ONT Authentication via Embedded Switch Logic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Active Ethernet networks face challenges in securing optical fiber links due to the lack of effective authentication mechanisms, allowing unauthorized devices to access the provider network, which requires maintaining a RADIUS server and additional infrastructure.

Innovation Solution

An optical network aggregation device with an authentication unit manages ONT authentication by exchanging authentication messages with ONTs, using pre-programmed keys shared between devices to authorize access, thereby preventing unauthorized access without the need for a RADIUS server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IEEE 802.1X authentication standard is used to prevent unauthorized access, then network security is improved, but additional infrastructure (RADIUS server) and administrative overhead are required

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication functionality from the centralized RADIUS server infrastructure and embeds it directly into the optical network terminal device. The ONT now performs authentication operations locally using pre-stored credential information, eliminating the need for external authentication servers while maintaining security functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The ONT device is configured with authentication credentials (username/password or digital certificates) and performs self-authentication with the optical Ethernet switch without requiring external authentication infrastructure. The device serves its own authentication needs independently, reducing administrative overhead and infrastructure requirements.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If loose coupling between ONT and optical Ethernet switch is maintained for ease of operation, then device compatibility is improved, but unauthorized devices can access the network

Engineering Contradiction:
Improvedevice compatibilityVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Authentication credentials are pre-configured in the ONT device before deployment. The device performs authentication operations before establishing network connectivity, ensuring that only authorized devices can access the network while maintaining compatibility with standard Ethernet interfaces.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an authentication message exchange as an intermediary step between the ONT and optical Ethernet switch. This authentication protocol acts as a mediator that verifies device authorization before allowing data transmission, securing the loose-coupled Ethernet interface without compromising compatibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8312275B2Network device authentication
Publication Date: 2012.11.13 CALIX INC
  • US8312275B2 patent drawing
  • US8312275B2 patent drawing
  • US8312275B2 patent drawing

AI summary

In general, this disclosure relates to maintaining security between an optical network terminal (ONT) and an optical network aggregation device in an Active Ethernet network. An optical network aggregation device includes one or more optical Ethernet switches that can be adaptively configured to support authentication of one or more ONTs. For example, the optical network aggregation device may include a controller with an authentication unit for managing ONT authentication and an optical Ethernet interface for transmitting and receiving data over the optical network. The authentication unit may exchange authentication request messages via the optical Ethernet interface with an ONT and grant the ONT access to the provider network based on the exchange, thereby preventing rogue devices from gaining access to the provider network.