Application-Aware MACsec Policy for Low-Latency Network Flows

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing point-to-point security protocols like MACsec reduce link capacity and introduce latency due to unnecessary encryption of all network traffic, including non-sensitive data, and lack mechanisms for selective application protection based on user traffic.

Innovation Solution

Implementing Deep Packet Inspection (DPI) to identify network applications and using a lookup table to selectively apply point-to-point security protocols like MACsec based on application-specific policies, reducing unnecessary encryption and enhancing link capacity and latency for non-sensitive traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If point-to-point security protocol (MACsec) is applied to all network traffic, then network security is improved, but link capacity is reduced and latency is introduced

Engineering Contradiction:
Improvenetwork securityVSAvoidlink capacity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies MACsec encryption selectively to specific applications (e.g., file transfer, email) rather than uniformly to all network traffic. The network device identifies applications using DPI and applies security protocols only to those requiring protection, leaving audio and video traffic unencrypted to maintain high link capacity and low latency.

Inventive Principle:
Principle #3Local quality

2Reliability

If point-to-point security protocol (MACsec) is applied to all network traffic, then network security is improved, but latency is increased

Engineering Contradiction:
Improvenetwork securityVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system differentiates between applications based on their security requirements and applies MACsec only where needed. Time-sensitive applications like audio and video are excluded from encryption, preventing latency introduction, while security-sensitive applications receive protection.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If Deep Packet Inspection is implemented to identify applications, then selective security application is enabled, but device complexity is increased

Engineering Contradiction:
Improveselective security applicationVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a lookup table as an intermediary component that stores pre-configured security policies for different applications. When DPI identifies an application, the system queries the lookup table to determine whether to apply MACsec, avoiding complex real-time security policy evaluation and simplifying the decision-making process.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12519837B2Policy-based application of a point-to-point security protocol to a network flow from a source application
Publication Date: 2026.01.06 HEWLETT PACKARD ENTERPRISE DEV LP
  • US12519837B2 patent drawing
  • US12519837B2 patent drawing
  • US12519837B2 patent drawing

AI summary

Some examples relate to applying a point-to-point security protocol to a network flow from a source application. In an example implementation, a network device can receive a network flow from a network client on a network. The network device can analyze a network packet of the network flow. Based on the analysis, the network device can identify a source application of the network flow. The network device can then refer to a lookup table in an integrated circuit (IC) on the network device that includes a point-to-point security protocol (PSP)-related policy for the source application. Based on the PSP policy in the lookup table, the network device can abstain from applying PSP-based encryption to the network flow from the source application.