Maintenance Entity Group Security via Secure Connectivity Association

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing techniques for protecting maintenance entity groups in communication networks are inadequate in preventing unauthorized processing and response to maintenance packets from non-trusted sources, altered packets, or replayed packets.

Innovation Solution

Establishing a secure connectivity association set for maintenance points, which includes determining and embedding security data within maintenance packets to authenticate trusted sources, encrypt sensitive information, and provide replay protection through sequence number fields.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If known techniques for protecting maintenance packets are used, then basic security is provided, but maintenance points cannot reliably distinguish trusted packets from non-trusted or altered packets

Engineering Contradiction:
Improvepacket authentication reliabilityVSAvoidsecurity mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A security association set is established beforehand between maintenance points, containing security parameters such as authentication keys and encryption algorithms. This preliminary setup enables maintenance points to verify packet authenticity using pre-configured security data, ensuring reliable distinction between trusted and untrusted packets without complex runtime negotiations

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Security data acts as an intermediary mechanism between maintenance points, embedding authentication information directly within maintenance packets. This intermediary security layer enables verification of packet origin and integrity without requiring complex peer-to-peer trust verification protocols

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If maintenance packets are transmitted without security data, then communication simplicity is maintained, but packets cannot be protected from replay attacks or unauthorized processing

Engineering Contradiction:
Improvepacket replay protectionVSAvoidpacket processing simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Sequence numbers are incorporated into the security data of maintenance packets in advance. This preliminary inclusion of sequence numbers enables receiving maintenance points to detect and reject replayed packets by comparing sequence numbers against previously processed packets, providing replay protection without complicating the packet processing workflow

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security data structure is designed to be self-contained within each maintenance packet, including all necessary authentication and verification information. This self-service approach enables maintenance points to independently verify packet authenticity and detect replay attempts using only the embedded security data, maintaining operational simplicity while ensuring robust security

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8752131B2Facilitating protection of a maintenance entity group
Publication Date: 2014.06.10 FUJITSU LTD
  • US8752131B2 patent drawing
  • US8752131B2 patent drawing
  • US8752131B2 patent drawing

AI summary

According to one embodiment, maintenance points of a maintenance entity group are identified. The maintenance points comprise end points and intermediate points. A secure connectivity association set is established for the maintenance points. The following is performed for each frame of a number of frames: determining security data of the secure connectivity association set; placing the security data into a frame; and communicating the frame to a maintenance point. The maintenance point is configured to determine whether a frame is acceptable from the security data of the frame.