Secure transmission method and device, optical module, storage medium and program product

By encrypting and decrypting the bitstream at the PCS layer of the optical module and carrying key information, the problem that traditional security mechanisms cannot cover the full range of fields and the time delay is solved, thus achieving high-security and low-latency data transmission.

CN121966903APending Publication Date: 2026-05-01CHINA MOBILE COMM LTD RES INST +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411709600.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-11-26
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

Traditional network security mechanisms such as IPSec and MACSec have problems in Ethernet computing network applications, such as inability to cover all fields, extended encryption and decryption processing time, and additional encapsulation overhead.

Method used

The PHYSec physical layer security mechanism is adopted to encrypt and decrypt the bit stream at the PCS layer of the optical module and carry key information in the padding field to achieve security protection for the Ethernet physical layer.

Benefits of technology

It achieves full field protection for the data link layer and network layer, masking traffic characteristics, providing extremely high security without adding extra encapsulation overhead, and reducing encryption and decryption latency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121966903A_ABST
    Figure CN121966903A_ABST
Patent Text Reader

Abstract

The invention discloses a secure transmission method and device, an optical module, a storage medium and a program product. The method comprises: obtaining a first bit stream from a first device, the first bit stream being a plaintext bit stream, the first bit stream being obtained by the first device processing an Ethernet media access control (MAC) frame through a physical layer; encrypting the first bit stream by using a first key through a PCS layer to obtain a second bit stream, wherein the second bit stream is a ciphertext bit stream; and carrying key information related to the first key through a filling field in front of the second bit stream by the PCS layer; and sending the second bit stream through an optical link.
Need to check novelty before this filing date? Find Prior Art

Description

Secure transmission methods and devices, optical modules, storage media, and software products Technical Field

[0001] This application relates to the field of data transmission technology, and in particular to a secure transmission method and apparatus, optical module, storage medium, and program product. Background Technology

[0002] Computing power networks, including Ethernet application scenarios such as intelligent computing center networks, intelligent connected vehicle networks, and the Industrial Internet, involve the secure transmission of sensitive data and have high requirements for link security protection. However, there are uncontrollable environments on the user network side, posing risks of data leakage and tampering. On the computing network side, the input path is long, increasing the risk of data leakage. On the inter-computing network side, inter-computing links are susceptible to physical eavesdropping. Frequent data exchange between nodes within the intelligent computing center also poses a risk of data leakage. Figure 1 illustrates an Ethernet application scenario for a computing power network, involving terminals, access networks, edge computing power, and wide area networks. In this Ethernet application scenario, data also faces risks of leakage and tampering.

[0003] Traditional network security mechanisms, such as Media Access Control (MAC) security (MACSec) and IP security (IPSec), can provide security protection for data at different network layers. However, when traditional network security mechanisms (such as IPSec and MACSec) are applied to Ethernet application scenarios in computing networks, there are problems such as inability to cover all fields, extended encryption and decryption processing time, and additional encapsulation overhead. Summary of the Invention

[0004] To address the aforementioned technical problems, embodiments of this application provide a secure transmission method and apparatus, an optical module, a storage medium, and a program product.

[0005] The secure transmission method provided in this application embodiment is applied to a first optical module, and the method includes:

[0006] A first bit stream is obtained from a first device. The first bit stream is a plaintext bit stream. The first bit stream is obtained by the first device through physical layer processing of Ethernet MAC frames.

[0007] The first bitstream is encrypted using a first key through a Physical Coding Sublayer (PCS) to obtain a second bitstream, which is a ciphertext bitstream; and key information related to the first key is carried in a padding field before the second bitstream by the PCS layer.

[0008] The second bit stream is transmitted via an optical link.

[0009] The secure transmission method provided in this application embodiment is applied to a second optical module, and the method includes:

[0010] The second bit stream is received via an optical link; the second bit stream is a ciphertext bit stream.

[0011] The key information is extracted from the padding field before the second bitstream through the PCS layer, and a first key is determined based on the key information; and the second bitstream is decrypted using the first key through the PCS layer to obtain a first bitstream, wherein the first bitstream is a plaintext bitstream.

[0012] The first bit stream is sent to the second device, and the first bit stream is used by the second device to obtain an Ethernet MAC frame through physical layer processing.

[0013] The secure transmission device provided in this application embodiment is applied to a first optical module, and the device includes:

[0014] The acquisition unit is used to acquire a first bit stream from the first device. The first bit stream is a plaintext bit stream, and the first bit stream is obtained by the first device performing physical layer processing on Ethernet MAC frames.

