Data transmission method, device, readable storage medium and chip system

By encrypting the bit stream at the physical layer of the data stream and using the alignment identifier to carry the encryption parameter information, the problem of user service bandwidth occupation caused by MAC layer encryption is solved, and the data transmission volume and security are improved.

CN115766046BActive Publication Date: 2025-09-09HUAWEI TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111034263.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-03
Publication Date
2025-09-09
Estimated Expiration
2041-09-03

AI Technical Summary

Technical Problem

Existing encryption technologies based on protocols such as MACsec require encryption parameters to be carried when encrypting each user frame at the MAC layer, resulting in large user service bandwidth usage and high costs.

Method used

The bit stream is encrypted at the physical layer of the data stream. The encryption parameter information is carried by the alignment identifier (AM) in the data stream to avoid adding extra bits to the user service bandwidth. The physical layer of the optical module or network device is used for encryption to ensure that all bits, including the source MAC address and the destination MAC address, are encrypted.

Benefits of technology

It improves data transmission volume and security without occupying user business bandwidth, reduces the impact of encryption parameters on other data processing, and improves security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115766046B_ABST
    Figure CN115766046B_ABST
Patent Text Reader

Abstract

A data transmission method, device, readable storage medium and chip system. In the present application, a first communication device obtains and sends a first ciphertext data stream. The first ciphertext data stream includes a first alignment identifier AM and an encrypted first data segment. The first AM includes a first identification field and / or a first check field. Some or all of the bits in the first identification field carry first information, and the first information is used to indicate the channel identifier of the first ciphertext data stream and is used to lock the AM of the first ciphertext data stream. Some bits in the first identification field, and / or some or all bits in the first check field are used to carry encryption parameter information of the first data segment. Since the encryption parameter information is transmitted through the above-mentioned bits of the first AM in the data stream, the method can be applied to the physical layer of an optical module or a network device, and the sent encryption parameters can not occupy the user service bandwidth.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communications, and in particular to a data transmission method, device, readable storage medium, and chip system. Background Art

[0002] Dedicated line services, such as finance, require secure transport. Security is a crucial consideration for customers choosing dedicated line services. Encryption is a key means of ensuring data security, effectively preventing private information from being stolen by attackers. Based on the different layers of encryption within the Open System Interconnection Reference Model (OSI), encryption can be categorized into Layer 2 encryption, media access control security (MACsec), and other protocols. The encryption algorithm generally uses the standard Advanced Encryption Standard-Calois / Counter Mode (AES-GCM) algorithm.

[0003] Existing encryption technologies based on protocols like MACsec are implemented above the MAC layer, encrypting and decrypting individual user frames. Using MACsec-based encryption at the MAC layer to encrypt each user frame requires encryption parameters to be included within each frame. These encryption parameters consume significant user service bandwidth and are costly. Summary of the Invention

[0004] In order to solve the above problems, the present application provides a data transmission method, device, readable storage medium and chip system, so as to achieve the purpose of not occupying user service bandwidth by encryption parameters.

[0005] In the first aspect, the present application provides a data transmission method, which can be executed by a device at the sending end, for example, it can be executed by a first communication device. The first communication device obtains a first ciphertext data stream and sends the first ciphertext data stream. The first ciphertext data stream includes a first alignment identifier AM and an encrypted first data segment; the first AM is used for data alignment of the first ciphertext data stream. The first AM includes at least one of a first identification field or a first check field; the first identification field is used to indicate the channel identifier of the first ciphertext data stream and is used to lock the AM of the first ciphertext data stream. Part of the bits in the first identification field, and / or part or all of the bits in the first check field are used to carry: encryption parameter information of the first data segment.

[0006] This application transmits encryption parameter information through bits in the first AM in a data stream. This method can be applied to the physical layer of optical modules or network devices. The transmitted encryption parameters do not occupy user service bandwidth, thereby increasing data transmission volume and data transmission rate. In addition, because this solution encrypts the bit stream at the physical layer, all bits in a user frame (including the source MAC address and destination MAC address) are encrypted, thereby improving security.

[0007] In one possible implementation, some or all of the bits in the first identification field carry first information; the first information is used to indicate the channel identifier of the first ciphertext data stream and is used for AM locking of the first ciphertext data stream. In other words, the first information carried by the first identification field can have two functions: indicating the channel identifier of the first ciphertext data stream and being used for AM locking of the first ciphertext data stream.

[0008] In a possible implementation, the first communication device may obtain N ciphertext data streams, where N is a positive integer, and the first ciphertext data stream is one of the N ciphertext data streams. Correspondingly, the first communication device may send the N ciphertext data streams.

[0009] In one possible implementation, the first ciphertext data stream includes at least two first AMs and at least two encrypted first data segments. An encrypted first data segment is included between every two first AMs, and another first AM is included between every two encrypted first data segments. Thus, it can be seen that the first AMs in the embodiments of the present application can appear periodically in the first ciphertext data stream. Similarly, it can be understood that the encrypted first data segments also appear periodically in the first ciphertext data stream. It can also be understood that each AM period includes a first AM and an encrypted first data segment.

[0010] In one possible implementation, the first ciphertext data stream is obtained based on the first plaintext data stream and encryption parameter information. The first plaintext data stream includes a second AM and an unencrypted first data segment. The second AM is used for data alignment of the first plaintext data stream.

[0011] In one possible implementation, the second AM includes at least one of a second identification field and a second check field. The second identification field is used to carry second information, which indicates a channel identifier for the first plaintext data stream and is used to lock the AM of the first plaintext data stream. The second check field is used to carry check information.

[0012] In a possible implementation, if the first identification field is not used to carry encryption parameter information, the information carried by the second identification field may be the same as the information carried by the first identification field.

[0013] If the first identification field carries encryption parameter information, the first identification field includes the first information and the encryption parameter information, and the second identification field includes the second information. The bit value corresponding to the second information in the second identification field can be divided into two parts, which can be referred to as the first part bit value and the second part bit value. The first part bit value is the same as the bit value corresponding to the first information, and the bits of the first part bit value in the second identification field correspond to the same bits of the first information in the first identification field. The bits of the second part bit value in the second identification field correspond to the same bits of the encryption parameter information in the first identification field, but the second part bit value is different from the bit value corresponding to the encryption parameter information in the first check field.

[0014] In another possible implementation, if the first identification field carries encryption parameter information, it can be understood that the first identification field can be obtained by replacing some bits in the second identification field with some or all of the encryption parameter information. For example, it can be understood that the first communication device updates the second portion of the bit value in the second identification field with the encryption parameter information to obtain the first identification field.

[0015] In this way, the first identification field of the first AM can be obtained by replacing part of the content of the second identification field of the second AM in the plaintext data stream. And because the content carried by the first identification field is the protocol value, the receiving end can restore the bits carrying the encryption parameters in the first identification field to the corresponding values ​​in the second identification field, thereby minimizing the impact of the transmission of encryption parameter information on other data processing processes.

[0016] In a possible implementation, if the first check field is not used to carry encryption parameter information, the information carried by the second check field may be the same as the information carried by the first check field.

[0017] If the first check field carries encryption parameter information, then the first check field includes the third information and the encryption parameter information, and the second check field includes the fourth information. The bit value corresponding to the fourth information in the second check field can be divided into two parts, which can be referred to as the third part bit value and the fourth part bit value. The third part bit value is the same as the bit value corresponding to the third information, and the bits of the third part bit value in the second check field correspond to the same bits of the third information in the first check field. The bits of the fourth part bit value in the second check field correspond to the same bits of the encryption parameter information in the first check field, but the fourth part bit value is different from the bit value corresponding to the encryption parameter information in the first check field.

[0018] In another possible implementation, if the first identification field carries encryption parameter information, it can be understood that the first check field can be obtained by replacing some bits in the second check field with some or all of the bits in the encryption parameter information. For example, it can be understood that the first communication device updates the fourth bit value in the second check field with the encryption parameter information to obtain the first check field.

[0019] In order to ensure 0 / 1 balance, the information belonging to the encryption parameter information carried by the first AM can be divided into two parts, namely the first part of information and the second part of information. The bit value corresponding to the second part of information and the bit value corresponding to the first part of information are inverted. For example, if the bit value corresponding to the second part of information is 1010, then the bit value corresponding to the first part of information is 0101. The first part of information can be used as a reference to invert the first part of information to obtain the second part of information. The second part of information can also be used as a reference to invert the second part of information to obtain the first part of information. For example, it can also be understood that the second part of information is information obtained by inverting the bit value corresponding to the first part of information, or it can be understood that the first part of information is information obtained by inverting the bit value corresponding to the second part of information. In this way, it can also effectively resist the influence of link errors on the reliability of encryption parameter transmission.

[0020] In one possible implementation, the encryption parameter information carried in the first identification field is divided into two parts, namely, a third part of information and a fourth part of information, and the bit values ​​corresponding to the third part of information and the bit values ​​corresponding to the fourth part of information are inverted. For example, the fourth part of information is obtained by inverting the bit values ​​corresponding to the third part of information, and for another example, the third part of information is obtained by inverting the bit values ​​corresponding to the fourth part of information. In this way, 0 / 1 balance can be guaranteed, and the impact of link errors on the reliability of encryption parameter transmission can be effectively resisted.

[0021] In one possible implementation, the information contained in the first check field and belonging to the encryption parameter information is divided into two parts, namely, a fifth part of information and a sixth part of information, and the bit values ​​corresponding to the fifth part of information and the bit values ​​corresponding to the sixth part of information are inverted. For example, the fifth part of information is obtained by inverting the bit values ​​corresponding to the sixth part of information, and for another example, the sixth part of information is obtained by inverting the bit values ​​corresponding to the fifth part of information. In this way, 0 / 1 balance can be ensured, and the impact of link errors on the reliability of encryption parameter transmission can be effectively resisted.

[0022] In one possible implementation, the bits in the first identification field used to carry the encryption parameter information are some of the bits in the following fields: the M0 field, the M1 field, the M2 field, the ~M0 field, the ~M1 field, and the ~M2 field. The encryption parameter information may be deployed in at least two of the M0 field, the M1 field, the M2 field, the ~M0 field, the ~M1 field, and the ~M2 field, for example, in the M1 field and the ~M1 field.

[0023] In one possible implementation, the bits used to carry the encryption parameter information in the first identification field may be the 8 bits of the M0 field, and the bits in the 8 bits of the ~M0 field. In another possible implementation, the bits used to carry the encryption parameter information in the first identification field may be the 8 bits of the M1 field, and the bits in the 8 bits of the ~M1 field. In another possible implementation, the bits used to carry the encryption parameter information in the first identification field may be the 8 bits of the M2 field, and the bits in the 8 bits of the ~M2 field. In this way, several specific implementation methods can be provided for the specific carrying location of the encryption parameter information. Furthermore, the receiving end can cooperate with the corresponding matching rules to perform AM locking and identification of the channel identification information, so as to minimize the impact on the locking performance of the AM and the identification of the channel identification information.

[0024] In one possible implementation, the bits in the first check field used to carry encryption parameter information are some or all of the bits in the following fields: the BIP3 field or the ~BIP3 field. Because the value carried by the ~BIP3 field in the plaintext data stream is the inverse of the value of the BIP3 field, the receiver can recover the other field carrying encryption parameter information based on the BIP3 field or the ~BIP3 field, whichever does not carry encryption parameter information.

[0025] In one possible implementation, the bits in the first check field used to carry encryption parameter information are the first four bits of the ~BIP3 field and the last four bits of the ~BIP3 field. Because the value carried by the ~BIP3 field in the plaintext data stream is the inverse of the value of the BIP3 field, the receiving end can restore the value carried by the ~BIP3 field in the first AM to the value carried by the ~BIP3 field in the second AM based on the value of the BIP3 field information field in the first AM, thereby minimizing the impact of the transmission of encryption parameter information on other data processing processes.

[0026] In one possible implementation, the encryption parameter information includes an initialization vector (IV) and a key identifier. These two parameters are key parameters in the encryption parameter information. The receiving end can determine the encryption key based on these two parameters and can then decrypt the encrypted data based on the encryption key.

