ONT Port Rate Limiting Module for Buffer Overflow Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In passive optical network (PON) systems, the internal buffer overflow and Denial of Service (DoS) attacks occur due to uncontrolled upstream data rates from user network interfaces (UNIs), leading to packet loss and service disruptions, as existing traffic control methods only manage rates at the GEM port network CTP without considering the significance of data streams from multiple UNIs.
Innovation Solution
The implementation of port rate limiting modules within the Optical Network Terminal (ONT) that receive and process data from UNIs, configured with rate limiting attributes via the Optical Network Unit (ONU) Management and Control Interface (OMCI) to control data rates and prevent buffer overflow and DoS attacks by performing traffic control based on preset rate parameters.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If traffic control is performed only at the GEM port network CTP, then the management complexity is reduced, but the internal buffer overflow and DoS attacks occur due to uncontrolled upstream data rates from multiple UNIs
Solution Approach 1:
The patent divides the traffic control function into separate port rate limiting modules, each responsible for controlling data rates at individual UNIs. This segmentation allows centralized management through OMCI while implementing distributed rate limiting at each port, preventing buffer overflow without excessive complexity
Solution Approach 2:
The patent introduces port rate limiting modules as intermediary components between the UNIs and the MAC bridge module. These modules act as mediators that enforce rate limiting policies before data reaches the internal buffer, preventing DoS attacks while maintaining manageable system architecture
2Reliability
If rate limiting attributes are configured for each UNI, then buffer overflow and DoS attacks are prevented, but the device complexity increases due to multiple port rate limiting modules
Solution Approach 1:
The patent implements universal rate limiting functionality across all UNIs through a standardized port rate limiting module design. Each module performs the same rate control function using identical mechanisms, allowing the system to handle multiple ports with consistent behavior while managing complexity through reuse of proven components
Solution Approach 2:
The patent uses parameter changes through OMCI messages to configure rate limiting attributes dynamically. Instead of hardcoding different control logic for each UNI, the system changes parameters (peak rate, sustained rate) through standardized interfaces, reducing device complexity while maintaining comprehensive protection
3Productivity
If the sum of data rates from all UNIs exceeds the total upstream bandwidth, then traffic control is necessary to prevent buffer overflow, but existing control methods cannot distinguish between legitimate and illegal traffic
Solution Approach 1:
The patent applies local quality control by implementing independent rate limiting at each UNI port. Each port rate limiting module evaluates and controls data rates specific to that port, allowing differentiated treatment of traffic from different users while preventing any single port from overwhelming the system
Solution Approach 2:
The patent implements feedback mechanisms where the OLT monitors traffic rates and sends OMCI messages to adjust port rate limiting attributes. This closed-loop feedback allows the system to respond to actual traffic conditions, distinguishing between legitimate high-rate traffic (which can be accommodated) and illegal traffic (which is blocked), thereby protecting legitimate users while preventing DoS attacks
Data Source
Figure 1~2
Figure 3~4
Figure 5~6
AI summary
The present invention relates to an optical network terminal (ONT), a method for configuring rate limiting attributes of ports, and a method for processing packets. The ONT includes a passive optical network (PON) protocol processing module, and a user network interface (UNI) module, which are connected through an internal interface. The ONT also includes a port rate limiting module connected to a UNI. The port rate limiting module stores rate limiting attributes, and the ONT uses these attributes to control the traffic of the UNI. The port rate limiting attributes are configured for the ONT through an ONT management and control interface (OMCI) message of an optical line terminal (OLT). In this way, when the ONT receives data from the UNI, it can control the traffic of the UNI according to the port rate limiting attributes. The present invention enables the port rate limiting function for the ONT, prevents overflow of the internal receiving buffer of the ONT, and prevents dial of service (DoS) attacks from illegal users.