OTN Overhead Encryption Bits for Seamless Key Rotation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing optical communication networks face challenges in efficiently encrypting data payloads due to computationally intensive encryption key generation and management, leading to potential data frame losses during encryption activation, deactivation, and key rotation.

Innovation Solution

The method utilizes overhead encryption bits in optical transport network (OTN) frames for encryption signaling, including set_encryption, deprovision_encryption, and encryption key bits, stored as additional authenticated data, to enable seamless transitions between encrypted and unencrypted states without data frame loss, using a 128-bit tag for integrity and a 48-bit counter for key changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional encryption methods are used in optical networks, then data security is improved, but data frames are dropped during encryption activation, deactivation, and key rotation

Engineering Contradiction:
Improvedata securityVSAvoiddata frame loss
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies preliminary action by pre-synchronizing encryption keys between transmitter and receiver before actual data transmission begins. The method establishes key synchronization through overhead signaling in advance, so that when encryption activation or key rotation occurs during data transmission, both ends are already prepared and no data frames need to be dropped. This resolves the contradiction by preparing the encryption state beforehand, eliminating information loss during transitions.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If encryption key generation and management is performed securely, then data security is improved, but computational overhead increases and network performance decreases

Engineering Contradiction:
Improvedata securityVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the computationally intensive key management operations from the data transmission path by utilizing overhead signaling resources. Encryption key synchronization is performed through dedicated overhead bits rather than through the main data channel, separating security functions from data transmission functions. This allows secure key management to occur in parallel without blocking or slowing down data flow, thus maintaining network performance while ensuring data security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces overhead signaling as an intermediary mechanism for key management. Instead of directly managing encryption keys through computationally intensive operations on the data path, the system uses overhead bits as a mediator to synchronize key states between transmitter and receiver. This intermediary approach handles the computational burden of key management separately, allowing the main data transmission path to operate at full speed without performance degradation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If encryption is activated or deactivated during data transmission, then data security flexibility is improved, but data frames are dropped during transitions

Engineering Contradiction:
Improveencryption flexibilityVSAvoiddata frame loss
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent implements feedback through overhead signaling that continuously communicates encryption state between transmitter and receiver. Before any encryption activation or deactivation occurs, the system uses overhead bits to signal the impending state change and confirm synchronization. This feedback mechanism ensures both ends are synchronized before transitioning, allowing encryption flexibility to be maintained without dropping data frames during transitions.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10469459B2Use of optical transport network overhead data for encryption
Publication Date: 2019.11.05 FUJITSU LTD
  • US10469459B2 patent drawing
  • US10469459B2 patent drawing
  • US10469459B2 patent drawing

AI summary

Methods and systems may use optical transport network overhead data for encryption. In particular, specific overhead encryption bits and other encryption data may be stored in an OTN header and used for signaling between a transmitter and a receiver for encrypted transmission without lost data frames.