PCS Alignment Markers for Secure Terabit Ethernet Lanes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The IEEE 802.3bs standard for Terabit Ethernet (TbE) does not provide security protection for physical coding sublayer (PCS) lanes, such as encryption and authentication, which is essential for secure data transmission.

Innovation Solution

A method is introduced to generate security-protected PCS signals by inserting alignment markers (AM) groups with security information, applying encryption and authentication to bit blocks, and using forward error correction to produce codewords, which are then transmitted over optical links, maintaining the existing PCS frame format without increasing bandwidth.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security protection (encryption and authentication) is added to PCS lanes, then data transmission security is improved, but transmission bandwidth is reduced due to additional overhead

Engineering Contradiction:
Improvedata transmission securityVSAvoidtransmission bandwidth
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts security information from the data payload and places it in dedicated overhead fields (alignment markers and FEC blocks). This separation allows security functionality to be added without consuming bandwidth that would otherwise carry user data, as the security overhead is systematically organized in specific structural elements rather than being distributed throughout the data stream

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The alignment markers and FEC blocks serve dual purposes: they maintain their original functions for frame synchronization and error correction, while simultaneously carrying security information such as encryption keys and authentication data. This multi-functionality allows security protection to be integrated without requiring separate dedicated channels, thereby preserving transmission bandwidth

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If security information is inserted into alignment markers and FEC blocks, then security protection is provided, but device complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidPCS layer processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments security information into distinct components and places them in different locations within the PCS frame structure. Encryption keys are inserted in specific alignment marker positions, while authentication data is placed in FEC blocks. This segmentation allows each security function to be processed independently at appropriate stages, reducing the complexity burden on any single processing element

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Security information is inserted into alignment markers and FEC blocks during the PCS encoding stage, before the data is transmitted through the physical layer. This preliminary action ensures that security processing is completed upfront, allowing subsequent layers to receive pre-secured data without needing to perform additional security operations, thereby reducing overall system complexity

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10404402B2Security protection of terabit ethernet PCS layer using alignment markers
Publication Date: 2019.09.03 CISCO TECHNOLOGY INC
  • US10404402B2 patent drawing
  • US10404402B2 patent drawing
  • US10404402B2 patent drawing

AI summary

A method generates, from an input data stream, multiple lanes of a physical coding sublayer (PCS) signal. The method converts the data stream to a sequence of bit blocks, and periodically inserts into the sequence of bit blocks an alignment marker (AM) group including multiple individual alignment markers for respective ones of the multiple lanes. The method adds security protection to each bit block according to a security protocol to produce a sequence of protected bit blocks, and modifies each AM group with security information to be used by the security protocol to remove the security protection added to the sequence of protected bit blocks. The method applies forward error correction to the sequence of protected bit blocks and the modified AM groups to produce forward error correction codewords, and produces the multiple lanes from the codewords. The method transmits the multiple lanes over an optical link.