Tunneling MACSec Packets Through Non-MACSec Nodes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Ethernet networks face challenges in upgrading to MACSec compatibility, as non-MACSec-enabled nodes cannot properly process MACSec frames due to the SecTAG being improperly parsed as a VLAN tag, leading to issues in network access control and security.

Innovation Solution

A method and system for tunneling MACSec packets through non-MACSec nodes by inserting additional header information, such as VLAN tags, into MACSec packets before transmission, allowing them to be identified and processed correctly by both MACSec and non-MACSec-enabled nodes, and removing this information when received from non-MACSec nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If MACSec frames are transmitted through non-MACSec nodes, then network security is improved, but the SecTAG is improperly parsed as a VLAN tag causing transmission failures

Engineering Contradiction:
Improvenetwork securityVSAvoidcompatibility with non-MACSec nodes
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a tunneling mechanism that acts as an intermediary between MACSec and non-MACSec nodes. The tunnel encapsulates MACSec frames within standard Ethernet frames, adding an outer Ethernet header that non-MACSec nodes can properly parse. This tunneling layer mediates the interaction, allowing secure MACSec traffic to pass through legacy infrastructure without modification to the underlying non-MACSec nodes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network into MACSec-capable segments and non-MACSec segments. By dividing the network path into these distinct segments, MACSec frames can be transmitted securely through MACSec-enabled portions while being tunnel-encoded for passage through non-MACSec portions. This segmentation allows the system to maintain security requirements while accommodating legacy infrastructure.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If hardware upgrades to MACSec compatibility are implemented, then packet processing accuracy is improved, but network deployment cost and complexity increase

Engineering Contradiction:
Improvepacket processing accuracyVSAvoidhardware upgrade requirements
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements dynamic packet handling where nodes can adapt their processing behavior based on the packet format received. MACSec-capable nodes dynamically detect and process tunnel-encoded MACSec frames, while non-MACSec nodes continue to handle standard Ethernet frames. This dynamic adaptation allows the network to function with mixed capabilities without requiring universal hardware upgrades.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The tunneling mechanism provides universal compatibility by making MACSec frames readable by both MACSec-capable and non-MACSec nodes. The outer Ethernet encapsulation makes the packets universally recognizable across different node types, allowing the same infrastructure to support both legacy and advanced security requirements without specialized hardware for each node type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7729276B2Method and system for tunneling MACSec packets through non-MACSec nodes
Publication Date: 2010.06.01 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
  • US7729276B2 patent drawing
  • US7729276B2 patent drawing
  • US7729276B2 patent drawing

AI summary

Aspects of a method and system for tunneling MACSec packets through non-MACSec-enabled nodes are provided. In this regard, aspects of the invention may be utilized for transmitting MACSec Ethernet packets over MACSec and/or non-MACSec-enabled network nodes. In one embodiment of the invention, additional header information may be inserted into a MACSec packet before transmitting the MACSec packet to a non-MACSec-enabled node. Accordingly, aspects of the invention may remove the additional header information from a packet received from a non-MACSec-enabled node to distinguish the packets comprising inserted additional header information, which may comprise a distinguishing Ethertype.