SlideShare a Scribd company logo
1 of 10
Download to read offline
Protecting
Data in Motion
with MACsec
Fall 2020
Gijs Willemse
Sr. Director of Product Management
2
• Data that is transferred between two devices and/or servers
• Many different sources and application
• Consumer electronics, Mobile devices, IoT
• Automotive, Infrastructure, Edge devices
• Cloud servers, Data centers, others
• Many different transmission medium
• Wireless: Mobile (3GPP) and WiFi (or combinations)
• Wired: Copper, Optical, long distance optical (OTN)
• Why do I need Secure Communication?
• Medium is in the public domain
• Transferred data is vulnerable for many different attacks, including:
physical, man-in-the-middle, (D)DoS, Sniffing, Spoofing…
What is “Data in Motion”
3
MACsec
• Media Access Control Security
(IEEE)
• Protect Ethernet links
• Switch – Switch
• Switch – Host
• Host – Host
• Extensions to deploy over VLAN
Crypto
• Products generally require FIPS
140-2 algorithm validated before
deployment in public domain
Protecting Data in Motion: Use Secure Communication Protocols
Session
TCP / UDP
IP
Layer 2 (Link)
Layer 1 (Physical)
Application
TCP / UDP
IP
Layer 2 (Link)
Layer 1 (Physical)
IPsec
MACsec
Client Server
OSI Protocol Stack
TLS
Crypto
IPsec
• Internet Protocol Security (IETF)
• Set up a Virtual Private Network
Secure IP traffic between
• Network – Network
• Network – Host
• Host – Host
TLS (SSL)
• Transport Layer Security (IETF)
• Secure communications
between two applications
• Web Browser – Web Server
• Client App – Cloud API
• Sensor chip – App Processor
4
• Meet line rate throughput
• Speed of optical links goes up to 800Gbps and fastest switches handle >10Tbps of traffic
• Limit Latency
• Realtime application is factory, medical or even consumer space have strict latency requirements
• Response times must be minimized
• Applications require constant latency
• Support Prioritization
• TSN Ethernet layer define prioritization: pre-emption of packets is required
• Cope with network diversity and various deployments
• Networks are virtual
• Connections can be hop-by-hop, but also end-to-end
• Traffic passes different networks and infrastructures
Requirements for Secure Communication
5
• MACsec is the L2 security standard, widely deployed in PHYs, switches, firewalls, gateways, NICs
and 5G equipment
• Advantages of MACsec
• Scalable crypto
• Low latency
• Fully inline datapath
• Negligible SW overhead
• Implementation Challenges
• Line rate under all conditions
• Prioritization / Frame Preemption
• Rambus has portfolio that covers all ranges and features optimized for the modern Ethernet
requirements, including custom classification. Meets line-rate under all conditions
• The only provider of control plane software
MACsec Security
PHY
MACsec
classifier
MACsec
transformation
MAC/PCS
PTP
MAC/PCS
Line:
8x112G
SerDes
Switch
MACsec
classifier
MACsec
transformation
Bufferingand
multiplexing
MAC/
PCSMAC/
PCSMAC/
PCS
MAC/
PCSMAC/
PCSMAC/
PCS
optionalPTP
6
• Ethernet is getting adopted in aerospace, automotive, manufacturing and utility industries
• Enables new levels of connectivity and cost reduction.
• Enables new uses cases
• These applications require deterministic traffic
• TSN group of standards is defined
• Adding: priority queues, minimum jitter, preemption, shaping/scheduling, time.
• TSN features are integrated into Ethernet subsystem
• Ethernet PHYs
• Switches
• Gateways
• Automotive/industrial TSN SOCs
Time Sensitive Networking (TSN Ethernet)
7
• TSN Ethernet does requires data protection. Yes, MACsec is a logical choice.
• Addition of Security must keep deterministic behavior of the Ethernet traffic
• This raises implementation challenges that are not covered by standards and must be resolved
• It must be possible to interleave packets, allowing priority packets to interrupt regular traffic
• Crypto works on native cipher block sizes (typical 16B), interruption of a data stream requires complex
state/date storage
• Rambus MACsec IPs support TSN, targeting MACsec-capable Ethernet ports
• Lowest latency of fixed latency modes
• Side-band signaling to interact with external PTP modules and classifiers
• Preemption support by processing two interleaved streams per port
• Preemption support by processing IEEE802.3br fragments while keeping the fragment size, latency
and relation unchanged
TSN MACsec: Translating Challenges into Solutions
8
Deployment in SoC/switch and PHY
SOC
PHY
MAC merge sublayer
eMAC pMAC
System MAC
TSN MACsec
Line MAC
PCS
DMA
PHY
SOC
TSN MACsec
MAC merge sublayer
eMAC pMAC
PCS
DMA / Switch Interface
9
• Catalog solutions include:
• Single port, MACsec/VLAN-in-clear for rates of 1G / 2.5G / 10G / 25G / 50G / 100G
• [New] Next generation single-port IPs with pre-emption from 1 to 50G TSN Ethernet
• Multichannel (TDM) MACsec for 100G to 800G: EIP-163/164. Optional support for proprietary classification
and other custom extensions
• Full-featured control plane product
• MACsec Toolkit: IEEE 802.1X (EAP + MKA). Includes a SW data plane for development purpose
• Non-MACsec TDM Silicon IP products for >1Tbps AES-GCM encryption
• Scalable AES-GCM engine
• IPsec AES-GCM transform engine for NICs
• TLS/IPsec and wireless algorithm (3GPP) packet engines: EIP-196/EIP-197
• TLS/IPsec/MACsec Toolkits implementing the key exchange protocol for all three security
stacks (MatrixSSL/QuickSec)
Rambus MACsec Offering
Thank you
For more information:
gwillemse@rambus.com

