MACsec Tunneling Protocol Independence via Packet Classification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security protocols are limited by specific tunneling protocols that are tied to the security protocol, restricting flexibility in network implementations and forcing administrators to use a single type of tunneling protocol with a particular security protocol.
Innovation Solution
A network device equipped with a packet processor that can classify packets to determine if encryption and tunneling headers are needed, allowing for the addition of a security header and a tunneling header with a format independent of the security protocol, enabling the use of any suitable tunneling protocol alongside any network security protocol.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If a network security protocol is tied to a specific tunneling protocol format, then the security implementation is simplified and standardized, but the flexibility and adaptability of network implementations are restricted
Solution Approach 1:
The patent separates the security protocol processing from the tunneling protocol processing by introducing distinct header structures. The security header (with security parameters like SCI, ICV) is segmented from the tunneling header (with routing information), allowing independent processing and validation of security functions while maintaining compatibility with multiple tunneling protocols.
Solution Approach 2:
The patent introduces an intermediary tunneling header structure that sits between the security-encrypted payload and the outer network headers. This intermediary layer provides a standardized interface for security protocols while allowing flexible outer header formats for different tunneling protocols (VXLAN, GRE, MPLS, etc.), thus mediating between security requirements and tunneling flexibility.
2Adaptability or versatility
If multiple tunneling protocols are supported with independent formats, then the adaptability to different network requirements is improved, but the device complexity increases
Solution Approach 1:
The patent creates a universal packet structure where a single security header format can work with multiple tunneling protocols. The classification engine universally identifies packets requiring security processing, and the same security header format is applied regardless of which tunneling protocol is used, making the security subsystem multi-functional and protocol-agnostic.
Solution Approach 2:
The patent uses parameter changes to differentiate tunneling protocols rather than structural changes. By modifying specific fields within the tunneling header (such as protocol type indicators, destination ports, or specific header fields), the system can support multiple tunneling protocols while maintaining a consistent overall packet structure and security processing approach.
3Reliability
If the entire packet is encrypted, then the security coverage is maximized, but the ability to perform selective processing and routing operations is reduced
Solution Approach 1:
The patent performs preliminary actions by adding the security header and performing encryption on specific portions of the packet before the packet enters the tunneling process. This allows security to be applied selectively to the necessary data portions while leaving other portions (such as outer headers) unencrypted for routing and processing operations.
Solution Approach 2:
The patent applies encryption with local quality by encrypting only specific portions of the packet that require security protection, while leaving other portions (such as outer headers, routing information, or non-sensitive data) in plaintext. This selective encryption approach maintains security for sensitive data while enabling efficient processing and routing of non-sensitive portions.
Data Source
AI summary
A network device is capable of transmitting and/or receiving packets that are encrypted according to a particular network security protocol, while being encapsulated according to any of a variety of tunneling protocols independent of the particular network security protocol. In such embodiments, a customer or network administrator can use the particular network security protocol while having the freedom to choose a particular tunneling protocol that is best suited for a network implementation instead of being limited to a specific tunneling protocol for a particular network security protocol.


