Authentication and initial key exchange in ethernet passive optical network over coaxial network

US9270651B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9270651-B2
Application numberUS-201414243387-A
CountryUS
Kind codeB2
Filing dateApr 2, 2014
Priority dateApr 5, 2013
Publication dateFeb 23, 2016
Grant dateFeb 23, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method comprising generating an updated security key upon expiration of a key exchange timer, transferring the updated security key to a Coaxial Network Unit (CNU), retaining an original key, wherein the updated security key comprises a different key identification number than the original key, accepting and decrypting upstream traffic that employs either the original key or the updated key, after transferring the updated security key to the CNU, creating a key switchover timer, before the key switchover timer expires, verify that upstream traffic transferred from the CNU on a logical link uses the updated security key, and when upstream traffic is encrypted using the updated security key, begin using the updated security key to encrypt downstream traffic and clear the key switchover timer.

First claim

Opening claim text (preview).

What is claimed is: 1. An Optical Line Terminal (OLT) comprising: a receiver coupled to a Passive Optical Network (PON) and configured to receive a security key request from a Fiber Coaxial Unit (FCU) via the PON wherein the receiver is further configured to receive an upstream message from a Coaxial Network Unit (CNU) via the FCU and an Ethernet PON over Coaxial (EPoC) network; a processor coupled to the receiver and configured to: generate a first security key responsive to the security key request from the FCU; encrypt the first security key in a security key response message; encrypt a downstream message with the first security key; decrypt the upstream first security key; and initiate a switchover from the first security key to a second security key upon expiration of a timer; a transmitter coupled to the processor and configured to transmit the security key response message comprising the encrypted first security key to the FCU via the PON, wherein the transmitter is further configured to transmit the downstream message toward the CNU via the FCU and the EPoC network, wherein the switchover comprises: generating and encrypting the second security key by the processor; transmitting the encrypted second security key toward the CNU by the transmitter; encrypting downstream traffic with the first security key until the receiver receives upstream traffic from the CNU that is encrypted with the second security key; and encrypting downstream traffic with the second security key in response to receiving upstream traffic that is encrypted with the second security key. 2. The OLT of claim 1 , wherein the transmitter is further configured to transmit a key switchover verification message to request an acknowledgement that the switchover is complete at the CNU. 3. The OLT of claim 2 , wherein the transmitter is further configured to transmit the key switchover verification message to request an acknowledgement that the switchover is complete at the FCU. 4. A method comprising: generating, by an Optical Line Terminal (OLT), an updated security key upon expiration of a key exchange timer; transferring, by the OLT, the updated security key to an endpoint, wherein the endpoint is at least one of a Fiber Coaxial Unit (FCU) and a Coaxial Network Unit (CNU), wherein the OLT transfers the updated security key to the FCU via a Passive Optical Network (PON) when the endpoint is the FCU, and wherein the OLT transfers the updated security key to the CNU via the FCU and an Ethernet PON over Coaxial (EPoC) network when the endpoint is the CNU; retaining an original security key, wherein the updated security key comprises a different key identification number than the original security key; accepting and decrypting upstream traffic that employs either the original security key or the updated security key; after transferring the updated security key to the endpoint, creating a key switchover timer; before the key switchover timer expires, verify that upstream traffic transferred from the endpoint on a logical link uses the updated security key; and begin, in response to upstream traffic being encrypted using the updated security key, using the updated security key to encrypt downstream traffic and clear the key switchover timer. 5. The method of claim 4 , wherein the original security key and the updated security keys each comprise a 128-bit random key string associated with the logical link.

Assignees

Inventors

Classifications

  • applying encryption of the keys · CPC title

  • Revocation or update of secret information, e.g. encryption key update or rekeying · CPC title

  • Star-type networks {or tree-type networks} · CPC title

  • using time-dependent keys, e.g. periodically changing keys (cryptographic mechanisms or cryptographic arrangements for controlling usage of secret information H04L9/088) · CPC title

  • Details about key distillation or coding, e.g. reconciliation, error correction, privacy amplification, polarisation coding or phase coding · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9270651B2 cover?
A method comprising generating an updated security key upon expiration of a key exchange timer, transferring the updated security key to a Coaxial Network Unit (CNU), retaining an original key, wherein the updated security key comprises a different key identification number than the original key, accepting and decrypting upstream traffic that employs either the original key or the updated key, …
Who is the assignee on this patent?
Futurewei Technologies Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/0471. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Feb 23 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).