[0015] The processing unit is configured to encrypt the first bit stream using a first key through a PCS layer to obtain a second bit stream, the second bit stream being a ciphertext bit stream; and to carry key information related to the first key through a padding field before the second bit stream by the PCS layer.

[0016] The transmitting unit is used to transmit the second bit stream via an optical link.

[0017] The secure transmission device provided in this application embodiment is applied to a second optical module, and the device includes:

[0018] The receiving unit is used to receive a second bit stream, which is a ciphertext bit stream, via an optical link;

[0019] The processing unit is configured to extract key information from the padding field preceding the second bitstream through the PCS layer, determine a first key based on the key information, and decrypt the second bitstream using the first key through the PCS layer to obtain a first bitstream, wherein the first bitstream is a plaintext bitstream.

[0020] The sending unit is used to send the first bit stream to the second device, wherein the first bit stream is used by the second device to obtain an Ethernet MAC frame through physical layer processing.

[0021] The optical module provided in this application includes a DSP, which is used to call a computer program to execute any of the above-described secure transmission methods.

[0022] The computer-readable storage medium provided in this application embodiment is used to store a computer program that causes a computer to execute any of the above-described secure transmission methods.

[0023] The computer program product provided in this application includes computer program instructions that cause a computer to execute any of the above-described secure transmission methods.

[0024] The technical solution of this application provides a security protection technology operating at the Ethernet physical layer. It uses an optical module to encrypt and decrypt the physical layer bitstream at the PCS layer and carries key information in the padding field. Since the Ethernet frame header of the data link layer and the IP header of the network layer are both part of the payload of the physical layer bitstream, the technical solution of this application can protect all fields of the upper-layer protocols (i.e., security protection can cover all fields), resulting in extremely high security. Furthermore, since the encryption and decryption processing is performed on the physical layer bitstream, the encryption and decryption processing latency is short, and it does not introduce additional encapsulation overhead. In addition, the padding field provides key information for the receiving end to decrypt the bitstream, ensuring the effective implementation of the encryption and decryption process. Attached Figure Description

[0025] Figure 1 is a schematic diagram of an Ethernet application scenario for a computing power network;

[0026] Figure 2 is a flowchart illustrating the secure transmission method provided in an embodiment of this application.

[0027] Figure 3 is a schematic diagram of the PCS frame structure of the 400ZR optical module provided in the embodiment of this application;

[0028] Figure 4 is a schematic diagram of the PCS frame overhead of the 400ZR optical module provided in the embodiment of this application;

[0029] Figure 5 is a schematic flowchart of the secure transmission method provided in an embodiment of this application.

[0030] Figure 6 is a schematic diagram of the overall framework provided in an embodiment of this application;

[0031] Figure 7 is a schematic diagram of the PHYSec data encryption and decryption process provided in an embodiment of this application;

[0032] Figure 8 is a data processing flow of the PCS layer of the optical module provided in an embodiment of this application;

[0033] Figure 9 is a schematic diagram of the structural composition of the secure transmission device provided in an embodiment of this application;

[0034] Figure 10 is a schematic diagram of the structural composition of the secure transmission device provided in an embodiment of this application;

[0035] Figure 11 is a schematic structural diagram of an optical module provided in an embodiment of this application;

[0036] Figure 12 is a schematic structural diagram of a chip according to an embodiment of this application. Detailed Implementation

[0037] The technical solutions of the embodiments of this application will now be described with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0038] In the following description, references are made to “some embodiments,” which describe a subset of all possible embodiments. However, it is understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.

[0039] It should also be noted that the terms "first, second, and third" used in the embodiments of this application are only used to distinguish similar objects and do not represent a specific order of objects. It is understood that "first, second, and third" can be interchanged in a specific order or sequence where permitted, so that the embodiments of this application described herein can be implemented in an order other than that illustrated or described herein.

[0040] In this document, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this document generally indicates that the preceding and following related objects have an "or" relationship. It should also be understood that the term "correspondence" mentioned in the embodiments of this application can indicate a direct or indirect correspondence between two objects, or it can indicate an association between them.

[0041] To facilitate understanding of the technical solutions of the embodiments of this application, the relevant technologies of the embodiments of this application will be described below.

