<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom"><title>Quarkslab's blog - XGS-PON</title><link href="http://blog.quarkslab.com/" rel="alternate"></link><link href="http://blog.quarkslab.com/feeds/xgs-pon.rss.xml" rel="self"></link><id>http://blog.quarkslab.com/</id><updated>2026-09-16T00:00:00+02:00</updated><entry><title>Overview of Passive Optical Networks (PONs) Security</title><link href="http://blog.quarkslab.com/overview-of-passive-optical-networks-pons-security.html" rel="alternate"></link><published>2026-09-16T00:00:00+02:00</published><updated>2026-09-16T00:00:00+02:00</updated><author><name>Thiébaud Fuchs</name></author><id>tag:blog.quarkslab.com,2026-09-16:/overview-of-passive-optical-networks-pons-security.html</id><summary type="html">&lt;p&gt;&lt;strong&gt;Passive Optical Networks (PONs)&lt;/strong&gt; connect end-users to infrastructure using optical fibre in the last kilometre (Fibre-to-the-x). This article provides a technical overview of the security features in ITU-T specifications: &lt;strong&gt;Gigabit-capable PON (GPON)&lt;/strong&gt;, &lt;strong&gt;10-Gigabit-capable PON (XG-PON)&lt;/strong&gt;, &lt;strong&gt;10-Gigabit-capable Symmetric PON (XGS-PON)&lt;/strong&gt;, &lt;strong&gt;Next-generation PON 2 (NG-PON2)&lt;/strong&gt;, and &lt;strong&gt;50-Gigabit-capable PON (50G-PON)&lt;/strong&gt;. The analysis covers authentication schemes, key derivation, encryption methods, and associated security implications.&lt;/p&gt;</summary><content type="html">&lt;p&gt;You're watching a video on your favourite streaming platform. The platform sends video frames over HTTPS (encrypted), encapsulated in an IP packet with your IP address, ultimately forwarded to your fibre router inside an Ethernet frame. What you might not expect is that this Ethernet frame, containing your encrypted video, is actually received by all your neighbours' routers as well.&lt;/p&gt;
&lt;p&gt;The technology behind this behaviour is &lt;strong&gt;Passive Optical Networks (PON)&lt;/strong&gt;: the optical signal received by your router is the same signal received by your neighbours, containing data for several nearby subscribers. It is effectively like having access to your neighbours' Ethernet cables from inside your home, but in one direction only.&lt;/p&gt;
&lt;p&gt;What can be extracted then depends entirely on what the subscriber is doing. If protocols are encrypted, the ONU only receives unencrypted metadata (source/destination addresses, ports, etc.), which can still reveal internet habits. If protocols are unencrypted, such as unencrypted DNS, unencrypted VoIP traffic, or legacy protocols, the entire payload is exposed.&lt;/p&gt;
&lt;p&gt;Several mechanisms can be activated to encrypt and authenticate each part of the signal so that only the intended recipient can decrypt and process it.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;ℹ️ &lt;strong&gt;Glossary&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;There are many acronyms and definitions used in this article. The glossary is available at &lt;a href="resources/2026-09-16_overview-of-passive-optical-network-security/annex-a-glossary.pdf" target="_blank"&gt;Annex A: Glossary&lt;/a&gt;.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h1 id="fibre-networks"&gt;Fibre networks&lt;/h1&gt;
&lt;p&gt;Internet Service Providers (ISPs) and companies often use Passive Optical Networks (PONs) to connect end-user devices to their infrastructure using optical fibre in the last kilometre (Fibre-to-the-x (FTTx)). If you have fibre internet in France or Europe, your router is probably using this technology, Gigabit-capable PON (GPON) or 10-Gigabit-capable (Symmetric) PON (XG(S)-PON) in particular.&lt;/p&gt;
&lt;p&gt;Before examining the security aspects of PONs, we will first review the evolution of the specifications, how PONs work, and how data is structured on the link. &lt;/p&gt;
&lt;h2 id="pon-specifications"&gt;PON specifications&lt;/h2&gt;
&lt;p&gt;Over the years, several iterations of PON specifications have been published by the &lt;strong&gt;ITU-T&lt;/strong&gt; (International Telecommunication Union Telecommunication Standardization Sector):&lt;/p&gt;
&lt;p class="center-text"&gt;
&lt;img src="resources/2026-09-16_overview-of-passive-optical-network-security/pon_spec_timeline.svg"/&gt;&lt;br/&gt;
&lt;i&gt;PON specifications timeline based on first specification publication date&lt;/i&gt;
&lt;/p&gt;
&lt;p&gt;All the iterations in the timeline above are currently in use (although XGS-PON might be preferred to XG-PON) and can often coexist. While GPON has been around for more than 20 years, it is still standard for basic internet plans in France.&lt;/p&gt;
&lt;p&gt;As for the latest specification, 50-Gigabit-capable PON (50G-PON), released 5 years ago, some ISPs are only now starting to make real-world deployments. Orange, a French multinational ISP, made a small-scale demonstration of 50G-PON in October 2025 which it calls &amp;ldquo;the future standard for transmission systems in fibre access networks (FTTH)&amp;rdquo;&lt;sup id="fnref:orange50G"&gt;&lt;a class="footnote-ref" href="#fn:orange50G"&gt;1&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;
&lt;p&gt;Newer PON specifications can be grouped by the PON development phase they belong to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Next-generation PON 1 (NG-PON1): XG-PON, XGS-PON.&lt;/li&gt;
&lt;li&gt;Next-generation PON 2 (NG-PON2): NG-PON2.&lt;/li&gt;
&lt;li&gt;Higher Speed PON (HSP): 50G-PON.&lt;/li&gt;
&lt;li&gt;Very High Speed PON (VHSP): in development.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We will stop at HSP/50G-PON, as it is the latest PON specification that has been released.&lt;/p&gt;
&lt;p&gt;Competing standards from the IEEE exist as well, to cite a few:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Ethernet PON (EPON): 1 Gbps symmetric.&lt;/li&gt;
&lt;li&gt;Asymmetric 10G-EPON: 10 Gbps downstream, 1 Gbps upstream.&lt;/li&gt;
&lt;li&gt;Symmetric 10G-EPON: 10 Gbps symmetric.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We will focus on the ITU-T standards as they seem to be prevalent in France and Europe.&lt;/p&gt;
&lt;h2 id="passive-optical-network-pon"&gt;Passive Optical Network (PON)&lt;/h2&gt;
&lt;h3 id="onus-olts-and-the-odn"&gt;ONUs, OLTs and the ODN&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;PONs&lt;/strong&gt;  are optical fibre networks connecting &lt;strong&gt;Optical Line Terminations (OLTs)&lt;/strong&gt; to &lt;strong&gt;Optical Network Units (ONUs)&lt;/strong&gt; through &lt;strong&gt;Optical Distribution Networks (ODNs)&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;ODNs used to be built around passive optical filters, splitters and combiners; hence the "Passive" Optical Network designation. However, newer specifications have introduced active elements such as Range Extenders, so the passive part depends on how the ODN is deployed.&lt;/p&gt;
&lt;p&gt;The ONU is the component of the router interfacing with the PON and it is sometimes a separate device connected to the router. When a single subscriber uses an ONU, it may also be called an Optical Network Termination (ONT). &lt;/p&gt;
&lt;p&gt;A simple description of an ONU would be that it is a device extracting Ethernet frames from the optical signal and forwarding them to the router. However, ONUs support other protocols as well (such as VoIP), have Quality-of-Service features (for time-sensitive signals), Layer-2/Layer-3 features (VLANs, IP configuration, TCP/UDP services, etc), configuration of xDSL if the ONU has xDSL ports, configuration of the security features, etc. The ONU Management and Control Interface (OMCI) specification, which defines the protocol used to configure the ONU, is 700 pages long. ONUs are more complex than they seem.&lt;/p&gt;
&lt;p&gt;ONUs are connected to an OLT which can be described as a fibre switch/router, through the ODN. The OLT is located on the service provider's side (ISP for instance).&lt;/p&gt;
&lt;p class="center-text"&gt;
&lt;img src="resources/2026-09-16_overview-of-passive-optical-network-security/onu_olt.jpg" width="600px"/&gt;&lt;br/&gt;
&lt;i&gt;ONU (top) connected to the OLT (bottom) through an optical fibre. The ONU is plugged on one of the passive optical splitter ports, the splitter is integrated with the OLT here.&lt;/i&gt;
&lt;/p&gt;
&lt;h3 id="the-optical-distribution-network-multiplexing-optical-signals"&gt;The Optical Distribution Network: multiplexing optical signals&lt;/h3&gt;
&lt;p&gt;One key aspect of an Optical Distribution Network (ODN) is that the signal is carried over a reduced number of optical fibres up to a splitter where individual fibres will carry the signal to the end user.&lt;/p&gt;
&lt;p&gt;To multiplex signals over a single fibre, several techniques are used depending on the specification or implementer's choice: &lt;strong&gt;Wavelength Division Multiplexing (WDM)&lt;/strong&gt;, &lt;strong&gt;Time Division Multiplexing (TDM)&lt;/strong&gt; or combining both using &lt;strong&gt;Time and Wavelength Division Multiplexing (TWDM)&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;WDM&lt;/strong&gt; uses different light frequencies to carry multiple signals. Due to carefully chosen frequencies, GPON, XG(S)-PON, NG-PON2 and 50G-PON can coexist on the ODN using a coexistence element (see ITU-T G.9805&lt;sup id="fnref:itutG9805"&gt;&lt;a class="footnote-ref" href="#fn:itutG9805"&gt;19&lt;/a&gt;&lt;/sup&gt;). For NG-PON2 and HSP, WDM is also used to increase the overall bandwidth by creating several channels that each use a different frequency pair. WDM can also designate the separation of transmit/receive frequencies to use on a single fibre, as opposed to using an individual fibre for each direction.&lt;/p&gt;
&lt;p&gt;Taking GPON as an example, the downstream signal is carried on a single fibre from the OLT up to a passive splitter. WDM is used: the upstream and downstream signals use separate wavelengths. The signal is then split (copied) between up to 128 users in the last kilometre and carried using individual fibres. Instead of running 128 individual fibres over up to 60km, only the last few metres will require individual fibres, which reduces the cost and complexity. However, this also means that all 128 users on the same ODN will receive the same downstream signal containing all users' data.&lt;/p&gt;
&lt;p class="center-text"&gt;
&lt;img src="resources/2026-09-16_overview-of-passive-optical-network-security/fiber_network_architecture.svg"/&gt;&lt;br/&gt;
&lt;i&gt;Downstream PON&lt;/i&gt;
&lt;/p&gt;
&lt;p&gt;As for the upstream signal, it uses &lt;strong&gt;Time Division Multiple Access (TDMA)&lt;/strong&gt;, a specific type of &lt;strong&gt;TDM&lt;/strong&gt;: each ONU sends bursts on a timing provided by the OLT, which enables all the individual optical signals from the ONUs to be passively aggregated again before reaching the OLT. &lt;/p&gt;
&lt;p class="center-text"&gt;
&lt;img src="resources/2026-09-16_overview-of-passive-optical-network-security/fiber_network_architecture_upstream.svg"/&gt;&lt;br/&gt;
&lt;i&gt;Upstream PON&lt;/i&gt;
&lt;/p&gt;
&lt;p&gt;For HSP and NG-PON2, the combination of WDM and TDM to create channels is designated as &lt;strong&gt;TWDM&lt;/strong&gt;.&lt;/p&gt;
&lt;h3 id="the-impact-of-pon-architecture-on-security"&gt;The impact of PON architecture on security&lt;/h3&gt;
&lt;p&gt;As the downstream signal is passively split between all the ONUs, they all receive the same downstream signal which contains their data but also their neighbours'. Basically, all downstream communications are broadcast at the link level, which mandates specific security measures.&lt;/p&gt;
&lt;p&gt;As for the upstream signal, it is not carried to other users. However, it can still be intercepted on each individual fibre or when aggregated by the combiner en route to the OLT.&lt;/p&gt;
&lt;p&gt;In both cases, authentication and encryption are desirable to avoid eavesdropping, tampering, or man-in-the-middle attacks, which brings us to the threat model of PON specifications.&lt;/p&gt;
&lt;h1 id="the-pons-protocol-stack_2"&gt;The PON's protocol stack&lt;/h1&gt;
&lt;p&gt;In the previous sections, we learned how PONs are structured. This section presents the protocols used to configure the PON link and how data is framed. The objective is to present a condensed view of the frame structure; it can be glossed over and used as a reference for the next security-focused part.&lt;/p&gt;
&lt;h2 id="three-main-configuration-channels-embedded-oam-ploam-and-omci"&gt;Three main configuration channels: &lt;em&gt;Embedded OAM&lt;/em&gt;, &lt;em&gt;PLOAM&lt;/em&gt; and &lt;em&gt;OMCI&lt;/em&gt;&lt;/h2&gt;
&lt;p&gt;Before going into the frame structures, let us mention three protocols used by GPON, XG(S)-PON, NG-PON2 and 50G-PON:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;em&gt;Embedded layer Operation, Administration and Maintenance&lt;/em&gt; (Embedded OAM): fields embedded in the frame headers for low latency access, for instance, the frame identifier or the upstream bandwidth allocation.&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Physical layer Operation, Administration and Maintenance&lt;/em&gt; (PLOAM): used for other information not sent by the above that relates to the link layer, information that is less time-sensitive but used to configure the connection. For instance, sending the serial number to the OLT, the ONU ID, sending the data encryption key, etc.&lt;/li&gt;
&lt;li&gt;&lt;em&gt;ONU Management and Control Interface&lt;/em&gt; (OMCI): the protocol used for high-level configuration of the ONU (the channel is actually called &lt;em&gt;ONU Management and Control Channel&lt;/em&gt; (OMCC)). The protocol is defined in the &lt;em&gt;ITU-T G.988 ONU management and control interface (OMCI)&lt;/em&gt; specification &lt;sup id="fnref4:itutG988"&gt;&lt;a class="footnote-ref" href="#fn:itutG988"&gt;15&lt;/a&gt;&lt;/sup&gt;. It uses a &lt;em&gt;Management Information Base&lt;/em&gt; (MIB) synchronised between the ONU and the OLT, and allows complex mutual authentication, Layer 2 and Layer 3 configuration, ONU debug, etc.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="four-layers"&gt;Four layers&lt;/h2&gt;
&lt;p&gt;GPON, XG(S)-PON, NG-PON2 and 50G-PON all have similar frame structures, sharing a few similar characteristics:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;When TDM is used (which is most of the time), the upstream frame structure is slightly different from the downstream frame structure.&lt;/li&gt;
&lt;li&gt;The frames have four layers: Physical Medium Dependent (PMD) layer, Transmission Convergence (TC) PHY Adaptation Sublayer, TC Framing Sublayer (FS) and TC Service Adaptation Sublayer.&lt;/li&gt;
&lt;li&gt;The lower layer is the PMD layer, which defines how data is encoded on the optical line.&lt;/li&gt;
&lt;li&gt;The layer between the PMD and user functionalities (Service Data Units, SDUs) is the TC layer. It's called GTC for GPON&lt;sup id="fnref3:itutG9843"&gt;&lt;a class="footnote-ref" href="#fn:itutG9843"&gt;4&lt;/a&gt;&lt;/sup&gt;, XGTC for XG-PON&lt;sup id="fnref7:itutG987.3"&gt;&lt;a class="footnote-ref" href="#fn:itutG987.3"&gt;9&lt;/a&gt;&lt;/sup&gt;, XGS-PON TC&lt;sup id="fnref2:itutG9807.1"&gt;&lt;a class="footnote-ref" href="#fn:itutG9807.1"&gt;10&lt;/a&gt;&lt;/sup&gt; for XGS-PON, TWDM TC for NG-PON2&lt;sup id="fnref4:itutG989.3"&gt;&lt;a class="footnote-ref" href="#fn:itutG989.3"&gt;14&lt;/a&gt;&lt;/sup&gt; and ComTC (for Common TC) for 50G-PON (HSP)&lt;sup id="fnref5:itutG9804.2"&gt;&lt;a class="footnote-ref" href="#fn:itutG9804.2"&gt;17&lt;/a&gt;&lt;/sup&gt;. 50G-PON/Higher Speed PON generalises the TC layer from XG-PON onwards.&lt;/li&gt;
