can be added to the end to reach 64 characters. For pre-shared keys longer than 64 characters, the first 64 characters can be retrieved.
[0163] Furthermore, for the GCM-AES-256 cipher suite, the MACsec encryption offset can be any value. For the GCM-AES-XPN-256 cipher suite, the MACsec encryption offset can be 0.
[0164] In one example, as shown in Figure 5A, the MACsec attribute field may include a MACsec option field (e.g., 2 bytes). Figure 5B shows a schematic diagram of the MACsec option field. The MACsec option field may relate to fields of the first MACsec parameter, specifically the following first MACsec parameter:
[0165] The MACsec Cipher Suite Option is a 6-bit option that indicates the list of cipher suites supported by the first MACsec slave device. For example, the value of the MACsec Cipher Suite Option can range from 1 to 100 (decimal), starting from 1, which corresponds to cipher suites such as GCM-AES-128, GCM-AES-256, GCM-AES-XPN-128, and GCM-AES-XPN-256.
[0166] During MACsec parameter-based session negotiation, negotiation messages can include a list of cipher suites, enabling capability exchange. For example, when a first MACsec slave device sends a negotiation message to a second MACsec slave device, this message carries the first MACsec slave device's list of cipher suites. Based on these lists, the second MACsec slave device determines which cipher suites are supported by both devices (e.g., the highest priority cipher suite) and performs encryption on data packets using these cipher suites. Similarly, when a second MACsec slave device sends a negotiation message to a first MACsec slave device, this message carries its own list of cipher suites. Based on these lists, the first MACsec slave device determines which cipher suites are supported by both devices (e.g., the highest priority cipher suite) and performs encryption on data packets using these cipher suites.
[0167] The Secure Channel Identifier (SCIOption) option can be 1 bit. This option indicates whether data packets between the first MACsec slave device and the second MACsec slave device carry a secure channel identifier. For example, the SCIOption option can be 0 or 1; 0 represents not carrying a secure channel identifier, and 1 represents carrying a secure channel identifier.
[0168] Because MACsec functionality may differ in its implementation, if the SecTAG (Security Label) of a data packet from the first MACsec slave device carries an SCI (Secure Channel Identifier), while the SecTAG of a data packet from the second MACsec slave device does not, then data packets from the first and second MACsec slave devices will not communicate. By configuring the Secure Channel Identifier option, it can be ensured that the configurations regarding whether or not to carry an SCI are consistent between the first and second MACsec slave devices; that is, both devices either carry an SCI, or neither device carries an SCI.
[0169] For example, during MACsec parameter-based session negotiation, the negotiation message may include a secure channel identifier option. If the first MACsec slave device and the second MACsec slave device use the same secure channel identifier option (e.g., both 1 or both 0), the session negotiation process continues. If the first MACsec slave device and the second MACsec slave device use different secure channel identifier options, the session negotiation process terminates. This process ensures that the secure channel identifier options of the two devices are consistent.
[0170] If the second MACsec slave device (or the first MACsec slave device) indicates that it should carry a secure channel identifier, then the first MACsec slave device (or the second MACsec slave device) will perform collision detection on the secure channel identifier during data packet transmission. Alternatively, if the second MACsec slave device indicates that it should not carry a secure channel identifier, then the first MACsec slave device will not perform collision detection on the secure channel identifier during data packet transmission. For example, the secure channel identifier can consist of the interface's MAC address and interface identifier, used to identify the source of the data packet.
[0171] The Shared key option, which can be 1 bit, indicates whether the key distribution method for data packets between the first MACsec slave device and the second MACsec slave device is ciphertext or plaintext. For example, the shared key option can take the value 0 or 1. 0 represents Cipher, meaning the key distribution method uses ciphertext (the key is in ciphertext), and 1 represents Simple, meaning the key distribution method uses plaintext (the key is in plaintext).
