MACsec CAK CKN Auto-Configuration via Public Key Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Manual configuration of Connectivity Association Key (CAK) and Connectivity Association Name (CKN) in MACsec capable devices is prone to errors and human fatigue, especially in complex network topologies, which can compromise security and is not suitable for auto-provisioning in cloud deployments.
Innovation Solution
A method where a first MACsec device generates and encrypts CAK, CKN, and a nonce using the second device's public key, sending an encrypted packet for configuration, allowing the second device to decrypt and verify, ensuring accurate key configuration and establishing a secure MACsec session.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual configuration of CAK and CKN is performed, then security can be maintained through human control, but human error and fatigue lead to configuration mistakes and security compromises
Solution Approach 1:
The system performs self-service through automated key configuration. The MACsec device automatically generates CAK and CKN, encrypts them using the peer's public key, and configures them without human intervention. This eliminates human error while maintaining security through cryptographic protocols.
Solution Approach 2:
The patent introduces an intermediary automated configuration mechanism that mediates between security requirements and operational simplicity. The system uses public key infrastructure as an intermediary to securely transfer and configure keys automatically, resolving the conflict between reliability and ease of operation.
2Productivity
If automated key configuration is implemented, then human error is eliminated and productivity increases, but complexity of the configuration process increases
Solution Approach 1:
The system performs preliminary actions by pre-generating cryptographic key pairs and preparing encryption/decryption mechanisms before actual key configuration is needed. This allows automated provisioning to proceed quickly without compromising security, resolving the conflict between productivity and complexity.
Solution Approach 2:
The patent replaces manual mechanical configuration processes with automated cryptographic operations. Public key encryption and decryption algorithms substitute for human manual key entry and management, increasing productivity while the automation itself manages the complexity.
3Loss of time
If manual key management is used, then device complexity is reduced, but time consumption increases due to tracking and configuring keys across multiple devices
Solution Approach 1:
Each MACsec device performs self-service by automatically generating its own cryptographic keys and configuring them without requiring manual tracking or intervention. This eliminates time-consuming manual key management while the automation handles the complexity of key distribution across multiple devices.
Data Source
AI summary
Examples disclosed herein relate to configuring a connectivity association key and a connectivity association name in a MACsec capable device. In an example, a first MACsec device may receive a MAC address and a device identifier of a second MACsec capable device. First MACsec capable device may authenticate the second MACsec capable device based on the device identifier. First MACsec capable device may generate a CAK, a CKN, and a nonce. The CAK, the CKN, and the nonce may be encrypted using a public key of the second MACsec capable device to generate an encrypted packet. The encrypted packet may be sent to the second MACsec capable device. The first MACsec capable device may receive a decrypted nonce from the second MACsec capable device. In response to a determination that the decrypted nonce matches with the nonce, CAK and CKN may be configured on first MACsec capable device.


