MACsec Tunneling Protocol Independence via Packet Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security protocols are limited by specific tunneling protocols that are tied to the security protocol, restricting flexibility in network implementations and forcing administrators to use a single type of tunneling protocol with a particular security protocol.

Innovation Solution

A network device equipped with a packet processor that can classify packets to determine if encryption and tunneling headers are needed, allowing for the addition of a security header and a tunneling header with a format independent of the security protocol, enabling the use of any suitable tunneling protocol alongside any network security protocol.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If a network security protocol is tied to a specific tunneling protocol format, then the security implementation is simplified and standardized, but the flexibility and adaptability of network implementations are restricted

Engineering Contradiction:
Improveimplementation simplicityVSAvoidtunneling protocol flexibility
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent separates the security protocol processing from the tunneling protocol processing by introducing distinct header structures. The security header (with security parameters like SCI, ICV) is segmented from the tunneling header (with routing information), allowing independent processing and validation of security functions while maintaining compatibility with multiple tunneling protocols.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary tunneling header structure that sits between the security-encrypted payload and the outer network headers. This intermediary layer provides a standardized interface for security protocols while allowing flexible outer header formats for different tunneling protocols (VXLAN, GRE, MPLS, etc.), thus mediating between security requirements and tunneling flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple tunneling protocols are supported with independent formats, then the adaptability to different network requirements is improved, but the device complexity increases

Engineering Contradiction:
Improvetunneling protocol supportVSAvoidpacket processing complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal packet structure where a single security header format can work with multiple tunneling protocols. The classification engine universally identifies packets requiring security processing, and the same security header format is applied regardless of which tunneling protocol is used, making the security subsystem multi-functional and protocol-agnostic.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses parameter changes to differentiate tunneling protocols rather than structural changes. By modifying specific fields within the tunneling header (such as protocol type indicators, destination ports, or specific header fields), the system can support multiple tunneling protocols while maintaining a consistent overall packet structure and security processing approach.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If the entire packet is encrypted, then the security coverage is maximized, but the ability to perform selective processing and routing operations is reduced

Engineering Contradiction:
Improvesecurity coverageVSAvoidselective packet processing
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent performs preliminary actions by adding the security header and performing encryption on specific portions of the packet before the packet enters the tunneling process. This allows security to be applied selectively to the necessary data portions while leaving other portions (such as outer headers) unencrypted for routing and processing operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies encryption with local quality by encrypting only specific portions of the packet that require security protection, while leaving other portions (such as outer headers, routing information, or non-sensitive data) in plaintext. This selective encryption approach maintains security for sensitive data while enabling efficient processing and routing of non-sensitive portions.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12088562B1Tunneling of MACsec frames
Publication Date: 2024.09.10 MARVELL ISRAEL (M L S L) LTD
  • US12088562B1 patent drawing
  • US12088562B1 patent drawing
  • US12088562B1 patent drawing

AI summary

A network device is capable of transmitting and/or receiving packets that are encrypted according to a particular network security protocol, while being encapsulated according to any of a variety of tunneling protocols independent of the particular network security protocol. In such embodiments, a customer or network administrator can use the particular network security protocol while having the freedom to choose a particular tunneling protocol that is best suited for a network implementation instead of being limited to a specific tunneling protocol for a particular network security protocol.