ALARM CONDITION PROCESSING IN NETWORK ELEMENT
Techniques for alarm condition processing in communication networks. In one example, a method comprises the following steps. An alarm condition associated with a network element of a communication network is detected. Alarm indication data is generated based on the alarm condition detected. The alarm indication data is protected using a cryptographic key to generate protected alarm indication data. The protected alarm indication data (e.g., tamper evidence) is stored in a non-volatile memory, and may be reset either autonomously (e.g., timer expiration) or from the communication network.
1 . A method, comprising:
detecting an alarm condition associated with a network element of a communication network;
generating alarm indication data based on the alarm condition detected;
protecting the alarm indication data using a cryptographic key to generate protected alarm indication data; and
storing the protected alarm indication data in a non-volatile memory.
2 . The method of claim 1 , wherein the protecting step further comprises integrity protecting the alarm indication data using the cryptographic key to generate integrity protected alarm indication data.
3 . The method of claim 1 , wherein the protecting step further comprises replay protecting the alarm indication data to generate replay protected alarm indication data.
4 . The method of claim 1 , wherein the protecting step further comprises confidentiality protecting the alarm indication data to generate confidentiality protected alarm indication data.
5 . The method of claim 1 , wherein the alarm indication data comprises at least one value indicative of the detected alarm condition.
6 . The method of claim 5 , wherein the alarm indication data comprises metadata associated with the at least one value indicative of the detected alarm condition.
7 . The method of claim 5 , wherein the alarm indication data comprises auxiliary data associated with the at least one value indicative of the detected alarm condition.
8 . The method of claim 1 , wherein the cryptographic key is stored in a tamper-resistant environment of the network element.
9 . The method of claim 1 , further comprising, upon a subsequent power up cycle of the network element, analyzing the protected alarm indication data stored in the non-volatile memory for a tamper indication.
10 . The method of claim 9 , further comprising initiating a power off cycle when the analysis indicates that the protected alarm indication data stored in the non-volatile memory has been or likely has been tampered with.
11 . The method of claim 9 , further comprising placing the network element in a limited functionality mode when the analysis indicates that the protected alarm indication data stored in the non-volatile memory has been or likely has been tampered with.
12 . The method of claim 1 , further comprising initiating a power off cycle after storing the protected alarm indication data in the non-volatile memory.
13 . The method of claim 1 , further comprising placing the network element in a limited functionality mode after storing the protected alarm indication data in the non-volatile memory.
14 . A computer program product comprising a processor-readable storage medium having encoded therein executable code of one or more software programs, wherein the one or more software programs when executed by at least one processor of the network element implement the steps of the method of claim 1 .
15 . An apparatus, comprising:
a non-volatile memory; and
at least one processor operatively coupled to the non-volatile memory and configured to:
detect an alarm condition associated with a network element of a communication network;
generate alarm indication data based on the alarm condition detected;
protect the alarm indication data using a cryptographic key to generate protected alarm indication data; and
store the protected alarm indication data in the non-volatile memory.
16 . The apparatus of claim 15 , wherein the protecting operation further comprises integrity protecting the alarm indication data using the cryptographic key to generate integrity protected alarm indication data.
17 . The apparatus of claim 15 , wherein the at least one processor is further configured to, upon a subsequent power up cycle of the network element, analyze the protected alarm indication data stored in the non-volatile memory for a tamper indication.
18 . The apparatus of claim 17 , wherein the at least one processor is further configured to initiate a power off cycle when the analysis indicates that the protected alarm indication data stored in the non-volatile memory has been or likely has been tampered with.
19 . The apparatus of claim 17 , wherein the at least one processor is further configured to place the network element in a limited functionality mode when the analysis indicates that the protected alarm indication data stored in the non-volatile memory has been or likely has been tampered with.
20 . A network element, comprising:
a non-volatile memory; and
at least one processor operatively coupled to the non-volatile memory and configured to:
detect an alarm condition associated with the network element;
generate alarm indication data based on the alarm condition detected;
protect the alarm indication data using a cryptographic key to generate protected alarm indication data; and
store the protected alarm indication data in the non-volatile memory.