Data transmission method, communication apparatus, and system

WO2026166382A1PCT designated stage Publication Date: 2026-08-13HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2026-01-28
Publication Date
2026-08-13

Smart Images

  • Figure CN2026075396_13082026_PF_FP_ABST
    Figure CN2026075396_13082026_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the embodiments of the present application are a data transmission method, a communication apparatus, and a system. The method comprises: a first communication apparatus receiving encryption / decryption information sent by a second communication apparatus directly connected thereto, and using the encryption / decryption information to encrypt or decrypt a first bit stream at a physical layer, so as to obtain a second bit stream. In this way, a second communication apparatus configures encryption / decryption information on a first communication apparatus to enable the first communication apparatus to encrypt or decrypt, on the basis of the encryption / decryption information, a bit stream transmitted at a physical layer, such that there is no need to add encryption / decryption-related information to an end-to-end transmitted Ethernet data frame (which belongs to service data of a user). Compared with a solution in which an Ethernet data frame is encrypted or decrypted on the basis of MACsec, the method avoids the problem of encryption / decryption-related information occupying a user bandwidth, also overcomes the issue of it being impossible to protect traffic characteristics of the user, and improves the transmission security of the service data of the user.
Need to check novelty before this filing date? Find Prior Art

Description

A data transmission method, communication device and system

[0001] This application claims priority to Chinese Patent Application No. 202510145071.9, filed with the State Intellectual Property Office of China on February 8, 2025, entitled "A Data Transmission Method, Communication Device and System", the entire contents of which are incorporated herein by reference. Technical Field

[0002] This application relates to the field of security technology, and in particular to a data transmission method, communication device and system. Background Technology

[0003] Currently, Media Access Control Security (MACsec) encryption technology is commonly used in Ethernet to ensure the security of data transmission. This MACsec technology is applied to the data link layer of the Open System Interconnection (OSI) reference model to encrypt or decrypt Ethernet data frames. During encryption, MACsec encryption is based on the Ethernet data link layer, protecting only user data and failing to mask user traffic characteristics. Frame addresses, lengths, and frequency periods are all exposed, leaving blind spots in security as some important network protocols cannot be protected. Summary of the Invention

[0004] Based on this, this application provides a data transmission method, communication device, and system. By configuring encryption and decryption information onto a first communication device through a second communication device, the first communication device can encrypt or decrypt bit streams transmitted via the Ethernet physical layer (PHY), thereby improving transmission security.

[0005] Firstly, this application provides a data transmission method in which a first communication device receives encryption / decryption information sent by a second communication device directly connected to it, and uses the encryption / decryption information to encrypt or decrypt a first bit stream of the PHY to obtain a second bit stream. In this way, by configuring the encryption / decryption information onto the first communication device through the second communication device, it becomes possible for the first communication device to encrypt or decrypt the bit stream transmitted at the physical layer based on the encryption / decryption information. This eliminates the need to add encryption / decryption related information to the end-to-end transmitted Ethernet data frames (belonging to the user's service data), improving transmission security and overcoming the problem of consuming user bandwidth by adding encryption / decryption related information to the Ethernet data frames in MACsec encryption / decryption schemes. It also overcomes the problem that MACsec encryption / decryption schemes only encrypt the MAC Service Data Unit (MSDU) in the Ethernet data frame, while user traffic characteristics such as frame address, frame length, and period frequency are not protected, resulting in insufficient security for user service data transmission.

[0006] In some possible communication methods, the encryption / decryption information may include at least one of the following: an encryption key, an initialization vector (IV), or an encryption key number. There may be at least two encryption keys, and the type of encryption key may be, for example, a secure association key (SAK). Different encryption algorithms may correspond to different key lengths, and the encryption keys must adhere to the principles of randomness and security. The encryption key number is used to indicate the encryption key used in the at least two encryption key sets. For example, a first communication device sends two encryption keys to a second communication device: encryption key a and encryption key b, with encryption key number 1 configured for encryption key a and encryption key number 2 configured for encryption key b. If the encryption / decryption information sent by the second communication device to the first communication device includes at least: encryption key a, encryption key b, and encryption key number 1, the first communication device, based on this encryption / decryption information, determines to use encryption key a indicated by encryption key number 1 for encryption or decryption, with encryption key b as a backup encryption key. It should be noted that the first communication device can also send the encryption key number as a specific field of the multiframe to the peer, so that the peer can obtain the encryption key number from the multiframe (i.e., the alignment mark (AM) code block), and thus know to use the same encryption key as the sender to successfully decrypt and obtain the decrypted bit stream. IV is the security parameter that is input into the encryption algorithm along with the encryption key.

[0007] In some possible implementations, the first communication device can be an optical module, and the second communication device can be a network device directly connected to the first communication device. It is understood that a direct connection between the network device and the optical module means that the optical module and the network device are directly connected, without any other device transmitting or processing the bit stream. For the case of a pluggable optical module, "direct connection" can be understood as the optical module connecting to the network device by inserting into a specific port; for the case of a non-pluggable optical module, "direct connection" can be understood as the optical module and the switching chip being packaged adjacently (i.e., the optical module and the switching chip are jointly packaged within the network device), and the two can be connected via circuitry.

[0008] As an example, the optical module's microcontroller unit (MCU) includes a security module for receiving encrypted and decrypted information. This example could be applied, for instance, to situations where there are more remaining available resources on the MCU.

[0009] As another example, the optical module's optical digital signal processing (oDSP) chip includes a security module on its inner microcontroller unit (iMCU) for receiving encrypted and decrypted information. This example could be applied, for instance, to situations where there are more remaining available resources on the iMCU.

[0010] It should be noted that the deployment location of the security module on the optical module used to receive encryption and decryption information can be flexibly designed based on the internal configuration of the optical module. For example, the deployment location of the security module on the optical module can depend on the resource occupancy of the MCU and iMCU on the optical module. If there are more available resources on the MCU, the security module can be deployed on the MCU; if there are more available resources on the iMCU, the security module can be deployed on the iMCU.

[0011] As an example, the first communication device encrypts or decrypts the first bit stream at the physical layer using encryption / decryption information. This can be implemented at the Physical Medium Attachment (PMA) sublayer of the first communication device. That is, the first communication device encrypts or decrypts the first bit stream at the PMA sublayer using encryption / decryption information to obtain the second bit stream. Thus, encrypting or decrypting the bit stream through the PMA sublayer of the optical module improves transmission security.

[0012] As an example, the first communication device receives encryption / decryption information sent by the second communication device. This may include, for instance, the first communication device receiving encryption / decryption information from the second communication device via an internal integrated circuit (IIC, or I2C) bus. In this way, the first communication device prepares to encrypt and decrypt the bitstream at the physical layer.

[0013] As an example, the process of obtaining the first bitstream processed by the first communication device may include: the first communication device receiving a third bitstream from a second communication device, detecting AM code blocks from the third bitstream, and obtaining the first bitstream based on the detected AM code blocks. Then, the second bitstream is obtained by the first communication device encrypting the physical layer's first bitstream using encryption / decryption information. After obtaining the second bitstream, the first communication device can also send it to a third communication device, which may be a network device or optical module at the peer of the first and second communication devices. In this way, the optical module can encrypt the bitstream sent by the directly connected network device, making it possible to send the encrypted bitstream (also called the ciphertext bitstream) to the peer.

[0014] As another example, the process of obtaining the first bit stream processed by the first communication device may include: the first communication device receiving the first bit stream from a third communication device. The third communication device may be a network device or optical module at the peer of the first and second communication devices. In this case, the second bit stream is obtained by the first communication device decrypting the first bit stream using encryption / decryption information. After obtaining the second bit stream, the first communication device can also send the second bit stream to the second communication device. In this way, the optical module can decrypt the bit stream received from the peer, making it possible to send the decrypted bit stream (also known as a plaintext bit stream) to the local network device.

[0015] In some other possible implementations, the first communication device can be a PHY interface (also called a PHY chip unit), and the second communication device can be a management chip. The first and second communication devices are integrated into a single network device. It is understood that a direct connection between the PHY interface and the management chip refers to a direct connection between the PHY interface and the management chip within the network device; that is, there are no other devices between the PHY interface and the management chip for transmitting or processing the bit stream.

[0016] As an example, a PHY interface may include a control unit and a PHY chip. The control unit of the PHY interface may include a security module for receiving encrypted / decrypted information. The PHY chip may include a security module for performing encryption or decryption of the bit stream.

[0017] As an example, the first communication device encrypts or decrypts the first bit stream at the physical layer using encryption / decryption information. This can be implemented in the Physical Coding Sublayer (PCS) of the first communication device. That is, the first communication device encrypts or decrypts the first bit stream in the PCS using encryption / decryption information to obtain the second bit stream. Thus, encrypting or decrypting the bit stream through the PCS at the PHY interface improves transmission security.

[0018] As an example, the first communication device receives encryption / decryption information sent by the second communication device. This may include, for instance, the first communication device receiving encryption / decryption information from the second communication device via a Management Data Input / Output (MDIO) interface. In this way, the first communication device prepares to encrypt and decrypt the bitstream at the physical layer.

[0019] As an example, the process of obtaining the first bit stream processed by the first communication device may include: the second communication device sending a bit stream with AM code blocks inserted to the first communication device; the first communication device receiving the bit stream from the second communication device and obtaining the first bit stream based on the AM code blocks in the bit stream; or, as the first communication device receiving the first bit stream from the second communication device, this first bit stream is a bit stream obtained based on the inserted AM code blocks. Then, the second bit stream is obtained by the first communication device encrypting the physical layer's first bit stream using encryption / decryption information. After obtaining the second bit stream, the first communication device can also send the second bit stream to a third communication device, which can be a network device or optical module at the peer of the first and second communication devices. In this way, the PHY interface can encrypt the bit stream sent by the management chip directly connected to it, making it possible to send the encrypted bit stream to the peer.

[0020] As another example, the process of obtaining the first bitstream processed by the first communication device may include: the first communication device receiving a third bitstream from a third communication device, detecting AM code blocks from the third bitstream, and obtaining the first bitstream based on the detected AM code blocks. The third communication device may be a network device or optical module at the peer of the first and second communication devices. In this case, the second bitstream is obtained by the first communication device decrypting the first bitstream using encryption / decryption information. After obtaining the second bitstream, the first communication device can also send the second bitstream to the second communication device. In this way, the PHY interface can decrypt the bitstream received from the peer, making it possible to send the decrypted bitstream to the local management chip.

[0021] In some possible implementations, the encrypted / decrypted information received by the first communication device from the second communication device can be plaintext (i.e., information not protected by encryption or other security measures). This can, to some extent, save the processing resources of both the first and second communication devices for encrypted / decrypted information.

[0022] In some other possible implementations, the encrypted / decrypted information received by the first communication device from the second communication device can be ciphertext (i.e., information protected by encryption or other security measures). Then, after obtaining the encrypted / decrypted information, the first communication device can further process (e.g., decrypt) the ciphertext to obtain the plaintext encrypted / decrypted information. Thus, the encryption or decryption of the first bitstream by the first communication device can refer to the first communication device using the plaintext encrypted / decrypted information to encrypt or decrypt the first bitstream. This improves the security of the encrypted / decrypted information transmitted between the first and second communication devices, thereby further enhancing the security of the user's business data transmission.

