In-band Session Key Control for Optical Transport Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing techniques for managing and controlling session keys in optical transport networks are inefficient, complex, and costly, as they rely on out-of-band mechanisms that require manual intervention or separate Operations, Administration, and Maintenance (OAM) networks, which are not secure and do not operate within the optical transport network.

Innovation Solution

Implementing in-band signaling between path termination equipment (PTEs) to provision and control session keys, where key messaging is exchanged within the overhead of frames, allowing for secure and efficient key generation, selection, and change without the need for external networks, using methods like Diffie-Hellman key exchange and encryption with master keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If out-of-band techniques are used for key provisioning and control, then key management can be implemented, but the system complexity and cost increase significantly

Engineering Contradiction:
Improvekey management securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges key management functions with the existing optical transport network by using in-band signaling within frame overhead. Instead of separate out-of-band systems, the key provisioning and control signals are integrated into the same network infrastructure that transports encrypted data, eliminating the need for separate OAM networks and reducing overall system complexity while maintaining security

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The frame overhead structure is made multi-functional by using it for both existing control purposes and for key management signaling. This universal approach allows the same infrastructure to serve multiple functions - data transport, control, and key provisioning - thereby reducing the need for additional dedicated systems and lowering overall complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If manual key provisioning is used, then key control is simple, but operational efficiency and speed decrease

Engineering Contradiction:
Improvekey provisioning simplicityVSAvoidkey management efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent implements self-service key management where PTEs automatically exchange and manage session keys through in-band signaling without requiring manual intervention. The system autonomously provisions, updates, and revokes keys based on network conditions and security requirements, thereby maintaining operational simplicity while dramatically improving efficiency and speed of key management

Inventive Principle:
Principle #25Self-service

3Reliability

If separate OAM networks are deployed for key management, then key control mechanisms can be established, but network infrastructure and cost increase

Engineering Contradiction:
Improvekey control capabilityVSAvoidnetwork infrastructure
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent eliminates the need for separate OAM networks by merging key management functions into the existing optical transport network. Key control signals are transmitted through the same frame infrastructure used for data transport, thereby reducing network infrastructure requirements while maintaining comprehensive key control capabilities

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent extracts the key management function from the physical network infrastructure layer and implements it through signaling within the existing frame overhead. This extraction allows key control to be achieved without additional hardware or network elements, using only software-based signaling protocols that leverage the existing transport network

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8897448B2Controlling session keys through in-band signaling
Publication Date: 2014.11.25 CIENA CORP
  • US8897448B2 patent drawing
  • US8897448B2 patent drawing
  • US8897448B2 patent drawing

AI summary

The present invention employs in-band signaling between PTEs to provision and control session keys, which are used by the PTEs for encrypting and decrypting traffic that is carried from one PTE to another over a transport network. In operation, a first PTE will receive incoming traffic from a first edge network, map the traffic to frames, encrypt the traffic with a session key, and send the frames with the encrypted traffic over the transport network to a second PTE. The second PTE will extract the encrypted traffic from the frames, decrypt the encrypted traffic with a session key, and send the recovered traffic over a second edge network toward an intended destination. If symmetric encryption is employed, the session key used by the first PTE to encrypt the traffic will be identical to the session key used by the second PTE to decrypt the traffic.