OMCI Channel Security for Passive Optical Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Passive optical network (PON) systems face security threats, particularly 'eavesdropping' of downstream broadcasts and potential tapping of upstream transmissions, which existing security improvements struggle to address effectively without requiring costly hardware modifications to the PLOAM channel.

Innovation Solution

Implementing security features through the OMCI channel using software, including security capability discovery, ONU authentication, OLT authentication, and key privacy, which can be extended or upgraded without modifying the PLOAM channel, utilizing OMCI ME attributes to support these functions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security improvements are implemented through hardware modifications to the PLOAM channel, then security for downstream and upstream transmissions is enhanced, but device complexity and cost increase due to hardware upgrades

Engineering Contradiction:
ImprovesecurityVSAvoidhardware modifications
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces hardware-based security mechanisms with software-based security features implemented through the OMCI channel. Instead of modifying the PLOAM channel hardware, the invention uses OMCI messages to perform authentication, key exchange, and security parameter negotiation, thereby eliminating the need for hardware upgrades while maintaining security enhancements

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces the OMCI channel as an intermediary for security operations. The OMCI channel acts as a mediator between the OLT and ONU, carrying security-related messages for authentication, capability exchange, and key management, thereby avoiding direct hardware modifications to the PLOAM channel while still achieving security improvements

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If encryption is applied to downstream broadcast transmissions, then eavesdropping threats are reduced, but loss of information increases due to key management complexity

Engineering Contradiction:
Improveeavesdropping protectionVSAvoidkey management complexity
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The patent implements a feedback mechanism where the OLT and ONU exchange security capability information through OMCI messages. The system negotiates encryption algorithms, generates session keys, and manages key distribution dynamically based on mutual capabilities and requirements, reducing key management complexity through automated feedback loops

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces dynamic key management where encryption keys are generated and exchanged on-demand through the OMCI channel. The system can dynamically negotiate security parameters, update keys, and adapt encryption settings based on current transmission requirements, thereby reducing the burden of static key management while maintaining strong encryption protection

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3125465B1Optical network terminal management control interface-based passive optical network security enhancement
Publication Date: 2021.09.01 HUAWEI TECH CO LTD
  • EP3125465B1 patent drawingFigure 1
  • EP3125465B1 patent drawingFigure 2
  • EP3125465B1 patent drawingFigure 3

AI summary

A network component comprising at least one processor coupled to a memory and configured to exchange security information using a plurality of attributes in a management entity (ME) in an optical network unit (ONU) via an ONU management control interface (OMCI) channel, wherein the ME supports a plurality of security functions that protect upstream transmissions between the ONU and an optical line terminal (OLT). Also included is an apparatus comprising an ONU configured to couple to an OLT and comprising an OMCI ME, wherein the OMCI ME comprises a plurality of attributes that support a plurality of security features for upstream transmissions between the ONU and the OLT, and wherein the attributes are communicated via an OMCI channel between the ONU and the OLT and provide the security features for the ONU and the OLT.