Application-Aware MACsec Policy for Low-Latency Network Flows
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing point-to-point security protocols like MACsec reduce link capacity and introduce latency due to unnecessary encryption of all network traffic, including non-sensitive data, and lack mechanisms for selective application protection based on user traffic.
Innovation Solution
Implementing Deep Packet Inspection (DPI) to identify network applications and using a lookup table to selectively apply point-to-point security protocols like MACsec based on application-specific policies, reducing unnecessary encryption and enhancing link capacity and latency for non-sensitive traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If point-to-point security protocol (MACsec) is applied to all network traffic, then network security is improved, but link capacity is reduced and latency is introduced
Solution Approach 1:
The patent applies MACsec encryption selectively to specific applications (e.g., file transfer, email) rather than uniformly to all network traffic. The network device identifies applications using DPI and applies security protocols only to those requiring protection, leaving audio and video traffic unencrypted to maintain high link capacity and low latency.
2Reliability
If point-to-point security protocol (MACsec) is applied to all network traffic, then network security is improved, but latency is increased
Solution Approach 1:
The system differentiates between applications based on their security requirements and applies MACsec only where needed. Time-sensitive applications like audio and video are excluded from encryption, preventing latency introduction, while security-sensitive applications receive protection.
3Adaptability or versatility
If Deep Packet Inspection is implemented to identify applications, then selective security application is enabled, but device complexity is increased
Solution Approach 1:
The patent introduces a lookup table as an intermediary component that stores pre-configured security policies for different applications. When DPI identifies an application, the system queries the lookup table to determine whether to apply MACsec, avoiding complex real-time security policy evaluation and simplifying the decision-making process.
Data Source
AI summary
Some examples relate to applying a point-to-point security protocol to a network flow from a source application. In an example implementation, a network device can receive a network flow from a network client on a network. The network device can analyze a network packet of the network flow. Based on the analysis, the network device can identify a source application of the network flow. The network device can then refer to a lookup table in an integrated circuit (IC) on the network device that includes a point-to-point security protocol (PSP)-related policy for the source application. Based on the PSP policy in the lookup table, the network device can abstain from applying PSP-based encryption to the network flow from the source application.


