MACsec Authentication Bypass for Low-Latency Packet Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
MACsec protocols introduce significant latency due to encryption, decryption, and authentication processes, which increase overall packet transmission and processing delays in Ethernet-based networks.
Innovation Solution
A system and method that includes a pipeline circuit for processing packets and an authentication engine to authenticate packets while providing an authentication signal, with a control circuit routing packets to either the authentication engine or a bypass path to minimize latency by bypassing authentication for unencrypted or unauthenticated packets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MACsec encryption and authentication processes are applied to all packets, then security is improved, but transmission latency increases
Solution Approach 1:
The patent applies different processing paths to different packets based on their security requirements. Encrypted packets requiring authentication are routed through the authentication engine, while unencrypted packets bypass it. This localized application of authentication reduces overall latency while maintaining security for packets that need it.
Solution Approach 2:
The system dynamically routes packets through different paths based on their encryption status and authentication requirements. The router determines whether each packet needs authentication processing and directs it accordingly, creating a flexible system that adapts to varying security needs rather than applying a static authentication process to all packets.
2Reliability
If authentication processing is performed on all incoming packets, then authentication reliability is improved, but processing throughput decreases
Solution Approach 1:
The authentication engine processes only those packets that require authentication verification, while other packets are handled by the bypass path. This selective processing maintains authentication reliability for necessary packets while preserving overall system throughput by avoiding unnecessary authentication operations on packets that don't require it.
3Reliability
If encryption and decryption operations are performed on all packets, then confidentiality is improved, but processing time increases
Solution Approach 1:
The patent extracts the encryption/decryption operations from the main packet processing path and handles them separately through the bypass path for unencrypted packets. This separation eliminates unnecessary encryption/decryption processing time for packets that don't require these operations, while maintaining confidentiality protection for packets that do need encryption.
Data Source
AI summary
An apparatus may include a pipeline circuit configured to process packets and an authentication engine configured to authenticate packets and to provide an authentication signal to the pipeline circuit based on whether packets have been authenticated. The apparatus may further include a control circuit configured to route a given incoming packet to both the authentication engine and to a bypass path. The bypass path may be configured to provide a copy of the given incoming packet to the pipeline circuit to bypass the authentication engine.