[0042] IPSec provides security services at the network layer (Layer 3), establishing an IPSec tunnel between two security gateways to implement encryption and authentication mechanisms, protecting the security of network layer data between communicating parties. However, IPSec cannot meet the needs when users require security protection for their data link layer or physical layer networks. Furthermore, IPSec requires complex encapsulation operations on raw data packets, such as encapsulating authentication headers, encrypted security payload headers, and packet trailers. This encapsulation process introduces significant packet encapsulation overhead, consuming bandwidth resources. The encryption and decryption of data packets by IPSec also incurs millisecond-level processing latency, requiring careful assessment of its impact on service latency.

[0043] MACSec is a data link layer secure encryption communication technology that can ensure the security of data frames between Ethernet devices and reduce the risk of information leakage and malicious network attacks. However, MACSec still has security vulnerabilities. On the one hand, MACSec cannot provide encryption protection for Ethernet frame headers, nor can it mask traffic characteristics such as transmission frequency and Ethernet frame length. This makes unencrypted Ethernet frame headers vulnerable to attackers to perform traffic model analysis attacks, thereby inferring user privacy and behavior. Related technologies have proposed various protection schemes to address this issue, but these technologies are still under discussion and will also introduce additional overhead and latency jitter, increasing implementation complexity. On the other hand, MACSec cannot encrypt priority flow control frames. Related technologies are discussing feasible solutions to this problem, but these involve modifications to the existing MAC layer architecture, increasing the complexity of implementation.

[0044] In summary, when security solutions such as IPSec and MACSec are applied to Ethernet computing network applications, they suffer from problems such as incomplete encryption coverage of all fields, prolonged encryption / decryption processing, and increased encapsulation overhead. To address these issues, the following technical solution is proposed in this application. This application proposes an Ethernet link security mechanism that constructs a novel encryption / decryption mechanism at the physical layer, meeting the security requirements of low latency and low overhead in the aforementioned scenarios.

[0045] It should be noted that the optical modules (such as the first optical module and the second optical module) described in the embodiments of this application are long-distance optical modules, such as ZR modules, ZR+ modules, etc. Alternatively, the optical modules (such as the first optical module and the second optical module) described in the embodiments of this application are optical modules with a first rate, where the first rate is greater than or equal to a rate threshold, such as an optical module with a rate of 400Gb / s (referred to as a 400ZR optical module), a 400GE ZR ZR+ module, etc.

[0046] It should be noted that the secure transmission method described in this application embodiment adopts the physical layer security (PHYSec) mechanism, which implements secure encryption and decryption at the Ethernet physical layer.

[0047] Figure 2 is a schematic flowchart of a secure transmission method provided in an embodiment of this application. The secure transmission method is applied to a first optical module. As shown in Figure 2, the secure transmission method includes:

[0048] Step 201: Obtain the first bit stream from the first device. The first bit stream is a plaintext bit stream, which is obtained by the first device through physical layer processing of Ethernet Media Access Control (MAC) frames.

[0049] In this embodiment of the application, the first device is a transmitting device, which refers to the device corresponding to the data transmitting end.

[0050] In some implementations, the first device is an Ethernet device.

[0051] In this embodiment of the application, a first optical module is connected to the first device side. The first optical module is used to convert the electrical signal of the first device side into an optical signal and transmit the optical signal through an optical link.

[0052] It should be noted that the first bit stream obtained by the first optical module from the first device is an electrical signal. The first bit stream is obtained by the first device through physical layer processing of the Ethernet MAC frame. Specifically, the Ethernet MAC frame is passed from the MAC layer of the first device to the PHY layer, where it is processed by encoding, scrambling, etc., and then transformed into the first bit stream, which is a plaintext bit stream.

[0053] Step 202: Encrypt the first bit stream using the first key through the PCS layer to obtain the second bit stream, which is a ciphertext bit stream; and carry key information related to the first key through the padding field before the second bit stream through the PCS layer.

[0054] In this embodiment, the first optical module has a digital signal processor (DSP), which can be called an optical DSP (oDSP). The first optical module uses the oDSP to encrypt the first bitstream at the PCS layer using a first key to obtain a second bitstream, and the padding field before the second bitstream carries key information related to the first key.

[0055] In this embodiment, the first optical module encrypts the first bit stream using a symmetric cryptography algorithm to obtain the second bit stream.

[0056] In some implementations, symmetric cryptographic algorithms include, but are not limited to, the Advanced Encryption Standard (AES) algorithm and the SM4 algorithm.

[0057] In some implementations, the first optical module generates a first key. The key used by the first optical module can be updated; for example, the first optical module can periodically generate new keys to be used by the first optical module.

[0058] In some implementations, the first optical module obtains a first key from a first device. The key used by the first optical module can be updated; for example, the first device can periodically generate new keys and issue them to the first optical module as the key used by the first optical module.

