MACsec Pre-Shared Key Advertisement for Quantum Resistance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The MACsec key agreement protocol is vulnerable to quantum attacks, which can compromise the security of MACsec traffic, and existing protocols lack functionality for entities to advertise and establish secure communication using pre-shared secret keys effectively.

Innovation Solution

The method involves using pre-shared secret keys or distributed shared keys for secure MAC layer communication, where entities can advertise their capability to communicate securely using these keys, and if one entity is not capable, they can switch to a distributed shared key for secure communication, with key derivation and negotiation processes based on post-quantum key sources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the MKA protocol uses EAP-TLS authentication with public-key cryptography, then mutual authentication and key derivation are achieved, but the system becomes vulnerable to quantum attacks that can compromise the security of MACsec traffic

Engineering Contradiction:
Improvesecurity of MACsec trafficVSAvoidquantum attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the cryptographic parameter from public-key cryptography to pre-shared secret key cryptography. This parameter change makes the system quantum-resistant while maintaining the essential functions of mutual authentication and key derivation. The pre-shared secret key is distributed out-of-band before communication, eliminating the need for quantum-vulnerable public-key operations.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent applies preliminary action by distributing the pre-shared secret key before the actual communication establishment. The key is pre-distributed through secure out-of-band methods, and then used during the MKA protocol execution. This preliminary key distribution avoids the need for quantum-vulnerable key exchange operations during the authentication process.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the protocol advertises pre-shared secret key capability, then quantum-secure communication can be established, but entities without this capability cannot communicate securely

Engineering Contradiction:
Improvequantum-secure communicationVSAvoidcompatibility with legacy entities
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamics by making the authentication method selectable and adaptable. The system dynamically chooses between pre-shared secret key mode and traditional EAP-TLS mode based on the capabilities of the communicating entities. The capability advertisement mechanism allows entities to signal their preferred method, and the protocol flexibly adapts to the lowest common denominator capability present in the communication pair.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent achieves universality by designing the MKA protocol to support multiple authentication methods within a single framework. The protocol can function with pre-shared secret keys, EAP-TLS, or other authentication methods. This multi-functionality ensures that the system can accommodate both quantum-capable and legacy entities, maintaining broad compatibility while enabling quantum-secure communication when both parties support it.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If pre-shared secret keys are used for quantum-secure communication, then security against quantum attacks is improved, but the key distribution and management complexity increases

Engineering Contradiction:
Improvequantum resistanceVSAvoidkey distribution and management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the key distribution problem from the protocol execution phase and moves it to a separate out-of-band setup phase. The pre-shared secret key is distributed through external secure channels (physical delivery, secure hardware, manual configuration) before the MKA protocol runs. This extraction simplifies the protocol itself, as it only needs to use the pre-distributed key rather than manage the complex distribution process.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary key management system that handles the complex aspects of pre-shared secret key distribution and management. This intermediary layer (separate from the MKA protocol) provides key generation, distribution, storage, and rotation services. By offloading these complex functions to a dedicated intermediary system, the MKA protocol itself remains relatively simple while still achieving quantum-secure communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11381391B2Pre-shared secret key capabilities in secure MAC layer communication protocols
Publication Date: 2022.07.05 CISCO TECHNOLOGY INC
  • US11381391B2 patent drawing
  • US11381391B2 patent drawing
  • US11381391B2 patent drawing

AI summary

A first computing node configures for communication with a second computing node according to a secure Media Access Layer (MAC) layer communication protocol. The first computing node transmits a first message, to the second computing node. The first message includes at least a first indication that the first computing node is capable of communicating according to the secure MAC layer communication protocol based on a pre-shared secret key. The first computing nodes determines to communicate with the second computing node according to the secure MAC layer communication protocol based on one of a pre-shared secret key or a distributed shared key. The first computing node, at least in part based on the determining, transmits a second message to the second computing node according to the secure MAC layer communication protocol based on the one of the pre-shared secret key or the distributed shared key.