[0172] For example, during a MACsec parameter-based session negotiation, the negotiation message may include shared key options. If the first MACsec slave device and the second MACsec slave device use the same shared key options (e.g., both 1 or both 0), the session negotiation process continues. If the first MACsec slave device and the second MACsec slave device use different shared key options, the session negotiation process terminates.
[0173] For example, when using ciphertext mode for key distribution, the key can be encrypted and transmitted as ciphertext when transmitting the key for data packets between the first MACsec slave device and the second MACsec slave device. When using plaintext mode for key distribution, the plaintext key can be transmitted when transmitting the key for data packets between the first MACsec slave device and the second MACsec slave device.
[0174] The Replay-protection Option is a 1-bit option used to indicate whether replay protection is enabled or disabled for data packets between the first MACsec slave device and the second MACsec slave device. For example, the value can be 0 or 1. 0 means replay protection is disabled (off), and 1 means replay protection is enabled (on).
[0175] For example, during MACsec parameter-based session negotiation, the negotiation message may include replay protection options. Based on the replay protection options of the second MACsec slave device, the first MACsec slave device can know whether the second MACsec slave device has enabled or disabled replay protection. Furthermore, based on the replay protection options of the first MACsec slave device, the second MACsec slave device can know whether the first MACsec slave device has enabled or disabled replay protection.
[0176] For example, if replay protection is enabled, data packets may be rearranged when transmitting data packets between the first MACsec slave device and the second MACsec slave device. The MACsec replay protection mechanism allows for a certain degree of out-of-order data packets. These out-of-order data packets can be legally received if their sequence numbers are within a user-specified window range; otherwise, data packets outside the window range will be discarded.
[0177] For example, if replay protection is disabled, out-of-order data packets will be discarded and not legally received when transmitting data packets between the first MACsec slave device and the second MACsec slave device.
[0178] The Validation Mode Option is a 2-bit option that indicates whether to perform integrity checks on data packets between the first and second MACsec slave devices. If integrity checks are performed, the option indicates whether to discard data packets that fail the checks. For example, the option can be 00, 01, or 10, where 00 represents disabled mode, 01 represents check mode, and 10 represents strict mode. Check mode performs integrity checks on data packets between the first and second MACsec slave devices without discarding those that fail. Disabled mode disables integrity checks on data packets between the first and second MACsec slave devices. Strict mode performs integrity checks on data packets between the first and second MACsec slave devices and discards those that fail the checks.
[0179] For example, during session negotiation based on MACsec parameters, the negotiation message may include verification mode options. Based on the verification mode options of the second MACsec slave device, the first MACsec slave device can learn the verification mode of the second MACsec slave device. Based on the verification mode options of the first MACsec slave device, the second MACsec slave device can learn the verification mode of the first MACsec slave device.
[0180] For example, if the verification mode is check mode, the first MACsec slave device (or the second MACsec slave device) needs to perform integrity verification on the data packet. If the verification fails, the data packet is not discarded. If the verification mode is disabled mode, the first MACsec slave device does not perform integrity verification on the data packet. If the verification mode is strict verification mode, the first MACsec slave device performs integrity verification on the data packet. If the verification fails, the data packet is discarded.
[0181] For example, when performing integrity verification on data packets, the session key derived from the pre-shared key can be used to calculate the Integrity Check Value (ICV) to obtain the first ICV. The data packet's trailer carries the second ICV (i.e., the ICV calculated in the same way). Then, the first ICV and the second ICV are compared. If they are the same, the verification is successful; otherwise, the verification fails.
[0182] The maintenance-mode option is a 1-bit option that indicates whether maintenance mode is enabled. If enabled, forwarding of data packets between the first and second MACsec slave devices is allowed until MACsec negotiation is complete. If disabled, forwarding of data packets between the first and second MACsec slave devices is prohibited until MACsec negotiation is complete. For example, the maintenance-mode option can be 0 or 1, where 0 represents maintenance mode disabled and 1 represents maintenance mode enabled.
