Layer 2 Secure Channel Test Identifier for Line Rate Decryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Testing communications networks over secure channels, particularly in high-speed multi-tenant data center environments, is challenging due to the complexity of MACsec protocols and the need for efficient encryption/decryption processes that maintain network speed without slowing down data rates.

Innovation Solution

A method and system for testing a network system under test (SUT) by sending and receiving test packets over a layer 2 secure channel, forming a test identifier using a subset of bits from the secure channel identifier, and decrypting packets using this identifier to efficiently manage secure key lookups and store test metrics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If full secure channel identifier is used for key lookup, then decryption accuracy is improved, but processing time and memory usage increase

Engineering Contradiction:
Improvedecryption accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent extracts only the necessary subset of bits from the full secure channel identifier to form a test identifier for key lookup. This extraction principle allows the system to use a shortened identifier that is sufficient for finding the correct security key without the overhead of processing the complete identifier, thus reducing processing time while maintaining decryption accuracy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the full secure channel identifier into multiple parts, using only the relevant subset for key lookup operations. This segmentation allows the system to separate the identifier into components, using only the necessary portion for decryption while ignoring the rest, thereby reducing memory usage and processing time without compromising decryption functionality.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If full secure channel identifier is used for key lookup, then decryption accuracy is improved, but memory usage increases

Engineering Contradiction:
Improvedecryption accuracyVSAvoidmemory usage
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent extracts only the necessary subset of bits from the full secure channel identifier to form a test identifier for key lookup. This extraction principle allows the system to use a shortened identifier that is sufficient for finding the correct security key without the overhead of processing the complete identifier, thus reducing processing time while maintaining decryption accuracy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the full secure channel identifier into multiple parts, using only the relevant subset for key lookup operations. This segmentation allows the system to separate the identifier into components, using only the necessary portion for decryption while ignoring the rest, thereby reducing memory usage and processing time without compromising decryption functionality.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If encryption/decryption is performed in software, then flexibility is improved, but network speed decreases

Engineering Contradiction:
Improvesoftware flexibilityVSAvoidnetwork speed
Core Design Contradiction:
Adaptability or versatilityVSSpeed

Solution Approach 1:

The patent performs preliminary actions by pre-establishing secure channels and organizing security keys before actual data transmission begins. This preliminary setup allows the system to optimize the decryption process for high-speed operation during actual testing, while the initial configuration can be done flexibly in software. The test system is also configured to efficiently manage and cache security keys for rapid lookup during line-rate decryption.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12015642B2Methods, systems, and computer readable media for testing a network system under test communicating over a secure channel
Publication Date: 2024.06.18 KEYSIGHT TECHNOLOGIES INC
  • US12015642B2 patent drawing
  • US12015642B2 patent drawing
  • US12015642B2 patent drawing

AI summary

Methods, systems, and computer readable media for testing a system under test (SUT). A method includes sending a first test packet to the SUT over a communication link. The first test packet is associated with a layer 2 secure channel that is bound to an emulated network device. The method includes receiving a second test packet from the SUT over the communication link. The second test packet includes an unencrypted portion and an encrypted portion. The method includes forming a test identifier that uniquely identifies the layer 2 secure channel and the emulated network device using a subset of bits from a secure channel identifier in the unencrypted portion of the second test packet. The method includes decrypting the encrypted portion of the second test packet by finding a security key using the test identifier.