Method and device for transmitting encrypted control overhead in optical transport network
By inserting the encryption control overhead into the OSU overhead channel of the OSU data stream in the OTN network and mapping it to the static load area of the OTN frame, the problem of the large number of bytes occupies in the security management information channel in the OTN network is solved, and flexible control of security management information is achieved.
Patent Information
- Application Number
- CN202010496150.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-06-03
- Publication Date
- 2025-05-02
- Estimated Expiration
- 2040-06-03
AI Technical Summary
When transmitting data, the security management information channel occupies a large number of bytes, making it difficult to effectively carry in limited ODUk reserved bytes, resulting in inflexibility.
The transmission of security management information is realized by inserting the encryption control overhead into the OSU overhead channel of the OSU data stream every interval M frames, and mapping the OSU data stream into the static load block PB of the static load area of the OTN frame.
On the basis of not occupying limited ODUk reserved bytes, the inflexibility of the security management information channel is solved and flexible control of security management information is realized.
Smart Images

Figure CN113765853B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communications, and in particular, to a method and device for transmitting encrypted control overhead in an optical transport network. Background Art
[0002] With the continuous evolution of OTN, the types of information security risks faced by various services carried by it are increasing, the scope is expanding, and the levels are deepening. Most of the existing OTNs are in a "unprotected" state. With the rapid development of attacks and eavesdropping technologies in optical fiber communication networks, the possibility of directly stealing optical fiber transmission data, modifying optical network management system information, and attacking optical network node devices has become a reality. Optical networks are facing security threats at any time and cannot guarantee the security of data information. Therefore, encryption and decryption technologies based on optical transmission networks are imminent.
[0003] In the data transmission process of the existing OTN network, in order to ensure the security of network data, the transmitted data must first be encrypted, and then the encrypted ciphertext must be decrypted after passing through the OTN network to obtain the network data. In the process of identity authentication, key mode switching, key lossless switching, etc., some important overhead information needs to be transmitted in the overhead channel. At present, in terms of the selection of overhead channels, the industry unanimously believes that the reserved overhead of OTN can be used as the security management information channel, but the number of reserved overhead bytes of OTN is limited. If the number of bytes occupied by the security management information channel is relatively large, how to carry these security management information in the limited reserved overhead bytes has become a research topic.
[0004] Figure 1 It is a schematic diagram of the implementation of the security management control information channel in the related technology, such as Figure 1 As shown in the figure, the security management information channel can be established by using the existing ODUk reserved bytes in the OTN frame structure. By transmitting multiple frames, the limited ODUk reserved bytes can be saved. The disadvantages of using the existing ODUk reserved bytes to establish the security management information channel are: on the one hand, the existing ODUk reserved bytes are limited. On the other hand, if the TCM4 / TCM5 / TCM6 / EXP bytes are reused, these bytes have special uses in special application scenarios. If they are used to establish the security management information channel, conflicts will occur, which is not very flexible.
[0005] In the related art, the use of the existing ODUk reserved bytes in the OTN frame structure to establish a security management information channel has the problems of limited number of ODUk reserved bytes, conflicts caused by reuse of some existing bytes in special scenarios, and inflexibility caused by saving limited ODUk reserved bytes through multi-frame transmission. No solution has been proposed yet. Summary of the invention
[0006] The embodiments of the present application provide a method and device for transmitting encrypted control overhead in an optical transport network, so as to at least solve the problems in the related art of using the existing ODUk reserved bytes in the OTN frame structure to establish a security management information channel, such as the limited number of ODUk reserved bytes, conflicts caused by reusing some existing bytes in special scenarios, and inflexibility caused by saving limited ODUk reserved bytes through multi-frame transmission.
[0007] According to an embodiment of the present application, a method for transmitting encrypted control overhead in an optical transport network is provided, comprising:
[0008] Mapping the customer service into an optical service layer unit (OSU) data stream, wherein the OSU is composed of N basic blocks, and the N basic blocks include an OSU overhead and N-1 OSU payloads;
[0009] Inserting the encryption control overhead into the OSU overhead channel of the OSU data stream every M frames, where M is an integer greater than or equal to 1;
[0010] Mapping the OSU data stream into a payload block PB in a payload area of an OTN frame;
[0011] The data frame is encapsulated into an optical conversion unit (OTU) frame, and the OTU frame is sent to the sink.
[0012] Optionally, inserting the encryption control overhead into the OSU overhead channel of the OSU data stream every M frames includes:
[0013] An encryption control overhead channel is established in the OSU overhead of every M frames in the OSU data stream, and the encryption control overhead is carried by the encryption control overhead channel to obtain multiple security frame headers SFH, wherein the encryption control overhead includes a counter, an encryption control word and the M, and the counter is used to count encryption units during the process of encrypting the OSU payload.
[0014] Optionally, before mapping the OSU data stream into the PB of the data frame, the method further includes:
[0015] Encrypting the OSU payloads between the multiple SFHs to obtain multiple security frame bodies SFB;
[0016] Combining each of the SFHs with the SFBs following the SFHs respectively to obtain a plurality of security frames;
[0017] The integrity of the multiple security frames is checked respectively, and the integrity check field is inserted into the tail of the corresponding security frame.
[0018] Optionally, encrypting the OSU payload between the multiple SFHs to obtain multiple security frame bodies SFB includes:
[0019] Encrypting the original key pre-negotiated with the destination end by using a combination of a multiframe alignment signal MFAS and the counter to obtain a target key;
[0020] The encryption units of the OSU payloads between the multiple SFHs are encrypted using the target key to obtain the multiple SFBs.
[0021] Optionally, each of the OSU frames includes X encryption units, the size of the counter is Y, the initial value of the counter is 0, and the value of the counter increases by 1 each time an OSU encryption unit is encrypted, wherein X=(P / 16)*(N-1), P is the number of bytes occupied by one basic block.
[0022] Optionally, after encrypting the encryption unit of the OSU payload between the multiple SFHs by using the target key to obtain the multiple SFBs, the method further includes:
[0023] After the preset timer of the original key expires, receiving the encrypted control word simultaneously with the sink;
[0024] inserting the encryption control word into the SFH of W consecutive OSU frames starting from the boundary of the next W OSU frames according to the MFAS, and starting the key update operation at the boundary of the next W frames, where W is an integer greater than 1;
[0025] The receiving end continuously searches for the encryption control word from the OSU data stream at intervals of M frames according to the MFAS at a period of W OSU frames, compares the encryption control word with the received encryption control word, and sends a key switching success message if the comparison result is consistent for more than W / 2 times;
[0026] The key switching success message is encrypted using the updated original key at the boundary of the next W frame.
[0027] Optionally, mapping the OSU data stream into a PB of a data frame includes:
[0028] Mapping the OSU data stream into the PB payload area of the data frame;
[0029] The overhead type of the OSU data stream is set in the PB overhead area of the data frame.