[0183] For example, during a MACsec parameter-based session negotiation, the negotiation message may include maintenance mode options. Based on the maintenance mode options of the second MACsec slave device, the first MACsec slave device can learn about the maintenance mode of the second MACsec slave device. Based on the maintenance mode options of the first MACsec slave device, the second MACsec slave device can learn about the maintenance mode of the first MACsec slave device.
[0184] For example, if maintenance mode is enabled, the first MACsec slave device (or the second MACsec slave device) can forward data packets before MACsec negotiation is completed. If maintenance mode is disabled, the first MACsec slave device (or the second MACsec slave device) is prohibited from forwarding data packets, i.e., data packets are discarded, before MACsec negotiation is completed.
[0185] For example, when establishing an MKA session between the first interface of the first MACsec slave device and the second interface of the second MACsec slave device, if MACsec functionality is configured on both interfaces, the first interface will be temporarily blocked, and the second interface will also be temporarily blocked. This prevents data packets transmitted between the first and second interfaces from being forwarded, resulting in packet loss.
[0186] To address the above findings, maintenance mode can be enabled for both the first and second interfaces. This ensures that both interfaces remain unblocked, regardless of whether an MKA session has been established between them. This allows for the forwarding of data packets between the two interfaces, preventing packet loss.
[0187] Step 308: The MACsec master device sends the second MACsec parameter to the second MACsec slave device, and the second MACsec slave device receives the second MACsec parameter sent by the MACsec master device.
[0188] The MACsec master device can send a second parameter response message to the second MACsec slave device. The second parameter response message may include the interface identifier and MAC address of the first interface of the first MACsec slave device, the interface identifier and MAC address of the second interface of the second MACsec slave device, and the second MACsec parameters.
[0189] The second parameter response message may include a BGP update message, which may include an NLRI field and a MACsec attribute field. The NLRI field may include an address family identifier and a variable-length NLRI field. The address family identifier indicates that the NLRI field carries MACsec information, and the variable-length NLRI field includes the interface identifier and the MAC address. The MACsec attribute field may include a second MACsec parameter.
[0190] In one example, the MACsec attribute field may include, but is not limited to, the following fields: type field, length field, MACsec option field, and the following fields related to the second MACsec parameter:
[0191] The connection association key name field carries the connection association key name. The pre-shared key field carries the pre-shared key, which is used to generate the session key. The session timeout field carries the session timeout period, which controls the session's lifespan. The MACsec replay protection window size field carries the MACsec replay protection window size, which is used to discard replayed data packets. The MACsec encryption offset field carries the MACsec encryption offset, which indicates the starting encryption position.
[0192] The MACsec options fields include the following fields related to the second MACsec parameters: MACsec Cipher Suite Option, indicating the list of cipher suites supported by the second MACsec slave device; Secure Channel Identifier Option, indicating whether to carry a secure channel identifier; Shared Key Option, indicating the key distribution method; Replay Protection Option, indicating whether to enable or disable replay protection; Verification Mode Option, indicating whether to perform integrity verification, and if so, whether to discard data packets that fail verification; Maintenance Mode Option, indicating whether to enable maintenance mode.
[0193] Step 309: The first MACsec slave device and the second MACsec slave device perform MACsec communication based on the first MACsec parameters and the second MACsec parameters. For example, the first MACsec slave device and the second MACsec slave device negotiate based on the first MACsec parameters and the second MACsec parameters. After the negotiation is successful, the first MACsec slave device and the second MACsec slave device perform MACsec communication.
[0194] In one example, after the first MACsec slave device receives the first parameter response message, it can also check whether the content of the NLRI field is consistent with the content of the NLRI field of the first parameter request message. If they are consistent, it checks whether the interface corresponding to the local interface identifier field (such as the first interface) has MACsec Desir enabled. If it is enabled, it expects to perform MACsec protection on the first interface, and then triggers negotiation with the second MACsec slave device based on the first MACsec parameter, and performs MACsec communication after the negotiation is successful.
