Short MACsec Headers for EPON Security and Bandwidth

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security standards for Ethernet Passive Optical Networks (EPON) lack effective measures to protect upstream and downstream data from hostile identification and jamming, particularly due to unencrypted MPCP messages and limited offset values that expose MAC addresses, leading to potential security breaches.

Innovation Solution

Implementing a system that encrypts local packets using short MACsec headers and pre-determined Secure Association Keys (SAKs), including encryption of OAM and MPCP packets, and using tunnel mode to secure data transmission, while also securing registration requests with pre-shared SAKs and random PN numbers to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If standard MACsec encryption is implemented with full headers, then data security is improved, but bandwidth consumption increases

Engineering Contradiction:
Improvedata securityVSAvoidbandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent extracts only the essential security functionality from the full MACsec header by implementing a shortened header format that retains encryption and authentication capabilities while removing redundant fields. This allows security to be maintained with reduced overhead, directly addressing the bandwidth consumption issue.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the parameter of header length from standard full length to shortened length, while adjusting other parameters such as key management and encryption scope to maintain security effectiveness. This parameter change resolves the contradiction between security and bandwidth usage.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If MPCP messages are left unencrypted for compatibility, then network interoperability is maintained, but security vulnerability increases

Engineering Contradiction:
Improvenetwork interoperabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies different encryption treatments to different message types: MPCP messages use a specialized encryption mode that maintains compatibility with existing infrastructure, while other traffic uses standard encryption. This local differentiation allows security improvement without completely breaking interoperability.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces an intermediary encryption layer for MPCP messages that acts as a bridge between secure and legacy systems. This intermediary approach allows encrypted MPCP messages to be processed by both secure and non-secure nodes, maintaining interoperability while improving security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If security offsets are limited to standard values, then implementation complexity is reduced, but security coverage is insufficient

Engineering Contradiction:
Improveimplementation complexityVSAvoidsecurity coverage
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent transforms the static, fixed security offset values into a dynamic, configurable system where offsets can be adjusted based on traffic type and security requirements. This dynamic approach increases security coverage without proportionally increasing implementation complexity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent segments the packet structure into encrypted and unencrypted portions using configurable offsets, allowing different parts of the packet to be treated differently. This segmentation enables flexible security coverage while maintaining manageable implementation through standardized offset mechanisms.

Inventive Principle:
Principle #1Segmentation

4Ease of operation

If MAC addresses are exposed in headers for identification, then packet routing is simplified, but host identification security is compromised

Engineering Contradiction:
Improvepacket routingVSAvoidhost identification security
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces pseudo-MAC addresses or temporary identifiers that copy the functional purpose of real MAC addresses for routing decisions without exposing the actual host identification information. These copied identifiers perform the routing function while protecting the underlying security requirement.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8397064B2Implementing IEEE 802.1AE and 802.1 af security in EPON (1GEPON and 10GEPON) networks
Publication Date: 2013.03.12 MICROSEMI ISRAEL STORAGE SOLUTIONS LTD
  • US8397064B2 patent drawing
  • US8397064B2 patent drawing
  • US8397064B2 patent drawing

AI summary

A method and system is provided for securing communication on an EPON. Particularly different types of encrypted messages, each with a respective short MAC SegTAG, may be sent from the OLT to an ONU and from an ONU to the OLT without need for a full SecTAG with an explicit SCI. Discovery and control messages may be encrypted and a security offset may be less than 30 bytes. A packet header including its MAC address may be encrypted.