Design method of optical transport network security slice payload encryption FPGA

By employing an FPGA design method based on advanced encryption standards in the OTN system, the encryption of the authentication tag in the OTN frame overhead and the frame payload is realized, solving the information security problem in the OTN communication link and enhancing the security and flexibility of OTN.

CN115914894BActive Publication Date: 2025-12-09THE 54TH RESEARCH INSTITUTE OF CHINA ELECTRONICS TECHNOLOGY GROUP CORPORATION
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211423152.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-15
Publication Date
2025-12-09
Estimated Expiration
2042-11-15

AI Technical Summary

Technical Problem

Information security issues in OTN communication links, especially eavesdropping and malicious data modification, are difficult to effectively address with existing technologies in OTN systems through encryption and decryption protection.

Method used

Employing an FPGA design approach based on advanced encryption standards, this method implements granular information of dynamically tuned slice channels, encryption and decryption processes within the frame architecture of the optical transport network, and utilizes the 100Gbit/s OTN encryption block diagram of the FPGA for information processing, including transceiver processing at the user-side and line-side interfaces, to achieve encryption of the authentication tag bearer and frame payload in the OTN frame overhead.

Benefits of technology

While retaining the advantages of OTN hard pipes and operation, management and maintenance, it provides finer time slot granularity and simple lossless bandwidth adjustment, realizing secure protection of the optical channel in OTN frames and enhancing the network's security performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115914894B_ABST
    Figure CN115914894B_ABST
Patent Text Reader

Abstract

The application discloses a design method of an optical transport network security slice payload encryption FPGA, and belongs to the technical field of optical communication. The method is realized by implementing the FPGA in a flexible packet enhanced packet transport network based on an advanced encryption standard, dynamically tuning the granularity information of a slice channel according to needs, and designing the FPGA by the correlation between the encryption overhead of continuous encryption packets and encrypted messages. An OTN structure processor is realized in the FPGA device. The OTN is an improvement of an OTN (OSSD-OTN) based on an optical service unit and aiming at the technical short board of a traditional OTN technology, and realizes 2M-100Gbps different granularity service bearing. In addition, a symmetric encryption and authentication mechanism is realized in the OSSD-OTN, and OTN signals are transmitted along a path into a backbone optical network. The encryption mechanism solves the important problem of optical channel information security in a slice OTN communication link, and meets the increasingly urgent needs of future optical networks for security performance.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of optical communication technology, in particular to a design method of optical transport network security slice payload encryption FPGA. BACKGROUND

[0002] With the increasing demand of Internet video and mobile data services, the transmission capacity of optical network is increasingly expanding, and the next generation 100G optical transport network (OTN) solution is urgently needed. When OTN is eavesdropped or attacked, data is destroyed, so that the legitimate party is unaware of the intrusion, and the intruder can detect data by eavesdropping one or more lines of a two-way communication channel. On the other hand, in the OTN system, the intruder can maliciously insert a regenerator module to detect traffic in the communication link, and as long as the intruder correctly updates the BIP-8 (bit interleaved parity- pure error detection scheme) value, the information content can be modified. The data terminal equipment will not find any modification of the OTN frame payload. In addition, the OTN based on optical service unit (OSU) (OSSD-OTN) is an improvement for the technical shortcomings of traditional OTN technology, which changes the characteristics of the traditional OTN time slot division frame structure, and adopts a more flexible payload block division method, which can realize 2M-100Gbps different granularity service bearing. SUMMARY

[0003] In view of the problems in the above background art, the present application provides a design method of optical transport network security slice payload encryption FPGA. The present application supports efficient bearing of 2M-100Gbps rate customer service, solves the important problem of information security in the OTN communication link, and enables the OTN to selectively encrypt / decrypt according to the actual network demand, and realizes the collaborative management of slice encryption and slice non-encryption through a simple and easy-to-implement algorithm.

[0004] The technical scheme of the present application is implemented as follows,

[0005] A design method of optical transport network security slice payload encryption FPGA, which realizes FPGA in a flexible packet enhanced packet transport network based on the advanced encryption standard, dynamically tunes the granularity information of the slice channel according to the needs, and designs FPGA through the correlation of the encryption overhead of the continuous encryption package and the encrypted message, and specifically includes the following processes:

[0006] There is a secure channel between nodes A and B of the optical transport network, and the two terminals exchange their keys through the secure channel;

[0007] The same password key is used to encrypt and decrypt the message according to the needs;

[0008] Load the encryption algorithm of the advanced encryption standard in the payload of the OSU of the frame architecture based on the optical transport network;

[0009] The frame architecture based on the optical transport network includes optical channel transmission unit overhead, optical path data unit overhead, optical path payload overhead and frame alignment signal, and through the frame architecture based on the optical transport network, the OTN bearing of different granularity services is realized.