[0030] According to another embodiment of the present application, a method for transmitting encrypted control overhead in an optical transport network is provided, comprising:
[0031] An optical conversion unit (OTU) frame encapsulated by the OTN frame and sent by a source end is received, wherein an OSU data stream is mapped in a payload block PB in a payload area of the OTN frame, an encryption control overhead is inserted in an OSU overhead channel at every M frames of the OSU data stream, a customer service is mapped in the OSU data stream, and the OSU is composed of N basic blocks, and the N basic blocks include one OSU overhead and N-1 OSU payloads;
[0032] The OSU data stream is obtained from the OTU frame.
[0033] Optionally, after acquiring the OSU data stream from the OTU frame, the method further includes:
[0034] The service is obtained by decrypting a plurality of security frame bodies SFB in the OSU data stream according to the multiframe alignment signal MFAS, a counter, an encryption control word and the M, wherein the encryption control overhead includes a counter, an encryption control word and the M, the counter is used to count encryption units in the process of encrypting the OSU payload, the plurality of security frames are respectively composed of a plurality of SFHs and the SFBs after the plurality of SFHs, an integrity check field is inserted at the tail of the plurality of security frames, the plurality of SFBs are obtained by encrypting the OSU payload between the plurality of SFHs, and the plurality of SFHs are obtained by inserting the encryption control overhead into the OSU overhead of each interval of M frames of the OSU data stream.
[0035] Optionally, the method further comprises:
[0036] After the preset timer of the original key expires, the encryption control word is received simultaneously with the source end, wherein the source end is used to insert the encryption control word into the SFH of W consecutive OSU frames starting from the boundary of the next W OSU frames according to the MFAS, and start the key update operation at the boundary of the next W frames, where W is an integer greater than 1;
[0037] continuously searching the encrypted control word from the OSU data stream at intervals of the M frames according to the MFAS with W OSU frames as a period, and comparing the encrypted control word with the received encrypted control word;
[0038] If the comparison result is that the number of consistent times is greater than W / 2, a key switching success message is sent to the source end, wherein the key switching success message is used to instruct the source end to use the updated original key for encryption at the boundary of the next W frames.
[0039] According to another embodiment of the present application, a device for transmitting encrypted control overhead in an optical transport network is provided, comprising:
[0040] A first mapping module, used for mapping a customer service into an optical service layer unit (OSU) data stream, wherein the OSU is composed of N basic blocks, and the N basic blocks include an OSU overhead and N-1 OSU payloads;
[0041] An inserting module, configured to insert the encryption control overhead into the OSU overhead channel of the OSU data stream every M frames, wherein M is an integer greater than or equal to 1;
[0042] A second mapping module, used for mapping the OSU data stream into a payload block PB in a payload area of an OTN frame;
[0043] The first sending module is used to encapsulate the data frame into an optical conversion unit (OTU) frame and send the OTU frame to the sink.
[0044] Optionally, the insertion module is also used
[0045] An encryption control overhead channel is established in the OSU overhead of every M frames in the OSU data stream, and the encryption control overhead is carried by the encryption control overhead channel to obtain multiple security frame headers SFH, wherein the encryption control overhead includes a counter, an encryption control word and the M, and the counter is used to count encryption units during the process of encrypting the OSU payload.
[0046] Optionally, the device further comprises:
[0047] An encryption module, used for encrypting the OSU payload between the plurality of SFHs to obtain a plurality of security frame bodies SFB;
[0048] A combining module, used for combining each of the SFH with the SFB after the SFH to obtain multiple security frames;
[0049] The verification module is used to verify the integrity of the multiple security frames respectively, and insert the integrity verification field into the tail of the corresponding security frame.
[0050] Optionally, the encryption module includes:
[0051] A first encryption submodule, configured to encrypt an original key pre-negotiated with the sink by using a combination of the MFAS and the counter to obtain a target key;
[0052] The second encryption submodule is used to encrypt the encryption unit of the OSU payload between the multiple SFHs by using the target key to obtain the multiple SFBs.
[0053] Optionally, each of the OSU frames includes X encryption units, the size of the counter is Y, the initial value of the counter is 0, and the value of the counter increases by 1 each time an OSU encryption unit is encrypted, wherein X=(P / 16)*(N-1), P is the number of bytes occupied by one basic block.
[0054] Optionally, the device further comprises:
[0055] A receiving submodule, configured to receive the encrypted control word simultaneously with the sink after a preset timer of the original key expires;
[0056] An inserting submodule, configured to insert the encryption control word into the SFH of W consecutive OSU frames starting from the boundary of the next W OSU frames according to the MFAS, and start the key update operation at the boundary of the next W frames, where W is an integer greater than 1;
[0057] A comparison submodule, configured to receive the encryption control word continuously searched by the sink for the encryption control word at intervals of M frames from the OSU data stream with W OSU frames as a period, compare the encryption control word with the received encryption control word, and send a key switching success message if the comparison result is consistent for more than W / 2 times;
[0058] The third encryption submodule is used to encrypt using the updated original key at the boundary of the next W frame according to the key switching success message.
[0059] Optionally, the second mapping module includes:
[0060] A mapping submodule, used for mapping the OSU data stream into the PB payload area of the data frame;
[0061] The setting submodule is used to set the overhead type of the OSU data stream in the PB overhead area of the data frame.
[0062] According to another embodiment of the present application, a device for transmitting encrypted control overhead in an optical transport network is provided, comprising:
[0063] A first receiving module is used to receive an optical conversion unit (OTU) frame encapsulated by the OTN frame and sent by a source end, wherein an OSU data stream is mapped in a payload block PB in a payload area of the OTN frame, an encryption control overhead is inserted in an OSU overhead channel every M frames of the OSU data stream, a customer service is mapped in the OSU data stream, and the OSU is composed of N basic blocks, and the N basic blocks include an OSU overhead and N-1 OSU payloads;
[0064] An acquisition module is used to acquire the OSU data stream from the OTU frame.
[0065] Optionally, the device further comprises:
[0066] A decryption module is used to decrypt multiple security frame bodies SFB in the OSU data stream according to the multiframe alignment signal MFAS, a counter, an encryption control word and the M to obtain the service, wherein the encryption control overhead includes a counter, an encryption control word and the M, the counter is used to count encryption units in the process of encrypting the OSU payload, the multiple security frames are respectively composed of a plurality of SFHs and the SFBs after the plurality of SFHs, an integrity check field is inserted at the tail of the plurality of security frames, the multiple SFBs are obtained by encrypting the OSU payload between the plurality of SFHs, and the multiple SFHs are obtained after the encryption control overhead is inserted into the OSU overhead of each interval of M frames of the OSU data stream.
