In-Band MACsec Key Updates for Retimer Channel Scalability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing MACsec retimer devices face a bottleneck in updating encryption keys due to slow data rates associated with management data input/output (MDIO) registers, limiting the number of secure channels that can be supported in secure Ethernet systems.
Innovation Solution
Implementing a retimer device with packet filtering logic and microcontroller to identify and update encryption keys in-band via high-speed data lanes, bypassing the need for MDIO registers, allowing for automatic key updates through secure egress channels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If MDIO registers are used to communicate encryption key updates from host device to retimer device, then the key update mechanism is simple and reliable, but the data rate is slow and limits the number of secure channels that can be supported
Solution Approach 1:
The patent extracts the key update communication from the slow MDIO register interface and moves it to the high-speed in-band data channels. The retimer device includes packet filtering logic that identifies and extracts key update packets from the data traffic stream, separating the key update function from the control register interface.
Solution Approach 2:
The patent introduces an intermediary mechanism - packet filtering logic with a buffer - that captures key update packets from the high-speed data stream and delivers them to the microcontroller. This intermediary allows the fast data path to communicate encryption keys without being constrained by the slow MDIO interface.
2Productivity
If MDIO registers are used for key update communication, then device complexity is low, but throughput is limited and creates a bottleneck for secure channel support
Solution Approach 1:
The patent makes the data channels multi-functional by using them for both data transmission and key update communication. The in-band key update mechanism allows the same high-speed data path to serve dual purposes, eliminating the need for a separate dedicated key update interface and thereby increasing throughput without proportionally increasing complexity.
Solution Approach 2:
The retimer device performs self-service by including packet filtering logic that automatically identifies, extracts, and buffers key update packets from the data stream. The microcontroller then processes these extracted packets to update encryption keys, allowing the device to autonomously manage key updates without external intervention through slow MDIO registers.
3Reliability
If encryption keys are updated every second via MDIO, then security requirements are met, but the slow data rate causes key updates to expire before completion for large numbers of channels
Solution Approach 1:
The patent implements preliminary action by buffering key update packets as they arrive from the high-speed data stream before the microcontroller processes them. This buffer ensures that key updates are captured and ready for processing without loss, even as the microcontroller manages multiple channels, preventing key expiration due to processing delays.
Solution Approach 2:
The system implements feedback through acknowledgment packets sent from the retimer to the host device. After the microcontroller successfully updates an encryption key, it sends an acknowledgment back to confirm the update. This feedback mechanism ensures reliable key update delivery and allows the host to verify that security updates are completed within the required time frame.
Data Source
AI summary
A system for automatic in-band MACsec encryption key updates includes a physical layer retimer device attachable to a host system, the host system connected to a peer device via a secure Ethernet link incorporating egress and ingress channels for encrypted data traffic. The host system generates encryption key updates for each secure egress or ingress channel, sending the key updates in-band as Ethernet packets via the secure egress channels. Key updates are identified and extracted from egress data traffic by the retimer device, which identifies the specific encryption key (e.g., corresponding to a specific egress channel or ingress channel) for which each key update is intended. Security blocks of the retimer device update the appropriate encryption key corresponding to each key update. The retimer device generates an acknowledgement packet for each successful key update, sending the acknowledgement packet back to the host device to confirm the key update.


