MACsec Key Server AN Cycling for Limited Hardware
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network devices with hardware limitations on association number (AN) values, such as only supporting {0, 1}, face challenges in reliable operation within MACsec groups due to the inability to manage the full range of AN values required by the IEEE 802.1X-2010 standard, potentially disrupting network activity.
Innovation Solution
A peer device in a MACsec group sets its key server priority to the highest value to maximize the likelihood of being elected as the key server and then cycles the AN between 0 and 1 for successive Secure Association Keys (SAKs), ensuring seamless operation and compatibility with AN-limited hardware.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a peer device sets its key server priority to the highest value to ensure election as key server, then the device can control AN cycling between 0 and 1, but this requires the device to have hardware capability to support only two AN values which limits the MACsec group configuration flexibility
Solution Approach 1:
The patent applies local quality by allowing different peer devices in the MACsec group to have different AN support capabilities. The key server (which may have limited AN support) controls the AN assignment locally, cycling between 0 and 1, while other peer devices with full AN support accommodate this limited range. This resolves the contradiction by making the AN value range adaptation local to the key server rather than requiring all devices to have the same capability.
Solution Approach 2:
Instead of requiring all peer devices to support the full range of AN values as specified by the IEEE standard, the patent inverts the approach by having the key server deliberately use only a subset of AN values (0 and 1). This inversion allows devices with hardware limitations to function as key servers while maintaining MACsec security, resolving the contradiction between reliability and adaptability.
2Device complexity
If hardware is designed to use only a single bit to manage the AN, then the device complexity is reduced, but the device can only support two AN values which disrupts network activity when more than two AN values are encountered
Solution Approach 1:
The patent applies parameter changes by modifying the AN value parameter used by the key server. Instead of using the full range of AN values that would require multi-bit hardware, the key server changes the parameter to use only two values (0 and 1). This allows simple single-bit hardware to maintain reliable network operation by adapting the AN parameter to match hardware capabilities.
Solution Approach 2:
The patent implements dynamics by making the AN assignment dynamic and controlled by the key server. The key server dynamically cycles between AN values 0 and 1 based on operational needs, rather than using static AN assignments. This dynamic approach allows the system to adapt to hardware limitations while maintaining reliable network operation.
Data Source
AI summary
Embodiments allow a network device whose hardware limits an Association Number (AN) to only {0, 1}, to be part of Media Access Control security (MACsec). Upon detecting a network device as being AN-limited, that device's priority value is assigned a maximum value, thereby ensuring election of the AN-limited device as the key server. The {0, 1} AN of the key server is used to generate a Secure Association Key (SAK) used for MACsec. Upon subsequent rekeying, the AN-limited key server automatically cycles to a next AN (either 0 or 1) to generate a new SAK, where that next AN is also recognized by other network devices. In this manner, the AN-limited network device can participate in the MACsec without encountering ANs (e.g., {2, 3}) that it does not recognize.