[0067] Optionally, the device further comprises:
[0068] A second receiving module, configured to receive the encryption control word simultaneously with the source end after a preset timer of the original key expires, wherein the source end is configured to insert the encryption control word into the SFH of W consecutive OSU frames starting from the boundary of the next W OSU frames according to the MFAS, and start the key update operation at the boundary of the next W frames, where W is an integer greater than 1;
[0069] A comparison module, configured to continuously search the encrypted control word from the OSU data stream at intervals of M frames according to the MFAS with W OSU frames as a period, and compare the encrypted control word with the received encrypted control word;
[0070] The second sending module is used to send a key switching success message to the source end if the comparison result is consistent the number of times greater than W / 2, wherein the key switching success message is used to instruct the source end to use the updated original key for encryption at the boundary of the next W frames.
[0071] According to another embodiment of the present application, a computer-readable storage medium is provided, in which a computer program is stored, wherein the computer program is configured to execute the steps of any of the above method embodiments when running.
[0072] According to another embodiment of the present application, an electronic device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.
[0073] Through the present application, the service is mapped into the OSU data stream, the encryption control overhead, i.e., the security management information, is inserted into the OSU overhead area of the OSU data stream, and is inserted into the PB divided in the static load area of the OTN frame. On the basis of not occupying the limited ODUk reserved bytes, the problem that the number of ODUk reserved bytes is limited, the reused part of the existing bytes conflicts in special scenarios, and the inflexibility caused by saving the limited ODUk reserved bytes by multi-frame transmission can be solved in the related art when the security management information channel is established by using the existing ODUk reserved bytes in the OTN frame structure, thereby realizing the flexible control of the security management information. BRIEF DESCRIPTION OF THE DRAWINGS
[0074] Figure 1 It is a schematic diagram of the implementation of a security management control information channel in the related art;
[0075] Figure 2 It is a hardware structure block diagram of a mobile terminal of a method for transmitting encrypted control overhead in an optical transport network according to an embodiment of the present invention;
[0076] Figure 3 The process of transmitting encrypted control overhead in an optical transport network according to an embodiment of the present invention is as follows Figure 1 ;
[0077] Figure 4 is a schematic diagram of the structure of an OSU frame according to an embodiment of the present application;
[0078] Figure 5 This is a schematic diagram of the structure of the OSU frame insertion overhead block according to an embodiment of the present application. Figure 1 ;
[0079] Figure 6 This is a schematic diagram of the structure of the OSU frame insertion overhead block according to an embodiment of the present application. Figure 2 ;
[0080] Figure 7 is a schematic diagram of mapping an OSU frame into a PB according to an embodiment of the present application;
[0081] Figure 8 is a schematic diagram of the relationship between the OSU structure and the minimum encryption unit according to an embodiment of the present application;
[0082] Fig. 9 is a schematic diagram of an encrypted control word in an OSU frame according to an embodiment of the present application;
[0083] Fig.10 The process of transmitting encrypted control overhead in an optical transport network according to an embodiment of the present invention is as follows Figure 2 ;
[0084] Fig.11 This is a schematic diagram of encryption processing based on the OSU structure according to an embodiment of the present application. Figure 1 ;
[0085] Fig.12 This is a schematic diagram of encryption processing based on the OSU structure according to an embodiment of the present application. Figure 2 ;
[0086] Fig.13 This is a schematic diagram of key switching at the source end according to an embodiment of the present application. Figure 1 ;
[0087] Fig.14 This is a schematic diagram of key switching at the sink according to an embodiment of the present application. Figure 1 ;
[0088] Fig.15 This is a schematic diagram of encryption processing based on the OSU structure according to an embodiment of the present application. Figure 3 ;
[0089] Fig.16 This is a schematic diagram of encryption processing based on the OSU structure according to an embodiment of the present application. Figure 4 ;
[0090] Fig.17 This is a schematic diagram of key switching at the source end according to an embodiment of the present application. Figure 2 ;
[0091] Fig.18 This is a schematic diagram of key switching at the sink according to an embodiment of the present application. Figure 2 ;
[0092] Fig.19 The structure frame of the encrypted control overhead transmission device in the optical transport network according to the embodiment of the present invention Figure 1 ;
[0093] Fig. 20 The structure frame of the encrypted control overhead transmission device in the optical transport network according to the embodiment of the present invention Figure 2 . DETAILED DESCRIPTION
[0094] Hereinafter, embodiments of the present invention will be described in detail with reference to the accompanying drawings and in combination with the embodiments.
[0095] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.
[0096] The method embodiments provided in the embodiments of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device. Taking running on a mobile terminal as an example, Figure 2 is a hardware structure block diagram of a mobile terminal of a method for transmitting encrypted control overhead in an optical transport network according to an embodiment of the present invention, such as Figure 2 As shown, the mobile terminal may include one or more ( Figure 2 Only one is shown in the figure) a processor 102 (the processor 102 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA) and a memory 104 for storing data, wherein the mobile terminal may also include a transmission device 106 and an input / output device 108 for communication functions. It can be understood by those skilled in the art that Figure 2 The structure shown is only for illustration and does not limit the structure of the mobile terminal. Figure 2 More or fewer components as shown, or with Figure 2 Different configurations are shown.
[0097] The memory 104 can be used to store computer programs, for example, software programs and modules of application software, such as the computer program corresponding to the encryption control overhead transmission method in the optical transport network in the embodiment of the present invention. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, to implement the above method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include a memory remotely arranged relative to the processor 102, and these remote memories may be connected to the mobile terminal via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0098] The transmission device 106 is used to receive or send data via a network. The specific example of the above network may include a wireless network provided by a communication provider of the mobile terminal. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, referred to as NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0099] In this embodiment, a method for transmitting encrypted control overhead in an optical transport network running on the above mobile terminal or network architecture is provided. Figure 3 The process of transmitting encrypted control overhead in an optical transport network according to an embodiment of the present invention is as follows Figure 1 ,like Figure 3 As shown, the process includes the following steps:
[0100] Step S302, mapping the customer service into an optical service layer unit OSU data stream, wherein the OSU is composed of N basic blocks, and the N basic blocks include an OSU overhead and N-1 OSU payloads;
[0101] Step S304, inserting the encryption control overhead into the OSU overhead channel of the OSU data stream every M frames, where M is an integer greater than or equal to 1;
[0102] In this embodiment, the above-mentioned step S304 can be specifically implemented in the following manner: establishing an encryption control overhead channel in the OSU overhead of every M frames in the OSU data stream, carrying the encryption control overhead through the encryption control overhead channel, and obtaining multiple security frame headers SFH, wherein the encryption control overhead includes a counter, an encryption control word and the M, and the counter is used to count the encryption units during the process of encrypting the OSU payload.
[0103] Step S306, mapping the OSU data stream into a payload block PB in the payload area of the OTN frame;
[0104] In this embodiment, the above step S306 may specifically include:
[0105] Mapping the OSU data stream into the PB payload area of the data frame;
[0106] The overhead type of the OSU data stream is set in the PB overhead area of the data frame.