&lt;li&gt;The TC service adaptation sublayer contains (X)GEM frames ((10) Gigabit PON Encapsulation Method) which encapsulate the actual data payload (Ethernet frames for instance).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The diagram below represents a downstream frame and its separation into different layers. This representation deliberately shows only a few fields which are relevant to explain how PON works or are security-related. Technically, it only applies to XG(S)-PON, NG-PON2 and 50G-PON, but GPON is similar. Moreover, while the name and overall purpose of a field might be the same between PON versions, the structure can differ.&lt;/p&gt;
&lt;p class="center-text"&gt;
&lt;img src="resources/2026-09-16_overview-of-passive-optical-network-security/ngpon_framing_downstream.svg"/&gt;&lt;br/&gt;
&lt;i&gt;XG(S)-PON, NG-PON2 and 50G-PON downstream frame structure&lt;/i&gt;
&lt;/p&gt;
&lt;p&gt;The fields shown on the diagram have the following use:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;em&gt;Superframe counter (SFC)&lt;/em&gt;: 51-bit (XG(S)-PON, NG-PON2 and 50G-PON), 30-bit (GPON), wraps around to 0. It is used in the data encryption process for the counter mode of operation.&lt;/li&gt;
&lt;li&gt;&lt;em&gt;PLOAMd&lt;/em&gt;: used by the OLT in the PLOAM configuration protocol, for instance to request a new data encryption key.&lt;/li&gt;
&lt;li&gt;&lt;em&gt;BWmap&lt;/em&gt;: not directly security-related, but contains the timings on which upstream frames can be sent for each ONU (for TDMA). More precisely, the OLT assigns Allocation IDs (Alloc-IDs) to the ONUs (a default one is always assigned for OMCI). These Alloc-IDs are then associated with Transmission Containers (T-CONs) which represent a group of logical connections which can be assigned a bandwidth. Finally, each downstream frame contains the bandwidth assignment for the Alloc-IDs, which means each Alloc-ID/T-CON will have a dedicated time to send an upstream burst. Note that the TC layer is only concerned with Alloc-IDs, T-CONs are managed through OMCI and another structure could map to Alloc-IDs. T-CONs are then mapped to (X)GEM ports, the smallest connection entity. Grouping (X)GEM ports into T-CON enables managing bandwidth for QoS (Quality-of-Service) purposes, to prioritise real-time signals such as voice audio.&lt;/li&gt;
&lt;li&gt;&lt;em&gt;Encryption key index&lt;/em&gt;: only for XG(S)-PON, NG-PON2 and 50G-PON. Indicates if the downstream payload is: unencrypted, encrypted using key 1, encrypted using key 2 (key index relative to the key slot). GPON does not have such a field: the OLT does not select a key slot but sends a &lt;em&gt;Superframe counter&lt;/em&gt; value to the ONU through PLOAMd at which the new key (to be sent) will be used.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;In GPON, the &lt;em&gt;FS Header&lt;/em&gt; and &lt;em&gt;PSBd&lt;/em&gt; are actually merged as a single header (named &lt;em&gt;GTC Header&lt;/em&gt; or &lt;em&gt;PCBd&lt;/em&gt;) with a similar purpose. Another difference is that while the &lt;em&gt;PLOAMd&lt;/em&gt;, &lt;em&gt;BWmap&lt;/em&gt; and &lt;em&gt;SFC&lt;/em&gt; fields are present in all PON versions, the &lt;em&gt;Encryption key index&lt;/em&gt; is only present in XG(S)-PON, NG-PON2 and 50G-PON.&lt;/p&gt;
&lt;p&gt;The diagram below represents an upstream frame for XG(S)-PON, NG-PON2 and 50G-PON; it differs slightly for GPON, but it is overall very similar:&lt;/p&gt;
&lt;p class="center-text"&gt;
&lt;img src="resources/2026-09-16_overview-of-passive-optical-network-security/ngpon_framing_upstream.svg"/&gt;&lt;br/&gt;
&lt;i&gt;XG(S)-PON, NG-PON2 and 50G-PON upstream frame structure&lt;/i&gt;
&lt;/p&gt;
&lt;p&gt;The upstream frames are sent in bursts. Each Alloc-ID is given an opportunity to send data according to the &lt;em&gt;BWMap&lt;/em&gt; field sent in the downstream frame. Alloc-ID bandwidth allocations that belong to the same ONU and are consecutive (in time and thus in the BWMap) are called an allocation series. They start with an &lt;em&gt;FS Header&lt;/em&gt; and end with an &lt;em&gt;FS Trailer&lt;/em&gt;. &lt;/p&gt;
&lt;h1 id="threat-models-of-gpon-xgs-pon-ng-pon2-and-50g-pon_1"&gt;Threat models of GPON, XG(S)-PON, NG-PON2 and 50G-PON&lt;/h1&gt;
&lt;p&gt;All the ITU-T PON specifications referenced have a threat model, which has greatly improved from GPON to XG-PON. XGS-PON/NG-PON2/50G-PON share the XG-PON threat model for the most part.&lt;/p&gt;
&lt;p&gt;The GPON&lt;sup id="fnref:itutG9843"&gt;&lt;a class="footnote-ref" href="#fn:itutG9843"&gt;4&lt;/a&gt;&lt;/sup&gt; threat model can be summarised as such:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;An attacker or user having reprogrammed an ONU, or having otherwise access to the incoming optical signal, can access all downstream communications including data from all the other OLT users.&lt;/li&gt;
&lt;li&gt;Other threats such as eavesdropping on the upstream link are considered impractical because the attacker would have to tap into the fibre, sometimes in public places and in a noticeable way for the PON.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The XG-PON specification&lt;sup id="fnref:itutG987.3"&gt;&lt;a class="footnote-ref" href="#fn:itutG987.3"&gt;9&lt;/a&gt;&lt;/sup&gt; as well as XGS-PON&lt;sup id="fnref2:itutG987.3"&gt;&lt;a class="footnote-ref" href="#fn:itutG987.3"&gt;9&lt;/a&gt;&lt;/sup&gt; &lt;sup id="fnref:itutG9807.1"&gt;&lt;a class="footnote-ref" href="#fn:itutG9807.1"&gt;10&lt;/a&gt;&lt;/sup&gt;, NG-PON2&lt;sup id="fnref:itutG989.3"&gt;&lt;a class="footnote-ref" href="#fn:itutG989.3"&gt;14&lt;/a&gt;&lt;/sup&gt; and 50G-PON&lt;sup id="fnref:itutG9804.2"&gt;&lt;a class="footnote-ref" href="#fn:itutG9804.2"&gt;17&lt;/a&gt;&lt;/sup&gt; have gone back on this model, taking upstream threats into account as well:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;An attacker or user having reprogrammed an ONU, or having otherwise access to the incoming optical signal, can access all downstream communications including data from all the other OLT users.&lt;/li&gt;
&lt;li&gt;An attacker or user having reprogrammed an ONU can impersonate another ONU and forge packets.&lt;/li&gt;
&lt;li&gt;An attacker could intercept or generate traffic at any point on the ODN (which sometimes spans 60 km) between the OLT and the ONU, impersonating the OLT or an ONU.&lt;/li&gt;
&lt;li&gt;An attacker or user could use any of the scenarios above to record and replay packets transmitted on the PON, or modify the packets (bitflips for instance).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Overall, the threat model has improved significantly since GPON, considering security issues in both directions (OLT to ONU and ONU to OLT), as well as eavesdropping anywhere between the OLT and ONUs. This translates into improved security features as well.&lt;/p&gt;
&lt;p&gt;Additionally, a study group with members from China Telecommunications Corporation, Verizon, Huawei Technologies Co., Ltd. and ZTE Corporation has published recommendations named "Practical aspects of PON security" starting from 2022. A first supplement has been published&lt;sup id="fnref:itutsuppl81"&gt;&lt;a class="footnote-ref" href="#fn:itutsuppl81"&gt;20&lt;/a&gt;&lt;/sup&gt;, with the objective &amp;ldquo;to guide the security experts on operators&amp;rsquo; expectations about the security of their access networks and on the criteria of a valuable security proposal, as well as the reference to the operators on configuring their networks to achieve the best possible security performance.&amp;rdquo;.&lt;/p&gt;
&lt;p&gt;The improved threat model in the supplement separates the threats into several categories:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Eavesdropping: downstream and upstream.&lt;/li&gt;
&lt;li&gt;Theft of service: unauthorised access to the PON.&lt;/li&gt;
&lt;li&gt;Denial of service.&lt;/li&gt;
&lt;li&gt;Theft of data.&lt;/li&gt;
&lt;li&gt;Impersonation.&lt;/li&gt;
&lt;li&gt;Disruption of operations: disruption from a single ODN to a larger scale (entire ISP for instance).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The supplement insists that &amp;ldquo;regardless of how strong the link-level encryption strength is, no end-to-end data security property can be derived from it&amp;rdquo;. Indeed, PON specifications are only concerned with establishing a secure channel between an ONU and an OLT, at the link level. This channel is not established between an end user and a service provider directly.&lt;/p&gt;
&lt;p&gt;Overall, the supplement gives more context to the threat model and makes recommendations on key management and handling of ONU identifier duplication. The XG-PON ITU-T G.987.3&lt;sup id="fnref3:itutG987.3"&gt;&lt;a class="footnote-ref" href="#fn:itutG987.3"&gt;9&lt;/a&gt;&lt;/sup&gt;, NG-PON2 ITU-T G.989.3&lt;sup id="fnref2:itutG989.3"&gt;&lt;a class="footnote-ref" href="#fn:itutG989.3"&gt;14&lt;/a&gt;&lt;/sup&gt; and 50G-PON ITU-T G.9804.2&lt;sup id="fnref2:itutG9804.2"&gt;&lt;a class="footnote-ref" href="#fn:itutG9804.2"&gt;17&lt;/a&gt;&lt;/sup&gt; specifications' latest amendments actually recommend using this supplement for best practices related to key management. As it is recommended by the specifications, it probably must be implemented.&lt;/p&gt;
&lt;p&gt;One threat that does not seem to be mentioned in any of the threat models is the exploitation of vulnerabilities in the OMCI Management Entities, which have a large attack surface. The implementation of the OMCI Management Entities functionalities is down to the manufacturer so this might be outside the specification perimeter however.&lt;/p&gt;
&lt;h1 id="pon-security-measures"&gt;PON security measures&lt;/h1&gt;
&lt;h2 id="authentication-and-cryptographic-schemes"&gt;Authentication and cryptographic schemes&lt;/h2&gt;
&lt;p&gt;Authentication in ITU-T PONs can be surprisingly complex, as there are multiple identifiers and schemes available. They are sometimes combined, and the authentication methods do not all ensure the same level of security.&lt;/p&gt;
&lt;p&gt;We will separate the use of these identifiers into two categories:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Identification: the OLT requests an identifier, but there is no secure channel bound to this identifier. In GPON, the OLT can request an identifier and then request an encryption key, but the key is not bound to the identifier, which is why only one authentication scheme is considered for GPON (OMCI-based).&lt;/li&gt;
&lt;li&gt;Authentication: the OLT (and the ONU if the authentication is symmetric) uses a cryptographic scheme to authenticate its counterpart. The results of this authentication can be used to establish a secure channel between the two devices. Keep in mind that, as we'll see in the next sections, a successful authentication does not mean the secure channel is activated, only that it can be. &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;All PON versions start with an identification step: at the very start of its connection to the OLT, the ONU sends its serial number.&lt;/p&gt;
&lt;p&gt;Then, for GPON, cryptographic authentication is entirely optional. For XG-PON and later, a &lt;em&gt;Registration ID&lt;/em&gt;-based authentication will always be performed after ONU initialis  ation, whether &lt;em&gt;Registration_ID&lt;/em&gt; is the default null string or a provisioned one. If a &lt;em&gt;Registration_ID&lt;/em&gt; is not provisioned, it will not provide meaningful authentication.&lt;/p&gt;
&lt;p&gt;After the mandatory identification or authentication steps, the OLT can start a new authentication process at any point, or request other identifiers. For authentication, up to three cryptographic schemes are available depending on the PON version. Some of these schemes allow for mutual authentication (ONU to OLT, but also OLT to ONU), all of them lead to the creation of a &lt;em&gt;Master Session Key (MSK)&lt;/em&gt; which can then be used to establish a secure channel.&lt;/p&gt;
&lt;p class="center-text"&gt;
&lt;img src="resources/2026-09-16_overview-of-passive-optical-network-security/authentication_choices.svg"/&gt;&lt;br/&gt;
&lt;i&gt;Authentication decision diagram&lt;/i&gt;
&lt;/p&gt;
&lt;p&gt;The Logical ONU ID (LOID) / LOID password identifiers often present in ONU web interfaces can be a bit confusing. They seem to be both implemented in custom OMCI Management Entities (as is the case for the Management Entity 65530 used by Huawei ONUs) and in the standard "ONU-G" OMCI Management Entity. The &lt;em&gt;O3 Labs&lt;/em&gt; website&lt;sup id="fnref:tripleoxygen"&gt;&lt;a class="footnote-ref" href="#fn:tripleoxygen"&gt;21&lt;/a&gt;&lt;/sup&gt; lists several vendor-specific OMCI Management Entities.&lt;/p&gt;
&lt;p&gt;Note that a combination of these identifiers and schemes can be used at different steps during the configuration of the ONU. For an XGS-PON link the following sequence could be used:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Identify the ONU through the serial number sent at the start of the link initialisation.&lt;/li&gt;
&lt;li&gt;Request the &lt;em&gt;Registration ID&lt;/em&gt; from the ONU, derive an &lt;em&gt;MSK&lt;/em&gt; using the corresponding cryptographic scheme and enable encryption.&lt;/li&gt;
&lt;li&gt;Start the OMCI cryptographic scheme and transition to the new &lt;em&gt;MSK&lt;/em&gt;.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="the-mutual-secure-authentication-mechanisms"&gt;The (mutual) secure authentication mechanisms&lt;/h2&gt;
&lt;p&gt;In the previous section, we mentioned three authentication mechanisms based on cryptography: Registration ID-based, OMCI-based and IEEE 802.1X-based.&lt;/p&gt;
&lt;p&gt;Only the last two are mutual authentication schemes that authenticate both the ONU and the OLT.&lt;/p&gt;
&lt;h3 id="registration-id-based-authentication"&gt;Registration ID-based authentication&lt;/h3&gt;
&lt;p&gt;Only available in XG(S)-PON, NG-PON2 and 50G-PON. This is the default authentication mode based on a 36-byte value called &lt;em&gt;Registration_ID&lt;/em&gt; and it is not mutual. The &lt;em&gt;Registration_ID&lt;/em&gt; is requested by the OLT during the ONU activation process and can be queried at any time through a PLOAM message, which is unencrypted.&lt;/p&gt;
&lt;p&gt;This mechanism is thus vulnerable to several threats, for instance:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;An attacker can unplug the target optical fibre, plug it in their OLT, request the &lt;em&gt;Registration_ID&lt;/em&gt;, derive the keys and use them to decrypt the encrypted data encryption key transmitted through PLOAM after the device has been plugged back to the original OLT.&lt;/li&gt;
&lt;li&gt;An attacker could tap at any point between the targeted user and the OLT and see the &lt;em&gt;Registration_ID&lt;/em&gt; in clear form, derive the keys and use them to decrypt the encrypted data encryption key transmitted through PLOAM.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The &lt;em&gt;Registration_ID&lt;/em&gt; is not meant to be changed regularly, the attacker can query it once and reuse it at any time. Moreover, if it is unchanged, the default  is used.&lt;/p&gt;
&lt;p&gt;A key consideration is that &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;Registration_ID&lt;/mtext&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