[0195] In one example, after the second MACsec slave device receives the second parameter response message, it can also check whether the content of the NLRI field is consistent with the content of the NLRI field of the second parameter request message. If they are consistent, it checks whether the interface corresponding to the local interface identifier field (such as the second interface) has MACsec Desir enabled. If it is enabled, that is, it expects to perform MACsec protection on the second interface, and then triggers negotiation with the first MACsec slave device based on the second MACsec parameter, and performs MACsec communication after the negotiation is successful.
[0196] In one example, the implementation of MACsec involves a session negotiation process, a secure communication process, and a session termination process. For the session negotiation process, the first and second MACsec slave devices use a configured pre-shared key as the CAK to initiate a negotiation session via negotiation messages. The interface with higher priority between devices is elected as the Key Server, responsible for generating and distributing the SAK. The first and second MACsec slave devices communicate their capabilities and various parameters required for the session (such as first or second MACsec parameters) to each other via the MKA protocol.
[0197] For secure communication, after session negotiation is completed, the first MACsec slave device and the second MACsec slave device have available SAKs and use the SAKs to encrypt data packets to begin encrypted communication.
[0198] Regarding the session termination process, after the first or second MACsec slave device receives the offline request message from the other party, the corresponding security session is cleared. If the local end still does not receive an MKA protocol message from the peer end after the session timeout timer expires, the corresponding security session is also cleared.
[0199] As can be seen from the above technical solutions, in this embodiment, the adjacency relationship of the MACsec slave devices is reported to the MACsec master device. The MACsec master device then obtains the MACsec parameters from the MACsec slave devices, thereby centralizing the processing of the MACsec parameters. The MACsec master device centrally manages the MACsec parameters and distributes them to the MACsec slave devices, completing the configuration of the MACsec parameters. This simplifies the MACsec parameter configuration process, enables automatic deployment of MACsec parameters, and simplifies the deployment and maintenance of MACsec, solving the problem of complex MACsec deployment. By using LLDP and BGP to achieve automatic deployment and expansion configuration distribution, MACsec deployment and network expansion are more convenient, making MACsec applicable to larger-scale networks and allowing for smooth upgrades of devices supporting MACsec.
[0200] Based on the same concept as the above method, this application proposes a parameter configuration device for use in a MACsec master device. Referring to Figure 6A, which is a schematic diagram of the device, the device includes:
[0201] The receiving module 611 is configured to receive a first parameter request message sent by a first MACsec slave device, the first parameter request message including the interface identifier and MAC address of the first interface of the first MACsec slave device, and the interface identifier and MAC address of the neighbor interface of the neighbor device of the first MACsec slave device; and to receive a second parameter request message sent by a second MACsec slave device, the second parameter request message including the interface identifier and MAC address of the second interface of the second MACsec slave device, and the interface identifier and MAC address of the neighbor interface of the neighbor device of the second MACsec slave device.
[0202] The acquisition module 612 is used to acquire the first MACsec parameter corresponding to the first MACsec slave device and the second MACsec parameter corresponding to the second MACsec slave device if it is determined that the first interface and the second interface are successfully paired based on the first parameter request message and the second parameter request message.
[0203] The sending module 613 is used to send the first MACsec parameter to the first MACsec slave device and send the second MACsec parameter to the second MACsec slave device, so that the first MACsec slave device and the second MACsec slave device can perform MACsec communication based on the first MACsec parameter and the second MACsec parameter.
[0204] In one example, the first parameter request message includes first MACsec expectation information, which indicates whether the first MACsec slave device expects or does not expect MACsec protection for the first interface; the second parameter request message includes second MACsec expectation information, which indicates whether the second MACsec slave device expects or does not expect MACsec protection for the second interface; the acquisition module 612 acquires the first MACsec parameter corresponding to the first MACsec slave device and the second MACsec parameter corresponding to the second MACsec slave device specifically as follows: if the first MACsec expectation information indicates that the first MACsec slave device expects MACsec protection for the first interface, and the second MACsec expectation information indicates that the second MACsec slave device expects MACsec protection for the second interface, then the first MACsec parameter corresponding to the first MACsec slave device is acquired, and the second MACsec parameter corresponding to the second MACsec slave device is acquired.
