Blanking Decision State Machine for Secure DWDM Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
High-speed optical DWDM networks with modern iteratively decoded FEC codecs face challenges in secure payload transport due to erroneous authentication failures caused by post-FEC errors, which can lead to malicious packet injection and network attacks, as the error floor in these codecs occurs at very low bit error rates, making it difficult to distinguish between genuine errors and malicious traffic.
Innovation Solution
A receiver system comprising a FEC decoder and an authentication engine that buffers and blanks payload data based on the frequency of FEC decoder errors, using a blanking decision state machine to differentiate between rare and malicious errors, thereby suppressing unnecessary blanking and maintaining network integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If modern iteratively decoded FEC codecs are used to enable high-throughput coherent optical transmission, then the system can operate at high pre-FEC BER levels, but erroneous authentication failures occur due to error floors at very low post-FEC BER levels
Solution Approach 1:
The patent introduces an intermediary authentication monitoring mechanism that sits between the FEC decoder and the security verification process. This intermediary monitors authentication failure rates and distinguishes between genuine security threats and erroneous failures caused by FEC error floors, preventing false security actions while maintaining system security.
Solution Approach 2:
The patent changes the operational parameters by introducing dynamic thresholds for authentication failure rates. Instead of using fixed thresholds, the system adapts thresholds based on observed error patterns and FEC performance characteristics, allowing the system to tolerate higher failure rates during error floor conditions while still detecting genuine security threats.
2Reliability
If authentication failures are treated as security threats, then network security is maintained, but legitimate secure traffic is incorrectly blocked due to post-FEC errors
Solution Approach 1:
The patent implements preliminary monitoring and analysis of authentication failure patterns before triggering security actions. By analyzing the temporal distribution and characteristics of failures beforehand, the system can distinguish between random errors and coordinated attacks, preventing false blocking of legitimate traffic while maintaining security responses to genuine threats.
3Reliability
If strict authentication checking is performed on all packets, then malicious traffic is blocked, but network latency increases due to verification overhead
Solution Approach 1:
The patent applies partial authentication checking by performing full verification only on packets that trigger suspicious patterns, while using lighter verification for normal traffic. This selective approach reduces the overall verification overhead and latency while maintaining security by applying strict checking only when necessary based on observed anomaly patterns.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
In one embodiment an apparatus, method, and system is described, the embodiment an apparatus, method including receiving a stream of data frames at an input interface, the data frames one of including security frames, or being included in security frames, wherein the security frames include payload data, performing forward error correction on the data frames a forward error correction (FEC) decoder, buffering received data frames at a buffer and blanker engine and building a complete security frame of the received data frames, determining whether or not to suppress taking a consequent action based on a frequency of authentication errors at an authentication engine, wherein the consequent action to be taken or suppressed, when taken, is taken upon payload data of one or more security frames including a data frame upon which an authentication error occurred. Related apparatus, methods and systems are also described.