Encryption Logic for Fiber Security via Super Frame Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Fiber-based communication networks face security vulnerabilities due to the difficulty in detecting and isolating fiber cuts and the feasibility of undetectable clip-on tapping devices, which can compromise the security of optical signal transmission.

Innovation Solution

Implementing encryption logic that creates a data super frame with encrypted payloads and distributes security control parameters across unused bytes in multiple data frames, using AES-based encryption and counter-mode encryption, such as Galois Counter Mode (GCM), to ensure secure transmission without additional overhead or slowdowns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption is implemented to secure fiber-based communications, then security is improved, but transmission overhead and processing time increase

Engineering Contradiction:
ImprovesecurityVSAvoidtransmission time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the encryption process by applying counter-mode encryption (GCM) that processes data in parallel blocks, allowing multiple data frames to be encrypted simultaneously without sequential processing delays. This segmentation enables secure transmission while maintaining native wire speeds through parallel化处理

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by pre-computing encryption keys and security control parameters before data transmission begins. The encryption logic is pre-configured with security parameters that are distributed across unused bytes in data frames, eliminating the need for real-time key exchange and reducing transmission overhead

Inventive Principle:
Principle #10Preliminary action

2Difficulty of detecting and measuring

If monitoring systems are deployed to detect fiber cuts and tapping devices, then detection capability is improved, but system complexity and cost increase

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent uses an intermediary approach by embedding security control parameters within the existing data frame structure itself, specifically in unused bytes. This eliminates the need for separate monitoring systems and reduces complexity by leveraging the existing communication infrastructure for both data transmission and security monitoring

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies universality by making the data frame structure serve multiple functions: carrying user data, embedding security control parameters, and enabling detection of tampering attempts. The same infrastructure handles both communication and security monitoring, reducing overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If clip-on tapping devices are used to intercept optical signals without cutting fibers, then ease of intrusion is improved, but signal loss detection becomes less effective

Engineering Contradiction:
Improveease of intrusionVSAvoidsignal loss detection precision
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent implements feedback by continuously monitoring the integrity of encrypted data frames through security control parameters embedded in the transmission. Any tampering attempt by clip-on tapping devices would alter the encrypted data, triggering immediate detection through the feedback mechanism that compares received frames against expected cryptographic parameters

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8462784B2Security approach for transport equipment
Publication Date: 2013.06.11 CISCO TECHNOLOGY INC
  • US8462784B2 patent drawing
  • US8462784B2 patent drawing
  • US8462784B2 patent drawing

AI summary

An apparatus comprising encryption logic that provides security for fiber-based communications may be implemented in accordance with an embodiment of the present invention. A data super frame is created by the encryption logic to comprise two or more data frames. Each of the data frames contains a payload portion. The encryption logic may receive one or more data payloads that are associated with a client signal. Using a single set of security control parameters, the encryption logic encrypts and stores a different encrypted payload in a payload portion of a different frame of the data frames in the data super frame. Instead of storing the set of security control parameters in a single data frame, the encryption logic stores the set of security control parameters in different sets of unused bytes associated with at least two different frames of the data frames.