[0027] In a possible implementation, the encryption parameter information includes error correction information of the encryption parameter information, so as to effectively resist the influence of link errors on the reliability of encryption parameter transmission.

[0028] The error correction information for the encrypted parameter information can be a Reed-Solomon forward error correction (RS-FEC) code. RS-FEC codes are well-suited for dealing with burst errors. The error correction information for the encrypted parameter information can also be a BCH code, which stands for Bose, Ray-Chaudhuri, and Hocquenghem.

[0029] In a possible implementation, the encryption parameter information further includes multiframe start identifier information, which is used to indicate the start bit of the multiframe carrying the encryption parameter information. This allows the receiving end to identify the multiframe start bit corresponding to the encryption parameter information.

[0030] In one possible implementation, the encryption parameter information further includes multiframe lock status identification information, where the multiframe lock status identification information is used to indicate whether the multiframes of the transmitting end and / or the receiving end are locked. In this way, the receiving end can identify the multiframe lock status of the transmitting end and / or the receiving end.

[0031] In a possible implementation, the solution provided in the present application may be applied to a system architecture without a forward error correction (FEC) layer, and the transmission rate of the first ciphertext data stream may be 100 Gbps.

[0032] In the second aspect, an embodiment of the present application provides a data transmission method, which can be executed by a device at the receiving end, for example, it can be executed by a second communication device. The second communication device obtains a first ciphertext data stream. The second communication device decrypts the encrypted first data segment based on the encryption parameter information carried by the first AM in the first ciphertext data stream to obtain a first plaintext data stream. The first ciphertext data stream includes a first alignment identifier AM and an encrypted first data segment. The first AM is used for data alignment of the first ciphertext data stream. The first AM includes at least one of a first identification field or a first check field. The first identification field is used to indicate the channel identifier of the first ciphertext data stream and is used to lock the AM of the first ciphertext data stream; wherein, some bits in the first identification field, and / or some or all bits in the first check field are used to carry: encryption parameter information of the first data segment.

[0033] This application transmits encryption parameter information via bits in the first AM in a data stream. This method can be applied to the physical layer of optical modules or network devices, and the transmitted encryption parameters do not occupy user service bandwidth. Furthermore, because this solution encrypts the bit stream at the physical layer, all bits in a user frame (including the source and destination MAC addresses) are encrypted, thereby improving security.

[0034] In a possible implementation, some or all of the bits in the first identification field carry first information; the first information is used to indicate a channel identifier of the first ciphertext data stream and is used for AM locking of the first ciphertext data stream.

[0035] In one possible implementation, after obtaining the first ciphertext data stream and before decrypting the encrypted first data segment, the second communication device may further perform AM locking on the first ciphertext data stream based on at least k consecutive first AMs in the first ciphertext data stream, where the at least k consecutive first AMs satisfy a preset rule, where k is an integer greater than 1. The first AM among the at least k first AMs satisfying the preset rule includes: when information carried by some bits in the first identification field of the first AM includes part or all of the encryption parameter information, the bits in the information carried by the first identification field, excluding the encryption parameter information, completely match the preset AM locking information. In this embodiment of the present application, a matching rule for AM locking is proposed to maximize the performance of locking based on the first AM locking information. For example, if the first identification field has a total of 48 bits, 16 of which carry encryption parameter information, a matching rule may be: when 32 bits in the first identification field, excluding the 16 bits of encryption parameter information, completely match the preset AM locking information, the AM is determined to satisfy the preset rule.

[0036] In one possible implementation, after the second communication device completes AM locking of the first ciphertext data stream based on at least k consecutive first AMs in the first ciphertext data stream, it can also determine the channel identifier of the first ciphertext data stream based on information carried by the first AMs, excluding encryption parameter information. In other words, the second communication device can perform AM locking and identify the channel identifier based on the first AMs that carry encryption parameter information. Furthermore, after performing AM locking and identifying the channel identifier, the first AM can be restored to obtain a second AM, thereby minimizing the impact of the transmission of encryption parameter information via the first AM on other data processing flows.

[0037] In one possible implementation, the first ciphertext data stream is obtained based on the first plaintext data stream and encryption parameter information; the first plaintext data stream includes a second AM and an unencrypted first data segment; and the second AM is used for data alignment in the first plaintext data stream. For related introductions and beneficial effects, please refer to the aforementioned content related to the first aspect and will not be repeated here.

[0038] In one possible implementation, the second communication device decrypts the encrypted first data segment based on the encryption parameter information carried by the first AM in the first ciphertext data stream, obtaining the unencrypted first data segment in the first plaintext data stream. The second communication device may also process the first AM to obtain a second AM in the first plaintext data stream. Because the second communication device restores the first AM to the second AM in the plaintext data stream, the impact of the transmission of encryption parameter information on other data processing processes can be minimized.

[0039] In one possible implementation, the second AM includes at least one of a second identification field and a second check field. The second identification field is used to carry second information, which indicates the channel identifier of the first plaintext data stream and is used to lock the AM of the first plaintext data stream. The second check field is used to carry check information. For related introductions and beneficial effects, please refer to the aforementioned relevant content of the first aspect and will not be repeated here.

[0040] In one possible implementation, the first identification field may be obtained by replacing some bits in the second identification field with some or all bits in the encryption parameter information. The first check field may be obtained by replacing some bits in the second check field with some or all bits in the encryption parameter information. For related introductions and beneficial effects, please refer to the relevant content of the first aspect above and will not be repeated here.

[0041] If some bits in the first identification field are used to carry encryption parameter information, the second communication device may restore the information in the bits in the first identification field used to carry encryption parameter information to a preset value. The preset value may be a value specified by the protocol, thereby minimizing the impact of transmitting the encryption parameter information on other data processing processes.

[0042] Because the value carried by the first check field is divided into two parts, one of which is the inverse of the bit value of the other part, if some bits in the first check field are used to carry encryption parameter information, the second communication device can, based on the first check information carried in the first check field, restore the information on the bits in the first check field used to carry encryption parameter information to the inverse of the bit value corresponding to the first check information. This can minimize the impact of the transmission of encryption parameter information on other data processing processes.

[0043] In one possible implementation, for at least two first AMs that carry part or all of the encryption parameter information of at least one encrypted first data segment, the encryption parameter information carried by the first AM is divided into two parts: a first information part and a second information part. The second information part is obtained by inverting the corresponding bit values ​​of the first information part. For related introductions and beneficial effects, please refer to the relevant content of the first aspect above and will not be repeated here.

[0044] In a possible implementation, the information belonging to the encryption parameter information carried in the first identification field can be divided into two parts, namely the third part of information and the fourth part of information, and the fourth part of information is obtained by inverting the bit value corresponding to the third part of information.

[0045] The encryption parameter information carried in the first check field can be divided into two parts: a fifth part of information and a sixth part of information. The fifth part of information is obtained by inverting the bit values ​​corresponding to the sixth part of information. For related introductions and beneficial effects, please refer to the relevant content of the first aspect above and will not be repeated here.

[0046] In one possible implementation, the bits in the first identification field used to carry encryption parameter information are some of the bits in the following fields: M0 field, M1 field, M2 field, ~M0 field, ~M1 field, and ~M2 field. For related introductions and beneficial effects, please refer to the relevant content of the first aspect above and will not be repeated here.

[0047] In one possible implementation, the bits in the first identification field used to carry the encryption parameter information may be the 8 bits of the M0 field, and the bits in the 8 bits of the ~M0 field. In another possible implementation, the bits in the first identification field used to carry the encryption parameter information may be the 8 bits of the M1 field, and the bits in the 8 bits of the ~M1 field. In another possible implementation, the bits in the first identification field used to carry the encryption parameter information may be the 8 bits of the M2 field, and the bits in the 8 bits of the ~M2 field. For relevant introductions and beneficial effects, please refer to the relevant content of the first aspect mentioned above, which will not be repeated here.

[0048] In one possible implementation, the bits in the first check field used to carry encryption parameter information are part or all of the bits in the following fields: the BIP3 field or the ~BIP3 field. In another possible implementation, the bits in the first check field used to carry encryption parameter information are the first 4 bits of the ~BIP3 field and the last 4 bits of the ~BIP3 field. For related introductions and beneficial effects, please refer to the relevant content of the first aspect above and will not be repeated here.

[0049] In a possible implementation, the encryption parameter information includes an initialization vector IV and a key identifier. For related introduction and beneficial effects, please refer to the related content of the first aspect above, which will not be repeated here.

[0050] In a possible implementation, the encrypted parameter information includes: error correction information of the encrypted parameter information. For related introduction and beneficial effects, please refer to the related content of the first aspect above, which will not be repeated here.

[0051] In a possible implementation, the error correction information of the encrypted parameter information includes: RS-FEC code and / or BCH code. For related introduction and beneficial effects, please refer to the related content of the first aspect above, which will not be repeated here.

[0052] In one possible implementation, the encryption parameter information further includes: multiframe start identifier information, which is used to indicate the start bit of the multiframe that carries the encryption parameter information. In another possible implementation, the encryption parameter information further includes: multiframe lock status identifier information, which is used to indicate whether the multiframe of the transmitting end and / or the receiving end is locked.

[0053] In one possible implementation, after the second communication device obtains the first ciphertext data stream and before decrypting the encrypted first data segment, the second communication device further includes: obtaining error correction information for the encryption parameter information in the first ciphertext data stream; and performing error correction on other information in the encryption parameter information based on the error correction information. This effectively mitigates the impact of link errors on the reliability of encryption parameter transmission.

[0054] In a third aspect, a communication device is provided, comprising a communication unit and a processing unit. The communication device may be the first communication device described above, or the second communication device described above. The communication device may implement any of the first to second aspects described above, and any implementation of any aspect. The communication unit is configured to perform functions related to sending and receiving. Optionally, the communication unit includes a receiving unit and a sending unit. In one design, the communication device is a communication chip, the processing unit may be one or more processors or processor cores, and the communication unit may be an input / output circuit or port of the communication chip.

[0055] In another design, the communication unit may be a transmitter and a receiver, or the communication unit may be a transmitter and a receiver.

[0056] Optionally, the communication device further includes modules that can be used to execute any one of the first to second aspects above, and any implementation of any one of the aspects.

[0057] In a fourth aspect, a communication device is provided, comprising a processor and a memory. The communication device may be the first communication device described above or the second communication device described above. Optionally, the device further comprises a transceiver, the memory being configured to store a computer program or instruction, and the processor being configured to retrieve and execute the computer program or instruction from the memory. When the processor executes the computer program or instruction in the memory, the communication device executes any one of the first and second aspects described above, as well as any implementation of any one of the aspects.

[0058] Optionally, there are one or more processors and one or more memories.

[0059] Optionally, the memory may be integrated with the processor, or the memory may be provided separately from the processor.

[0060] Optionally, the transceiver may include a transmitter (transmitter) and a receiver (receiver).

[0061] In a fifth aspect, a communication device is provided, comprising a processor. The communication device may be the first communication device described above, or the second communication device described above. The processor is coupled to a memory and may be configured to execute any of the first and second aspects, as well as any implementation manner of any aspect. The communication device may be the first communication device described above, or the second communication device described above. Optionally, the communication device further comprises a memory. Optionally, the communication device further comprises a communication interface, and the processor is coupled to the communication interface.

[0062] In one implementation, when the communication device is the first communication device, the communication interface may be a transceiver, or an input / output interface. Alternatively, the transceiver may be a transceiver circuit. Alternatively, the input / output interface may be an input / output circuit.

[0063] In another implementation, when the communication device is a chip or chip system of the first communication device, the communication interface may be an input / output interface, interface circuit, output circuit, input circuit, pin, or related circuit on the chip or chip system. The processor may also be embodied as a processing circuit or a logic circuit.

[0064] In one implementation, when the communication device is a second communication device, the communication interface may be a transceiver, or an input / output interface. Alternatively, the transceiver may be a transceiver circuit. Alternatively, the input / output interface may be an input / output circuit.