\text{Registration\_ID}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; has a default value &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mn&gt;0&lt;/mn&gt;&lt;mi&gt;x&lt;/mi&gt;&lt;mn&gt;00&lt;/mn&gt;&lt;msub&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mn&gt;36&lt;/mn&gt;&lt;/msub&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

(0x00)_{36}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;, which will be used for the Registration ID-based authentication unless a &lt;em&gt;Registration_ID&lt;/em&gt; has been provisioned. Thus, the specifications effectively allow the use of one of the cryptographic authentication schemes with a known (weak) secret. Having the possibility to use an unauthenticated/unencrypted channel, which would not provide a false sense of security, would seem preferable.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;
&lt;strong&gt; Registration ID-based MSK derivation&lt;/strong&gt;
&lt;/p&gt;
&lt;p&gt;Let:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;Registration_ID&lt;/mtext&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

\text{Registration\_ID}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; be the 36-byte Registration ID.&lt;/li&gt;
&lt;li&gt;&lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;msub&gt;&lt;mi&gt;T&lt;/mi&gt;&lt;mrow&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;/mrow&gt;&lt;/msub&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

T_{MSK}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; be the required MSK length.&lt;/li&gt;
&lt;li&gt;&lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

K&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; be the 128-bit AES key used in the AES-ECMAC definition.&lt;/li&gt;
&lt;li&gt;&lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

M&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; be the input message used in the AES-ECMAC definition.&lt;/li&gt;
&lt;li&gt;&lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;T&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

Tlen&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; be the requested MAC output length in bits.&lt;/li&gt;
&lt;li&gt;&lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;msub&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mtext&gt;lessLastBlock&lt;/mtext&gt;&lt;/msub&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

M_{\text{lessLastBlock}}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; be the &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

M&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; with its final 16 octets removed.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

MSK&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; is derived the following way:&lt;/p&gt;
&lt;p&gt;&lt;span class="katex"&gt;&lt;math display="block" xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mrow&gt;&lt;mo fence="true"&gt;{&lt;/mo&gt;&lt;mtable columnalign="left left" columnspacing="1em" rowspacing="0.36em"&gt;&lt;mtr&gt;&lt;mtd&gt;&lt;mstyle displaystyle="false" scriptlevel="0"&gt;&lt;mrow&gt;&lt;mi mathvariant="normal"&gt;AES-128-CMAC&lt;/mi&gt;&lt;mo&gt;&amp;af;&lt;/mo&gt;&lt;mrow&gt;&lt;mo fence="true"&gt;(&lt;/mo&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mtext&gt;0x55&lt;/mtext&gt;&lt;msub&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mn&gt;16&lt;/mn&gt;&lt;/msub&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mtext&gt;Registration_ID&lt;/mtext&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mn&gt;128&lt;/mn&gt;&lt;mo fence="true"&gt;)&lt;/mo&gt;&lt;/mrow&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;/mrow&gt;&lt;/mstyle&gt;&lt;/mtd&gt;&lt;mtd&gt;&lt;mstyle displaystyle="false" scriptlevel="0"&gt;&lt;mrow&gt;&lt;msub&gt;&lt;mi&gt;T&lt;/mi&gt;&lt;mrow&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;/mrow&gt;&lt;/msub&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mn&gt;128&lt;/mn&gt;&lt;/mrow&gt;&lt;/mstyle&gt;&lt;/mtd&gt;&lt;/mtr&gt;&lt;mtr&gt;&lt;mtd&gt;&lt;mstyle displaystyle="false" scriptlevel="0"&gt;&lt;mrow&gt;&lt;mi mathvariant="normal"&gt;AES-128-ECMAC&lt;/mi&gt;&lt;mo&gt;&amp;af;&lt;/mo&gt;&lt;mrow&gt;&lt;mo fence="true"&gt;(&lt;/mo&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mtext&gt;0x55&lt;/mtext&gt;&lt;msub&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mn&gt;16&lt;/mn&gt;&lt;/msub&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mtext&gt;Registration_ID&lt;/mtext&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mn&gt;256&lt;/mn&gt;&lt;mo fence="true"&gt;)&lt;/mo&gt;&lt;/mrow&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;/mrow&gt;&lt;/mstyle&gt;&lt;/mtd&gt;&lt;mtd&gt;&lt;mstyle displaystyle="false" scriptlevel="0"&gt;&lt;mrow&gt;&lt;msub&gt;&lt;mi&gt;T&lt;/mi&gt;&lt;mrow&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;/mrow&gt;&lt;/msub&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mn&gt;256&lt;/mn&gt;&lt;mtext&gt;&amp;nbsp;(50G-PON/HSP)&lt;/mtext&gt;&lt;/mrow&gt;&lt;/mstyle&gt;&lt;/mtd&gt;&lt;/mtr&gt;&lt;/mtable&gt;&lt;/mrow&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}


MSK
=
\begin{cases}
\operatorname{AES-128-CMAC}\left((\text{0x55})_{16}, \text{Registration\_ID}, 128\right),
&amp;amp; T_{MSK}=128 \\[6pt]
\operatorname{AES-128\text{-}ECMAC}\left((\text{0x55})_{16}, \text{Registration\_ID}, 256\right),
&amp;amp; T_{MSK}=256 \text{ (50G-PON/HSP)}
\end{cases}
&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;where&lt;/p&gt;
&lt;p&gt;&lt;span class="katex"&gt;&lt;math display="block" xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi mathvariant="normal"&gt;AES-128-ECMAC&lt;/mi&gt;&lt;mo&gt;&amp;af;&lt;/mo&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mi&gt;T&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mrow&gt;&lt;mo fence="true"&gt;{&lt;/mo&gt;&lt;mtable columnalign="left left" columnspacing="1em" rowspacing="0.36em"&gt;&lt;mtr&gt;&lt;mtd&gt;&lt;mstyle displaystyle="false" scriptlevel="0"&gt;&lt;mrow&gt;&lt;mi mathvariant="normal"&gt;AES-128-CMAC&lt;/mi&gt;&lt;mo&gt;&amp;af;&lt;/mo&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mi&gt;T&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;/mrow&gt;&lt;/mstyle&gt;&lt;/mtd&gt;&lt;mtd&gt;&lt;mstyle displaystyle="false" scriptlevel="0"&gt;&lt;mrow&gt;&lt;mi&gt;T&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mo&gt;&amp;le;&lt;/mo&gt;&lt;mn&gt;128&lt;/mn&gt;&lt;/mrow&gt;&lt;/mstyle&gt;&lt;/mtd&gt;&lt;/mtr&gt;&lt;mtr&gt;&lt;mtd&gt;&lt;mstyle displaystyle="false" scriptlevel="0"&gt;&lt;mrow&gt;&lt;mi mathvariant="normal"&gt;AES-128-CMAC&lt;/mi&gt;&lt;mo&gt;&amp;af;&lt;/mo&gt;&lt;mrow&gt;&lt;mo fence="true"&gt;(&lt;/mo&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;msub&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mtext&gt;lessLastBlock&lt;/mtext&gt;&lt;/msub&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mn&gt;128&lt;/mn&gt;&lt;mo fence="true"&gt;)&lt;/mo&gt;&lt;/mrow&gt;&lt;mi mathvariant="normal"&gt;&amp;smid;&lt;/mi&gt;&lt;mi mathvariant="normal"&gt;AES-128-CMAC&lt;/mi&gt;&lt;mo&gt;&amp;af;&lt;/mo&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mn&gt;128&lt;/mn&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;/mrow&gt;&lt;/mstyle&gt;&lt;/mtd&gt;&lt;mtd&gt;&lt;mstyle displaystyle="false" scriptlevel="0"&gt;&lt;mrow&gt;&lt;mi&gt;T&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mn&gt;256&lt;/mn&gt;&lt;/mrow&gt;&lt;/mstyle&gt;&lt;/mtd&gt;&lt;/mtr&gt;&lt;/mtable&gt;&lt;/mrow&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}


\operatorname{AES-128\text{-}ECMAC}(K, M, Tlen)
=
\begin{cases}
\operatorname{AES-128-CMAC}(K, M, Tlen),
&amp;amp; Tlen \leq 128 \\[4pt]
\operatorname{AES-128-CMAC}\left(K, M_{\text{lessLastBlock}}, 128\right)
|
\operatorname{AES-128-CMAC}(K, M, 128),
&amp;amp; Tlen = 256
\end{cases}
&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3 id="omci-based-authentication"&gt;OMCI-based authentication&lt;/h3&gt;
&lt;p&gt;This is one of the two mutual secure authentication mechanisms, now defined in ITU-T G.988&lt;sup id="fnref:itutG988"&gt;&lt;a class="footnote-ref" href="#fn:itutG988"&gt;15&lt;/a&gt;&lt;/sup&gt; (originated in ITU-T G.984.4&lt;sup id="fnref:itutG9844"&gt;&lt;a class="footnote-ref" href="#fn:itutG9844"&gt;5&lt;/a&gt;&lt;/sup&gt; for GPON). The scheme assumes a Pre-Shared Key (&lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;P&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

PSK&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;) has been provisioned on both the ONU and OLT beforehand.&lt;/p&gt;
&lt;p&gt;A three-step challenge-based mutual authentication is used:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;
&lt;strong&gt; Three-step OMCI authentication&lt;/strong&gt;
&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;The OLT sends its list of supported MAC (Message Authentication Code) functions and &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;O&lt;/mi&gt;&lt;mi&gt;L&lt;/mi&gt;&lt;mi&gt;T&lt;/mi&gt;&lt;mtext&gt;&amp;nbsp;&lt;/mtext&gt;&lt;mi&gt;r&lt;/mi&gt;&lt;mi&gt;a&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mi&gt;d&lt;/mi&gt;&lt;mi&gt;o&lt;/mi&gt;&lt;mi&gt;m&lt;/mi&gt;&lt;mtext&gt;&amp;nbsp;&lt;/mtext&gt;&lt;mi&gt;c&lt;/mi&gt;&lt;mi&gt;h&lt;/mi&gt;&lt;mi&gt;a&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mi&gt;g&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

OLT\ random\ challenge&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; to the ONU.&lt;/li&gt;
&lt;li&gt;Then, the ONU selects one of the supported OLT MAC functions, then sends the &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;O&lt;/mi&gt;&lt;mi&gt;N&lt;/mi&gt;&lt;mi&gt;U&lt;/mi&gt;&lt;mtext&gt;&amp;nbsp;&lt;/mtext&gt;&lt;mi&gt;r&lt;/mi&gt;&lt;mi&gt;a&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mi&gt;d&lt;/mi&gt;&lt;mi&gt;o&lt;/mi&gt;&lt;mi&gt;m&lt;/mi&gt;&lt;mtext&gt;&amp;nbsp;&lt;/mtext&gt;&lt;mi&gt;c&lt;/mi&gt;&lt;mi&gt;h&lt;/mi&gt;&lt;mi&gt;a&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mi&gt;g&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

