System, Method and Devices for MKA Negotiation Between the Devices
Abstract
Disclosed are a system, method and devices for simultaneous MACsec key agreement (MKA) negotiation between the devices. The present application controls a basic TLV message exchange between supplicant and authenticator in case of race condition to establish the secure association key (SAK) channel. The present application by controlling a basic TLV message exchange enables to establish a secure channel in race condition and achieves a high reliability of the product as this makes product launch MACsec services quickly and available for the service. Accordingly, when both sides (two supplicants) exchange hello with basic TLV at the same time, triggering the race condition, drops first message from the authenticator at supplicant and update the peer MN and the supplicant will not send reply. The authenticator when send next message (basic+potential peer TLV) with peer MN incremented by 1 , the supplicant will respond with incremental message with live peer TLV.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A key agreement system comprising:
a first port access entity (PAE) and a second PAE, configured to:
exchange, by the first PAE and the second PAE, a first message and a second message with each other to initiate a key agreement process, wherein the first message comprises a first message number (MN) associated with the first message, and wherein the second message comprises a second MN associated with the second message and does not comprise the first MN;
after receiving the second message, not respond, by the first PAE, to the second PAE until a third message with the first MN is received from the second PAE, wherein the third message comprises a third MN associated with the third message; and
in response to the first MN being received in the third message, send, by the first PAE, a fourth message with the third MN to the second PAE.
2 . The system of claim 1 , wherein a race condition is identified in response to the second message from the second PAE not comprising the first MN associated with the first message after the first message has been sent to the second PAE.
3 . The system of claim 1 , wherein the key agreement process is a media access control (MAC) security (MACsec) Key Agreement (MKA) process.
4 . The system of claim 1 , wherein the first message comprises a media access control (MAC) security (MACsec) key agreement protocol data unit (MKPDU).
5 . The system of claim 1 , wherein the third message comprises a potential peer type-length-value (TLV) field, and the potential peer TLV field comprises the first MN associated with the first message.
6 . A key agreement method, implemented by a first port access entity (PAE), the method comprising:
initiating a key agreement process by sending a first message to a second PAE, wherein the first message comprises a first message number (MN) associated with the first message; receiving, from the second PAE, a second message comprising a second MN associated with the second message and not comprising the first MN; after receiving the second message, not responding to the second PAE until a third message with the first MN is received from the second PAE, the third message comprising a third MN associated with the third message; receiving the third message; and in response to the first MN being received in the third message, sending a fourth message with the third MN to the second PAE.
7 . The method of claim 6 , wherein the first PAE initiates the key agreement process simultaneously with the second PAE.
8 . The method of claim 6 , wherein a race condition is identified in response to the second message from the second PAE not comprising the first MN associated with the first message after the first message has been sent to the second PAE.
9 . The method of claim 6 , wherein the key agreement process is a media access control (MAC) security (MACsec) Key Agreement (MKA) process.
10 . The method of claim 6 , wherein the first message comprises MAC security (MACsec) key agreement protocol data unit (MKPDU).
11 . The method of claim 6 , wherein the third message comprises a potential peer type-length-value (TLV) field, and the potential peer TLV field comprises the first MN associated with the first message.
12 . A key agreement device, comprising:
a non-transitory memory storing instructions; and a processor coupled to the non-transitory memory, the instructions executed by the processor, cause the device to:
initiate a key agreement process by sending a first message to a second PAE, wherein the first message comprises a first message number (MN) associated with the first message;
receive, from the second PAE, a second message comprising a second MN associated with the second message and not comprising the first MN;
after receiving the second message, not respond the second PAE until a third message with the first MN is received from the second PAE, wherein the third message comprises a third MN associated with the third message;
receive the third message; and
in response to the first MN being received in the third message, send a fourth message with the third MN to the second PAE.
13 . The device of claim 12 , wherein the key agreement device initiates the key agreement process simultaneously with the second PAE.
14 . The device of claim 12 , wherein a race condition is identified in response to the second message from the second PAE not comprising the first MN associated with the first message after the first message has been sent to the second PAE.
15 . The device of claim 14 , wherein the race condition is avoided when the key agreement device is reflected in the third message in a potential peer type-length-value (TLV) field or live peer TLV field.
16 . The device of claim 12 , wherein the key agreement process is a Mac security (MACsec) Key Agreement (MKA) process.
17 . The device of claim 12 , wherein the first message comprises MAC security (MACsec) key agreement protocol data unit (MKPDU).
18 . The device of claim 12 , wherein the third message comprises a potential peer type-length-value (TLV) field, and the potential peer TLV field comprises the first MN associated with the first message.
19 . The device of claim 12 , wherein the key agreement device is a supplicant, and the second PAE is an authenticator.
20 . The device of claim 12 , wherein the first message comprises a basic parameter type-length-value (TLV) filed, and the basic parameter TLV field comprises the first MN.Join the waitlist — get patent alerts
Track US2021105348A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.