Multicast Encryption in Passive Optical Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current PON systems lack effective encryption mechanisms for multicast data, leading to security vulnerabilities where a compromised key can decrypt all service content, increasing the burden on the OLT and complicating encryption processes.

Innovation Solution

Implementing a method where the OLT generates a common key for multicast service data and sends it via a management control channel to activated ONUs, with key regeneration and aging to ensure secure encryption, reducing the complexity of the encryption mechanism and limiting key distribution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a universal key is set in the overall network range to encrypt services, then encryption coverage is improved, but security deteriorates because once the key is acquired by a malicious user, all service content in the overall network will be decrypted and stolen

Engineering Contradiction:
Improveencryption coverageVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent divides the network into multiple PON ports, each with its own encryption key. Instead of using a single universal key for the entire network, the encryption scope is segmented by PON port, so that compromise of one key only affects services on that specific port, not the entire network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each PON port is assigned a unique encryption key specific to that port's services. This localizes the security properties to each port, allowing differentiated security management where each port can have its own key without affecting other ports.

Inventive Principle:
Principle #3Local quality

2Reliability

If multicast service data packets are duplicated to each PON port and unicast channel with unicast encryption mechanism applied, then security against malicious users is improved, but device complexity increases due to the burden on the OLT

Engineering Contradiction:
ImprovesecurityVSAvoidOLT burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the encryption function from the data duplication process. Instead of encrypting after duplication, the system encrypts the original multicast data before distribution, eliminating the need for separate unicast encryption channels while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The encryption mechanism is designed to work universally across all PON ports and all multicast services. A single encryption operation on the original data provides security for all distributed copies, making the encryption system multi-functional rather than requiring separate encryption for each channel.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If a common key is used for all multicast service data in the same bearer channel, then ease of operation is improved, but security deteriorates because the key must be sent to multiple ONUs, increasing exposure risk

Engineering Contradiction:
Improveencryption managementVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the key distribution scope by PON port. Each PON port has its own encryption key that is only distributed to ONUs connected to that specific port. This segmentation maintains operational simplicity within each port while reducing the security risk associated with key distribution to multiple ONUs across the entire network.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2439871B1Method and device for encrypting multicast service in passive optical network system
Publication Date: 2018.01.31 ZTE CORP
  • EP2439871B1 patent drawingFigure 1
  • EP2439871B1 patent drawingFigure 2
  • EP2439871B1 patent drawingFigure 3

AI summary

A method for encrypting multicast services in a passive optical network system is provided in the present invention, and the method includes: an Optical Line Terminal (OLT) generating a public key, and using the public key to encrypt the multicast service data in a bearer channel and then transmitting the encrypted data, the multicast service data in the same one bearer channel being encrypted using the same public key; and said OLT sending the public key ,which is used to encrypt the multicast service data, via a management control channel to an Optical Network Unit (ONU) which is activated successfully and requests to receive said multicast service data. A device for encrypting multicast services in a passive optical network system is also provided in the present invention. By applying the bearer channel encryption mechanism, the present invention is able to reduce the complexity of the OLT encryption mechanism and the ONU decryption mechanism on the premise of ensuring the encryption of the multicast services.