MACSec Session Recovery Using Keep Alive Probes Over WAN
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security protocols like MACSec fail to automatically reestablish sessions over wide area networks due to the lack of direct connectivity at the MAC layer, leading to manual intervention being required for reconnection after a session is prematurely torn down.
Innovation Solution
Implementing a keep alive probe mechanism where electronic devices transmit keep alive probes, such as MACSec HELLO packets, over a wide area network to automatically reestablish the MACSec session after detecting a fault, such as through a VxLAN tunnel.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If MACSec session is established over wide area network through VxLAN tunnel, then network security and flexibility are improved, but automatic reestablishment capability is lost when session is torn down
Solution Approach 1:
The patent introduces a keep alive probe mechanism as an intermediary to detect MAC layer connection status. When the MACSec session is torn down, the electronic device sends keep alive probes through the VxLAN tunnel to check if the underlying MAC layer connection is still intact. If the probe succeeds, the device automatically reinitiates the MACSec handshaking procedure to reestablish the session, thus restoring automatic reestablishment capability over wide area networks.
2Reliability
If direct physical link is used between electronic devices, then automatic MACSec session reestablishment is enabled, but network flexibility and wide area network connectivity are limited
Solution Approach 1:
The patent makes the keep alive probe mechanism universal by implementing it in both direct physical link scenarios and VxLAN tunnel scenarios. The same probe mechanism works regardless of whether the underlying transport is a direct physical link or a wide area network tunnel, allowing automatic session reestablishment to function universally across different network topologies and transport mechanisms.
3Reliability
If MACSec session is torn down due to failure detection, then security is maintained, but manual intervention is required for reconnection over wide area networks
Solution Approach 1:
The patent enables the MACSec session to be self-service by automatically detecting connection status through keep alive probes and autonomously reinitiating the handshaking procedure when the session is torn down but the underlying connection is intact. This eliminates the need for manual intervention to reestablish sessions over wide area networks, while maintaining security by only automatically reestablishing when the probe confirms the connection is safe to restore.
Data Source
AI summary
A first electronic device communicates over a wide area network by establishing a MACSec session with a second electronic device over the wide area network. The MACSec session is thereafter torn down in response to the first electronic device sensing a fault in the MACSec session. Then, one or more keep alive probes are transmitted to the second electronic device over the wide area network. A response to the keep alive probe is thereafter received. The MACSec session may then be automatically reestablished in response to receiving the probe.


