Ethernet MACsec Symmetric Key Generation via Digital Certificates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing methods for implementing MACsec on Ethernet devices from different OEMs face challenges in provisioning symmetric keys, leading to resource-intensive key management and network overhead, especially when using RADIUS servers or manual provisioning, which limits interoperability and security across multiple OEMs.

Innovation Solution

Ethernet devices can self-generate a symmetric key by exchanging unique identifiers and obtaining digital certificates from a trusted certificate authority, using these to independently generate a shared secret key without pre-sharing or dynamic provisioning, thereby reducing resource consumption and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual key provisioning or RADIUS server dependency is used for MACsec, then key management can be implemented, but resource consumption increases and interoperability between different OEMs is limited

Engineering Contradiction:
ImproveMACsec security connectionVSAvoidkey management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling Ethernet devices to autonomously generate and exchange symmetric keys through digital certificate-based authentication. Each device obtains its own digital certificate from a certificate authority and uses it to independently generate symmetric keys with peer devices, eliminating the need for external RADIUS servers or manual provisioning. This self-service mechanism reduces resource consumption and simplifies key management while maintaining security.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If RADIUS server or manual provisioning is used, then symmetric key distribution is achieved, but network overhead and resource consumption increase

Engineering Contradiction:
Improvesymmetric key provisioningVSAvoidresource consumption
Core Design Contradiction:
Ease of operationVSUse of energy by moving object

Solution Approach 1:

Devices perform self-service key provisioning by automatically obtaining digital certificates from a certificate authority and using these certificates to generate symmetric keys with peer devices. This eliminates the need for RADIUS server infrastructure and manual configuration, reducing network overhead and resource consumption while maintaining ease of operation through automated processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces a certificate authority as an intermediary that issues digital certificates to devices. These certificates serve as trusted mediators that enable devices to authenticate each other and generate symmetric keys without requiring continuous communication with a RADIUS server. The certificate-based intermediary approach reduces ongoing resource consumption while maintaining secure key provisioning.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If pre-shared keys are exchanged between devices, then MACsec security is established, but interoperability between different OEMs is limited

Engineering Contradiction:
Improvedata confidentiality and integrityVSAvoidinteroperability across OEMs
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements universality by using industry-standard digital certificate authorities that can issue certificates to devices from any OEM. Instead of OEM-specific pre-shared keys, the system uses universally accepted certificate-based authentication. Any device with a valid certificate from a trusted authority can establish secure connections with any other such device, enabling broad interoperability while maintaining data confidentiality and integrity through standardized cryptographic protocols.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20200358764A1System and method for generating symmetric key to implement media access control security check
Publication Date: 2020.11.12 VERIZON PATENT & LICENSING INC
  • US20200358764A1 patent drawing
  • US20200358764A1 patent drawing
  • US20200358764A1 patent drawing

AI summary

A first device may transmit, to a peer device, a first digital certificate containing a first unique identifier associated with the first device and receive, from the peer device, a second digital certificate containing a second unique identifier associated with the peer device. The first device and the peer device may independently generate a symmetric key using a cryptographic hash function based on respectively determining that a certificate authority signed the first digital certificate and the second digital certificate. For example, the first device and the peer device may independently generate the symmetric key using the cryptographic hash function based on the first unique identifier, the second unique identifier, and one or more random numbers. Accordingly, the first device and the peer device may use the symmetric key to establish a secure communication session over an Ethernet link.