[0065] In another implementation, when the communication device is a chip or chip system of a second communication device, the communication interface may be an input / output interface, interface circuit, output circuit, input circuit, pin, or related circuit on the chip or chip system. The processor may also be embodied as a processing circuit or a logic circuit.

[0066] In a sixth aspect, a system is provided, which includes the above-mentioned first communication device and second communication device.

[0067] In the seventh aspect, a computer program product is provided, which includes: a computer program (also referred to as code, or instructions), which, when run, enables a computer to execute any one of the above-mentioned first to second aspects, and any implementation of any aspect.

[0068] In an eighth aspect, a computer-readable storage medium is provided, which stores a computer program (also referred to as code, or instructions) which, when run on a computer, enables the computer to execute any one of the above-mentioned first to second aspects, and any implementation of any one of the aspects.

[0069] In the ninth aspect, a chip system is provided, which may include a processor. The processor is coupled to a memory and can be used to perform any of the first to second aspects above, and any embodiment of any aspect. Optionally, the chip system also includes a memory. The memory is used to store a computer program (also referred to as code, or instructions). The processor is used to call and run the computer program from the memory, so that the device equipped with the chip system performs any of the first to second aspects, and any embodiment of any aspect.

[0070] In a tenth aspect, a processing device is provided, comprising: an interface circuit and a processing circuit. The interface circuit may include an input circuit and an output circuit. The processing circuit is configured to receive signals via the input circuit and transmit signals via the output circuit, thereby implementing any of the first and second aspects, and any implementation scheme of any of the aspects.

[0071] In a specific implementation, the processing device may be a chip, the input circuit may be an input pin, the output circuit may be an output pin, and the processing circuit may be a transistor, a gate circuit, a trigger, or various logic circuits. The input signal received by the input circuit may be, for example, but not limited to, received and input by a receiver, and the signal output by the output circuit may be, for example, but not limited to, output to and transmitted by a transmitter. The input circuit and the output circuit may be the same circuit, which functions as an input circuit and an output circuit at different times. This application does not limit the specific implementation of the processor and various circuits.

[0072] In another implementation, the communication device may be a component of the first communication device, such as an integrated circuit product such as a system-on-chip (SoC) or a communication chip. The interface circuit may be an input / output interface, interface circuit, output circuit, input circuit, pin, or related circuit on the chip or chip system. The processing circuit may be a logic circuit on the chip.

[0073] In another implementation, the communication device may be a component of a second communication device, such as an integrated circuit product such as a system-on-chip (SoC) or a communication chip. The interface circuit may be an input / output interface, interface circuit, output circuit, input circuit, pin, or related circuit on the chip or chip system. The processing circuit may be a logic circuit on the chip. BRIEF DESCRIPTION OF THE DRAWINGS

[0074] Figure 1 This is a schematic diagram of a two-layer encrypted data structure;

[0075] Figure 2a A schematic diagram of a system architecture provided in an embodiment of the present application;

[0076] Figure 2b A schematic diagram of another system architecture provided in an embodiment of the present application;

[0077] Figure 2c It is an OSI reference model architecture;

[0078] Figure 2d A schematic diagram of the architecture of a communication device provided in an embodiment of the present application;

[0079] Figure 2e A schematic diagram of a data processing flow at a transmitting end and a receiving end provided in an embodiment of the present application;

[0080] Figure 3a A schematic diagram of the AM format for each logical channel in a 100Gbps FEC-free system architecture provided in an embodiment of the present application;

[0081] Figure 3b A schematic diagram of the AM format for each logical channel in 100Gbps provided in an embodiment of the present application;

[0082] Figure 4a A flowchart of a data transmission method provided in an embodiment of the present application;

[0083] Figure 4b A flowchart of another data transmission method provided in an embodiment of the present application;

[0084] Figure 5a Provided in the embodiments of this application Figure 3aSchematic diagram of the bits in AM that can be used to carry encryption parameter information;

[0085] Figure 5b A schematic diagram of the structure of a multiframe of encryption parameter information carried in a first ciphertext data stream provided in an embodiment of the present application;

[0086] Figure 6 A flowchart of another data transmission method provided in an embodiment of the present application;

[0087] Figure 7 A schematic diagram illustrating the average time to loss of lock and the average time to lock in four situations is provided for an embodiment of the present application;

[0088] Figure 8 A schematic diagram of the architecture of another communication device provided in an embodiment of the present application;

[0089] Figure 9 A schematic diagram of the architecture of another communication device provided in an embodiment of the present application;

[0090] Figure 10 A schematic diagram of the architecture of another communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0091] Let's combine Figure 1 Introducing an encryption scheme, Figure 1 A schematic diagram of a two-layer encrypted data structure is shown as an example. Figure 1 As shown, the encryption side uses a key (Key) and an initialization vector (IV) to encrypt each data frame separately. The encryption side can use the locally pre-configured key (Key) and initialization vector to encrypt the unencrypted data (unencrypted data can also be called plain data (PlainData)) of a data frame in the figure to obtain encrypted data, which can also be called ciphertext data (EncryptedData). In order to prevent data from being tampered with by attackers during transmission, the encryption side usually also generates a check value, such as an integrity check value (ICV). When the encryption side sends a message, it carries the ciphertext data, security tag (SecTAG) and ICV generated during the encryption process in the message, where SecTAG contains the key identification (Key Identification) and IV identification (IV Identification).

[0092] After receiving the data frame, the decryption side decrypts it using the key corresponding to the key identifier and the IV corresponding to the IV identifier. After decryption, the ciphertext data becomes plaintext data. To determine whether the data has been tampered with during transmission, the decryption side calculates an ICV. The decryption is considered valid only if this ICV matches the ICV carried in the data frame; otherwise, the decryption is invalid.

[0093] Encryption technologies based on protocols such as MACsec are implemented above the MAC layer, encrypting and decrypting individual user frames. Using MACsec-based encryption technology to encrypt each user frame at the MAC layer requires encryption parameters to be carried within each frame. When the encryption parameters are at least 28 bytes (IV 12 bytes, ICV 16 bytes) and the average frame length is 64 bytes, the encryption parameters consume 43% (28 / 64 = 43%) of the user traffic bandwidth, which is a significant cost. Therefore, embodiments of the present application provide a data transmission solution that eliminates the need for encryption parameters to consume user traffic bandwidth. The embodiments of the present application are further described below with reference to the accompanying figures.

[0094] Figure 2a A schematic diagram of a system architecture provided by an embodiment of the present application is shown as an example. Figure 2a As shown, the system architecture includes a first communication device and a second communication device. Any of the first and second communication devices can be a network device or a chip set inside the network device. The device can be a network device that supports high-speed Ethernet interfaces (such as 200G, 400G). The device includes but is not limited to: optical modules, core routers, Internet Protocol Radio Access Network (IPRAN)-based radio access networks, packet transport networks (PTN) box-type or frame-type switch devices. The optical module can be, for example, a module including an optical digital signal processor (oDSP) chip.

[0095] In an embodiment of the present application, a first communication device obtains a first ciphertext data stream and sends the first ciphertext data stream. For example, the first ciphertext data stream can be sent to a second communication device. The first ciphertext data stream includes a first alignment identifier AM and an encrypted first data segment; the first AM is used for data alignment of the first ciphertext data stream. The first AM includes at least one of a first identification field or a first check field. Some or all bits in the first identification field carry first information; the first information is used to indicate the channel identifier of the first ciphertext data stream and is used to lock the AM of the first ciphertext data stream. Some bits in the first identification field and / or some or all bits in the first check field are used to carry: encryption parameter information of the first data segment. The second communication device obtains the first ciphertext data stream, decrypts the encrypted first data segment according to the encryption parameter information carried by the first AM in the first ciphertext data stream, and obtains the first plaintext data stream.

[0096] This application transmits encryption parameter information through bits in the first AM in the data stream, and does not add additional bits for transmitting encryption parameter information. Therefore, the transmission of encryption parameter information does not occupy user service bandwidth, thereby reducing the degree to which encryption parameters occupy user bandwidth. On the other hand, because this application encrypts the data stream (or bit stream) in the physical layer for transmission, all bits in the Ethernet frame (including the source MAC address and destination MAC address) can be encrypted, thereby improving security.

[0097] In the embodiments of the present application, the first communication device may also be referred to as a transmitting end, an encryption end, a source end, a transmitting device, a transmitting side, a transmitting end side, etc., and the second communication device may also be referred to as a receiving end, a decryption end, a destination end, a receiving device, a receiving side, a receiving end side, etc., and the embodiments of the present application do not impose specific restrictions. In the embodiments of the present application, the relevant schemes of the transmitting end may refer to the schemes on the first communication device side, and the schemes of the receiving end may refer to the schemes on the second communication device side.

[0098] Figure 2b Another system architecture diagram provided in an embodiment of the present application is exemplarily shown, where the system architecture includes multiple devices, such as device 1, device 2, device 3, and device 4. Figure 2a The first communication device and the second communication device in the embodiment may be Figure 2b Any two communication devices in Figure 2b In the embodiment of the present application, data transmission can be bidirectional, for example, the data transmission direction can be from Figure 2bThe data can be transmitted from device 1 to device 4, or from device 4 to device 1. For example, the first communication device is device 1, and the second communication device is device 2. For another example, the first communication device is device 2, and the second communication device is device 3. For another example, the first communication device is device 3, and the second communication device is device 4.

[0099] It should be noted that when device 1 sends data to device 2, device 2 can execute the receiving side solution. When device 2 sends data to device 3, device 2 can also execute the sending side solution. In other words, in the embodiment of the present application, a device can execute both the sending side solution and the receiving side solution. Among them, the sending side solution of the device can refer to the solution on the first communication device side, and the receiving side solution can refer to the solution on the second communication device side. Figure 2b In the example, the first communication device is device 2 and the second communication device is device 3.

[0100] Figure 2c An OSI reference model architecture is exemplified. The OSI reference model architecture is a network interconnection model that defines a seven-layer framework for network interconnection, which, from bottom to top, are the physical layer, data link layer, network layer, transport layer, session layer, presentation layer, and application layer.

[0101] Ethernet is located at the data link layer and physical layer in the OSI reference model. Figure 2c As shown, the data link layer includes two sublayers: the logical link control (LLC) sublayer (also called the LLC layer) and the medium access control (MAC) sublayer (also called the MAC layer) responsible for parsing and assembling Ethernet frames.

[0102] like Figure 2c As shown in FIG, the physical layer may include a physical medium dependent sublayer (PMD) (also called a PMD layer), a physical medium attachment sublayer (PMA) (also called a PMA layer), and a physical coding sublayer (PCS) (also called a PCS layer). A reconciliation sublayer (RS) (also called an RS layer) is also included between the PCS layer and the MAC layer.

[0103] Figure 2cThe figure also shows the medium connected to the PMD, which can be a cable, a pluggable optical module, or an optical fiber.

[0104] It should be noted that the MACsec technology used in the prior art is specifically deployed above the MAC sublayer in the data link layer. The encryption and decryption objects are Ethernet frames (or user frames). However, the solution provided in the embodiments of the present application is deployed at the physical layer, and the encryption and decryption objects can be a data segment of a logical channel.

[0105] It should be noted that Figure 2c The OSI reference model architecture provided by the embodiment of the present application does not include forward error correction (FEC) (also referred to as an FEC layer). The embodiment of the present application can be applied to a system architecture without an FEC layer.

[0106] Figure 2d The schematic diagram of the architecture of a communication device provided by an embodiment of the present application is exemplarily shown. The embodiment of the present application can be applied to an optical module that supports Ethernet connection. Figure 2d The communication device is illustrated as an optical module, and Figure 2d The figure shows possible deployment locations of the embodiment of the present application when deployed on an optical module.

[0107] like Figure 2d As shown, the optical module may include a bit multiplexer or demultiplexer (BitMux), an oDSP, a micro-controller unit (MCU), and an optoelectronic transceiver device (including a transmitter (TX) / receiver (RX).