[0023] In some possible implementations, the first and second communication devices can also obtain indication information, which indicates the plaintext or ciphertext mode of the encryption / decryption information. The first and second communication devices can obtain the indication information through negotiation or configuration by a controller or other communication devices. If the indication information is carried in the message containing the encryption / decryption information, the first communication device can also obtain the indication information by parsing the message. This application does not specifically limit the implementation. This ensures that the first and second communication devices can transmit encryption / decryption information using the same mode, improving communication effectiveness.

[0024] In some possible implementations, the first communication device can receive a first bit stream from the service data interface. For scenarios where the first communication device is an optical module, the service data interface can be any of the following types of interfaces: a serializing / deserializing circuitry (SerDes) interface, a 10 Gigabit attachment unit interface (XAUI), or a 100 Gigabit attachment unit interface (CAUI). For scenarios where the first communication device is a PHY interface, the service data interface can be any of the following types of interfaces: a media independent interface (MII) or other derived MIIs (which can also be represented as xMII).

[0025] In some possible implementations, the process of the second communication device querying the encryption capability of the first communication device may include, for example, the second communication device sending a query read command to the first communication device, the query read command being used to query the encryption capability of the first communication device; after receiving the query read command sent by the second communication device, the first communication device sends a response message to the second communication device, thereby the second communication device receiving the response message sent by the first communication device, the response message including the encryption specification information of the first communication device, the encryption specification information being used to indicate the encryption capability of the first communication device. The encryption specification information may include at least one of the following: whether PHYsec is supported, the supported encryption rate, the supported encryption algorithm, or the supported key mode. Wherein, whether PHYsec is supported can be understood as whether the first communication device has the ability to perform encryption and decryption using PHYsec; the supported encryption rate can be understood as the specific rate of PHYsec supported by the first communication device; the supported encryption algorithm may include, for example, but not limited to, Advanced Encryption Standard (AES) and SM4; the supported key mode may indicate the length of the encryption key, for example, it may be 256 bits or 128 bits. Thus, if the first communication device does not support encryption (i.e. does not have encryption capability), the process is terminated; if the first communication device supports encryption (i.e. has encryption capability), it notifies the other end of the encryption capability and negotiates the encryption method. Then, the second communication device will perform the relevant configuration for encryption initialization and subsequent processes according to the negotiation result of the encryption method.

[0026] Secondly, this application also provides a data transmission method in which a second communication device sends encryption / decryption information to a first communication device directly connected to it. This encryption / decryption information is used by the first communication device to encrypt or decrypt a bit stream at the physical layer; thereby, a bit stream is transmitted between the second and first communication devices. In this way, the second communication device configures the encryption / decryption information onto the first communication device, enabling the first communication device to encrypt or decrypt the bit stream transmitted at the physical layer based on this encryption / decryption information. This eliminates the need to add encryption / decryption related information to the Ethernet data frames transmitted end-to-end, thus improving transmission security.

[0027] In some possible implementations, the encrypted / decrypted information can be plaintext. Alternatively, the encrypted / decrypted information can also be ciphertext, in which case the encrypted / decrypted information sent by the second communication device to the first communication device is the encrypted / decrypted information encrypted by the second communication device.

[0028] In some possible implementations, the method may further include: a second communication device obtaining indication information, which indicates whether the encrypted or decrypted information is in plaintext mode or ciphertext mode.

[0029] In some possible implementations, the first communication device is an optical module, and the second communication device is a network device directly connected to the first communication device; or, the first communication device is the PHY interface of the network device, and the second communication device is the management chip of the network device, which is used to manage the PHY interface.

[0030] In some possible implementations, the transmission of a bit stream between the second communication device and the first communication device may include: the second communication device sending a first bit stream to the first communication device, whereby the first communication device uses encryption / decryption information to encrypt the first bit stream. Alternatively, the transmission of a bit stream between the second communication device and the first communication device may include: the second communication device receiving a second bit stream sent by the first communication device, where the second bit stream is obtained by the first communication device decrypting a bit stream received from a third communication device using encryption / decryption information.

[0031] In some possible implementations, the method may further include: a second communication device sending a query read instruction to a first communication device, the query read instruction being used to query the encryption capabilities of the first communication device; the second communication device receiving a response message sent by the first communication device, the response message including encryption specification information of the first communication device, the encryption specification information being used to indicate the encryption capabilities of the first communication device, the encryption specification information including at least one of the following: whether PHYsec is supported, supported encryption rate, supported encryption algorithm, or supported key mode.

[0032] It should be noted that the method provided in the second aspect corresponds to the method provided in the first aspect, and the relevant introduction and technical effects can be found in the corresponding description in the first aspect.

[0033] Thirdly, this application also provides a data transmission apparatus applied to a first communication device. The apparatus may include a transceiver unit and a processing unit. The transceiver unit is used to receive encryption / decryption information sent by a second communication device, wherein the first and second communication devices are directly connected. The processing unit is used to encrypt or decrypt a first bitstream at the physical layer using the encryption / decryption information to obtain a second bitstream.

[0034] In some possible implementations, the first communication device is an optical module.

[0035] As an example, the MCU of the optical module, or the iMCU of the oDSP chip of the optical module, includes a security module for receiving encryption and decryption information.

[0036] As an example, the processing unit is specifically used to: encrypt or decrypt the first bit stream of the PMA sublayer using encryption and decryption information to obtain the second bit stream.

[0037] As an example, the transceiver unit is specifically used to receive encryption and decryption information sent by the second communication device from the IIC.

[0038] As an example, the transceiver unit is also used to receive a third bit stream from the second communication device; the processing unit is also used to detect AM code blocks from the third bit stream and obtain a first bit stream based on the detected AM code blocks. Specifically, the processing unit is used to: encrypt the first bit stream using encryption / decryption information to obtain a second bit stream.

[0039] As another example, the transceiver unit is also used to receive a first bit stream from a third communication device. The processing unit is specifically used to: decrypt the first bit stream using encryption / decryption information to obtain a second bit stream.

[0040] In some other possible implementations, the first communication device is a physical layer PHY interface.

[0041] As an example, the control unit of the PHY interface includes a security module for receiving encrypted and decrypted information.

[0042] As an example, the processing unit is specifically used to: encrypt or decrypt the first bit stream of the PCS using encryption / decryption information to obtain the second bit stream.

[0043] As an example, the transceiver unit is specifically used to receive encryption and decryption information sent by the second communication device from the MDIO interface.

[0044] As an example, the transceiver unit is also configured to receive a first bit stream from the second communication device, the first bit stream being a bit stream obtained based on an already inserted AM code block. The processing unit is then specifically configured to: encrypt the first bit stream using encryption / decryption information to obtain a second bit stream.

[0045] As another example, the transceiver unit is also configured to receive a third bit stream from a third communication device; the processing unit is also configured to detect AM code blocks from the third bit stream and obtain a first bit stream based on the detected AM code blocks. Specifically, the processing unit is configured to: decrypt the first bit stream using encryption / decryption information to obtain a second bit stream.

[0046] In some possible implementations, the encrypted / decrypted information is in plaintext.

[0047] In some other possible implementations, the encryption / decryption information is ciphertext, and the processing unit is specifically used to: decrypt the received encryption / decryption information to obtain the decrypted encryption / decryption information; and use the decrypted encryption / decryption information to encrypt or decrypt the first bit stream to obtain the second bit stream.

[0048] In some possible implementations, the encryption / decryption information includes at least one of the following: encryption key, IV, or encryption key number.

[0049] In some possible implementations, the device may further include an acquisition unit. This acquisition unit is used to acquire indication information, which indicates the plaintext or ciphertext mode of the encrypted / decrypted information.

[0050] In some possible implementations, the transceiver unit is also used to receive a first bit stream from a service data interface, which is any one of the following types of interfaces: SerDes interface, XAUI, CAUI, MII, or xMII.

[0051] In some possible implementations, the transceiver unit is further configured to receive a query read instruction sent by the second communication device, the query read instruction being used to query the encryption capability of the first communication device; the transceiver unit is further configured to send a response message to the second communication device, the response message including encryption specification information of the first communication device, the encryption specification information being used to indicate the encryption capability of the first communication device, the encryption specification information including at least one of the following: whether PHYsec is supported, the supported encryption rate, the supported encryption algorithm, or the supported key mode.

[0052] It should be noted that for the relevant description of the apparatus in the third aspect, please refer to the corresponding description in the first aspect.

[0053] Fourthly, this application also provides a data transmission apparatus applied to a second communication device. The apparatus may include a transceiver unit. This transceiver unit is used to send encryption / decryption information to a first communication device, which is directly connected to the second communication device. The encryption / decryption information is used by the first communication device to encrypt or decrypt a bit stream at the physical layer. The transceiver unit is also used to transmit a bit stream with the first communication device.

[0054] In some possible implementations, the encryption / decryption information is plaintext; or, if the encryption / decryption information is ciphertext, then the encryption / decryption information sent to the first communication device is the encrypted encryption / decryption information.

[0055] In some possible implementations, the device may further include an acquisition unit. The acquisition unit is used to acquire indication information, which indicates whether the encrypted / decrypted information is in plaintext or ciphertext mode.

[0056] In some possible implementations, the first communication device is an optical module and the second communication device is a network device; or, the first communication device is the PHY interface of the network device and the second communication device is the management chip of the network device, with the management chip used to manage the PHY interface.

[0057] In some possible implementations, the transceiver unit is specifically used to: send a first bit stream to a first communication device, and the encryption / decryption information is used by the first communication device to encrypt the first bit stream.

[0058] In some other possible implementations, the transceiver unit is specifically used to: receive a second bit stream sent by the first communication device, wherein the second bit stream is obtained by the first communication device decrypting the bit stream received from the third communication device using encryption and decryption information.

[0059] In some possible implementations, the transceiver unit is further configured to send a query read instruction to the first communication device, the query read instruction being used to query the encryption capability of the first communication device; the transceiver unit is further configured to receive a response message sent by the first communication device, the response message including encryption specification information of the first communication device, the encryption specification information being used to indicate the encryption capability of the first communication device, the encryption specification information including at least one of the following: whether PHYsec is supported, the supported encryption rate, the supported encryption algorithm, or the supported key mode.

[0060] It should be noted that for the relevant description of the apparatus in the fourth aspect, please refer to the corresponding description in the second aspect.

[0061] Fifthly, this application provides a communication device, which includes a processor and a memory; the processor is configured to execute instructions stored in the memory to cause the communication device to implement the method corresponding to the first aspect or the second aspect and their possible implementations.

[0062] Sixthly, this application provides a chip including an interface circuit and a processing circuit, wherein the interface circuit is connected to the processing circuit. The interface circuit is used to perform the receiving and transmitting operations in the method corresponding to the first aspect or the second aspect and its possible implementations; the processing circuit is used to perform other operations in the method corresponding to the first aspect or the second aspect and its possible implementations besides the receiving and transmitting operations.

[0063] In a seventh aspect, this application also provides a communication device, which includes an interface and a processor; the interface is used to receive instructions and transmit them to the processor; the processor is used to execute the method corresponding to the first aspect or the second aspect and their possible implementations.

[0064] Eighthly, this application also provides a communication system, which includes a first communication device and a second communication device. The first communication device is used to execute the method corresponding to the first aspect and its possible implementations; the second communication device is used to execute the method corresponding to the second aspect and its possible implementations.

