Extending MACsec MKA Protocol with Attestation Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing MACsec protocol lacks a mechanism to verify if peers or devices in communication have been compromised, as it does not provide any means to validate the integrity of hardware, firmware, or software during the session, leaving the network vulnerable to tampering or unauthorized access.

Innovation Solution

The proposed solution extends the MAC Security Key Agreement (MKA) protocol by incorporating a 'canary stamp' or attestation data into the MACsec protocol, allowing devices to validate the integrity of peers during the initial handshake, ensuring secure communication by confirming the uncompromised state of nodes and devices within the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If MACsec protocol is used to secure Ethernet links, then data integrity and security are improved, but the protocol cannot verify if peers or devices have been compromised

Engineering Contradiction:
Improvedata securityVSAvoidintegrity verification capability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies preliminary action by incorporating attestation data into the MKA protocol exchange during the initial key establishment phase. This allows devices to verify each other's integrity before securing the link, preventing compromised devices from establishing secure connections in the first place

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces attestation data as an intermediary element that mediates between devices during the MKA protocol exchange. This attestation data carries integrity information about the devices, allowing peer verification without requiring direct inspection of hardware or firmware

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If MACsec provides point-to-point security, then most security threats are prevented, but the protocol lacks mechanism to validate hardware, firmware, or software integrity

Engineering Contradiction:
Improvesecurity protectionVSAvoidintegrity validation mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by extending the existing MKA protocol to serve multiple functions: not only key agreement and link security establishment, but also device integrity verification. This avoids creating a separate complex validation system while maintaining the protocol's core security functions

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements feedback by having devices exchange attestation data during the MKA protocol exchange. Each device receives and validates attestation information from its peer, providing feedback on whether the peer is compromised, which determines whether to proceed with link establishment

Inventive Principle:
Principle #23Feedback

3Reliability

If MACsec secures all Ethernet link traffic, then data integrity checks are performed, but there is no way to confirm nodes are uncompromised

Engineering Contradiction:
Improvedata integrityVSAvoidnode compromise detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies preliminary action by performing integrity verification through attestation data exchange before the MACsec link is fully established. This allows devices to detect compromised nodes in advance, preventing them from participating in the secured communication

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces the need for direct physical inspection or complex monitoring of device internals with a cryptographic attestation mechanism. Devices prove their integrity through cryptographic signatures on attestation data, substituting mechanical or invasive verification methods with a software-based cryptographic proof system

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11316869B2Systems and methods for providing attestation of data integrity
Publication Date: 2022.04.26 CISCO TECHNOLOGY INC
  • US11316869B2 patent drawing
  • US11316869B2 patent drawing
  • US11316869B2 patent drawing

AI summary

Disclosed is a method of establishing secure communications. The method includes receiving an attestation parameter associated with a first peer in a potential peer-to-peer communication, adding the attestation parameter to an MACsec Key Agreement (MKA) protocol key exchange, transmitting the key exchange from the first peer to a second peer in the potential peer-to-peer communication and upon a validation of the attestation parameter by the second peer, enabling secure communication between the first peer and the second peer.