Intermediate Message Authentication in Optical Transport Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In switched-path networks, such as optical transport networks, it is challenging to identify and mitigate message tampering by untrustworthy communication nodes, as existing end-to-end authentication methods cannot determine the source of tampering within the network.

Innovation Solution

Implementing authentication logic within communication nodes to periodically authenticate messages using different authentication keys and involving an authentication authority to identify and remediate compromised nodes by routing around them or taking other corrective actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If end-to-end authentication is used to detect message tampering, then message integrity can be verified, but the source of tampering cannot be identified

Engineering Contradiction:
Improvemessage integrity verificationVSAvoidsource identification of tampering
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the end-to-end authentication process into intermediate authentication steps at each communication node. Each node performs authentication on the message as it passes through, dividing the single verification task into multiple distributed verification points. This segmentation enables identification of which specific node detects tampering, thereby resolving the contradiction between verifying integrity and identifying the tampering source.

Inventive Principle:
Principle #1Segmentation

2Difficulty of detecting and measuring

If intermediate authentication is implemented at each communication node, then the source of message tampering can be identified, but network complexity increases

Engineering Contradiction:
Improvesource identification of tamperingVSAvoidnetwork structure complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication mechanism that can be deployed at any communication node in the network. The same authentication logic and cryptographic operations are used throughout the network, allowing any node to perform intermediate authentication. This universality enables source identification without requiring complex or specialized infrastructure at each node, thus managing network complexity while achieving the goal of identifying tampering sources.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If intermediate authentication is performed at each communication node, then message tampering can be detected, but processing overhead and authentication time increase

Engineering Contradiction:
Improvemessage tampering detectionVSAvoidauthentication processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent employs preliminary cryptographic operations where authentication tags are generated and attached to messages before they enter the switched-path network. Intermediate nodes perform verification of these pre-computed tags rather than performing full authentication computations on each message. This preliminary action reduces the processing time at intermediate nodes while maintaining reliable tampering detection capability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2811715B1Systems and methods for intermediate message authentication in a switched-path network
Publication Date: 2018.11.14 ALTERA CORP
  • EP2811715B1 patent drawingFigure 1
  • EP2811715B1 patent drawingFigure 2
  • EP2811715B1 patent drawingFigure 3~4

AI summary

Systems, methods, and devices are provided for intermediate authentication of a message transmitted through a switched-path network, such as an optical transport network (OTN). In one method, a message transmitted through communication nodes of a switched-path network may be authenticated, at least partially, by authentication logic of one or more of the communication nodes. The one or more communication nodes may identify whether a prior communication node has tampered with or corrupted the message or may generate an authentication tag to enable an authentication authority to authenticate the message.