Passive Optical Network Security via Encrypted Stream Hash Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Passive optical networks lack security features, allowing unauthorized access and data exploitation due to the absence of power connections and reliance on an honor system for data disposal, which can be exploited by malicious actors.
Innovation Solution
A system that generates and sends encrypted data streams with hash codes, where decryption keys combine a network device's key with a hash code, allowing devices to verify authorization by deleting unauthorized data streams and alerting on unauthorized network use, thereby enhancing security in passive optical networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If passive routers are used to eliminate power connection requirements, then ease of operation and deployment are improved, but security features deteriorate
Solution Approach 1:
The patent segments the network into active components (OLT, key management system) that perform security functions and passive components (PON devices) that transmit data. This segmentation allows the network to maintain passive infrastructure for ease of deployment while incorporating active security elements where needed.
Solution Approach 2:
The patent introduces an intermediary key management system and encryption mechanism between the OLT and PON devices. This intermediary layer provides security verification and data protection without requiring the passive routers themselves to have active security capabilities, thus maintaining deployment simplicity while adding security.
2Reliability
If encryption is implemented for network data transmission, then network security is improved, but device complexity increases
Solution Approach 1:
The patent merges the encryption and decryption functions into the existing OLT and PON device architecture. Rather than adding separate encryption hardware, the security functions are integrated into the existing network equipment, reducing overall system complexity while maintaining security.
Solution Approach 2:
The OLT and PON devices perform multiple functions including data transmission, encryption, decryption, and security verification. This multi-functionality reduces the need for separate dedicated security devices, thereby simplifying the overall system architecture while providing comprehensive security.
3Reliability
If data streams are monitored and verified for authorization, then network security is improved, but productivity decreases
Solution Approach 1:
The patent performs authorization verification and encryption setup in advance before data transmission begins. The OLT encrypts data streams beforehand and distributes them to PON devices, which then only need to perform decryption and verification of pre-established keys, significantly reducing real-time processing overhead and maintaining high transmission efficiency.
Solution Approach 2:
Once authorization is verified and encryption is established, the system rushes through data transmission without repeated verification steps. The pre-verified authorization allows bulk data transmission to proceed rapidly without continuous security checks, thereby maintaining productivity while ensuring security.
Data Source
AI summary
Improved optical network security (e.g., using a computerized tool) is enabled. Various embodiments herein can send (e.g., via a network) to a group of network devices comprising a first network device and a second network device, a first encrypted data stream, a second encrypted data stream, a first hash code, and a second hash code, wherein the first network device deletes the second encrypted data stream after the first network device hashes the second encrypted data stream, and in response to the second network device being determined not to have received the second hash code within a defined threshold time, determine that the first network device is unauthorized to use the network.