[0205] In one example, all MACsec parameters include a first type of parameter and a second type of parameter. When the acquisition module 612 acquires the first MACsec parameter corresponding to the first MACsec slave device and the second MACsec parameter corresponding to the second MACsec slave device, it specifically performs the following: For each first type of parameter, acquire a reference parameter value for that first type of parameter; the reference parameter value is selected from a set of parameter values, or the reference parameter value is a default parameter value; For each second type of parameter, acquire a first parameter value and a second parameter value for that second type of parameter, where the first parameter value is the same as or different from the second parameter value; the first parameter value is selected from a set of parameter values, or the first parameter value is a default parameter value; the second parameter value is selected from a set of parameter values, or the second parameter value is a default parameter value; acquire a first MACsec parameter, which includes the reference parameter value for each first type of parameter and the first parameter value for each second type of parameter; acquire a second MACsec parameter, which includes the reference parameter value for each first type of parameter and the second parameter value for each second type of parameter.
[0206] In one example, when the sending module 613 sends the first MACsec parameter to the first MACsec slave device and sends the second MACsec parameter to the second MACsec slave device, it is specifically used for:
[0207] Send a first parameter response message to the first MACsec slave device. The first parameter response message includes the interface identifier and MAC address of the first interface of the first MACsec slave device, the interface identifier and MAC address of the second interface of the second MACsec slave device, and the first MACsec parameter.
[0208] Send a second parameter response message to the second MACsec slave device. The second parameter response message includes the interface identifier and MAC address of the second interface of the second MACsec slave device, the interface identifier and MAC address of the first interface of the first MACsec slave device, and the second MACsec parameter.
[0209] In one example, the first parameter request message and the second parameter request message include a first BGP update message, which includes a first NLRI field and a first MACsec attribute field; wherein, the first NLRI field includes an address family identifier and a variable-length NLRI field, the address family identifier indicating that the first NLRI field carries MACsec information, and the variable-length NLRI field includes an interface identifier and a MAC address; wherein, the first MACsec attribute field includes MACsec expectation information.
[0210] In one example, the first parameter response message and the second parameter response message include a second BGP update message, which includes a second NLRI field and a second MACsec attribute field; wherein, the second NLRI field includes an address family identifier and a variable-length NLRI field, the address family identifier indicating that the second NLRI field carries MACsec information, and the variable-length NLRI field includes an interface identifier and a MAC address; wherein, the second MACsec attribute field includes MACsec parameters.
[0211] Based on the same application concept as the above method, this application proposes a parameter configuration device for any MACsec slave device. Referring to Figure 6B, which is a schematic diagram of the device, the device includes: an acquisition module 621, used to acquire the interface identifier and MAC address of the neighbor interface of a neighboring device of the MACsec slave device; wherein the neighboring device is another MACsec slave device; a sending module 622, used to send a parameter request message to a MACsec master device, the parameter request message including the interface identifier and MAC address of the local interface of the MACsec slave device, and the interface identifier and MAC address of the neighboring interface of the neighboring device; wherein the local interface is connected to the neighboring interface; a receiving module 623, used to receive MACsec parameters corresponding to the MACsec slave device sent by the MACsec master device; wherein the MACsec parameters are acquired by the MACsec master device when it determines that the local interface and the neighboring interface are successfully paired based on the parameter request message; and a communication module 624, used to perform MACsec communication with the neighboring device based on the MACsec parameters.
