MACsec Key Distribution for Processorless Ethernet Bridges

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Ethernet bridges with limited resources face challenges in implementing the MACsec Key Agreement (EAPOL-MKA) protocol due to the need for significant silicon space and memory, which is typically handled by a processor and non-volatile storage, making it inefficient for resource-constrained devices.

Innovation Solution

A hardware-based protocol for secured key distribution is implemented using existing MACsec hardware blocks in Ethernet bridges, generating session encryption keys independently by the host and bridge, and exchanging frames to match and install Secure Association Keys (SAKs) without requiring a CPU or flash memory, utilizing AES-GCM and AES-CMAC for encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If EAPOL-MKA protocol is implemented using software and processor, then secure key distribution is achieved, but silicon space and memory requirements increase significantly

Engineering Contradiction:
Improvesecure key distributionVSAvoidsilicon space and memory
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces the software-based EAPOL-MKA protocol implementation with a hardware-based MACsec protocol implementation. The Ethernet bridge uses dedicated hardware blocks (MACsec encryptor, cryptographic engine) to perform key distribution and security functions that traditionally required software processing, thereby reducing silicon space and memory requirements while maintaining security reliability

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The Ethernet bridge autonomously generates session encryption keys using its internal cryptographic engine and hardware blocks without requiring external processor intervention. The bridge independently manages key distribution, installation, and security channel establishment, eliminating the need for software-based protocol state machines and reducing overall system complexity

Inventive Principle:
Principle #25Self-service

2Device complexity

If resource-constrained Ethernet bridge is used, then device simplicity is improved, but ability to implement EAPOL-MKA protocol deteriorates

Engineering Contradiction:
Improvedevice simplicityVSAvoidprotocol implementation capability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal MACsec hardware architecture in the Ethernet bridge that can handle multiple security functions including key generation, key distribution, encryption, and authentication. This multi-functional hardware design enables resource-constrained bridges to implement secure key distribution protocols without requiring separate software components or additional processing resources

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent substitutes software-based protocol implementation with hardware-based MACsec protocol execution. The Ethernet bridge uses dedicated hardware blocks to automatically perform key distribution and security management functions, enabling resource-constrained devices to achieve protocol capability without the overhead of software processing

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20260025261A1Method and apparatus for secured key distribution between a host and a resource constrained ethernet bridge
Publication Date: 2026.01.22 MARVELL ASIA PTE LTD
  • US20260025261A1 patent drawing
  • US20260025261A1 patent drawing
  • US20260025261A1 patent drawing

AI summary

A new approach is proposed to support secured key distribution between a host and a resource-constrained Ethernet bridge using MACSec, wherein the resource-constrained Ethernet bridge is a hardware having a plurality of hardware blocks but no processor or non-volatile storage. Under the proposed approach, a protocol for secured key distribution is fully implemented using existing hardware blocks of the resource-constrained Ethernet bridge. First, session encryption keys (SEKs) are generated independently by both the host and the Ethernet bridge. If the SEKs match, the host is configured to generate and distribute a Secure Association Key (SAK) to the Ethernet bridge to be installed on it. After the SAK is installed on the Ethernet bridge, a secured communication channel is established between the host and the Ethernet bridge. The secured communication channel can be utilized for secured communication of sensitive data collected by the Ethernet bridge from a plurality of electronic devices.