Physical Layer Encryption for Industrial Ethernet in Gigabit Optical Links

Adrián Pérez-Resa,Miguel García-Bosque,Carlos Sánchez-Azqueta,Santiago Celma
DOI: https://doi.org/10.1109/TIE.2018.2847670
2024-01-27
Abstract:Industrial Ethernet is a technology widely spread in factory floors and critical infrastructures where a high amount of data need to be collected and transported. Fiber optic networks at gigabit rates fit well with that type of environments where speed, system performance and reliability are critical. In this work a new encryption method for high speed optical communications suitable for such kind of networks is proposed. This new encryption method consists of a symmetric streaming encryption of the 8b/10b data flow at PCS (Physical Coding Sublayer) level. It is carried out thanks to an FPE (Format Preserving Encryption) blockcipher working in CTR (Counter) mode. The overall system has been simulated and implemented in an FPGA (Field Programmable Gate Array). Thanks to experimental results it can be concluded that it is possible to cipher traffic at this physical level in a secure way. In addition, no overhead is introduced during encryption, getting minimum latency and maximum throughput.
Cryptography and Security,Signal Processing,Systems and Control
What problem does this paper attempt to address?
This paper proposes a new encryption method for Industrial Ethernet in high-speed optical communication, which is particularly suitable for environments requiring a large amount of data collection and transmission. Currently, although fiber optic networks are widely used in industrial environments, their security needs improvement as optical signals can be intercepted even without introducing electromagnetic interference. The paper proposes using symmetric stream encryption at the Physical Coding Sublayer (PCS) level, working in Counter (CTR) mode based on Format Preserving Encryption (FPE) block cipher, to achieve secure encryption of data streams without introducing additional overhead, thus achieving minimum latency and maximum throughput. The main innovation of this method is that it uses FPE for stream encryption on 8b/10b data streams, ensuring the preservation of encoding format. Because the encryption is done at the physical layer, unlike encryption protocols at other layers, it does not introduce additional data fields, reducing encryption latency and improving efficiency. The paper also discusses the FPE operation modes recommended by NIST, such as FF1 and FF3, and chooses CTR mode as it is more suitable for high throughput applications. Experimental results show that this method can securely encrypt Ethernet traffic based on the 1000Base-X standard at the physical layer without introducing additional overhead. Furthermore, through analysis of the key stream, it is demonstrated that the generated key stream has good randomness, meeting the security requirements of encryption. Finally, the paper describes the application of this encryption system in Gigabit optical Ethernet links and provides detailed information on hardware implementation.