Secure Power over Ethernet Communication via Encrypted Layer 2 Messaging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing Power over Ethernet (PoE) systems face challenges in securely managing power communication between computing devices and switches, particularly due to the exposure of confidential information and the risk of denial of service attacks through unencrypted power management information transmission over the network.

Innovation Solution

The implementation of an encrypted communication mechanism for Power over Ethernet (PoE) messages, where power management information is collected, formatted into Layer 2 or higher packets, encrypted, and transmitted securely to the Power Sourcing Equipment (PSE) to determine power requests and priorities, ensuring confidentiality and preventing malicious interference.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If power management information is transmitted unencrypted over the network, then communication simplicity is maintained, but confidentiality is compromised and denial of service attacks become possible

Engineering Contradiction:
Improvecommunication simplicityVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an encryption mechanism as an intermediary layer between the PoE communication entities. The encryption/decryption process acts as a mediator that protects power management information while maintaining the underlying communication protocol's simplicity. This allows the system to achieve both security reliability and communication simplicity by adding a transparent security layer without fundamentally changing the communication architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption is implemented for PoE messages, then confidentiality and security are improved, but device complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidcommunication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the encryption functionality into a separate, dedicated component rather than embedding it throughout the entire PoE communication system. By isolating the encryption/decryption operations to specific modules or layers, the system achieves security reliability while minimizing the complexity impact on the overall PoE communication architecture. This allows the core PoE functionality to remain simple while adding security where needed.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If power management information is transmitted without encryption, then processing overhead is minimized, but the system becomes vulnerable to malicious interference

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidvulnerability to attacks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies encryption to power management information before transmission occurs. This preliminary action of encrypting the data preemptively ensures that even if the transmission is intercepted or manipulated, the information remains protected. The encryption is performed in advance as part of the message preparation process, allowing the system to maintain processing efficiency while eliminating vulnerability to attacks during transmission.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8001399B2System and method for secure communication for power over ethernet between a computing device and a switch
Publication Date: 2011.08.16 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
  • US8001399B2 patent drawing
  • US8001399B2 patent drawing
  • US8001399B2 patent drawing

AI summary

A system and method for secure communication for power over Ethernet (PoE) between a computing device and a switch. Various power management information can be used as inputs in a process for determining a power request/priority. This power management information can be communicated in Layer 2, Layer 3, or higher messaging during initial power allocation and ongoing power reallocation. Encryption of such messaging enables confidentiality, secure allocation processes, and prevention of denial of service attacks.