[0059] In some implementations, the first optical module inserts padding bits before the first bit stream (corresponding to the payload) via the PCS layer. Additionally, it inserts one or more fields such as alignment fields and overhead fields. Based on this, the first optical module carries key information related to the first key in the padding fields via the PCS layer.

[0060] In some implementations, the key information related to the first key includes, but is not limited to: the content of the first key and the generation parameters of the first key. The generation parameters of the first key are used to generate the content of the first key.

[0061] In one example, Figure 3 shows the PCS frame structure of a 400ZR optical module. This frame structure uses a block format of 10280 columns × 4096 rows, where the 4096 rows can consist of either 1 × 4096 rows or 16 × 256 rows. Figure 4 shows the PCS frame overhead of the 400ZR optical module, including 16 × 120 bits of alignment markers, 1920 bits of padding, and 4 × 320 bits of overhead, all located in the first row of the frame structure. Additionally, there is 20 bits of extra padding between the overhead and the payload, and the payload area is 10220 × 257 bits in size. The series of bits corresponding to the payload area constitutes the first bit stream. It should be noted that 'b' in Figures 3 and 4 refers to bits.

[0062] In some implementations, the N bits in the padding field carry key information, wherein the M1 bit of the N bits is used to identify the start position of the information, the M2 bit of the N bits is used to carry key information, and the M3 bit of the N bits is used to identify the end position of the information, where N is a positive integer, and M1, M2 and M3 are positive integers less than N.

[0063] In one example, the padding field preceding the first / second bitstream carries key information. The M1 = 8 bits in the padding field have a first value (e.g., 10101010) to identify the start of the information. The M2 = 256 bits in the padding field have a specific value to identify a specific key. The M3 = 8 bits in the padding field have a second value (e.g., 00001111) to identify the end of the information. Table 1 below provides an explanation of at least some of the bits in the padding field.

[0064] Table 1: Explanation of Fill Fields

[0065]

[0066]

[0067] Step 203: Send the second bit stream via the optical link.

[0068] In some implementations, before step 202, the first optical module inserts a padding field before the first bitstream via the PCS layer, and this padding field carries key information. Therefore, after the first optical module encrypts the first bitstream into a second bitstream, a padding field carrying key information is inserted before the second bitstream.

[0069] The technical solution of this application proposes a secure encryption mechanism (PHYSec) operating at the Ethernet physical layer. This mechanism encrypts and decrypts the physical layer bitstream (i.e., the first bitstream). Since the Ethernet frame header of the data link layer and the IP header of the network layer are both part of the payload of the physical layer bitstream, PHYSec can protect all upper-layer protocols and data, mask traffic characteristics, and has extremely high security. Furthermore, the technical solution of this application extracts some bits from the padding field inserted in the PCS layer of the optical module to carry the key information of PHYSec, thereby constructing a new physical layer encoding format and providing a basis for physical layer data decryption.

[0070] Figure 5 is a schematic flowchart of the secure transmission method provided in this embodiment of the application. The secure transmission method is applied to a second optical module. As shown in Figure 5, the secure transmission method includes:

[0071] Step 501: Receive the second bit stream via the optical link. The second bit stream is a ciphertext bit stream.

[0072] In this embodiment of the application, the second device is a receiving device, which refers to the device corresponding to the data receiving end.

[0073] In some implementations, the second device is an Ethernet device.

[0074] In this embodiment of the application, a second optical module is connected to the second device side. The second optical module is used to convert the optical signal received through the optical link into an electrical signal and forward the electrical signal to the second device.

[0075] It should be noted that the second bitstream received by the second optical module through the optical link is an optical signal. The second bitstream is obtained by the first optical module encrypting the first bitstream using the first key, as detailed in the description in Figure 2 above.

[0076] Step 502: Extract key information from the padding field before the second bit stream through the PCS layer, determine the first key based on the key information; and decrypt the second bit stream using the first key through the PCS layer to obtain the first bit stream, which is a plaintext bit stream.

[0077] In this embodiment, the second optical module has a DSP, which can be referred to as oDSP. The second optical module extracts key information from the padding field before the second bitstream at the PCS layer using the oDSP, determines the first key based on the key information, and decrypts the second bitstream using the first key at the PCS layer to obtain the first bitstream.

[0078] In this embodiment, the second optical module decrypts the second bit stream using a symmetric cryptography algorithm to obtain the first bit stream.

[0079] In some implementations, symmetric cryptographic algorithms include, but are not limited to, AES algorithm, SM4 algorithm, etc.

