Optical Network Terminals for Hitless Key Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Optical data transmission networks face challenges in secure key management and encryption key exchange across operator boundaries, particularly in scenarios involving dynamic service setups and Software Defined Networks (SDN), where centralized key servers can become bottlenecks and pre-shared keys may have security disadvantages.
Innovation Solution
The use of operator-specific control information within the G.709 Optical channel Data Unit (ODU) for in-band transmission of encryption instructions, enabling decentralized key exchange mechanisms like Diffie-Hellman key exchange and Pre-Shared Key (PSK) or Public Key Infrastructure (PKI), allowing for seamless key changes without traffic interruptions and compatibility with existing network topologies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If centralized key servers are used for key management, then key distribution can be centralized and controlled, but system complexity increases and performance bottlenecks occur in dynamic service setups
Solution Approach 1:
The patent extracts the key exchange functionality from centralized key servers and implements it directly in the optical network terminals using Diffie-Hellman key exchange. This removes the centralization bottleneck while maintaining security, allowing terminals to autonomously establish encryption keys without centralized coordination.
Solution Approach 2:
The optical network terminals perform self-service key generation and exchange through Diffie-Hellman key exchange mechanisms. Each terminal independently generates its own key pair and exchanges public keys with the remote terminal, eliminating dependency on centralized key servers for key distribution in dynamic service setups.
2Ease of operation
If pre-shared keys are used for encryption, then key distribution is simplified, but security is compromised due to key management vulnerabilities
Solution Approach 1:
The patent replaces the mechanical key distribution system (pre-shared keys requiring secure physical or manual distribution) with a cryptographic key exchange system (Diffie-Hellman). This substitution allows secure key establishment over insecure optical channels without requiring secure pre-distribution, thereby maintaining both ease of operation and security.
3Adaptability or versatility
If General Communication Channels (GCC) are used for key exchange, then additional communication capabilities are provided, but device complexity and potential security risks increase
Solution Approach 1:
The patent makes the optical data packets serve multiple functions: they simultaneously carry user data and encryption key exchange information through embedded control fields. This eliminates the need for separate General Communication Channels while maintaining key exchange capability, reducing device complexity without sacrificing adaptability.
Solution Approach 2:
The patent merges the key exchange communication function with the existing optical data transmission channel. Encryption-related control information and key exchange data are combined within the same optical packet structure, eliminating the need for separate communication infrastructure and reducing overall system complexity.
4Adaptability or versatility
If encryption instructions are transmitted using reserved bytes, then standard compliance is maintained, but the instructions may be altered during transport over network elements of different providers
Solution Approach 1:
The patent introduces authentication mechanisms and secure embedding methods as intermediaries between the encryption instructions and the transmission channel. These intermediaries protect the integrity of the control information during transport, preventing alteration by network elements while maintaining standard compliance through proper use of reserved bytes and authentication protocols.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Embodiments relate to apparatuses (10; 20), a system (350), methods and computer programs suitable for transmitting encrypted output data packets and/or receiving encrypted input data packets in an optical data transmission network (300). The apparatus (10) is suitable for transmitting encrypted output data packets in the optical data transmission network (300). The apparatus (10) comprises one or more interfaces (12) to obtain input data packets and to provide the encrypted output data packets. The apparatus (10) further comprises a control module (14) to determine the encrypted output data packets based on the input data packets and information related to an encryption. The encrypted output data packets comprise information related to control information and information related to payload information. The information related to the control information comprises information related to operator-specific control information. The information related to the operator-specific control information comprises information related to encryption instructions based on the information related to the encryption.