[0107] Step S308: encapsulate the data frame into an optical conversion unit (OTU) frame, and send the OTU frame to the sink.
[0108] Through the above steps S302 to S308, the service is mapped into the OSU data stream, the encryption control overhead, i.e., the security management information, is inserted into the OSU overhead area of the OSU data stream, and is inserted into the PB divided in the static load area of the OTN frame. On the basis of not occupying the limited ODUk reserved bytes, the problems of limited number of ODUk reserved bytes, conflict of reused part of existing bytes in special scenarios, and inflexibility caused by saving limited ODUk reserved bytes in a multi-frame transmission mode when establishing a security management information channel in the related art can be solved, thereby realizing flexible control of security management information.
[0109] Figure 4 is a schematic diagram of the structure of an OSU frame according to an embodiment of the present application, such as Figure 4As shown, the embodiment of the present application maps the customer service to the OSU. The OSU consists of N basic block structures, including two types: overhead and payload. The value of N is different for different services. The first basic block in each OSU is the OSU overhead, and the remaining N-1 basic blocks are the OSU payload.
[0110] In one embodiment, before mapping the OSU data stream into the PB of the data frame, the OSU payload between the multiple SFHs is encrypted to obtain multiple security frame bodies SFB. Further, the original key pre-negotiated with the host end is encrypted using a combination of a multiframe alignment signal MFAS and the counter to obtain a target key; the encryption unit of the OSU payload between the multiple SFHs is encrypted using the target key to obtain the multiple SFBs; each of the SFHs is combined with the SFB after the SFH to obtain multiple security frames; the integrity of the multiple security frames is checked respectively, and the integrity check field is inserted into the tail of the corresponding security frame, and the multiframe alignment signal MFAS is an OSU basic overhead.
[0111] In this embodiment, each of the OSU frames includes X encryption units, the size of the counter is Y, the initial value of the counter is 0, and the value of the counter is increased by 1 each time an OSU encryption unit is encrypted, wherein X=(P / 16)*(N-1), P is the number of bytes occupied by one basic block.
[0112] The basic block length of OSU is P bytes, and OSU consists of N*P bytes. When encrypting OSU, in addition to encrypting the OSU payload part, some security management information needs to be added, so a security management information channel needs to be defined; in addition, the integrity of the security frame needs to be checked, and a security frame integrity check value is generated and inserted into the tail of the security frame. The encrypted OSU payload part is called SFB, and the security management information is called SFH (encryption control overhead). The security frame includes SFH and SFB. The security frame integrity check field is called SFC, and SFC is inserted after the security frame. The structure after encryption and integrity check is that the header of the security frame is SFH, the tail of the security frame is SFC, and the encrypted payload area SFB is left after removing the header and tail. Among them, SFH includes control information transmitted from the encryption end to the decryption end, as well as other control information associated with secure transmission, and SFC is the integrity check of the security frame.
[0113] In order to implement OSU encryption, an encryption channel can be constructed in the OSU data stream, that is, an encryption overhead block can be inserted into the OSU data stream. The encryption control block can be inserted based on a single OSU frame or multiple OSU frames. The SFH is carried in the encryption overhead block. Figure 5This is a schematic diagram of the structure of the OSU frame insertion overhead block according to an embodiment of the present application. Figure 1 ,like Figure 5 As shown, SFH is inserted once per OSU frame. Figure 6 This is a schematic diagram of the structure of the OSU frame insertion overhead block according to an embodiment of the present application. Figure 2 ,like Figure 6 As shown, N OSU frames are inserted once, and SFC is inserted into the end of the encrypted frame after one OSU frame or N OSU frames are encrypted. The bandwidth of the encryption control block is the ratio of the length of the encryption control block to the insertion period of the encryption control block.
[0114] In this embodiment, after the encryption unit of the OSU payload between the multiple SFHs is encrypted by the target key to obtain the multiple SFBs, after the preset timer of the original key expires, the encrypted control word is received simultaneously with the sink end; the encrypted control word is inserted into the SFH of W consecutive OSU frames starting from the boundary of the next W OSU frames according to the MFAS, and the key update operation is started at the boundary of the next W frames, where W is an integer greater than 1;
[0115] The receiving end continuously searches for the encryption control word from the OSU data stream at intervals of the M frames according to the MFAS at a period of W OSU frames, compares the encryption control word with the received encryption control word, and sends a key switching success message if the comparison result is consistent for more than W / 2 times; and encrypts using the updated original key at the boundary of the next W frames according to the key switching success message.
[0116] Figure 7 Schematic diagram of mapping OSU frames into PB according to an embodiment of the present application, such as Figure 7 As shown, the payload area of the optical transport network frame is divided into PBs, which include an overhead area and a payload area. The OSU data stream inserted into the encryption control block is mapped to the payload area of the PB. The encryption control block and the OSU overhead are two different types of control blocks. In order to identify these two types of control blocks, an indication mark is set in the overhead area of the PB, and the indication mark is used to indicate the type of control block carried in the PB.
[0117] Figure 8 is a schematic diagram of the relationship between the OSU structure and the minimum encryption unit according to an embodiment of the present application, such as Figure 8As shown, the encryption control block in SFH mainly includes two parts: counter and encryption control word. Since the OSU frame is based on N*P bytes, the payload part occupies (N-1)*P bytes, and the AES-CTR encryption mode is adopted, the minimum encryption unit is 128 bits (i.e. 16 bytes). Each OSU frame contains (P / 16)*(N-1) encryption units, and the size of the counter (in bits) is log2((P / 16)*(N-1)) rounded. In this mode, the 128-bit original key is first encrypted using the combination of MFAS and counter to obtain a new key, and then the user target data (the minimum encryption unit of OSU) is encrypted using the new key. Both the encryption end and the decryption end use the local original key, counter and local value of the multi-frame alignment signal MFAS. The original key needs to be negotiated between the encryption end and the decryption end; the counting behavior is consistent between the encryption end and the decryption end; and the MFAS is extracted from the local frame. The counter starts from 0, and the value of the counter increases by 1 for each encrypted 128-bit OSU encryption unit. The counter value ranges from 0 to (P / 16)*(N-1)-1. The minimum encryption unit is encrypted starting from the frame header of each OSU frame until the end of the OSU frame. The counter restarts counting at the frame header of the next OSU frame. Therefore, there is no need to transmit the counter value and MFAS value in the security management channel SFH. It is only necessary to transmit the original key in the channel, and the encryption end and the decryption end must reach an agreement. Whether SFH is inserted once for each OSU frame or once for N OSU frames, the processing method is consistent because encryption is for each OSU frame.