[0065] As an example, the communication system may also include a third communication device that is connected to the second communication device via the first communication device.

[0066] Ninthly, this application also provides a storage medium storing instructions that, when executed on a processor, implement the method corresponding to the first aspect or the second aspect and their possible implementations.

[0067] In a tenth aspect, this application also provides a program product comprising a program that, when run on a processor, implements a method corresponding to the first aspect or the second aspect and its possible implementations. Attached Figure Description

[0068] Figure 1 is a schematic diagram of the MACsec encryption format for Ethernet data frames;

[0069] Figure 2 is a schematic diagram of the framework for implementing MACsec function based on PHY chip;

[0070] Figure 3 is a schematic diagram of the system applicable to the embodiments of this application;

[0071] Figure 4 is a schematic diagram of a network architecture applicable to an embodiment of this application;

[0072] Figure 5 is a schematic diagram of the processing flow corresponding to the network architecture shown in Figure 4 in an embodiment of this application;

[0073] Figure 6 is a possible structural diagram of the optical module in the network architecture shown in Figure 4 in an embodiment of this application;

[0074] Figure 7 is a schematic diagram of another possible structure of the optical module in the network architecture shown in Figure 4 in an embodiment of this application;

[0075] Figure 8 is a schematic diagram of another network architecture applicable to the embodiments of this application;

[0076] Figure 9 is a schematic diagram of the processing flow corresponding to the network architecture shown in Figure 8 in an embodiment of this application;

[0077] Figure 10 is a possible structural diagram of the PHY interface in the network architecture shown in Figure 8 in an embodiment of this application;

[0078] Figure 11 is a flowchart illustrating a data transmission method 100 in an embodiment of this application;

[0079] Figure 12 is a flowchart illustrating the transmission process of encrypted and decrypted information in an embodiment of this application;

[0080] Figure 13 is a flowchart illustrating the process of obtaining encrypted and decrypted information in an embodiment of this application;

[0081] Figure 14 is a flowchart illustrating an encryption / decryption process in an embodiment of this application;

[0082] Figure 15 is a flowchart illustrating an example of the process performed before encrypting or decrypting the bit stream in an embodiment of this application.

[0083] Figure 16 is a schematic diagram of the structure of a first communication device 1600 in an embodiment of this application;

[0084] Figure 17 is a schematic diagram of the structure of a second communication device 1700 in an embodiment of this application;

[0085] Figure 18 is a schematic diagram of the structure of a communication system 1800 according to an embodiment of this application;

[0086] Figure 19 is a schematic diagram of the structure of a communication device 1900 according to an embodiment of this application;

[0087] Figure 20 is a schematic diagram of the structure of a chip 2000 in an embodiment of this application. Detailed Implementation

[0088] With the increasing application of Ethernet, higher demands are being placed on network security. On the one hand, fields such as industrial parks, IoT, industrial internet, and telecommunications networks all face the risk of data and signaling transmitted via links being intercepted or cracked, requiring high security. On the other hand, for the increasingly important intelligent computing centers, transmitting artificial intelligence (AI) model parameters and high-security data related to enterprise security production via Ethernet involves the processing and transmission of a large amount of data resources in network scenarios within, between, and in computing environments. If this data is intercepted, attacked, or leaked during transmission, it will result in incalculable economic losses, making it a matter of extremely high security. For intelligent computing centers, there is a need to strengthen security both within and between centers. Within intelligent computing centers, typical scenarios such as exposed communication links and device ports, network expansion and upgrades, frequent maintenance, and multi-tenancy require encryption of all communication traffic between computing nodes to ensure the security of tenant model architectures, parameters, and other data. Between intelligent computing centers, the long distances of high-speed interconnecting fiber optic cables make it difficult to achieve comprehensive, blind-spot-free monitoring, and the exposed physical facilities such as fiber optic cable conduits pose a risk of attack and interception.

[0089] Currently, to improve network security, MACsec technology is commonly used to encrypt or decrypt Ethernet data frames frame by frame. MACsec is a secure communication method on local area networks based on the 802.1AE and 802.1X protocols. It ensures the security of Ethernet data frames through functions such as authentication, data encryption, integrity verification, and replay protection, preventing network devices from processing messages with security threats. Therefore, deploying MACsec in a network can protect transmitted Ethernet data frames to a certain extent, reducing the risk of information leakage and malicious network attacks.

[0090] MACsec ensures the secure transmission of user business data within the local area network (LAN) in several ways: First, data encryption. MACsec uses the AES-GCM algorithm for encryption and decryption. Specifically, the sender encrypts Ethernet data frames using the AES-CTR algorithm, and the Ethernet data frames are transmitted in ciphertext form over the LAN link. The receiver decrypts the received encrypted Ethernet data frames using the AES-CTR algorithm before performing further processing. Second, integrity verification. The receiver performs integrity verification on the received Ethernet data frames to determine if they have been tampered with. Specifically, the sender calculates the integrity check value based on the entire Ethernet data frame and the GCM algorithm. Value (ICV)1 is appended to the Ethernet data frame. After receiving the Ethernet data frame, the receiver calculates ICV2 based on the Ethernet data frame without ICV1 and the same GCM algorithm. ICV1 and ICV2 are compared. If they are the same, the Ethernet data frame is considered to have not been tampered with and the verification passes. If they are different, the Ethernet data frame is considered to have been tampered with and is discarded. Thirdly, replay protection is implemented to prevent malicious users from launching network attacks by repeatedly sending captured Ethernet data frames. By default, the receiver will discard duplicate or out-of-order Ethernet data frames. Specifically, Ethernet data frames may be rearranged during transmission in the network. The replay protection mechanism allows Ethernet data frames to be out of order to a certain extent. These out-of-order Ethernet data frames can be legally received within the user-specified window range. Ethernet data frames outside the window will be discarded. Assuming the configured replay protection window size is 'a', if an Ethernet data frame with sequence number 'x' is received, the sequence number of the next Ethernet data frame that is allowed to be received must be greater than or equal to (x+1-a). In addition, in order to transmit information such as security parameters and security capabilities to the receiver, the sender adds a security tag (SECtag) field to the frame header of the Ethernet data frame. The SECtag field is used to transmit information such as security parameters and security capabilities.

[0091] Taking an Ethernet data frame as an example, this section describes the format changes of an Ethernet data frame using MACsec. Referring to Figure 1, an Ethernet data frame before MACsec encryption may include: destination address, source address, MSDU, and Frame Check Sequence (FCS). The MSDU may include: Virtual Local Area Network (VLAN), Ethernet Type (ETH Type), and User Data. MACsec encrypts the MSDU in this Ethernet data frame to obtain Secure Data. Furthermore, a SECtag is added before Secure Data, and an ICV is added after Secure Data. The SECtag, Secure Data, and ICV can be referred to as the MAC Protocol Data Unit (MPDU) in this Ethernet data frame. Therefore, an Ethernet data frame encrypted with MACsec may include: destination address, source address, MPDU, and FCS.

[0092] As can be seen, the problems with using MACsec technology to encrypt Ethernet data frames include: Firstly, MACsec only protects the MSDU (Multi-access Dictionary Unit), failing to protect user traffic characteristics (such as frame address (including the destination and source addresses in Figure 1), frame length, and frequency). These user traffic characteristics are exposed during transmission, failing to protect some important network protocols, creating security blind spots. This is a problem also present in other security protocols (such as IPSec at the Internet Protocol (IP) layer, and TLS (Transport Layer Security) or DTLS (Datagram Transport Layer Security) at the transport layer). Secondly, the sender needs to add ICV and SECtag fields to each Ethernet data frame, consuming a significant amount of user bandwidth. For example, when the average Ethernet frame length is 64 bytes, each MACsec-encrypted Ethernet frame requires at least 28 bytes (including a 12-byte SECtag field and a 16-byte ICV), consuming (28 / 64) = 43% of user bandwidth, a substantial cost.

[0093] Furthermore, with the rapid growth in network equipment capacity in recent years, the engineering challenges related to heat dissipation and power supply brought about by power consumption are increasing, and users' demands for power reduction are becoming increasingly strong. Meanwhile, with the accelerated promotion of high-performance computing and AI, the focus on network latency is also growing. Although MACsec is a technology that implements data encryption and decryption at the Ethernet data link layer, with the increase in system capacity and port bandwidth, the power consumption required to implement MACsec functionality based on high-speed, high-capacity chips is becoming increasingly high; and the impact of network latency under new services is becoming increasingly apparent. It should be noted that MACsec functionality can be implemented through an external physical chip supporting MACsec on a single board, or through a switching chip. Taking the implementation of MACsec via an external physical chip supporting MACsec on a single board as an example, as shown in Figure 2, after the single board performs MAC / PHY processing on the Ethernet data frame 1 to be sent, it enters the physical chip. The physical chip sequentially performs PHY / MAC, MACsec encryption, and MAC / PHY on the Ethernet data frame 1. Afterward, the Ethernet data frame 1 sequentially enters the PMA sublayer and the Physical Medium Dependent (PMD) sublayer. The MACsec encryption step can be executed by the module implementing the MACsec function in the physical chip. For the received Ethernet data frame 2, after sequential processing by the PMD sublayer and PMA sublayer, the physical chip sequentially performs PHY / MAC, MACsec decryption, and MAC / PHY on the Ethernet data frame 2. Afterward, the single board performs PHY / MAC processing on the Ethernet data frame 2. The MACsec decryption step can be executed by the module implementing the MACsec function in the physical chip. It should be noted that the multiple Ethernet data frames 1 mentioned above may have different contents or formats after being processed through different steps. This application embodiment does not involve an elaborate description of these changes. Since they are obtained from the same Ethernet data frame, they are all referred to as Ethernet data frames 1 for ease of description. Similarly, the multiple Ethernet data frames 2 mentioned above may have different contents or formats after being processed through different steps. This application embodiment does not involve an elaborate description of these changes. Since they are obtained from the same Ethernet data frame, they are all referred to as Ethernet data frames 2 for ease of description.

[0094] Understandably, in the process shown in Figure 2, the physical chip requires a separate retimer, consuming twice the MAC / PHY resources, resulting in high cost and power consumption. It's also understandable that regardless of whether MACsec is implemented based on a physical chip or a switching chip, the MACsec function is strongly dependent on the single-board hardware. Therefore, for users with existing traditional single-board computers, the need to improve data transmission security based on MACsec cannot be met. Furthermore, user requirements for port encryption are often dynamic and unpredictable. For example, when purchasing network equipment, based on the initial needs, purchasing a network device with only 8 fixed ports supporting MACsec might suffice. However, subsequent applications may require more MACsec ports, necessitating hardware upgrades and additional investment. Purchasing network equipment with far more MACsec-supporting ports than actually needed risks over-investment. Moreover, for high-speed network equipment, it's difficult to enable MACsec on all ports. Ethernet data frames transmitted on ports without MACsec enabled cannot guarantee transmission security; that is, MACsec cannot serve as a security guarantee for all Ethernet data frames transmitted on high-speed network equipment. In summary, implementing MACsec requires significant resources, bandwidth and latency, consumes a lot of power, and has high hardware implementation costs. It cannot meet the security requirements of data transmission in situations such as existing traditional hardware systems or dynamically changing needs.