[0108] Among them, the microcontroller unit (MCU) in the optical module can be responsible for configuring the parameters of each functional module. For example, the MCU can be used to configure the initialization parameters required for encryption and decryption in the embodiments of the present application, including starting or pausing the encryption and decryption functions, configuring the upper-layer negotiated keys and other key information.

[0109] like Figure 2d As shown in the figure, BitMux mainly converts the signal stream of the input channel to the output channel in a bit-interleaved manner. When BitMux is deployed at the physical layer, it is used to convert between N logical channels and M physical channels, for example, converting the signal stream of 20 logical channels to 4 physical channels.

[0110] When a BitMux is deployed in an optical module, it is used to convert signals from M physical channels into K digital signals. For example, it can convert the signal streams of four physical channels into two digital signals. Figure 2d The communication device architecture can split the BitMUX between the M physical channels (M is a positive integer) and the K channels (K is a positive integer) within the oDSP into two, namely M:N and N:K bitMUXs, where N is the number of logical channels and N is a positive integer. Then, encryption and decryption and corresponding functional modules are introduced between the two BitMUXs. In the embodiment of the present application, the encryption and / or decryption side solutions of the embodiment of the present application are introduced between the two bitMUXs, and other functional components within the module are not aware of them.

[0111] Figure 2d The optical module shown in should be able to implement the receiving end solution. Figure 2a Taking device 2 in the example, when the optical module implements the receiving end solution, it can receive the optical signal from device 1 via optical fiber. In this example, the solution implemented by device 2 can refer to the solution on the second communication device side, and the solution implemented by device 1 can refer to the solution on the first communication device side. The optical signal is converted by the receiver and processed by the oDSP algorithm (such as dispersion compensation), and then the digital signal is output to the BitMux. The BitMux then converts the digital signal output by the oDSP into N logical channel signals, and converts the N logical channel signals into M physical channel signals for transmission to the electrical chip in the physical layer. It should be noted that the aforementioned physical channel signals and logical channel signals are digital signals.

[0112] Figure 2d The optical module shown in should also be able to perform the transmitter solution. Figure 2a Taking device 2 in the example, when the optical module executes the transmitter solution, the BitMux converts the M physical channel signals input into the optical module into N logical channel signals. These N logical channel signals are then converted into K physical channel signals, which are then input into the oDSP's digital signals. The oDSP is responsible for performing algorithmic processing (such as dispersion compensation preprocessing) on ​​the input digital signals, which are then processed by the transmitter in the optoelectronic transceiver and transmitted via optical fiber to device 3. In this example, the solution implemented by device 2 can refer to the solution implemented by the first communication device, and the solution implemented by device 3 can refer to the solution implemented by the second communication device.

[0113] refer to Figure 2e , is a schematic diagram of a data processing flow at a transmitting end and a receiving end provided in an embodiment of the present application. It should be noted that the embodiment of the present application is illustrated by taking a non-FEC channel as an example, so the logical channel in the embodiment of the present application refers to the logical channel of the PCS layer.

[0114] Take the system architecture without FEC channel at 100Gbps transmission rate as an example Figure 2e For illustration, this example takes the number of physical channels as 4 and the number of logical channels of the PCS layer as 20. In practical applications, the number of physical channels may also be other values, such as 4, etc., and this embodiment of the application does not limit this.

[0115] Figure 2e The transmitter receives a data stream, which is processed by the MAC and RS layers before entering the PCS layer. The PCS layer encodes the data stream to produce a 64 / 66B block stream (this block stream can also be encoded in other formats; 64 / 66B is used as an example here). After scrambling, the block stream is then distributed. Block distribution of this scrambled block stream generates 20 block streams corresponding to 20 PCS channels (also called PCS logical channels), with one PCS channel corresponding to one block stream. Furthermore, the transmitter can perform AM insertion on these 20 block streams, periodically inserting AM into the block stream corresponding to each of the 20 PCS channels. After the PCS layer converts one serial data stream into 20 parallel block streams corresponding to the 20 PCS channels, the transmitter can input these 20 block streams into the PMA layer.

[0116] Furthermore, at the transmitter, the PMA uses the built-in bitMux to convert the 20 code block streams corresponding to the 20 PCS channels into four physical channels at a 20:4 ratio, resulting in code block streams corresponding to the four physical channels. These code block streams are then transmitted through the PMD and media as electrical or optical signals.

[0117] like Figure 2e As shown, for the transmitting end, the encryption scheme can be implemented by the physical layer chip after obtaining the data streams corresponding to multiple PCS channels through the PMA and before restoring the serial stream, or by the optical module (medium) when processing the received data stream.

[0118] like Figure 2e As shown in the figure, the receiving end can process the 4 code block streams corresponding to the 4 received physical channels at the PMD, and then input the 4 processed code block streams into the PMA layer. At the PMA layer, the 4 code block streams corresponding to the 4 physical channels will be converted into 20 PCF channels at a ratio of 4:20, thereby obtaining 20 code block streams corresponding to the 20 PCF channels, and the 20 code block streams will be input into the PCS layer.

[0119] Furthermore, the receiving end performs lane block alignment, alignment lock, lane deskew, and lane reordering on the 20 parallel code block streams at the PCS layer to obtain a 64 / 66B string of code block streams. AM removal is performed on this serial code block stream to remove the AM in the serial code block stream. The serial code block stream with AM removed is descrambled and decoded to restore a serial data stream. Furthermore, the receiving end processes this serial data stream in the RS layer and MAC layer in sequence to restore the original service data stream sent by the transmitter.

[0120] like Figure 2e As shown, for the receiving end, the decryption scheme can be implemented by the physical layer chip after obtaining the data streams corresponding to multiple PCS channels through the PMA and before restoring the serial stream, or by the optical module (medium) when processing the received data stream.

[0121] The following first explains some concepts or the relationships between concepts that appear in the embodiments of the present application.

[0122] (1) Plaintext data stream.

[0123] In the embodiment of the present application, N plaintext data streams refer to N unencrypted data streams. Take one of the N plaintext data streams as an example for illustration. For the sake of distinction, one of the N plaintext data streams is referred to as the first plaintext data stream, where N is a positive integer.

[0124] The first plaintext data stream includes at least two AMs and at least one unencrypted data segment. For purposes of distinction, the AMs in the first plaintext data stream are referred to as second AMs, and the at least one data segment in the first plaintext data stream is referred to as a first data segment. The unencrypted first data segment may also be referred to as a plaintext data segment or a plaintext first data segment. The at least two second AMs are used to align data in the N plaintext data streams.

[0125] Therein, a plaintext data segment may be included between every two second AMs, and a second AM may be included between every two plaintext data segments.

[0126] As an implementation method, the second AM in the first plaintext data stream can be periodically inserted. The second AM and the unencrypted first data segment in the first plaintext data stream can appear periodically. Each period can include one second AM and one plaintext data segment.

[0127] (2) Ciphertext data stream.

[0128] In the embodiment of the present application, N ciphertext data streams refer to N encrypted data streams. Take one of the N ciphertext data streams as an example for illustration. For the sake of distinction, one of the N ciphertext data streams is referred to as the first ciphertext data stream.

[0129] The first ciphertext data stream includes at least two AMs and at least one encrypted data segment. For the sake of distinction, the aligned data unit in the first ciphertext data stream is referred to as the first AM. The data segment in the first ciphertext data stream is the encrypted data segment, which can also be referred to as the ciphertext data segment.

[0130] The first ciphertext data stream includes at least two AMs and at least one encrypted data segment. For purposes of distinction, the AMs in the first ciphertext data stream are referred to as first AMs, and the at least one encrypted data segment in the first ciphertext data stream is referred to as an encrypted first data segment. The encrypted first data segment may also be referred to as a ciphertext data segment or a ciphertext first data segment. The at least two first AMs are used to align data in the N-way ciphertext data stream.

[0131] (3) The relationship between plaintext data stream and ciphertext data stream.

[0132] In the embodiment of the present application, N plaintext data streams are encrypted to obtain N ciphertext data streams. The N plaintext data streams correspond one to one with the N ciphertext data streams.

[0133] For example, the first plaintext data stream in N plaintext data streams corresponds to the first ciphertext data stream in N ciphertext data streams. Encrypting the unencrypted first data segment in the first plaintext data stream yields the encrypted first data segment in the first ciphertext data stream. Processing the second AM in the first plaintext data stream yields the first AM corresponding to the second AM in the first ciphertext data stream.

[0134] In the embodiment of the present application, the processing of the second AM in the first plaintext data stream may include operations such as adding encryption parameter information to the second AM.

[0135] (4)Logical channel.

[0136] In the embodiments of the present application, a logical lane is also referred to as a virtual lane. For example, it can be a PCS lane. The PCS distributes serial streams to multiple lanes, which are generally distributed within the implementation unit. To distinguish them from PAM lanes, they are generally referred to as logical lanes or virtual lanes. For example, in the Ethernet specification, in a system architecture without Reed-Solomon forward error correction (RS-FEC) codes, the number of logical lanes corresponding to 100 Gbps is 20.

[0137] The embodiment of the present application can be applied to the system architecture without FEC layer. The system architecture without FEC layer can refer to the aforementioned Figure 2e , I will not go into details here.

[0138] (5) Physical channel.

[0139] In the embodiment of the present application, a physical lane may be a PMA lane. A physical lane may carry data from one or more logical lanes. In Ethernet networks of different speeds, the number of physical lanes may vary depending on the implementation.

[0140] (6) First AM and second AM.

[0141] When data streams are transmitted on different logical channels, the receiving end can align multiple logical channels based on AM (such as the first AM or the second AM mentioned above). The AM in the embodiment of the present application is a bit or multiple consecutive bits that carry information including data alignment information of N-way plaintext data streams. The information carried on an AM may refer to the information carried on the bits included in the AM. The IEEE 802.3 specification designs an alignment marker (AM). In addition to the AM designed for existing specifications, the AM mentioned in the embodiment of the present application can also be a bit or multiple consecutive bits defined in other future specifications or other forms that carry data alignment information of N-way plaintext data streams.

[0142] When the sending end sends a serial stream to N logical channels, it periodically inserts an AM into each logical channel (for example, the second AM in the first plaintext data stream).

[0143] The receiving end obtains the data streams in N logical channels (for example, N encrypted data streams) and can lock the channels according to the AM of each logical channel (for example, the first AM in the first encrypted data stream) so as to merge the data streams in the N logical channels and restore the aforementioned serial stream.

[0144] Figure 3aThe following is a schematic diagram showing the format of AM on a logical channel with a transmission rate of 100 gigabits per second (Gbps) in a system architecture without an FEC layer, as shown in FIG. Figure 3a As shown, an AM may include 8 fields, namely, M0 field, M1 field, M2 field, BIP3 field, ~M0 field, ~M1 field, ~M2 field and ~BIP3 field, wherein each field may include 8 bytes.

[0145] like Figure 3a As shown in Figure 1, the information carried by AM can be divided into two categories: identification information and check information. The M0, M1, M2, ~M0, ~M1, and ~M2 fields carry identification information, while the BIP3 and ~BIP3 fields carry check information, such as the bit interleaving parity (BIP) value.

[0146] Based on this, all fields included in an AM can be divided into two fields: an identification field and a check field.

[0147] The identification field of an AM may include the AM's M0 field, M1 field, M2 field, ~M0 field, ~M1 field, and ~M2 field. It should be noted that an AM may be said to include an identification field. For clearer identification in the figure, an identification field of an AM is marked as two parts in the figure: one part is the M0 field, M1 field, and M2 field, and the other part is the ~M0 field, ~M1 field, and ~M2 field.

[0148] The checksum field of an AM can include a BIP3 field and a ~BIP3 field. It should be noted that an AM can be said to include a checksum field. For clearer identification in the figure, the checksum field of an AM is marked as two parts in the figure: one part is the BIP3 field, and the other part is the ~BIP3 field.

[0149] Figure 3b The following example shows the specific values ​​of each field of AM in 20 logical channels with a transmission rate of 100 Gbps in a system architecture without an FEC layer. Figure 3b It can be seen from the figure that the AMs of any two logical channels are different, which can also be understood as the value of at least one bit in the AMs of any two logical channels being different.

