FlexE PCS Encryption Key Exchange and Bulk Data Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network protocols for encryption, such as IPSec and MACSec, face limitations including packet inflation, increased complexity, power consumption, and cost, as well as the inability to encrypt headers, which are not addressed by existing Layer 1 protocols like OTNSec, particularly in the context of Flexible Ethernet (FlexE) applications.
Innovation Solution
Implementing Physical Coding Sublayer (PCS) encryption using an encryption messaging channel for key exchange and authentication, applied to 64b/66b bit streams at the FlexE client or shim layer, utilizing Advanced Encryption Standard (AES) and Galois/Counter Mode (GCM), which allows for bulk encryption and efficient key management within the FlexE framework.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IPSec or MACSec is used for encryption, then security is provided, but packet inflation occurs and effective throughput decreases
Solution Approach 1:
The patent segments the encryption function into a dedicated security processing unit separate from the main data path. The encryption/decryption operations are performed in parallel with data transmission, dividing the system into independent security and data processing segments that do not interfere with each other's performance.
Solution Approach 2:
The patent introduces an intermediary security processing unit that handles all encryption/decryption operations. This intermediary component sits between the data source and the network interface, absorbing the computational overhead of security operations without affecting the main data transmission path and thus preventing packet inflation impacts on throughput.
2Reliability
If IPSec or MACSec is used for encryption, then security is provided, but device complexity and cost increase
Solution Approach 1:
The security processing unit is designed to be self-contained and self-service, incorporating all necessary encryption/decryption logic and key management functions within a single integrated component. This eliminates the need for complex external security infrastructure and reduces overall system complexity while maintaining robust security.
Solution Approach 2:
The security processing unit is designed as a universal component that can handle multiple encryption protocols and modes of operation. This multi-functional design consolidates what would otherwise require multiple separate security mechanisms, reducing device complexity and cost while providing comprehensive security coverage.
3Reliability
If IPSec or MACSec is used for encryption, then payload confidentiality is provided, but headers remain unencrypted and power consumption increases
Solution Approach 1:
The encryption scope is made dynamic and configurable, allowing the system to adapt between encrypting only payload data or encrypting both payload and header information based on security requirements. This dynamic approach optimizes power consumption by encrypting only what is necessary for each specific application scenario.
Solution Approach 2:
The patent implements parameter changes in the encryption process, allowing selective encryption of different data portions (payload only vs. payload and header) based on security needs. This parameter control enables the system to minimize power consumption by encrypting only the necessary portions of data while maintaining confidentiality where required.
Data Source
AI summary
Systems and methods for Physical Coding Sublayer (PCS) encryption implemented by a first network element communicatively coupled to a second network element include utilizing an encryption messaging channel to establish an authenticated session and exchanging one or more encryption keys with a second network element; encrypting a signal, based on the one or more encryption keys; and transmitting the encrypted signal to the second network element.