[0010] The FPGA-based 100Gbit / s OTN encryption block diagram contains the transceivers in two directions of the user side interface and the line side interface and the transmitter and receiver processors;

[0011] The number of ports of the transceivers in two directions of the user side interface and the line side interface of the FPGA-based 100Gbit / s OTN encryption block diagram depends on the parallel processing of high-speed serial service streams;

[0012] The transmitter processing part of the FPGA-based 100Gbit / s OTN encryption block diagram includes that data from the 640-bit interface of the client is firstly processed by an optical transmission layer IP block, then passes through an FEC decoder, a frame receiver and is placed in a FIFO cache, recovered data is subjected to block operation of an OSU by a sending processor for encryption, then is framed and sent, is subjected to FEC encoding and passes through an OTL encoder and finally is output at the line interface;

[0013] The receiver processing part of the FPGA-based 100Gbit / s OTN encryption block diagram includes that data from the line side interface is firstly processed by an optical transmission layer IP block, then passes through an FEC decoder, a frame receiver and is placed in a FIFO cache, recovered data is subjected to block operation of an OSU by a receiving processor for decryption, then is framed and sent, is subjected to FEC encoding and passes through an OTL encoder and finally is output at the user interface.

[0014] Compared with the prior art, the application has the advantages that:

[0015] The application provides finer time slot granularity, a more concise bandwidth lossless adjustment mechanism and uses existing reserved bytes in the OTN frame overhead to bear authentication labels, realizes AES-based encryption in the frame payload and realizes the security protection of optical channels in the slice OTN while retaining the advantages of traditional OTN hard pipes and rich operation management and maintenance (OAM). BRIEF DESCRIPTION OF DRAWINGS

[0016] Figure 1 The application provides a 100G OTN encryption total scheme diagram.

[0017] Figure 2 The application provides an updated frame architecture diagram of 100G OTN based on slicing.

[0018] Figure 3 The application is based on 100G OTN slice encryption process schematic diagram. DETAILED DESCRIPTION

[0019] The application will be described in detail below with reference to the accompanying drawings and specific embodiments.

[0020] The application scenario of the OTN processor can be configured as a 100 Gigabit Ethernet (GbE) OTN transponder or an optical channel transmission unit (OTU4) OTN regenerator. The OTU4 OTN regenerator is for long-haul transmission applications and performs 3R regeneration of optical signals. The transponder is an application that transmits and recovers user-side data encryption to OTN frames. The 100Gbit / s OTN transponder has two different interfaces, the user side and the line side. Gigabit Ethernet data packets are transmitted from the Ethernet device to the user-side interface of the transponder at a speed of 100Gbit / s. At the user port, they are encapsulated into OTN frames and transmitted through the line to the OTU4 of the optical network.

[0021] Referring to Figure 1 , the communication nodes A and B use the same cryptographic key to encrypt and decrypt messages. The cryptographic system implementation premise is that there is a secure channel through which both terminals can exchange their keys. The encryption function f(x, k) receives two inputs: the plaintext message (x) to be transmitted and the secret key (k). The output of f(x, k) is the encrypted ciphertext message (y). Only by applying the decryption function f(y, k) to the encrypted message using the correct key (k) can the original message be recovered. The selected encryption function must make it difficult for an intruder to guess the key from the encrypted message, and the larger the size of the key (in bits) the longer it takes to crack it using other mathematical methods.

[0022] The Advanced Encryption Standard (AES) and the way it operates, proposed by Joan Daemen and Vincent Rijmen, is a widely accepted, widely used and worldwide standardized symmetric encryption algorithm, which is a data-iterative block encryption cipher using 128 / 192 / 256-bit keys. The OSSD OTN-based encryption method uses a 100G AES encryption machine solution, which is composed of many sub-blocks with special functions.

[0023] Reference Figure 2The frame structure of the OSSD OTN mainly consists of an optical channel transport unit overhead (OTU OH), an optical path data unit overhead (ODU OH), an optical path payload overhead (OPU OH), and a frame alignment signal (FAS). N represents the number of OSUflexes contained in a frame structure. A tributary port number (TPN) identifies the correspondence between a service and a port. The fixed-length frame structure of the OSUflex contains an AES-encrypted overhead and an AES-encrypted payload. Therefore, by performing encryption on the slices in the OSU, the flexibility of the services in the enhanced OTN is enhanced, and the security performance of the network is enhanced. Specifically, the AES encryption process is as follows: first, a key is added to the plaintext at the source end, the plaintext is grouped into sub-bytes, a row shift transformation and a mixed data column are performed, the key is added, key counting and multiplexing and final counting are performed after the key is added, and finally, ciphertext is generated. The ciphertext after transmission is sent to the destination end, and the ciphertext decoding control part is performed in the opposite direction of the source end. The control part mainly includes AES-encrypted overhead processing and key generation and negotiation.

