OTN Frame Encryption Control via Overhead Bits

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for encryption in optical networks are computationally intensive and can cause data loss when generating and rotating encryption keys, especially in dense networks with multiple nodes, and often result in dropped data frames during key activation or deactivation.

Innovation Solution

The method involves using a Transport Layer Security (TLS) connection to generate and share encryption keys, with overhead encryption bits in OTN frames indicating encryption status, allowing seamless transitions between encrypted and unencrypted states without data loss, and enabling key rotation without frame drops.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional encryption methods are used in optical networks, then data security is improved, but computational overhead increases and data frames may be lost during key activation or rotation

Engineering Contradiction:
Improvedata securityVSAvoidcomputational overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by establishing the TLS connection and generating encryption keys before actual data transmission begins. The overhead encryption bits are prepared in advance in the OTN frame structure, allowing the receiver to be pre-notified of encryption status changes. This prevents computational delays during transmission by having all cryptographic operations completed beforehand.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism using overhead encryption bits in the OTN frame structure that act as a mediator between the encryption system and data transmission. These bits carry encryption status information (set_encryption, deprovision_encryption, EK) without requiring direct computational intervention during data flow, thus reducing computational overhead while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If encryption keys are activated or deactivated during transmission, then security management is improved, but data frames are dropped

Engineering Contradiction:
Improvesecurity managementVSAvoiddata frame continuity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent uses preliminary action by setting the set_encryption bit in overhead bits before the actual encryption of data payload begins. This advance notification allows the receiver to prepare for encryption/decryption operations without causing frame drops. The deprovision_encryption bit similarly provides advance notice before encryption is deactivated, ensuring smooth transitions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback through the overhead encryption bits that continuously inform the receiver about the encryption status. The EK bit provides feedback about which encryption key is currently active, allowing the receiver to adjust its decryption operations accordingly. This feedback mechanism ensures that no frames are lost during key transitions.

Inventive Principle:
Principle #23Feedback

3Reliability

If multiple encryption keys are rotated during transmission, then security is improved, but transmission interruptions occur

Engineering Contradiction:
ImprovesecurityVSAvoidtransmission continuity
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent applies preliminary action by notifying the receiver in advance through the EK bit about upcoming encryption key changes. The overhead bits are set before the actual key rotation occurs in the data payload, allowing the receiver to pre-load and prepare the next encryption key for immediate use without interrupting transmission flow.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent maintains continuity of useful action by ensuring that encryption/decryption operations continue uninterrupted during key rotation. The overhead encryption bits enable seamless transitions between keys by providing continuous status information, allowing the receiver to switch keys without stopping data reception or causing transmission interruptions.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS10511629B2Encryption control in optical networks without data loss
Publication Date: 2019.12.17 1FINITY INC
  • US10511629B2 patent drawing
  • US10511629B2 patent drawing
  • US10511629B2 patent drawing

AI summary

Methods and systems for encryption control in optical networks without data loss enable various transitions related to encryption of an ODU data payload. A transition from unencrypted data payload to encrypted data payload is performed without data loss or dropping of OTN frames. A transition from encrypted data payload to unencrypted data payload is performed without data loss or dropping of OTN frames. A rotation of the encryption key to another encryption key is also performed without data loss or dropping of OTN frames.