Monitoring a media access control security session

US11876800B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11876800-B2
Application numberUS-202217660471-A
CountryUS
Kind codeB2
Filing dateApr 25, 2022
Priority dateJul 9, 2019
Publication dateJan 16, 2024
Grant dateJan 16, 2024

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A device may determine that a first link of the device is active. The device may determine whether a Media Access Control Security (MACsec) session is established on the first link. The device may selectively enable or disable a second link of the device based on determining whether the MACsec session is established on the first link.

First claim

Opening claim text (preview).

What is claimed is: 1. A non-transitory computer-readable medium storing instructions, the instructions comprising: one or more instructions that, when executed by one or more processors of a device, cause the one or more processors to: disable a first link between a server device and the device based on determining that a Media Access Control Security (MACsec) session is not established on a second link between the device and a different device; determine, after disabling the first link, that the MACsec session is established on the second link; enable the first link based on determining that the MACsec session is established on the second link; and send, after enabling the second link, data to the different device via the second link. 2. The non-transitory computer-readable medium of claim 1 , wherein the one or more instructions further cause the one or more processors to: determine that a physical layer of the first link is active. 3. The non-transitory computer-readable medium of claim 1 , wherein the one or more instructions further cause the one or more processors to: determine that a datalink layer of the first link is active. 4. The non-transitory computer-readable medium of claim 1 , wherein the one or more instructions further cause the one or more processors to: receive the data from the server device via the first link; process the data; and wherein the one or more instructions that cause the one or more processors to send the data to the different device via the second link, cause the one or more processors to: send the data to the different device after the data is processed. 5. The non-transitory computer-readable medium of claim 1 , wherein the one or more instructions further cause the one or more processors to: receive the data from the server device via the first link; cause the data to be encrypted using an encryption algorithm associated with the MACsec session; and wherein the one or more instructions that cause the one or more processors to send the data to the different device via the second link, cause the one or more processors to: send the data to the different device after the data is encrypted. 6. The non-transitory computer-readable medium of claim 1 , wherein the second link is an Ethernet link that connects a physical port of the device to a physical port of the different device. 7. The non-transitory computer-readable medium of claim 1 , wherein the MACsec session is not established on the second link between the device and the different device because an authentication process associated with the second link was not successful. 8. A device, comprising: one or more memories; and one or more processors to: disable a first link between the device and another device based on determining that a Media Access Control Security (MACsec) session is not established on a second link between the device and a different device; determine, after disabling the first link, that the MACsec session is established on the second link; enable the first link based on determining that the MACsec session is established on the second link; and send, after enabling the second link, data to the different device via the second link. 9. The device of claim 8 , wherein the one or more processors are further to: determine that a physical layer of the first link is active. 10. The device of claim 8 , wherein the one or more processors are further to: determine that a datalink layer of the first link is active. 11. The device of claim 8 , wherein the one or more processors, to determine that the MACsec session is established on the second link, are to: determine that the device and the different device successfully exchanged and verified security keys. 12. The device of claim 8 , wherein the one or more processors, to disable the first link, are to: de-active the first link by changing a status of either a physical layer or a datalink layer of the first link to inactive. 13. The device of claim 8 , wherein the one or more processors are further to: cause power to cease to be provided to the first link. 14. The device of claim 8 , wherein the one or more processors, to determine that the MACsec session is established on the second link, are to: determine that the MACsec session is established on the second link based on determining that an authentication process associated with the MACsec session was successful. 15. A method comprising: disabling, by a device, a first link based on determining that a Media Access Control Security (MACsec) session is not established on a second link between the device and a different device; determining, by the device and after disabling the first link, that the MACsec session is established on the second link; enabling, by the device, the first link based on determining that the MACsec session is established on the second link; and sending, by the device, after enabling the second link, data to the different device via the second link. 16. The method of claim 15 , wherein disabling the first link comprises: de-activating the first link by changing a status of either a physical layer or a datalink layer of the first link to inactive. 17. The method of claim 15 , wherein the first link is between the device and a server device. 18. The method of claim 15 , further comprising: determining that a physical layer of the first link is active. 19. The method of claim 15 , further comprising: determining that a datalink layer of the first link is active. 20. The method of claim 15 , further comprising: receiving the data from a server device via the first link; causing the data to be encrypted using an encryption algorithm associated with the MACsec session; and wherein sending the data to the different device via the second link comprises: sending the data to the different device after the data is encrypted.

Assignees

Inventors

Classifications

  • based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint · CPC title

  • Providing cryptographic facilities or services · CPC title

  • for key exchange, e.g. in peer-to-peer networks (cryptographic mechanisms or cryptographic arrangements for key agreement H04L9/0838) · CPC title

  • Setup of application sessions (admission control or resource allocation in data switching networks H04L47/70) · CPC title

  • G06F21/606Primary

    by securing the transmission between two devices or processes · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11876800B2 cover?
A device may determine that a first link of the device is active. The device may determine whether a Media Access Control Security (MACsec) session is established on the first link. The device may selectively enable or disable a second link of the device based on determining whether the MACsec session is established on the first link.
Who is the assignee on this patent?
Juniper Networks Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/0876. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jan 16 2024 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).