Data volumes are increasing in hyperscale data centers, 5G networks with Open RAN, and in-vehicle networks, as well as due to privacy regulations such as the General Data Protection Regulation (GDPR). As a result, security must be ensured at every layer of the Open Systems Interconnection (OSI) stack as data travels from one destination to the next.
MACsec, defined by the IEEE 802.1AE standard , provides inline data encryption for high-speed Ethernet and plays a key role in authenticating and encrypting packets between two devices with Layer 2 MACsec capabilities. It has become an important encryption technology that is now being incorporated into next-generation chips, routers, and switches.
Keysight's MACsec testing solution offers the following key benefits:
• Enables validation from hardware design and software stack implementation to system integration with comprehensive coverage of various MACsec functions.
• Supports data rate encryption evaluations under realistic mixes of cloud and data center traffic workloads.
• Ensures service continuity during key rotations and stability under various adverse conditions.
• Provides inline MACsec traffic encryption/decryption with 100GE 4-level Pulse Amplitude Modulation (PAM4) and non-return-to-zero (NRZ) schemes; static provisioning of Secure Association Keys (SAK) or dynamic key negotiation with the MACsec Key Agreement Protocol (MKA), using Keysight's AresONE High Performance 400GE test platform
“With the promise of securing data in motion without impacting performance, MACsec has been adopted by hyperscale cloud service providers and data center operators to secure connectivity to external networks throughout their network infrastructure,” said Ram Periakaruppan, vice president and general manager of Network Security and Testing Solutions at Keysight. “Keysight is the first to provide a solution that fully addresses MACsec testing at the chip, switch, or router levels for massive cloud or data center deployments, enabling customers to validate proper encryption and data rates without compromising network performance.”
