Role-Based MACsec Security Association via VLAN Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In networks protected by the MACsec standard, maintaining role-based security associations is challenging due to issues like mobile devices changing IP addresses and asynchronous updates to access control lists across distributed access points, leading to potential security breaches and access privilege mismanagement.

Innovation Solution

Incorporating a role-based authentication tag into data packets, which can be transmitted within both MACsec and VLAN headers, allowing network devices to maintain their own access control lists based on assigned roles rather than IP addresses, ensuring secure and synchronized access control across the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IP address-based access control is used in MACsec networks, then network security can be implemented, but security associations are broken when mobile devices change IP addresses

Engineering Contradiction:
Improvesecurity association stabilityVSAvoidmobility support
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent changes the parameter used for access control from IP address to role-based authentication tags. The system extracts role information from MACsec security tags or VLAN tags and uses this role-based identification to maintain consistent access control policies regardless of IP address changes, thereby resolving the contradiction between security association stability and mobility support

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces role-based authentication tags as an intermediary mechanism between network devices and access control policies. This intermediary layer abstracts the mobility issue by providing a stable role identifier that persists across IP address changes, enabling continuous security associations for mobile devices without requiring IP-based policy reconfiguration

Inventive Principle:
Principle #24Intermediary (Mediator)

2Area of stationary object

If distributed access control lists are used across multiple access points, then network coverage is expanded, but asynchronous updates cause security breaches

Engineering Contradiction:
Improvenetwork coverageVSAvoidaccess control consistency
Core Design Contradiction:
Area of stationary objectVSReliability

Solution Approach 1:

The patent implements feedback mechanisms where access control decisions are propagated back through the network to synchronize updates across distributed access points. When a role-based access control policy is updated, the system ensures consistent propagation of this update throughout the network, preventing asynchronous behavior and potential security breaches while maintaining expanded network coverage

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent employs preliminary actions by pre-configuring role-based access control policies at central controllers before devices join the network. Role information is extracted and processed in advance, allowing distributed access points to have consistent access control lists synchronized from the beginning, thereby preventing security issues before they occur while maintaining wide network coverage

Inventive Principle:
Principle #10Preliminary action

3Reliability

If role-based authentication tags are propagated through VLAN headers, then access control is synchronized, but data packet processing complexity increases

Engineering Contradiction:
Improveaccess control synchronizationVSAvoidpacket processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by making VLAN tags serve multiple functions: traditional VLAN identification and role-based access control carrier. The same VLAN header structure is used to convey both switching information and security role information, eliminating the need for separate processing mechanisms and reducing overall packet processing complexity while achieving synchronized access control

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the access control functionality into the existing VLAN tag structure. By combining role-based authentication information with VLAN identification in a single tag mechanism, the system avoids adding separate processing complexity layers. The network device processes both VLAN switching and access control decisions through a unified mechanism, maintaining synchronization while minimizing processing overhead

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8700891B2Preserving security association in MACsec protected network through VLAN mapping
Publication Date: 2014.04.15 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
  • US8700891B2 patent drawing
  • US8700891B2 patent drawing
  • US8700891B2 patent drawing

AI summary

According to one general aspect, a method of using a network device may include receiving, via an ingress port, a data packet that includes a payload portion, a source network address and a destination network address. In various embodiments, the method may also include determining if the data packet includes a security tag that includes a role based authentication tag. In some embodiments, the method may include, if the data packet includes a security tag that includes a role based authentication tag, transmitting, via an egress port, at least the payload portion and the role based authentication tag towards, in a topological sense, the destination network address.