OTN Overhead Encryption Bits for Seamless Key Rotation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing optical communication networks face challenges in efficiently encrypting data payloads due to computationally intensive encryption key generation and management, leading to potential data frame losses during encryption activation, deactivation, and key rotation.
Innovation Solution
The method utilizes overhead encryption bits in optical transport network (OTN) frames for encryption signaling, including set_encryption, deprovision_encryption, and encryption key bits, stored as additional authenticated data, to enable seamless transitions between encrypted and unencrypted states without data frame loss, using a 128-bit tag for integrity and a 48-bit counter for key changes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional encryption methods are used in optical networks, then data security is improved, but data frames are dropped during encryption activation, deactivation, and key rotation
Solution Approach 1:
The patent applies preliminary action by pre-synchronizing encryption keys between transmitter and receiver before actual data transmission begins. The method establishes key synchronization through overhead signaling in advance, so that when encryption activation or key rotation occurs during data transmission, both ends are already prepared and no data frames need to be dropped. This resolves the contradiction by preparing the encryption state beforehand, eliminating information loss during transitions.
2Reliability
If encryption key generation and management is performed securely, then data security is improved, but computational overhead increases and network performance decreases
Solution Approach 1:
The patent extracts the computationally intensive key management operations from the data transmission path by utilizing overhead signaling resources. Encryption key synchronization is performed through dedicated overhead bits rather than through the main data channel, separating security functions from data transmission functions. This allows secure key management to occur in parallel without blocking or slowing down data flow, thus maintaining network performance while ensuring data security.
Solution Approach 2:
The patent introduces overhead signaling as an intermediary mechanism for key management. Instead of directly managing encryption keys through computationally intensive operations on the data path, the system uses overhead bits as a mediator to synchronize key states between transmitter and receiver. This intermediary approach handles the computational burden of key management separately, allowing the main data transmission path to operate at full speed without performance degradation.
3Adaptability or versatility
If encryption is activated or deactivated during data transmission, then data security flexibility is improved, but data frames are dropped during transitions
Solution Approach 1:
The patent implements feedback through overhead signaling that continuously communicates encryption state between transmitter and receiver. Before any encryption activation or deactivation occurs, the system uses overhead bits to signal the impending state change and confirm synchronization. This feedback mechanism ensures both ends are synchronized before transitioning, allowing encryption flexibility to be maintained without dropping data frames during transitions.
Data Source
AI summary
Methods and systems may use optical transport network overhead data for encryption. In particular, specific overhead encryption bits and other encryption data may be stored in an OTN header and used for signaling between a transmitter and a receiver for encrypted transmission without lost data frames.


