Optical Intrusion Detection via Double-Modulation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Optical networks are vulnerable to man-in-the-middle (MITM) attacks, where an intruder intercepts and regenerates signals, making it difficult to detect unauthorized access without impacting network performance or increasing costs.

Innovation Solution

Embedding security information in optical signals using double-modulation techniques, where a low-speed security signal is amplitude modulated into a high-speed payload signal, hidden within channel noise, allowing detection of intrusion devices by the absence of security information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If an intrusion device is inserted into the fiber path to intercept signals, then unauthorized access to data is achieved, but the intrusion device becomes detectable through signal analysis

Engineering Contradiction:
Improvenetwork securityVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by embedding security codes into optical signals before transmission through the fiber. This pre-embedding of detection markers allows the system to proactively identify intrusion devices without requiring complex real-time analysis infrastructure, thus improving network security while avoiding excessive system complexity

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses security codes as an intermediary element that mediates between the transmitted data and the detection mechanism. These codes act as hidden markers within the optical signal that enable intrusion detection without requiring direct interaction between the detection system and the data stream, simplifying the overall detection architecture

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If security codes are embedded in optical signals using double-modulation, then intrusion detection capability is improved, but signal processing complexity increases

Engineering Contradiction:
Improveintrusion detection accuracyVSAvoidsignal processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements nesting by embedding security codes within the optical signal using double-modulation techniques. The security codes are nested within the data signal structure, allowing the detection system to extract and analyze these hidden markers without interfering with the primary data transmission, thereby achieving high detection accuracy while managing signal processing complexity

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent applies partial action by focusing the detection system's analysis only on the specific security code portions of the signal rather than processing the entire data stream. This selective analysis of embedded markers provides high intrusion detection accuracy while significantly reducing the overall signal processing complexity

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If security information is hidden in optical channel noise, then detection of intrusion devices is enabled, but signal-to-noise ratio requirements become more stringent

Engineering Contradiction:
Improveintrusion detection reliabilityVSAvoidsignal power requirements
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies local quality by concentrating the security information into specific localized portions of the optical signal rather than distributing it uniformly. This concentration of security markers in defined signal regions enables reliable intrusion detection while allowing the system to operate with standard signal-to-noise ratios, avoiding excessive power requirements

Inventive Principle:
Principle #3Local quality

4Reliability

If the receiving device checks for security information in received signals, then intrusion devices are detected, but processing time increases

Engineering Contradiction:
Improvesecurity verification reliabilityVSAvoidsignal processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent uses preliminary action by pre-embedding security codes into the optical signals during the transmission process. This allows the receiving device to perform simple presence/absence checks on pre-placed markers rather than conducting complex real-time analysis, achieving high security verification reliability with minimal additional processing time

Inventive Principle:
Principle #10Preliminary action

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Effectively detects and alerts administrators of MITM attacks without interfering with payload data recovery, preventing further data transmission until the security of the fiber is verified, thus enhancing network security without performance degradation.

Implementation Method 1

a low-speed security signal is amplitude modulated into a high-speed payload signal, hidden within channel noise

Methodology Applied
Scientific EffectAmplitude modulation: Phase Modulation

Data Source

PatentUS8701161B1Systems and methods for detecting network intrusion devices
Publication Date: 2014.04.15 ADTRAN INC
  • US8701161B1 patent drawing
  • US8701161B1 patent drawing
  • US8701161B1 patent drawing

AI summary

An optical communication system has a transmitter that generates an optical signal containing payload data and security data. The transmitter double modulates an optical signal where payload data is in-band and security data is out-of-band. If a man-in-the-middle attack occurs and the intrusion device is unable to detect the out-of-band signal, the intrusion device will not replicate the out-of-band signal thereby allowing the presence of the intrusion device to be detected.