More Related Content

What's hot

Wifi cracking Step by Step Using CMD and Kali Linux 2018
Wifi cracking Step by Step Using CMD and Kali Linux 2018Wifi cracking Step by Step Using CMD and Kali Linux 2018
Wifi cracking Step by Step Using CMD and Kali Linux 2018Mohammad Fareed
 
VPN - Virtual Private Network
VPN - Virtual Private NetworkVPN - Virtual Private Network
VPN - Virtual Private NetworkPeter R. Egli
 
Cisco hsrp configuration
Cisco hsrp configurationCisco hsrp configuration
Cisco hsrp configurationWahyu Nasution
 
3PAR: HOW TO CHANGE THE IP ADDRESS OF HP 3PAR SAN
3PAR: HOW TO CHANGE THE IP ADDRESS OF HP 3PAR SAN3PAR: HOW TO CHANGE THE IP ADDRESS OF HP 3PAR SAN
3PAR: HOW TO CHANGE THE IP ADDRESS OF HP 3PAR SANSaroj Sahu
 
Experiment no. 1,2 and assignment no.1 cn
Experiment no. 1,2 and assignment no.1 cnExperiment no. 1,2 and assignment no.1 cn
Experiment no. 1,2 and assignment no.1 cnHusainGadiwala1
 
LTE network: How it all comes together architecture technical poster
LTE network: How it all comes together architecture technical posterLTE network: How it all comes together architecture technical poster
LTE network: How it all comes together architecture technical posterDavid Swift
 
Self-Configuration and Self-Optimization Network
Self-Configuration and Self-Optimization NetworkSelf-Configuration and Self-Optimization Network
Self-Configuration and Self-Optimization NetworkPraveen Kumar
 
How to Troubleshooting VLAN Switch Problems-Part1
How to Troubleshooting VLAN Switch Problems-Part1How to Troubleshooting VLAN Switch Problems-Part1
How to Troubleshooting VLAN Switch Problems-Part1IT Tech
 
Cisco Live! :: Cisco ASR 9000 Architecture :: BRKARC-2003 | Las Vegas 2017
Cisco Live! :: Cisco ASR 9000 Architecture :: BRKARC-2003 | Las Vegas 2017Cisco Live! :: Cisco ASR 9000 Architecture :: BRKARC-2003 | Las Vegas 2017
Cisco Live! :: Cisco ASR 9000 Architecture :: BRKARC-2003 | Las Vegas 2017Bruno Teixeira
 