[0118] Fig. 9 is a schematic diagram of an encrypted control word in an OSU frame according to an embodiment of the present application, such as Fig. 9As shown, for the lossless switching between keys and modes, the large number judgment method of M encryption frame MFAS is used to ensure reliability. For the case where SFH is inserted once in each OSU frame, after receiving their own local encryption control words, the encryption end inserts the M frame encryption control words in the designated overhead position in the consecutive M frames according to the local MFAS at the adjacent M frame boundary, and the decryption end continuously searches and compares the encryption control words with M frames as a cycle. Finally, the decryption end confirms whether the synchronization operation between the decryption end and the encryption end is completed according to the large number judgment principle, and realizes the lossless switching of CTR, ECB, direct-through and other modes as well as the encryption end and decryption end keys. The large number judgment principle here is based on M frames. As long as the number of times the encryption control word of the sink end and the control word transmitted from the source end are the same as more than M / 2 times, the synchronization is considered to be completed. For the case where SFH is inserted once in N OSU frames, in addition to transmitting the encryption control word to the decryption end, the encryption end also needs to transmit the N value, that is, how many frames to insert the SFH once. The encryption control word and the N value are both transmitted as security management information. Taking N OSU frames as a unit, as a whole frame, the encryption end inserts M frame encryption control words at the specified overhead position for M consecutive whole frames starting from the adjacent M whole frame boundaries according to the MFAS of the first OSU frame of the local whole frame. The decryption end continuously searches and compares the encryption control words with M whole frames as a period. If the encryption control words are consistent, the mode switching and lossless switching are initiated.
[0119] This embodiment also provides a method for transmitting encrypted control overhead in an optical transport network. Fig.10 The process of transmitting encrypted control overhead in an optical transport network according to an embodiment of the present invention is as follows Figure 2 ,like Fig.10 As shown, the process includes the following steps:
[0120] Step S1002, receiving an optical conversion unit OTU frame encapsulated by the OTN frame and sent by a source end, wherein an OSU data stream is mapped in a payload block PB in a payload area of the OTN frame, an encryption control overhead is inserted in an OSU overhead channel every M frames of the OSU data stream, a customer service is mapped in the OSU data stream, and the OSU is composed of N basic blocks, and the N basic blocks include one OSU overhead and N-1 OSU payloads;
[0121] Step S1004: Acquire the OSU data stream from the OTU frame.
[0122] In one embodiment, after obtaining the OSU data stream from the OTU frame, multiple security frame bodies SFB in the OSU data stream are decrypted according to the multiframe alignment signal MFAS, the counter, the encryption control word and the M to obtain the service, wherein the encryption control overhead includes a counter, an encryption control word and the M, the counter is used to count encryption units in the process of encrypting the OSU payload, the multiple security frames are respectively composed of multiple SFHs and the SFBs after the multiple SFHs, an integrity check field is inserted at the tail of the multiple security frames, the multiple SFBs are obtained by encrypting the OSU payload between the multiple SFHs, and the multiple SFHs are obtained after the encryption control overhead is inserted into the OSU overhead of each M frame interval of the OSU data stream.
[0123] In another embodiment, after the preset timer of the original key expires, the encrypted control word is received simultaneously with the source end, wherein the source end is used to insert the encrypted control word into the SFH of W consecutive OSU frames starting from the boundary of the immediately adjacent W OSU frames according to the MFAS, and start the key update operation at the boundary of the next W frames, where W is an integer greater than 1; the encrypted control word is continuously searched from the OSU data stream at intervals of the M frames according to the MFAS with W OSU frames as a period, and the encrypted control word is compared with the received encrypted control word;
[0124] If the comparison result is that the number of consistent times is greater than W / 2, a key switching success message is sent to the source end, wherein the key switching success message is used to instruct the source end to use the updated original key for encryption at the boundary of the next W frames.
[0125] The embodiments of the present application are described in detail below with reference to specific examples.
[0126] A 100Mbit / s customer service A and a 155.52Mbit / s customer service B are transmitted between two OTN devices through the optical conversion unit OTU2. The device at the source end encrypts customer service A and customer service B. The encryption control overhead is inserted once in each OSU frame. The device at the sink end decrypts the encrypted service and restores the original customer service A and customer service B. At the same time, in order to ensure the security of the key, the key needs to be updated regularly.
[0127] Step 1, in this embodiment, the basic block length of OSU is 64 bytes, and the data frame is composed of the payload of ODU2, including 200 PBs. According to the relationship between the OSU bandwidth and the PB payload bandwidth, the number of PBs occupied by OSU can be calculated. OSU#1 carrying customer service A is composed of 6 64-byte basic blocks, and OSU#2 carrying customer service B is composed of 10 64-byte basic blocks.
[0128] Step 2, Fig.11 This is a schematic diagram of encryption processing based on the OSU structure according to an embodiment of the present application. Figure 1 ,like Fig.11 As shown, SFH is inserted once in each OSU frame, so customer service A is inserted once every 6 basic blocks, and the SFH insertion period is recorded as Ta; Fig.12 This is a schematic diagram of encryption processing based on the OSU structure according to an embodiment of the present application. Figure 2 ,like Fig.12 As shown in the figure, customer service B is inserted once every 10 basic blocks, and the SFH insertion period is recorded as Tb. According to the design of bypass overhead, the overhead is sent first and then the data. For customer service A, the source end sends the encryption control overhead SFH once according to the period Ta, and for customer service B, the source end sends the encryption control overhead SFH once according to the period Tb.
[0129] Step 3: After client service A and client service B send encryption control overheads according to their respective cycles, the source sends data OSU and fills it between the two encryption control overheads. The payload of this part is divided into 128 bits as an encryption unit for encryption processing. The encrypted data constitutes SFB. Finally, the integrity of the security frame (SFH+SFB) is checked, and the integrity check value C is calculated. The check value is inserted into the end of the security frame, that is, SFC.
[0130] Step 4: Customer service A and customer service B periodically complete the encryption processing and integrity processing of OSU#1 and OSU#2 according to the processing method in step 3.
[0131] Step 5: Multiplex OSU#1 and OSU#2 into the PB at the corresponding position in the data frame. After the multiplexing of OSU#1 and OSU#2 is completed, encapsulate the data frame into OTU2 and send it out.
[0132] Step 6: After receiving OTU2, the sink demaps the corresponding OSU#1 and OSU#2 from the PB of the data frame.
[0133] Step 7: The sink then identifies the data block, IDLE block, basic overhead block and encryption overhead block according to the type identifier.
[0134] Step 8, for the encrypted OSU block, locally calculate a check value D, compare the received integrity check value C with the locally calculated check value D, if the two are different, discard the OSU block; if the two are the same, decrypt the original service type A and service type B from the OSU block.
[0135] Step 9: When the key update timer expires, the upper layer software first sends an encryption control word to the source device and the sink device at the same time, and then the source device initiates the key update operation.
