Short MACsec Headers for EPON Security and Bandwidth
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security standards for Ethernet Passive Optical Networks (EPON) lack effective measures to protect upstream and downstream data from hostile identification and jamming, particularly due to unencrypted MPCP messages and limited offset values that expose MAC addresses, leading to potential security breaches.
Innovation Solution
Implementing a system that encrypts local packets using short MACsec headers and pre-determined Secure Association Keys (SAKs), including encryption of OAM and MPCP packets, and using tunnel mode to secure data transmission, while also securing registration requests with pre-shared SAKs and random PN numbers to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If standard MACsec encryption is implemented with full headers, then data security is improved, but bandwidth consumption increases
Solution Approach 1:
The patent extracts only the essential security functionality from the full MACsec header by implementing a shortened header format that retains encryption and authentication capabilities while removing redundant fields. This allows security to be maintained with reduced overhead, directly addressing the bandwidth consumption issue.
Solution Approach 2:
The patent changes the parameter of header length from standard full length to shortened length, while adjusting other parameters such as key management and encryption scope to maintain security effectiveness. This parameter change resolves the contradiction between security and bandwidth usage.
2Adaptability or versatility
If MPCP messages are left unencrypted for compatibility, then network interoperability is maintained, but security vulnerability increases
Solution Approach 1:
The patent applies different encryption treatments to different message types: MPCP messages use a specialized encryption mode that maintains compatibility with existing infrastructure, while other traffic uses standard encryption. This local differentiation allows security improvement without completely breaking interoperability.
Solution Approach 2:
The patent introduces an intermediary encryption layer for MPCP messages that acts as a bridge between secure and legacy systems. This intermediary approach allows encrypted MPCP messages to be processed by both secure and non-secure nodes, maintaining interoperability while improving security.
3Device complexity
If security offsets are limited to standard values, then implementation complexity is reduced, but security coverage is insufficient
Solution Approach 1:
The patent transforms the static, fixed security offset values into a dynamic, configurable system where offsets can be adjusted based on traffic type and security requirements. This dynamic approach increases security coverage without proportionally increasing implementation complexity.
Solution Approach 2:
The patent segments the packet structure into encrypted and unencrypted portions using configurable offsets, allowing different parts of the packet to be treated differently. This segmentation enables flexible security coverage while maintaining manageable implementation through standardized offset mechanisms.
4Ease of operation
If MAC addresses are exposed in headers for identification, then packet routing is simplified, but host identification security is compromised
Solution Approach 1:
The patent introduces pseudo-MAC addresses or temporary identifiers that copy the functional purpose of real MAC addresses for routing decisions without exposing the actual host identification information. These copied identifiers perform the routing function while protecting the underlying security requirement.
Data Source
AI summary
A method and system is provided for securing communication on an EPON. Particularly different types of encrypted messages, each with a respective short MAC SegTAG, may be sent from the OLT to an ONU and from an ONU to the OLT without need for a full SecTAG with an explicit SCI. Discovery and control messages may be encrypted and a security offset may be less than 30 bytes. A packet header including its MAC address may be encrypted.


