Multicast Encryption in Passive Optical Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current PON systems lack effective encryption mechanisms for multicast data, leading to security vulnerabilities where a compromised key can decrypt all service content, increasing the burden on the OLT and complicating encryption processes.
Innovation Solution
Implementing a method where the OLT generates a common key for multicast service data and sends it via a management control channel to activated ONUs, with key regeneration and aging to ensure secure encryption, reducing the complexity of the encryption mechanism and limiting key distribution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a universal key is set in the overall network range to encrypt services, then encryption coverage is improved, but security deteriorates because once the key is acquired by a malicious user, all service content in the overall network will be decrypted and stolen
Solution Approach 1:
The patent divides the network into multiple PON ports, each with its own encryption key. Instead of using a single universal key for the entire network, the encryption scope is segmented by PON port, so that compromise of one key only affects services on that specific port, not the entire network.
Solution Approach 2:
Each PON port is assigned a unique encryption key specific to that port's services. This localizes the security properties to each port, allowing differentiated security management where each port can have its own key without affecting other ports.
2Reliability
If multicast service data packets are duplicated to each PON port and unicast channel with unicast encryption mechanism applied, then security against malicious users is improved, but device complexity increases due to the burden on the OLT
Solution Approach 1:
The patent extracts the encryption function from the data duplication process. Instead of encrypting after duplication, the system encrypts the original multicast data before distribution, eliminating the need for separate unicast encryption channels while maintaining security.
Solution Approach 2:
The encryption mechanism is designed to work universally across all PON ports and all multicast services. A single encryption operation on the original data provides security for all distributed copies, making the encryption system multi-functional rather than requiring separate encryption for each channel.
3Ease of operation
If a common key is used for all multicast service data in the same bearer channel, then ease of operation is improved, but security deteriorates because the key must be sent to multiple ONUs, increasing exposure risk
Solution Approach 1:
The patent segments the key distribution scope by PON port. Each PON port has its own encryption key that is only distributed to ONUs connected to that specific port. This segmentation maintains operational simplicity within each port while reducing the security risk associated with key distribution to multiple ONUs across the entire network.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method for encrypting multicast services in a passive optical network system is provided in the present invention, and the method includes: an Optical Line Terminal (OLT) generating a public key, and using the public key to encrypt the multicast service data in a bearer channel and then transmitting the encrypted data, the multicast service data in the same one bearer channel being encrypted using the same public key; and said OLT sending the public key ,which is used to encrypt the multicast service data, via a management control channel to an Optical Network Unit (ONU) which is activated successfully and requests to receive said multicast service data. A device for encrypting multicast services in a passive optical network system is also provided in the present invention. By applying the bearer channel encryption mechanism, the present invention is able to reduce the complexity of the OLT encryption mechanism and the ONU decryption mechanism on the premise of ensuring the encryption of the multicast services.