ONOS: Open Network Operating System. An Open-Source Distributed SDN Operating...
ONOS: Open Network Operating System. An Open-Source Distributed SDN Operating...ONOS: Open Network Operating System. An Open-Source Distributed SDN Operating...
ONOS: Open Network Operating System. An Open-Source Distributed SDN Operating...ON.LAB
 
VLAN, VTP, DTP, Ether channel Cheat Sheet With examples.pptx
VLAN, VTP, DTP, Ether channel  Cheat Sheet With examples.pptxVLAN, VTP, DTP, Ether channel  Cheat Sheet With examples.pptx
VLAN, VTP, DTP, Ether channel Cheat Sheet With examples.pptxINFitunes
 

What's hot (20)

Implementing Network Redundancy
Implementing Network RedundancyImplementing Network Redundancy
Implementing Network Redundancy
 
Wifi cracking Step by Step Using CMD and Kali Linux 2018
Wifi cracking Step by Step Using CMD and Kali Linux 2018Wifi cracking Step by Step Using CMD and Kali Linux 2018
Wifi cracking Step by Step Using CMD and Kali Linux 2018
 
VPN - Virtual Private Network
VPN - Virtual Private NetworkVPN - Virtual Private Network
VPN - Virtual Private Network
 
Cisco hsrp configuration
Cisco hsrp configurationCisco hsrp configuration
Cisco hsrp configuration
 
3PAR: HOW TO CHANGE THE IP ADDRESS OF HP 3PAR SAN
3PAR: HOW TO CHANGE THE IP ADDRESS OF HP 3PAR SAN3PAR: HOW TO CHANGE THE IP ADDRESS OF HP 3PAR SAN
3PAR: HOW TO CHANGE THE IP ADDRESS OF HP 3PAR SAN
 
Experiment no. 1,2 and assignment no.1 cn
Experiment no. 1,2 and assignment no.1 cnExperiment no. 1,2 and assignment no.1 cn
Experiment no. 1,2 and assignment no.1 cn
 
Vpn presentation
Vpn presentationVpn presentation
Vpn presentation
 
LTE network: How it all comes together architecture technical poster
LTE network: How it all comes together architecture technical posterLTE network: How it all comes together architecture technical poster
LTE network: How it all comes together architecture technical poster
 
Self-Configuration and Self-Optimization Network
Self-Configuration and Self-Optimization NetworkSelf-Configuration and Self-Optimization Network
Self-Configuration and Self-Optimization Network
 
SD WAN
SD WANSD WAN
SD WAN
 
How to Troubleshooting VLAN Switch Problems-Part1
How to Troubleshooting VLAN Switch Problems-Part1How to Troubleshooting VLAN Switch Problems-Part1
How to Troubleshooting VLAN Switch Problems-Part1
 
Wi-Fi Module
Wi-Fi ModuleWi-Fi Module
Wi-Fi Module
 
Acl cisco
Acl ciscoAcl cisco
Acl cisco
 
VTP
VTPVTP
VTP
 
Basic Concepts in Wireless LAN
Basic Concepts in Wireless LANBasic Concepts in Wireless LAN
Basic Concepts in Wireless LAN
 
Guest Access with ArubaOS
Guest Access with ArubaOSGuest Access with ArubaOS
Guest Access with ArubaOS
 
Cisco Live! :: Cisco ASR 9000 Architecture :: BRKARC-2003 | Las Vegas 2017
Cisco Live! :: Cisco ASR 9000 Architecture :: BRKARC-2003 | Las Vegas 2017Cisco Live! :: Cisco ASR 9000 Architecture :: BRKARC-2003 | Las Vegas 2017
Cisco Live! :: Cisco ASR 9000 Architecture :: BRKARC-2003 | Las Vegas 2017
 
ONOS: Open Network Operating System. An Open-Source Distributed SDN Operating...
ONOS: Open Network Operating System. An Open-Source Distributed SDN Operating...ONOS: Open Network Operating System. An Open-Source Distributed SDN Operating...
ONOS: Open Network Operating System. An Open-Source Distributed SDN Operating...
 
