Parallel Timeslot Encryption for High-Speed Optical Transport Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current silicon technology struggles to implement encryption and authentication algorithms at high line rates greater than 10 Gbps due to complexity and practicality issues, posing a challenge for secure data transmission in Optical Transport Networks (OTNs) with increasing data rates.

Innovation Solution

The proposed solution involves using parallel encryption processes to encrypt selected portions of OTN payloads, limiting the complexity of encryption engines and allowing scalability to support higher bit rates by grouping timeslots into blocks and utilizing multiple encryption engines to process data in parallel, with the same encryption key and overhead for all encrypted blocks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption and authentication algorithms are implemented at high line rates greater than 10 Gbps, then secure data transmission is achieved, but device complexity and practicality issues arise

Engineering Contradiction:
Improvesecure data transmissionVSAvoidencryption engine complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the high-speed data stream into multiple lower-speed lanes, each processed by separate encryption engines. This segmentation allows standard encryption algorithms to operate at achievable speeds while collectively handling the full high line rate, resolving the contradiction between security requirements and device complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from a single-dimensional high-speed encryption approach to a multi-dimensional parallel processing architecture. By distributing encryption across multiple engines operating in parallel on different data lanes, the system achieves high line rate security without requiring any single engine to handle the full complexity of high-speed encryption.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If encryption is applied to all OTN payloads at high data rates, then security is improved, but implementation becomes impractical with current silicon technology

Engineering Contradiction:
Improvedata securityVSAvoidimplementation feasibility
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent segments the OTN payload into multiple timeslots that can be independently encrypted. This allows selective encryption of specific timeslots rather than requiring encryption of the entire high-speed data stream, making implementation feasible with current silicon technology while maintaining data security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies encryption to selected portions (timeslots) of the OTN payload rather than attempting to encrypt the entire data stream at full line rate. This partial action approach achieves adequate security for sensitive data while avoiding the impracticality of full-line-rate encryption with current technology.

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If multiple encryption engines are used to process data in parallel, then scalability to higher bit rates is achieved, but device complexity increases

Engineering Contradiction:
Improveencryption throughputVSAvoidnumber of encryption engines
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent designs multiple encryption engines with identical, standardized interfaces and functionality. Each engine processes a specific timeslot using the same encryption algorithm and control mechanisms, allowing for scalable deployment where additional engines can be added without increasing per-engine complexity. This universality enables productivity scaling while managing device complexity through standardization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2909966B1Timeslot encryption in an optical transport network
Publication Date: 2020.02.12 CISCO TECHNOLOGY INC
  • EP2909966B1 patent drawingFigure 1
  • EP2909966B1 patent drawingFigure 2
  • EP2909966B1 patent drawingFigure 3A

AI summary

An Optical Transport Network (OTN) frame comprises an optical channel payload unit that is divided into a plurality of timeslots. This OTN frame is received at a transmitter and the timeslots are grouped into blocks of timeslots. Two or more blocks of timeslots are selected for encryption and are encrypted/authenticated in parallel to generate an encrypted OTN frame in which only certain blocks of timeslots are encrypted.