US2021105348A1PendingUtilityA1

System, Method and Devices for MKA Negotiation Between the Devices

Assignee: HUAWEI TECH CO LTDPriority: Nov 26, 2016Filed: Dec 16, 2020Published: Apr 8, 2021
Est. expiryNov 26, 2036(~10.3 yrs left)· nominal 20-yr term from priority
H04L 9/0838H04L 63/20H04W 84/12H04L 69/324H04W 12/0431H04L 63/061H04L 63/08H04L 63/10H04L 9/0844H04L 63/00H04L 63/162H04W 12/04031
47
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Disclosed are a system, method and devices for simultaneous MACsec key agreement (MKA) negotiation between the devices. The present application controls a basic TLV message exchange between supplicant and authenticator in case of race condition to establish the secure association key (SAK) channel. The present application by controlling a basic TLV message exchange enables to establish a secure channel in race condition and achieves a high reliability of the product as this makes product launch MACsec services quickly and available for the service. Accordingly, when both sides (two supplicants) exchange hello with basic TLV at the same time, triggering the race condition, drops first message from the authenticator at supplicant and update the peer MN and the supplicant will not send reply. The authenticator when send next message (basic+potential peer TLV) with peer MN incremented by 1 , the supplicant will respond with incremental message with live peer TLV.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A key agreement system comprising:
 a first port access entity (PAE) and a second PAE, configured to:
 exchange, by the first PAE and the second PAE, a first message and a second message with each other to initiate a key agreement process, wherein the first message comprises a first message number (MN) associated with the first message, and wherein the second message comprises a second MN associated with the second message and does not comprise the first MN; 
 after receiving the second message, not respond, by the first PAE, to the second PAE until a third message with the first MN is received from the second PAE, wherein the third message comprises a third MN associated with the third message; and 
 in response to the first MN being received in the third message, send, by the first PAE, a fourth message with the third MN to the second PAE. 
   
     
     
         2 . The system of  claim 1 , wherein a race condition is identified in response to the second message from the second PAE not comprising the first MN associated with the first message after the first message has been sent to the second PAE. 
     
     
         3 . The system of  claim 1 , wherein the key agreement process is a media access control (MAC) security (MACsec) Key Agreement (MKA) process. 
     
     
         4 . The system of  claim 1 , wherein the first message comprises a media access control (MAC) security (MACsec) key agreement protocol data unit (MKPDU). 
     
     
         5 . The system of  claim 1 , wherein the third message comprises a potential peer type-length-value (TLV) field, and the potential peer TLV field comprises the first MN associated with the first message. 
     
     
         6 . A key agreement method, implemented by a first port access entity (PAE), the method comprising:
 initiating a key agreement process by sending a first message to a second PAE, wherein the first message comprises a first message number (MN) associated with the first message;   receiving, from the second PAE, a second message comprising a second MN associated with the second message and not comprising the first MN;   after receiving the second message, not responding to the second PAE until a third message with the first MN is received from the second PAE, the third message comprising a third MN associated with the third message;   receiving the third message; and   in response to the first MN being received in the third message, sending a fourth message with the third MN to the second PAE.   
     
     
         7 . The method of  claim 6 , wherein the first PAE initiates the key agreement process simultaneously with the second PAE. 
     
     
         8 . The method of  claim 6 , wherein a race condition is identified in response to the second message from the second PAE not comprising the first MN associated with the first message after the first message has been sent to the second PAE. 
     
     
         9 . The method of  claim 6 , wherein the key agreement process is a media access control (MAC) security (MACsec) Key Agreement (MKA) process. 
     
     
         10 . The method of  claim 6 , wherein the first message comprises MAC security (MACsec) key agreement protocol data unit (MKPDU). 
     
     
         11 . The method of  claim 6 , wherein the third message comprises a potential peer type-length-value (TLV) field, and the potential peer TLV field comprises the first MN associated with the first message. 
     
     
         12 . A key agreement device, comprising:
 a non-transitory memory storing instructions; and   a processor coupled to the non-transitory memory, the instructions executed by the processor, cause the device to:
 initiate a key agreement process by sending a first message to a second PAE, wherein the first message comprises a first message number (MN) associated with the first message; 
 receive, from the second PAE, a second message comprising a second MN associated with the second message and not comprising the first MN; 
 after receiving the second message, not respond the second PAE until a third message with the first MN is received from the second PAE, wherein the third message comprises a third MN associated with the third message; 
 receive the third message; and 
 in response to the first MN being received in the third message, send a fourth message with the third MN to the second PAE. 
   
     
     
         13 . The device of  claim 12 , wherein the key agreement device initiates the key agreement process simultaneously with the second PAE. 
     
     
         14 . The device of  claim 12 , wherein a race condition is identified in response to the second message from the second PAE not comprising the first MN associated with the first message after the first message has been sent to the second PAE. 
     
     
         15 . The device of  claim 14 , wherein the race condition is avoided when the key agreement device is reflected in the third message in a potential peer type-length-value (TLV) field or live peer TLV field. 
     
     
         16 . The device of  claim 12 , wherein the key agreement process is a Mac security (MACsec) Key Agreement (MKA) process. 
     
     
         17 . The device of  claim 12 , wherein the first message comprises MAC security (MACsec) key agreement protocol data unit (MKPDU). 
     
     
         18 . The device of  claim 12 , wherein the third message comprises a potential peer type-length-value (TLV) field, and the potential peer TLV field comprises the first MN associated with the first message. 
     
     
         19 . The device of  claim 12 , wherein the key agreement device is a supplicant, and the second PAE is an authenticator. 
     
     
         20 . The device of  claim 12 , wherein the first message comprises a basic parameter type-length-value (TLV) filed, and the basic parameter TLV field comprises the first MN.

Join the waitlist — get patent alerts

Track US2021105348A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.