EPON Security Channel Setup via MPCP Message Structure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Ethernet passive optical network (EPON) technologies lack a standardized method for simultaneously registering optical network units (ONUs) and negotiating security channels without additional key distribution protocols, leading to bandwidth waste and requiring ONUs to have a central processing unit (CPU) for security functions, which complicates key distribution and restricts compatibility.
Innovation Solution
A method for setting a security channel using Multi-Point Control Protocol (MPCP) messages between an Optical Line Terminator (OLT) and ONUs, allowing for reciprocal security capability negotiation and automatic registration, enabling encryption key distribution without additional protocols, and supporting ONUs without CPUs, using MPCP message structures that include security capability information for frame transmission control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If additional key distribution protocols are used for security channel setup, then security capability is improved, but bandwidth is wasted and device complexity increases
Solution Approach 1:
The patent combines security channel setup and key distribution functions with the existing MPCP registration protocol. Security capability negotiation, encryption key distribution, and ONU registration are integrated into a single unified process, eliminating the need for separate key distribution protocols and reducing bandwidth overhead.
Solution Approach 2:
The MPCP protocol is enhanced to perform multiple functions simultaneously: registration, security capability negotiation, and key distribution. This multi-functional approach allows the existing infrastructure to handle security tasks without requiring additional dedicated protocols.
2Reliability
If additional key distribution protocols are used for security channel setup, then security capability is improved, but device complexity increases
Solution Approach 1:
The patent merges security channel setup and key distribution functions with the existing MPCP registration protocol. Security capability negotiation, encryption key distribution, and ONU registration are integrated into a single unified process, eliminating the need for separate key distribution protocols and reducing bandwidth overhead.
Solution Approach 2:
The MPCP protocol is enhanced to perform multiple functions simultaneously: registration, security capability negotiation, and key distribution. This multi-functional approach allows the existing infrastructure to handle security tasks without requiring additional dedicated protocols.
3Reliability
If ONUs require CPU for security functions, then security capability is improved, but device complexity and cost increase
Solution Approach 1:
The OLT performs all security processing functions including encryption key generation, management, and distribution. ONUs simply receive and apply the provided encryption keys without requiring local CPU-based security processing, thereby reducing ONU complexity and cost while maintaining security capabilities.
Solution Approach 2:
The OLT acts as an intermediary that centralizes security processing. It generates encryption keys, negotiates security capabilities with ONUs, and distributes the necessary cryptographic materials, relieving ONUs of the need for complex local security processing units.
4Reliability
If security negotiation occurs outside discovery interval, then security capability is improved, but time efficiency decreases
Solution Approach 1:
Security capability negotiation is performed preliminarily during the discovery interval, before formal service establishment. This allows security parameters to be pre-negotiated and encryption keys to be pre-distributed, so that security is already in place when data transmission begins, avoiding time delays.
Solution Approach 2:
The patent merges security channel setup and key distribution functions with the existing MPCP registration protocol. Security capability negotiation, encryption key distribution, and ONU registration are integrated into a single unified process, eliminating the need for separate key distribution protocols and reducing bandwidth overhead.
Data Source
AI summary
Provided is a method for setting a security channel between an OLT and at least one ONU in an EPON. In detail, a channel is generated by which the OLT makes a reciprocal security capability agreement with the ONU that wants to set a security channel in a discovery interval and then automatically registers the ONU with the security capability agreement. The security channel is set by which the OLT distributes an encryption key for the security with the ONU completed with the security capability agreement. A renewal point of the encryption key is shared by transmitting a message indicative of a time to change the encryption key between the OLT and the ONU both completed with the encryption key distribution.


