OTN Frame Encryption Control via Overhead Bits
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for encryption in optical networks are computationally intensive and can cause data loss when generating and rotating encryption keys, especially in dense networks with multiple nodes, and often result in dropped data frames during key activation or deactivation.
Innovation Solution
The method involves using a Transport Layer Security (TLS) connection to generate and share encryption keys, with overhead encryption bits in OTN frames indicating encryption status, allowing seamless transitions between encrypted and unencrypted states without data loss, and enabling key rotation without frame drops.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional encryption methods are used in optical networks, then data security is improved, but computational overhead increases and data frames may be lost during key activation or rotation
Solution Approach 1:
The patent applies preliminary action by establishing the TLS connection and generating encryption keys before actual data transmission begins. The overhead encryption bits are prepared in advance in the OTN frame structure, allowing the receiver to be pre-notified of encryption status changes. This prevents computational delays during transmission by having all cryptographic operations completed beforehand.
Solution Approach 2:
The patent introduces an intermediary mechanism using overhead encryption bits in the OTN frame structure that act as a mediator between the encryption system and data transmission. These bits carry encryption status information (set_encryption, deprovision_encryption, EK) without requiring direct computational intervention during data flow, thus reducing computational overhead while maintaining security.
2Adaptability or versatility
If encryption keys are activated or deactivated during transmission, then security management is improved, but data frames are dropped
Solution Approach 1:
The patent uses preliminary action by setting the set_encryption bit in overhead bits before the actual encryption of data payload begins. This advance notification allows the receiver to prepare for encryption/decryption operations without causing frame drops. The deprovision_encryption bit similarly provides advance notice before encryption is deactivated, ensuring smooth transitions.
Solution Approach 2:
The patent implements feedback through the overhead encryption bits that continuously inform the receiver about the encryption status. The EK bit provides feedback about which encryption key is currently active, allowing the receiver to adjust its decryption operations accordingly. This feedback mechanism ensures that no frames are lost during key transitions.
3Reliability
If multiple encryption keys are rotated during transmission, then security is improved, but transmission interruptions occur
Solution Approach 1:
The patent applies preliminary action by notifying the receiver in advance through the EK bit about upcoming encryption key changes. The overhead bits are set before the actual key rotation occurs in the data payload, allowing the receiver to pre-load and prepare the next encryption key for immediate use without interrupting transmission flow.
Solution Approach 2:
The patent maintains continuity of useful action by ensuring that encryption/decryption operations continue uninterrupted during key rotation. The overhead encryption bits enable seamless transitions between keys by providing continuous status information, allowing the receiver to switch keys without stopping data reception or causing transmission interruptions.
Data Source
AI summary
Methods and systems for encryption control in optical networks without data loss enable various transitions related to encryption of an ODU data payload. A transition from unencrypted data payload to encrypted data payload is performed without data loss or dropping of OTN frames. A transition from encrypted data payload to unencrypted data payload is performed without data loss or dropping of OTN frames. A rotation of the encryption key to another encryption key is also performed without data loss or dropping of OTN frames.


