In-Band MACsec Key Updates for Retimer Channel Scalability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing MACsec retimer devices face a bottleneck in updating encryption keys due to slow data rates associated with management data input/output (MDIO) registers, limiting the number of secure channels that can be supported in secure Ethernet systems.

Innovation Solution

Implementing a retimer device with packet filtering logic and microcontroller to identify and update encryption keys in-band via high-speed data lanes, bypassing the need for MDIO registers, allowing for automatic key updates through secure egress channels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If MDIO registers are used to communicate encryption key updates from host device to retimer device, then the key update mechanism is simple and reliable, but the data rate is slow and limits the number of secure channels that can be supported

Engineering Contradiction:
Improvekey update speedVSAvoidnumber of secure channels
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The patent extracts the key update communication from the slow MDIO register interface and moves it to the high-speed in-band data channels. The retimer device includes packet filtering logic that identifies and extracts key update packets from the data traffic stream, separating the key update function from the control register interface.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary mechanism - packet filtering logic with a buffer - that captures key update packets from the high-speed data stream and delivers them to the microcontroller. This intermediary allows the fast data path to communicate encryption keys without being constrained by the slow MDIO interface.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If MDIO registers are used for key update communication, then device complexity is low, but throughput is limited and creates a bottleneck for secure channel support

Engineering Contradiction:
ImprovethroughputVSAvoidretimer device complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent makes the data channels multi-functional by using them for both data transmission and key update communication. The in-band key update mechanism allows the same high-speed data path to serve dual purposes, eliminating the need for a separate dedicated key update interface and thereby increasing throughput without proportionally increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The retimer device performs self-service by including packet filtering logic that automatically identifies, extracts, and buffers key update packets from the data stream. The microcontroller then processes these extracted packets to update encryption keys, allowing the device to autonomously manage key updates without external intervention through slow MDIO registers.

Inventive Principle:
Principle #25Self-service

3Reliability

If encryption keys are updated every second via MDIO, then security requirements are met, but the slow data rate causes key updates to expire before completion for large numbers of channels

Engineering Contradiction:
Improvekey update reliabilityVSAvoidkey update time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by buffering key update packets as they arrive from the high-speed data stream before the microcontroller processes them. This buffer ensures that key updates are captured and ready for processing without loss, even as the microcontroller manages multiple channels, preventing key expiration due to processing delays.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback through acknowledgment packets sent from the retimer to the host device. After the microcontroller successfully updates an encryption key, it sends an acknowledgment back to confirm the update. This feedback mechanism ensures reliable key update delivery and allows the host to verify that security updates are completed within the required time frame.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12519634B2Automatic in-band media access control security (MACsec) key update for retimer device
Publication Date: 2026.01.06 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
  • US12519634B2 patent drawing
  • US12519634B2 patent drawing
  • US12519634B2 patent drawing

AI summary

A system for automatic in-band MACsec encryption key updates includes a physical layer retimer device attachable to a host system, the host system connected to a peer device via a secure Ethernet link incorporating egress and ingress channels for encrypted data traffic. The host system generates encryption key updates for each secure egress or ingress channel, sending the key updates in-band as Ethernet packets via the secure egress channels. Key updates are identified and extracted from egress data traffic by the retimer device, which identifies the specific encryption key (e.g., corresponding to a specific egress channel or ingress channel) for which each key update is intended. Security blocks of the retimer device update the appropriate encryption key corresponding to each key update. The retimer device generates an acknowledgement packet for each successful key update, sending the acknowledgement packet back to the host device to confirm the key update.