ONU\ random\ challenge&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; and the following MAC to the OLT:
&lt;span class="katex"&gt;&lt;math display="block" xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;MACFunction&lt;/mtext&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mtext&gt;PSK&lt;/mtext&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mi&gt;s&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;c&lt;/mi&gt;&lt;mi&gt;t&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;d&lt;/mi&gt;&lt;mi mathvariant="normal"&gt;_&lt;/mi&gt;&lt;mi&gt;c&lt;/mi&gt;&lt;mi&gt;r&lt;/mi&gt;&lt;mi&gt;y&lt;/mi&gt;&lt;mi&gt;p&lt;/mi&gt;&lt;mi&gt;t&lt;/mi&gt;&lt;mi&gt;o&lt;/mi&gt;&lt;mi&gt;g&lt;/mi&gt;&lt;mi&gt;r&lt;/mi&gt;&lt;mi&gt;a&lt;/mi&gt;&lt;mi&gt;p&lt;/mi&gt;&lt;mi&gt;h&lt;/mi&gt;&lt;mi&gt;i&lt;/mi&gt;&lt;mi&gt;c&lt;/mi&gt;&lt;mi mathvariant="normal"&gt;_&lt;/mi&gt;&lt;mi&gt;c&lt;/mi&gt;&lt;mi&gt;a&lt;/mi&gt;&lt;mi&gt;p&lt;/mi&gt;&lt;mi&gt;a&lt;/mi&gt;&lt;mi&gt;b&lt;/mi&gt;&lt;mi&gt;i&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;i&lt;/mi&gt;&lt;mi&gt;t&lt;/mi&gt;&lt;mi&gt;i&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;s&lt;/mi&gt;&lt;mi mathvariant="normal"&gt;&amp;smid;&lt;/mi&gt;&lt;mi&gt;O&lt;/mi&gt;&lt;mi&gt;L&lt;/mi&gt;&lt;mi&gt;T&lt;/mi&gt;&lt;mtext&gt;&amp;nbsp;&lt;/mtext&gt;&lt;mi&gt;r&lt;/mi&gt;&lt;mi&gt;a&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mi&gt;d&lt;/mi&gt;&lt;mi&gt;o&lt;/mi&gt;&lt;mi&gt;m&lt;/mi&gt;&lt;mtext&gt;&amp;nbsp;&lt;/mtext&gt;&lt;mi&gt;c&lt;/mi&gt;&lt;mi&gt;h&lt;/mi&gt;&lt;mi&gt;a&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mi&gt;g&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi mathvariant="normal"&gt;&amp;smid;&lt;/mi&gt;&lt;mi&gt;O&lt;/mi&gt;&lt;mi&gt;N&lt;/mi&gt;&lt;mi&gt;U&lt;/mi&gt;&lt;mtext&gt;&amp;nbsp;&lt;/mtext&gt;&lt;mi&gt;r&lt;/mi&gt;&lt;mi&gt;a&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mi&gt;d&lt;/mi&gt;&lt;mi&gt;o&lt;/mi&gt;&lt;mi&gt;m&lt;/mi&gt;&lt;mtext&gt;&amp;nbsp;&lt;/mtext&gt;&lt;mi&gt;c&lt;/mi&gt;&lt;mi&gt;h&lt;/mi&gt;&lt;mi&gt;a&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mi&gt;g&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi mathvariant="normal"&gt;&amp;smid;&lt;/mi&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mn&gt;0&lt;/mn&gt;&lt;mi&gt;x&lt;/mi&gt;&lt;mn&gt;00&lt;/mn&gt;&lt;msub&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mn&gt;16&lt;/mn&gt;&lt;/msub&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}


\text{MACFunction}(\text{PSK}, (selected\_cryptographic\_capabilities|OLT\ random\ challenge|ONU\ random\ challenge|(0x00)_{16}))
&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;Finally, OLT then sends a MAC to the ONU as well:
&lt;span class="katex"&gt;&lt;math display="block" xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;MACFunction&lt;/mtext&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mtext&gt;PSK&lt;/mtext&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mi&gt;s&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;c&lt;/mi&gt;&lt;mi&gt;t&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;d&lt;/mi&gt;&lt;mi mathvariant="normal"&gt;_&lt;/mi&gt;&lt;mi&gt;c&lt;/mi&gt;&lt;mi&gt;r&lt;/mi&gt;&lt;mi&gt;y&lt;/mi&gt;&lt;mi&gt;p&lt;/mi&gt;&lt;mi&gt;t&lt;/mi&gt;&lt;mi&gt;o&lt;/mi&gt;&lt;mi&gt;g&lt;/mi&gt;&lt;mi&gt;r&lt;/mi&gt;&lt;mi&gt;a&lt;/mi&gt;&lt;mi&gt;p&lt;/mi&gt;&lt;mi&gt;h&lt;/mi&gt;&lt;mi&gt;i&lt;/mi&gt;&lt;mi&gt;c&lt;/mi&gt;&lt;mi mathvariant="normal"&gt;_&lt;/mi&gt;&lt;mi&gt;c&lt;/mi&gt;&lt;mi&gt;a&lt;/mi&gt;&lt;mi&gt;p&lt;/mi&gt;&lt;mi&gt;a&lt;/mi&gt;&lt;mi&gt;b&lt;/mi&gt;&lt;mi&gt;i&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;i&lt;/mi&gt;&lt;mi&gt;t&lt;/mi&gt;&lt;mi&gt;i&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;s&lt;/mi&gt;&lt;mi mathvariant="normal"&gt;&amp;smid;&lt;/mi&gt;&lt;mi&gt;O&lt;/mi&gt;&lt;mi&gt;N&lt;/mi&gt;&lt;mi&gt;U&lt;/mi&gt;&lt;mtext&gt;&amp;nbsp;&lt;/mtext&gt;&lt;mi&gt;r&lt;/mi&gt;&lt;mi&gt;a&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mi&gt;d&lt;/mi&gt;&lt;mi&gt;o&lt;/mi&gt;&lt;mi&gt;m&lt;/mi&gt;&lt;mtext&gt;&amp;nbsp;&lt;/mtext&gt;&lt;mi&gt;c&lt;/mi&gt;&lt;mi&gt;h&lt;/mi&gt;&lt;mi&gt;a&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mi&gt;g&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi mathvariant="normal"&gt;&amp;smid;&lt;/mi&gt;&lt;mi&gt;O&lt;/mi&gt;&lt;mi&gt;L&lt;/mi&gt;&lt;mi&gt;T&lt;/mi&gt;&lt;mtext&gt;&amp;nbsp;&lt;/mtext&gt;&lt;mi&gt;r&lt;/mi&gt;&lt;mi&gt;a&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mi&gt;d&lt;/mi&gt;&lt;mi&gt;o&lt;/mi&gt;&lt;mi&gt;m&lt;/mi&gt;&lt;mtext&gt;&amp;nbsp;&lt;/mtext&gt;&lt;mi&gt;c&lt;/mi&gt;&lt;mi&gt;h&lt;/mi&gt;&lt;mi&gt;a&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mi&gt;g&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi mathvariant="normal"&gt;&amp;smid;&lt;/mi&gt;&lt;mi&gt;O&lt;/mi&gt;&lt;mi&gt;N&lt;/mi&gt;&lt;mi&gt;U&lt;/mi&gt;&lt;mtext&gt;&amp;nbsp;&lt;/mtext&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;r&lt;/mi&gt;&lt;mi&gt;i&lt;/mi&gt;&lt;mi&gt;a&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mtext&gt;&amp;nbsp;&lt;/mtext&gt;&lt;mi&gt;N&lt;/mi&gt;&lt;mi&gt;u&lt;/mi&gt;&lt;mi&gt;m&lt;/mi&gt;&lt;mi&gt;b&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;r&lt;/mi&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}


\text{MACFunction}(\text{PSK}, (selected\_cryptographic\_capabilities|ONU\ random\ challenge|OLT\ random\ challenge|ONU\ Serial\ Number))
&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/blockquote&gt;
&lt;p&gt;The OLT advertises its supported &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;A&lt;/mi&gt;&lt;mi&gt;C&lt;/mi&gt;&lt;mi&gt;F&lt;/mi&gt;&lt;mi&gt;u&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mi&gt;c&lt;/mi&gt;&lt;mi&gt;t&lt;/mi&gt;&lt;mi&gt;i&lt;/mi&gt;&lt;mi&gt;o&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

MACFunction&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; in the "OLT crypto capabilities" attribute of the OMCI "Enhanced security control" Management Entity. Then, the ONU chooses one of these &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;A&lt;/mi&gt;&lt;mi&gt;C&lt;/mi&gt;&lt;mi&gt;F&lt;/mi&gt;&lt;mi&gt;u&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mi&gt;c&lt;/mi&gt;&lt;mi&gt;t&lt;/mi&gt;&lt;mi&gt;i&lt;/mi&gt;&lt;mi&gt;o&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mi&gt;s&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

MACFunctions&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; and sets the "ONU selected crypto capabilities" attribute of the OMCI "Enhanced security control" Management Entity. It is then used as &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;onu_selected_cryptographic_capabilities&lt;/mtext&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

\text{onu\_selected\_cryptographic\_capabilities}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;.&lt;/p&gt;
&lt;p&gt;&lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;A&lt;/mi&gt;&lt;mi&gt;C&lt;/mi&gt;&lt;mi&gt;F&lt;/mi&gt;&lt;mi&gt;u&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mi&gt;c&lt;/mi&gt;&lt;mi&gt;t&lt;/mi&gt;&lt;mi&gt;i&lt;/mi&gt;&lt;mi&gt;o&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

MACFunction&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; is chosen from the following list:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;AES-CMAC-128 (default, must be supported).&lt;/li&gt;
&lt;li&gt;HMAC-SHA-256.&lt;/li&gt;
&lt;li&gt;HMAC-SHA-512.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="master-session-key-derivation"&gt;Master Session Key derivation&lt;/h4&gt;
&lt;p&gt;Finally, the &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

MSK&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; is derived from the &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;P&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

PSK&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; and the challenges. The following formula is used when a 128-bit &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

MSK&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; is required, which is always the case for GPON, XG(S)-PON and NG-PON2:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;
&lt;strong&gt; OMCI-based 128-bit &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

MSK&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; derivation&lt;/strong&gt;
&lt;/p&gt;
&lt;p&gt;&lt;span class="katex"&gt;&lt;math display="block" xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;MSK&lt;/mtext&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mtext&gt;MACFunction&lt;/mtext&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mtext&gt;PSK&lt;/mtext&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mi&gt;O&lt;/mi&gt;&lt;mi&gt;L&lt;/mi&gt;&lt;mi&gt;T&lt;/mi&gt;&lt;mtext&gt;&amp;nbsp;&lt;/mtext&gt;&lt;mi&gt;r&lt;/mi&gt;&lt;mi&gt;a&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mi&gt;d&lt;/mi&gt;&lt;mi&gt;o&lt;/mi&gt;&lt;mi&gt;m&lt;/mi&gt;&lt;mtext&gt;&amp;nbsp;&lt;/mtext&gt;&lt;mi&gt;c&lt;/mi&gt;&lt;mi&gt;h&lt;/mi&gt;&lt;mi&gt;a&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mi&gt;g&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi mathvariant="normal"&gt;&amp;smid;&lt;/mi&gt;&lt;mi&gt;O&lt;/mi&gt;&lt;mi&gt;N&lt;/mi&gt;&lt;mi&gt;U&lt;/mi&gt;&lt;mtext&gt;&amp;nbsp;&lt;/mtext&gt;&lt;mi&gt;r&lt;/mi&gt;&lt;mi&gt;a&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mi&gt;d&lt;/mi&gt;&lt;mi&gt;o&lt;/mi&gt;&lt;mi&gt;m&lt;/mi&gt;&lt;mtext&gt;&amp;nbsp;&lt;/mtext&gt;&lt;mi&gt;c&lt;/mi&gt;&lt;mi&gt;h&lt;/mi&gt;&lt;mi&gt;a&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mi&gt;g&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mtext&gt;,&amp;nbsp;take&amp;nbsp;the&amp;nbsp;128&amp;nbsp;most&amp;nbsp;significant&amp;nbsp;bits.&lt;/mtext&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}


  \text{MSK} = \text{MACFunction}(\text{PSK}, (OLT\ random\ challenge | ONU\ random\ challenge))\text{, take the 128 most significant bits.}
&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;However, 50G-PON also supports 256-bit MSKs. When combining the ITU-T G.988 (OMCI)&lt;sup id="fnref2:itutG988"&gt;&lt;a class="footnote-ref" href="#fn:itutG988"&gt;15&lt;/a&gt;&lt;/sup&gt; and ITU-T G.9804.2 (50G-PON)&lt;sup id="fnref3:itutG9804.2"&gt;&lt;a class="footnote-ref" href="#fn:itutG9804.2"&gt;17&lt;/a&gt;&lt;/sup&gt; specifications, it is unclear how &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

MSK&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; should be derived in this situation. ITU-T G.9804.2 also defers to ITU-T G.987.3&lt;sup id="fnref4:itutG987.3"&gt;&lt;a class="footnote-ref" href="#fn:itutG987.3"&gt;9&lt;/a&gt;&lt;/sup&gt; for OMCI authentication.&lt;/p&gt;
&lt;p&gt;When &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;MACFunction&lt;/mtext&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mtext&gt;AES-CMAC-128&lt;/mtext&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

\text{MACFunction}=\text{AES-CMAC-128}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;, the equation is clear:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;
&lt;strong&gt; OMCI-based 50G-PON 256-bit MSK derivation for &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;MACFunction&lt;/mtext&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mtext&gt;AES-CMAC-128&lt;/mtext&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

\text{MACFunction}=\text{AES-CMAC-128}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;&lt;/strong&gt;
&lt;/p&gt;
&lt;p&gt;&lt;span class="katex"&gt;&lt;math display="block" xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;MSK&lt;/mtext&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mi mathvariant="normal"&gt;AES-128-ECMAC&lt;/mi&gt;&lt;mo&gt;&amp;af;&lt;/mo&gt;&lt;mrow&gt;&lt;mo fence="true"&gt;(&lt;/mo&gt;&lt;mtext&gt;PSK&lt;/mtext&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mi&gt;O&lt;/mi&gt;&lt;mi&gt;L&lt;/mi&gt;&lt;mi&gt;T&lt;/mi&gt;&lt;mtext&gt;&amp;nbsp;&lt;/mtext&gt;&lt;mi&gt;r&lt;/mi&gt;&lt;mi&gt;a&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mi&gt;d&lt;/mi&gt;&lt;mi&gt;o&lt;/mi&gt;&lt;mi&gt;m&lt;/mi&gt;&lt;mtext&gt;&amp;nbsp;&lt;/mtext&gt;&lt;mi&gt;c&lt;/mi&gt;&lt;mi&gt;h&lt;/mi&gt;&lt;mi&gt;a&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mi&gt;g&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi mathvariant="normal"&gt;&amp;smid;&lt;/mi&gt;&lt;mi&gt;O&lt;/mi&gt;&lt;mi&gt;N&lt;/mi&gt;&lt;mi&gt;U&lt;/mi&gt;&lt;mtext&gt;&amp;nbsp;&lt;/mtext&gt;&lt;mi&gt;r&lt;/mi&gt;&lt;mi&gt;a&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mi&gt;d&lt;/mi&gt;&lt;mi&gt;o&lt;/mi&gt;&lt;mi&gt;m&lt;/mi&gt;&lt;mtext&gt;&amp;nbsp;&lt;/mtext&gt;&lt;mi&gt;c&lt;/mi&gt;&lt;mi&gt;h&lt;/mi&gt;&lt;mi&gt;a&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mi&gt;g&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mn&gt;256&lt;/mn&gt;&lt;mo fence="true"&gt;)&lt;/mo&gt;&lt;/mrow&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}