[0136] Step 10, Fig.13 This is a schematic diagram of key switching at the source end according to an embodiment of the present application. Figure 1 ,like Fig.13 As shown, the source device inserts 8 frames of encryption control words in the designated overhead position SFH for OSU#1 carrying customer service A and OSU#2 carrying customer service B according to the local MFAS[2:0] starting from the adjacent 8-frame boundary for 8 consecutive frames, and after the 8-frame encryption control words are inserted, the switching operation is started at the next MFAS[2:0] 8-frame boundary;
[0137] Step 11, Fig.14 This is a schematic diagram of key switching at the sink according to an embodiment of the present application. Figure 1 ,like Fig.14 As shown, the sink searches for the encryption control word at the SFH position of the received OSU frame based on the local MFAS[2:0] starting from the next 8-frame boundary, with a period of 8 frames, and compares it with the local encryption control word. If the encryption control word successfully matches more than 4 times in a certain 8-frame period comparison, the synchronization is confirmed to be successful, and the sink switches the new key at the next 8-frame boundary and reports the event of successful switching. If the number of successful comparisons is less than 5 times, the switching failure event is reported, and the sink will continue to search and compare the encryption control word with a period of 8 frames.
[0138] A 2.24Mbit / s customer service A and a 49.96Mbit / s customer service B are transmitted between two OTN devices through OTU2. The device at the source end encrypts customer service A and customer service B. The encryption control overhead is inserted once every 2 OSU frames. The device at the sink end decrypts the encrypted services and restores the original customer service A and customer service B. At the same time, in order to ensure the security of the key, the key needs to be updated regularly.
[0139] Step 1, in this embodiment, the basic block length of OSU is 64 bytes, and the data frame is composed of the payload of ODU2, including 200 PBs. According to the relationship between the OSU bandwidth and the PB payload bandwidth, the number of PBs occupied by OSU can be calculated. OSU#1 carrying customer service A is composed of 3 64-byte basic blocks, and OSU#2 carrying customer service B is composed of 5 64-byte basic blocks.
[0140] Step 2, Fig.15 This is a schematic diagram of encryption processing based on the OSU structure according to an embodiment of the present application. Figure 3 ,like Fig.15 As shown, SFH is inserted once every 2 OSU frames, so customer service A is inserted once every 6 basic blocks, and the SFH insertion period is recorded as Ta; Fig.16 This is a schematic diagram of encryption processing based on the OSU structure according to an embodiment of the present application. Figure 4 ,like Fig.16 As shown in the figure, customer service B is inserted once every 10 basic blocks, and the SFH insertion period is recorded as Tb. According to the design of bypass overhead, the overhead is sent first and then the data. For customer service A, the source end sends the encryption control overhead SFH once according to the period Ta, and for customer service B, the source end sends the encryption control overhead SFH once according to the period Tb.
[0141] Step 3: After client service A and client service B send the encryption control overhead according to their respective cycles, the source sends the data OSU and fills it between the two encryption control overheads. The payload of this part is divided into 128 bits as an encryption unit for encryption processing. The encrypted data constitutes SFB. Finally, the integrity of the security frame (SFH+SFB) is checked, and the integrity check value C is calculated. The check value is inserted into the end of the security frame, that is, SFC.
[0142] Step 4: Customer service A and customer service B periodically complete the encryption processing and integrity processing of OSU#1 and OSU#2 according to the processing method in step 3.
[0143] Step 5: Multiplex OSU#1 and OSU#2 into the PB at the corresponding position in the data frame. After the multiplexing of OSU#1 and OSU#2 is completed, encapsulate the data frame into OTU2 and send it out.
[0144] Step 6: After receiving OTU2, the sink demaps the corresponding OSU#1 and OSU#2 from the PB of the data frame.
[0145] Step 7: The sink then identifies the data block, IDLE block, basic overhead block and encryption overhead block according to the location and type identifier of the data and overhead.
[0146] Step 8, for the encrypted OSU block, locally calculate a check value D, compare the received integrity check value C with the locally calculated check value D, if the two are different, discard the OSU block; if the two are the same, decrypt the original service type A and service type B from the OSU block.
[0147] Step 9: When the key update timer expires, the upper layer software first sends an encryption control word to the source device and the sink device at the same time, and then the source device initiates the key update operation.
[0148] Step 10, Fig.17 This is a schematic diagram of key switching at the source end according to an embodiment of the present application. Figure 2 ,like Fig.17 As shown, the source device inserts 4 frames of encryption control words in the designated overhead position SFH for OSU#1 carrying customer service A and OSU#2 carrying customer service B according to the local MFAS[2:0] at the 4 adjacent overall frame boundaries for 4 consecutive overall frames, that is, inserts encryption control words at the positions of MFAS[2:0]=0,2,4,6. After the insertion of the 4 frames of encryption control words is completed, the switching operation is started at the 4 overall frame boundaries of the next MFAS[2:0]. At the same time, since SFH is inserted once every 2 OSU frames, the source end also needs to insert the "N value" (that is, how many OSU frames are inserted once SFH) in the designated overhead position SFH and pass the value to the destination end.
[0149] Step 11, Fig.18 This is a schematic diagram of key switching at the sink according to an embodiment of the present application. Figure 2 ,like Fig.18 As shown, after receiving the OSU frame sent by the source, the sink parses the content in the SFH and obtains the "N value", which corresponds to 2 in this embodiment. Then, according to the local MFAS[2:0], it starts from the next 4 whole frame boundaries and searches for the encryption control word at the SFH position of the received OSU frame with a period of 4 whole frames, that is, it searches for the encryption control word at the position of MFAS[2:0]=0,2,4,6, and compares it with the local encryption control word. If the number of successful matches of the encryption control word is greater than 2 times in the period comparison of a certain 4 whole frames, the synchronization is confirmed to be successful, and the sink switches the new key at the boundary of the next 4 whole frames and reports the event of successful switching. If the number of successful comparisons is less than 2 times, the switching failure event is reported, and the sink will continue to search and compare the encryption control word with a period of 4 whole frames.
[0150] Through the description of the above implementation methods, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus a necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, a magnetic disk, or an optical disk), and includes a number of instructions for a terminal device (which can be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods described in each embodiment of the present invention.
[0151] In this embodiment, a device for transmitting encrypted control overhead in an optical transport network is also provided, and the device is used to implement the above-mentioned embodiments and preferred implementation modes, and the descriptions that have been made are not repeated here. As used below, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the device described in the following embodiments is preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceivable.
[0152] Fig.19 The structure frame of the encrypted control overhead transmission device in the optical transport network according to the embodiment of the present invention Figure 1 ,like Fig.19 As shown, the device comprises:
[0153] A first mapping module 192, configured to map a customer service into an optical service layer unit (OSU) data stream, wherein the OSU is composed of N basic blocks, and the N basic blocks include an OSU overhead and N-1 OSU payloads;
[0154] An inserting module 194, configured to insert the encryption control overhead into the OSU overhead channel of the OSU data stream every M frames, wherein M is an integer greater than or equal to 1;
[0155] A second mapping module 196, configured to map the OSU data stream into a payload block PB in a payload area of an OTN frame;
[0156] The first sending module 198 is used to encapsulate the data frame into an optical conversion unit (OTU) frame and send the OTU frame to the sink.
