Chaotic Encryption for 10-Gb Ethernet Optical Links

Adrián Pérez-Resa,Miguel Garcia-Bosque,Carlos Sánchez-Azqueta,Santiago Celma
DOI: https://doi.org/10.1109/TCSI.2018.2867918
2024-01-27
Abstract:In this paper, a new physical layer encryption method for optical 10-Gb Ethernet links is proposed. Necessary modifications to introduce encryption in Ethernet 10GBase-R standard have been considered. This security enhancement has consisted of a symmetric streaming encryption of the 64b/66b data flow at physical coding sublayer level thanks to two keystream generators based on a chaotic algorithm. The overall system has been implemented and tested in a field programmable gate array. Ethernet traffic has been encrypted, transmitted, and decrypted over a multimode optical link. Experimental results are analyzed concluding that it is possible to cipher traffic at this level and hide the complete Ethernet traffic pattern from any passive eavesdropper. In addition, no overhead is introduced during encryption, getting no losses in the total throughput.
Cryptography and Security,Signal Processing
What problem does this paper attempt to address?
The paper primarily aims to address the lack of encryption mechanisms at the physical layer for 10Gb Ethernet optical links. Specifically, the research team proposes a new physical layer encryption method designed to provide security enhancements for 10Gb Ethernet optical links. The key contributions of the paper can be summarized as follows: 1. **Encryption Method**: A symmetric stream encryption method based on a chaotic algorithm is proposed. This method is applied to the 64b/66b data stream in the 10GBase-R standard, achieving encryption at the physical coding sublayer level. 2. **Necessary Modifications**: The necessary modifications to introduce encryption into the 10GBase-R standard are considered to ensure that the encryption functionality is compatible with the existing standard. 3. **System Implementation**: The overall system has been implemented and tested on a Field Programmable Gate Array (FPGA), demonstrating that Ethernet traffic can be encrypted, transmitted, and decrypted over multimode fiber. 4. **Security Enhancement**: By encrypting at the physical layer, not only can the content of data packets be encrypted, but the entire Ethernet traffic pattern can also be hidden. This makes it impossible for any passive eavesdropper to recognize traffic patterns, thereby enhancing security. 5. **No Overhead**: No additional overhead is introduced during the encryption process, so there is no loss of total throughput, maintaining maximum efficiency. 6. **Synchronization Mechanism**: The paper also details the infrastructure used for synchronizing encryption operations, including encryption and decryption modules as well as management modules, ensuring synchronization between the sender and receiver. In summary, this paper proposes an effective physical layer encryption scheme that addresses the security issues present in current 10Gb Ethernet optical links and validates its feasibility and effectiveness in practical applications.