APPARATUS AND METHOD FOR AVOIDING DETERMINISTIC BLANKING OF SECURE TRAFFIC

    公开(公告)号:US20200067660A1

    公开(公告)日:2020-02-27

    申请号:US16667958

    申请日:2019-10-30

    Abstract: In one embodiment an apparatus, method, and system is described, the embodiment an apparatus, method including receiving a stream of data frames at an input interface, the data frames one of including security frames, or being included in security frames, wherein the security frames include payload data, performing forward error correction on the data frames a forward error correction (FEC) decoder, buffering received data frames at a buffer and blanker engine and building a complete security frame of the received data frames, determining whether or not to suppress taking a consequent action based on a frequency of authentication errors at an authentication engine, wherein the consequent action to be taken or suppressed, when taken, is taken upon payload data of one or more security frames including a data frame upon which an authentication error occurred. Related apparatus, methods and systems are also described.

    ENCRYPTED AND AUTHENTICATED DATA FRAME
    23.
    发明申请

    公开(公告)号:US20170230338A1

    公开(公告)日:2017-08-10

    申请号:US15015548

    申请日:2016-02-04

    Abstract: At a source network device, data is compiled into a plurality of data blocks for transmission in a data frame over a network to a destination network device. The plurality of data blocks are arranged into a plurality of data block groups such that each data block group comprises a predetermined number of data blocks. Encryption information is generated for each of the plurality of data blocks groups. The encryption information identifies an encryption key for each of the plurality of data block groups. Overhead data configured to allow the destination network device to align and decode the data frame is generated. The data frame is transmitted from the source network device to the destination network device such that the encryption information for each of the plurality of data block groups is transmitted consecutively with a respective data block group, and a portion of the overhead data is transmitted prior to each consecutive transmission of encryption information with a data block group.

    DATA SECURITY FOR NETWORKS COMBINING ENCRYPTION WITH ERROR CORRECTION

    公开(公告)号:US20250070989A1

    公开(公告)日:2025-02-27

    申请号:US18454416

    申请日:2023-08-23

    Abstract: In one example embodiment, data is received at a node of a network. The data includes encrypted data segments containing data portions and error correction information. The encrypted data segments are decrypted to produce the data portions and the error correction information. Error correction is performed on the data portions using the error correction information. Corrupt data is determined based on the error correction indicating uncorrectable data.

    Method, apparatus and system for error control

    公开(公告)号:US11258537B2

    公开(公告)日:2022-02-22

    申请号:US17101083

    申请日:2020-11-23

    Abstract: A first device receives a first container frame having a payload of a first length. The payload of the container frame includes multiple optical transport unit (OTU) frames, each of which includes an optical data unit (ODU) frame and a sequence of forward error correction (FEC) bits for the ODU frame. Each OTU frame is associated with a first sequence of error-identifying bits. The first device determines, for each OTU frame, a second sequence of error-identifying bits, and forms a second container frame including the OTU frames, the first sequences of error-identifying bits, and the second sequences of error-identifying bits. The first device transmits the second container frame to a second device.

    Security over optical transport network beyond 100G

    公开(公告)号:US10985847B2

    公开(公告)日:2021-04-20

    申请号:US15849959

    申请日:2017-12-21

    Abstract: A method divides data traffic into multiple optical transport units formatted according to an optical transport network (OTN) standard. The multiple optical transport units include a master optical network unit and one or more slave optical network units. Each optical network unit includes overhead and a payload. The overhead includes used overhead specifically defined in the OTN standard and unused overhead not specifically defined in the OTN standard. The method encrypts each optical network unit with a respective one of multiple encryption keys, defines security control parameters identifying the multiple encryption keys, and inserts the security control parameters into the unused overhead of a first slave optical network unit among the one or more slave optical network units. The method transmits the optical network units in encrypted form.

    Security protection of terabit ethernet PCS layer using alignment markers

    公开(公告)号:US10404402B2

    公开(公告)日:2019-09-03

    申请号:US15712385

    申请日:2017-09-22

    Abstract: A method generates, from an input data stream, multiple lanes of a physical coding sublayer (PCS) signal. The method converts the data stream to a sequence of bit blocks, and periodically inserts into the sequence of bit blocks an alignment marker (AM) group including multiple individual alignment markers for respective ones of the multiple lanes. The method adds security protection to each bit block according to a security protocol to produce a sequence of protected bit blocks, and modifies each AM group with security information to be used by the security protocol to remove the security protection added to the sequence of protected bit blocks. The method applies forward error correction to the sequence of protected bit blocks and the modified AM groups to produce forward error correction codewords, and produces the multiple lanes from the codewords. The method transmits the multiple lanes over an optical link.

    Timeslot encryption in an optical transport network
    30.
    发明授权
    Timeslot encryption in an optical transport network 有权
    光传输网络中的时隙加密

    公开(公告)号:US08942379B2

    公开(公告)日:2015-01-27

    申请号:US13653521

    申请日:2012-10-17

    Abstract: An Optical Transport Network (OTN) frame comprises an optical channel payload unit that is divided into a plurality of timeslots. This OTN frame is received at a transmitter and the timeslots are grouped into blocks of timeslots. Two or more blocks of timeslots are selected for encryption and are encrypted/authenticated in parallel to generate an encrypted OTN frame in which only certain blocks of timeslots are encrypted.

    Abstract translation: 光传输网络(OTN)帧包括被分成多个时隙的光信道有效载荷单元。 该OTN帧在发射机处被接收,时隙被分组成时隙块。 选择两个或更多个时隙块进行加密,并且并行加密/认证,以生成加密的OTN帧,其中仅某些时隙块被加密。

Patent Agency Ranking