[0157] Optionally, the insertion module 194 is also used to
[0158] An encryption control overhead channel is established in the OSU overhead of every M frames in the OSU data stream, and the encryption control overhead is carried by the encryption control overhead channel to obtain multiple security frame headers SFH, wherein the encryption control overhead includes a counter, an encryption control word and the M, and the counter is used to count encryption units during the process of encrypting the OSU payload.
[0159] Optionally, the device further comprises:
[0160] An encryption module, used for encrypting the OSU payload between the plurality of SFHs to obtain a plurality of security frame bodies SFB;
[0161] A combining module, used for combining each of the SFH with the SFB after the SFH to obtain multiple security frames;
[0162] The verification module is used to verify the integrity of the multiple security frames respectively, and insert the integrity verification field into the tail of the corresponding security frame.
[0163] Optionally, the encryption module includes:
[0164] A first encryption submodule, configured to encrypt an original key pre-negotiated with the sink end by using a combination of a multiframe alignment signal MFAS and the counter to obtain a target key;
[0165] The second encryption submodule is used to encrypt the encryption unit of the OSU payload between the multiple SFHs by using the target key to obtain the multiple SFBs.
[0166] Optionally, each of the OSU frames includes X encryption units, the size of the counter is Y, the initial value of the counter is 0, and the value of the counter increases by 1 each time an OSU encryption unit is encrypted, wherein X=(P / 16)*(N-1), P is the number of bytes occupied by one basic block.
[0167] Optionally, the device further comprises:
[0168] A receiving submodule, configured to receive the encrypted control word simultaneously with the sink after a preset timer of the original key expires;
[0169] An inserting submodule, configured to insert the encryption control word into the SFH of W consecutive OSU frames starting from the boundary of the next W OSU frames according to the MFAS, and start the key update operation at the boundary of the next W frames, where W is an integer greater than 1;
[0170] A comparison submodule, configured to receive the encryption control word continuously searched by the sink for the encryption control word at intervals of M frames from the OSU data stream with W OSU frames as a period, compare the encryption control word with the received encryption control word, and send a key switching success message if the comparison result is consistent for more than W / 2 times;
[0171] The third encryption submodule is used to encrypt using the updated original key at the boundary of the next W frame according to the key switching success message.
[0172] Optionally, the second mapping module 196 includes:
[0173] A mapping submodule, used for mapping the OSU data stream into the PB payload area of the data frame;
[0174] The setting submodule is used to set the overhead type of the OSU data stream in the PB overhead area of the data frame.
[0175] It should be noted that the above modules can be implemented by software or hardware. For the latter, it can be implemented in the following ways, but not limited to: the above modules are all located in the same processor; or the above modules are located in different processors in any combination.
[0176] In this embodiment, a device for transmitting encrypted control overhead in an optical transport network is also provided, and the device is used to implement the above-mentioned embodiments and preferred implementation modes, and the descriptions that have been made are not repeated here. As used below, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the device described in the following embodiments is preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceivable.
[0177] Fig. 20 The structure frame of the encrypted control overhead transmission device in the optical transport network according to the embodiment of the present invention Figure 2 ,like Fig. 20 As shown, the device comprises:
[0178] The first receiving module 202 is used to receive an optical conversion unit OTU frame encapsulated by the OTN frame and sent by the source end, wherein an OSU data stream is mapped in a payload block PB in a payload area of the OTN frame, an encryption control overhead is inserted in an OSU overhead channel every M frames of the OSU data stream, a customer service is mapped in the OSU data stream, and the OSU is composed of N basic blocks, and the N basic blocks include an OSU overhead and N-1 OSU payloads;
[0179] The acquisition module 204 is configured to acquire the OSU data stream from the OTU frame.
[0180] Optionally, the device further comprises:
[0181] A decryption module is used to decrypt multiple security frame bodies SFB in the OSU data stream according to the multiframe alignment signal MFAS, a counter, an encryption control word and the M to obtain the service, wherein the encryption control overhead includes a counter, an encryption control word and the M, the counter is used to count encryption units in the process of encrypting the OSU payload, the multiple security frames are respectively composed of a plurality of SFHs and the SFBs after the plurality of SFHs, an integrity check field is inserted at the tail of the plurality of security frames, the multiple SFBs are obtained by encrypting the OSU payload between the plurality of SFHs, and the multiple SFHs are obtained after the encryption control overhead is inserted into the OSU overhead of each interval of M frames of the OSU data stream.
[0182] Optionally, the device further comprises:
[0183] A second receiving module, configured to receive the encryption control word simultaneously with the source end after a preset timer of the original key expires, wherein the source end is configured to insert the encryption control word into the SFH of W consecutive OSU frames starting from the boundary of the next W OSU frames according to the MFAS, and start the key update operation at the boundary of the next W frames, where W is an integer greater than 1;
[0184] A comparison module, configured to continuously search the encrypted control word from the OSU data stream at intervals of M frames according to the MFAS with W OSU frames as a period, and compare the encrypted control word with the received encrypted control word;
[0185] The second sending module is used to send a key switching success message to the source end if the comparison result is consistent the number of times greater than W / 2, wherein the key switching success message is used to instruct the source end to use the updated original key for encryption at the boundary of the next W frames.
[0186] It should be noted that the above modules can be implemented by software or hardware. For the latter, it can be implemented in the following ways, but not limited to: the above modules are all located in the same processor; or the above modules are located in different processors in any combination.
[0187] An embodiment of the present invention further provides a computer-readable storage medium, in which a computer program is stored, wherein the computer program is configured to execute the steps of any of the above method embodiments when running.
[0188] In an exemplary embodiment, the computer-readable storage medium may include, but is not limited to, various media that can store computer programs, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk.
[0189] An embodiment of the present invention further provides an electronic device, including a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.
[0190] In an exemplary embodiment, the electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor, and the input / output device is connected to the processor.
[0191] For specific examples in this embodiment, reference may be made to the examples described in the above embodiments and exemplary implementation modes, and this embodiment will not be described in detail herein.
[0192] Obviously, those skilled in the art should understand that the above modules or steps of the present invention can be implemented by a general computing device, they can be concentrated on a single computing device, or distributed on a network composed of multiple computing devices, they can be implemented by a program code executable by a computing device, so that they can be stored in a storage device and executed by the computing device, and in some cases, the steps shown or described can be executed in a different order than here, or they can be made into individual integrated circuit modules, or multiple modules or steps therein can be made into a single integrated circuit module for implementation. Thus, the present invention is not limited to any specific combination of hardware and software.