[0212] Based on the same application concept as the above method, this application proposes an electronic device (such as a MACsec master device, a first MACsec slave device, or a second MACsec slave device). Referring to FIG7, the electronic device includes: a processor 71 and a machine-readable storage medium 72. The machine-readable storage medium 72 stores machine-executable instructions that can be executed by the processor 71. The processor 71 is used to execute the machine-executable instructions to implement the parameter configuration method disclosed in the above example of this application.
[0213] Based on the same concept as the above method, this application also provides a machine-readable storage medium storing a plurality of computer instructions, which, when executed by a processor, can implement the parameter configuration method disclosed in the above examples of this application.
[0214] The aforementioned machine-readable storage medium can be any electronic, magnetic, optical, or other physical storage device that can contain or store information, such as executable instructions, data, etc. For example, machine-readable storage media can be: RAM (Random Access Memory), volatile memory, non-volatile memory, flash memory, storage drives (such as hard disk drives), solid-state drives, any type of storage disk (such as optical discs, DVDs, etc.), or similar storage media, or combinations thereof.
[0215] Based on the same concept as the methods described above, this application also provides a computer program product, which may include a computer program. When executed by a processor, the computer program implements the parameter configuration method disclosed in the examples above.
[0216] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, embodiments of this application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0217] The above description is merely an embodiment of this application and is not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.
Claims
1. A parameter configuration method, characterized in that, Applied to MACsec master devices, including: Receive a first parameter request message sent by a first MACsec slave device. The first parameter request message includes the interface identifier and MAC address of the first interface of the first MACsec slave device, and the interface identifier and MAC address of the neighbor interface of the neighbor device of the first MACsec slave device. Receive a second parameter request message sent by the second MACsec slave device. The second parameter request message includes the interface identifier and MAC address of the second interface of the second MACsec slave device, the interface identifier and MAC address of the neighbor interface of the neighbor device of the second MACsec slave device; If it is determined that the first interface and the second interface are successfully paired based on the first parameter request message and the second parameter request message, then the first MACsec parameter corresponding to the first MACsec slave device and the second MACsec parameter corresponding to the second MACsec slave device are obtained. The first MACsec parameter is sent to the first MACsec slave device, and the second MACsec parameter is sent to the second MACsec slave device. The first MACsec slave device and the second MACsec slave device then perform MACsec communication based on the first MACsec parameter and the second MACsec parameter.
2. The method according to claim 1, characterized in that, The first parameter request message includes first MACsec expectation information, which indicates whether the first MACsec slave device expects or does not expect MACsec protection for the first interface; the second parameter request message includes second MACsec expectation information, which indicates whether the second MACsec slave device expects or does not expect MACsec protection for the second interface. The step of obtaining the first MACsec parameter corresponding to the first MACsec slave device and the second MACsec parameter corresponding to the second MACsec slave device includes: if the first MACsec expectation information indicates that the first MACsec slave device expects to perform MACsec protection on the first interface, and the second MACsec expectation information indicates that the second MACsec slave device expects to perform MACsec protection on the second interface, then the first MACsec parameter corresponding to the first MACsec slave device and the second MACsec parameter corresponding to the second MACsec slave device are obtained.
3. The method according to claim 1 or 2, characterized in that, All MACsec parameters contain a first type of parameter and a second type of parameter. Obtaining the first MACsec parameter corresponding to the first MACsec slave device and the second MACsec parameter corresponding to the second MACsec slave device includes: For each first type of parameter, obtain a reference parameter value for that first type of parameter; wherein, the reference parameter value is selected from the parameter value set, or, the reference parameter value is a default parameter value; For each second type of parameter, obtain the first parameter value and the second parameter value of that second type of parameter, wherein the first parameter value is the same as or different from the second parameter value; wherein the first parameter value is selected from the parameter value set, or the first parameter value is a default parameter value; the second parameter value is selected from the parameter value set, or the second parameter value is a default parameter value; Obtain the first MACsec parameter, which includes a reference parameter value for each first type of parameter and a first parameter value for each second type of parameter; Obtain the second MACsec parameter, which includes a reference parameter value for each first type of parameter and a second parameter value for each second type of parameter.
