IP Library Granted Patent US 11,677,727
Granted Patent B2
US 11,677,727 · App. 17/193,172 · Granted Jun 13, 2023

Low-latency MACsec authentication

Inventor: Brian Branscomb (Hopkinton, MA)
Assignee: Microchip Technology Incorporated
H04L63/0435H04L45/566H04L63/0245H04L63/166H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,677,727
App. No.
17/193,172
Granted
Jun 13, 2023
Kind
B2
Abstract

An apparatus may include a pipeline circuit configured to process packets and an authentication engine configured to authenticate packets and to provide an authentication signal to the pipeline circuit based on whether packets have been authenticated. The apparatus may further include a control circuit configured to route a given incoming packet to both the authentication engine and to a bypass path. The bypass path may be configured to provide a copy of the given incoming packet to the pipeline circuit to bypass the authentication engine.

Claims (46)

1. An apparatus, comprising:

a pipeline circuit to process packets; and

an authentication engine to authenticate packets and to provide an authentication signal to the pipeline circuit based on whether packets have been authenticated; and

a control circuit to route a given incoming packet to both the authentication engine and to a bypass path, the bypass path to provide a copy of the given incoming packet to the pipeline circuit to bypass the authentication engine;

wherein the pipeline circuit is to:

receive the given incoming packet;

receive the authentication signal for the given incoming packet; and

between receipt of the given incoming packet and the authentication signal for the given incoming packet, process the given incoming packet to generate an output packet;

based upon an indication in the authentication signal that the given incoming packet failed authentication, take a corrective action; and

based upon an indication in the authentication signal that the given incoming packet has been authenticated, issue the output packet.

2. The apparatus of claim 1 , comprising an encryption and decryption engine to encrypt or decrypt packets and to provide resultant encrypted or decrypted packets to the pipeline circuit, wherein the control circuit is to route the given incoming packet selectively to either the bypass path or to the encryption and decryption engine.

3. The apparatus of claim 1 , comprising an encryption and decryption engine to encrypt or decrypt packets and to provide resultant encrypted or decrypted packets to the pipeline circuit, wherein the control circuit is to selectively route the given incoming packet to the authentication engine and to the bypass path based on a determination that the given incoming packet is to be authenticated but are not to be decrypted.

4. The apparatus of claim 1 , comprising an encryption and decryption engine to encrypt or decrypt packets and to provide resultant encrypted or decrypted packets to the pipeline circuit, wherein the control circuit is to selectively route the given incoming packet to the encryption and decryption engine based on a determination that the given incoming packet is to be encrypted or decrypted.

5. The apparatus of claim 1 , wherein the control circuit is to route, in parallel, copies of the given incoming packet to the authentication engine and to the pipeline circuit through the bypass path.

6. A method, comprising:

receiving a given incoming packet at an apparatus;

routing the given incoming packet to both a bypass path and an authentication engine of the apparatus;

at the authentication engine, authenticating the given incoming packet and providing an authentication signal to a pipeline circuit based on whether packets have been authenticated;

wherein routing the given incoming packet to the bypass path includes providing a copy of the given incoming packet to the pipeline circuit to bypass the authentication engine; and

at the pipeline circuit:

receiving the given incoming packet;

receiving an authentication signal for the given incoming packet from the authentication engine; and

between receipt of the given incoming packet and the authentication signal for the given incoming packet, processing the given incoming packet to generate an output packet;

based upon an indication in the authentication signal that the given incoming packet failed authentication, taking a corrective action; and

based upon an indication in the authentication signal that the given incoming packet has been authenticated, issuing the output packet.

7. The method of claim 6 , comprising routing the given incoming packet selectively to either the bypass path or to an encryption and decryption engine of the apparatus.

8. The method of claim 6 , comprising selectively routing the given incoming packet to the authentication engine and to the bypass path based on a determination that the given incoming packet is to be authenticated but are not to be decrypted.

9. The method of claim 6 , comprising selectively routing the given incoming packet to an encryption and decryption engine of the apparatus based on a determination that the given incoming packet is to be encrypted or decrypted.

10. The method of claim 6 , comprising routing, in parallel, copies of the given incoming packet to the authentication engine and to the pipeline circuit through the bypass path.

11. An article of manufacture comprising instructions on a non-transitory machine-readable medium, the instructions, when read and loaded by a processor, cause the processor to:

receive a given incoming packet at an apparatus;

route the given incoming packet to both a bypass path and an authentication engine of the apparatus;

at the authentication engine, authenticate the given incoming packet and providing an authentication signal to a pipeline circuit based on whether packets have been authenticated;

wherein routing the given incoming packet to the bypass path includes providing a copy of the given incoming packet to the pipeline circuit to bypass the authentication engine; and

at the pipeline circuit:

receive the given incoming packet;

receive an authentication signal for the given incoming packet from the authentication engine; and

between receipt of the given incoming packet and the authentication signal for the given incoming packet, process the given incoming packet to generate an output packet;

based upon an indication in the authentication signal that the given incoming packet failed authentication, take a corrective action; and

based upon an indication in the authentication signal that the given incoming packet has been authenticated, issue the output packet.

12. The article of claim 11 , wherein the instructions are to cause the processor to route the given incoming packet selectively to either the bypass path or to an encryption and decryption engine of the apparatus.

13. The article of claim 11 , wherein the instructions are to cause the processor to selectively route the given incoming packet to the authentication engine and to the bypass path based on a determination that the given incoming packet is to be authenticated but are not to be decrypted.

14. The article of claim 11 , wherein the instructions are to cause the processor to selectively route the given incoming packet to an encryption and decryption engine of the apparatus based on a determination that the given incoming packet is to be encrypted or decrypted.

15. The article of claim 11 , wherein the instructions are to cause the processor to route, in parallel, copies of the given incoming packet to the authentication engine and to the pipeline circuit through the bypass path.

16. The apparatus of claim 1 , wherein the output packet is processed based upon a payload of the given incoming packet.

17. The apparatus of claim 16 , wherein the output packet includes the payload of the given incoming packet.

Assignments (11)
RELEASE OF SECURITY INTEREST Recorded Mar 11, 2022
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
Reel/Frame 059363/0001 →
RELEASE OF SECURITY INTEREST Recorded Mar 9, 2022
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION
Reel/Frame 059358/0398 →
RELEASE OF SECURITY INTEREST Recorded Mar 9, 2022
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
Reel/Frame 059357/0823 →
RELEASE OF SECURITY INTEREST Recorded Mar 9, 2022
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
Reel/Frame 059358/0335 →
RELEASE OF SECURITY INTEREST Recorded Feb 28, 2022
From: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
To: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
Reel/Frame 059264/0384 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Nov 19, 2021
From: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 058213/0959 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Nov 19, 2021
From: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 058214/0625 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Nov 19, 2021
From: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 058214/0238 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Nov 19, 2021
From: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 058214/0380 →
SECURITY INTEREST Recorded Jun 4, 2021
From: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 057935/0474 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 5, 2021
From: BRANSCOMB, BRIAN
To: MICROCHIP TECHNOLOGY INCORPORATED
Reel/Frame 055505/0734 →
Continuity (2)
Provisional Application 62990003 · Mar 16, 2020
Related Publication 20210288945A1 · Sep 16, 2021