Extending MACsec MKA Protocol with Attestation Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing MACsec protocol lacks a mechanism to verify if peers or devices in communication have been compromised, as it does not provide any means to validate the integrity of hardware, firmware, or software during the session, leaving the network vulnerable to tampering or unauthorized access.
Innovation Solution
The proposed solution extends the MAC Security Key Agreement (MKA) protocol by incorporating a 'canary stamp' or attestation data into the MACsec protocol, allowing devices to validate the integrity of peers during the initial handshake, ensuring secure communication by confirming the uncompromised state of nodes and devices within the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MACsec protocol is used to secure Ethernet links, then data integrity and security are improved, but the protocol cannot verify if peers or devices have been compromised
Solution Approach 1:
The patent applies preliminary action by incorporating attestation data into the MKA protocol exchange during the initial key establishment phase. This allows devices to verify each other's integrity before securing the link, preventing compromised devices from establishing secure connections in the first place
Solution Approach 2:
The patent introduces attestation data as an intermediary element that mediates between devices during the MKA protocol exchange. This attestation data carries integrity information about the devices, allowing peer verification without requiring direct inspection of hardware or firmware
2Reliability
If MACsec provides point-to-point security, then most security threats are prevented, but the protocol lacks mechanism to validate hardware, firmware, or software integrity
Solution Approach 1:
The patent applies universality by extending the existing MKA protocol to serve multiple functions: not only key agreement and link security establishment, but also device integrity verification. This avoids creating a separate complex validation system while maintaining the protocol's core security functions
Solution Approach 2:
The patent implements feedback by having devices exchange attestation data during the MKA protocol exchange. Each device receives and validates attestation information from its peer, providing feedback on whether the peer is compromised, which determines whether to proceed with link establishment
3Reliability
If MACsec secures all Ethernet link traffic, then data integrity checks are performed, but there is no way to confirm nodes are uncompromised
Solution Approach 1:
The patent applies preliminary action by performing integrity verification through attestation data exchange before the MACsec link is fully established. This allows devices to detect compromised nodes in advance, preventing them from participating in the secured communication
Solution Approach 2:
The patent replaces the need for direct physical inspection or complex monitoring of device internals with a cryptographic attestation mechanism. Devices prove their integrity through cryptographic signatures on attestation data, substituting mechanical or invasive verification methods with a software-based cryptographic proof system
Data Source
AI summary
Disclosed is a method of establishing secure communications. The method includes receiving an attestation parameter associated with a first peer in a potential peer-to-peer communication, adding the attestation parameter to an MACsec Key Agreement (MKA) protocol key exchange, transmitting the key exchange from the first peer to a second peer in the potential peer-to-peer communication and upon a validation of the attestation parameter by the second peer, enabling secure communication between the first peer and the second peer.


