Role-Based MACsec Security Association via VLAN Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In networks protected by the MACsec standard, maintaining role-based security associations is challenging due to issues like mobile devices changing IP addresses and asynchronous updates to access control lists across distributed access points, leading to potential security breaches and access privilege mismanagement.
Innovation Solution
Incorporating a role-based authentication tag into data packets, which can be transmitted within both MACsec and VLAN headers, allowing network devices to maintain their own access control lists based on assigned roles rather than IP addresses, ensuring secure and synchronized access control across the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IP address-based access control is used in MACsec networks, then network security can be implemented, but security associations are broken when mobile devices change IP addresses
Solution Approach 1:
The patent changes the parameter used for access control from IP address to role-based authentication tags. The system extracts role information from MACsec security tags or VLAN tags and uses this role-based identification to maintain consistent access control policies regardless of IP address changes, thereby resolving the contradiction between security association stability and mobility support
Solution Approach 2:
The patent introduces role-based authentication tags as an intermediary mechanism between network devices and access control policies. This intermediary layer abstracts the mobility issue by providing a stable role identifier that persists across IP address changes, enabling continuous security associations for mobile devices without requiring IP-based policy reconfiguration
2Area of stationary object
If distributed access control lists are used across multiple access points, then network coverage is expanded, but asynchronous updates cause security breaches
Solution Approach 1:
The patent implements feedback mechanisms where access control decisions are propagated back through the network to synchronize updates across distributed access points. When a role-based access control policy is updated, the system ensures consistent propagation of this update throughout the network, preventing asynchronous behavior and potential security breaches while maintaining expanded network coverage
Solution Approach 2:
The patent employs preliminary actions by pre-configuring role-based access control policies at central controllers before devices join the network. Role information is extracted and processed in advance, allowing distributed access points to have consistent access control lists synchronized from the beginning, thereby preventing security issues before they occur while maintaining wide network coverage
3Reliability
If role-based authentication tags are propagated through VLAN headers, then access control is synchronized, but data packet processing complexity increases
Solution Approach 1:
The patent applies universality by making VLAN tags serve multiple functions: traditional VLAN identification and role-based access control carrier. The same VLAN header structure is used to convey both switching information and security role information, eliminating the need for separate processing mechanisms and reducing overall packet processing complexity while achieving synchronized access control
Solution Approach 2:
The patent merges the access control functionality into the existing VLAN tag structure. By combining role-based authentication information with VLAN identification in a single tag mechanism, the system avoids adding separate processing complexity layers. The network device processes both VLAN switching and access control decisions through a unified mechanism, maintaining synchronization while minimizing processing overhead
Data Source
AI summary
According to one general aspect, a method of using a network device may include receiving, via an ingress port, a data packet that includes a payload portion, a source network address and a destination network address. In various embodiments, the method may also include determining if the data packet includes a security tag that includes a role based authentication tag. In some embodiments, the method may include, if the data packet includes a security tag that includes a role based authentication tag, transmitting, via an egress port, at least the payload portion and the role based authentication tag towards, in a topological sense, the destination network address.