[0095] Based on this, to provide a method for data security transmission with better performance, in this embodiment, after receiving encryption / decryption information from a second communication device directly connected to it, the first communication device uses the encryption / decryption information to encrypt or decrypt the PHY bitstream. Thus, by configuring the encryption / decryption information onto the first communication device through the second communication device, it becomes possible for the first communication device to encrypt or decrypt the bitstream transmitted at the physical layer. This eliminates the need to add encryption / decryption related information to the end-to-end user data transmission, avoiding the consumption of user bandwidth by adding encryption / decryption related information. This overcomes the problems of high resource cost, high bandwidth overhead and latency, high power consumption, high hardware implementation cost, and inability to guarantee the transmission security of all user data in MACsec. Furthermore, by encrypting or decrypting the bitstream at the physical layer, all bits after the Ethernet data frame conversion are encrypted and decrypted. Compared to MACsec, which encrypts and decrypts the MSDU in the Ethernet data frame, user traffic characteristics such as frame address, frame length, and period frequency cannot be protected. The method provided in this embodiment avoids the risk of exposing user traffic characteristics, resulting in higher security.

[0096] Before proceeding with the technical solutions provided in the embodiments of this application, a brief description of the system architecture applicable to the embodiments of this application will be given.

[0097] The method provided in this application embodiment can be applied to the system shown in Figure 3. The system may include a sender 1 and a receiver 2. The sender 1 can encrypt plaintext bitstream 1 to obtain ciphertext bitstream 1 and send the ciphertext bitstream 1 to the receiver 2. After receiving the ciphertext bitstream 1, the receiver 2 can decrypt the ciphertext bitstream 1 back to plaintext bitstream 1. It is understood that the communication between the sender 1 and the receiver 2 can be bidirectional. The sender and receiver are defined with respect to the transmission direction of bitstream 1. For example, for bitstream 2 transmitted from receiver 2 to sender 1, receiver 2 can encrypt plaintext bitstream 2 to obtain ciphertext bitstream 2 and send it to sender 1. After receiving the ciphertext bitstream 2, sender 1 can decrypt the ciphertext bitstream 2 back to plaintext bitstream 2. In this process, for bitstream 2, sender 1 acts as receiver, and receiver 2 acts as sender. Corresponding to the embodiments of this application, the first communication device and the second communication device can be deployed at the sender or the receiver of data transmission. Regardless of whether they are deployed at the sender or receiver, they both possess the encryption and decryption functions provided in the data transmission method of this application. That is, when the first and second communication devices, as senders, are receivers in other connection relationships, they can also implement the decryption function process provided in this application. The following description only introduces the encryption function of the sender and the decryption function of the receiver based on their deployment location.

[0098] It should be noted that sender 1 and receiver 2 can be deployed on the same network. For example, both sender 1 and receiver 2 belong to intelligent computing center A, and sender 1 and receiver 2 can be two communication devices within intelligent computing center A that can directly or indirectly transmit data. Alternatively, sender 1 and receiver 2 can also be deployed on two networks of the same or different types, where the network where sender 1 is located and the network where receiver 2 is located can directly or indirectly transmit data. For example, sender 1 is deployed in intelligent computing center A, and receiver 2 is deployed in intelligent computing center B. Or, sender 1 is deployed in intelligent computing center A, and receiver 2 is deployed in campus network C. The types of networks can include, but are not limited to, campus networks, IoT, industrial internet, and intelligent computing centers. Figure 3 illustrates the data transmission between sender 1 in intelligent computing center A and receiver 2 in intelligent computing center B as an example.

[0099] It should be noted that the network devices (also referred to as communication devices or communication apparatuses) corresponding to sender 1 and receiver 2 can include network-side devices such as switches, routers, and firewalls, or end-side devices such as servers, controllers, user hosts, or vehicle-side hosts. In the embodiments of this application, the first communication apparatus can be an optical module, and the second communication apparatus is the network device to which the optical module is plugged; alternatively, the first communication apparatus can be a PHY interface within the network device, and the second communication apparatus is a management chip used to manage the PHY interface, such as the central processing unit (CPU) of the network device.

[0100] It should be noted that the communication devices corresponding to sender 1 and receiver 2 may include or be connected to optical modules. An optical module can be understood as a photoelectric signal conversion device that is directly connected to network equipment. According to whether it is pluggable, optical modules can include pluggable and non-pluggable optical modules. Non-pluggable optical modules can include co-packaged optics (CPO), while pluggable optical modules can include linear-drive pluggable optics (LPO). According to speed, optical modules can include 25G, 100G, 400G, 800G, and 1.6T optical modules. Here, G can be understood as gigabits per second (Gbps), and T can be understood as terabits per second (Tbps). According to distance, optical modules can include short-range (SR) optical modules, long-range (LR) optical modules, extended-range (ER) optical modules, and zoned-range (Zoned) optical modules. Reach (ZR) optical modules and SR optical modules are typically used inside data centers with a transmission distance of 100 to 300 meters; LR optical modules are typically used in metropolitan area networks with a transmission distance of up to 10 kilometers; ER optical modules have a transmission distance of up to 40 kilometers; and ZR optical modules have a transmission distance of up to 80 kilometers or more.

[0101] It should be noted that the optical module may include a processor capable of performing digital signal processing on the bitstream; this processor may include, for example, an oDSP. The optical module may also include: a laser driver (Laser DRV), a laser, a photodiode (PD), and a transimpedance amplifier (TIA).

[0102] For example, the process involved in the embodiments of this application may include, but is not limited to: the second communication device of the sender sending encryption and decryption information (which may include, but is not limited to, IV, encryption key, and encryption key number) to the first communication device of the sender; the first communication device of the sender encrypting the physical layer bitstream using the encryption and decryption information and sending the ciphertext bitstream to the receiver; and the first communication device of the receiver receiving the encryption and decryption information from the second communication device of the receiver decrypting the received ciphertext bitstream to obtain the plaintext bitstream. It should be noted that, on the one hand, the sending party's first communication device can carry part of the encryption / decryption information (such as the IV and encryption key number) in a physical layer-specific location and send it to the receiving party. This physical layer-specific location can be, for example, an Operation Administration and Maintenance (OAM) code block. This part of the encryption / decryption information does not occupy user bandwidth during its transmission from the sending party to the receiving party. This part of the encryption / decryption information can be sent to the receiving party together with the encrypted bit stream, or before sending the encrypted bit stream, or after sending the encrypted bit stream. On the other hand, the receiving party's first communication device can receive the encryption key from the receiving party's second communication device before performing the decryption operation. Combined with the part of the encryption / decryption information (such as the IV and encryption key number) received from the peer, it can prepare in advance for decrypting the received bit stream (such as pre-calculating the decryption string Ek corresponding to Figure 14), making it possible to reduce the latency of the decryption process.

[0103] The following describes two possible implementation methods applicable to the embodiments of this application in conjunction with the accompanying drawings.

[0104] In a first possible implementation, the method provided in this application embodiment can be implemented in an optical module. Figure 4 is a schematic diagram of a network architecture applicable to this application embodiment. Referring to Figure 4, the network architecture 100 may include: a network device 11, an optical module 12, an optical module 22, and a network device 21. Network device 11 is directly connected to optical module 12, and network device 21 is directly connected to optical module 22. Optical module 12 and optical module 22 can be connected via optical fiber. The network device 11 and optical module 12 include an interface 13 for transmitting management data and an interface 14 for transmitting service data. Similarly, the network device 21 and optical module 22 include an interface 23 for transmitting management data and an interface 24 for transmitting service data. Interfaces 13 and 23 can be, for example, IIC; interfaces 14 and 24 can be, for example, SerDes interfaces, XAUI, or CAUI. The term "direct connection" above can refer to a direct connection, meaning that there are no other devices between the optical module and the network device for transmitting or processing the bit stream. For pluggable optical modules, "direct connection" can be understood as the optical module connecting to the network device by inserting it into a specific port; for non-pluggable optical modules, "direct connection" can be understood as the optical module and the switching chip being packaged close together (i.e., the optical module and the switching chip are packaged together in the network device), and the two can be connected by circuitry.

[0105] Corresponding to the network architecture shown in Figure 4, taking a scenario with a data transmission rate of 200G or 400G as an example, as shown in Figure 5, the processing flow of Ethernet data frames by network device 21 can include the following steps S11 to S16: S11, after the frame enters the PHY layer through the MAC layer, it first undergoes 64B / 66B encoding to obtain multiple 66B code blocks, forming a 64B / 66B code block stream; S12, the multiple 66B code blocks undergo 256 / 257B transcoding to obtain multiple 257B code blocks, forming a 256B / 257B code block stream; S13, after the 257B code blocks are scrambled, AM code blocks are inserted. An AM code block can be understood as multiple 257B code blocks. For example, in 200G, the AM code block consists of 4 257B code blocks, and in 400G, the AM code block consists of 8 257B code blocks. For 200G, after inserting AM code blocks, one AM code block (i.e., four consecutive 257B code blocks) can be found in the bitstream every 81,920 257B code blocks; for 400G, one AM code block (i.e., eight consecutive 257B code blocks) can be found in every 163,840 257B code blocks. S14, after inserting AM code blocks, every 20 257B code blocks (i.e., 20 * 257 = 5140 bits) of the bitstream undergoes Reed-Solomon forward error correction (RS-FEC) encoding. For example, RS-FEC(544, 514) encoding can be used. Therefore, the 5140 bits of each code block are encoded using RS-FEC(544, 514) to obtain a 5440-bit FEC codeword. S15, the FEC codeword is distributed to each virtual channel through a distribution process. On each lane (VLane), AM code blocks are periodically distributed to each VLane. Each VLane contains 120 standard-defined bits ("120 standard-defined bits" can be understood as 120 bits with values ​​defined by the standard, such as 120 bits with all values ​​of 0. It should be noted that the values ​​of these 120 standard-defined bits on each VLane can be the same or different); S16, the bit streams on all VLanes are then distributed to interface 14 through a multiplexer (Mux), for example, to multiple SerDes included in interface 14.Next, the processing of the bit stream received from the network device 11 on the optical module 12 may include the following steps S21 to S24: S21 After receiving the bit stream through multiple interfaces 14, it is restored to the bit stream on each VLane by a demultiplexer (Demux); S22, based on the periodic appearance of 120 standard-defined bits on each VLane, AM lock is implemented to determine the boundary; S23, the bit stream between AM code blocks of each VLane is encrypted, while the AM code blocks themselves are not encrypted, resulting in an encrypted bit stream; S24, the encrypted bit stream is transmitted to the network device 21 through optical fiber. It should be noted that the step numbers in this document are designed only for ease of reading and understanding and may not be shown in the accompanying drawings, but can be correlated with the content of the accompanying drawings through textual descriptions.

[0106] The network device 21 and optical module 22, acting as the receiving end, perform the reverse of the encryption process described above. After receiving the bit stream sent by optical module 12, the decryption process performed by optical module 22 may include at least: performing AM lock on the received bit stream and then decrypting it to obtain the decrypted bit stream; and sending the decrypted bit stream to network device 21 through interface 24. After receiving the bit stream from optical module 22 through interface 24, network device 21 may sequentially perform the following processes: AM lock, deskew, recorder, RS-FEC, AM code block removal, and descramble to obtain a frame.

[0107] In this first possible implementation, the optical module may include a first security module in addition to a second security module with encryption and decryption functions. The first security module receives encryption / decryption information (i.e., the information required for encryption or decryption in this embodiment) from the directly connected network device and configures the encryption / decryption information onto the second security module. Taking optical module 12 as an example, the deployment locations of the first and second security modules on the optical module are described.