EMEA Airheads- ArubaOS - High availability with AP Fast Failover
EMEA Airheads- ArubaOS - High availability with AP Fast FailoverEMEA Airheads- ArubaOS - High availability with AP Fast Failover
EMEA Airheads- ArubaOS - High availability with AP Fast Failover
 
VLAN, VTP, DTP, Ether channel Cheat Sheet With examples.pptx
VLAN, VTP, DTP, Ether channel  Cheat Sheet With examples.pptxVLAN, VTP, DTP, Ether channel  Cheat Sheet With examples.pptx
VLAN, VTP, DTP, Ether channel Cheat Sheet With examples.pptx
 

Similar to Protecting Data In Motion with MACsec - Gijs Willemse - Rambus Design Summit 2020

IT8602 Mobile Communication - Unit III
IT8602 Mobile Communication  - Unit IIIIT8602 Mobile Communication  - Unit III
IT8602 Mobile Communication - Unit IIIpkaviya
 
Geef Industry 4.0 een boost
Geef Industry 4.0 een boostGeef Industry 4.0 een boost
Geef Industry 4.0 een boostHowest_ENM
 
Network Topologies, L1-L2 Basics, Networking Devices
Network Topologies, L1-L2 Basics, Networking DevicesNetwork Topologies, L1-L2 Basics, Networking Devices
Network Topologies, L1-L2 Basics, Networking DevicesAalok Shah
 
249549548 spider-ds-scsn-90002-112513
249549548 spider-ds-scsn-90002-112513249549548 spider-ds-scsn-90002-112513
249549548 spider-ds-scsn-90002-112513Zarobiza
 
zigbee technology
zigbee technology zigbee technology
zigbee technology N.CH Karthik
 
System design of multiprotocol iot
System design of multiprotocol iotSystem design of multiprotocol iot
System design of multiprotocol iotDev Bhattacharya
 
SELTA Access Network Portfolio
SELTA Access Network PortfolioSELTA Access Network Portfolio
SELTA Access Network PortfolioSELTA
 
Power Utilities Migration Solutions
Power Utilities Migration SolutionsPower Utilities Migration Solutions
Power Utilities Migration SolutionsNir Cohen
 
Multimedia network services and protocols for multimedia communications
Multimedia network services and protocols for multimedia communicationsMultimedia network services and protocols for multimedia communications
Multimedia network services and protocols for multimedia communicationsMazin Alwaaly
 
VET4SBO Level 3 module 1 - unit 2 - 0.009 en
VET4SBO Level 3   module 1 - unit 2 - 0.009 enVET4SBO Level 3   module 1 - unit 2 - 0.009 en
VET4SBO Level 3 module 1 - unit 2 - 0.009 enKarel Van Isacker
 
OSI reference model
OSI reference modelOSI reference model
OSI reference modelshanthishyam
 

Similar to Protecting Data In Motion with MACsec - Gijs Willemse - Rambus Design Summit 2020 (20)

Dm3000
Dm3000Dm3000
Dm3000
 
IT8602 Mobile Communication - Unit III
IT8602 Mobile Communication  - Unit IIIIT8602 Mobile Communication  - Unit III
IT8602 Mobile Communication - Unit III
 
MPLS ppt
MPLS pptMPLS ppt
MPLS ppt
 
ATM
ATMATM
ATM
 
06-Networks-Software.pdf
06-Networks-Software.pdf06-Networks-Software.pdf
06-Networks-Software.pdf
 
MC PPT.pptx
MC PPT.pptxMC PPT.pptx
MC PPT.pptx
 
Geef Industry 4.0 een boost
Geef Industry 4.0 een boostGeef Industry 4.0 een boost
Geef Industry 4.0 een boost
 
