MACsec Link Alert for Faster Session Failure Rerouting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The MACsec standard's requirement for frequent MKPDU exchanges leads to significant delays in detecting session failures, causing data buffering and inefficient resource usage due to the delay between the cessation of effective communication and rerouting, resulting in network anomalies and reduced throughput.

Innovation Solution

Implementing an early alarm mechanism that signals a MACsec link alert after a single 'liveness' interval without receiving an MKPDU, allowing for earlier rerouting and reducing data buffering.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If MKPDU exchanges are performed at the frequency specified by the MACsec standard, then security session maintenance is ensured, but detection delay increases and network throughput decreases

Engineering Contradiction:
ImproveMACsec session maintenanceVSAvoidsession failure detection delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces a preliminary alarm mechanism that triggers before the standard MACsec session timeout. When a router detects that an MKPDU has not been received within a threshold time (shorter than the full MKA Lifetime period), it generates a link alert and initiates rerouting procedures in advance, before the session officially times out. This preliminary action prevents the detection delay inherent in the standard approach.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the MACsec session timeout threshold is used as the detection criterion, then session security is maintained, but data buffering increases and resource usage becomes inefficient

Engineering Contradiction:
Improvesession securityVSAvoidnetwork throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The invention performs preliminary rerouting actions by generating link alerts before the MACsec session officially times out. When the threshold time elapses without receiving an MKPDU, the router proactively triggers rerouting procedures, allowing data to be redirected to alternative paths before buffering occurs. This maintains session security requirements while preventing productivity loss from data buffering.

Inventive Principle:
Principle #10Preliminary action

3Loss of time

If early alarm mechanism is implemented, then network convergence time is improved, but additional signaling overhead is introduced

Engineering Contradiction:
Improvenetwork convergence timeVSAvoidsignaling overhead
Core Design Contradiction:
Loss of timeVSQuantity of substance

Solution Approach 1:

The patent changes the time parameter by introducing a configurable threshold time that is shorter than the standard MKA Lifetime period. This parameter adjustment enables earlier detection and alarm generation without fundamentally changing the MACsec protocol structure. The threshold can be tuned to balance between early detection benefits and minimizing false alarms, thus managing signaling overhead while improving convergence time.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3979588B1Improved error handling for media access control security
Publication Date: 2025.12.10 JUNIPER NETWORKS INC
  • EP3979588B1 patent drawingFigure 1
  • EP3979588B1 patent drawingFigure 2
  • EP3979588B1 patent drawingFigure 3

AI summary

Embodiments improve error detection and recovery in media access control security sessions. A MACsec session is torn down after three liveness time intervals elapse without receiving a MACsec key exchange protocol data unit (MKPDU) from a remote peer. This delay between a cessation of effective network communication over the MACsec session and the expiration of the three "liveness" intervals results in increased packet loss and an increased network convergence time as a network continues to route/forward data over the MACsec session for a period of time after the MACsec session has entered secure block mode. To solve this problem, embodiments define a new alarm, called a MACsec link alert, which is raised earlier than a MACsec session timeout generated by traditional embodiments. The MACsec link alert is raised, by at least some embodiments, after a failure to successfully receive an MKPDU from the remote peer after a single MACsec "liveness" timeout interval elapses.