4. The method according to claim 1, characterized in that, Sending the first MACsec parameter to the first MACsec slave device and sending the second MACsec parameter to the second MACsec slave device includes: Send a first parameter response message to the first MACsec slave device. The first parameter response message includes the interface identifier and MAC address of the first interface of the first MACsec slave device, the interface identifier and MAC address of the second interface of the second MACsec slave device, and the first MACsec parameter. Send a second parameter response message to the second MACsec slave device. The second parameter response message includes the interface identifier and MAC address of the second interface of the second MACsec slave device, the interface identifier and MAC address of the first interface of the first MACsec slave device, and the second MACsec parameter.
5. The method according to claim 1 or 4, characterized in that, The first parameter request message and the second parameter request message include a first BGP update message, which includes a first NLRI field and a first MACsec attribute field; wherein, the first NLRI field includes an address family identifier and a variable-length NLRI field, the address family identifier indicating that the first NLRI field carries MACsec information, and the variable-length NLRI field includes an interface identifier and a MAC address; wherein, the first MACsec attribute field includes MACsec expectation information; The first parameter response message and the second parameter response message include a second BGP update message, which includes a second NLRI field and a second MACsec attribute field. The second NLRI field includes an address family identifier and a variable-length NLRI field. The address family identifier indicates that the second NLRI field carries MACsec information, and the variable-length NLRI field includes an interface identifier and a MAC address. The second MACsec attribute field includes MACsec parameters.
6. A parameter configuration method, characterized in that, Applicable to any MACsec slave device, including: Obtain the interface identifier and MAC address of the neighboring interface of the neighboring device of this MACsec slave device; Send a parameter request message to the MACsec master device. The parameter request message includes the interface identifier and MAC address of the local interface of the MACsec slave device, and the interface identifier and MAC address of the neighbor interface of the neighbor device; wherein the local interface is connected to the neighbor interface. Receive the MACsec parameters corresponding to the local MACsec slave device sent by the MACsec master device; wherein, the MACsec parameters are obtained by the MACsec master device when it determines that the local interface and the neighbor interface are successfully paired based on the parameter request message; Based on the MACsec parameters, perform MACsec communication with the neighboring device.
7. A parameter configuration device, characterized in that, Applied to MACsec master devices, including: The receiving module is configured to receive a first parameter request message sent by a first MACsec slave device, the first parameter request message including the interface identifier and MAC address of the first interface of the first MACsec slave device, and the interface identifier and MAC address of the neighbor interface of the neighbor device of the first MACsec slave device; and to receive a second parameter request message sent by a second MACsec slave device, the second parameter request message including the interface identifier and MAC address of the second interface of the second MACsec slave device, and the interface identifier and MAC address of the neighbor interface of the neighbor device of the second MACsec slave device. The acquisition module is used to acquire the first MACsec parameter corresponding to the first MACsec slave device and the second MACsec parameter corresponding to the second MACsec slave device if it is determined that the first interface and the second interface are successfully paired based on the first parameter request message and the second parameter request message. The sending module is used to send the first MACsec parameter to the first MACsec slave device and the second MACsec parameter to the second MACsec slave device, so that the first MACsec slave device and the second MACsec slave device can perform MACsec communication based on the first MACsec parameter and the second MACsec parameter.
8. The apparatus according to claim 7, characterized in that, The first parameter request message includes first MACsec expectation information, which indicates whether the first MACsec slave device expects or does not expect MACsec protection for the first interface; the second parameter request message includes second MACsec expectation information, which indicates whether the second MACsec slave device expects or does not expect MACsec protection for the second interface. When the acquisition module acquires the first MACsec parameter corresponding to the first MACsec slave device and the second MACsec parameter corresponding to the second MACsec slave device, it is specifically used to: if the first MACsec expectation information indicates that the first MACsec slave device expects to perform MACsec protection on the first interface, and the second MACsec expectation information indicates that the second MACsec slave device expects to perform MACsec protection on the second interface, then the first MACsec parameter corresponding to the first MACsec slave device is acquired, and the second MACsec parameter corresponding to the second MACsec slave device is acquired.
