EPoC Key Switchover Mechanism for Secure Hybrid Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Hybrid access networks like Ethernet Passive Optical Network over Coaxial (EPoC) face security concerns due to the susceptibility of coaxial networks to eavesdropping and unauthorized access, as they are not inherently secure like optical networks.

Innovation Solution

Implementing a Fiber Coaxial Unit (FCU) that couples to an Optical Line Terminal (OLT) via a PON, which generates and manages security keys, encrypts messages, and performs key exchanges to secure communications between the OLT and Coaxial Network Units (CNUs), ensuring only authorized devices can decrypt messages, and periodically updating keys to prevent long-term exposure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security keys are periodically updated in EPoC networks, then security against eavesdropping and unauthorized access is improved, but key management complexity and communication overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-establishing key update mechanisms and procedures before security threats can exploit long-term key exposure. The system proactively updates encryption keys at predetermined intervals or trigger events, preventing potential security breaches rather than reacting to them. This includes pre-configuring key generation algorithms, update timing mechanisms, and fallback procedures in the FCU and CNU devices.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies periodic action by implementing regular, scheduled security key updates between the Fiber Coaxial Unit (FCU) and Coaxial Network Units (CNUs). The system uses time-based or event-based triggers to initiate key renewal cycles, ensuring that encryption keys do not remain static for extended periods. This periodic refresh mechanism maintains security while establishing predictable management patterns that reduce long-term complexity.

Inventive Principle:
Principle #19Periodic action

2Reliability

If encryption is implemented in EPoC networks to prevent eavesdropping, then security is improved, but processing overhead and communication latency increase

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent reduces communication latency through preliminary action by completing key establishment and authentication procedures during initial network setup or idle periods, before actual data transmission begins. The FCU and CNU exchange and verify encryption keys in advance, so that when data needs to be transmitted, the security framework is already in place and encryption can commence immediately without adding delay to the critical data path.

Inventive Principle:
Principle #10Preliminary action

3Duration of action of stationary object

If seamless key switchover is implemented, then continuous communication flow is maintained, but verification overhead and processing complexity increase

Engineering Contradiction:
Improvecommunication continuityVSAvoidverification overhead
Core Design Contradiction:
Duration of action of stationary objectVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by implementing key switchover verification during idle periods or using previously established verification channels, rather than verifying every key change in real-time on the primary data path. The FCU prepares verification mechanisms in advance, and the system uses redundant communication paths or timing windows to confirm key acceptance without interrupting ongoing communications. This allows seamless switchover while distributing verification overhead across different time periods and channels.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9838363B2Authentication and initial key exchange in ethernet passive optical network over coaxial network
Publication Date: 2017.12.05 FUTUREWEI TECHNOLOGIES INC
  • US9838363B2 patent drawing
  • US9838363B2 patent drawing
  • US9838363B2 patent drawing

AI summary

A method comprising generating an updated security key upon expiration of a key exchange timer, transferring the updated security key to a Coaxial Network Unit (CNU), retaining an original key, wherein the updated security key comprises a different key identification number than the original key, accepting and decrypting upstream traffic that employs either the original key or the updated key, after transferring the updated security key to the CNU, creating a key switchover timer, before the key switchover timer expires, verify that upstream traffic transferred from the CNU on a logical link uses the updated security key, and when upstream traffic is encrypted using the updated security key, begin using the updated security key to encrypt downstream traffic and clear the key switchover timer.