EPON Security Channel Setup via MPCP Message Structure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Ethernet passive optical network (EPON) technologies lack a standardized method for simultaneously registering optical network units (ONUs) and negotiating security channels without additional key distribution protocols, leading to bandwidth waste and requiring ONUs to have a central processing unit (CPU) for security functions, which complicates key distribution and restricts compatibility.

Innovation Solution

A method for setting a security channel using Multi-Point Control Protocol (MPCP) messages between an Optical Line Terminator (OLT) and ONUs, allowing for reciprocal security capability negotiation and automatic registration, enabling encryption key distribution without additional protocols, and supporting ONUs without CPUs, using MPCP message structures that include security capability information for frame transmission control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If additional key distribution protocols are used for security channel setup, then security capability is improved, but bandwidth is wasted and device complexity increases

Engineering Contradiction:
Improvesecurity capabilityVSAvoidbandwidth waste
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent combines security channel setup and key distribution functions with the existing MPCP registration protocol. Security capability negotiation, encryption key distribution, and ONU registration are integrated into a single unified process, eliminating the need for separate key distribution protocols and reducing bandwidth overhead.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The MPCP protocol is enhanced to perform multiple functions simultaneously: registration, security capability negotiation, and key distribution. This multi-functional approach allows the existing infrastructure to handle security tasks without requiring additional dedicated protocols.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If additional key distribution protocols are used for security channel setup, then security capability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity capabilityVSAvoidprotocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges security channel setup and key distribution functions with the existing MPCP registration protocol. Security capability negotiation, encryption key distribution, and ONU registration are integrated into a single unified process, eliminating the need for separate key distribution protocols and reducing bandwidth overhead.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The MPCP protocol is enhanced to perform multiple functions simultaneously: registration, security capability negotiation, and key distribution. This multi-functional approach allows the existing infrastructure to handle security tasks without requiring additional dedicated protocols.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If ONUs require CPU for security functions, then security capability is improved, but device complexity and cost increase

Engineering Contradiction:
Improvesecurity capabilityVSAvoidONU complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The OLT performs all security processing functions including encryption key generation, management, and distribution. ONUs simply receive and apply the provided encryption keys without requiring local CPU-based security processing, thereby reducing ONU complexity and cost while maintaining security capabilities.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The OLT acts as an intermediary that centralizes security processing. It generates encryption keys, negotiates security capabilities with ONUs, and distributes the necessary cryptographic materials, relieving ONUs of the need for complex local security processing units.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If security negotiation occurs outside discovery interval, then security capability is improved, but time efficiency decreases

Engineering Contradiction:
Improvesecurity capabilityVSAvoidregistration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Security capability negotiation is performed preliminarily during the discovery interval, before formal service establishment. This allows security parameters to be pre-negotiated and encryption keys to be pre-distributed, so that security is already in place when data transmission begins, avoiding time delays.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent merges security channel setup and key distribution functions with the existing MPCP registration protocol. Security capability negotiation, encryption key distribution, and ONU registration are integrated into a single unified process, eliminating the need for separate key distribution protocols and reducing bandwidth overhead.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8086872B2Method for setting security channel based on MPCP between OLT and ONUs in EPON, and MPCP message structure for controlling frame transmission
Publication Date: 2011.12.27 ELECTRONICS & TELECOMM RES INST
  • US8086872B2 patent drawing
  • US8086872B2 patent drawing
  • US8086872B2 patent drawing

AI summary

Provided is a method for setting a security channel between an OLT and at least one ONU in an EPON. In detail, a channel is generated by which the OLT makes a reciprocal security capability agreement with the ONU that wants to set a security channel in a discovery interval and then automatically registers the ONU with the security capability agreement. The security channel is set by which the OLT distributes an encryption key for the security with the ONU completed with the security capability agreement. A renewal point of the encryption key is shared by transmitting a message indicative of a time to change the encryption key between the OLT and the ONU both completed with the encryption key distribution.