[0150] In the embodiment of the present application, the information carried by the identification field (M0 field, M1 field, M2 field, ~M0 field, ~M1 field and ~M2 field) of an AM has two functions, one is used to lock the AM, and the other is to identify the channel identification of the AM.

[0151] In the embodiment of the present application, the encryption parameter information for encrypting the first plaintext data stream can be transmitted through the AM. That is to say, the AM in the first ciphertext data stream is obtained by adding the encryption parameter information to the AM in the first plaintext data stream. In the embodiment of the present application, for the sake of distinction, the AM in the first ciphertext data stream is referred to as the first AM, and the AM in the first plaintext data stream is referred to as the second AM. In the embodiment of the present application, if a first AM corresponds to a second AM, it can be understood that the first AM is obtained by processing the second AM (such as adding encryption parameter information). In the embodiment of the present application, for the sake of distinction, the identification field in the first AM is referred to as the first identification field, and the identification field in the second AM is referred to as the second identification field. The identification field in the first AM is referred to as the first check field, and the identification field in the second AM is referred to as the second check field.

[0152] by Figure 3a The AM shown is the second AM for example. Figure 3a As shown, the second identification field of the second AM is used to carry the second information. The second information is used to indicate the channel identification of the first plaintext data stream and is used to lock the AM of the first plaintext data stream. In other words, the second information has two functions, which can be used to perform AM locking and also to identify the channel identification. Figure 3a As shown, the second check field is used to carry check information.

[0153] (7) Encryption parameters.

[0154] In the embodiment of the present application, the encryption parameter information may be deployed in one or more AMs. It can also be understood that the encryption parameter information may be carried in one AM included in one AM cycle, or in multiple AMs included in multiple AM ​​cycles.

[0155] In one possible implementation, the encryption parameter can be used to encrypt data segments within the AM period in which the encryption parameter is located. In another possible implementation, the encryption parameter can be used to encrypt data segments within other AM periods (except the AM period in which the encryption parameter is located).

[0156] The encryption parameters in the embodiments of the present application may include a key identifier and an initialization vector identifier. The key identifier indicates the encryption key used to encrypt the data segment. The IV identifier indicates the initialization vector used to encrypt the data segment.

[0157] Based on the above, Figure 4aThe following is an exemplary flow chart of a data transmission method provided by an embodiment of the present application. The method can be executed by the first communication device and the second communication device or by modules or chips within the first communication device and the second communication device. For the relevant introduction of the first communication device and the second communication device, please refer to the above content and will not be repeated here. Figure 4a As shown, the method includes:

[0158] S401: Obtain a first ciphertext data stream.

[0159] The first ciphertext data stream includes a first alignment marker AM and an encrypted first data segment; the first AM is used for data alignment of the first ciphertext data stream. The first AM includes at least one of a first identification field and a first checksum field. Some or all bits in the first identification field carry first information. The first information is used to indicate a channel identifier for the first ciphertext data stream and is used to lock the AM of the first ciphertext data stream. Some bits in the first identification field and / or some or all bits in the first checksum field are used to carry encryption parameter information for the first data segment.

[0160] S402: The first communication device sends a first ciphertext data stream to the second communication device.

[0161] S403: The second communication device obtains the first ciphertext data stream.

[0162] S404: The second communication device decrypts the encrypted first data segment according to the encryption parameter information carried by the first AM in the first ciphertext data stream to obtain the unencrypted first data segment in the first plaintext data stream.

[0163] After S404, S405 may also be included:

[0164] S405: The second communication device processes the first AM in the first ciphertext data stream to obtain a second AM in the first plaintext data stream.

[0165] In S401, the first communication device can obtain N ciphertext data streams, where N is a positive integer. Correspondingly, in S402, the first communication device can send N ciphertext data streams. In S403, the second communication device can obtain N ciphertext data streams. In S404 and S405, the second communication device can restore the N ciphertext data streams into N plaintext data streams. Among them, the first ciphertext data stream is one ciphertext data stream among the N ciphertext data streams. The first plaintext data stream is one plaintext data stream among the N plaintext data streams. The first ciphertext data stream corresponds to the first plaintext data stream. In the embodiment of the present application, each ciphertext data stream among the N ciphertext data streams can be encrypted and decrypted separately, and the encryption parameters of any two ciphertext data streams can be unrelated. In the embodiment of the present application, N can be a positive integer greater than 1. The processing method of other ciphertext data streams among the N ciphertext data streams can refer to the processing method of the first ciphertext data stream and will not be repeated here.

[0166] The present application transmits the encryption parameter information through the bits in the existing aligned data units in the data stream, and does not add additional bits for transmitting the encryption parameter information. Therefore, the transmission of the encryption parameter information does not occupy the user service bandwidth.

[0167] On the other hand, since the present application encrypts the data stream (or bit stream) in the physical layer for transmission, all bits in the Ethernet frame (including the source MAC address and the destination MAC address) can be encrypted, thereby improving security.

[0168] In this embodiment of the present application, encryption parameters for each logical channel can be transmitted separately. This means that the encryption and decryption processes for each logical channel are independent of each other. The encryption parameters for a data stream transmitted by a logical channel can be extracted independently from that data stream, and the data stream for that logical channel can be decrypted. Furthermore, because the second communication device processes the first AM and restores it to the second AM in the first plaintext data stream, the solution of this embodiment of the present application has essentially no impact on the upper-layer MAC.

[0169] In one possible implementation of the first communication device acquiring N ciphertext data streams in S401, the first communication device may acquire N plaintext data streams and obtain the N ciphertext data streams based on encryption parameters corresponding to data segments in the N plaintext data streams.

[0170] The N plaintext data streams correspond one-to-one to the N ciphertext data streams. The first plaintext data stream is one of the N plaintext data streams. The first ciphertext data stream is the ciphertext data stream corresponding to the first plaintext data stream in the N ciphertext data streams. The first plaintext data stream includes at least two second AMs and at least one unencrypted first data segment. The at least two second AMs are used for data alignment of the N plaintext data streams.

[0171] Figure 4b The following is a flow chart of another data transmission method provided in an embodiment of the present application. Figure 4b In the description, the first communication device is taken as an optical module or a module or unit in an optical module as an example.

[0172] like Figure 4b As shown, the first communication device obtains M physical channel signals and converts them into N logical channel signals (such as logical channel 0 to logical channel N-1) via BitMux (A) in the BitMux according to a set ratio (e.g., M:N). The first communication device searches for the AM within each logical channel and locks it within a specified interval (the AM interval can be different for different Ethernet MAC / PHY rates).

[0173] The N logical channel signals include plaintext data and can also be referred to as N plaintext data streams. For one of the N plaintext data streams (e.g., the first plaintext data stream), the MCU can encrypt the unencrypted first data segment in the first plaintext data stream to obtain the encrypted first data segment in the first ciphertext data stream. Furthermore, encryption parameter information can be inserted into the second AM in the first plaintext data stream to obtain the second AM in the first ciphertext data stream. Furthermore, the N ciphertext data streams are converted by BitMux (B) in the BitMux into K digital signals that can be input to the oDSP.

[0174] In the embodiment of the present application, the MCU can configure and update the encryption parameter information required by the encryption module. The encryption parameter information includes encryption key parameters, such as the initialization vector IV and the key identifier. Optionally, corresponding functional modules such as the AM locking module and the encryption / decryption module can also be deployed in the BitMux of the first communication device. Specifically, the AM locking module and the encryption / decryption module can be deployed separately for each logical channel. Among them, for each plaintext data stream corresponding to each logical channel, the AM locking module can be used to insert the encryption parameter information into the AM in the plaintext data stream, and the encryption / decryption module can be used to encrypt (Encryption) the plaintext data stream based on the encryption parameters to obtain a ciphertext data stream. Specifically, the MCU can configure the IV at the first startup, and the encryption / decryption module will automatically update the IV according to the set rules. The MCU configures and modifies the key identifier. The AM locking module can be responsible for locking the AM in the logical channel and using the locked AM to carry the latest encryption parameters.

[0175] In the embodiment of the present application, the second AM in the first plaintext data stream can be processed to obtain the first AM in the first ciphertext data stream. Specifically, the first communication device can carry at least one of the partial bits in the second identification field of the second AM, or partial or all bits in the second check field: encryption parameter information of at least one first data segment (can also be understood as part or all of the encryption parameter information of at least one first data segment), thereby obtaining the first AM in the first ciphertext data stream. It can also be understood that there are two fields in the second AM that can be used to carry encryption parameter information. The two fields are introduced separately below.

[0176] (1) The second identification field and the first identification field.

[0177] In the embodiments of this application, the second AM in the first plaintext data stream and the first AM in the first ciphertext data stream are used as examples. The first AM is obtained by processing the second AM (for example, by adding encryption parameter information to the second AM). In other words, the first AM corresponds to the second AM.

[0178] When the first identification field of the first AM does not carry encryption parameter information, that is, the first identification field is used to carry information for AM locking and channel identification, the information carried by the second identification field is the same as the information carried by the first identification field.

[0179] When the first identification field of the first AM carries part or all of the encryption parameter information, in one possible implementation, the information carried by the first identification field is obtained by replacing the information carried by some bits in the second identification field with part or all of the encryption parameter information.

[0180] The structural form of the second AM in the embodiment of this application can be referred to the aforementioned Figure 3a and Figure 3b Related descriptions, such as Figure 3a As shown, the second identification field can be Figure 3a The identification field in the first plaintext data stream may specifically be an M0 field, an M1 field, an M2 field, a ~M0 field, a ~M1 field, and a ~M2 field. The second identification field is used to carry second information. The second information is used to indicate the channel identifier of the first plaintext data stream and is used for AM locking of the first plaintext data stream.

[0181] The first identification field in the first AM obtained by processing the second AM may specifically be the M0 field, the M1 field, the M2 field, the ~M0 field, the ~M1 field, and the ~M2 field. The bits in the first identification field that may be used to carry encryption parameter information may be some of the bits in the following fields: the M0 field, the M1 field, the M2 field, the ~M0 field, the ~M1 field, and the ~M2 field.

[0182] In the embodiment of the present application, 16 bits are used from the first identification field to carry encryption parameter information. Furthermore, the receiving end can lock the AM according to the corresponding matching rules, thereby minimizing the impact on the AM's locking performance and minimizing the impact on the recognition of the channel identification information.

[0183] In one possible implementation, the bit in the first identification field used to carry the encryption parameter information is one of the following:

[0184] 8 bits of the M0 field, and bits in the 8 bits of the ~M0 field;

[0185] M1 field 8 bits, and bits in the ~M1 field 8 bits; or,

[0186] The M2 field is 8 bits, and the bits in the 8 bits of the M2 field are ~.

[0187] Figure 5a An example is shown Figure 3a A schematic diagram of the bits in the AM that can be used to carry encryption parameter information, such as Figure 5a As shown, the bits in the first identification field used to carry the encryption parameter information may be the 8 bits of the M1 field, and part or all of the 8 bits of the M1 field.

[0188] In another possible implementation, in order to ensure 0 / 1 balance, for at least two first AMs that carry part or all of the encryption parameter information of at least one first data segment: the information belonging to the encryption parameter information carried by the first AM is divided into two parts, namely the first part of information and the second part of information, and the second part of information is obtained by inverting the bit value corresponding to the first part of information.

[0189] There are many possible ways to distribute the first part of information and the second part of information. In one possible implementation, the first communication device can carry a portion of the original encryption parameter information and the inverted information of the original encryption parameter information in each field of the identification field and the verification information field. For example, the information belonging to the encryption parameter information carried in the first identification field is divided into two parts, namely the third part of information and the fourth part of information, and the fourth part of information is information obtained by inverting the bit values ​​corresponding to the third part of information.

