WaveLogic Encryption Solutions App Note
WaveLogic Encryption Solutions App Note
R U D
T
E
RE
L
R
IA U
BLE C
& SE
APPLICATION NOTE
1 Ponemon, Experian Data Breach Resolution research report: 2016 Is your company ready for a big data breach?; September 2016;
http://www.experian.com/data-breach/2016-ponemon-preparedness.html
2 Ponemon, IBM study: Cost of a Data Breach 2016; http://ibm.co/1MkF24s
Encryption technology
Encryption is defined as the process of transforming information
using an algorithm to make it unreadable to anyone except
those possessing special knowledge, referred to as the key in
Server & At-rest
cryptography. Essentially, this process locks down the network Database Encryption
Security
by encrypting this data, rendering it completely unusable to an
intruder that retrieves it, or to anyone not in possession of the
correct key to decipher the message. In-flight
Encryption
There are many ways to encrypt data, defined by various
standards that specify the encryption requirements of the
supporting products and keys, and set a certification process Figure 1. Encryption of in-flight data is part of
a holistic security strategy
for network equipment. Several standards-based encryption
algorithms exist, including Advanced Encryption Standard
a company’s reputation, criminal prosecution, expensive
(AES), which has various key sizes (56-, 128-, 256-bits) published
regulatory fines, and high customer churn.
by the National Institute of Standards and Technology (NIST).
These standards are published as U.S. Federal Information A range of commonly used techniques exists today to protect
Processing Standard (FIPS) publications. As an example, the at-rest data for secure servers, databases, routers, and
AES-256 encryption algorithm was published as FIPS 197. In switches by managing user access and credentialing. However,
addition to algorithm-specific publications such as FIPS 197, in today’s web-scale networks, large amounts of critical data
NIST also publishes standards coordinating the requirements are in-flight as high-bandwidth communications occur beyond
for cryptographic modules that include both hardware and the walls of the data center, traversing a larger, potentially
software components in FIPS 140-2.This provides service worldwide network. A comprehensive IT security approach
providers and end-users the assurance that the encryption must therefore encompass a robust in-flight encryption
solution has demonstrated compliance to the defined solution as part its holistic security strategy, as shown in
requirements by having successfully completed the rigorous Figure 1. By encrypting data as it leaves the security of the
laboratory testing and reviews mandated by the standards. private cloud, operators can ensure this data is protected from
unauthorized intercept as it traverses the network, crossing
Securing web-scale networks varying security levels as it reaches its destination.
Encryption is widely used today to secure both at-rest and
in-flight data. According to a Ponemon report on encryption While many organizations are adding in-flight data encryption
trends, only 15 percent of global respondents have no to their security strategy, the focus traditionally has been on
encryption strategy. Organizations of all sizes in every industry
3 encrypting in-flight data at Layer 2 or higher. Although this
must go to great lengths to protect information stored in may be a good option for some low-speed IT applications
their data centers from unauthorized access. The impact and that are not data-intensive or time-sensitive, it is often not
cost of a data breach cannot be ignored and has increasingly enterprise-wide and only encrypts IP application data. This
severe consequences to an organization, including degrading operational model for deploying an encryption solution is
SONET/SDH
Fibre
Channel
3 Ponemon, Thales e-Security research report: 2016 Global Encryption Trends Study; February 2016; http://bit.ly/1EonUfs
2
quite cumbersome and costly, as shown in
Figure 2, as it typically requires protocol-
specific standalone encryption devices
and can contribute significant amounts of
latency, impacting the application throughput managed managed
keys keys
and resulting in inefficient use of bandwidth.
Furthermore, encryption key management and
authentication across multiple independent Any
Protocol
devices is complex and labor-intensive, and 10G, 100G or 200G
Interconnect
end-to-end network troubleshooting is further
complicated across many independent devices.
