MACSEC Switch Router Packet Handling Information Placement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current MACSEC protocols require at least two devices to transport secure packets across third-party networks, with security information inserted after destination/source addresses, limiting network intelligence and efficiency in handling packets.
Innovation Solution
An enhanced MACSEC switch-router integrates MACSEC communication and VLAN/MPLS functions into a single device, inserting packet handling information ahead of security information, allowing controlled packet handling without decrypting the data, enabling priority routing and billing without hardware/software changes in intermediate network equipment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security information is inserted after destination/source addresses in MACSEC packets, then packet security is maintained, but network intelligence and efficiency in handling packets is limited
Solution Approach 1:
The packet structure is segmented into clear and protected portions. Packet handling information is placed in the clear portion before security information, allowing network devices to process routing and QoS decisions without decrypting the payload, while security information remains protected after encryption
Solution Approach 2:
Packet handling information is inserted in the clear ahead of security information processing. This preliminary placement of handling information enables network devices to make routing and QoS decisions before the security verification and decryption processes occur
2Reliability
If two separate devices are used to encrypt and tunnel MACSEC packets, then security is maintained, but device complexity and cost increase
Solution Approach 1:
The patent combines multiple functions (MACSEC encryption, VLAN tagging, MPLS labeling, and packet handling information insertion) into a single integrated device. This consolidation eliminates the need for separate encryption and tunneling devices, reducing complexity while maintaining security through the preserved clear/protected portion structure
3Reliability
If all packet information is hidden from forwarding networks, then security is improved, but network intelligence in handling packets is reduced
Solution Approach 1:
Different portions of the packet are assigned different security qualities. The clear portion contains packet handling information accessible to network devices for intelligent routing and QoS, while the protected portion contains encrypted payload information that remains confidential. This local differentiation allows both security and network intelligence
Data Source
AI summary
Techniques are provided to append packet handling information “in the clear” ahead of security related information in a packet to be routed over a network to optimize wide area network deployments of security-configured equipment. In one form, at a network device that performs connectionless secure communication and network routing of packets, data is received from a source device to be sent through a network to a destination device. Packet handling information is inserted in a packet that is to be used to transport the data. The packet handling information is configured to enable controlled handling of the packet in the network and is inserted in an unprotected portion of the packet. Encrypted payload data is generated from the data received from the source device. The encrypted payload data and security information are inserted in a protected portion of the packet and the packet is sent to the network.


