Optical Line Terminal Secure Identifier Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In point-to-multipoint optical networks, the transmission of ONU credentials without encryption compromises network security, as intercepted credentials can be used to generate shared keys.

Innovation Solution

The optical line terminal (OLT) is configured to receive and decrypt encrypted identifiers from ONUs using a preconfigured encryption algorithm and key, thereby determining shared keys securely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If credentials are transmitted without encryption, then the authentication process is simple and fast, but network security is compromised as intercepted credentials can generate shared keys

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-configuring encryption algorithms and keys in both the OLT and ONUs before the authentication process. This allows the system to maintain simple authentication flows while ensuring security, as the encryption mechanisms are already in place and require no additional operational complexity during the authentication process itself.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses encryption as an intermediary mechanism between the credential transmission and key generation processes. By introducing encryption as an intermediate layer, the system protects credentials during transmission without changing the fundamental authentication flow, thus maintaining simplicity while enhancing security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If credentials are encrypted before transmission, then network security is improved by preventing key generation from intercepted data, but the encryption and decryption process adds operational complexity

Engineering Contradiction:
Improvenetwork securityVSAvoidprovisioning process ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies preliminary action by pre-configuring encryption algorithms and keys in both the OLT and ONUs before the authentication process. This eliminates the need for operational complexity during provisioning, as all encryption parameters are already in place and require no additional manual configuration or operational intervention.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system performs self-service by automatically handling encryption and decryption of credentials during the authentication process. The OLT and ONUs autonomously manage the encryption operations using their pre-configured keys and algorithms, eliminating the need for manual encryption/decryption operations and simplifying the overall provisioning process.

Inventive Principle:
Principle #25Self-service

3Productivity

If preconfigured encryption algorithms and keys are used, then provisioning time is reduced and operational complexity is minimized, but the system requires pre-established security parameters

Engineering Contradiction:
Improveprovisioning speedVSAvoidpreconfiguration requirements
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-configuring encryption algorithms and keys in both the OLT and ONUs before deployment. This preliminary setup eliminates the need for time-consuming encryption configuration during the provisioning process, significantly accelerating deployment while the pre-established security parameters remain manageable through standardized preconfiguration protocols.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250184162A1Secure identifier exchange in an optical network
Publication Date: 2025.06.05 NOKIA SOLUTIONS & NETWORKS OY
  • US20250184162A1 patent drawing
  • US20250184162A1 patent drawing
  • US20250184162A1 patent drawing

AI summary

Example embodiments describe an optical line terminal (OLT) configured to communicate in a point-to-multipoint optical network with optical network units (ONUs); where the OLT and a respective ONU share a set of shared keys. The OLT configured to perform receiving, from a respective ONU, at least one identifier encrypted according to a preconfigured encryption algorithm and a preconfigured key; wherein the at least one identifier is characteristic for the respective ONU. The OLT configured to perform decrypting the at least one received identifier according to the preconfigured encryption algorithm and the preconfigured key; and determining at least one shared key based on the at least one decrypted identifier.