[0024] With reference to Figure 3 The FPGA-based 100Gbit / s OTN processor and application mainly include transceivers in two directions of a user-side interface and a line-side interface, and transmitter and receiver processors. Due to high data rates and large logic circuit densities, the typical core clock frequency of the OTN is below 400 Mhz. Therefore, parallel processing of high-speed signals is required. The two 100Gbit / s client and line-side interfaces are composed of 10 channels with a rate of 10 Gbit / s. A 640-bit-wide data path is created by a SerDes (serialization / deserialization) IP block inside.

[0025] In the interface of the transmitting client, the transmission rate is a 100Gbit / s OTU4 signal received by 10 10Gbit / s channels. Each channel is processed by a SerDes device running on a 64-bit input / output bus at 174.70 MHz.

[0026] The data from the 640-bit interface of the client is first processed by an optical transport layer (OTL) IP block, then decoded by a forward error correction (FEC) decoder, a frame receiver, and placed in a first-in-first-out (FIFO) buffer. The recovered data is processed by the transmitting processor for OSU block operations (for encryption), then framed, FEC encoded, and encoded by the OTL encoder, and finally output on the line-side interface.

[0027] On the contrary, the decryption processor module is executed by the processor of the receiving end, specifically, the data from the line side interface is firstly processed by the optical transmission layer (OTL) IP block, then the FEC decoder, frame receiver, and placed in the FIFO buffer, the recovered data is operated by the block operation (for decryption) of the receiving end processor, then framed, FEC encoded and passed through the OTL encoder, and finally output at the user side interface.

[0028] The present application mainly aims at the encryption method verification implementation of the OSSD OTN. Since the latest FPGA can perform high-speed data transmission protocol verification, such as using operation, management and maintenance (OAM) function and embedded design, the flexibility and excellent performance can be provided for 100Gbit / s OTN traffic transmission, the present application provides an OTN structure processor implemented in the FPGA device, the structure processor implements the symmetric encryption and authentication mechanism, and the OTN signal is transmitted along the path into the backbone optical network. The existing OTN system adopts the AES encryption mechanism, but so far there is no FPGA real-time verification of AES in the OSSD-OTN. The present application reserves the advantages of the traditional OTN hard pipeline, rich operation management and maintenance (OAM) and the like, provides finer time slot granularity, more concise bandwidth lossless adjustment mechanism, and uses the existing reserved bytes in the OTN frame overhead to carry the authentication label; the encryption based on the AES is implemented in the frame payload, and the security protection of the optical channel in the sliced OTN is realized.

[0029] In summary, the present application realizes an FPGA implementation method of OTN security encryption, and the FPGA-based OTN security encryption method is realized through a simple and easy-to-implement algorithm. The present application reserves the advantages of the traditional OTN hard pipeline, rich operation management and maintenance (OAM) and the like, provides finer time slot granularity, more concise bandwidth lossless adjustment mechanism, and uses the existing reserved bytes in the OTN frame overhead to carry the authentication label; the encryption based on the AES is implemented in the frame payload, and the security protection of the optical channel in the sliced OTN is realized.

[0030] The above merely describes specific embodiments of the present application, but the protection scope of the present application is not limited thereto, any changes or replacements within the technical range disclosed by the present application can be easily thought by those skilled in the art, and should be covered within the protection scope of the present application.

Claims

1. A design method of an optical transport network security slice payload encryption FPGA, characterized in that, The implementation of FPGA in flexible packet enhanced packet transfer network based on advanced encryption standard, dynamically tuning the granularity information of slice channel, the design of FPGA through the correlation of encryption overhead of continuous encryption package and encrypted message, specifically including the following processes: There is a secure channel between node A and B of optical transport network, and the two terminals exchange their keys through the secure channel; The same password key is used for encryption and decryption of the message; The encryption algorithm of advanced encryption standard is loaded in the payload of OSU based on the frame architecture of optical transport network; The frame architecture based on optical transport network includes optical channel transmission unit overhead, optical path data unit overhead, optical path payload overhead and frame positioning signal, and carries different granularity services of OTN; 100Gbit / s OTN based on FPGA includes transceivers in two directions of user side interface and line side interface and transmitter and receiver processors; The number of ports of transceivers in two directions of user side interface and line side interface is determined based on the parallel processing of high-speed serial service flow; The transmitter processing part includes data from the client 640-bit interface, which is first processed by the optical transmission layer IP block, then by the FEC decoder, frame receiver and placed in the FIFO cache, the recovered data is processed by the OSU block operation of the sender processor for encryption, then framed and sent, FEC encoded and passed through the OTL encoder, and finally output at the line interface; The receiver processing part includes data from the line side interface, which is first processed by the optical transmission layer IP block, then by the FEC decoder, frame receiver and placed in the FIFO cache, the recovered data is processed by the OSU block operation of the receiver processor for decryption, then framed and sent, FEC encoded and passed through the OTL encoder, and finally output at the user interface.

Citation Information

Patent Citations

  • Timeslot encryption in an optical transport network

    CN104718720A

  • Encryption method and equipment and decryption method and equipment

    CN108075883A