This section explains the key features of OTNSec encryption on the NCS 1014 platform.
The OTNSec encryption feature in the NCS 1014 platform includes these key characteristics:
-
Layer 1 security: Encryption is applied at the OTN layer 1 level, specifically targeting the OPU client payload.
-
Encryption algorithm: The system uses the Galois-Counter-Mode (GCM) AES 256-bit cipher as the default method for encrypting and decrypting OPU payloads.
-
Independent encrypted channels: Each client operates with a separate encrypted channel for both transmission and reception.
-
Programmable key registers: Two banks of 256-bit programmable key registers are available:
-
Current key: Used for ongoing encryption.
-
Future key: Allows for seamless key updates via software without disrupting traffic.
Each key is associated with an Association Number (AN[1:0]), supporting up to four distinct numbers.
-
-
Interhost key exchange: Key exchange between hosts is supported through communication over the GCC .
-
Headless mode support: The encryption functionality remains operational even in headless mode.However, headless mode support is timebound and depends on the rekey interval.The maximum supported duration in headless mode is 14 days.