Autonomic Optical Network Element Secure Enrollment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Optical transport networks are highly manually driven, requiring significant human intervention for deployment and management, which limits their efficiency and security.

Innovation Solution

The implementation of autonomic optical transport networks that use a registrar and proxy network elements with secure modules to securely bootstrap new network elements, establishing trusted communication and minimizing human intervention through autonomic control planes for secure enrollment, self-configuring, and self-management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual procedures are used for deploying and managing optical networks, then human control and oversight are maintained, but deployment efficiency is reduced and significant human intervention is required

Engineering Contradiction:
Improvedeployment efficiencyVSAvoidhuman intervention level
Core Design Contradiction:
ProductivityVSExtent of automation

Solution Approach 1:

The patent implements autonomic control planes in network elements that enable self-configuration, self-management, and automatic enrollment. New network elements autonomously discover the network, establish secure communications, and configure themselves without manual intervention, thereby improving deployment efficiency while maintaining security through cryptographic verification

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent pre-provisions secure modules with cryptographic credentials (certificates and keys) before network elements are deployed. This preliminary setup of security infrastructure enables automatic authentication and enrollment processes, allowing network elements to self-configure upon deployment without requiring manual security configuration

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual deployment procedures are used, then security can be individually configured, but the process requires significant human intervention and time

Engineering Contradiction:
Improvesecurity authenticityVSAvoidcommissioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Network elements automatically perform security authentication and enrollment by presenting their pre-provisioned cryptographic credentials to the registrar. The autonomic control plane handles the entire security verification and enrollment process autonomously, maintaining security authenticity while eliminating manual configuration time

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements a feedback mechanism where the registrar verifies cryptographic credentials and provides authentication responses that confirm secure enrollment. This automated feedback loop ensures security requirements are met while significantly reducing the time compared to manual security configuration processes

Inventive Principle:
Principle #23Feedback

3Ease of operation

If traditional optical transport networks are used, then established standards and protocols are maintained, but the networks remain highly manually driven and inefficient

Engineering Contradiction:
Improvenetwork management simplicityVSAvoiddeployment speed
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent enables network elements to automatically discover the network, establish secure communications with the registrar, and configure themselves using standardized protocols. This self-service capability simplifies operation by eliminating manual configuration steps while dramatically increasing deployment speed through automated enrollment and configuration processes

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12149873B2Secure autonomic optical transport networks
Publication Date: 2024.11.19 INFINERA CORP
  • US12149873B2 patent drawing
  • US12149873B2 patent drawing
  • US12149873B2 patent drawing

AI summary

Consistent with the present disclosure, a method and related system for secure autonomic optical transport networks are disclosed. The method includes steps for adding a network element in an optical network. The method includes an initial step of verifying, with a new network element, a first identifier certificate from a proxy network element. In a further step, a second identifier certificate from the new network element is verified with the proxy element. A registrar is used for verifying the second identifier certificate from the proxy network element and sending domain specific parameters to the proxy network element for forwarding to the new network element Next, a local certificate is generated on the new network element. The local certificate is derived from a secure module and sent to the proxy network element for forwarding to the registrar. Further, the new network element in the autonomic domain is enrolled, with the registrar. Moreover, the local certificate is signed with the registrar and the signed local certificate is sent to the new network element.