[0108] As an example, as shown in Figure 6, the optical module 12 may include an MCU 121 and an oDSP 122. The second security module 1 may be deployed on the oDSP 122, and the first security module 2 may be deployed on the MCU 121. The oDSP 122 may also include an iMCU 3. After the first security module 2 on the MCU 121 receives encryption and decryption information from the network device 11 through interface 13, it sends the encryption and decryption information to the oDSP 122. Within the oDSP 122, the encryption and decryption information is configured to the second security module 1 through the iMCU 3.

[0109] As another example, as shown in Figure 7, the difference from Figure 6 is that the first security module 2 can be deployed on the iMCU3 of the oDSP 122. The network device 11 can send encryption and decryption information to the iMCU3 sequentially through interface 13 and MCU 121; the iMCU3 can configure the encryption and decryption information to the second security module 1.

[0110] It should be noted that the deployment location of the first security module 2 can be flexibly determined based on the design of the optical module 12. For example, the deployment location of the first security module 2 can depend on the resource usage of the MCU 121 and iMCU 3 of the optical module 12. If there are more remaining available resources on the MCU 121, the first security module 2 can be deployed on the MCU 121; if there are more remaining available resources on the iMCU 3, the first security module 2 can be deployed on the iMCU 3.

[0111] It should be noted that, in one scenario, after obtaining the encryption / decryption information of the plaintext, the first security module 2 can immediately configure the encryption / decryption information of the plaintext onto the second security module 1; in another scenario, after obtaining the encryption / decryption information, the first security module 2 can first store the encryption / decryption information, and then configure the encryption / decryption information of the plaintext onto the second security module 1 when the configuration conditions are met. This latter scenario is applicable when the first security module 2 obtains the encryption / decryption information but the second security module 1 has not yet started running. The configuration conditions may include, but are not limited to: the first security module 2 receiving a call request from the second security module 1, which is used to request the encryption / decryption information; or, the time for the first security module 2 to obtain or store the encryption / decryption information reaches a preset time threshold; or, the occupancy rate of the storage space on the MCU or iMCU where the first security module 2 resides reaches a preset occupancy rate threshold; or, the first security module 2 recognizing that the second security module 1 has started running.

[0112] In the scenario shown in Figure 6 or Figure 7, the second security module 1 on the oDSP 122 of the optical module 12 can encrypt the bit stream received from the network device 11 through interface 14 using the encryption and decryption information configured above before sending it to the optical module 22. The second security module 1 on the oDSP 122 of the optical module 12 receives the bit stream from the optical module 22 through the optical fiber, decrypts it using the encryption and decryption information configured above, and then sends it to the network device 11 through interface 14.

[0113] In this first possible implementation, the bit stream is encrypted or decrypted at the PMA sublayer of the optical module.

[0114] It is evident that configuring encryption and decryption information into the optical module and having the optical module encrypt and decrypt the bit stream can overcome the technical shortcomings of MACsec encryption and decryption solutions, such as the need to send encryption and decryption related information to the peer, which would consume user bandwidth, and the inability to protect user traffic characteristics.

[0115] In a second possible implementation, the method provided in this application embodiment can be implemented in the PHY interface (also called PHY chip unit) of the network device. Figure 8 is a schematic diagram of another network architecture applicable to this application embodiment. Referring to Figure 8, the network architecture 200 may include: network device 31 and network device 41. Network device 31 and network device 41 can be connected via optical modules or electrical connections; this application embodiment does not limit this connection. If connected via optical modules, the optical modules can be optical modules including oDSP or optical modules not including oDSP (e.g., LPO). Network device 31 may include a management chip 311 and a PHY interface 312. Similarly, network device 41 may include a management chip 411 and a PHY interface 412. The management chip 311 and PHY interface 312 can be connected, for example, via an MDIO interface 313, and the management chip 411 and PHY interface 412 can be connected, for example, via an MDIO interface 413. The term "direct connection" in the text above can refer to a direct connection, meaning that there is no other device between the PHY interface and the management chip for transmitting or processing the bit stream.

[0116] Corresponding to the network architecture shown in Figure 8, taking a data transmission rate of 200G or 400G as an example, as shown in Figure 9, the processing flow of the frame by the network device 31 can include the following S41 to S46: S41, after the frame enters the PHY layer through the MAC layer, it is first encoded by 64B / 66B to become multiple 66B code blocks; S42, the 66B code blocks are transcoded by 256 / 257B to become multiple 257B code blocks; S43, after the 257B code blocks are scrambled, AM code blocks are inserted; S44, after the bit stream is inserted by AM code blocks, every 20 257B code blocks are grouped together and enter RS-FEC(544,514) encoding to become 5440-bit FEC codewords; S45, the FEC codewords are distributed to each VLane through the distribution process; S46, the PHY interface 312 performs the encryption operation provided in this application embodiment to obtain the encrypted bit stream and sends the encrypted bit stream to the network device 41.

[0117] Network device 41, acting as the receiving end, performs the reverse of the encryption process described above. After receiving the encrypted bitstream, the decryption process performed by network device 41 can at least include: performing AM lock on the received bitstream and then decrypting it to obtain the decrypted bitstream. After obtaining the decrypted bitstream, network device 41 can sequentially perform processes such as Deskew, Recorder, RS-FEC, AM code block removal, and Descramble to obtain a frame.

[0118] In this second possible implementation, the PHY interface may include a first security module in addition to a second security module with encryption and decryption functions. This first security module receives encryption and decryption information from the management chip of the network device and configures the encryption and decryption information onto the second security module. Taking PHY interface 312 as an example, the deployment locations of the first and second security modules on the PHY interface are described.

[0119] As an example, as shown in Figure 10, the PHY interface 312 may include a control unit a1 and a PHY chip b1. The second security module 1 may be deployed on the PHY chip b1, and the first security module 2 may be deployed on the control unit a1. After receiving encryption and decryption information from the management chip 311 through the MDIO interface, the first security module 2 on the control unit a1 configures the encryption and decryption information to the second security module 1 on the PHY chip b1.

[0120] It should be noted that the timing of when the first security module 2 configures the plaintext encryption and decryption information to the second security module 1 can be found in the corresponding description in the first possible implementation.

[0121] In the scenario shown in Figure 10, the second security module 1 on PHY chip b1 can encrypt the bit stream received from management chip 311 via MII or xMII using the encryption / decryption information configured above before sending it to network device 41. Similarly, the second security module 1 on PHY chip b1 can decrypt the bit stream received from network device 41 using the encryption / decryption information configured above before sending it to management chip 311 via MII or xMII. It should be noted that Figure 8 only shows the MDIO interface between the management chip and the PHY interface; the service data interface used for transmitting bit streams between the management chip and the PHY interface is not shown. This service data interface could be, for example, MII or xMII.

[0122] In this second possible implementation, the bit stream is encrypted or decrypted at the PCS of the network device.

[0123] As can be seen, the network device's management chip configures encryption and decryption information to the PHY interface, which then encrypts and decrypts the bit stream. This overcomes the technical shortcomings of MACsec, such as avoiding the problem of bandwidth consumption when transmitting encryption and decryption related information between the sender and receiver while ensuring network security.

[0124] To provide a clearer description of the embodiments of this application, the method 100 provided in the embodiments of this application will be described below with reference to the accompanying drawings.

[0125] Figure 11 is a schematic flowchart of a data transmission method 100 provided in an embodiment of this application. In this method 100, the interaction between a first communication device and a second communication device is used to illustrate the embodiment of this application. The first communication device and the second communication device are directly connected. The first communication device may be, for example, the optical module 12 or optical module 22 shown in Figure 1, or the PHY interface 312 or PHY interface 412 shown in Figure 8; correspondingly, the second communication device may be, for example, the network device 11 or network device 21 shown in Figure 4, or the management chip 311 or management chip 411 shown in Figure 8.

[0126] As shown in Figure 11, the method 100 may include, for example, the following steps S301 to S303:

[0127] S301, the second communication device sends encryption / decryption information to the first communication device.

[0128] S302, the first communication device receives encryption / decryption information sent by the second communication device.

[0129] Encryption / decryption information can be understood as information obtained by the second communication device and required by the first communication device to encrypt or decrypt the bit stream. The specific content of the encryption / decryption information is determined by the encryption algorithm used; different encryption algorithms may correspond to different encryption / decryption information.

[0130] Encryption algorithms can be divided into symmetric encryption algorithms and asymmetric encryption algorithms. Symmetric encryption algorithms are those that use the same key for both encryption and decryption; examples include, but are not limited to, AES and SM4. Asymmetric encryption algorithms are those that use different keys for encryption and decryption; examples include, but are not limited to, RSA (Rivest-Shamir-Adleman), Elliptic Curve Cryptography (ECC), and Diffie-Hellman (Whitfield-Diffie-Martin Hellman).

[0131] It should be noted that in the embodiments of this application, the first communication device encrypts or decrypts the bit stream, typically using a symmetric encryption algorithm.

[0132] As an example, encryption / decryption information may include, but is not limited to, at least one of the following: encryption key, IV, or encryption key number. The encryption key may consist of at least two sets, and the type of encryption key may be, for example, SAK. The encryption key number indicates the encryption key used in the at least two sets of encryption keys. For example, a first communication device sends two sets of encryption keys to a second communication device: encryption key a and encryption key b, configuring encryption key a with encryption key number 1 and encryption key b with encryption key number 2. If the encryption / decryption information sent by the second communication device to the first communication device includes at least: encryption key a, encryption key b, and encryption key number 1, the first communication device, based on this encryption / decryption information, determines to use encryption key a indicated by encryption key number 1 for encryption or decryption, with encryption key b as a backup encryption key. It should be noted that the first communication device may also send the encryption key number as a specific field of a multiframe to the peer, so that the peer can obtain the encryption key number from the multiframe (i.e., AM code block), and thus know to successfully decrypt using the same encryption key as the sender to obtain the decrypted bit stream. The IV is a security parameter input to the encryption algorithm along with the encryption key.

[0133] Optionally, to improve the security of the encryption / decryption information transmitted between the second and first communication devices, the encryption / decryption information can be encrypted and transmitted as ciphertext. In this case, the encryption / decryption information may also include a working key, which is used to encrypt and decrypt the encryption key. The working key can be, for example, a key encrypting key (KEK), used to encrypt and decrypt the SAK. It should be noted that the roles of each part of the encryption / decryption information in the encryption and decryption process of the bit stream are detailed in the relevant description in Figure 14.

[0134] In one scenario, the second communication device can send encrypted / decrypted information in plaintext form to the first communication device. That is, the encrypted / decrypted information in S301 and S302 refers to encrypted / decrypted information in plaintext form. This scenario can also be referred to as the plaintext mode for transmitting encrypted / decrypted information. In another scenario, to improve the security of encrypted / decrypted information transmission between the second and first communication devices, the second communication device can encrypt the plaintext encrypted / decrypted information and send the resulting ciphertext encrypted / decrypted information to the first communication device. The first communication device decrypts the ciphertext encrypted / decrypted information and configures the resulting plaintext encrypted / decrypted information to perform encryption and decryption operations on the bit stream. That is, the encrypted / decrypted information in S301 and S302 refers to encrypted / decrypted information in ciphertext form. This scenario can also be referred to as the ciphertext mode for transmitting encrypted / decrypted information.

