MACsec Link Alert for Faster Session Failure Rerouting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The MACsec standard's requirement for frequent MKPDU exchanges leads to significant delays in detecting session failures, causing data buffering and inefficient resource usage due to the delay between the cessation of effective communication and rerouting, resulting in network anomalies and reduced throughput.
Innovation Solution
Implementing an early alarm mechanism that signals a MACsec link alert after a single 'liveness' interval without receiving an MKPDU, allowing for earlier rerouting and reducing data buffering.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MKPDU exchanges are performed at the frequency specified by the MACsec standard, then security session maintenance is ensured, but detection delay increases and network throughput decreases
Solution Approach 1:
The patent introduces a preliminary alarm mechanism that triggers before the standard MACsec session timeout. When a router detects that an MKPDU has not been received within a threshold time (shorter than the full MKA Lifetime period), it generates a link alert and initiates rerouting procedures in advance, before the session officially times out. This preliminary action prevents the detection delay inherent in the standard approach.
2Reliability
If the MACsec session timeout threshold is used as the detection criterion, then session security is maintained, but data buffering increases and resource usage becomes inefficient
Solution Approach 1:
The invention performs preliminary rerouting actions by generating link alerts before the MACsec session officially times out. When the threshold time elapses without receiving an MKPDU, the router proactively triggers rerouting procedures, allowing data to be redirected to alternative paths before buffering occurs. This maintains session security requirements while preventing productivity loss from data buffering.
3Loss of time
If early alarm mechanism is implemented, then network convergence time is improved, but additional signaling overhead is introduced
Solution Approach 1:
The patent changes the time parameter by introducing a configurable threshold time that is shorter than the standard MKA Lifetime period. This parameter adjustment enables earlier detection and alarm generation without fundamentally changing the MACsec protocol structure. The threshold can be tuned to balance between early detection benefits and minimizing false alarms, thus managing signaling overhead while improving convergence time.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Embodiments improve error detection and recovery in media access control security sessions. A MACsec session is torn down after three liveness time intervals elapse without receiving a MACsec key exchange protocol data unit (MKPDU) from a remote peer. This delay between a cessation of effective network communication over the MACsec session and the expiration of the three "liveness" intervals results in increased packet loss and an increased network convergence time as a network continues to route/forward data over the MACsec session for a period of time after the MACsec session has entered secure block mode. To solve this problem, embodiments define a new alarm, called a MACsec link alert, which is raised earlier than a MACsec session timeout generated by traditional embodiments. The MACsec link alert is raised, by at least some embodiments, after a failure to successfully receive an MKPDU from the remote peer after a single MACsec "liveness" timeout interval elapses.