\text{MSK} = 
\operatorname{AES-128\text{-}ECMAC}\left(\text{PSK}, (OLT\ random\ challenge | ONU\ random\ challenge), 256\right)
&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;where
&lt;br&gt;
&lt;span class="katex"&gt;&lt;math display="block" xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi mathvariant="normal"&gt;AES-128-ECMAC&lt;/mi&gt;&lt;mo&gt;&amp;af;&lt;/mo&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mi&gt;T&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mrow&gt;&lt;mo fence="true"&gt;{&lt;/mo&gt;&lt;mtable columnalign="left left" columnspacing="1em" rowspacing="0.36em"&gt;&lt;mtr&gt;&lt;mtd&gt;&lt;mstyle displaystyle="false" scriptlevel="0"&gt;&lt;mrow&gt;&lt;mi mathvariant="normal"&gt;AES-128-CMAC&lt;/mi&gt;&lt;mo&gt;&amp;af;&lt;/mo&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mi&gt;T&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;/mrow&gt;&lt;/mstyle&gt;&lt;/mtd&gt;&lt;mtd&gt;&lt;mstyle displaystyle="false" scriptlevel="0"&gt;&lt;mrow&gt;&lt;mi&gt;T&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mo&gt;&amp;le;&lt;/mo&gt;&lt;mn&gt;128&lt;/mn&gt;&lt;/mrow&gt;&lt;/mstyle&gt;&lt;/mtd&gt;&lt;/mtr&gt;&lt;mtr&gt;&lt;mtd&gt;&lt;mstyle displaystyle="false" scriptlevel="0"&gt;&lt;mrow&gt;&lt;mi mathvariant="normal"&gt;AES-128-CMAC&lt;/mi&gt;&lt;mo&gt;&amp;af;&lt;/mo&gt;&lt;mrow&gt;&lt;mo fence="true"&gt;(&lt;/mo&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;msub&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mtext&gt;lessLastBlock&lt;/mtext&gt;&lt;/msub&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mn&gt;128&lt;/mn&gt;&lt;mo fence="true"&gt;)&lt;/mo&gt;&lt;/mrow&gt;&lt;mi mathvariant="normal"&gt;&amp;smid;&lt;/mi&gt;&lt;mi mathvariant="normal"&gt;AES-128-CMAC&lt;/mi&gt;&lt;mo&gt;&amp;af;&lt;/mo&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mn&gt;128&lt;/mn&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;/mrow&gt;&lt;/mstyle&gt;&lt;/mtd&gt;&lt;mtd&gt;&lt;mstyle displaystyle="false" scriptlevel="0"&gt;&lt;mrow&gt;&lt;mi&gt;T&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mn&gt;256&lt;/mn&gt;&lt;/mrow&gt;&lt;/mstyle&gt;&lt;/mtd&gt;&lt;/mtr&gt;&lt;/mtable&gt;&lt;/mrow&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}


\operatorname{AES-128\text{-}ECMAC}(K, M, Tlen)
=
\begin{cases}
\operatorname{AES-128-CMAC}(K, M, Tlen),
&amp;amp; Tlen \leq 128 \\[4pt]
\operatorname{AES-128-CMAC}\left(K, M_{\text{lessLastBlock}}, 128\right)
|
\operatorname{AES-128-CMAC}(K, M, 128),
&amp;amp; Tlen = 256
\end{cases}
&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;&lt;/br&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;When &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;MACFunction&lt;/mtext&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mtext&gt;HMAC-SHA-256&lt;/mtext&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

\text{MACFunction}=\text{HMAC-SHA-256}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; or &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;MACFunction&lt;/mtext&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mtext&gt;HMAC-SHA-512&lt;/mtext&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

\text{MACFunction}=\text{HMAC-SHA-512}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; are used, the specifications imply one of two things:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Following ITU-T G.9804.2 Annex C &amp;ldquo;Secure mutual authentication&amp;rdquo;, the output of &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;MACFunction&lt;/mtext&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

\text{MACFunction}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; is truncated to 256 bits, as &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;HMAC-SHA-256&lt;/mtext&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

\text{HMAC-SHA-256}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; generates a 256-bit value and &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;HMAC-SHA-512&lt;/mtext&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

\text{HMAC-SHA-512}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; a 512-bit value.&lt;/li&gt;
&lt;li&gt;ITU-T G.988 requires &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

MSK&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; to be truncated to 128 bits. According to ITU-T G.9804.2 clause 9.13, &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

MSK&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; must be extended to 256 bits using the same process as the "OMCI-based 50G-PON 256-bit MSK derivation for &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;MACFunction&lt;/mtext&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mtext&gt;AES-CMAC-128&lt;/mtext&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

\text{MACFunction}=\text{AES-CMAC-128}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;" equation above.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The key contradictory quotes are available in &lt;a href="resources/2026-09-16_overview-of-passive-optical-network-security/annex-c-contradictory-quotes.pdf" target="_blank"&gt;Annex C: Contradictory specification quotes relative to the derivation of a 256-bit &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

MSK&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; for HMACs with an output size of 256-bit or more&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;As both the ONU and OLT must derive the same &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

MSK&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;, a manufacturer testing this specific case with different ONUs or OLTs would notice any implementation mismatch. A clarification of the specification would make clear what is actually implemented, but all manufacturers should have the same implementation eventually. As 50G-PON is not widely deployed, they might not have faced this choice yet, especially with these specific &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;MACFunctions&lt;/mtext&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

\text{MACFunctions}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;.&lt;/p&gt;
&lt;h3 id="ieee-8021x-based-authentication"&gt;IEEE 802.1X-based authentication&lt;/h3&gt;
&lt;p&gt;This is the second mutual secure authentication mechanism, only available in XG(S)-PON, NG-PON2 and 50G-PON. Its implementation is mostly detailed in Annex D of ITU-T G.987.3&lt;sup id="fnref5:itutG987.3"&gt;&lt;a class="footnote-ref" href="#fn:itutG987.3"&gt;9&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;
&lt;p&gt;IEEE 802.1X supports many authentication methods through the Extensible Authentication Protocol (EAP)&lt;sup id="fnref:eap"&gt;&lt;a class="footnote-ref" href="#fn:eap"&gt;23&lt;/a&gt;&lt;/sup&gt;. EAP-GPSK&lt;sup id="fnref:eap_gpsk"&gt;&lt;a class="footnote-ref" href="#fn:eap_gpsk"&gt;24&lt;/a&gt;&lt;/sup&gt; which is based around a pre-shared key, must be supported according to ITU-T G.987.3&lt;sup id="fnref6:itutG987.3"&gt;&lt;a class="footnote-ref" href="#fn:itutG987.3"&gt;9&lt;/a&gt;&lt;/sup&gt;. EAP-TLS&lt;sup id="fnref:eap_tls"&gt;&lt;a class="footnote-ref" href="#fn:eap_tls"&gt;25&lt;/a&gt;&lt;/sup&gt; is also mentioned in the specification and allows the use of public-key cryptography. Any EAP method that supports mutual authentication and the generation of a secret &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;msub&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mrow&gt;&lt;mi&gt;E&lt;/mi&gt;&lt;mi&gt;A&lt;/mi&gt;&lt;mi&gt;P&lt;/mi&gt;&lt;/mrow&gt;&lt;/msub&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

MSK_{EAP}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; can be used.&lt;/p&gt;
&lt;p&gt;RFC 3748&lt;sup id="fnref2:eap"&gt;&lt;a class="footnote-ref" href="#fn:eap"&gt;23&lt;/a&gt;&lt;/sup&gt; mentions that the &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;msub&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mrow&gt;&lt;mi&gt;E&lt;/mi&gt;&lt;mi&gt;A&lt;/mi&gt;&lt;mi&gt;P&lt;/mi&gt;&lt;/mrow&gt;&lt;/msub&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

MSK_{EAP}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; generated must be at least 64 bytes long, however we need only 16 bytes or 32 bytes (50G-PON only). &lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;
&lt;strong&gt; IEEE 802.1X-based MSK derivation &lt;/strong&gt;
&lt;/p&gt;
&lt;p&gt;Let &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;msub&gt;&lt;mi&gt;T&lt;/mi&gt;&lt;mrow&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;/mrow&gt;&lt;/msub&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

T_{MSK}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; be the required &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;msub&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mrow&gt;&lt;mi&gt;P&lt;/mi&gt;&lt;mi&gt;O&lt;/mi&gt;&lt;mi&gt;N&lt;/mi&gt;&lt;/mrow&gt;&lt;/msub&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

MSK_{PON}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; size in bits. &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;msub&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mrow&gt;&lt;mi&gt;P&lt;/mi&gt;&lt;mi&gt;O&lt;/mi&gt;&lt;mi&gt;N&lt;/mi&gt;&lt;/mrow&gt;&lt;/msub&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

MSK_{PON}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; is derived from &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;msub&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mrow&gt;&lt;mi&gt;E&lt;/mi&gt;&lt;mi&gt;A&lt;/mi&gt;&lt;mi&gt;P&lt;/mi&gt;&lt;/mrow&gt;&lt;/msub&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

MSK_{EAP}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; as follows:&lt;/p&gt;
&lt;p&gt;&lt;span class="katex"&gt;&lt;math display="block" xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;msub&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mrow&gt;&lt;mi&gt;P&lt;/mi&gt;&lt;mi&gt;O&lt;/mi&gt;&lt;mi&gt;N&lt;/mi&gt;&lt;/mrow&gt;&lt;/msub&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;msub&gt;&lt;mi&gt;T&lt;/mi&gt;&lt;mrow&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;/mrow&gt;&lt;/msub&gt;&lt;mtext&gt;&amp;nbsp;most&amp;nbsp;significant&amp;nbsp;bits&amp;nbsp;of&amp;nbsp;&lt;/mtext&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;msub&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mrow&gt;&lt;mi&gt;E&lt;/mi&gt;&lt;mi&gt;A&lt;/mi&gt;&lt;mi&gt;P&lt;/mi&gt;&lt;/mrow&gt;&lt;/msub&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}


MSK_{PON} = T_{MSK}\text{ most significant bits of } MSK_{EAP}
&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="a-note-on-forward-secrecy_1"&gt;A note on Forward Secrecy&lt;/h2&gt;
&lt;p&gt;Only one authentication scheme, the IEEE 802.1X-based scheme with the right EAP (EAP-TLS with a Diffie-Hellman key exchange for instance), might lead to an encrypted session that provides perfect forward secrecy. For the other schemes, the leak of the &lt;em&gt;Registration_ID&lt;/em&gt; or &lt;em&gt;PSK&lt;/em&gt; would enable attackers to decrypt the signal in harvest now, decrypt later attacks. The encrypted data encryption key contained in the PLOAM messages could be decrypted, and then the payloads of the XGEM frames.&lt;/p&gt;
&lt;h2 id="key-derivation"&gt;Key Derivation&lt;/h2&gt;
&lt;p&gt;&lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

MSK&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; and its derived keys have three purposes: encrypting the data encryption key (using the &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

MSK&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; for GPON or the Key Encryption Key (&lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mi&gt;E&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

KEK&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;) otherwise), authenticating PLOAM messages and authenticating OMCI messages (XG-PON and above only).&lt;/p&gt;
&lt;p class="center-text"&gt;
&lt;img src="resources/2026-09-16_overview-of-passive-optical-network-security/aes_key_encryption_and_derivations.svg"/&gt;&lt;br/&gt;
&lt;i&gt;Key derivation decision diagram&lt;/i&gt;
&lt;/p&gt;
&lt;p&gt;Note that the typos and wordplays in the strings match the actual values used by the specifications, as specific string lengths were required.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;
&lt;strong&gt;XG(S)-PON and NG-PON2 derivations&lt;/strong&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;span class="katex"&gt;&lt;math display="block" xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mtext&gt;AES-128-CMAC&lt;/mtext&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mtext&gt;SN&lt;/mtext&gt;&lt;mi mathvariant="normal"&gt;&amp;smid;&lt;/mi&gt;&lt;mtext&gt;PON-TAG&lt;/mtext&gt;&lt;mi mathvariant="normal"&gt;&amp;smid;&lt;/mi&gt;&lt;mtext&gt;"SessionK"&lt;/mtext&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

SK = \text{AES-128-CMAC}(MSK, (\text{SN}|\text{PON-TAG}|\text{"SessionK"}))&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;
&lt;span class="katex"&gt;&lt;math display="block" xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;O&lt;/mi&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;C&lt;/mi&gt;&lt;mi&gt;I&lt;/mi&gt;&lt;mi mathvariant="normal"&gt;_&lt;/mi&gt;&lt;mi&gt;I&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mtext&gt;AES-128-CMAC&lt;/mtext&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mtext&gt;"OMCIIntegrityKey"&lt;/mtext&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

OMCI\_IK = \text{AES-128-CMAC}(SK, \text{"OMCIIntegrityKey"})&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;
&lt;span class="katex"&gt;&lt;math display="block" xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;P&lt;/mi&gt;&lt;mi&gt;L&lt;/mi&gt;&lt;mi&gt;O&lt;/mi&gt;&lt;mi&gt;A&lt;/mi&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi mathvariant="normal"&gt;_&lt;/mi&gt;&lt;mi&gt;I&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mtext&gt;AES-128-CMAC&lt;/mtext&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mtext&gt;"PLOAMIntegrtyKey"&lt;/mtext&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

PLOAM\_IK = \text{AES-128-CMAC}(SK, \text{"PLOAMIntegrtyKey"})&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;
&lt;span class="katex"&gt;&lt;math display="block" xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mi&gt;E&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mtext&gt;AES-128-CMAC&lt;/mtext&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mtext&gt;"KeyEncryptionKey"&lt;/mtext&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

KEK = \text{AES-128-CMAC}(SK, \text{"KeyEncryptionKey"})&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;
&lt;strong&gt; 50G-PON derivations&lt;/strong&gt;
&lt;/p&gt;
&lt;p&gt;Let:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

K&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; be the key used in the BC-ECMAC definition.&lt;/li&gt;
&lt;li&gt;&lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

M&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; be the input message used in the BC-ECMAC definition.&lt;/li&gt;
&lt;li&gt;&lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;T&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

Tlen&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; be the requested MAC output length in bits.&lt;/li&gt;
&lt;li&gt;&lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;B&lt;/mi&gt;&lt;mi&gt;C&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

BC&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; be the chosen Block Cipher.&lt;/li&gt;
&lt;li&gt;&lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;msub&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mtext&gt;lessLastBlock&lt;/mtext&gt;&lt;/msub&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

M_{\text{lessLastBlock}}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; be &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