[0135] It should be noted that whether S301 and S302 use plaintext mode or ciphertext mode, it does not affect the format of the message used to carry encryption and decryption information sent by the second communication device to the first communication device, or the interface for exchanging encryption and decryption information between the second communication device and the first communication device.

[0136] The second communication device sends a message carrying encryption / decryption information to the first communication device, conforming to the Common Management Interface Specification (CMIS) 5.0 standard. Taking the first communication device as a network device and the second communication device as an optical module as an example, the message format can be "device address + register address + data". For the "device address", since network devices have many ports and can connect dozens or hundreds of optical modules simultaneously, the "device address" is used to distinguish which specific optical module is being connected. The "register address" is used to distinguish the information type. Reserved register addresses can be used to carry encryption / decryption information such as IVs and encryption keys. Different contents in the encryption / decryption information can correspond to one or more reserved register addresses in CMIS 5.0. The specific use of reserved register addresses in CMIS 5.0 to carry encryption / decryption information can be flexibly designed according to requirements. The "data" is used to carry the specific content of the encryption / decryption information.

[0137] Corresponding to the first possible implementation above, that is, the second communication device is a network device and the first communication device is an optical module directly connected to the network device, then the second communication device can send encryption and decryption information to the first communication device through IIC, and the first communication device can receive the encryption and decryption information through IIC.

[0138] Corresponding to the second possible implementation above, that is, the second communication device is the management chip of the network device, and the first communication device is any PHY interface managed by the management chip. In this case, the second communication device can send encryption and decryption information to the first communication device through the MDIO interface, and the first communication device can receive the encryption and decryption information through the MDIO interface.

[0139] In some implementations, the first and second communication devices can transmit encrypted and decrypted information in plaintext mode (also known as unencrypted mode) or ciphertext mode (also known as encrypted mode). To ensure that the first and second communication devices can use the same mode, they can also obtain indication information, which indicates whether the encrypted or decrypted information is in plaintext or ciphertext mode. The first and second communication devices can obtain the indication information through negotiation or configuration by other communication devices such as controllers. If the indication information is carried in the message carrying the encrypted and decrypted information, it can also be obtained by parsing the message. This application does not specifically limit the implementation.

[0140] For example, as shown in Figure 12, the process of transmitting encryption / decryption information between the second communication device and the first communication device may include: S51, after the second communication device obtains the encryption / decryption information in plaintext form, it determines whether the encryption / decryption information needs to be encrypted based on the mode indicated by the indication information. If so, it executes S52; otherwise, it executes S54; S52, the second communication device encrypts the encryption / decryption information in plaintext form to obtain encryption / decryption information in ciphertext form; S53, the second communication device sends the encryption / decryption information in ciphertext form to the first communication device; S54, the second communication device... The first communication device sends the encrypted / decrypted information in plaintext mode to the first communication device; S55, after receiving the encrypted / decrypted information, the first communication device determines whether the received encrypted / decrypted information is in plaintext mode or ciphertext mode based on the mode indicated by the instruction information. If it is in ciphertext mode, then execute S56; if it is in plaintext mode, then execute S57; S56, the first communication device decrypts the encrypted / decrypted information in ciphertext form to obtain the encrypted / decrypted information in plaintext form; S57, the first communication device configures the encrypted / decrypted information in plaintext form onto the security module with encryption / decryption function (corresponding to the second security module mentioned above). It should be noted that S51 to S54 above can be understood as the operations performed by the first security module on the second communication device, and S55 to S57 above can be understood as the operations performed by the first security module on the first communication device.

[0141] In ciphertext mode, the second communication device encrypts the plaintext encrypted / decrypted information, and the first communication device decrypts the ciphertext encrypted / decrypted information. Symmetric or asymmetric encryption algorithms can be used, and this application embodiment does not impose specific limitations. If a symmetric encryption algorithm is used, the second communication device needs to configure a working key with the first communication device. Taking SAK as the encryption key and KEK as the working key as an example, after sending KEK to the first communication device, the second communication device encrypts the SAK using KEK and sends the encrypted SAK to the first communication device. The first communication device decrypts the encrypted SAK based on KEK to obtain the plaintext SAK, which is then used for subsequent encryption or decryption of the bitstream. If an asymmetric encryption algorithm is used, the first communication device will have a set of public and private keys. The second communication device can also obtain the public key (which may be actively sent to the second communication device by the first communication device, or sent to the second communication device by the first communication device in response to the second communication device reading). The second communication device uses the public key and the asymmetric encryption algorithm to encrypt the SAK. The encrypted SAK is sent to the first communication device. The first communication device uses the same asymmetric encryption algorithm and its internal private key to decrypt the encrypted SAK to obtain the plaintext SAK, which can then be used for subsequent encryption or decryption of the bit stream.

[0142] For example, in encrypted mode, as shown in Figure 13, the process of the second communication device sending encryption / decryption information to the first communication device can include the following steps: S61, the second communication device derives KEK and SAK based on the Connectivity Association Key (CAK); S62, the second communication device sends the SAK to the receiver through a key negotiation protocol. The process of the sender sending the SAK to the receiver through the key negotiation protocol can be implemented by the negotiation modules of the sender and the receiver; S63, the second communication device encrypts the SAK using the KEK to obtain the encrypted SAK; S64, the second communication device sends the KEK and the encrypted SAK to the first communication device via IIC; S65, the first communication device decrypts the encrypted SAK based on the KEK to obtain the plaintext SAK. For the receiver, the process of the second communication device sending encryption / decryption information to the first communication device may include: S71, the second communication device derives KEK based on CAK and receives SAK from the sender; S72, the second communication device encrypts the SAK using KEK to obtain an encrypted SAK; S73, the second communication device sends the KEK and the encrypted SAK to the first communication device via IIC; S74, the first communication device decrypts the encrypted SAK based on KEK to obtain the plaintext SAK. It should be noted that the KEK can be configured by the second communication device after each power-on, while the SAK needs to be updated based on a preset update cycle (e.g., every 2 hours), updating every few hours.

[0143] It is evident that the first communication device receives encryption / decryption information from the second communication device, thus preparing the first communication device to encrypt or decrypt the bit stream transmitted at the physical layer.

[0144] S303, the first communication device uses encryption and decryption information to encrypt or decrypt the first bit stream of the physical layer to obtain the second bit stream.

[0145] Before S303, the method 100 may further include: S304, the first communication device obtains the first bit stream.

[0146] Optionally, after S303, the method 100 may further include: S305, the first communication device sends a second bit stream.

[0147] As an example, the role of the first communication device can be that of the sender. In this case, S303 may include, for example, the first communication device encrypting the first bit stream of the physical layer using encryption and decryption information to obtain the second bit stream; S305 may include, for example, the first communication device sending the second bit stream to a fourth communication device, which can be understood as the network device or optical module of the receiver.

[0148] In one scenario, the first communication device is an optical module. In this case, step S304 may include: the first communication device receiving a third bitstream from the second communication device, detecting AM code blocks from the third bitstream, and obtaining a first bitstream based on the detected AM code blocks. For example, the first communication device may detect AM code blocks in the bitstream received from the second communication device based on an AM lock process. If the detected AM code blocks conform to a preset rule, the delimitation is considered successful, and the data code blocks between adjacent AM code blocks are recorded as the first bitstream. The encryption process provided in this application embodiment is then executed. In this case, step S303 may include: the first communication device encrypting the first bitstream of the PMA sublayer using encryption / decryption information to obtain a second bitstream. It should be noted that the first communication device receives the third bit stream from the second communication device through the service data interface between the first and second communication devices. This service data interface can be any one of the following types of interfaces: SerDes interface, XAUI, CAUI, MII, or xMII. Among them, the SerDes interface is an interface used for high-speed data transmission between the second and first communication devices, which can convert parallel signals into serial signals for transmission; XAUI and CAUI are parallel interfaces used for medium- and low-speed data transmission between the second and first communication devices; MII and xMII can correspond to the second possible implementation mentioned above.

[0149] In another scenario, the first communication device may be a PHY interface. In this case, S304 may include, for example, the first communication device receiving a first bit stream from the second communication device, wherein the first bit stream is a bit stream after the insertion of AM code blocks. In this case, S303 may include, for example, the first communication device encrypting the first bit stream of PCS using encryption / decryption information to obtain a second bit stream.

[0150] As another example, the role of the first communication device can be that of a receiver. In this case, S304 may include, for example, the first communication device obtaining a first bit stream from a third communication device, which can be understood as a network device or optical module of the sender; S303 may include, for example, the first communication device decrypting the first bit stream of the physical layer using encryption and decryption information to obtain a second bit stream; S305 may include, for example, the first communication device sending the second bit stream to the second communication device.

[0151] In one scenario, if the first communication device is an optical module, then S304 may include, for example, the first communication device receiving a first bit stream from a third communication device. In this case, S303 may include, for example, the first communication device decrypting the first bit stream of the PMA sublayer using encryption / decryption information to obtain a second bit stream. S305 may include, for example, the first communication device sending the second bit stream to the second communication device through a service data interface.

[0152] In another scenario, the first communication device may be a PHY interface. In this case, S304 may include, for example, the first communication device receiving a third bit stream from the second communication device, detecting AM code blocks from the third bit stream, and obtaining a first bit stream based on the detected AM code blocks. For instance, the first communication device may detect AM code blocks in the bit stream received from the second communication device based on an AM lock process. If the detected AM code blocks conform to a preset rule, the delimitation is considered successful, and the data code blocks between adjacent AM code blocks are recorded as the first bit stream. The decryption process provided in this application embodiment is then executed. In this case, S303 may include, for example, the first communication device decrypting the first bit stream of the PCS using encryption and decryption information to obtain a second bit stream.

[0153] For example, referring to Figure 14, the specific processes of encryption and decryption by the sender and receiver in this embodiment of the application are explained. As shown in Figure 14, both the encryption process performed by the sender and the decryption process performed by the receiver involve a counter, an IV, and an encryption key. The counter can be understood as the count value of a counter maintained on the first communication device (such as the oDSP chip of the optical module), with a length of 32 bits. The value of the counter is automatically incremented by one for each 128-bit bit stream encrypted or decrypted.

[0154] As shown in Figure 14, the process by which the sender encrypts the first bitstream in plaintext using encryption and decryption information can include: the first communication device takes the IV and counter as one set of inputs to the encryption algorithm, and the encryption key as another set of data for the encryption algorithm. After processing by the encryption algorithm, a 128-bit encrypted string (denoted as Ek in Figure 14) is output; then, the first communication device performs an XOR operation (denoted as ⊕ in Figure 14) on Ek and the 128-bit plaintext first bitstream to obtain the second bitstream in ciphertext; finally, the first communication device sends the second bitstream in ciphertext to the receiver. The IV is transmitted to the receiver through the frame header of the multiframe.

[0155] As shown in Figure 14, the process by which the receiver decrypts the second bit stream in ciphertext form using encryption and decryption information can include: after the first communication device parses the IV from the frame header of the received multiframe, similar to the encryption at the sending end, the IV and counter are used as one set of inputs to the encryption key, and the encryption key is used as another set of inputs to the encryption algorithm. After processing by the encryption algorithm, a 128-bit decryption string (also denoted as Ek in Figure 14) is output; then, the first communication device performs an XOR operation on the second bit stream in ciphertext form and Ek to obtain the first bit stream in plaintext form.

