Optical Transport Unit Encryption for 100G+ Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The B100 G standard for optical transport networks does not provide security protection mechanisms such as encryption and authentication for data rates beyond 100 Gbps, leaving a gap in securing high-speed client signals.

Innovation Solution

A network device is configured to divide high-speed data traffic into multiple optical transport units, encrypt each unit with unique encryption keys, and insert security control parameters into unused overhead fields, providing encryption and authentication mechanisms for secure transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If the B100 G standard is used for optical transport networks, then data transmission speed exceeds 100 Gbps, but security protection mechanisms are not provided

Engineering Contradiction:
Improvedata transmission speedVSAvoidsecurity protection
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent segments the optical transport unit into distinct overhead regions, allocating specific unused overhead fields for security control information. This segmentation allows security mechanisms to be integrated into the existing B100 G frame structure without disrupting the high-speed data transmission capability, thereby resolving the contradiction between speed and security protection.

Inventive Principle:
Principle #1Segmentation

2Reliability

If encryption and authentication are added to B100 G, then security protection is provided, but device complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal security protection mechanism that can be applied across all B100 G optical transport units using a standardized approach. By defining a common security overhead structure and control information format that works for all encryption and authentication operations, the system achieves security protection without proportionally increasing device complexity, as the same security framework handles multiple security functions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The security protection mechanism is integrated directly into the optical transport network infrastructure itself, allowing the network to provide security services autonomously. The unused overhead fields automatically carry security control information, and the system self-manages encryption and authentication without requiring external security appliances, thereby limiting the increase in device complexity.

Inventive Principle:
Principle #25Self-service

3Reliability

If security control information is inserted into overhead fields, then authentication is enabled, but overhead utilization increases

Engineering Contradiction:
ImproveauthenticationVSAvoidoverhead usage
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent applies local quality by selectively using only the unused overhead fields for security control information, leaving the used overhead fields intact for their original purposes. This localized approach to overhead allocation ensures that authentication is enabled while minimizing the impact on overall overhead utilization, as only previously unused portions of the overhead structure are repurposed for security functions.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10985847B2Security over optical transport network beyond 100G
Publication Date: 2021.04.20 CISCO TECHNOLOGY INC
  • US10985847B2 patent drawing
  • US10985847B2 patent drawing
  • US10985847B2 patent drawing

AI summary

A method divides data traffic into multiple optical transport units formatted according to an optical transport network (OTN) standard. The multiple optical transport units include a master optical network unit and one or more slave optical network units. Each optical network unit includes overhead and a payload. The overhead includes used overhead specifically defined in the OTN standard and unused overhead not specifically defined in the OTN standard. The method encrypts each optical network unit with a respective one of multiple encryption keys, defines security control parameters identifying the multiple encryption keys, and inserts the security control parameters into the unused overhead of a first slave optical network unit among the one or more slave optical network units. The method transmits the optical network units in encrypted form.