M&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; with its final 16 octets removed.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
&lt;span class="katex"&gt;&lt;math display="block" xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mtext&gt;BC-ECMAC&lt;/mtext&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;N&lt;/mi&gt;&lt;mi mathvariant="normal"&gt;&amp;smid;&lt;/mi&gt;&lt;mtext&gt;PON-TAG&lt;/mtext&gt;&lt;mi mathvariant="normal"&gt;&amp;smid;&lt;/mi&gt;&lt;mtext&gt;PON-TAG&lt;/mtext&gt;&lt;mi mathvariant="normal"&gt;&amp;smid;&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;N&lt;/mi&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mi&gt;T&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

SK = \text{BC-ECMAC}(MSK, (SN|\text{PON-TAG}|\text{PON-TAG}|SN), Tlen)&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;
&lt;span class="katex"&gt;&lt;math display="block" xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;O&lt;/mi&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;C&lt;/mi&gt;&lt;mi&gt;I&lt;/mi&gt;&lt;mi mathvariant="normal"&gt;_&lt;/mi&gt;&lt;mi&gt;I&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mtext&gt;BC-ECMAC&lt;/mtext&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mtext&gt;&amp;nbsp;"OMCIIntegrityKeyMakeOMCImoreSafe"&lt;/mtext&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mi&gt;T&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

OMCI\_IK = \text{BC-ECMAC}(SK, \text{ "OMCIIntegrityKeyMakeOMCImoreSafe"}, Tlen)&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;
&lt;span class="katex"&gt;&lt;math display="block" xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;P&lt;/mi&gt;&lt;mi&gt;L&lt;/mi&gt;&lt;mi&gt;O&lt;/mi&gt;&lt;mi&gt;A&lt;/mi&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi mathvariant="normal"&gt;_&lt;/mi&gt;&lt;mi&gt;I&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mtext&gt;AES-128-CMAC&lt;/mtext&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;msub&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mtext&gt;16&amp;nbsp;least&amp;nbsp;significant&amp;nbsp;bytes&lt;/mtext&gt;&lt;/msub&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mtext&gt;"PLOAMIntegrtyKey"&lt;/mtext&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

PLOAM\_IK = \text{AES-128-CMAC}(SK_\text{16 least significant bytes}, \text{"PLOAMIntegrtyKey"})&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;
&lt;span class="katex"&gt;&lt;math display="block" xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mi&gt;E&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mtext&gt;BC-ECMAC&lt;/mtext&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mtext&gt;"KeyEncryptionKeyMakeKEKMoreSafey"&lt;/mtext&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mi&gt;T&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

KEK = \text{BC-ECMAC}(SK, \text{"KeyEncryptionKeyMakeKEKMoreSafey"}, Tlen)&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;

where

&lt;span class="katex"&gt;&lt;math display="block" xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi mathvariant="normal"&gt;BC-ECMAC&lt;/mi&gt;&lt;mo&gt;&amp;af;&lt;/mo&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mi&gt;T&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mrow&gt;&lt;mo fence="true"&gt;{&lt;/mo&gt;&lt;mtable columnalign="left left" columnspacing="1em" rowspacing="0.36em"&gt;&lt;mtr&gt;&lt;mtd&gt;&lt;mstyle displaystyle="false" scriptlevel="0"&gt;&lt;mrow&gt;&lt;mi mathvariant="normal"&gt;BC-CMAC&lt;/mi&gt;&lt;mo&gt;&amp;af;&lt;/mo&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mi&gt;T&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;/mrow&gt;&lt;/mstyle&gt;&lt;/mtd&gt;&lt;mtd&gt;&lt;mstyle displaystyle="false" scriptlevel="0"&gt;&lt;mrow&gt;&lt;mi&gt;T&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mo&gt;&amp;le;&lt;/mo&gt;&lt;mn&gt;128&lt;/mn&gt;&lt;/mrow&gt;&lt;/mstyle&gt;&lt;/mtd&gt;&lt;/mtr&gt;&lt;mtr&gt;&lt;mtd&gt;&lt;mstyle displaystyle="false" scriptlevel="0"&gt;&lt;mrow&gt;&lt;mi mathvariant="normal"&gt;BC-CMAC&lt;/mi&gt;&lt;mo&gt;&amp;af;&lt;/mo&gt;&lt;mrow&gt;&lt;mo fence="true"&gt;(&lt;/mo&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;msub&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mtext&gt;lessLastBlock&lt;/mtext&gt;&lt;/msub&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mn&gt;128&lt;/mn&gt;&lt;mo fence="true"&gt;)&lt;/mo&gt;&lt;/mrow&gt;&lt;mi mathvariant="normal"&gt;&amp;smid;&lt;/mi&gt;&lt;mi mathvariant="normal"&gt;BC-CMAC&lt;/mi&gt;&lt;mo&gt;&amp;af;&lt;/mo&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mn&gt;128&lt;/mn&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;/mrow&gt;&lt;/mstyle&gt;&lt;/mtd&gt;&lt;mtd&gt;&lt;mstyle displaystyle="false" scriptlevel="0"&gt;&lt;mrow&gt;&lt;mi&gt;T&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mn&gt;256&lt;/mn&gt;&lt;/mrow&gt;&lt;/mstyle&gt;&lt;/mtd&gt;&lt;/mtr&gt;&lt;/mtable&gt;&lt;/mrow&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}


\operatorname{BC\text{-}ECMAC}(K, M, Tlen)
=
\begin{cases}
\operatorname{BC-CMAC}(K, M, Tlen),
&amp;amp; Tlen \leq 128 \\[4pt]
\operatorname{BC-CMAC}\left(K, M_{\text{lessLastBlock}}, 128\right)
|
\operatorname{BC-CMAC}(K, M, 128),
&amp;amp; Tlen = 256
\end{cases}
&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;For GPON, the data encryption key is only sent encrypted when the OMCI authentication is used; otherwise it is sent in clear form. The key is always sent encrypted in XG(S)-PON, NG-PON2 and 50G-PON, using the &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mi&gt;E&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

KEK&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; key derived from the &lt;em&gt;MSK&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;The other two keys derived from the &lt;em&gt;MSK&lt;/em&gt; in XG(S)-PON, NG-PON2 and 50G-PON are used for the authentication of OMCI and PLOAM messages, so only OMCI and PLOAM have authenticity checks, not the main payload. GPON does not have such a mechanism.&lt;/p&gt;
&lt;h2 id="authentication-of-ploam-and-omci-messages"&gt;Authentication of PLOAM and OMCI messages&lt;/h2&gt;
&lt;p&gt;Only XG(S)-PON, NG-PON2 and 50G-PON authenticate the PLOAM and OMCI messages; GPON does not. Authentication ensures the messages have been sent by the right peer and that they have not been tampered with.&lt;/p&gt;
&lt;p&gt;The PLOAM and OMCI &lt;em&gt;Message Integrity Check (MIC)&lt;/em&gt; values are derived the following way:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;
&lt;strong&gt; PLOAM and OMCI MIC calculation &lt;/strong&gt;
&lt;/p&gt;
&lt;p&gt;&lt;span class="katex"&gt;&lt;math display="block" xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;PLOAM-MIC&lt;/mtext&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mtext&gt;AES-128-CMAC&lt;/mtext&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mtext&gt;PLOAM_IK&lt;/mtext&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;msub&gt;&lt;mi&gt;C&lt;/mi&gt;&lt;mrow&gt;&lt;mi&gt;d&lt;/mi&gt;&lt;mi&gt;i&lt;/mi&gt;&lt;mi&gt;r&lt;/mi&gt;&lt;/mrow&gt;&lt;/msub&gt;&lt;mi mathvariant="normal"&gt;&amp;smid;&lt;/mi&gt;&lt;mtext&gt;PLOAM_CONTENT&lt;/mtext&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mn&gt;64&lt;/mn&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}


\text{PLOAM-MIC} = \text{AES-128-CMAC} (\text{PLOAM\_IK}, (C_{dir} | \text{PLOAM\_CONTENT}), 64)
&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span class="katex"&gt;&lt;math display="block" xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;OMCI-MIC&lt;/mtext&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mtext&gt;BC-CMAC&lt;/mtext&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mtext&gt;OMCI_IK&lt;/mtext&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;msub&gt;&lt;mi&gt;C&lt;/mi&gt;&lt;mrow&gt;&lt;mi&gt;d&lt;/mi&gt;&lt;mi&gt;i&lt;/mi&gt;&lt;mi&gt;r&lt;/mi&gt;&lt;/mrow&gt;&lt;/msub&gt;&lt;mi mathvariant="normal"&gt;&amp;smid;&lt;/mi&gt;&lt;mtext&gt;OMCI_CONTENT&lt;/mtext&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mn&gt;32&lt;/mn&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}


\text{OMCI-MIC} = \text{BC-CMAC} (\text{OMCI\_IK}, (C_{dir} | \text{OMCI\_CONTENT}), 32)
&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;
&lt;br&gt;
where &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;msub&gt;&lt;mi&gt;C&lt;/mi&gt;&lt;mrow&gt;&lt;mi&gt;d&lt;/mi&gt;&lt;mi&gt;i&lt;/mi&gt;&lt;mi&gt;r&lt;/mi&gt;&lt;/mrow&gt;&lt;/msub&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mn&gt;0&lt;/mn&gt;&lt;mi&gt;x&lt;/mi&gt;&lt;mn&gt;01&lt;/mn&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

C_{dir} = 0x01&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; for downstream and &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;msub&gt;&lt;mi&gt;C&lt;/mi&gt;&lt;mrow&gt;&lt;mi&gt;d&lt;/mi&gt;&lt;mi&gt;i&lt;/mi&gt;&lt;mi&gt;r&lt;/mi&gt;&lt;/mrow&gt;&lt;/msub&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mn&gt;0&lt;/mn&gt;&lt;mi&gt;x&lt;/mi&gt;&lt;mn&gt;02&lt;/mn&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

C_{dir} = 0x02&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; for upstream.
&lt;br&gt;
&lt;br&gt;
and
&lt;br&gt;
&lt;br&gt;
&lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;BC-CMAC&lt;/mtext&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

\text{BC-CMAC}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; is &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;AES-128-CMAC&lt;/mtext&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

\text{AES-128-CMAC}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; for XG(S)-PON and NG-PON2. For 50G-PON, the chosen block cipher used across data encryption, key derivation and message integrity checks is used for OMCI. This allows 50G-PON to use stronger keys (256-bit). PLOAM, however, always uses &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;AES-128-CMAC&lt;/mtext&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

\text{AES-128-CMAC}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;.&lt;/br&gt;&lt;/br&gt;&lt;/br&gt;&lt;/br&gt;&lt;/br&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;PLOAM and OMCI authentication is always enabled; however, before any &lt;em&gt;MSK&lt;/em&gt; has been derived a default key is used for PLOAM: &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mn&gt;0&lt;/mn&gt;&lt;mi&gt;x&lt;/mi&gt;&lt;mn&gt;5&lt;/mn&gt;&lt;msub&gt;&lt;mn&gt;5&lt;/mn&gt;&lt;mn&gt;16&lt;/mn&gt;&lt;/msub&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

0x55_{16}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;. The default key is always used for downstream broadcast PLOAM messages, as well as some unicast PLOAM messages such as the &lt;em&gt;Serial_Number_ONU&lt;/em&gt;, &lt;em&gt;Deactivate_ONU-ID&lt;/em&gt;, &lt;em&gt;Request_Registration&lt;/em&gt; and &lt;em&gt;Registration&lt;/em&gt; PLOAM messages. After that, the keys derived from the &lt;em&gt;MSK&lt;/em&gt; established from the &lt;em&gt;Registration_ID&lt;/em&gt; are used, and finally the keys derived from any new &lt;em&gt;MSK&lt;/em&gt; established from one of the authentication mechanisms.&lt;/p&gt;
&lt;h2 id="generating-the-data-encryption-keys"&gt;Generating the data encryption keys&lt;/h2&gt;
&lt;p&gt;There are two types of data encryption keys: unicast and multicast (broadcast). In the previous sections, we only mentioned which keys are used to encrypt the unicast data encryption key; not how it is generated.&lt;/p&gt;
&lt;p&gt;The unicast data encryption key used in the GPON, XG(S)-PON and NG-PON2 specifications is generated by each ONU, not the OLT.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;
&lt;strong&gt; GPON, XG-PON and NG-PON2 data encryption key generation&lt;/strong&gt;
&lt;/p&gt;
&lt;p&gt;&lt;span class="katex"&gt;&lt;math display="block" xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;E&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mi&gt;c&lt;/mi&gt;&lt;mi&gt;r&lt;/mi&gt;&lt;mi&gt;y&lt;/mi&gt;&lt;mi&gt;p&lt;/mi&gt;&lt;mi&gt;t&lt;/mi&gt;&lt;mi&gt;i&lt;/mi&gt;&lt;mi&gt;o&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;y&lt;/mi&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mtext&gt;ONU-generated&amp;nbsp;random&amp;nbsp;generated&amp;nbsp;value&amp;nbsp;of&amp;nbsp;size&amp;nbsp;128&amp;nbsp;bits&lt;/mtext&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}


EncryptionKey = \text{ONU-generated random generated value of size 128 bits}
&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;A secure random number generator must be used.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Moreover, if the key is not generated properly, all the authentication and key encryption will not matter as the attacker could bruteforce the data encryption key. Thus, according to the XG(S)-PON and NG-PON2 specifications, &amp;ldquo;the ONU
generates a new encryption key using a random number generator suitable for cryptographic purposes&amp;rdquo;&lt;sup id="fnref3:itutG989.3"&gt;&lt;a class="footnote-ref" href="#fn:itutG989.3"&gt;14&lt;/a&gt;&lt;/sup&gt;. The GPON specification has a similar mention &amp;ldquo;The ONU should generate a cryptographically unpredictable key.&amp;rdquo;&lt;sup id="fnref2:itutG9843"&gt;&lt;a class="footnote-ref" href="#fn:itutG9843"&gt;4&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;
&lt;p&gt;As for 50G-PON, the unicast data encryption key is now derived from both an OLT and an ONU random number, instead of being taken directly from the random number generator output:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;
&lt;strong&gt; 50G-PON data encryption key generation &lt;/strong&gt;
&lt;/p&gt;
&lt;p&gt;Let:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;KEK&lt;/mtext&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

\text{KEK}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; be the &lt;em&gt;Key Encryption Key&lt;/em&gt; derived from &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

MSK&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;.&lt;/li&gt;
&lt;li&gt;&lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;BC&lt;/mtext&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

\text{BC}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; be the chosen Block Cipher.&lt;/li&gt;
&lt;li&gt;&lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;Tlen&lt;/mtext&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

\text{Tlen}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; be the &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;BC&lt;/mtext&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

\text{BC}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; key size.&lt;/li&gt;
&lt;li&gt;&lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;KeyControl_RandomX&lt;/mtext&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

\text{KeyControl\_RandomX}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; and &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;KeyControl_RandomX&lt;/mtext&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

