Key distribution over IP/UDP
Technique for distributing encryption keys for Layer 2.5/3 transport using MKA (MACsec (Media Access Control Security) Key Agreement). A transmitting (TX) node generates an MKA packet having a Layer 2 header, an IP header, a UDP header, an IEEE 802.1x header, and an MKA payload containing the encryption key for encrypting a packet flow transmitted from the TX node to a receiving (RX) node. The IEEE 802.1x header includes a Security Channel Identification (SCI) that uniquely identifies the packet flow and the encrypting TX node. The TX node transmits the MKA packet to the RX node via a Layer 3 transport. The RX node receives the MKA packet and obtains the encryption key from the MKA packet. The TX node uses the encryption key to encrypt Layer 2.5/3 transport to the RX node, which uses the encryption key to decrypt the encrypted Layer 2.5/3 transport received from the TX node.
1 . A transmitting (TX) node, comprising:
at least one processor; and
at least one memory including computer program code;
wherein the at least one memory and the computer program code are configured to, with the at least one processor, cause the TX node to at least:
generate an MKA (MACsec (Media Access Control Security) Key Agreement) packet comprising a Layer 2 header, an Internet Protocol (IP) header, a User Datagram Protocol (UDP) header, an IEEE 802.1x header, and an MKA payload containing an encryption key for encrypting a packet flow transmitted from the TX node to a receiving (RX) node; and
transmit the MKA packet to the RX node via a Layer 3 transport, wherein:
the IEEE 802.1x header comprises a Security Channel Identification (SCI) that uniquely identifies the packet flow and the encrypting TX node; and
the SCI comprises an encryption segment identifier (SID) to identify the encrypting TX node and a unique identifier of a tunnel on the encrypting TX node.
2 . The TX node of claim 1 , wherein the encryption key is a Secure Association Key (SAK).
3 . The TX node of claim 1 , wherein the TX node is configured to receive the SAK from a key server using Advanced Encryption Standard (AES) Key Wrap.
4 . The TX node of claim 1 , wherein the TX node is configured to encrypt the encryption key in the MKA packet using AES Key Wrap.
5 . The TX node of claim 1 , wherein the TX node is configured to:
generate the unique identifier locally; and
transmit the SCI to the RX node using MKA over IP/UDP header.
6 . The TX node of claim 1 , wherein the TX node is configured to:
use the encryption key to encrypt packets of the packet flow; and
transmit the encrypted packets to the RX node via Layer 2.5/3 transport.
7 . The TX node of claim 6 , wherein the Layer 2.5/3 transport is a Layer 2.5 Multiprotocol Label Switching (MPLS) transport.
8 . The TX node of claim 6 , wherein the Layer 2.5/3 transport is a Layer 3 Internet Protocol (IP) transport.
9 . The TX node of claim 1 , wherein the Layer 3 transport is IP transport.
10 . A receiving (RX) node, comprising:
at least one processor; and
at least one memory including computer program code;
wherein the at least one memory and the computer program code are configured to, with the at least one processor, cause the RX node to at least:
receive, from a transmitting (TX) node via a Layer 3 transport, an MKA packet comprising a Layer 2 header, an IP header, a UDP header, an IEEE 802.1x header, and an MKA payload containing an encryption key for decrypting a packet flow transmitted from the TX node to the RX node; and
process the MKA packet to obtain the encryption key, wherein:
the IEEE 802.1x header comprises an SCI that uniquely identifies the packet flow and the encrypting TX node; and
the SCI comprises an encryption SID to identify the encrypting TX node and a unique identifier of a tunnel on the encrypting TX node.
11 . The RX node of claim 10 , wherein the encryption key is a SAK.
12 . The RX node of claim 10 , wherein the encryption key is encrypted in the MKA packet using AES Key wrap.
13 . The RX node of claim 10 , wherein the RX node is configured to receive the SCI from the TX node using MKA over IP/UDP header.
14 . The RX node of claim 10 , wherein the RX node is configured to:
receive encrypted packets of the packet flow from the TX node via the Layer 2.5/3 transport; and
use the encryption key to decrypt the encrypted packets.
15 . The RX node of claim 14 , wherein the Layer 2.5/3 transport is a Layer 2.5 MPLS transport.
16 . The RX node of claim 14 , wherein the Layer 2.5/3 transport is a Layer 3 IP transport.
17 . The RX node of claim 10 , wherein the Layer 3 transport is IP transport.
18 . A method comprising:
a TX node generating an MKA packet comprising a Layer 2 header, an IP header, a UDP header, an IEEE 802.1x header, and an MKA payload containing an encryption key for encrypting a packet flow transmitted from the TX node to an RX node; and
the TX node transmitting the MKA packet to the RX node via a Layer 3 transport, wherein:
the IEEE 802.1x header comprises an SCI that uniquely identifies the packet flow and the encrypting TX node; and
the SCI comprises an encryption SID to identify the encrypting TX node and a unique identifier of a tunnel on the encrypting TX node.
19 . A method comprising:
an RX node receiving, from a TX node via a Layer 3 transport, an MKA packet comprising a Layer 2 header, an IP header, a UDP header, an IEEE 802.1x header, and an MKA payload containing an encryption key for decrypting a packet flow transmitted from the TX node to the RX node; and
the RX node processing the MKA packet to obtain the encryption key, wherein:
the IEEE 802.1x header comprises an SCI that uniquely identifies the packet flow and the encrypting TX node; and
the SCI comprises an encryption SID to identify the encrypting TX node and a unique identifier of a tunnel on the encrypting TX node.