[0080] In some implementations, a padding field carrying key information is inserted before the second bitstream; the second optical module extracts the key information from the padding field through the PCS layer. The second optical module obtains / generates a first key based on the key information, and uses this first key to decrypt the second bitstream to obtain the first bitstream.

[0081] In some implementations, the key information includes, but is not limited to: the content of the first key and the generation parameters of the first key. The generation parameters of the first key are used to generate the content of the first key.

[0082] In some implementations, the N bits in the padding field carry key information, wherein the M1 bit of the N bits is used to identify the start position of the information, the M2 bit of the N bits is used to carry key information, and the M3 bit of the N bits is used to identify the end position of the information, where N is a positive integer, and M1, M2 and M3 are positive integers less than N.

[0083] Step 503: Send the first bit stream to the second device. The first bit stream is used by the second device to obtain Ethernet MAC frames through physical layer processing.

[0084] The technical solution of this application proposes a secure encryption mechanism (PHYSec) operating at the Ethernet physical layer. This mechanism encrypts and decrypts the physical layer bitstream (i.e., the first bitstream). Since the Ethernet frame header of the data link layer and the IP header of the network layer are both part of the payload of the physical layer bitstream, PHYSec can protect all upper-layer protocols and data, mask traffic characteristics, and has extremely high security. Furthermore, the technical solution of this application extracts some bits from the padding field inserted in the PCS layer of the optical module to carry the key information of PHYSec, thereby constructing a new physical layer encoding format and providing a basis for physical layer data decryption.

[0085] Figure 6 is a schematic diagram of the overall framework provided in the embodiment of this application. As shown in Figure 6, both device A and device B are Ethernet devices. Device A corresponds to the first device in the above scheme, and device B corresponds to the second device in the above scheme. The optical module on the device A side corresponds to the first optical module in the above scheme, and the optical module on the device B side corresponds to the second optical module in the above scheme. The link between the first optical module and the second optical module is an optical link.

[0086] Figure 7 is a schematic diagram of the PHYSec data encryption and decryption process provided in an embodiment of this application. PHYSec data encryption and decryption mainly provides confidentiality and integrity protection for data, preventing data leakage and tampering. PHYSec encrypts and decrypts data based on symmetric cryptographic algorithms, and can flexibly select appropriate symmetric cryptographic algorithms according to the use scenario, such as AES algorithm, SM4 algorithm, etc. PHYSec is implemented at the physical layer, offloading the encryption / decryption algorithm to the oDSP of the optical module to achieve line-speed encryption / decryption. Specifically, as shown in Figure 7, the MAC layer of device A sends the encapsulated Ethernet MAC frame to the PHY chip. The PHY chip encodes, scrambles, transcodes (256B / 257B), performs forward error correction (FEC) encoding, and segments the Ethernet MAC frame at the PCS layer. At the Physical Medium Attachment (PMA) layer, it converts the parallel data from the PCS layer into a serial data stream (i.e., the first bit stream / plaintext bit stream) and sends the plaintext bit stream to the optical module. The optical module encrypts the plaintext bit stream into a ciphertext bit stream through the oDSP (the oDSP implements PHYSec at the PCS layer and is equipped with an encryption algorithm), and sends the ciphertext bit stream out through the optical link. After receiving the ciphertext bitstream, the optical module on device B decrypts the ciphertext bitstream back into a plaintext bitstream using oDSP (oDSP implements PHYSec at the PCS layer and has a decryption algorithm). The plaintext bitstream is then sent to the PHY chip of device B. The PHY chip converts the serial plaintext bitstream into a parallel data stream at the PMA layer and delivers the parallel data stream to the PCS layer. At the PCS layer, the parallel data stream from the PMA layer undergoes segment merging, FFC decoding, 256B / 257B inversion coding, descrambling, and decoding. The resulting Ethernet MAC is then delivered to the MAC layer.

[0087] Figure 8 illustrates the data processing flow of the PCS layer of the optical module provided in this embodiment. As shown in Figure 8, at the transmitting end, the PCS layer of the optical module encodes, transcodes (256B / 257B), performs Generic Mapping Procedure (GMP) mapping, overhead / marking (OH / AM) insertion, padding insertion, scrambling, FEC encoding / interleaving / channel distribution, and Poil insertion on the bit stream (i.e., the first bit stream) corresponding to the Ethernet MAC frame. During padding insertion, the padding field carries key information, and the first bit stream is encrypted using this first key. The resulting second bit stream is then transmitted through the optical link. At the receiving end, the PCS layer of the optical module first extracts the key information from the padding field, decrypts the second bit stream using this first key to obtain the first bit stream, and then performs Poil deletion, channel merging / deinterleaving, descrambling, padding deletion, AM / OH detection and deletion, GMP inverse mapping, inversion coding, and decoding on the first bit stream, ultimately restoring the Ethernet MAC frame.

