MACsec Enabled Link Aggregation Group Traffic Reliability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

When using Link Aggregation Groups (LAGs) with Media Access Control Security (MACsec), existing technologies face issues where traffic is dropped if a MACsec session has not been established or has terminated on a particular link, and devices cannot utilize other available MACsec enabled links within the LAG, limiting bandwidth utilization.

Innovation Solution

A method and device implementation that allows establishing MACsec sessions on multiple links within a LAG, updating data structures to identify these links as MACsec enabled, and sending traffic over any available MACsec enabled links, ensuring continuous data transmission even if a specific link's MACsec session terminates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a MACsec session is established on a single link of a LAG, then security is provided on that link, but traffic is dropped if the session terminates and other available links cannot be utilized

Engineering Contradiction:
Improvetraffic transmission reliabilityVSAvoidlink utilization flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent merges multiple LAG links into a unified MACsec-enabled interface by creating a shared MACsec session context. The system combines multiple physical links (port-channel) and applies a single MACsec security domain across all of them, allowing traffic to be distributed across multiple links while maintaining security. When one link fails, traffic automatically shifts to other available links within the same MACsec session, preventing traffic drops.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent makes the MACsec session universal across multiple LAG links by implementing a shared security context that can serve multiple physical interfaces simultaneously. The MACsec session is not bound to a single link but is instead associated with the LAG as a whole, enabling any link in the group to carry secured traffic. This multi-functional approach allows the system to adapt to link failures and utilize any available link for traffic transmission.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If MACsec sessions are established on multiple links within a LAG, then bandwidth utilization increases, but device complexity increases

Engineering Contradiction:
Improvebandwidth utilizationVSAvoidsession management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent reduces device complexity by merging the management of multiple MACsec sessions into a single unified session. Instead of independently managing MACsec sessions on each LAG link, the system creates one MACsec session that spans multiple links. This consolidation simplifies session establishment, key management, and state tracking while still enabling bandwidth aggregation across multiple physical links through the port-channel interface.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If traffic is sent over a single MACsec enabled link, then security is maintained, but bandwidth utilization is limited

Engineering Contradiction:
Improvesecurity maintenanceVSAvoidbandwidth utilization
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent combines multiple physical links into a single logical interface (port-channel) and applies MACsec security at the logical interface level rather than individual link level. This allows traffic to be distributed across multiple physical links for increased bandwidth while maintaining a single security context. The MACsec encryption and authentication are applied uniformly across all links in the aggregation group, ensuring security is maintained while utilizing the combined bandwidth of all links.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12273325B2Media access control security (MACsec) enabled links of a link aggregation group (LAG)
Publication Date: 2025.04.08 JUNIPER NETWORKS INC
  • US12273325B2 patent drawing
  • US12273325B2 patent drawing
  • US12273325B2 patent drawing

AI summary

A device may cause a Media Access Control Security (MACsec) session to be established on a first link of a link aggregation group (LAG) that includes a plurality of links with a different device. The device may cause a data structure to be updated to identify the first link as a MACsec enabled LAG link and may send traffic via the first link. The device may cause a MACsec session to be established on at least one additional link of the LAG and may cause the data structure to be updated to identify the at least one additional link as a MACsec enabled LAG link. The device may send, after causing the data structure to be updated to identify the at least one additional link as a MACsec enabled LAG link, additional traffic via the first link and the at least one additional link.