Network Topologies, L1-L2 Basics, Networking Devices
Network Topologies, L1-L2 Basics, Networking DevicesNetwork Topologies, L1-L2 Basics, Networking Devices
Network Topologies, L1-L2 Basics, Networking Devices
 
249549548 spider-ds-scsn-90002-112513
249549548 spider-ds-scsn-90002-112513249549548 spider-ds-scsn-90002-112513
249549548 spider-ds-scsn-90002-112513
 
zigbee technology
zigbee technology zigbee technology
zigbee technology
 
Ethernet basics
Ethernet basicsEthernet basics
Ethernet basics
 
System design of multiprotocol iot
System design of multiprotocol iotSystem design of multiprotocol iot
System design of multiprotocol iot
 
SELTA Access Network Portfolio
SELTA Access Network PortfolioSELTA Access Network Portfolio
SELTA Access Network Portfolio
 
Allied Telesis IE510-28GSX
Allied Telesis IE510-28GSXAllied Telesis IE510-28GSX
Allied Telesis IE510-28GSX
 
Power Utilities Migration Solutions
Power Utilities Migration SolutionsPower Utilities Migration Solutions
Power Utilities Migration Solutions
 
ADAM-3600 Sales kit_WATER.pptx
ADAM-3600 Sales kit_WATER.pptxADAM-3600 Sales kit_WATER.pptx
ADAM-3600 Sales kit_WATER.pptx
 
Multimedia network services and protocols for multimedia communications
Multimedia network services and protocols for multimedia communicationsMultimedia network services and protocols for multimedia communications
Multimedia network services and protocols for multimedia communications
 
VET4SBO Level 3 module 1 - unit 2 - 0.009 en
VET4SBO Level 3   module 1 - unit 2 - 0.009 enVET4SBO Level 3   module 1 - unit 2 - 0.009 en
VET4SBO Level 3 module 1 - unit 2 - 0.009 en
 
OSI reference model
OSI reference modelOSI reference model
OSI reference model
 
Basic networking
Basic networkingBasic networking
Basic networking
 

Recently uploaded

Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...DianaGray10
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FMESafe Software
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Jeffrey Haguewood
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FMESafe Software
 
Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024The Digital Insurer
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingEdi Saputra
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century educationjfdjdjcjdnsjd
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MIND CTI
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native ApplicationsWSO2
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...Zilliz
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAndrey Devyatkin
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfsudhanshuwaghmare1
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoffsammart93
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...apidays
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesrafiqahmad00786416
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024The Digital Insurer
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherRemote DBA Services
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsNanddeep Nachan
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusZilliz
 

Recently uploaded (20)

Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 

Protecting Data In Motion with MACsec - Gijs Willemse - Rambus Design Summit 2020

