EPoC Key Switchover Mechanism for Secure Hybrid Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Hybrid access networks like Ethernet Passive Optical Network over Coaxial (EPoC) face security concerns due to the susceptibility of coaxial networks to eavesdropping and unauthorized access, as they are not inherently secure like optical networks.
Innovation Solution
Implementing a Fiber Coaxial Unit (FCU) that couples to an Optical Line Terminal (OLT) via a PON, which generates and manages security keys, encrypts messages, and performs key exchanges to secure communications between the OLT and Coaxial Network Units (CNUs), ensuring only authorized devices can decrypt messages, and periodically updating keys to prevent long-term exposure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security keys are periodically updated in EPoC networks, then security against eavesdropping and unauthorized access is improved, but key management complexity and communication overhead increase
Solution Approach 1:
The patent implements preliminary action by pre-establishing key update mechanisms and procedures before security threats can exploit long-term key exposure. The system proactively updates encryption keys at predetermined intervals or trigger events, preventing potential security breaches rather than reacting to them. This includes pre-configuring key generation algorithms, update timing mechanisms, and fallback procedures in the FCU and CNU devices.
Solution Approach 2:
The patent applies periodic action by implementing regular, scheduled security key updates between the Fiber Coaxial Unit (FCU) and Coaxial Network Units (CNUs). The system uses time-based or event-based triggers to initiate key renewal cycles, ensuring that encryption keys do not remain static for extended periods. This periodic refresh mechanism maintains security while establishing predictable management patterns that reduce long-term complexity.
2Reliability
If encryption is implemented in EPoC networks to prevent eavesdropping, then security is improved, but processing overhead and communication latency increase
Solution Approach 1:
The patent reduces communication latency through preliminary action by completing key establishment and authentication procedures during initial network setup or idle periods, before actual data transmission begins. The FCU and CNU exchange and verify encryption keys in advance, so that when data needs to be transmitted, the security framework is already in place and encryption can commence immediately without adding delay to the critical data path.
3Duration of action of stationary object
If seamless key switchover is implemented, then continuous communication flow is maintained, but verification overhead and processing complexity increase
Solution Approach 1:
The patent applies preliminary action by implementing key switchover verification during idle periods or using previously established verification channels, rather than verifying every key change in real-time on the primary data path. The FCU prepares verification mechanisms in advance, and the system uses redundant communication paths or timing windows to confirm key acceptance without interrupting ongoing communications. This allows seamless switchover while distributing verification overhead across different time periods and channels.
Data Source
AI summary
A method comprising generating an updated security key upon expiration of a key exchange timer, transferring the updated security key to a Coaxial Network Unit (CNU), retaining an original key, wherein the updated security key comprises a different key identification number than the original key, accepting and decrypting upstream traffic that employs either the original key or the updated key, after transferring the updated security key to the CNU, creating a key switchover timer, before the key switchover timer expires, verify that upstream traffic transferred from the CNU on a logical link uses the updated security key, and when upstream traffic is encrypted using the updated security key, begin using the updated security key to encrypt downstream traffic and clear the key switchover timer.


