Terminal Device Link Layer Encryption Switch Burden

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wired local area networks lack data security, as existing standards do not support link layer encryption and decryption, making them vulnerable to data interception, and existing solutions like IEEE 802.1AE impose a heavy computing burden on switch devices and are not compatible with hybrid network deployments.

Innovation Solution

A terminal device with a link layer processing module that includes a control module, data frame encryption and decryption modules, a key management module, and an algorithm module, capable of managing shared keys between devices and switch devices for secure data transmission, supporting various link layer encryption protocols and reducing the burden on access switch devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IEEE 802.1AE link layer encryption is implemented, then data security is improved, but computing burden on access switch devices increases and data transmission delay increases

Engineering Contradiction:
Improvedata securityVSAvoidcomputing burden on access switch
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the encryption and decryption functions from the access switch devices and relocates them to the terminal devices. Each terminal device independently performs encryption before transmission and decryption after reception, eliminating the need for switch devices to process cryptographic operations. This extraction resolves the contradiction by maintaining data security while significantly reducing the computing burden on access switches.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements self-service by enabling terminal devices to autonomously perform encryption and decryption operations using their own cryptographic keys. Each terminal device manages its own security operations independently without requiring assistance from or imposing processing requirements on switch devices. This self-service approach maintains security while avoiding the computing burden and transmission delay problems of centralized switch-based encryption.

Inventive Principle:
Principle #25Self-service

2Reliability

If IEEE 802.1AE link layer encryption is implemented, then data security is improved, but data transmission delay increases

Engineering Contradiction:
Improvedata securityVSAvoiddata transmission delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts encryption and decryption operations from the data transmission path in switch devices and relocates them to terminal devices. Encryption occurs at the source terminal before transmission, and decryption occurs at the destination terminal after reception, eliminating the need for intermediate decryption-encryption cycles at each switch. This extraction significantly reduces transmission delay while maintaining data security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements a skipping approach by allowing encrypted data frames to pass through intermediate switch devices without requiring decryption or re-encryption operations. The data frame is encrypted at the source terminal and decrypted only at the destination terminal, skipping the unnecessary processing steps at intermediate devices. This rushing through mechanism maintains security while minimizing transmission delay.

Inventive Principle:
Principle #21Skipping (Rushing through)

3Reliability

If IEEE 802.1AE link layer encryption is implemented, then data security is improved, but compatibility with hybrid network deployment is reduced

Engineering Contradiction:
Improvedata securityVSAvoidhybrid network deployment compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements universality by designing a system where terminal devices can perform encryption and decryption using multiple cryptographic algorithms and key management mechanisms. The terminal device can adapt to different network configurations and work with both IEEE 802.1AE compliant devices and standard devices, providing multi-functionality that ensures compatibility across hybrid network deployments while maintaining data security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9009466B2Terminal device capable of link layer encryption and decryption and data processing method thereof
Publication Date: 2015.04.14 CHINA IWNCOMM
  • US9009466B2 patent drawing
  • US9009466B2 patent drawing

AI summary

There are a terminal device capable of link layer encryption and decryption and a data process method thereof, and the terminal device includes a link layer processing module including a control module, a data frame encryption module, a data frame decryption module, a key management module, an algorithm module, a transmission port and a reception port; and the control module is connected with the transmission port through the data frame encryption module, the reception port is connected with the control module through the data frame decryption module, the control module is connected with the key management module, the data frame encryption module is connected with the data frame decryption module through the key management module, and the data frame encryption module is connected with the data frame decryption module through the algorithm module.