[0193] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. For those skilled in the art, the present invention may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A method for transmitting encrypted control overhead in an optical transport network, characterized in that: include: Mapping the customer service into an optical service layer unit (OSU) data stream, wherein the OSU is composed of N basic blocks, and the N basic blocks include an OSU overhead and N-1 OSU payloads; Inserting the encryption control overhead into the OSU overhead channel of the OSU data stream every M frames, where M is an integer greater than or equal to 1; Mapping the OSU data stream into a payload block PB in a payload area of an OTN frame; The data frame is encapsulated into an optical conversion unit (OTU) frame, and the OTU frame is sent to the sink.
2. The method according to claim 1, characterized in that Inserting the encryption control overhead into the OSU overhead channel of the OSU data stream every M frames comprises: An encryption control overhead channel is established in the OSU overhead of every M frames in the OSU data stream, and the encryption control overhead is carried by the encryption control overhead channel to obtain multiple security frame headers SFH, wherein the encryption control overhead includes a counter, an encryption control word and the M, and the counter is used to count encryption units during the process of encrypting the OSU payload.
3. The method according to claim 2, characterized in that Before mapping the OSU data stream into the PB of the data frame, the method further comprises: Encrypting the OSU payloads between the multiple SFHs to obtain multiple security frame bodies SFB; Combining each of the SFHs with the SFBs following the SFHs respectively to obtain a plurality of security frames; The integrity of the multiple security frames is checked respectively, and the integrity check field is inserted into the tail of the corresponding security frame.
4. The method according to claim 3, characterized in that The OSU payloads between the multiple SFHs are encrypted to obtain multiple security frame bodies SFB including: Encrypting the original key pre-negotiated with the destination end by using a combination of a multiframe alignment signal MFAS and the counter to obtain a target key; The encryption units of the OSU payloads between the multiple SFHs are encrypted using the target key to obtain the multiple SFBs.
5. The method according to claim 4, characterized in that Each of the OSU frames contains X encryption units, the size of the counter is Y, the initial value of the counter is 0, and the value of the counter increases by 1 each time an OSU encryption unit is encrypted, wherein X=(P / 16)*(N-1), P is the number of bytes occupied by one basic block.
6. The method according to claim 4, characterized in that After encrypting the encryption unit of the OSU payload between the plurality of SFHs by using the target key to obtain the plurality of SFBs, the method further includes: After the preset timer of the original key expires, receiving the encrypted control word simultaneously with the sink; inserting the encryption control word into the SFH of W consecutive OSU frames starting from the boundary of the next W OSU frames according to the MFAS, and starting the key update operation at the boundary of the next W frames, where W is an integer greater than 1; The receiving end continuously searches for the encryption control word from the OSU data stream at intervals of M frames according to the MFAS at a period of W OSU frames, compares the encryption control word with the received encryption control word, and sends a key switching success message if the comparison result is consistent for more than W / 2 times; The key switching success message is encrypted using the updated original key at the boundary of the next W frame.
7. The method according to any one of claims 1 to 6, characterized in that Multiplexing the OSU data stream into the PB of the data frame includes: Mapping the OSU data stream into the PB payload area of the data frame; The overhead type of the OSU data stream is set in the PB overhead area of the data frame.
8. A method for transmitting encrypted control overhead in an optical transport network, characterized in that: include: An optical conversion unit (OTU) frame encapsulated by an OTN frame and sent by a source end is received, wherein an OSU data stream is mapped in a payload block PB in a payload area of the OTN frame, an encryption control overhead is inserted in an OSU overhead channel at intervals of M frames of the OSU data stream, a customer service is mapped in the OSU data stream, and the OSU is composed of N basic blocks, and the N basic blocks include an OSU overhead and N-1 OSU payloads; The OSU data stream is obtained from the OTU frame.
9. The method according to claim 8, characterized in that After acquiring the OSU data stream from the OTU frame, the method further includes: The service is obtained by decrypting a plurality of security frame bodies SFB in the OSU data stream according to the multiframe alignment signal MFAS, a counter, an encryption control word and the M, wherein the encryption control overhead includes a counter, an encryption control word and the M, the counter is used to count encryption units in the process of encrypting the OSU payload, the plurality of security frames are respectively composed of a plurality of SFHs and the SFBs after the plurality of SFHs, an integrity check field is inserted at the tail of the plurality of security frames, the plurality of SFBs are obtained by encrypting the OSU payload between the plurality of SFHs, and the plurality of SFHs are obtained by inserting the encryption control overhead into the OSU overhead of each interval of M frames of the OSU data stream.
10. The method according to claim 9, characterized in that The method further comprises: After the timer of the preset original key expires, the encrypted control word is received simultaneously with the source end, wherein the source end is used to insert the encrypted control word into the SFH of W consecutive OSU frames starting from the boundary of the next W OSU frames according to the MFAS, and start the key update operation at the boundary of the next W frames, where W is an integer greater than 1; continuously searching the encrypted control word from the OSU data stream at intervals of the M frames according to the MFAS with W OSU frames as a period, and comparing the encrypted control word with the received encrypted control word; If the comparison result is that the number of consistent times is greater than W / 2, a key switching success message is sent to the source end, wherein the key switching success message is used to instruct the source end to use the updated original key for encryption at the boundary of the next W frames.
11. An encrypted control overhead transmission device in an optical transport network, characterized in that: include: A first mapping module, used for mapping a customer service into an optical service layer unit (OSU) data stream, wherein the OSU is composed of N basic blocks, and the N basic blocks include an OSU overhead and N-1 OSU payloads; An inserting module, configured to insert the encryption control overhead into the OSU overhead channel of the OSU data stream every M frames, wherein M is an integer greater than or equal to 1; A second mapping module, used for mapping the OSU data stream into a payload block PB in a payload area of an OTN frame; The first sending module is used to encapsulate the data frame into an optical conversion unit (OTU) frame and send the OTU frame to the sink.
12. An encrypted control overhead transmission device in an optical transport network, characterized in that: include: A first receiving module is used to receive an optical conversion unit (OTU) frame encapsulated by an OTN frame and sent by a source end, wherein an OSU data stream is mapped in a payload block PB in a payload area of the OTN frame, an encryption control overhead is inserted in an OSU overhead channel every M frames of the OSU data stream, a customer service is mapped in the OSU data stream, and the OSU is composed of N basic blocks, and the N basic blocks include an OSU overhead and N-1 OSU payloads; An acquisition module is used to acquire the OSU data stream from the OTU frame.
13. A computer-readable storage medium, characterized in that: The storage medium stores a computer program, wherein the computer program is configured to execute the method described in any one of claims 1 to 7 and 8 to 10 when executed.
14. An electronic device comprising a memory and a processor, characterized in that: A computer program is stored in the memory, and the processor is configured to run the computer program to perform the method described in any one of claims 1 to 7 and 8 to 10.
Citation Information
Patent Citations
Optical network system
CN103918226A
Method for realizing data transmission and optical channel transmission equipment
CN106161416A