[0156] It should be noted that IV and counter can be collectively referred to as encryption material on the sender and decryption material on the receiver; the format can be written as (IVn-1[95:0]||counter[31:0]), where IVn-1 can refer to the IV corresponding to the next round of multiframe encryption or decryption of IVn.

[0157] It should be noted that the sender and receiver use the same encryption algorithm, the same encryption key and IV, and the same counter (AM lock can ensure the synchronization of the sender and receiver counters). Therefore, the encrypted and decrypted strings obtained by the sender and receiver will definitely be the same. The sender performs an XOR operation on the encrypted string and the first bit stream to obtain the second bit stream, and the receiver performs an XOR operation on the second bit stream and the decrypted string to recover the first bit stream.

[0158] It should be noted that the encryption and decryption operations in the embodiments of this application can be called PHYsec. Specifically, it can be implemented by a PHYsec chip or by other second security modules with corresponding encryption and decryption functions. For example, it can also be implemented by a MACsec chip. For example, the first bit stream is converted into Ethernet data frame 1, Ethernet data frame 1 is MACseced to obtain encrypted Ethernet data frame 2, and then Ethernet data frame 2 is converted into the second bit stream.

[0159] In some implementations, as shown in Figure 15, before S301, the method 100 may also include: a cryptographic capability query and initialization stage, an identity authentication stage, and a key negotiation stage, with S301 to S303 corresponding to data encryption and decryption stages.

[0160] As shown in Figure 15, the encryption capability query and initialization phase can be understood as follows: The second communication device obtains the encryption specification information of the first communication device by calling the driver interface. If the return of encryption specification information fails, the process terminates. If the return of encryption specification information succeeds, the second communication device determines whether the first communication device has encryption capability. If the first communication device does not support encryption (i.e., does not have encryption capability), the process terminates. If the first communication device supports encryption (i.e. has encryption capability), it notifies the peer of the encryption capability and negotiates the encryption method. The second communication device will perform the relevant configuration for encryption initialization based on the negotiation result of the encryption method.

[0161] The process of the second communication device querying the encryption capability of the first communication device may include, for example, the second communication device sending a query read command to the first communication device to query its encryption capability; after receiving the query read command, the first communication device sends a response message to the second communication device, thereby the second communication device receiving the response message, which includes encryption specification information of the first communication device. This encryption specification information indicates the encryption capability of the first communication device and may include at least one of the following: whether it supports a physical layer security protocol (PHYsec), the supported encryption rate, the supported encryption algorithm, or the supported key mode. Whether it supports PHYsec can be understood as whether the first communication device has the ability to use PHYsec for encryption and decryption; the supported encryption rate can be understood as the specific PHYsec rate supported by the first communication device; the supported encryption algorithm may include, but is not limited to, AES and SM4; the supported key mode may indicate the length of the encryption key, for example, 256 bits or 128 bits.

[0162] Taking the first communication device as an optical module as an example, the second communication device interacts with the first communication device via IIC to query read commands and response messages, following the CMIS 5.0 standard. The message format is detailed in the aforementioned description of the CMIS 5.0 message format. The first communication device internally reserves specific register addresses according to the CMIS 5.0 standard to store its own encryption specification information. When the second communication device queries the encryption capabilities of the first communication device, the first communication device can report the contents of the registers indicated by these reserved register addresses (i.e., the aforementioned encryption specification information) to the second communication device via IIC.

[0163] As shown in Figure 15, the identity authentication phase can be understood as follows: the sender and receiver exchange authentication information to perform two-way identity authentication. If the authentication is successful, the next phase (such as the key negotiation phase) is carried out. The identity authentication mechanism mainly ensures that both parties communicating with each other have legitimate identities.

[0164] As shown in Figure 15, the key negotiation phase can be understood as: ensuring that both communicating parties negotiate the same encryption key and being responsible for updating and switching the key during encryption and decryption. Once the key negotiation is complete, the two communicating parties establish a secure channel. For example, taking the first communication device as an optical module and the second communication device as a network device, this process may include: S81, the first communication device sends a message to the second communication device indicating successful multiframe locking and synchronization; S82, the second communication device negotiates a consistent encryption key with the peer network device; S83, the second communication device sends encryption / decryption information to the first communication device; S84, the first communication device installs the encryption key from the encryption / decryption information; S85, the first communication device returns a message to the second communication device indicating successful installation and configuration; S86, the second communication device configures decryption enable to the first communication device; S87, the first communication device returns a message to the second communication device indicating successful decryption enable configuration; S88, the second communication device and the peer network device mutually announce the encryption key and decryption enable preparation completion; S89, the second communication device configures encryption enable to the first communication device.

[0165] As can be seen, through this method 100, the second communication device configures encryption / decryption information onto the first communication device, enabling the first communication device to encrypt or decrypt the bitstream transmitted at the physical layer. This eliminates the need to add encryption / decryption related information to the end-to-end user data, avoiding the consumption of user bandwidth by adding such information. It overcomes the problems of high resource cost, bandwidth overhead and latency, high power consumption, high hardware implementation cost, and inability to guarantee the security of all user data transmissions inherent in MACsec. Furthermore, by encrypting or decrypting the bitstream at the physical layer, all bits after the Ethernet data frame conversion are encrypted and decrypted. Compared to MACsec, which encrypts and decrypts only information other than address information in the Ethernet data frame, this avoids the risk of address information exposure, resulting in higher security.

[0166] Accordingly, this application also provides a first communication device 1600, as shown in FIG16. The device 1600 may include, for example, a transceiver unit 1601 and a processing unit 1602.

[0167] The transceiver unit 1601 is used to receive encryption and decryption information sent by the second communication device. The first communication device and the second communication device are directly connected. The function of the transceiver unit 1601 corresponds to the relevant description of S302 in Figure 11.

[0168] Processing unit 1602 is used to encrypt or decrypt the first bit stream of the physical layer using encryption / decryption information to obtain the second bit stream. The function of processing unit 1602 corresponds to the relevant description of S303 in Figure 11.

[0169] In some possible implementations, the first communication device 1600 is an optical module.

[0170] As an example, the MCU of the optical module, or the iMCU of the oDSP chip of the optical module, includes a security module for receiving encryption and decryption information.

[0171] As an example, processing unit 1602 is specifically used to: encrypt or decrypt the first bit stream of the PMA sublayer using encryption and decryption information to obtain the second bit stream.

[0172] As an example, transceiver unit 1601 is specifically used to receive encryption and decryption information sent by the second communication device from the IIC.

[0173] As an example, transceiver unit 1601 is further configured to receive a third bit stream from the second communication device; processing unit 1602 is further configured to detect AM code blocks from the third bit stream and obtain a first bit stream based on the detected AM code blocks. Specifically, processing unit 1602 is configured to: encrypt the first bit stream using encryption / decryption information to obtain a second bit stream.

[0174] As another example, transceiver unit 1601 is also used to receive a first bit stream from a third communication device. Then, processing unit 1602 is specifically used to: decrypt the first bit stream using encryption / decryption information to obtain a second bit stream.

[0175] In some other possible implementations, the first communication device 1600 is a physical layer PHY interface.

[0176] As an example, the control unit of the PHY interface includes a security module for receiving encrypted and decrypted information.

[0177] As an example, processing unit 1602 is specifically used to: encrypt or decrypt the first bit stream of PCS using encryption / decryption information to obtain the second bit stream.

[0178] As an example, transceiver unit 1601 is specifically used to receive encryption and decryption information sent by a second communication device from the MDIO interface.

[0179] As an example, transceiver unit 1601 is also configured to receive a first bit stream from a second communication device, the first bit stream being a bit stream obtained based on an already inserted AM code block. Then, processing unit 1602 is specifically configured to: encrypt the first bit stream using encryption / decryption information to obtain a second bit stream.

[0180] As another example, the transceiver unit 1601 is further configured to receive a third bit stream from a third communication device; the processing unit 1602 is further configured to detect AM code blocks from the third bit stream and obtain a first bit stream based on the detected AM code blocks. Specifically, the processing unit 1602 is configured to: decrypt the first bit stream using encryption / decryption information to obtain a second bit stream.

[0181] In some possible implementations, the encrypted / decrypted information is in plaintext.

[0182] In some other possible implementations, the encryption / decryption information is ciphertext, and the processing unit 1602 is specifically used to: decrypt the received encryption / decryption information to obtain the decrypted encryption / decryption information; and use the decrypted encryption / decryption information to encrypt or decrypt the first bit stream to obtain the second bit stream.

[0183] In some possible implementations, the encryption / decryption information includes at least one of the following: encryption key, IV, or encryption key number.

[0184] In some possible implementations, the device 1600 may further include an acquisition unit. This acquisition unit is used to acquire indication information, which indicates the plaintext or ciphertext mode of the encrypted / decrypted information.

[0185] In some possible implementations, the transceiver unit 1601 is also used to receive a first bit stream from a service data interface, which is any one of the following types of interfaces: SerDes interface, XAUI, CAUI, MII, or xMII.

[0186] In some possible implementations, the transceiver unit 1601 is further configured to receive a query read instruction sent by the second communication device, the query read instruction being used to query the encryption capability of the first communication device; the transceiver unit 1601 is further configured to send a response message to the second communication device, the response message including encryption specification information of the first communication device, the encryption specification information being used to indicate the encryption capability of the first communication device, the encryption specification information including at least one of the following: whether PHYsec is supported, the supported encryption rate, the supported encryption algorithm, or the supported key mode.

[0187] It should be noted that for relevant descriptions of the device 1600, please refer to the description of the first communication device execution step in method 100.

[0188] Accordingly, this application also provides a second communication device 1700, as shown in FIG17. The device 1700 may include, for example, a transceiver unit 1701.

[0189] The transceiver unit 1701 is used to send encryption / decryption information to the first communication device, which is directly connected to the second communication device. The encryption / decryption information is used by the first communication device to encrypt or decrypt the bit stream at the physical layer. The function of the transceiver unit 1701 corresponds to the relevant description of S301 in Figure 11.

[0190] The transceiver unit 1701 is also used to transmit bit streams with the first communication device. The function of the transceiver unit 1701 corresponds to the relevant descriptions of S304 or S305 in Figure 11.

[0191] In some possible implementations, the encryption / decryption information is plaintext; or, if the encryption / decryption information is ciphertext, then the encryption / decryption information sent to the first communication device is the encrypted encryption / decryption information.

[0192] In some possible implementations, the device 1700 may further include an acquisition unit 1702. The acquisition unit 1702 is used to acquire indication information, which indicates whether the encrypted / decrypted information is in plaintext mode or ciphertext mode.

[0193] In some possible implementations, the first communication device is an optical module and the second communication device 1700 is a network device; or, the first communication device is the PHY interface of the network device and the second communication device 1700 is the management chip of the network device, the management chip being used to manage the PHY interface.

[0194] In some possible implementations, the transceiver unit 1701 is specifically used to: send a first bit stream to the first communication device, and the encryption / decryption information is used by the first communication device to encrypt the first bit stream.

[0195] In some other possible implementations, the transceiver unit 1701 is specifically used to: receive a second bit stream sent by the first communication device, wherein the second bit stream is obtained by the first communication device decrypting the bit stream received from the third communication device using encryption and decryption information.

