In-band Session Key Control for Optical Transport Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing techniques for managing and controlling session keys in optical transport networks are inefficient, complex, and costly, as they rely on out-of-band mechanisms that require manual intervention or separate Operations, Administration, and Maintenance (OAM) networks, which are not secure and do not operate within the optical transport network.
Innovation Solution
Implementing in-band signaling between path termination equipment (PTEs) to provision and control session keys, where key messaging is exchanged within the overhead of frames, allowing for secure and efficient key generation, selection, and change without the need for external networks, using methods like Diffie-Hellman key exchange and encryption with master keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If out-of-band techniques are used for key provisioning and control, then key management can be implemented, but the system complexity and cost increase significantly
Solution Approach 1:
The patent merges key management functions with the existing optical transport network by using in-band signaling within frame overhead. Instead of separate out-of-band systems, the key provisioning and control signals are integrated into the same network infrastructure that transports encrypted data, eliminating the need for separate OAM networks and reducing overall system complexity while maintaining security
Solution Approach 2:
The frame overhead structure is made multi-functional by using it for both existing control purposes and for key management signaling. This universal approach allows the same infrastructure to serve multiple functions - data transport, control, and key provisioning - thereby reducing the need for additional dedicated systems and lowering overall complexity
2Ease of operation
If manual key provisioning is used, then key control is simple, but operational efficiency and speed decrease
Solution Approach 1:
The patent implements self-service key management where PTEs automatically exchange and manage session keys through in-band signaling without requiring manual intervention. The system autonomously provisions, updates, and revokes keys based on network conditions and security requirements, thereby maintaining operational simplicity while dramatically improving efficiency and speed of key management
3Reliability
If separate OAM networks are deployed for key management, then key control mechanisms can be established, but network infrastructure and cost increase
Solution Approach 1:
The patent eliminates the need for separate OAM networks by merging key management functions into the existing optical transport network. Key control signals are transmitted through the same frame infrastructure used for data transport, thereby reducing network infrastructure requirements while maintaining comprehensive key control capabilities
Solution Approach 2:
The patent extracts the key management function from the physical network infrastructure layer and implements it through signaling within the existing frame overhead. This extraction allows key control to be achieved without additional hardware or network elements, using only software-based signaling protocols that leverage the existing transport network
Data Source
AI summary
The present invention employs in-band signaling between PTEs to provision and control session keys, which are used by the PTEs for encrypting and decrypting traffic that is carried from one PTE to another over a transport network. In operation, a first PTE will receive incoming traffic from a first edge network, map the traffic to frames, encrypt the traffic with a session key, and send the frames with the encrypted traffic over the transport network to a second PTE. The second PTE will extract the encrypted traffic from the frames, decrypt the encrypted traffic with a session key, and send the recovered traffic over a second edge network toward an intended destination. If symmetric encryption is employed, the session key used by the first PTE to encrypt the traffic will be identical to the session key used by the second PTE to decrypt the traffic.