9. The apparatus according to claim 7 or 8, characterized in that, All MACsec parameters include both type I and type II parameters; When the acquisition module acquires the first MACsec parameter corresponding to the first MACsec slave device and the second MACsec parameter corresponding to the second MACsec slave device, it is specifically used for: For each first type of parameter, obtain a reference parameter value for that first type of parameter; wherein, the reference parameter value is selected from the parameter value set, or, the reference parameter value is a default parameter value; For each second type of parameter, obtain the first parameter value and the second parameter value of that second type of parameter, wherein the first parameter value is the same as or different from the second parameter value; wherein the first parameter value is selected from the parameter value set, or the first parameter value is a default parameter value; the second parameter value is selected from the parameter value set, or the second parameter value is a default parameter value; Obtain the first MACsec parameter, which includes a reference parameter value for each first type of parameter and a first parameter value for each second type of parameter; Obtain the second MACsec parameter, which includes a reference parameter value for each first type of parameter and a second parameter value for each second type of parameter.
10. The apparatus according to claim 7, characterized in that, When the sending module sends the first MACsec parameter to the first MACsec slave device and the second MACsec parameter to the second MACsec slave device, it is specifically used for: Send a first parameter response message to the first MACsec slave device. The first parameter response message includes the interface identifier and MAC address of the first interface of the first MACsec slave device, the interface identifier and MAC address of the second interface of the second MACsec slave device, and the first MACsec parameter. Send a second parameter response message to the second MACsec slave device. The second parameter response message includes the interface identifier and MAC address of the second interface of the second MACsec slave device, the interface identifier and MAC address of the first interface of the first MACsec slave device, and the second MACsec parameter.
11. The apparatus according to claim 7 or 10, characterized in that, The first parameter request message and the second parameter request message include a first BGP update message, which includes a first NLRI field and a first MACsec attribute field; wherein, the first NLRI field includes an address family identifier and a variable-length NLRI field, the address family identifier indicating that the first NLRI field carries MACsec information, and the variable-length NLRI field includes an interface identifier and a MAC address; wherein, the first MACsec attribute field includes MACsec expectation information; The first parameter response message and the second parameter response message include a second BGP update message, which includes a second NLRI field and a second MACsec attribute field. The second NLRI field includes an address family identifier and a variable-length NLRI field. The address family identifier indicates that the second NLRI field carries MACsec information, and the variable-length NLRI field includes an interface identifier and a MAC address. The second MACsec attribute field includes MACsec parameters.
12. A parameter configuration device, characterized in that, Applicable to any MACsec slave device, including: The acquisition module is used to acquire the interface identifier and MAC address of the neighbor interface of the neighbor device of the MACsec slave device; wherein, the neighbor device is another MACsec slave device; The sending module is used to send a parameter request message to the MACsec master device. The parameter request message includes the interface identifier and MAC address of the local interface of the MACsec slave device, and the interface identifier and MAC address of the neighbor interface of the neighbor device; wherein the local interface is connected to the neighbor interface. The receiving module is used to receive the MACsec parameters corresponding to the local MACsec slave device sent by the MACsec master device; wherein, the MACsec parameters are obtained by the MACsec master device when it determines that the local interface and the neighbor interface are successfully paired based on the parameter request message; A communication module is used to perform MACsec communication with the neighboring device based on the MACsec parameters.
13. An electronic device, characterized in that, include: A processor and a machine-readable storage medium, the machine-readable storage medium storing machine-executable instructions that can be executed by the processor; The processor is configured to execute machine-executable instructions to implement the method of any one of claims 1-6.