Additionally, this approach leaves a gap in
Carrier or Enterprise Managed Encrypted Service
the organization’s in-flight data protection
strategy. While, traditionally, the risk of fiber-optic Figure 3. Ciena’s 6500 WaveLogic Encryption solution
WaveLogic Encryption The flexibility of the 6500 platform enables customers to select
the optimal shelf size to best meet their site-specific capacity,
As part of Ciena’s Assured Networking solution, which helps
space, and power requirements for cost-efficient transport
customers create trusted, reliable, and secure networks,
of encrypted services. An additional key benefit is that the
Ciena’s WaveLogic Encryption combines the proven
solution is fully protocol-agnostic, supporting a wide range of
encryption technology deployed on platforms that have a
flexible clients, including Ethernet, SONET/SDH, Fibre Channel,
large global installed base with the proven reliability of the
and OTN, to address multiple applications among security-
market-leading 6500 Packet-Optical Platform, deployed
conscious customers.
by more than 500 operators around the globe. Additionally,
Ciena’s WaveLogic Encryption capabilities extend to Ciena’s
Waveserver stackable interconnect system enabling 400G Differentiate with encryption 24/7
of wire-speed encryption capacity in 1RU for simple, rack- Encryption is always enabled in Ciena’s WaveLogic Encryption
and-stack DCI applications. solutions, ensuring the highest level of security, as all network
traffic is always encrypted. Although the ability to turn
encryption on or off may seem like added flexibility, simple
Data Security with Optical Encryption human error can result in sensitive traffic being sent over the
Download infographic now network unencrypted. Operators can leverage a differentiated
infrastructure that protects all in-flight data, all the time,
Simple to deploy as it spans the globe across metro, regional, long-haul, or
submarine distances. Additionally, operators can increase
With WaveLogic Encryption, operators can benefit from
revenues and customer retention by offering differentiated
a solution that simplifies the deployment of encryption by
high speed Service Level Agreements (SLAs) leveraging
integrating encryption functionality directly into the network
encrypted services with ultra-low-latency connectivity and
several path/equipment protection options.
3
Ironclad encryption 200G of encrypted traffic simply by adding an additional
Ciena’s WaveLogic Encryption is validated externally and client card. Additionally, operators can deploy high-capacity
independently certified by a third party to ensure it is encrypted services across the network, leveraging the 6500’s
implemented with industry-standard algorithms and advanced high-capacity hybrid packet/OTN fabric, maximizing the
security features. It provides a FIPS-certified AES-256 efficiency of network resources.
encryption engine with standards-based authentication
On the Waveserver, operators leverage up to 400 Gb/s of
mechanisms (such as X.509 certificates), enabling seamless
FIPS-certified, AES-256 wire-speed encryption line capacity in
integration into existing enterprise PKIs. Additionally, the
just 1RU and the flexibility to support a mix of 10GE, 40GE, and
6500 hardware and software components of the cryptographic
100GE clients on the same device. Programmable modulation
modules are compliant with FIPS 140-2, offering service
allows the Waveserver to optimize its wire-speed encryption
providers and end-users the assurance that the encryption
line capacity for each application/need, enabling two 100 Gb/s,
solution complies with all aspects covered by this
150 Gb/s or 200 Gb/s wavelengths for secure in-flight data
comprehensive evaluation, including encryption algorithms,
protection across metro, regional, or long-haul applications.
key exchange mechanisms, and user authentication.
For enhanced data protection, two distinct and independent High-capacity Wire-speed
sets of keys are used for authentication and data encryption Encryption Modules
functions, with a fast encryption key rotation interval of Download data sheet now
seconds instead of minutes. The AES-256 data encryption
session keys are autonomously negotiated and rotated every
second, independently on each line port, without impacting 6500 10G wire-speed encryption
traffic or throughput, and without user intervention. Operators Operators can cost-effectively provide 10G encrypted
can deploy the next generation of public key cryptography services by leveraging the 4x10G Optical Transponder with
algorithms with support for Elliptic Curve Cryptography (ECC), encryption module. This single-slot module provides 40G of
which provides a significantly more secure strategy than wire-speed encrypted service capacity via four distinct 10G
first-generation public key cryptography systems. protocol-independent encrypted line ports, so customers
can benefit from simpler network designs with integrated
Programmable 100G, 150G or 200G wire-speed encryption encryption capability in any 6500 chassis variant. The module
To meet the needs of today’s web-scale communications, offers enhanced security with its FIPS 140-2 Level 3-compliant
Ciena’s WaveLogic Encryption leverages industry-leading design, providing protection against physical tampering of the
WaveLogic 3 Extreme coherent technology to enable high- card, with support for zeroisation. This ensures that all critical
capacity, flexible, and customizable encryption solutions. security information is erased upon detection of any physical
WaveLogic 3 Extreme builds on the capabilities of WaveLogic 3 tampering of the cryptographic module by setting all data to
and provides extreme performance for all coherent networking zero, even when the card is not plugged into the shelf.