[0190] like Figure 5aAs shown, the 8 bits of the M1 field can be used to carry the 8 bits of information in the original encryption parameter information, and the 8 bits of the ~M1 field can carry the inverted value of the 8 bits of the M1 field. For example, if the value of the 0th bit in the 8 bits of the M1 field is 0, then the value of the 0th bit in the 8 bits of the ~M1 field is 1. For another example, if the value of the 0th bit in the 8 bits of the M1 field is 1, then the value of the 0th bit in the 8 bits of the ~M1 field is 0.

[0191] Figure 5a The above is just an example. There are many possible implementation methods for placing the original encryption parameter information and the inverted information of the original encryption parameter. For example, a part of the original encryption parameter information can be carried in the 8 bits of the M1 field and the first 4 bits of the ~M1 field, and then the inverted value of all the bit values ​​of the 8 bits of the M1 field and the first 4 bits of the ~M1 field are carried in the ~BIP3 field and the last 4 bits of the ~M1 field.

[0192] On the other hand, in the above S405, when the second communication device is processing the second AM, if some bits in the first identification field carry encryption parameter information, the second communication device can restore the value of the bit that carries the encryption parameter information in the first identification field to the preset value in S405. The preset value is the value carried by the corresponding bit (such as 8 bits of the M1 field and 8 bits of the ~M1 field) in the second identification field of the second AM corresponding to the first AM. The preset value can also be understood as the original value specified by the protocol, such as the above Figure 3b The M1 field in the AM in the logical channel shown in is 8 bits, and the value carried by the 8 bits of the M1 field.

[0193] (2) The second check field and the first check field.

[0194] The second check field is used to carry verification information of the first plaintext data stream. When the first check field of the first AM does not carry encryption parameter information, that is, the first check field is used to carry verification information (such as BIP information), the information carried by the second check field is the same as the information carried by the first check field.

[0195] When the first check field of the first AM carries part or all of the encrypted parameter information, in one possible implementation, the information carried by the first check field is obtained by replacing the information carried by some bits in the second check field with part or all of the encrypted parameter information.

[0196] Below Figure 3a and Figure 3b For example, the first plaintext data stream is Figure 3b The data stream corresponding to a logical channel (such as logical channel 0) in the second AM is as follows: Figure 3b The values ​​corresponding to logical channel 0 are shown in the figure.

[0197] like Figure 3a As shown, the second check field can be Figure 3a The check field in may specifically be a BIP3 field and a ~BIP3 field.

[0198] The bits used to carry encryption parameter information in the first check field of the first AM obtained by processing the second AM are part or all of the bits of the following fields: the BIP3 field or the ~BIP3 field. Figure 5a In the example, the bits used to carry the encryption parameter information in the first check field are part or all of the bits in the ~BIP3 field. For example, the bits used to carry the encryption parameter information in the first check field may include the first 4 bits of the ~BIP3 field and the bits in the last 4 bits of the ~BIP3 field.

[0199] In another possible implementation, in order to ensure 0 / 1 balance, the information belonging to the encryption parameter information carried in the first check field is divided into two parts, namely the fifth part of information and the sixth part of information, and the fifth part of information is obtained by inverting the bit value corresponding to the sixth part of information.

[0200] like Figure 5a As shown, the first 4 bits of the ~BIP3 field can be used to carry the 4 bits of information in the original encryption parameter information, while the last 4 bits of the ~BIP3 field can carry the value of the inverted first 4 bits of the M1 field. For example, if the value of the 0th bit in the first 4 bits of the ~BIP3 field is 0, then the value of the 0th bit in the last 4 bits of the ~BIP3 field can be 1. For another example, if the value of the 0th bit in the first 4 bits of the ~BIP3 field is 1, then the value of the 0th bit in the last 4 bits of the ~BIP3 field is 0. Figure 5a The above is only an example, and there are many possible implementations for placing the original encryption parameter information and the information after the original encryption parameter information is inverted.

[0201] On the other hand, in the above-mentioned S405, when the second communication device is processing the second AM, if the first check field carries encryption parameter information, the second communication device can restore the value of the bit that carries the encryption parameter information in the first check field in S405. For example, based on the first check information (BIP3 field) carried in the first check field, the information on the bits (~8 bits of the BIP3 field) used to carry the encryption parameter information in the first check field is restored to the information after the bit value corresponding to the first check information (the bit value of the 8 bits of the BIP3 field) is inverted. It can be seen that in the embodiment of the present application, the content of the first check field can be restored to its original value without identifying the logical channel identifier of the first ciphertext data stream.

[0202] Figure 5b The schematic diagram of the structure of the multi-frame of the encryption parameter information carried in the first ciphertext data stream provided by the embodiment of the present application is shown as follows: Figure 5b As shown, the first ciphertext data stream includes multiple first AM sets. For one first AM set, the first AM set may include L first AMs, where L is a positive integer. Figure 5b In the example shown, each first AM has 24 bits that can be used to carry encryption parameter information, of which 12 bits can carry the original encryption parameter information, and the remaining 12 bits are used to carry the inverse of the bit value of the original encryption parameter information carried in the first AM. Based on this, 12 bits of encryption parameter information can be placed in one first AM.

[0203] like Figure 5b As shown, the multiframe may include item 3 and item 5 of the following content. In a possible implementation manner, the multiframe may further include one or more of the other items (except items 3 and 5) in the following content.

[0204] (1) Multiframe start identification information: The multiframe start identification information is used to indicate the start bit of the multiframe that carries encryption parameter information.

[0205] For example, a two-bit value of "10" can be used to indicate the start of a multiframe, repeated six times, occupying 12 bits. The remaining 12 bits in the first AM can be the inverse of the value of the occupied 12 bits. For example, the 8-bit binary value of M1 in the first AM used to carry the multiframe start identification information is "10101010"; the 8-bit binary value of ~M1 in the first AM is "01010101". The first 4 bits of the ~BIP field of the first identification field in the first AM are "1010", and the last 4 bits of the ~BIP field are "0101".

[0206] (2) Multiframe lock status identification information. The multiframe lock status identification information is used to indicate whether the multiframes of the transmitter and / or receiver are locked. For example, if the start identification information of two consecutive multiframes matches a predefined pattern (i.e., "10"), it indicates that the multiframe is locked. If the start identification information of three consecutive multiframes does not match the predefined pattern (i.e., "10"), it indicates that the multiframe is not locked.

[0207] The first communication device may select the next AM after the first AM carrying the multiframe start identifier information, and use two bits on this first AM to indicate the multiframe lock status of the transmitting and / or receiving end. For example, 01 indicates that the local multiframe is not locked; 11 indicates that the local multiframe is locked and waiting for the remote multiframe to be locked; and 10 indicates that the local multiframe is locked and the remote multiframe is locked.

[0208] (3) Key identification.

[0209] The first communication device may select the next first AM after the first AM that carries the multiframe start identifier information, and use two bits with values ​​of "10" and "01" on the first AM to represent the key identifier. A change in the key identifier from "10" to "01" or from "01" to "10" indicates that a new encryption key will be used in the next multiframe period.

[0210] (4) Reserved bit.

[0211] To be compatible with future technologies, a certain number of reserved bits may be set aside to carry other information.

[0212] (5) Initialization vector identifier.

[0213] In this embodiment, the IV length is 12 bytes, so the IV occupies the first 8 AMs in 8 (12*8 / 12=8) AM cycles.

[0214] In the embodiment of the present application, there may be multiple encryption algorithms for the first data, for example, Advanced Encryption Standard Galois / Counter Mode (AES-GCM) may be selected.

[0215] (6) Error correction information of encrypted parameter information.

[0216] The error correction information for the encryption parameter information can be an RS-FEC code. The RS-FEC code is well-suited for dealing with sudden bit errors and can effectively mitigate the impact of link errors on the reliability of encryption parameter transmission. For example, the error correction information can be an RS-FEC code (RS-FEC(57, 33, 12, 2^8)), which is defined over the finite field GF(2^8). Each symbol is 8 bits, where 33 is the length of the data symbol. By adding 24 check symbols, a codeword of length 57 symbols is formed, which can correct any 12 symbols within the codeword. Under a random channel model, for a bit error rate of 2.4e-04, the error probability of this codeword is extremely low, and the error time meets the cosmic-year reliability requirement. Therefore, using the RS-FEC code to correct the information in the multiframe of the encryption parameter information can ensure cosmic-year reliability and effectively mitigate the impact of link errors on the reliability of encryption parameter transmission.

[0217] The encryption parameter information can also be corrected using BCH codes, which are an abbreviation of Bose, Ray-Chaudhuri, and Hocquenghem. BCH codes are also mature error-correcting codes that can effectively handle random errors and mitigate the impact of link errors on the reliability of encryption parameter transmission.

[0218] In one possible implementation, after S403 and before S404, the second communication device may obtain error correction information for the encryption parameter information in the first ciphertext data stream and, based on the error correction information for the encryption parameter information, perform error correction on other information in the encryption parameter information. This effectively mitigates the impact of link errors on the reliability of encryption parameter transmission.

[0219] Since encryption and decryption are implemented at the physical layer in the embodiment of the present application, MAC / PHY internal mechanisms such as AM alignment locking, scrambling, transcoding, and FCS checking can resist tampering, so integrity protection is not required. Therefore, the encryption parameter information in the embodiment of the present application may not include an integrity check value (ICV), thereby reducing the delay and power consumption overhead caused by calculating the ICV.

[0220] It should be noted that the encryption parameter information carried in the first AM set may be the encryption parameter information of the first data segment included in the first AM set, or the encryption parameter information of the first data segment included in other first AM sets. For example, the encryption parameter information carried in the first AM set is the encryption parameter information of the first data segment included in the next first AM set.

[0221] Figure 6 The following is a flow chart of another data transmission method provided in an embodiment of the present application. Figure 4bThe second communication device is an optical module or a module or unit in the optical module as an example. The decryption solution in the embodiment of the present application can be specifically deployed in the BitMux of the optical module, and the MCU can control the decryption of data during the process of converting multiple logical channel signals in the BitMux.

[0222] like Figure 6 As shown, the optical signal received by the second communication device is recovered into K digital signals via the oDSP. The BitMux (B) in the BitMux can convert the K digital signals into N ciphertext data streams. The second communication device can then perform AM searches on each of the N ciphertext data streams and lock the AM within a specified interval (different Ethernet MAC / PHY rates have different AM intervals). The second communication device decrypts the data segments in the ciphertext data stream and recovers the values ​​of the bits carrying encryption parameter information in the second AM in the ciphertext data stream (for example, recovering them to the second AM in the plaintext data stream), resulting in N plaintext data streams. The channel identification information of each of the N plaintext data streams is then identified based on the second AM in the N plaintext data streams.

[0223] For example, the AM locking module deployed in a BitMux can be used to lock N ciphertext data streams, and the encryption / decryption module deployed in the BitMux can be used to decrypt the N ciphertext data streams, resulting in N plaintext data streams. These N plaintext data streams are also called N logical channel signals (such as logical channel 0 to logical channel N-1 in the figure). The BitMux (A) in the BitMux can restore the N logical channel signals into M physical channel signals (such as physical channel 0 to physical channel M-1 in the figure) according to a set ratio, such as M:N. The optical module then transmits the M physical channel signals to the electrical chip at the physical layer.

[0224] After S403 and before S404, the second communication device may also perform AM locking on the first ciphertext data stream. In one possible implementation, upon determining that at least k consecutive first AMs exist in the first ciphertext data stream and satisfy a preset rule, the second communication device determines to perform AM locking on the first ciphertext data stream based on the at least k first AMs. k is an integer greater than 1, for example, k may be 2.

[0225] Among them, the first AM among at least k first AMs satisfies the preset rules, including: when the information carried by some bits in the first identification field of the first AM includes part or all of the encryption parameter information: the bits in the information carried by the first identification field except those belonging to the encryption parameter information completely match the preset AM lock information.

[0226] The preset AM locking information in the embodiment of the present application may refer to the information used for AM locking in the AM specified in the protocol, such as Figure 3b The information carried by the identification field in the logical channels 0 to 19 shown in FIG.

