OTN Payload Encryption Using Synchronized Key Switching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Optical Transport Network (OTN) standards do not provide encryption for payload carried in OTN frames, relying on high-layer solutions for end-to-end encryption, which are inefficient and prone to network latency and security vulnerabilities.

Innovation Solution

A method and system for encrypting and decrypting OTN payload content using a series of ordered encryption and decryption keys, synchronized through key synchronization data within the OTN frames, ensuring secure and efficient in-flight encryption and authentication by periodically switching encryption keys and initialization vectors, and utilizing in-band messaging for key management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If high-layer solutions are used for end-to-end encryption, then encryption functionality is provided, but network latency increases and security vulnerabilities arise

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent moves encryption from the high-layer (Layer 3 or above) to the physical layer (Layer 1) by implementing encryption directly on OTN frames. This dimensional shift in the OSI model allows encryption to occur at the earliest possible point in the data transmission stack, eliminating the need for higher-layer processing and thereby reducing latency while improving security.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

Encryption is performed at the source OTN device before data enters the network core, and decryption is performed at the destination OTN device. This preliminary action at the edges of the network eliminates the need for intermediate encryption/decryption operations that would otherwise occur at higher layers throughout the network path, reducing cumulative latency.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If encryption keys are managed through traditional methods, then key distribution is achieved, but key compromise risk increases

Engineering Contradiction:
ImprovesecurityVSAvoidkey compromise risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements periodic key switching where the encryption key changes at predetermined intervals (e.g., every N frames or every M seconds). This segmentation of the encryption process into discrete key periods limits the exposure window for any single key, so that if a key is compromised, only the data encrypted with that specific key during its valid period is affected, not the entire data stream.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs periodic key switching and synchronization operations at predetermined intervals. This periodic action ensures that keys are regularly updated and rotated, preventing long-term key exposure and reducing the impact of potential key compromise events.

Inventive Principle:
Principle #19Periodic action

3Productivity

If in-band messaging is used for key synchronization, then key management efficiency is improved, but OTN frame structure complexity increases

Engineering Contradiction:
Improvekey management efficiencyVSAvoidframe structure
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent utilizes existing OTN frame structures and messaging mechanisms to carry key synchronization information. By making the OTN frame structure multi-functional (carrying both data and key management information), the patent avoids creating entirely new complex structures while efficiently integrating key management into the existing OTN protocol framework.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10104047B2Method and system for encrypting/decrypting payload content of an OTN frame
Publication Date: 2018.10.16 MICROSEMI SOLUTIONS US INC
  • US10104047B2 patent drawing
  • US10104047B2 patent drawing
  • US10104047B2 patent drawing

AI summary

The present disclosure relates to a system and method of encrypting and decrypting Optical Transport Network (OTN) payload content. A transmitter of the system includes a series of ordered encryption keys and a counter for generating an initialization vector to be combined with one of the encryption keys for encrypting the OTN payload content. A receiver of the system includes a series of ordered decryption keys and a counter for generating an initialization vector to be combined with one of the decryption keys for decrypting the encrypted OTN payload content. The system synchronizes switching, at the transmitter and the receiver, the encryption and decryption keys to the next keys in each series. The system also synchronizes the counters for generating the same initialization vector at the transmitter and the receiver.