Network Interface Device Layer 2 Encryption Layer 3 Tunneling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security technologies, such as MACsec for Layer 2 networks and IPsec for Layer 3 networks, face limitations in scalability and compatibility when extending encryption and security across different network layers, particularly in multi-layer network environments, where switches may not efficiently handle encryption and decryption operations without additional cryptographic circuitry and increased costs.

Innovation Solution

Implementing circuitry in network interface devices that can perform MACsec encryption and decryption operations and tunnel packets using Layer 3 networks, allowing for secure communication across Layer 2 and Layer 3 networks by utilizing virtual private networks (VPNs) like VxLAN, which enables secure packet forwarding and tunneling without requiring separate Layer 3 cryptographic circuitry.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If MACsec encryption is applied to Layer 2 networks, then security is improved, but device complexity and cost increase due to required cryptographic circuitry

Engineering Contradiction:
Improvenetwork securityVSAvoidcryptographic circuitry
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines Layer 2 MACsec encryption with Layer 3 tunneling protocols (VXLAN, GRE, MPLS) into a unified security architecture. The network interface device applies MACsec encryption to packets and then encapsulates them in Layer 3 tunnels, merging two separate security approaches into a single integrated solution that provides both link-layer and network-layer security without requiring separate cryptographic hardware for each layer

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent makes the network interface device multi-functional by enabling it to perform both MACsec encryption/decryption operations and Layer 3 tunneling operations through a single cryptographic circuitry unit. This universal design allows the same hardware resources to serve multiple security functions across different network layers, reducing overall device complexity and cost

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If IPsec is applied to Layer 3 networks, then security is improved, but compatibility and scalability are reduced when integrating with Layer 2 MACsec environments

Engineering Contradiction:
Improvenetwork securityVSAvoidmulti-layer compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces Layer 3 tunneling protocols as an intermediary layer between MACsec-encrypted Layer 2 networks and the broader IP network infrastructure. The tunneling protocol acts as a mediator that carries MACsec-encrypted packets across Layer 3 networks without requiring IPsec, enabling seamless integration between Layer 2 and Layer 3 security domains while maintaining compatibility with existing network architectures

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the security function into distinct layers: MACsec handles Layer 2 link-layer security while Layer 3 tunneling handles network-layer transport. This segmentation allows each layer to operate independently with its own security mechanisms, improving adaptability across different network environments and enabling flexible deployment in multi-layer networks without requiring full IPsec implementation

Inventive Principle:
Principle #1Segmentation

3Reliability

If separate Layer 3 cryptographic circuitry is added for IPsec, then security is improved, but cost and device complexity increase

Engineering Contradiction:
Improvenetwork securityVSAvoidmanufacturing cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent designs the network interface device with universal cryptographic circuitry that can perform both MACsec and IPsec operations, as well as Layer 3 tunneling encapsulation/decapsulation. This multi-functional design eliminates the need for separate cryptographic hardware for different security protocols, reducing manufacturing costs and device complexity while maintaining comprehensive security capabilities across Layer 2 and Layer 3 networks

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20230155988A1Packet security over multiple networks
Publication Date: 2023.05.18 INTEL CORP
  • US20230155988A1 patent drawing
  • US20230155988A1 patent drawing
  • US20230155988A1 patent drawing

AI summary

Examples described herein relate to a network interface device that includes an interface and circuitry. In some examples, the circuitry coupled to the interface is to apply encryption for packets received from a first network interface device and tunnel the encrypted packets to a second network interface device. In some examples, forwarding operations by the first network interface device and forwarding operations in the second network interface device are based on different header fields.