[0227] Since the first identification field in the first plaintext data stream includes 48 bits, one matching rule is: when the 48 bits completely match the preset AM lock information, the AM is considered to match. However, since some bits in the second identification field are used to carry encryption parameter information in the embodiment of the present application, for example, 16 bits are used to carry encryption parameter information, and 32 bits are left to carry AM lock information, the embodiment of the present application proposes another AM matching rule, that is, when the information carried by the first identification field, excluding the information belonging to the encryption parameter information (32 bits), completely matches the preset AM lock information, the AM is considered to match. If two consecutive AMs match, it is considered that AM lock is completed.

[0228] Furthermore, the second communication device can also identify the channel identification information corresponding to the first AM based on the bits other than the encryption parameter information in the information carried by the first identification field in the first AM. For example, if the 8 bits of the M1 field and the 8 bits of the ~M1 field of the first identification field carry the encryption parameter information, the second communication device can identify the channel identification information corresponding to the first AM based on the bits other than the encryption parameter information in the information carried by the first identification field in the first AM. Figure 3b The 32 bits of the corresponding positions in the 20 AMs in the first identification field are compared, and when it is determined that the 32 bits of the information carried by the first identification field except the encryption parameter information are the same as Figure 3b If the AM matches the AM of a certain logical channel in the , for example, it is completely consistent with the 32 bits of logical channel 0 (8 bits of the M0 field, 8 bits of the M2 field, 8 bits of the ~M0 field and 8 bits of the ~M23 field of logical channel 0, a total of 32 bits), then it is determined that the AM meets the preset rules. If k consecutive AMs meet the preset rules, the AM is locked and the channel identifier indicated by the AM is identified as logical channel 0.

[0229] The following further describes the embodiments of the present application through simulation results. Figure 7 The following diagrams illustrate the mean time to loss of alignment (MTTLA) and the mean time to alignment (MTTA) under two circumstances. The five circumstances are:

[0230] Case a0: The 48 bits of the first identification field are used to carry the second information. The AM matching rule is: when it is determined that the 48 bits of the first identification field match the preset AM locking information, the first AM is determined to be matched.

[0231] Case a1: 16 of the 48 bits in the first identification field are used to carry encryption parameter information, and the remaining 32 bits are used to carry first information. This first information indicates the channel identifier of the first ciphertext data stream and is used for AM lock of the first ciphertext data stream. The AM match rule is: if the 32-bit first information in the first identification field, excluding the encryption parameter information, completely matches the preset AM lock information, then the first AM match is determined.

[0232] Table 1 below exemplifies a false locking performance evaluation table.

[0233] Table 1 False lock performance evaluation table

[0234]

[0235] From the above content, we can see that when the bit error rate is 2×10 -9 In the case of , we can see that in terms of false lock probability, lock time and lock loss time, the performance of case a0 and case a1 is equivalent. Therefore, occupying the 16 bits in the first identification field to carry encryption parameter information has almost no impact on the AM locking performance.

[0236] It is understood that in order to implement the functions in the above embodiments, the communication device includes hardware structures and / or software modules corresponding to the execution of each function. It should be readily apparent to those skilled in the art that, in combination with the units and method steps of each example described in the embodiments disclosed in this application, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in hardware or in a manner driven by computer software depends on the specific application scenario and design constraints of the technical solution.

[0237] Figure 8 、 Figure 9 and Figure 10 Schematic diagram of the structure of possible communication devices provided for embodiments of the present application. These communication devices can be used to implement the functions of the first communication device in the above method embodiment, and thus can also achieve the beneficial effects possessed by the above method embodiment. These communication devices can also be used to implement the functions of the second communication device in the above method embodiment, and thus can also achieve the beneficial effects possessed by the above method embodiment. In the embodiments of the present application, the communication device can be as follows Figure 2a 、 Figure 2b Figure 2c 、 Figure 2d and Figure 2eThe transmitting end device or the first communication device in the embodiment of the present application may also be a module (such as a chip) applied to the transmitting end device or the first communication device. Figure 2a 、 Figure 2b Figure 2c 、 Figure 2d and Figure 2e The receiving device or the second communication device may also be a module (such as a chip) applied to the receiving device or the second communication device.

[0238] like Figure 8 As shown, the communication device 1300 includes a processing unit 1310 and a transceiver unit 1320. The communication device 1300 is used to implement the above Figure 4a The functions of the first communication device in the method embodiment are shown.

[0239] When the communication device 1300 is used to implement Figure 4a The function of the first communication device in the method embodiment shown is: the processing unit 1310 is used to execute through the transceiver unit 1320: obtain the first ciphertext data stream, and send the first ciphertext data stream. The first ciphertext data stream includes a first alignment identifier AM and an encrypted first data segment; the first AM is used for data alignment of the first ciphertext data stream. The first AM includes at least one of the first identification field or the first check field; some or all bits in the first identification field carry the first information; the first information is used to indicate the channel identification of the first ciphertext data stream and is used for AM locking of the first ciphertext data stream. Some bits in the first identification field, and / or some or all bits in the first check field are used to carry: encryption parameter information of the first data segment.

[0240] like Figure 8 As shown, the communication device 1300 includes a processing unit 1310 and a transceiver unit 1320. The communication device 1300 is used to implement the above Figure 4a The functions of the second communication device in the method embodiment are shown.

[0241] When the communication device 1300 is used to implement Figure 4aIn the method embodiment shown, the function of the second communication device is as follows: the processing unit 1310 is used to execute, through the transceiver unit 1320: obtaining a first ciphertext data stream, decrypting the encrypted first data segment according to the encryption parameter information carried by the first AM in the first ciphertext data stream, and obtaining a first plaintext data stream. The first ciphertext data stream includes a first alignment identifier AM and an encrypted first data segment; the first AM is used for data alignment of the first ciphertext data stream; the first AM includes at least one of a first identification field and a first check field; some or all bits in the first identification field carry first information; the first information is used to indicate the channel identifier of the first ciphertext data stream and is used to lock the AM of the first ciphertext data stream; some bits in the first identification field and / or some or all bits in the first check field are used to carry: encryption parameter information of the first data segment.

[0242] When the communication device 1300 is used to implement Figure 4a In the illustrated method embodiment, the second communication device functions as follows: the processing unit 1310 is further configured to execute, via the transceiver unit 1320, the following: if at least k consecutive first AMs exist in the first ciphertext data stream and satisfy a preset rule, determine that AM locking is completed for the first ciphertext data stream based on the at least k first AMs; k is an integer greater than 1. The relevant details of the preset rule can be found in the aforementioned content and are not further elaborated here.

[0243] When the communication device 1300 is used to implement Figure 4a In the illustrated method embodiment, the second communication device functions as follows: the processing unit 1310 is specifically configured to execute, via the transceiver unit 1320, decrypting the encrypted first data segment based on the encryption parameter information carried by the first AM in the first ciphertext data stream to obtain the unencrypted first data segment in the first plaintext data stream; and processing the first AM to obtain the second AM in the first plaintext data stream.

[0244] When the communication device 1300 is used to implement Figure 4a The function of the second communication device in the method embodiment shown is: the processing unit 1310 is specifically used to execute through the transceiver unit 1320: determine the channel identifier of the first ciphertext data stream based on the information carried by the first AM except the encryption parameter information.

[0245] When the communication device 1300 is used to implement Figure 4a The function of the second communication device in the method embodiment shown is: the processing unit 1310 is specifically used to execute through the transceiver unit 1320: restoring the information on the bit used to carry encryption parameter information in the first identification field to a preset value.

[0246] When the communication device 1300 is used to implement Figure 4aWhen the function of the second communication device in the method embodiment shown is: the processing unit 1310 is specifically used to execute through the transceiver unit 1320: based on the first verification information carried in the first verification field, the information on the bit used to carry the encryption parameter information in the first verification field is restored to the information after the bit value corresponding to the first verification information is inverted.

[0247] When the communication device 1300 is used to implement Figure 4a In the method embodiment shown, the second communication device functions as follows: the processing unit 1310 is further configured to execute, via the transceiver unit 1320, obtaining error correction information for the encryption parameter information in the first ciphertext data stream, and performing error correction on other information in the encryption parameter information based on the error correction information for the encryption parameter information.

[0248] For more detailed description of the processing unit 1310 and the transceiver unit 1320, please refer to Figure 4a The relevant description in the method embodiment shown is directly obtained and will not be repeated here.

[0249] like Figure 9 As shown, communication device 1400 includes a processing circuit 1410 and an interface circuit 1420. Processing circuit 1410 and interface circuit 1420 are coupled to each other. It is understood that interface circuit 1420 can be a transceiver or an input / output interface. Optionally, communication device 1400 may further include a memory for storing instructions executed by the processing circuit, input data required by processing circuit 1410 to execute instructions, or data generated after processing circuit 1410 executes instructions.

[0250] When the communication device 1400 is used to implement Figure 4a In the method shown, the processing circuit 1410 is used to implement the functions of the processing unit 1310, and the interface circuit 1420 is used to implement the functions of the transceiver unit 1320.

[0251] like Figure 10 As shown, communication device 1500 includes a processor 1510 and a communication interface 1520. Processor 1510 and communication interface 1520 are coupled to each other. It is understood that communication interface 1520 can be a transceiver or an input / output interface. Optionally, communication device 1500 may also include a memory 1530 for storing instructions executed by processor 1510, input data required by processor 1510 to execute instructions, or data generated after processor 1510 executes instructions.

[0252] When the communication device 1500 is used to implement Figure 4a When the method is shown, the processor 1510 is used to implement the functions of the processing unit 1310, and the communication interface 1520 is used to implement the functions of the transceiver unit 1320.

[0253] When the communication device 1500 is used to implement Figure 4a The function of the first communication device in the method embodiment shown is: the processor 1510 is used to execute through the communication interface 1520: obtaining the first ciphertext data stream, and sending the first ciphertext data stream. The first ciphertext data stream includes a first alignment identifier AM and an encrypted first data segment; the first AM is used for data alignment of the first ciphertext data stream. The first AM includes at least one of the first identification field or the first check field; some or all bits in the first identification field carry the first information; the first information is used to indicate the channel identification of the first ciphertext data stream and is used for AM locking of the first ciphertext data stream. Some bits in the first identification field, and / or some or all bits in the first check field are used to carry: encryption parameter information of the first data segment.

[0254] When the communication device 1500 is used to implement Figure 4a The function of the second communication device in the method embodiment shown is as follows: the processor 1510 is used to execute, through the communication interface 1520: obtaining a first ciphertext data stream, and decrypting the encrypted first data segment according to the encryption parameter information carried by the first AM in the first ciphertext data stream to obtain a first plaintext data stream. The first ciphertext data stream includes a first alignment identifier AM and an encrypted first data segment; the first AM is used for data alignment of the first ciphertext data stream; the first AM includes at least one of a first identification field and a first check field; some or all bits in the first identification field carry first information; the first information is used to indicate the channel identifier of the first ciphertext data stream and is used to lock the AM of the first ciphertext data stream; and some bits in the first identification field and / or some or all bits in the first check field are used to carry: encryption parameter information of the first data segment.

[0255] When the communication device is a chip used in a communication device, the communication device chip implements the functions of the communication device in the above method embodiments. The communication device chip receives information from other modules in the communication device (such as a radio frequency module or antenna), and the information is sent by the network device to the communication device; or the communication device chip sends information to other modules in the communication device (such as a radio frequency module or antenna), and the information is sent by the communication device to the network device.

[0256] It is understood that the processor in the embodiments of the present application may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.

[0257] According to the method provided in the embodiment of the present application, the present application also provides a computer program product, which includes: a computer program or instruction, which, when the computer program or instruction is run on a computer, causes the computer to execute Figure 4a A method according to any one of the embodiments shown.

[0258] According to the method provided in the embodiment of the present application, the present application also provides a computer-readable storage medium, which stores a program or instruction, which, when executed on a computer, causes the computer to execute Figure 4a A method according to any one of the embodiments shown.

