ONT Port Rate Limiting Module for Buffer Overflow Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In passive optical network (PON) systems, the internal buffer overflow and Denial of Service (DoS) attacks occur due to uncontrolled upstream data rates from user network interfaces (UNIs), leading to packet loss and service disruptions, as existing traffic control methods only manage rates at the GEM port network CTP without considering the significance of data streams from multiple UNIs.

Innovation Solution

The implementation of port rate limiting modules within the Optical Network Terminal (ONT) that receive and process data from UNIs, configured with rate limiting attributes via the Optical Network Unit (ONU) Management and Control Interface (OMCI) to control data rates and prevent buffer overflow and DoS attacks by performing traffic control based on preset rate parameters.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If traffic control is performed only at the GEM port network CTP, then the management complexity is reduced, but the internal buffer overflow and DoS attacks occur due to uncontrolled upstream data rates from multiple UNIs

Engineering Contradiction:
Improvemanagement complexityVSAvoidbuffer overflow prevention
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent divides the traffic control function into separate port rate limiting modules, each responsible for controlling data rates at individual UNIs. This segmentation allows centralized management through OMCI while implementing distributed rate limiting at each port, preventing buffer overflow without excessive complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces port rate limiting modules as intermediary components between the UNIs and the MAC bridge module. These modules act as mediators that enforce rate limiting policies before data reaches the internal buffer, preventing DoS attacks while maintaining manageable system architecture

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If rate limiting attributes are configured for each UNI, then buffer overflow and DoS attacks are prevented, but the device complexity increases due to multiple port rate limiting modules

Engineering Contradiction:
ImproveDoS attack preventionVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements universal rate limiting functionality across all UNIs through a standardized port rate limiting module design. Each module performs the same rate control function using identical mechanisms, allowing the system to handle multiple ports with consistent behavior while managing complexity through reuse of proven components

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses parameter changes through OMCI messages to configure rate limiting attributes dynamically. Instead of hardcoding different control logic for each UNI, the system changes parameters (peak rate, sustained rate) through standardized interfaces, reducing device complexity while maintaining comprehensive protection

Inventive Principle:
Principle #35Parameter changes

3Productivity

If the sum of data rates from all UNIs exceeds the total upstream bandwidth, then traffic control is necessary to prevent buffer overflow, but existing control methods cannot distinguish between legitimate and illegal traffic

Engineering Contradiction:
Improvetraffic control effectivenessVSAvoidlegitimate traffic impact
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality control by implementing independent rate limiting at each UNI port. Each port rate limiting module evaluates and controls data rates specific to that port, allowing differentiated treatment of traffic from different users while preventing any single port from overwhelming the system

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements feedback mechanisms where the OLT monitors traffic rates and sends OMCI messages to adjust port rate limiting attributes. This closed-loop feedback allows the system to respond to actual traffic conditions, distinguishing between legitimate high-rate traffic (which can be accommodated) and illegal traffic (which is blocked), thereby protecting legitimate users while preventing DoS attacks

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP2012463B1Optical network termination, configuration method for limiting rate property of ports therefor, and message handling method
Publication Date: 2012.06.13 HUAWEI TECH CO LTD
  • EP2012463B1 patent drawingFigure 1~2
  • EP2012463B1 patent drawingFigure 3~4
  • EP2012463B1 patent drawingFigure 5~6

AI summary

The present invention relates to an optical network terminal (ONT), a method for configuring rate limiting attributes of ports, and a method for processing packets. The ONT includes a passive optical network (PON) protocol processing module, and a user network interface (UNI) module, which are connected through an internal interface. The ONT also includes a port rate limiting module connected to a UNI. The port rate limiting module stores rate limiting attributes, and the ONT uses these attributes to control the traffic of the UNI. The port rate limiting attributes are configured for the ONT through an ONT management and control interface (OMCI) message of an optical line terminal (OLT). In this way, when the ONT receives data from the UNI, it can control the traffic of the UNI according to the port rate limiting attributes. The present invention enables the port rate limiting function for the ONT, prevents overflow of the internal receiving buffer of the ONT, and prevents dial of service (DoS) attacks from illegal users.