Terminal Device Link Layer Encryption Switch Burden
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wired local area networks lack data security, as existing standards do not support link layer encryption and decryption, making them vulnerable to data interception, and existing solutions like IEEE 802.1AE impose a heavy computing burden on switch devices and are not compatible with hybrid network deployments.
Innovation Solution
A terminal device with a link layer processing module that includes a control module, data frame encryption and decryption modules, a key management module, and an algorithm module, capable of managing shared keys between devices and switch devices for secure data transmission, supporting various link layer encryption protocols and reducing the burden on access switch devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IEEE 802.1AE link layer encryption is implemented, then data security is improved, but computing burden on access switch devices increases and data transmission delay increases
Solution Approach 1:
The patent extracts the encryption and decryption functions from the access switch devices and relocates them to the terminal devices. Each terminal device independently performs encryption before transmission and decryption after reception, eliminating the need for switch devices to process cryptographic operations. This extraction resolves the contradiction by maintaining data security while significantly reducing the computing burden on access switches.
Solution Approach 2:
The patent implements self-service by enabling terminal devices to autonomously perform encryption and decryption operations using their own cryptographic keys. Each terminal device manages its own security operations independently without requiring assistance from or imposing processing requirements on switch devices. This self-service approach maintains security while avoiding the computing burden and transmission delay problems of centralized switch-based encryption.
2Reliability
If IEEE 802.1AE link layer encryption is implemented, then data security is improved, but data transmission delay increases
Solution Approach 1:
The patent extracts encryption and decryption operations from the data transmission path in switch devices and relocates them to terminal devices. Encryption occurs at the source terminal before transmission, and decryption occurs at the destination terminal after reception, eliminating the need for intermediate decryption-encryption cycles at each switch. This extraction significantly reduces transmission delay while maintaining data security.
Solution Approach 2:
The patent implements a skipping approach by allowing encrypted data frames to pass through intermediate switch devices without requiring decryption or re-encryption operations. The data frame is encrypted at the source terminal and decrypted only at the destination terminal, skipping the unnecessary processing steps at intermediate devices. This rushing through mechanism maintains security while minimizing transmission delay.
3Reliability
If IEEE 802.1AE link layer encryption is implemented, then data security is improved, but compatibility with hybrid network deployment is reduced
Solution Approach 1:
The patent implements universality by designing a system where terminal devices can perform encryption and decryption using multiple cryptographic algorithms and key management mechanisms. The terminal device can adapt to different network configurations and work with both IEEE 802.1AE compliant devices and standard devices, providing multi-functionality that ensures compatibility across hybrid network deployments while maintaining data security.
Data Source
AI summary
There are a terminal device capable of link layer encryption and decryption and a data process method thereof, and the terminal device includes a link layer processing module including a control module, a data frame encryption module, a data frame decryption module, a key management module, an algorithm module, a transmission port and a reception port; and the control module is connected with the transmission port through the data frame encryption module, the reception port is connected with the control module through the data frame decryption module, the control module is connected with the key management module, the data frame encryption module is connected with the data frame decryption module through the key management module, and the data frame encryption module is connected with the data frame decryption module through the algorithm module.