  • 1. Protecting Data in Motion with MACsec Fall 2020 Gijs Willemse Sr. Director of Product Management
  • 2. 2 • Data that is transferred between two devices and/or servers • Many different sources and application • Consumer electronics, Mobile devices, IoT • Automotive, Infrastructure, Edge devices • Cloud servers, Data centers, others • Many different transmission medium • Wireless: Mobile (3GPP) and WiFi (or combinations) • Wired: Copper, Optical, long distance optical (OTN) • Why do I need Secure Communication? • Medium is in the public domain • Transferred data is vulnerable for many different attacks, including: physical, man-in-the-middle, (D)DoS, Sniffing, Spoofing… What is “Data in Motion”
  • 3. 3 MACsec • Media Access Control Security (IEEE) • Protect Ethernet links • Switch – Switch • Switch – Host • Host – Host • Extensions to deploy over VLAN Crypto • Products generally require FIPS 140-2 algorithm validated before deployment in public domain Protecting Data in Motion: Use Secure Communication Protocols Session TCP / UDP IP Layer 2 (Link) Layer 1 (Physical) Application TCP / UDP IP Layer 2 (Link) Layer 1 (Physical) IPsec MACsec Client Server OSI Protocol Stack TLS Crypto IPsec • Internet Protocol Security (IETF) • Set up a Virtual Private Network Secure IP traffic between • Network – Network • Network – Host • Host – Host TLS (SSL) • Transport Layer Security (IETF) • Secure communications between two applications • Web Browser – Web Server • Client App – Cloud API • Sensor chip – App Processor
  • 4. 4 • Meet line rate throughput • Speed of optical links goes up to 800Gbps and fastest switches handle >10Tbps of traffic • Limit Latency • Realtime application is factory, medical or even consumer space have strict latency requirements • Response times must be minimized • Applications require constant latency • Support Prioritization • TSN Ethernet layer define prioritization: pre-emption of packets is required • Cope with network diversity and various deployments • Networks are virtual • Connections can be hop-by-hop, but also end-to-end • Traffic passes different networks and infrastructures Requirements for Secure Communication
  • 5. 5 • MACsec is the L2 security standard, widely deployed in PHYs, switches, firewalls, gateways, NICs and 5G equipment • Advantages of MACsec • Scalable crypto • Low latency • Fully inline datapath • Negligible SW overhead • Implementation Challenges • Line rate under all conditions • Prioritization / Frame Preemption • Rambus has portfolio that covers all ranges and features optimized for the modern Ethernet requirements, including custom classification. Meets line-rate under all conditions • The only provider of control plane software MACsec Security PHY MACsec classifier MACsec transformation MAC/PCS PTP MAC/PCS Line: 8x112G SerDes Switch MACsec classifier MACsec transformation Bufferingand multiplexing MAC/ PCSMAC/ PCSMAC/ PCS MAC/ PCSMAC/ PCSMAC/ PCS optionalPTP
  • 6. 6 • Ethernet is getting adopted in aerospace, automotive, manufacturing and utility industries • Enables new levels of connectivity and cost reduction. • Enables new uses cases • These applications require deterministic traffic • TSN group of standards is defined • Adding: priority queues, minimum jitter, preemption, shaping/scheduling, time. • TSN features are integrated into Ethernet subsystem • Ethernet PHYs • Switches • Gateways • Automotive/industrial TSN SOCs Time Sensitive Networking (TSN Ethernet)
  • 7. 7 • TSN Ethernet does requires data protection. Yes, MACsec is a logical choice. • Addition of Security must keep deterministic behavior of the Ethernet traffic • This raises implementation challenges that are not covered by standards and must be resolved • It must be possible to interleave packets, allowing priority packets to interrupt regular traffic • Crypto works on native cipher block sizes (typical 16B), interruption of a data stream requires complex state/date storage • Rambus MACsec IPs support TSN, targeting MACsec-capable Ethernet ports • Lowest latency of fixed latency modes • Side-band signaling to interact with external PTP modules and classifiers • Preemption support by processing two interleaved streams per port • Preemption support by processing IEEE802.3br fragments while keeping the fragment size, latency and relation unchanged TSN MACsec: Translating Challenges into Solutions
  • 8. 8 Deployment in SoC/switch and PHY SOC PHY MAC merge sublayer eMAC pMAC System MAC TSN MACsec Line MAC PCS DMA PHY SOC TSN MACsec MAC merge sublayer eMAC pMAC PCS DMA / Switch Interface
  • 9. 9 • Catalog solutions include: • Single port, MACsec/VLAN-in-clear for rates of 1G / 2.5G / 10G / 25G / 50G / 100G • [New] Next generation single-port IPs with pre-emption from 1 to 50G TSN Ethernet • Multichannel (TDM) MACsec for 100G to 800G: EIP-163/164. Optional support for proprietary classification and other custom extensions • Full-featured control plane product • MACsec Toolkit: IEEE 802.1X (EAP + MKA). Includes a SW data plane for development purpose • Non-MACsec TDM Silicon IP products for >1Tbps AES-GCM encryption • Scalable AES-GCM engine • IPsec AES-GCM transform engine for NICs • TLS/IPsec and wireless algorithm (3GPP) packet engines: EIP-196/EIP-197 • TLS/IPsec/MACsec Toolkits implementing the key exchange protocol for all three security stacks (MatrixSSL/QuickSec) Rambus MACsec Offering
  • 10. Thank you For more information: gwillemse@rambus.com