[0196] In some possible implementations, the transceiver unit 1701 is further configured to send a query read instruction to the first communication device, the query read instruction being used to query the encryption capability of the first communication device; the transceiver unit 1701 is further configured to receive a response message sent by the first communication device, the response message including encryption specification information of the first communication device, the encryption specification information being used to indicate the encryption capability of the first communication device, the encryption specification information including at least one of the following: whether PHYsec is supported, the supported encryption rate, the supported encryption algorithm, or the supported key mode.

[0197] It should be noted that for relevant descriptions of the device 1700, please refer to the description of the second communication device execution steps in method 100.

[0198] Furthermore, this application embodiment also provides a communication system 1800, as shown in FIG18. The communication system 1800 may include a first communication device 1801 and a second communication device 1802. Corresponding to method 100, the first communication device 1801 is used to implement the steps performed by the first communication device in method 100; the second communication device 1802 is used to implement the steps performed by the second communication device in method 100.

[0199] As an example, the communication system 1800 may also include a third communication device 1803, which is connected to the second communication device 1802 via the first communication device 1801.

[0200] Accordingly, this application also provides a communication device 1900, as shown in FIG19. The communication device 1900 includes a processor 1901 and a memory 1902; the processor 1901 is used to execute instructions stored in the memory 1902 so that the communication device 1900 implements the method provided in this application embodiment.

[0201] Accordingly, this application also provides a communication device, which includes an interface and a processor; the interface is used to receive instructions and transmit them to the processor; the processor is used to implement the method provided in this application.

[0202] Accordingly, this application provides a chip 2000, as shown in FIG20. The chip 2000 includes an interface circuit 2001 and a processing circuit 2002, with the interface circuit 2001 connected to the processing circuit 2002. The interface circuit 2001 is used to execute the receiving and transmitting operations in the method provided in this application embodiment; the processing circuit 2002 is used to execute other operations in the method provided in this application embodiment besides the receiving and transmitting operations.

[0203] It should be noted that the modules or units with corresponding functions in the above communication device can be understood as interchangeable. For example, transceiver unit 1601 and transceiver unit 1701 can correspond to interface circuit 2001; processing unit 1602 can correspond to processor 1901 or processing circuit 2002.

[0204] Furthermore, this application embodiment also provides a storage medium storing program code or instructions, which, when run on a processor, cause the processor to execute the method under any of the above embodiments.

[0205] Furthermore, this application also provides a program product that, when run on a processor, causes the processor to execute the method under any of the aforementioned implementations.

[0206] It should be understood that "determining B based on A" mentioned in the embodiments of this application does not mean determining B solely based on A, but also determining B based on A and / or other information.

[0207] It should be understood that the network architecture and business scenarios described in the embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.

[0208] In this application, ordinal numbers such as “1”, “2”, “3”, “first”, “second”, and “third” are used to distinguish multiple objects, not to limit the order of multiple objects.

[0209] The reference to "A and / or B" in this application should be understood to include the following situations: including only A, including only B, or including both A and B.

[0210] As can be seen from the above description of the embodiments, those skilled in the art can clearly understand that all or part of the steps in the methods of the above embodiments can be implemented by means of software plus a general-purpose hardware platform. Based on this understanding, the technical solution of this application can be embodied in the form of a software product. This computer software product can be stored in a storage medium, such as a read-only memory (ROM) / RAM, magnetic disk, optical disk, etc., including several instructions to cause a computer device (which may be a personal computer, a server, or a network communication device such as a router) to execute the methods described in various embodiments or some parts of the embodiments of this application.

[0211] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the system and device embodiments are basically similar to the method embodiments, so the descriptions are relatively simple; relevant parts can be referred to the descriptions in the method embodiments. The device and system embodiments described above are merely illustrative. Modules described as separate components may or may not be physically separate, and components shown as modules may or may not be physical modules; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without creative effort.

[0212] The above description is merely a preferred embodiment of this application and is not intended to limit the scope of protection of this application. It should be noted that those skilled in the art can make various improvements and modifications without departing from this application, and these improvements and modifications should also be considered within the scope of protection of this application.

Claims

1. A data transmission method, characterized in that, Applied to a first communication device, the method includes: The first communication device receives encryption and decryption information sent by the second communication device, and the first communication device is directly connected to the second communication device. The encryption / decryption information is used to encrypt or decrypt the first bit stream of the physical layer to obtain the second bit stream.

2. The method according to claim 1, characterized in that, The first communication device is an optical module.

3. The method according to claim 2, characterized in that, The microcontroller unit (MCU) of the optical module, or the internal microcontroller unit (iMCU) of the optical digital signal processor (oDSP) chip of the optical module, includes a security module for receiving the encryption and decryption information.

4. The method according to claim 2 or 3, characterized in that, The step of encrypting or decrypting the first bitstream at the physical layer using the encryption / decryption information to obtain the second bitstream includes: The encryption / decryption information is used to encrypt or decrypt the first bit stream of the Physical Medium Attachment (PMA) sublayer to obtain the second bit stream.

5. The method according to any one of claims 2-4, characterized in that, The receipt of encryption / decryption information sent by the second communication device includes: The encryption / decryption information sent by the second communication device is received from the internal integrated circuit bus (IIC).

6. The method according to any one of claims 2-5, characterized in that, The method further includes: Receive a third bit stream from the second communication device; Alignment identifier AM code blocks are detected from the third bit stream, and the first bit stream is obtained based on the detected AM code blocks; The step of encrypting or decrypting the first bitstream at the physical layer using the encryption / decryption information to obtain the second bitstream includes: The first bitstream is encrypted using the encryption / decryption information to obtain the second bitstream.

7. The method according to any one of claims 2-5, characterized in that, The method further includes: Receive the first bit stream from the third communication device; The step of encrypting or decrypting the first bitstream at the physical layer using the encryption / decryption information to obtain the second bitstream includes: The first bitstream is decrypted using the encryption / decryption information to obtain the second bitstream.

8. The method according to claim 1, characterized in that, The first communication device is a physical layer PHY interface.

9. The method according to claim 8, characterized in that, The control unit of the PHY interface includes a security module for receiving the encryption and decryption information.

10. The method according to claim 8 or 9, characterized in that, The step of encrypting or decrypting the first bitstream at the physical layer using the encryption / decryption information to obtain the second bitstream includes: The encryption / decryption information is used to encrypt or decrypt the first bit stream of the Physical Coding Sublayer (PCS) to obtain the second bit stream.

11. The method according to any one of claims 8-10, characterized in that, The receipt of encryption / decryption information sent by the second communication device includes: The encryption / decryption information sent by the second communication device is received from the Management Data Input / Output (MDIO) interface.

12. The method according to any one of claims 8-11, characterized in that, The method further includes: The first bit stream is received from the second communication device, wherein the first bit stream is a bit stream obtained based on the inserted AM code block; The step of encrypting or decrypting the first bitstream at the physical layer using the encryption / decryption information to obtain the second bitstream includes: The first bitstream is encrypted using the encryption / decryption information to obtain the second bitstream.

13. The method according to any one of claims 8-11, characterized in that, The method further includes: Receive a third bit stream from a third communication device; Detect AM code blocks from the third bit stream, and obtain the first bit stream based on the detected AM code blocks; The step of encrypting or decrypting the first bitstream at the physical layer using the encryption / decryption information to obtain the second bitstream includes: The first bitstream is decrypted using the encryption / decryption information to obtain the second bitstream.

14. The method according to any one of claims 1-13, characterized in that, The encrypted / decrypted information is in plaintext.

15. The method according to any one of claims 1-13, characterized in that, The encryption / decryption information is ciphertext. The step of using the encryption / decryption information to encrypt or decrypt the first bitstream at the physical layer to obtain the second bitstream includes: The received encrypted and decrypted information is decrypted to obtain the decrypted encrypted and decrypted information; The first bitstream is encrypted or decrypted using the decrypted information to obtain the second bitstream.

16. The method according to any one of claims 1-15, characterized in that, The encryption / decryption information includes at least one of the following: encryption key, initialization vector IV, or encryption key number.

17. The method according to any one of claims 1-16, characterized in that, The method further includes: Obtain instruction information, which is used to indicate the plaintext mode or ciphertext mode of the encryption / decryption information.

18. The method according to any one of claims 1-17, characterized in that, The method further includes: The first bit stream is received from the service data interface, which is any one of the following types of interfaces: serial / parallel circuit SerDes interface, 10 Gigabit Interconnect Unit interface XAUI, 100 Gigabit Interconnect Unit interface CAUI, Media Independent Interface MII or a derived Media Independent Interface xMII.

19. The method according to any one of claims 1-18, characterized in that, The method further includes: Receive a query read command sent by the second communication device, the query read command being used to query the encryption capability of the first communication device; A response message is sent to the second communication device. The response message includes encryption specification information of the first communication device. The encryption specification information is used to indicate the encryption capability of the first communication device. The encryption specification information includes at least one of the following: whether it supports physical layer security protocols, supported encryption rates, supported encryption algorithms, or supported key modes.

20. A data transmission method, characterized in that, Applied to a second communication device, the method includes: The encryption and decryption information is sent to the first communication device, which is directly connected to the second communication device. The encryption and decryption information is used by the first communication device to encrypt or decrypt the bit stream of the physical layer. Transmit bit streams with the first communication device.

21. The method according to claim 20, characterized in that, The encrypted / decrypted information is in plaintext; Alternatively, if the encryption / decryption information is ciphertext, then the encryption / decryption information sent to the first communication device is the encrypted encryption / decryption information.

22. The method according to claim 21, characterized in that, The method further includes: Obtain indication information, which is used to indicate whether the encrypted / decrypted information is in plaintext mode or ciphertext mode.

23. The method according to any one of claims 20-22, characterized in that, The first communication device is an optical module, and the second communication device is a network device; Alternatively, the first communication device may be the PHY interface of a network device, and the second communication device may be the management chip of the network device, wherein the management chip is used to manage the PHY interface.

24. The method according to any one of claims 20-23, characterized in that, The transmission of bit streams with the first communication device includes: A first bit stream is sent to the first communication device, and the encryption / decryption information is used by the first communication device to encrypt the first bit stream.

25. The method according to any one of claims 20-23, characterized in that, The transmission of bit streams with the first communication device includes: The first communication device sends a second bit stream, which is obtained by the first communication device decrypting the bit stream received from the third communication device using the encryption and decryption information.

26. The method according to any one of claims 20-25, characterized in that, The method further includes: Send a query read command to the first communication device, the query read command being used to query the encryption capability of the first communication device; The system receives a response message sent by the first communication device. The response message includes encryption specification information of the first communication device. The encryption specification information is used to indicate the encryption capability of the first communication device. The encryption specification information includes at least one of the following: whether it supports physical layer security protocols, supported encryption rates, supported encryption algorithms, or supported key modes.

27. A communication device, characterized in that, The communication device includes a processor, which is configured to perform the method according to any one of claims 1-19, or the processor is configured to perform the method according to any one of claims 20-26.

28. A communication system, characterized in that, Includes a first communication device and a second communication device; The first communication device is configured to perform the method described in any one of claims 1-19. The second communication device is used to perform the method described in any one of claims 20-26.

29. The communication system according to claim 28, characterized in that, Also includes: A third communication device, wherein the third communication device is connected to the second communication device through the first communication device.