MACSEC Switch Router Packet Handling Information Placement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current MACSEC protocols require at least two devices to transport secure packets across third-party networks, with security information inserted after destination/source addresses, limiting network intelligence and efficiency in handling packets.

Innovation Solution

An enhanced MACSEC switch-router integrates MACSEC communication and VLAN/MPLS functions into a single device, inserting packet handling information ahead of security information, allowing controlled packet handling without decrypting the data, enabling priority routing and billing without hardware/software changes in intermediate network equipment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security information is inserted after destination/source addresses in MACSEC packets, then packet security is maintained, but network intelligence and efficiency in handling packets is limited

Engineering Contradiction:
Improvepacket securityVSAvoidpacket handling efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The packet structure is segmented into clear and protected portions. Packet handling information is placed in the clear portion before security information, allowing network devices to process routing and QoS decisions without decrypting the payload, while security information remains protected after encryption

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Packet handling information is inserted in the clear ahead of security information processing. This preliminary placement of handling information enables network devices to make routing and QoS decisions before the security verification and decryption processes occur

Inventive Principle:
Principle #10Preliminary action

2Reliability

If two separate devices are used to encrypt and tunnel MACSEC packets, then security is maintained, but device complexity and cost increase

Engineering Contradiction:
ImprovesecurityVSAvoidnumber of devices
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple functions (MACSEC encryption, VLAN tagging, MPLS labeling, and packet handling information insertion) into a single integrated device. This consolidation eliminates the need for separate encryption and tunneling devices, reducing complexity while maintaining security through the preserved clear/protected portion structure

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If all packet information is hidden from forwarding networks, then security is improved, but network intelligence in handling packets is reduced

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork intelligence
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Different portions of the packet are assigned different security qualities. The clear portion contains packet handling information accessible to network devices for intelligent routing and QoS, while the protected portion contains encrypted payload information that remains confidential. This local differentiation allows both security and network intelligence

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9571283B2Enabling packet handling information in the clear for MACSEC protected frames
Publication Date: 2017.02.14 CISCO TECHNOLOGY INC
  • US9571283B2 patent drawing
  • US9571283B2 patent drawing
  • US9571283B2 patent drawing

AI summary

Techniques are provided to append packet handling information “in the clear” ahead of security related information in a packet to be routed over a network to optimize wide area network deployments of security-configured equipment. In one form, at a network device that performs connectionless secure communication and network routing of packets, data is received from a source device to be sent through a network to a destination device. Packet handling information is inserted in a packet that is to be used to transport the data. The packet handling information is configured to enable controlled handling of the packet in the network and is inserted in an unprotected portion of the packet. Encrypted payload data is generated from the data received from the source device. The encrypted payload data and security information are inserted in a protected portion of the packet and the packet is sent to the network.