IP Library Granted Patent US 10,567,352
Granted Patent B2
US 10,567,352 · App. 16/255,926 · Granted Feb 18, 2020

Flexible ethernet encryption systems and methods

Inventors: Sebastien Gareau (Ottawa, CA); Timothy L. Norman (Ottawa, CA); Marc W. Leclair (Gatineau, CA); Michael Watford (Ottawa, CA)
Assignee: Ciena Corporation
H04L63/0428H04J3/1652H04L1/0002H04L1/0061H04L9/0631H04L9/0637H04L9/0819H04L9/30H04L9/3215H04L63/0876
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,567,352
App. No.
16/255,926
Granted
Feb 18, 2020
Kind
B2
Abstract

Systems and methods for Physical Coding Sublayer (PCS) encryption implemented by a first network element communicatively coupled to a second network element include encrypting a Flexible Ethernet (FlexE) signal based on a first encryption key with encryption applied to a 64b/66b bit stream associated with the FlexE signal at one or more of a FlexE client layer and a FlexE shim layer; switching to a second encryption key at a predetermined point in the FlexE signal; and encrypting the FlexE signal with the second encryption key subsequent to the switching.

Claims (36)

1. A method for Physical Coding Sublayer (PCS) encryption implemented by a first network element communicatively coupled to a second network element, the method comprising:

encrypting a Flexible Ethernet (FlexE) signal based on a first encryption key with encryption applied to a 64b/66b bit stream associated with the FlexE signal at one or more of a FlexE client layer and a FlexE shim layer;

switching to a second encryption key at a predetermined point in the FlexE signal; and

encrypting the FlexE signal with the second encryption key subsequent to the switching.

2. The method of claim 1 , wherein the predetermined point in the FlexE signal is a multiframe boundary in FlexE overhead.

3. The method of claim 1 , further comprising

utilizing an encryption messaging channel in FlexE overhead to coordinate the switching.

4. The method of claim 3 , further comprising

utilizing the encryption messaging channel to establish the first encryption key and the second encryption key.

5. The method of claim 3 , wherein the encryption messaging channel utilizes one or more of reserved bytes in the FlexE overhead and a management channel.

6. The method of claim 3 , wherein the encryption messaging channel utilizes a FlexE client or PCS stream with a designed Operational code.

7. The method of claim 1 , wherein the encryption is applied to the 64b/66b bit stream with one of (i) only data blocks encrypted and (ii) data blocks encrypted along with one or more control blocks comprising a start of packet and an end of packet.

8. The method of claim 1 , wherein the encryption utilizes one or more of Advanced Encryption Standard (AES) and Galois/Counter Mode (GCM).

9. An apparatus for Physical Coding Sublayer (PCS) encryption implemented at a first network element communicatively coupled to a second network element, the apparatus comprising:

circuitry configured to encrypt a Flexible Ethernet (FlexE) signal based on a first encryption key with encryption applied to a 64b/66b bit stream associated with the FlexE signal at one or more of a FlexE client layer and a FlexE shim layer;

circuitry configured to switch to a second encryption key at a predetermined point in the FlexE signal; and

circuitry configured to encrypt the FlexE signal with the second encryption key subsequent to the switch to the second encryption key.

10. The apparatus of claim 9 , wherein the predetermined point in the FlexE signal is a multiframe boundary in FlexE overhead.

11. The apparatus of claim 9 , further comprising

circuitry configured to utilize an encryption messaging channel in FlexE overhead to coordinate the switch to the second encryption key.

12. The apparatus of claim 11 , further comprising

circuitry configured to utilize the encryption messaging channel to establish the first encryption key and the second encryption key.

13. The apparatus of claim 11 , wherein the encryption messaging channel utilizes one or more of reserved bytes in the FlexE overhead and a management channel.

14. The apparatus of claim 11 , wherein the encryption messaging channel utilizes a FlexE client or PCS stream with a designed Operational code.

15. The apparatus of claim 9 , wherein the encryption is applied to the 64b/66b bit stream with one of (i) only data blocks encrypted and (ii) data blocks encrypted along with one or more control blocks comprising a start of packet and an end of packet.

16. The apparatus of claim 9 , wherein the encryption utilizes one or more of Advanced Encryption Standard (AES) and Galois/Counter Mode (GCM).

17. A network configured for Physical Coding Sublayer (PCS) encryption, the network comprising:

a first network element; and

a second network element communicatively coupled to the first network element,

wherein the first network element is configured to

encrypt a Flexible Ethernet (FlexE) signal based on a first encryption key with encryption applied to a 64b/66b bit stream associated with the FlexE signal at one or more of a FlexE client layer and a FlexE shim layer;

switch to a second encryption key at a predetermined point in the FlexE signal; and

encrypt the FlexE signal with the second encryption key subsequent to the switch to the second encryption key.

18. The network of claim 17 , wherein the predetermined point in the FlexE signal is a multiframe boundary in FlexE overhead.

19. The network of claim 17 , wherein an encryption messaging channel in FlexE overhead is used to coordinate the switch to the second encryption key.

20. The network of claim 17 , wherein the encryption utilizes one or more of Advanced Encryption Standard (AES) and Galois/Counter Mode (GCM).

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2019
From: GAREAU, SEBASTIEN; NORMAN, TIMOTHY L.; LECLAIR, MARC W.; WATFORD, MICHAEL
To: CIENA CORPORATION
Reel/Frame 048118/0229 →
Continuity (2)
Continuation In Part 14966779 · Dec 11, 2015
Related Publication 20190173856A1 · Jun 6, 2019
Cited By (3)
US 12,445,196 US 12,556,376 US 12,671,517