Switch Port Module Link Layer Security Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current switch devices for local area networks lack link layer secured transmission capabilities, making them insecure against data interception, and existing solutions like IEEE 802.1 AE impose a heavy computational burden and delay due to the need to decrypt and re-encrypt all data packets.
Innovation Solution
A switch device with port modules that support link layer key management, enabling the creation of shared keys for encrypting and decrypting data frames, and a data processing method that processes frames based on header information to determine encryption and decryption needs, reducing the computational load and supporting various link layer encryption protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a switch device supports IEEE 802.1 AE encryption per hop, then data transmission security is improved, but the computing burden on the switch device increases significantly and transmission delay increases
Solution Approach 1:
The patent segments the encryption/decryption processing by introducing a security gateway that handles the cryptographic operations separately from the core switch device. The switch device only performs simple routing based on MAC addresses, while the security gateway performs the computationally intensive encryption and decryption operations. This segmentation reduces the computing burden on the switch device while maintaining security.
Solution Approach 2:
The security gateway acts as an intermediary between the switch device and the network nodes. It mediates the encryption and decryption processes, allowing the switch device to forward encrypted frames without needing to decrypt them. This intermediary approach enables the switch to operate with minimal computational burden while still providing end-to-end security.
2Reliability
If a switch device supports IEEE 802.1 AE encryption per hop, then data transmission security is improved, but transmission delay increases
Solution Approach 1:
By segmenting the processing functions, the patent allows the switch device to perform only simple MAC address-based routing without the time-consuming decryption and re-encryption operations. The security gateway handles encryption/decryption in parallel or at endpoints, reducing the time the data frame spends in the switching path and thus reducing overall transmission delay.
Solution Approach 2:
The security gateway performs encryption and decryption operations in advance or in parallel with the switching operation, rather than sequentially. This allows the switch device to forward frames based on MAC addresses without waiting for cryptographic operations to complete, significantly reducing transmission delay while maintaining security.
3Speed
If a switch device forwards all data packets directly without link layer security capability, then transmission speed is maintained, but data security deteriorates
Solution Approach 1:
The security gateway serves as an intermediary that adds security functionality without interfering with the high-speed forwarding capability of the switch device. The switch continues to forward frames at line rate based on MAC addresses, while the security gateway handles security operations separately, thus maintaining transmission speed while improving data security.
Solution Approach 2:
The patent segments security processing from data forwarding processing. The switch device handles only the high-speed forwarding function, while the security gateway handles the security function. This segmentation allows the switch to maintain its transmission speed while the security gateway provides the necessary security protections.
Data Source
AI summary
A switch equipment and data processing method for supporting link layer security transmission are provided. The switch equipment for supporting link layer security transmission comprises a switch module and multiple port modules, each port module is electrically connected with the switch module respectively; the port module supports a link layer key management capability, and is used for establishing a share key for encrypting and decrypting data frames between the switch equipment and other network nodes.

