Network Interface Device Layer 2 Encryption Layer 3 Tunneling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security technologies, such as MACsec for Layer 2 networks and IPsec for Layer 3 networks, face limitations in scalability and compatibility when extending encryption and security across different network layers, particularly in multi-layer network environments, where switches may not efficiently handle encryption and decryption operations without additional cryptographic circuitry and increased costs.
Innovation Solution
Implementing circuitry in network interface devices that can perform MACsec encryption and decryption operations and tunnel packets using Layer 3 networks, allowing for secure communication across Layer 2 and Layer 3 networks by utilizing virtual private networks (VPNs) like VxLAN, which enables secure packet forwarding and tunneling without requiring separate Layer 3 cryptographic circuitry.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MACsec encryption is applied to Layer 2 networks, then security is improved, but device complexity and cost increase due to required cryptographic circuitry
Solution Approach 1:
The patent combines Layer 2 MACsec encryption with Layer 3 tunneling protocols (VXLAN, GRE, MPLS) into a unified security architecture. The network interface device applies MACsec encryption to packets and then encapsulates them in Layer 3 tunnels, merging two separate security approaches into a single integrated solution that provides both link-layer and network-layer security without requiring separate cryptographic hardware for each layer
Solution Approach 2:
The patent makes the network interface device multi-functional by enabling it to perform both MACsec encryption/decryption operations and Layer 3 tunneling operations through a single cryptographic circuitry unit. This universal design allows the same hardware resources to serve multiple security functions across different network layers, reducing overall device complexity and cost
2Reliability
If IPsec is applied to Layer 3 networks, then security is improved, but compatibility and scalability are reduced when integrating with Layer 2 MACsec environments
Solution Approach 1:
The patent introduces Layer 3 tunneling protocols as an intermediary layer between MACsec-encrypted Layer 2 networks and the broader IP network infrastructure. The tunneling protocol acts as a mediator that carries MACsec-encrypted packets across Layer 3 networks without requiring IPsec, enabling seamless integration between Layer 2 and Layer 3 security domains while maintaining compatibility with existing network architectures
Solution Approach 2:
The patent segments the security function into distinct layers: MACsec handles Layer 2 link-layer security while Layer 3 tunneling handles network-layer transport. This segmentation allows each layer to operate independently with its own security mechanisms, improving adaptability across different network environments and enabling flexible deployment in multi-layer networks without requiring full IPsec implementation
3Reliability
If separate Layer 3 cryptographic circuitry is added for IPsec, then security is improved, but cost and device complexity increase
Solution Approach 1:
The patent designs the network interface device with universal cryptographic circuitry that can perform both MACsec and IPsec operations, as well as Layer 3 tunneling encapsulation/decapsulation. This multi-functional design eliminates the need for separate cryptographic hardware for different security protocols, reducing manufacturing costs and device complexity while maintaining comprehensive security capabilities across Layer 2 and Layer 3 networks
Data Source
AI summary
Examples described herein relate to a network interface device that includes an interface and circuitry. In some examples, the circuitry coupled to the interface is to apply encryption for packets received from a first network interface device and tunnel the encrypted packets to a second network interface device. In some examples, forwarding operations by the first network interface device and forwarding operations in the second network interface device are based on different header fields.


