MACsec Key Server AN Cycling for Limited Hardware

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network devices with hardware limitations on association number (AN) values, such as only supporting {0, 1}, face challenges in reliable operation within MACsec groups due to the inability to manage the full range of AN values required by the IEEE 802.1X-2010 standard, potentially disrupting network activity.

Innovation Solution

A peer device in a MACsec group sets its key server priority to the highest value to maximize the likelihood of being elected as the key server and then cycles the AN between 0 and 1 for successive Secure Association Keys (SAKs), ensuring seamless operation and compatibility with AN-limited hardware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a peer device sets its key server priority to the highest value to ensure election as key server, then the device can control AN cycling between 0 and 1, but this requires the device to have hardware capability to support only two AN values which limits the MACsec group configuration flexibility

Engineering Contradiction:
Improvereliable operationVSAvoidAN value range support
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by allowing different peer devices in the MACsec group to have different AN support capabilities. The key server (which may have limited AN support) controls the AN assignment locally, cycling between 0 and 1, while other peer devices with full AN support accommodate this limited range. This resolves the contradiction by making the AN value range adaptation local to the key server rather than requiring all devices to have the same capability.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

Instead of requiring all peer devices to support the full range of AN values as specified by the IEEE standard, the patent inverts the approach by having the key server deliberately use only a subset of AN values (0 and 1). This inversion allows devices with hardware limitations to function as key servers while maintaining MACsec security, resolving the contradiction between reliability and adaptability.

Inventive Principle:
Principle #13The other way round (Inversion)

2Device complexity

If hardware is designed to use only a single bit to manage the AN, then the device complexity is reduced, but the device can only support two AN values which disrupts network activity when more than two AN values are encountered

Engineering Contradiction:
Improvehardware complexityVSAvoidnetwork operation reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent applies parameter changes by modifying the AN value parameter used by the key server. Instead of using the full range of AN values that would require multi-bit hardware, the key server changes the parameter to use only two values (0 and 1). This allows simple single-bit hardware to maintain reliable network operation by adapting the AN parameter to match hardware capabilities.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements dynamics by making the AN assignment dynamic and controlled by the key server. The key server dynamically cycles between AN values 0 and 1 based on operational needs, rather than using static AN assignments. This dynamic approach allows the system to adapt to hardware limitations while maintaining reliable network operation.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12192330B2Media access control (MAC) security with association number flexibility
Publication Date: 2025.01.07 ARISTA NETWORKS INC
  • US12192330B2 patent drawing
  • US12192330B2 patent drawing
  • US12192330B2 patent drawing

AI summary

Embodiments allow a network device whose hardware limits an Association Number (AN) to only {0, 1}, to be part of Media Access Control security (MACsec). Upon detecting a network device as being AN-limited, that device's priority value is assigned a maximum value, thereby ensuring election of the AN-limited device as the key server. The {0, 1} AN of the key server is used to generate a Secure Association Key (SAK) used for MACsec. Upon subsequent rekeying, the AN-limited key server automatically cycles to a next AN (either 0 or 1) to generate a new SAK, where that next AN is also recognized by other network devices. In this manner, the AN-limited network device can participate in the MACsec without encountering ANs (e.g., {2, 3}) that it does not recognize.