IPsec to MACsec Protocol Converter for Hybrid Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Hybrid networks employing both IPsec and MACsec protocols face incompatibility issues, limiting their ability to provide expected network services such as packet payload viewing and traffic classification due to differences in security protocols used at different network abstraction layers.

Innovation Solution

A method and system that enable conversion between Ethernet packets secured with IPsec and MACsec protocols, allowing for the preservation of existing network infrastructure while providing data authentication and integrity, and enabling traffic classification and payload inspection by detecting and converting between IPsec and MACsec secured packets based on protocol fields and data structures stored in network nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If both IPsec and MACsec protocols are employed in a hybrid network, then network security coverage is improved, but protocol compatibility and service functionality deteriorate

Engineering Contradiction:
Improvenetwork securityVSAvoidprotocol compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a protocol converter as an intermediary device between IPsec and MACsec networks. This converter detects packets from one protocol type and translates them to the other protocol type, enabling communication between hybrid network segments without requiring full protocol compatibility across the entire network. The converter acts as a mediator that resolves the incompatibility issue while maintaining security functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the protocol parameters and packet formats dynamically based on the detection results. When a packet is detected as IPsec-protected, the system changes its handling parameters to process it as MACsec after conversion, and vice versa. This parameter transformation enables the network to adapt to different security protocol implementations while maintaining consistent security operations.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If protocol conversion between IPsec and MACsec is implemented, then network service functionality is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork service functionalityVSAvoidconversion system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the protocol conversion function into distinct processing stages: packet detection, protocol identification, conversion processing, and packet forwarding. By dividing the complex conversion task into separate functional modules, the system reduces the complexity burden on any single component and enables modular implementation of the protocol converter.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent designs a universal packet processing framework that can handle both IPsec and MACsec protocols through a single conversion mechanism. The system uses a unified detection and conversion approach that works for both protocol types, reducing the need for separate dedicated processing paths and simplifying the overall device architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7853691B2Method and system for securing a network utilizing IPsec and MACsec protocols
Publication Date: 2010.12.14 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
  • US7853691B2 patent drawing
  • US7853691B2 patent drawing
  • US7853691B2 patent drawing

AI summary

Aspects of a method and system for securing a network utilizing IPsec and MACsec protocols are provided. In one or more network nodes, aspects of the invention may enable conversion between Ethernet packets comprising payloads secured utilizing IPsec protocols and Ethernet packets secured utilizing MACsec protocols. For example, IPsec connections may be terminated at an ingress network node and IPsec connections may be regenerated at an egress network node. Packets secured utilizing MACsec protocols may be detected based on an Ethertype. Packets comprising payloads secured utilizing IPsec protocols may be detected based on a protocol field or a next header field. The conversion may be based on a data structure stored by and/or accessible to the network nodes. Aspects of the invention may enable securing data utilizing MACsec protocols when tunneling IPsec secured data through non-IPsec enabled nodes.