Maintenance Entity Group Security via Secure Connectivity Association
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing techniques for protecting maintenance entity groups in communication networks are inadequate in preventing unauthorized processing and response to maintenance packets from non-trusted sources, altered packets, or replayed packets.
Innovation Solution
Establishing a secure connectivity association set for maintenance points, which includes determining and embedding security data within maintenance packets to authenticate trusted sources, encrypt sensitive information, and provide replay protection through sequence number fields.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If known techniques for protecting maintenance packets are used, then basic security is provided, but maintenance points cannot reliably distinguish trusted packets from non-trusted or altered packets
Solution Approach 1:
A security association set is established beforehand between maintenance points, containing security parameters such as authentication keys and encryption algorithms. This preliminary setup enables maintenance points to verify packet authenticity using pre-configured security data, ensuring reliable distinction between trusted and untrusted packets without complex runtime negotiations
Solution Approach 2:
Security data acts as an intermediary mechanism between maintenance points, embedding authentication information directly within maintenance packets. This intermediary security layer enables verification of packet origin and integrity without requiring complex peer-to-peer trust verification protocols
2Reliability
If maintenance packets are transmitted without security data, then communication simplicity is maintained, but packets cannot be protected from replay attacks or unauthorized processing
Solution Approach 1:
Sequence numbers are incorporated into the security data of maintenance packets in advance. This preliminary inclusion of sequence numbers enables receiving maintenance points to detect and reject replayed packets by comparing sequence numbers against previously processed packets, providing replay protection without complicating the packet processing workflow
Solution Approach 2:
The security data structure is designed to be self-contained within each maintenance packet, including all necessary authentication and verification information. This self-service approach enables maintenance points to independently verify packet authenticity and detect replay attempts using only the embedded security data, maintaining operational simplicity while ensuring robust security
Data Source
AI summary
According to one embodiment, maintenance points of a maintenance entity group are identified. The maintenance points comprise end points and intermediate points. A secure connectivity association set is established for the maintenance points. The following is performed for each frame of a number of frames: determining security data of the secure connectivity association set; placing the security data into a frame; and communicating the frame to a maintenance point. The maintenance point is configured to determine whether a frame is acceptable from the security data of the frame.