[0088] Figure 9 is a schematic diagram of the structure of a secure transmission device provided in an embodiment of this application, applied to a first optical module. As shown in Figure 9, the secure transmission device includes:

[0089] The acquisition unit 901 is used to acquire a first bit stream from the first device. The first bit stream is a plaintext bit stream, and the first bit stream is obtained by the first device performing physical layer processing on Ethernet MAC frames.

[0090] Processing unit 902 is configured to encrypt the first bit stream using a first key through a PCS layer to obtain a second bit stream, the second bit stream being a ciphertext bit stream; and to carry key information related to the first key through a padding field before the second bit stream by the PCS layer.

[0091] The transmitting unit 903 is used to transmit the second bit stream via an optical link.

[0092] In some implementations, the N bits in the padding field carry the key information, wherein M1 bits of the N bits are used to identify the start position of the information, M2 bits of the N bits are used to carry the key information, and M3 bits of the N bits are used to identify the end position of the information, where N is a positive integer, and M1, M2, and M3 are positive integers less than N.

[0093] In some embodiments, the apparatus further includes a generation unit for generating the first key.

[0094] In some implementations, the acquisition unit 901 is used to acquire the first key from the first device.

[0095] In some implementations, the first optical module is a long-distance optical module, or the first optical module is an optical module with a first rate, wherein the first rate is greater than or equal to a rate threshold.

[0096] Those skilled in the art should understand that the functions of each unit in the secure transmission device shown in Figure 9 can be understood with reference to the relevant description of the aforementioned method. The functions of each unit in the secure transmission device shown in Figure 9 can be implemented by a program running on a processor, or by specific logic circuits.

[0097] Figure 10 is a schematic diagram of the structure of the secure transmission device provided in this application embodiment, applied to the second optical module. As shown in Figure 10, the secure transmission device includes:

[0098] The receiving unit 1001 is used to receive a second bit stream via an optical link, wherein the second bit stream is a ciphertext bit stream;

[0099] Processing unit 1002 is configured to extract key information from the padding field before the second bitstream through the PCS layer, determine a first key based on the key information, and decrypt the second bitstream using the first key through the PCS layer to obtain a first bitstream, wherein the first bitstream is a plaintext bitstream.

[0100] The sending unit 1003 is used to send the first bit stream to the second device, wherein the first bit stream is used by the second device to obtain an Ethernet MAC frame through physical layer processing.

[0101] In some embodiments, a padding field is inserted before the second bitstream, the padding field carrying the key information; the apparatus further includes an extraction unit for extracting the key information from the padding field via a PCS layer.

[0102] In some implementations, the N bits in the padding field carry the key information, wherein M1 bits of the N bits are used to identify the start position of the information, M2 bits of the N bits are used to carry the key information, and M3 bits of the N bits are used to identify the end position of the information, where N is a positive integer, and M1, M2, and M3 are positive integers less than N.

[0103] In some implementations, the second optical module is a long-distance optical module, or the second optical module is an optical module with a first rate, wherein the first rate is greater than or equal to a rate threshold.

[0104] Those skilled in the art should understand that the functions of each unit in the secure transmission device shown in Figure 10 can be understood with reference to the relevant description of the aforementioned method. The functions of each unit in the secure transmission device shown in Figure 10 can be implemented by a program running on a processor, or by specific logic circuits.

[0105] Figure 11 is a schematic structural diagram of an optical module 1100 provided in an embodiment of this application. The optical module 1100 shown in Figure 11 includes a DSP 1110, which can call and run computer programs from memory to implement the methods in the embodiments of this application.

[0106] Optionally, as shown in FIG11, the optical module 1100 may further include a memory 1120. The DSP 1110 can call and run computer programs from the memory 1120 to implement the methods in the embodiments of this application.

[0107] The memory 1120 can be a separate device independent of the DSP 1110, or it can be integrated into the DSP 1110.

[0108] Optionally, as shown in Figure 11, the optical module 1100 may also include a transceiver 1130. The DSP 1110 can control the transceiver 1130 to communicate with other devices. Specifically, it can send information or data to other devices or receive information or data sent by other devices.