\text{KeyControl\_RandomX}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; be values sent to the ONU through PLOAM by the OLT.&lt;/li&gt;
&lt;li&gt;&lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;BC-ECMAC&lt;/mtext&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

\text{BC-ECMAC}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; as previously defined.&lt;/li&gt;
&lt;li&gt;&lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;BC-ECB&lt;/mtext&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

\text{BC-ECB}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; be &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;BC&lt;/mtext&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

\text{BC}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; with the ECB cipher mode.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span class="katex"&gt;&lt;math display="block" xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;E&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mi&gt;c&lt;/mi&gt;&lt;mi&gt;r&lt;/mi&gt;&lt;mi&gt;y&lt;/mi&gt;&lt;mi&gt;p&lt;/mi&gt;&lt;mi&gt;t&lt;/mi&gt;&lt;mi&gt;i&lt;/mi&gt;&lt;mi&gt;o&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;y&lt;/mi&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mtext&gt;BC-ECMAC&lt;/mtext&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mi&gt;E&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mtext&gt;ONUKeyContrib&lt;/mtext&gt;&lt;mi mathvariant="normal"&gt;&amp;smid;&lt;/mi&gt;&lt;mtext&gt;OLTKeyContrib&lt;/mtext&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mi&gt;T&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}


EncryptionKey = \text{BC-ECMAC}(KEK, \text{ONUKeyContrib}|\text{OLTKeyContrib}, Tlen)
&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;&lt;/p&gt;
&lt;!-- \text{BC-ECB}(KEK, \text{random number sent by the OLT}) --&gt;
&lt;p&gt;where&lt;/p&gt;
&lt;p&gt;&lt;span class="katex"&gt;&lt;math display="block" xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;OLTKeyContrib&lt;/mtext&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mrow&gt;&lt;mo fence="true"&gt;{&lt;/mo&gt;&lt;mtable columnalign="left left" columnspacing="1em" rowspacing="0.36em"&gt;&lt;mtr&gt;&lt;mtd&gt;&lt;mstyle displaystyle="false" scriptlevel="0"&gt;&lt;mrow&gt;&lt;mi mathvariant="normal"&gt;BC-ECB&lt;/mi&gt;&lt;mo&gt;&amp;af;&lt;/mo&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mi&gt;E&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mtext&gt;KeyControl_RandomX&lt;/mtext&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;/mrow&gt;&lt;/mstyle&gt;&lt;/mtd&gt;&lt;mtd&gt;&lt;mstyle displaystyle="false" scriptlevel="0"&gt;&lt;mrow&gt;&lt;mi&gt;T&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mn&gt;128&lt;/mn&gt;&lt;/mrow&gt;&lt;/mstyle&gt;&lt;/mtd&gt;&lt;/mtr&gt;&lt;mtr&gt;&lt;mtd&gt;&lt;mstyle displaystyle="false" scriptlevel="0"&gt;&lt;mrow&gt;&lt;mi mathvariant="normal"&gt;BC-ECB&lt;/mi&gt;&lt;mo&gt;&amp;af;&lt;/mo&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mi&gt;E&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mtext&gt;KeyControl_RandomX|KeyControl_RandomY&lt;/mtext&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;/mrow&gt;&lt;/mstyle&gt;&lt;/mtd&gt;&lt;mtd&gt;&lt;mstyle displaystyle="false" scriptlevel="0"&gt;&lt;mrow&gt;&lt;mi&gt;T&lt;/mi&gt;&lt;mi&gt;l&lt;/mi&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;n&lt;/mi&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mn&gt;256&lt;/mn&gt;&lt;/mrow&gt;&lt;/mstyle&gt;&lt;/mtd&gt;&lt;/mtr&gt;&lt;/mtable&gt;&lt;/mrow&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}


\text{OLTKeyContrib} = 
\begin{cases}
\operatorname{BC-ECB}(KEK, \text{KeyControl\_RandomX}),
&amp;amp; Tlen=128 \\[4pt]
\operatorname{BC-ECB}(KEK, \text{KeyControl\_RandomX|KeyControl\_RandomY}),
&amp;amp; Tlen=256
\end{cases}
&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;and&lt;/p&gt;
&lt;p&gt;&lt;span class="katex"&gt;&lt;math display="block" xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;ONUKeyContrib&lt;/mtext&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mtext&gt;ONU-generated&amp;nbsp;random&amp;nbsp;generated&amp;nbsp;value&amp;nbsp;of&amp;nbsp;size&amp;nbsp;Tlen&lt;/mtext&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}


\text{ONUKeyContrib} = \text{ONU-generated random generated value of size Tlen}
&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;
&lt;br&gt;
A secure random number generator must be used.&lt;/br&gt;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;
&lt;br/&gt;&lt;/br&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;However, the key is still generated on the ONU side, sent encrypted to the OLT and used as-is. Thus, it seems that the ONU can still hardcode a key or ignore the OLT's contribution, and is responsible for the key strength more generally. But the ONU can now use the OLT entropy pool to increase the data encryption key strength.&lt;/p&gt;
&lt;p&gt;Finally, for XG-PON and above, the data encryption key is sent encrypted to the OLT, using the chosen block cipher in ECB mode and &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mi&gt;E&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

KEK&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; as key. For GPON, &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

MSK&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; is used instead of &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mi&gt;E&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

KEK&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;, and encryption of the data encryption key not mandatory.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;
&lt;strong&gt; Encryption of the data encryption key&lt;/strong&gt;
&lt;/p&gt;
&lt;p&gt;For GPON
&lt;span class="katex"&gt;&lt;math display="block" xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;Encrypted&amp;nbsp;EncryptionKey&lt;/mtext&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mi mathvariant="normal"&gt;AES-128-ECB&lt;/mi&gt;&lt;mo&gt;&amp;af;&lt;/mo&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mtext&gt;Encryption&amp;nbsp;Key&lt;/mtext&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}


\text{Encrypted EncryptionKey} = \operatorname{AES-128-ECB}(MSK, \text{Encryption Key}),
&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;For XG-PON and above
&lt;span class="katex"&gt;&lt;math display="block" xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mtext&gt;Encrypted&amp;nbsp;EncryptionKey&lt;/mtext&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mi mathvariant="normal"&gt;BC-ECB&lt;/mi&gt;&lt;mo&gt;&amp;af;&lt;/mo&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mi&gt;E&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;mtext&gt;Encryption&amp;nbsp;Key&lt;/mtext&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mo separator="true"&gt;,&lt;/mo&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}


\text{Encrypted EncryptionKey} = \operatorname{BC-ECB}(KEK, \text{Encryption Key}),
&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;
&lt;br/&gt;
where &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;B&lt;/mi&gt;&lt;mi&gt;C&lt;/mi&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mi&gt;A&lt;/mi&gt;&lt;mi&gt;E&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mo&gt;&amp;minus;&lt;/mo&gt;&lt;mn&gt;128&lt;/mn&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

BC = AES-128&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; for XG(S)-PON and NG-PON2.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;XG(S)-PON, NG-PON2 and 50G-PON also allow the use of a multicast data encryption key which is generated on the OLT and allows a frame to be encrypted once so that it can be decrypted by multiple ONUs.&lt;/p&gt;
&lt;h2 id="enabling-encryption"&gt;Enabling encryption&lt;/h2&gt;
&lt;p&gt;Encryption is mostly disabled by default for all PON versions.&lt;/p&gt;
&lt;p&gt;For GPON, the encryption of a GEM port is activated through PLOAM, and only the downstream frames are encrypted. For XG-PON and above, the default XGEM port which is used for OMCI is always set for bidirectional unicast encryption, other XGEM ports must be provisioned (unicast/multicast, direction of the encryption, etc). However, the encryption of the frame is still enabled by the &lt;em&gt;Key_index&lt;/em&gt; field in the frame header, although the XG-PON specification does mention that it must be done &amp;ldquo;within the explicitly configured or pre-defined capabilities of the associated XGEM port&amp;rdquo;.&lt;/p&gt;
&lt;p class="center-text"&gt;
&lt;img src="resources/2026-09-16_overview-of-passive-optical-network-security/enabling_encryption.svg"/&gt;&lt;br/&gt;
&lt;i&gt;Enabling encryption decision diagram&lt;/i&gt;
&lt;/p&gt;
&lt;p&gt;For the encryption of the OMCI messages (on the OMCC channel), no OMCI Management Entity needs to be configured.
For XG-PON and above, ITU-T G.988&lt;sup id="fnref3:itutG988"&gt;&lt;a class="footnote-ref" href="#fn:itutG988"&gt;15&lt;/a&gt;&lt;/sup&gt; mentions that &amp;ldquo;If the GEM frame itself contains an encryption key index, it is understood to refer to the unicast key and to require encryption both up- and downstream.&amp;rdquo; and the XG(S)-PON and above specifications say &amp;ldquo;Whenever the default XGEM port traffic is encrypted in the downstream direction, the ONU is expected to encrypt the default XGEM port traffic upstream&amp;rdquo;. One interpretation of that last quote could imply that an unencrypted frame can be sent to the default (OMCI) XGEM port, which slightly contradicts the ITU-T G.988 specification.&lt;/p&gt;
&lt;p&gt;Implementers should make sure that the &lt;em&gt;Key_index&lt;/em&gt; value of a specific frame matches the configuration of the XGEM port.&lt;/p&gt;
&lt;h2 id="ploam-messages-and-omci-management-entities-relevant-to-security-features"&gt;PLOAM messages and OMCI Management Entities relevant to security features&lt;/h2&gt;
&lt;p&gt;There are a few PLOAM messages and OMCI Management Entities related to security features that are scattered in the specifications. &lt;a href="resources/2026-09-16_overview-of-passive-optical-network-security/annex-b-ploam-and-omci-security-related-messages.pdf" target="_blank"&gt;Annex B: PLOAM and OMCI security-related messages&lt;/a&gt; can be used as a reference and might be useful for the next section.&lt;/p&gt;
&lt;h2 id="encrypted-communications"&gt;Encrypted communications&lt;/h2&gt;
&lt;p&gt;Finally! We've identified the ONU, passed the authentication process, established an &lt;em&gt;MSK&lt;/em&gt;, derived the keys, generated a random data encryption key and sent it encrypted to the OLT, we've enabled the encryption on the (X)GEM port, set the right fields in the (X)GEM header, authenticated the OMCI and PLOAM messages (unless GPON), and at last we can send our encrypted message!&lt;/p&gt;
&lt;h3 id="block-cipher-and-ctr-mode"&gt;Block cipher and CTR mode&lt;/h3&gt;
&lt;p&gt;First of all, only the payload of the X(GEM) frame is encrypted, not the X(GEM) header.&lt;/p&gt;
&lt;p&gt;The default encryption method is AES-128-CTR (AES-128 with the counter mode of operation specified in NIST SP 800-38A&lt;sup id="fnref:nistsp800_38a"&gt;&lt;a class="footnote-ref" href="#fn:nistsp800_38a"&gt;22&lt;/a&gt;&lt;/sup&gt;) and it must be supported by both the ONU and the OLT. In addition to AES-128, 50G-PON (ITU-T G.9804.2&lt;sup id="fnref4:itutG9804.2"&gt;&lt;a class="footnote-ref" href="#fn:itutG9804.2"&gt;17&lt;/a&gt;&lt;/sup&gt;) must also support AES-256. However, for 50G-PON, the OMCI "ONU2-G" Management Entity can advertise and enable support for other block ciphers: Camellia-128, Camellia-256 and SM4-128.&lt;/p&gt;
&lt;p&gt;While technically, the NIST SP 800-38A&lt;sup id="fnref2:nistsp800_38a"&gt;&lt;a class="footnote-ref" href="#fn:nistsp800_38a"&gt;22&lt;/a&gt;&lt;/sup&gt; &amp;ldquo;assumes that a FIPS-approved symmetric key block cipher algorithm has been chosen as the underlying algorithm&amp;rdquo;, and Camellia and SM4 are not NIST-approved, the same counter mode is used for all block ciphers.&lt;/p&gt;
&lt;p&gt;Even though CTR is a strong encryption mode, it does not provide authentication, which means an attacker can blindly modify the encrypted payload. Other protocols such as TLS 1.3 use AEAD (Authenticated encryption with additional data) modes to provide both encryption and authentication of the main payload, as well as authentication of additional data that must stay visible (a header for instance).&lt;/p&gt;
&lt;h3 id="the-counter"&gt;The Counter&lt;/h3&gt;
&lt;p&gt;The counter is reset at the start of each (X)GEM frame, and its initial value is called &lt;em&gt;Initial Counter Block&lt;/em&gt; in XG-PON and later but this designation works for GPON as well. It is then increased by one after each 16-byte block inside the (X)GEM frame. &lt;/p&gt;
&lt;p&gt;The &lt;em&gt;Initial Counter Block&lt;/em&gt; is a function of the SFC which is sent by the OLT and the &lt;em&gt;Intraframe counter&lt;/em&gt; (IFC). The &lt;em&gt;IFC&lt;/em&gt; is reset to 0 at the start of each FS frame, increased every 4 bytes for GPON and every 16 bytes for XG-PON and later. The &lt;em&gt;IFC&lt;/em&gt; value used in the &lt;em&gt;Initial Counter Block&lt;/em&gt; calculation is the &lt;em&gt;IFC&lt;/em&gt; value at the first byte of the GEM header for GPON, and at the position of the first four bytes for XG-PON and later (XGEM frames are aligned on a 4-byte boundary).&lt;/p&gt;
&lt;p&gt;The figures below represent the &lt;em&gt;SFC&lt;/em&gt;, &lt;em&gt;IFC&lt;/em&gt; and how (X)GEM frames are encrypted for downstream GPON and XG-PON (and above).&lt;/p&gt;
&lt;p class="center-text"&gt;
&lt;img src="resources/2026-09-16_overview-of-passive-optical-network-security/gpon_encryption.svg"/&gt;&lt;br/&gt;
&lt;i&gt;Encryption of a downstream (GPON) GEM frame&lt;/i&gt;
&lt;/p&gt;
&lt;p class="center-text"&gt;
&lt;img src="resources/2026-09-16_overview-of-passive-optical-network-security/ngpon_encryption.svg"/&gt;&lt;br/&gt;
&lt;i&gt;Encryption of a downstream XGEM frame&lt;/i&gt;
&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;
&lt;strong&gt; Duplicated counter blocks &lt;/strong&gt;
&lt;/p&gt;
&lt;p&gt;The XG-PON specification and above mention two &lt;em&gt;SFC&lt;/em&gt; values which lead to duplicated counter blocks in both directions:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;For XG(S)-PON and NG-PON2: &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;F&lt;/mi&gt;&lt;mi&gt;C&lt;/mi&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mn&gt;49..0&lt;/mn&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mn&gt;0&lt;/mn&gt;&lt;mi&gt;b&lt;/mi&gt;&lt;mn&gt;1&lt;/mn&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mn&gt;0&lt;/mn&gt;&lt;msub&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mn&gt;49&lt;/mn&gt;&lt;/msub&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

