Optical Network Aggregation Device Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Active Ethernet networks face challenges in securing optical fiber links due to the lack of effective authentication mechanisms, allowing unauthorized devices to access the provider network, which requires maintenance of additional infrastructure and administrative overhead for credential management.

Innovation Solution

An optical network aggregation device with an authentication unit manages ONT authentication by exchanging authentication messages with ONTs, using a shared key to authorize access, thereby preventing unauthorized access without the need for a RADIUS server or unique credentials for each subscriber.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IEEE 802.1X authentication standard is used to prevent unauthorized access, then network security is improved, but additional infrastructure (RADIUS server) and administrative overhead are required

Engineering Contradiction:
Improvenetwork securityVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication functionality from the centralized RADIUS server infrastructure and embeds it directly into the optical network terminal device. The ONT now performs authentication operations locally using stored credential pairs, eliminating the need for external authentication servers and reducing infrastructure complexity while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The ONT device is configured with authentication credential pairs and performs self-authentication with the optical Ethernet switch without requiring external authentication infrastructure. The device serves its own authentication needs by locally verifying credentials against the switch, reducing administrative overhead and infrastructure requirements.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If loose coupling between ONT and optical Ethernet switch is maintained for ease of operation, then device interchangeability is improved, but unauthorized device access becomes possible

Engineering Contradiction:
Improvedevice interchangeabilityVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

Authentication credential pairs are pre-configured in the ONT device before deployment. This preliminary configuration enables the device to perform authentication operations locally without requiring external infrastructure, maintaining ease of operation while preventing unauthorized access through pre-established security credentials.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an authentication credential pair as an intermediary mechanism between the ONT and the optical Ethernet switch. This credential-based mediation allows legitimate devices to communicate freely while blocking unauthorized devices, reconciling device interchangeability with security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8495371B2Network device authentication
Publication Date: 2013.07.23 CALIX INC
  • US8495371B2 patent drawing
  • US8495371B2 patent drawing
  • US8495371B2 patent drawing

AI summary

In general, this disclosure relates to maintaining security between an optical network terminal (ONT) and an optical network aggregation device in an Active Ethernet network. An optical network aggregation device includes one or more optical Ethernet switches that can be adaptively configured to support authentication of one or more ONTs. For example, the optical network aggregation device may include a controller with an authentication unit for managing ONT authentication and an optical Ethernet interface for transmitting and receiving data over the optical network. The authentication unit may exchange authentication request messages via the optical Ethernet interface with an ONT and grant the ONT access to the provider network based on the exchange, thereby preventing rogue devices from gaining access to the provider network.