applications through the use of additional modulations and
enhanced mitigation of both linear and non-linear impairments. Encryption management made simple
This cutting-edge solution provides software-programmable A best-in-class transport layer security solution would not
modulation to enable 100G wire-speed encryption with be complete without a simplified, integrated encryption
QPSK modulation, 150G wire-speed encryption with 8QAM management approach. Partitioning encryption management
modulation, and 200G wire-speed encryption with 16QAM from transport management allows added flexibility in an
modulation—an industry first. operator- or enterprise-maintained infrastructure.
In either case, it is important that the ‘owner’ of the data—
On the 6500, operators can integrate a WaveLogic 3 Extreme the end-user—maintain full control of the encryption security
line module with encryption with any one of various client parameters associated with their critical data, issuing new
interfaces, to flexibly deploy a solution tailored to meet their keys or certificates as required by their security policies,
specific traffic needs, be it 10G, 40G or 100G service transport. while remaining aware of any security alarms and logs
As demands increase, with this pay-as-you-grow modular on an end-to-end basis.
offering, the same line module can be programmed to carry
4
Ciena’s 6500 WaveLogic Encryption solution includes
MyCryptoTool, a dedicated encryption management interface HEALTHCARE
HD VIDEO DCI
designed for distributed management of the network that
enables the end-user/security officer to independently manage
the security parameters and alarms of carrier-managed or FINANCIAL UTILITIES
GOVERNMENT
enterprise-managed networks. MyCryptoTool is a simple-to-
0.2 0 ASZCCC 0.1222 0.2 0 ASZCCC
0.1222 1 ASZCCC 1.1270 1.0 1 0.1222 0.2
ASZCCC 1.0 ASZCCC 1.1270 0
ASZCCC 1.1270 1 ASZCCC 1.1100 1.1 1 ASZCCC 1.0
1.1 1.1100 1
ASZCCC 1.1100 1 ASZCCC 1.1 1 ASZCCC 1.1 1
1.1
ASZCCC 1.1 1
0 ASZCCC 0.2 0.2 0
0.2 0.2 1 1 ASZCCC 0.2
ASZCCC ASZCCC 1.0 1.0 ASZCCC 0.2 0
1.0 1.0 1 1 1.0 1.0
ASZCCC 1.1 ASZCCC 1.1 1.1 ASZCCC 1
1.1 1 1.1 1.1 1 1.1 1.1
ASZCCC 1.1 1.1 1
Key applications
Ciena’s WaveLogic Encryption solutions are tailored to Figure 4. Examples of key WaveLogic Encryption applications
protect critical in-transit data in all of today’s high-capacity
applications. Key applications that would benefit from these
Summary
solutions include:
As increasingly more sensitive information gets
• Enterprise DCI for high-capacity storage and data encrypted distributed across fiber-optic networks, today’s web-scale
transport communications must deploy an IT security approach that
• Government and institutions that require certified, secure, encompasses not just server security and at-rest encryption,
high-speed communications between different locations but also a robust in-flight encryption solution. Ciena’s
WaveLogic Encryption combines a high degree of flexibility and
• Healthcare applications with high-quality, low-latency security, with ease of operation and administration, to enable
requirements for secure, efficient, and timely collaboration cost-effective, high-capacity, wire-speed encryption solutions
between healthcare stakeholders for securing virtually all in-flight data, all the time, whether it is
traveling across the street, across the city, across borders, or
• Managed service applications
across the ocean.
Ciena may make changes at any time to the products or specifications contained herein without notice. Ciena and the Ciena Logo are trademarks or registered trademarks of
Ciena Corporation in the U.S. and other countries. A complete list of Ciena’s trademarks is available at www.ciena.com. Third-party trademarks are the property of their respective
owners and do not imply a partnership between Ciena and any other company. Copyright © 2017 Ciena® Corporation. All rights reserved. AN107 5.2017