[0259] According to the method provided in the embodiment of the present application, the present application also provides a chip system, which may include a processor. The processor is coupled to the memory and can be used to execute Figure 4a The method of any one of the embodiments shown. Optionally, the chip system also includes a memory. The memory is used to store computer programs (also called codes or instructions). The processor is used to call and run the computer program from the memory so that the device equipped with the chip system executes Figure 4a A method according to any one of the embodiments shown.

[0260] According to the method provided in the embodiment of the present application, the present application also provides a system, which includes the aforementioned first communication device and second communication device.

[0261] The method steps in the embodiments of the present application can be implemented by hardware or by a processor executing software instructions. The software instructions can be composed of corresponding software modules, which can be stored in random access memory (RAM), flash memory, read-only memory (ROM), programmable read-only memory, erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory, registers, hard disks, solid-state drives (SSDs), mobile hard disks, portable read-only memories (CD-ROMs), or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be an integral part of the processor. The processor and storage medium can be located in an ASIC. In addition, the ASIC can be located in a communication device. Of course, the processor and storage medium can also be present in the communication device as discrete components.

[0262] In the above embodiments, all or part of the embodiments may be implemented using software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments may be implemented in the form of a computer program product. A computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, all or part of the processes or functions of the embodiments of the present application are performed. The computer may be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, or other programmable device. The computer program or instructions may be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program or instructions may be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center that integrates one or more available media. The available media may be magnetic media, such as floppy disks, hard disks, or magnetic tapes; optical media, such as digital video disks; or semiconductor media, such as solid-state drives. The computer-readable storage medium may be a volatile or nonvolatile storage medium, or may include both volatile and nonvolatile types of storage media.

[0263] In the various embodiments of the present application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.

[0264] In this application, "multiple" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. In the text description of this application, the character " / " generally indicates that the previous and next associated objects are in an "or" relationship; in the formula of this application, the character " / " indicates that the previous and next associated objects are in a "division" relationship. "Including at least one of A, B or C" can mean: including A; including B; including C; including A and B; including A and C; including B and C; including A, B and C.

[0265] It is understood that the various numbers used in the embodiments of this application are merely for ease of description and are not intended to limit the scope of the embodiments of this application. The order of the sequence numbers of the above-mentioned processes does not necessarily imply a specific order of execution; the order of execution of the processes should be determined by their functions and inherent logic.

Claims

1. A data transmission method, characterized in that: The method is applicable to a system architecture without a forward error correction (FEC) layer, and includes: Obtaining a first ciphertext data stream; Sending the first ciphertext data stream; The first ciphertext data stream includes a first alignment marker AM and an encrypted first data segment; the first AM is used for data alignment of the first ciphertext data stream; The first AM includes at least one of a first identification field and a first check field; the first identification field is used to indicate a channel identifier of the first ciphertext data stream and is used to lock the AM of the first ciphertext data stream; Part of the bits in the first identification field and / or part or all of the bits in the first check field are used to carry: encryption parameter information of the first data segment; The bits in the first identification field used to carry the encryption parameter information are some of the bits in the following fields: M0 field, M1 field, M2 field, ~M0 field, ~M1 field and ~M2 field.

2. The method according to claim 1, wherein The first ciphertext data stream is obtained according to the first plaintext data stream and the encryption parameter information; the first plaintext data stream includes the second AM and the unencrypted first data segment; The second AM is used for data alignment of the first plaintext data stream.

3. The method according to claim 2, wherein The first identification field is obtained by replacing some bits in the second identification field of the second AM with the encryption parameter information; and / or, The first check field is obtained by replacing some bits in the second check field of the second AM with the encryption parameter information.

4. The method according to any one of claims 1 to 3, wherein The bit in the first identification field used to carry the encryption parameter information is one of the following: 8 bits of the M0 field, and bits in the 8 bits of the ~M0 field; M1 field 8 bits, and bits in the ~M1 field 8 bits; or, The M2 field is 8 bits, and the bits in the 8 bits of the M2 field are ~.

5. The method according to any one of claims 1 to 4, characterized in that The bits in the first check field used to carry the encryption parameter information are part or all of the bits in the following fields: BIP3 field, or ~BIP3 field.

6. The method according to any one of claims 1 to 5, wherein: The encryption parameter information includes: error correction information of the encryption parameter information.

7. A data transmission method, characterized in that: The method is applicable to a system architecture without a forward error correction (FEC) layer, and includes: Obtain a first ciphertext data stream, wherein the first ciphertext data stream includes a first alignment identifier AM and an encrypted first data segment; the first AM is used for data alignment of the first ciphertext data stream; the first AM includes at least one of a first identification field or a first check field; the first identification field is used to indicate a channel identifier of the first ciphertext data stream and is used to lock the AM of the first ciphertext data stream; wherein some bits in the first identification field and / or some or all bits in the first check field are used to carry: encryption parameter information of the first data segment; the bits in the first identification field used to carry the encryption parameter information are some bits in the following fields: M0 field, M1 field, M2 field, ~M0 field, ~M1 field, and ~M2 field; The encrypted first data segment is decrypted according to the encryption parameter information to obtain a first plaintext data stream.

8. The method according to claim 7, wherein Before decrypting the encrypted first data segment, the method further includes: Performing AM locking on the first ciphertext data stream according to at least k consecutive first AMs in the first ciphertext data stream, where the at least k consecutive first AMs satisfy a preset rule; where k is an integer greater than 1; The preset rules include: In the case where the information carried by some bits in the first identification field of the first AM includes the encryption parameter information: the bits in the information carried by the first identification field except for the encryption parameter information completely match the preset AM locking information.

9. The method according to any one of claims 7 to 8, wherein The first ciphertext data stream is obtained according to the first plaintext data stream and the encryption parameter information; the first plaintext data stream includes the second AM and the unencrypted first data segment; The second AM is used for data alignment of the first plaintext data stream.

10. The method according to claim 9, wherein The first identification field is obtained by replacing some bits in the second identification field of the second AM with part or all of the encryption parameter information; and / or, The first check field is obtained by replacing some bits in the second check field of the second AM with part or all of the encryption parameter information.

11. The method according to any one of claims 7 to 10, wherein: The bit in the first identification field used to carry the encryption parameter information is one of the following: 8 bits of the M0 field, and bits in the 8 bits of the ~M0 field; M1 field 8 bits, and bits in the ~M1 field 8 bits; or, The M2 field is 8 bits, and the bits in the 8 bits of the M2 field are ~.

12. The method according to any one of claims 7 to 11, wherein: The bits in the first check field used to carry the encryption parameter information are part or all of the bits in the following fields: BIP3 field, or ~BIP3 field.

13. The method according to any one of claims 7 to 12, wherein: The encryption parameter information includes: error correction information of the encryption parameter information.

14. A communication device, characterized in that: The communication device is applicable to a system architecture without a forward error correction (FEC) layer. The communication device includes a processing unit and a transceiver unit. The processing unit is configured to execute, through the transceiver unit: Obtaining a first ciphertext data stream; Sending the first ciphertext data stream; The first ciphertext data stream includes a first alignment marker AM and an encrypted first data segment; the first AM is used for data alignment of the first ciphertext data stream; The first AM includes at least one of a first identification field and a first check field; the first identification field is used to indicate a channel identifier of the first ciphertext data stream and is used to lock the AM of the first ciphertext data stream; Part of the bits in the first identification field and / or part or all of the bits in the first check field are used to carry: encryption parameter information of the first data segment; The bits in the first identification field used to carry the encryption parameter information are some of the bits in the following fields: M0 field, M1 field, M2 field, ~M0 field, ~M1 field and ~M2 field.

15. The device according to claim 14, wherein The first ciphertext data stream is obtained according to the first plaintext data stream and the encryption parameter information; the first plaintext data stream includes the second AM and the unencrypted first data segment; The second AM is used for data alignment of the first plaintext data stream.

16. The device according to claim 15, characterized in that The first identification field is obtained by replacing some bits in the second identification field of the second AM with part or all of the encryption parameter information; and / or, The first check field is obtained by replacing some bits in the second check field of the second AM with part or all of the encryption parameter information.

17. The device according to any one of claims 14 to 16, characterized in that The bit in the first identification field used to carry the encryption parameter information is one of the following: 8 bits of the M0 field, and bits in the 8 bits of the ~M0 field; M1 field 8 bits, and bits in the ~M1 field 8 bits; or, The M2 field is 8 bits, and the bits in the 8 bits of the M2 field are ~.

18. The device according to any one of claims 14 to 17, characterized in that The bits in the first check field used to carry the encryption parameter information are part or all of the bits in the following fields: BIP3 field, or ~BIP3 field.

19. The device according to any one of claims 14 to 18, characterized in that The encryption parameter information includes: error correction information of the encryption parameter information.

20. A communication device, characterized in that: The communication device is applicable to a system architecture without a forward error correction (FEC) layer. The communication device includes a processing unit and a transceiver unit. The processing unit is configured to execute, through the transceiver unit: Obtain a first ciphertext data stream, wherein the first ciphertext data stream includes a first alignment identifier AM and an encrypted first data segment; the first AM is used for data alignment of the first ciphertext data stream; the first AM includes at least one of a first identification field or a first check field; the first identification field is used to indicate a channel identifier of the first ciphertext data stream and is used to lock the AM of the first ciphertext data stream; wherein some bits in the first identification field and / or some or all bits in the first check field are used to carry: encryption parameter information of the first data segment; the bits in the first identification field used to carry the encryption parameter information are some bits in the following fields: M0 field, M1 field, M2 field, ~M0 field, ~M1 field, and ~M2 field; The encrypted first data segment is decrypted according to the encryption parameter information to obtain a first plaintext data stream.

21. The device according to claim 20, characterized in that The processing unit is further configured to execute, through the transceiver unit: Performing AM locking on the first ciphertext data stream according to at least k consecutive first AMs in the first ciphertext data stream, where the at least k consecutive first AMs satisfy a preset rule; where k is an integer greater than 1; The preset rules include: In the case where the information carried by some bits in the first identification field of the first AM includes the encryption parameter information: the bits in the information carried by the first identification field except for the encryption parameter information completely match the preset AM locking information.

22. The device according to any one of claims 20-21, characterized in that The first ciphertext data stream is obtained according to the first plaintext data stream and the encryption parameter information; the first plaintext data stream includes the second AM and the unencrypted first data segment; The second AM is used for data alignment of the first plaintext data stream.

23. The device according to claim 22, wherein The second AM includes at least one of a second identification field or a second check field; The first identification field is obtained by replacing some bits in the second identification field with some or all bits in the encryption parameter information; And / or, the first check field is obtained by replacing some bits in the second check field with part or all of the encryption parameter information.

24. The device according to any one of claims 20 to 23, characterized in that The bit in the first identification field used to carry the encryption parameter information is one of the following: 8 bits of the M0 field, and bits in the 8 bits of the ~M0 field; M1 field 8 bits, and bits in the ~M1 field 8 bits; or, The M2 field is 8 bits, and the bits in the 8 bits of the M2 field are ~.

25. The device according to any one of claims 20 to 24, characterized in that The bits in the first check field used to carry the encryption parameter information are part or all of the bits in the following fields: BIP3 field, or ~BIP3 field.

26. The device according to any one of claims 20 to 25, characterized in that The encryption parameter information includes: error correction information of the encryption parameter information.

27. A communication device, characterized in that: The apparatus includes a processor coupled to a memory, The memory is used to store computer programs or instructions; The processor is configured to execute a computer program or instruction in a memory, so that the method according to any one of claims 1 to 6 is executed, or the method according to any one of claims 7 to 13 is executed.

28. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions, which, when called by a computer, enable the method described in any one of claims 1 to 6 to be executed, or enable the method described in any one of claims 7 to 13 to be executed.

29. A chip system, characterized in that: include: Communication interface, used for inputting and / or outputting signaling or data; A processor for executing a computer executable program so that a device equipped with the chip system executes the method described in any one of claims 1 to 6, or executes the method described in any one of claims 7 to 13.

Citation Information

Patent Citations

  • Security protection of terabit ethernet PCS layer using alignment markers

    US20190097748A1