MACsec CAK CKN Auto-Configuration via Public Key Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Manual configuration of Connectivity Association Key (CAK) and Connectivity Association Name (CKN) in MACsec capable devices is prone to errors and human fatigue, especially in complex network topologies, which can compromise security and is not suitable for auto-provisioning in cloud deployments.

Innovation Solution

A method where a first MACsec device generates and encrypts CAK, CKN, and a nonce using the second device's public key, sending an encrypted packet for configuration, allowing the second device to decrypt and verify, ensuring accurate key configuration and establishing a secure MACsec session.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration of CAK and CKN is performed, then security can be maintained through human control, but human error and fatigue lead to configuration mistakes and security compromises

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs self-service through automated key configuration. The MACsec device automatically generates CAK and CKN, encrypts them using the peer's public key, and configures them without human intervention. This eliminates human error while maintaining security through cryptographic protocols.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediary automated configuration mechanism that mediates between security requirements and operational simplicity. The system uses public key infrastructure as an intermediary to securely transfer and configure keys automatically, resolving the conflict between reliability and ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If automated key configuration is implemented, then human error is eliminated and productivity increases, but complexity of the configuration process increases

Engineering Contradiction:
Improveprovisioning speedVSAvoidconfiguration complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-generating cryptographic key pairs and preparing encryption/decryption mechanisms before actual key configuration is needed. This allows automated provisioning to proceed quickly without compromising security, resolving the conflict between productivity and complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual mechanical configuration processes with automated cryptographic operations. Public key encryption and decryption algorithms substitute for human manual key entry and management, increasing productivity while the automation itself manages the complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Loss of time

If manual key management is used, then device complexity is reduced, but time consumption increases due to tracking and configuring keys across multiple devices

Engineering Contradiction:
Improvekey management timeVSAvoidprovisioning automation
Core Design Contradiction:
Loss of timeVSExtent of automation

Solution Approach 1:

Each MACsec device performs self-service by automatically generating its own cryptographic keys and configuring them without requiring manual tracking or intervention. This eliminates time-consuming manual key management while the automation handles the complexity of key distribution across multiple devices.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10686595B2Configuring connectivity association key and connectivity association name in a media access control security capable device
Publication Date: 2020.06.16 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10686595B2 patent drawing
  • US10686595B2 patent drawing
  • US10686595B2 patent drawing

AI summary

Examples disclosed herein relate to configuring a connectivity association key and a connectivity association name in a MACsec capable device. In an example, a first MACsec device may receive a MAC address and a device identifier of a second MACsec capable device. First MACsec capable device may authenticate the second MACsec capable device based on the device identifier. First MACsec capable device may generate a CAK, a CKN, and a nonce. The CAK, the CKN, and the nonce may be encrypted using a public key of the second MACsec capable device to generate an encrypted packet. The encrypted packet may be sent to the second MACsec capable device. The first MACsec capable device may receive a decrypted nonce from the second MACsec capable device. In response to a determination that the decrypted nonce matches with the nonce, CAK and CKN may be configured on first MACsec capable device.