[0109] The transceiver 1130 may include a transmitter and a receiver. The transceiver 1130 may further include an antenna, and the number of antennas may be one or more.

[0110] Optionally, the optical module 1100 may specifically be the first optical module in the embodiments of this application, and the optical module 1100 may implement the corresponding processes implemented by the first optical module in the various methods of the embodiments of this application. For the sake of brevity, it will not be described in detail here.

[0111] Optionally, the optical module 1100 may specifically be the second optical module in the embodiments of this application, and the optical module 1100 may implement the corresponding processes implemented by the second optical module in the various methods of the embodiments of this application. For the sake of brevity, it will not be described in detail here.

[0112] Figure 12 is a schematic structural diagram of a chip according to an embodiment of this application. The chip 1200 shown in Figure 12 includes a processor 1210, which can call and run computer programs from memory to implement the methods in the embodiments of this application.

[0113] Optionally, as shown in FIG12, chip 1200 may further include memory 1220. Processor 1210 may retrieve and run computer programs from memory 1220 to implement the methods in the embodiments of this application.

[0114] The memory 1220 can be a separate device independent of the processor 1210, or it can be integrated into the processor 1210.

[0115] Optionally, the chip 1200 may also include an input interface 1230. The processor 1210 can control the input interface 1230 to communicate with other devices or chips; specifically, it can acquire information or data sent by other devices or chips.

[0116] Optionally, the chip 1200 may also include an output interface 1240. The processor 1210 can control the output interface 1240 to communicate with other devices or chips, specifically, to output information or data to other devices or chips.

[0117] Optionally, the chip can be applied to the first optical module in the embodiments of this application, and the chip can implement the corresponding processes implemented by the first optical module in the various methods of the embodiments of this application. For the sake of brevity, it will not be described in detail here.

[0118] Optionally, the chip can be applied to the second optical module in the embodiments of this application, and the chip can implement the corresponding processes implemented by the second optical module in the various methods of the embodiments of this application. For the sake of brevity, it will not be described in detail here.

[0119] It should be understood that the chip mentioned in the embodiments of this application may also be referred to as a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc.

[0120] It should be understood that the processor in the embodiments of this application may be an integrated circuit chip with signal processing capabilities. In implementation, the steps of the above method embodiments can be completed by integrated logic circuits in the processor's hardware or by instructions in software form. The processor described above can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly embodied in the execution of a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software modules can be located in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. The storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method.

[0121] It is understood that the memory in the embodiments of this application can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as Static Random Access Memory (SRAM), Dynamic Random Access Memory (DRAM), Synchronous DRAM (SDRAM), Double Data Rate SDRAM (DDR SDRAM), Enhanced Synchronous DRAM (ESDRAM), Synchlink DRAM (SLDRAM), and Direct Rambus RAM (DR RAM). It should be noted that the memory used in the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0122] It should be understood that the above-described memory is exemplary and not a limiting description. For example, the memory in the embodiments of this application may also be static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct memory bus RAM (DR RAM), etc. That is to say, the memory in the embodiments of this application is intended to include, but is not limited to, these and any other suitable types of memory.

[0123] This application also provides a computer-readable storage medium for storing computer programs.

[0124] Optionally, the computer-readable storage medium can be applied to the first optical module in the embodiments of this application, and the computer program causes the computer to execute the corresponding processes implemented by the first optical module in the various methods of the embodiments of this application. For the sake of brevity, it will not be described in detail here.

[0125] Optionally, the computer-readable storage medium can be applied to the second optical module in the embodiments of this application, and the computer program causes the computer to execute the corresponding processes implemented by the second optical module in the various methods of the embodiments of this application. For the sake of brevity, it will not be described in detail here.

[0126] This application also provides a computer program product, including computer program instructions.

[0127] Optionally, the computer program product can be applied to the first optical module in the embodiments of this application, and the computer program instructions cause the computer to execute the corresponding processes implemented by the first optical module in the various methods of the embodiments of this application. For the sake of brevity, they will not be described in detail here.

[0128] Optionally, the computer program product can be applied to the second optical module in the embodiments of this application, and the computer program instructions cause the computer to execute the corresponding processes implemented by the second optical module in the various methods of the embodiments of this application. For the sake of brevity, they will not be described in detail here.

[0129] This application also provides a computer program.

[0130] Optionally, the computer program can be applied to the first optical module in the embodiments of this application. When the computer program is run on a computer, it causes the computer to execute the corresponding processes implemented by the first optical module in the various methods of the embodiments of this application. For the sake of brevity, it will not be described in detail here.

