CAST adds Ethernet bridges and MACsec key management

CAST adds Ethernet bridges and MACsec key management

CAST has added bridge interfaces and software for Ethernet security. The development allows hardware MACsec engines to be inserted between existing Ethernet MACs and physical interfaces, with key agreement software supporting embedded operating systems and bare-metal applications.


IN Brief:

  • New xMII interface bridges connect MACsec encryption engines between existing MAC and PHY blocks.
  • MACSEC-1G supports 10/100/1000 Mbps links; MACSEC-MG covers faster Ethernet implementations.
  • An IEEE 802.1X MKA software stack supports security associations and key management.

CAST has extended its MACsec semiconductor intellectual property portfolio with Ethernet interface bridges and an IEEE 802.1X key agreement software stack, providing another way to integrate hardware encryption into existing embedded network designs. The additions allow compatible MACsec engines to be positioned between an Ethernet media access controller and physical layer transceiver without requiring extensive changes to the host processor interface or established packet processing architecture.

CAST’s existing MACSEC-1G and MACSEC-MG engines provide IEEE 802.1AE authenticated link encryption, with confidentiality, integrity and replay protection determined by the selected cipher suite and configuration. The new interface bridges and MKA software extend how those engines can be integrated and controlled within a device.

Integrating this capability into a new system-on-chip is relatively straightforward when the Ethernet processing path can be planned around a streaming security engine. Retrofitting the same function into an established design presents additional constraints because the Ethernet MAC may already be integrated with processor interfaces, direct memory access functions, time-sensitive networking logic and existing software.

Existing Ethernet MACs may already be tightly coupled to host interfaces and direct memory access functions, making a wholesale redesign of the packet path undesirable. CAST’s bridges connect the encryption engine between the MAC and physical layer transceiver while leaving established host interactions in place.

MACSEC-1G supports 10, 100 and 1,000 Mbps Ethernet through MII, RMII, GMII and RGMII interfaces, with a 32-bit datapath. Higher bandwidth implementations use the MACSEC-MG core with XGMII and a 128-bit datapath; CAST specifies full-duplex operation up to 16.75 Gbps for suitable configurations. Actual line rates depend on the selected integration and physical interfaces.

Both cores retain native AXI-Stream interfaces, allowing integration directly into a newly designed packet processing pipeline where that arrangement is preferable. Optional bridges therefore provide additional architectural flexibility rather than replacing existing interfaces. Control and status registers remain accessible through a host interface, with bridge options supporting common embedded bus arrangements.

In Ethernet switches and time-sensitive networking equipment, forwarding and scheduling logic may require access to unencrypted frame information. Placing the MACsec engine towards the external link allows those internal operations to occur before the outgoing Ethernet traffic is protected.

The link security boundary ends at the device terminating MACsec, so host processors, switching fabrics and other internal components still require their own protection. The engine’s location also needs to be reconciled with timestamping, frame inspection and network management functions that interact with transmitted traffic.

CAST has accompanied hardware changes with an IEEE 802.1X MACsec Key Agreement software stack, known as MKA, and drivers controlling the encryption engine. MKA coordinates security relationships between participating devices, including peer authentication, security association establishment and key changes. These operations are managed throughout a connection rather than performed only when equipment starts.

Separating key agreement from packet encryption allows dedicated hardware to perform high-throughput cryptographic work while software manages security state. CAST supplies stack and driver components for FreeRTOS, bare-metal applications and Linux. Embedded systems without a full operating system can use management functions rather than implementing an MKA subsystem independently.

Linux environments may already support MACsec key management through software such as wpa_supplicant, but still require a method of configuring and monitoring the specific hardware engine. CAST’s driver support addresses that interface, while FreeRTOS and bare-metal implementations provide an alternative for constrained environments. Integration testing must verify interaction among host software, register interfaces, security state and Ethernet data paths.

The MACsec cores support IEEE 802.1AE and related amendments, including AES-GCM with 128-bit or 256-bit keys and extended packet numbering. CAST also supports configurations where VLAN tags remain visible outside encrypted portions of a frame. This can aid classification by network equipment, although designers must understand what fields remain observable. The European Union’s Cyber Resilience Act places wider requirements on product security; deploying MACsec alone does not establish compliance with those obligations.

In industrial controllers and automotive network gateways expected to remain in service for years, the bridges provide an integration route for Ethernet encryption without replacing an existing MAC architecture. Engineers still need to match supported signalling speeds, timing, software key management and security policy to the final semiconductor implementation.


Stories for you


  • Arteris secures .3m for chip IP assurance research

    Arteris secures $3.3m for chip IP assurance research

    Arteris secured additional funding for third-party semiconductor security assurance research. The $3.3 million award expands its work with BAE Systems and SiFive on repeatable methods for evaluating security weaknesses in commercially sourced IP blocks and their integration into complex chips.


  • CAST adds Ethernet bridges and MACsec key management

    CAST adds Ethernet bridges and MACsec key management

    CAST has added bridge interfaces and software for Ethernet security. The development allows hardware MACsec engines to be inserted between existing Ethernet MACs and physical interfaces, with key agreement software supporting embedded operating systems and bare-metal applications.