WAN Frame Security with Selective VLAN Tag Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security measures for frames with tags or headers in wide area networks, such as Media Access Control (MAC) Security, interfere with network operations by making encrypted or secured tags inaccessible or unmodifiable, which can lead to frame rejection due to invalidation of check values.

Innovation Solution

A transmission and receive device with circuitry that determines the class of security processing for frames, excluding virtual local area network (VLAN) tags from security processing, allowing tags to be accessible and modifiable within the wide area network while maintaining frame integrity through selective security processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security processing is applied to frames with VLAN tags in wide area networks, then frame security and integrity are improved, but tags become inaccessible or unmodifiable by network devices

Engineering Contradiction:
Improveframe securityVSAvoidtag accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the frame into protected and unprotected portions. Security processing (encryption and integrity checking) is applied only to specific fields of the frame, while VLAN tags are excluded from security processing. This allows network devices to access and modify tags without affecting the security-protected portions of the frame.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different parts of the frame receive different treatments. The patent applies security processing selectively to certain frame fields while leaving VLAN tags and other routing information unencrypted and unprotected. This local differentiation enables both security for sensitive data and accessibility for network operations.

Inventive Principle:
Principle #3Local quality

2Reliability

If security processing is applied to frames with check values, then frame integrity is improved, but tags cannot be modified without invalidating check values

Engineering Contradiction:
Improveframe integrityVSAvoidtag modifiability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent divides the frame into segments with different security treatments. Check values are calculated and applied only to specific fields, while VLAN tags are excluded. This allows network devices to modify tags without invalidating the check values, maintaining both integrity protection and routing flexibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies integrity checking locally to specific frame fields rather than the entire frame. By excluding VLAN tags from the integrity check scope, the patent enables tag modification while maintaining integrity verification for the protected portions.

Inventive Principle:
Principle #3Local quality

3Reliability

If encrypted tags are used in wide area networks, then security is improved, but network devices cannot read or process tag information

Engineering Contradiction:
ImprovesecurityVSAvoidtag information accessibility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies encryption selectively to specific frame fields while leaving VLAN tags in plaintext. This local differentiation ensures that sensitive information is protected while routing and control information remains accessible to network devices for proper packet handling.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments the frame content into encrypted and unencrypted portions. VLAN tags are placed in the unencrypted segment, allowing network devices to read and process them, while other sensitive fields are encrypted to maintain security.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9094375B2WAN transport of frames with MAC security
Publication Date: 2015.07.28 MICROSEMI STORAGE SOLUTIONS INC
  • US9094375B2 patent drawing
  • US9094375B2 patent drawing
  • US9094375B2 patent drawing

AI summary

A physical layer device provides security processing on communication frames that may include tags or headers that are for use in a wide area network. As frames pass through the physical layer device, the frames are classified for a type of security processing. Depending on the classification a cipher is applied to the frames for integrity checking of data in the frames. Some frames are also encrypted. The security processing may exclude some of the tags or headers. The frames may also be filtered and buffered.