[0131] Optionally, the computer program can be applied to the second optical module in the embodiments of this application. When the computer program is run on a computer, it causes the computer to execute the corresponding processes implemented by the second optical module in the various methods of the embodiments of this application. For the sake of brevity, it will not be described in detail here.

[0132] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0133] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0134] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0135] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0136] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0137] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0138] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A secure transmission method, characterized in that, Applied to a first optical module, the method includes: obtaining a first bit stream from a first device, the first bit stream being a plaintext bit stream, the first bit stream being obtained by the first device through physical layer processing of Ethernet Media Access Control (MAC) frames; encrypting the first bit stream using a first key through a Physical Coding Sublayer (PCS) to obtain a second bit stream, the second bit stream being a ciphertext bit stream; carrying key information related to the first key through a padding field before the second bit stream by the PCS layer; and transmitting the second bit stream through an optical link.

2. The method according to claim 1, characterized in that, The N bits in the padding field carry the key information, wherein M1 bits of the N bits are used to identify the start position of the information, M2 bits of the N bits are used to carry the key information, and M3 bits of the N bits are used to identify the end position of the information, where N is a positive integer, and M1, M2 and M3 are positive integers less than N.

3. The method according to any one of claims 1 to 2, characterized in that, The method further includes: generating the first key; or obtaining the first key from the first device.

4. The method according to any one of claims 1 to 2, characterized in that, The first optical module is a long-distance optical module, or the first optical module is an optical module with a first rate, wherein the first rate is greater than or equal to a rate threshold.

5. A secure transmission method, characterized in that, The method, applied to a second optical module, includes: receiving a second bit stream via an optical link, the second bit stream being a ciphertext bit stream; extracting key information from a padding field preceding the second bit stream via a PCS layer, and determining a first key based on the key information; decrypting the second bit stream using the first key via the PCS layer to obtain a first bit stream, the first bit stream being a plaintext bit stream; and sending the first bit stream to a second device, the first bit stream being used by the second device to obtain an Ethernet MAC frame through physical layer processing.

6. The method according to claim 5, characterized in that, The N bits in the padding field carry the key information, wherein M1 bits of the N bits are used to identify the start position of the information, M2 bits of the N bits are used to carry the key information, and M3 bits of the N bits are used to identify the end position of the information, where N is a positive integer, and M1, M2 and M3 are positive integers less than N.

7. The method according to any one of claims 5 to 6, characterized in that, The second optical module is a long-distance optical module, or the second optical module is an optical module with a first rate, wherein the first rate is greater than or equal to a rate threshold.

8. A secure transmission device, characterized in that, The device, applied to a first optical module, comprises: an acquisition unit for acquiring a first bit stream from a first device, wherein the first bit stream is a plaintext bit stream and is obtained by the first device performing physical layer processing on Ethernet MAC frames; a processing unit for encrypting the first bit stream using a first key through a PCS layer to obtain a second bit stream, wherein the second bit stream is a ciphertext bit stream; and for carrying key information related to the first key through a padding field before the second bit stream by the PCS layer; and a transmission unit for transmitting the second bit stream through an optical link.

9. The apparatus according to claim 8, characterized in that, The first optical module is a long-distance optical module, or the first optical module is an optical module with a first rate, wherein the first rate is greater than or equal to a rate threshold.

10. A secure transmission device, characterized in that, The device, applied to a second optical module, comprises: a receiving unit for receiving a second bit stream via an optical link, wherein the second bit stream is a ciphertext bit stream; a processing unit for extracting key information from a padding field preceding the second bit stream via a PCS layer, determining a first key based on the key information; and decrypting the second bit stream using the first key via the PCS layer to obtain a first bit stream, wherein the first bit stream is a plaintext bit stream; and a sending unit for sending the first bit stream to a second device, wherein the first bit stream is used by the second device to obtain an Ethernet MAC frame through physical layer processing.

11. The apparatus according to claim 8, characterized in that, The second optical module is a long-distance optical module, or the second optical module is an optical module with a first rate, wherein the first rate is greater than or equal to a rate threshold.

12. An optical module, characterized in that, include: A DSP, wherein the DSP is used to invoke and run a computer program to perform the method as described in any one of claims 1 to 7.

13. A computer-readable storage medium, characterized in that, Used to store a computer program that causes a computer to perform the method as described in any one of claims 1 to 7.

14. A computer program product, characterized in that, It includes computer program instructions that cause a computer to perform the method as described in any one of claims 1 to 7.