Pluggable Security Device Offloading MACsec Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The integration of MACsec security standards into network switches or NICs is costly and limits functionality, as it requires hardware and software modifications, making it difficult to implement secure point-to-point communication efficiently.

Innovation Solution

A pluggable security device with processing circuitry and memory that can be inserted into network devices, offloading MACsec encryption/decryption operations and enabling a lookaside feature, allowing the network switch to perform additional operations like tunneling encapsulation, thereby transforming non-MACsec devices into MACsec-capable devices without the need for costly hardware modifications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If MACsec security standards are integrated into network switches or NICs, then security functionality is provided, but cost increases and functionality is limited

Engineering Contradiction:
Improvesecurity functionalityVSAvoidhardware and software integration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security functionality from the network switch by using a separate security device that can be independently configured and managed. This allows the switch to remain simple while security functions are provided by a dedicated component that can be plugged in or out as needed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary security device that sits between the network switch and the network, providing MACsec encryption/decryption without requiring modifications to the switch itself. This mediator approach allows security functionality to be added without increasing the complexity of the core switching hardware or software.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hardware modifications are made to implement MACsec, then security is achieved, but cost increases

Engineering Contradiction:
ImprovesecurityVSAvoidcost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent extracts the MACsec security functionality from the network switch hardware and places it in a separate, standalone security device. This extraction eliminates the need for costly hardware modifications to the switch while still providing the required security functions through the external device.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent employs a disposable or replaceable security device that can be easily upgraded or replaced without modifying the core network switch infrastructure. This approach reduces manufacturing costs by allowing security functions to be provided through cheaper, dedicated components rather than expensive integrated hardware modifications.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If security functions are integrated into the switch, then security is provided, but additional operations like tunneling encapsulation cannot be performed

Engineering Contradiction:
ImprovesecurityVSAvoidadditional operations capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent adds another dimension to the network architecture by introducing a separate security device layer that operates independently from the switch. This dimensional separation allows the switch to focus on switching operations while the security device handles encryption, decryption, and other security-related operations including tunneling encapsulation.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent creates a universal security device that can perform multiple functions including MACsec encryption/decryption, tunneling encapsulation, and other security operations. This multi-functional device replaces the need for integrated switch modifications and enables versatile operations without limiting the switch's capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11729181B2Pluggable security devices and systems including the same
Publication Date: 2023.08.15 MELLANOX TECHNOLOGIES LTD(IL)
  • US11729181B2 patent drawing
  • US11729181B2 patent drawing
  • US11729181B2 patent drawing

AI summary

A networking system includes a pluggable security device comprising at least one port interface that is insertable into at least one physical port, memory that stores a security key used to provide security over a network link, and processing circuitry coupled with the at least one port interface and with the memory. The processing circuitry utilizes the security key to verify security of a point-to-point connection established over the network link and after verifying the security of the point-to-point connection, provides a data integrity check function for data packets received at the at least one port interface.