MACsec 802.1AE header – security TAG

The MACsec 802.1AE header includes a security TAG (SecTAG) field, which is identified by the MACsec Ethertype. The SecTAG field contains the following information:

  • association number (AN) within the channel

  • packet number (PN) to provide a unique initialization vector for encryption and authentication algorithms, as well as protection against replay attacks

  • optionally encoded LAN-wide secure channel identifier (SCI)

  • TAG control information (TCI)

  • short length (SL)

The following figure shows the format of the SecTAG.

Figure 1. SecTAG format