SFC(49..0)=0b1(0)_{49}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; and &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;F&lt;/mi&gt;&lt;mi&gt;C&lt;/mi&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mn&gt;49..0&lt;/mn&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mn&gt;0&lt;/mn&gt;&lt;mi&gt;b&lt;/mi&gt;&lt;mn&gt;0&lt;/mn&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mn&gt;1&lt;/mn&gt;&lt;msub&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mn&gt;49&lt;/mn&gt;&lt;/msub&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

SFC(49..0)=0b0(1)_{49}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;. According to the specifications, the duplicated counter blocks appear for 250&amp;mu;s once every 4000 years. &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;F&lt;/mi&gt;&lt;mi&gt;C&lt;/mi&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mn&gt;49..0&lt;/mn&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

SFC(49..0)&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; is used, as one of the 51 bits of &lt;em&gt;SFC&lt;/em&gt; is dropped before the counter calculation.&lt;/li&gt;
&lt;li&gt;For HSP/50G-PON: &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;F&lt;/mi&gt;&lt;mi&gt;C&lt;/mi&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mn&gt;47..0&lt;/mn&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mn&gt;0&lt;/mn&gt;&lt;mi&gt;b&lt;/mi&gt;&lt;mn&gt;1&lt;/mn&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mn&gt;0&lt;/mn&gt;&lt;msub&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mn&gt;47&lt;/mn&gt;&lt;/msub&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

SFC(47..0)=0b1(0)_{47}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; and &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;F&lt;/mi&gt;&lt;mi&gt;C&lt;/mi&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mn&gt;47..0&lt;/mn&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mo&gt;=&lt;/mo&gt;&lt;mn&gt;0&lt;/mn&gt;&lt;mi&gt;b&lt;/mi&gt;&lt;mn&gt;0&lt;/mn&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mn&gt;1&lt;/mn&gt;&lt;msub&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;mn&gt;47&lt;/mn&gt;&lt;/msub&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

SFC(47..0)=0b0(1)_{47}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;. According to the specification, the duplicated counter blocks appear for 100&amp;mu;s once every 1000 years. &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;F&lt;/mi&gt;&lt;mi&gt;C&lt;/mi&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mn&gt;47..0&lt;/mn&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

SFC(47..0)&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; is used, as three of the 51 bits of &lt;em&gt;SFC&lt;/em&gt; are dropped before the counter calculation.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;where &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;F&lt;/mi&gt;&lt;mi&gt;C&lt;/mi&gt;&lt;mo stretchy="false"&gt;(&lt;/mo&gt;&lt;mi&gt;x&lt;/mi&gt;&lt;mi mathvariant="normal"&gt;.&lt;/mi&gt;&lt;mi mathvariant="normal"&gt;.&lt;/mi&gt;&lt;mi&gt;y&lt;/mi&gt;&lt;mo stretchy="false"&gt;)&lt;/mo&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

SFC(x..y)&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; represents &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;F&lt;/mi&gt;&lt;mi&gt;C&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

SFC&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;'s bits x to y (included) in that order.
&lt;br&gt;
&lt;br&gt;
To mitigate this issue, the specifications recommend initialising &lt;em&gt;SFC&lt;/em&gt; to a small value.&lt;/br&gt;&lt;/br&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;As for the upstream payloads, GPON does not encrypt them. For XG-PON and above, upstream frames can be encrypted, when they are the operation is very similar to the encryption of downstream frames.&lt;/p&gt;
&lt;p&gt;The main difference is how &lt;em&gt;IFC&lt;/em&gt; is calculated: instead of starting at &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mn&gt;0&lt;/mn&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

0&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;, &lt;em&gt;IFC&lt;/em&gt; starts with a value derived from the &lt;em&gt;StartTime&lt;/em&gt; at which the upstream burst is sent. This way, &lt;em&gt;IFC&lt;/em&gt; is unique for each Alloc-ID.&lt;/p&gt;
&lt;h2 id="reduced-data-encryption-strength-why_1"&gt;Reduced data encryption strength: why?&lt;/h2&gt;
&lt;p&gt;All the ITU-T PON specifications discussed specify the use of data encryption keys with &amp;ldquo;reduced effective length&amp;rdquo;.&lt;/p&gt;
&lt;p&gt;Instead of generating a 128-bit encryption key, an ONU may generate a key of size &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;msub&gt;&lt;mi&gt;L&lt;/mi&gt;&lt;mrow&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;f&lt;/mi&gt;&lt;mi&gt;f&lt;/mi&gt;&lt;/mrow&gt;&lt;/msub&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

L_{eff}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; bits where &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;msub&gt;&lt;mi&gt;L&lt;/mi&gt;&lt;mrow&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;f&lt;/mi&gt;&lt;mi&gt;f&lt;/mi&gt;&lt;/mrow&gt;&lt;/msub&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

L_{eff}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; is a multiple of 8, filling the remaining most significant bytes with &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mn&gt;0&lt;/mn&gt;&lt;mi&gt;x&lt;/mi&gt;&lt;mn&gt;55&lt;/mn&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

0x55&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt;.&lt;/p&gt;
&lt;p&gt;&lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;msub&gt;&lt;mi&gt;L&lt;/mi&gt;&lt;mrow&gt;&lt;mi&gt;e&lt;/mi&gt;&lt;mi&gt;f&lt;/mi&gt;&lt;mi&gt;f&lt;/mi&gt;&lt;/mrow&gt;&lt;/msub&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

L_{eff}&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; can be reported through the OMCI "Enhanced security control" Management Entity and the "Effective key length" attribute, but it is optional.&lt;/p&gt;
&lt;p&gt;While this provision was probably in place to support older devices, it is odd that it is still present in newer specifications that require more capable devices.&lt;/p&gt;
&lt;h2 id="bringing-it-all-together-onu-initialisation-and-key-switching"&gt;Bringing it all together: ONU initialisation and key switching&lt;/h2&gt;
&lt;p&gt;While we have all the bricks to authenticate and encrypt secure channels between ONUs and OLTs, timing is important: some authentication methods are not available right away, keys are renewed regularly (key switching) or must transition from one authentication method to another, etc.&lt;/p&gt;
&lt;p&gt;The diagram below presents the key events of an XG-PON ONU from power-up to the establishment of a secure data channel, highlighting the transitions between authentication schemes. Note that this is a "happy path" scenario; it is designed to demonstrate the integration of the security mechanisms discussed in this post rather than provide an exhaustive state-machine analysis of the full specification. &lt;/p&gt;
&lt;p&gt;On the left of the diagram are represented the approximate ONU and key management states that are used in state-machines in the specification; not all events are displayed and some are simplified.&lt;/p&gt;
&lt;p class="center-text"&gt;
&lt;img src="resources/2026-09-16_overview-of-passive-optical-network-security/xgpon_timeline.svg"/&gt;&lt;br/&gt;
&lt;i&gt;XG-PON timeline for power-up to secure channel&lt;/i&gt;
&lt;/p&gt;
&lt;p&gt;The data encryption key should be regularly regenerated by the ONU on the OLT's request; however, the renewal frequency is at the OLT's discretion. &lt;/p&gt;
&lt;p&gt;During key renewal, all PON specifications implement measures to ensure only valid keys are used and the link is not left broken. For GPON, the OLT simply sends a superframe counter value to the ONU, at which the new key will be used. For XG-PON and above, the process is more complex and involves timers and state machines. While the XG-PON and later specifications mention two ONU timers (the &amp;ldquo;ONU key exchange waiting timer&amp;rdquo; and &amp;ldquo;Key Ack waiting timer&amp;rdquo;), the ITU-T Supplement 81&lt;sup id="fnref2:itutsuppl81"&gt;&lt;a class="footnote-ref" href="#fn:itutsuppl81"&gt;20&lt;/a&gt;&lt;/sup&gt; deprecates them &amp;ldquo;the ONT-side timers are deprecated&amp;rdquo;, leaving timeout management to the OLT.&lt;/p&gt;
&lt;h1 id="conclusion_1"&gt;Conclusion&lt;/h1&gt;
&lt;p&gt;ITU-T PON specifications implement link-level encryption and authentication between OLTs and ONUs to protect against eavesdropping, data theft, and impersonation. However, there are many choices to make and steps to follow, and the specifications do not always have a "secure by default" approach.&lt;/p&gt;
&lt;p&gt;GPON, as the oldest PON specification in this blog post, offers the most limited security: downstream-only encryption and optional OMCI-based authentication. Without OMCI authentication, unicast data encryption keys are transmitted unencrypted to the OLT.&lt;/p&gt;
&lt;p&gt;XG-PON and newer PON specifications (XGS-PON, NG-PON2, 50G-PON) mandate authentication and support bidirectional encryption. However, the &lt;em&gt;Registration ID-based&lt;/em&gt; scheme will use a default null string if not provisioned: while the resulting secure channel will be authenticated and encrypted, it will be based on a known secret, which defeats the purpose of the secure channel. Only the IEEE 801.2X-based scheme with the right EAP mode (such as EAP-TLS with a Diffie-Hellman key exchange) can support Perfect Forward Secrecy (PFS), preventing "harvest now, decrypt later" attacks. &lt;/p&gt;
&lt;p&gt;For all PON versions, encryption is usually disabled by default. Only the OMCI XGEM port is always encrypted in both directions for XG-PON and above.&lt;/p&gt;
&lt;p&gt;Then, a block cipher (usually AES-128) is used in CTR mode for the actual encryption of the (X)GEM payloads. The CTR mode does not provide authentication of the payload, which means an attacker can blindly modify the ciphertext without being detected. AEAD modes, which are the only modes supported by TLS 1.3 for instance, provide both encryption and authentication of the payload simultaneously.&lt;/p&gt;
&lt;p&gt;A somewhat new evolution in the PON specifications is the support of 256-bit block ciphers by the Higher Speed PON (HSP)/50G-PON specifications. 50G-PON now mandates the support of 256-bit keys, and generalises the use of ciphers of this key size. While we do not make any conclusions on the specifications' resilience against quantum cryptography, 256-bit AES keys are recommended by multiple agencies' post-quantum cryptography notes&lt;sup id="fnref:anssipqc"&gt;&lt;a class="footnote-ref" href="#fn:anssipqc"&gt;26&lt;/a&gt;&lt;/sup&gt;&lt;sup id="fnref:enisapqc"&gt;&lt;a class="footnote-ref" href="#fn:enisapqc"&gt;27&lt;/a&gt;&lt;/sup&gt; as a measure against Grover's algorithm. ITU-T Supplement 81&lt;sup id="fnref3:itutsuppl81"&gt;&lt;a class="footnote-ref" href="#fn:itutsuppl81"&gt;20&lt;/a&gt;&lt;/sup&gt; recommends using HMAC-SHA-256 in the OMCI-based authentication scheme for quantum-resistance.&lt;/p&gt;
&lt;p&gt;50G-PON also changes how the unicast data encryption key is generated by including an OLT-generated value. However, the key is still generated on the ONU's side and sent to the OLT, unlike a Diffie-Hellman key exchange for instance, where the shared secret is at least guaranteed to include each sides' secret.&lt;/p&gt;
&lt;p&gt;Moreover, 50G-PON still includes a section relative to "reduced data encryption strength", which has carried on across PON specifications since GPON. It is unclear why such a provision is still necessary when 256-bit keys have been introduced.&lt;/p&gt;
&lt;p&gt;Finally, while we did go through a lot of PON security threats and features, there are other concerns that we did not discuss. The ITU-T specifications and supplements also mention "rogue ONUs", ONUs that do not behave according to the specification, and how to protect against them. Cloned ONUs, attacks against OMCI Management Entities, are other subjects we did not tackle.&lt;/p&gt;
&lt;h2 id="acknowledgments"&gt;Acknowledgments&lt;/h2&gt;
&lt;p&gt;I would like to thank my colleagues Ang&amp;egrave;le Bossuat and C&amp;eacute;lian Gl&amp;eacute;naz for their review, as well as all other reviewers of this blog post!&lt;/p&gt;
&lt;h2 id="further-reading"&gt;Further reading&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="resources/2026-09-16_overview-of-passive-optical-network-security/annex-a-glossary.pdf" target="_blank"&gt;Annex A: Glossary&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="resources/2026-09-16_overview-of-passive-optical-network-security/annex-b-ploam-and-omci-security-related-messages.pdf" target="_blank"&gt;Annex B: PLOAM and OMCI security-related messages&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="resources/2026-09-16_overview-of-passive-optical-network-security/annex-c-contradictory-quotes.pdf" target="_blank"&gt;Annex C: Contradictory specification quotes relative to the derivation of a 256-bit &lt;span class="katex"&gt;&lt;math xmlns="http://www.w3.org/1998/Math/MathML"&gt;&lt;semantics&gt;&lt;mrow&gt;&lt;mi&gt;M&lt;/mi&gt;&lt;mi&gt;S&lt;/mi&gt;&lt;mi&gt;K&lt;/mi&gt;&lt;/mrow&gt;&lt;annotation encoding="application/x-tex"&gt;
\def\pelican{\textrm{pelican}^2}

MSK&lt;/annotation&gt;&lt;/semantics&gt;&lt;/math&gt;&lt;/span&gt; for HMACs with an output size of 256-bit or more&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="references"&gt;References&lt;/h2&gt;
&lt;div class="footnote"&gt;
&lt;hr/&gt;
&lt;ol&gt;
&lt;li id="fn:orange50G"&gt;
&lt;p&gt;R. Rousseau, &amp;ldquo;Avec le 50G-PON, Orange propose une exp&amp;eacute;rience in&amp;eacute;dite en France et d&amp;eacute;montre la prouesse de la fibre du futur,&amp;rdquo; Newsroom Groupe Orange. Available: &lt;a href="https://newsroom.orange.com/?p=60059"&gt;https://newsroom.orange.com/?p=60059&lt;/a&gt;.&amp;nbsp;&lt;a class="footnote-backref" href="#fnref:orange50G" title="Jump back to footnote 1 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:itutG9841"&gt;
&lt;p&gt;&lt;a href="https://handle.itu.int/11.1002/1000/9379"&gt;ITU-T G.984.1 (03/2008) - Gigabit-capable passive optical networks (GPON): General characteristics&lt;/a&gt;&amp;nbsp;&lt;a class="footnote-backref" href="#fnref:itutG9841" title="Jump back to footnote 2 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:itutG9842"&gt;
&lt;p&gt;&lt;a href="https://handle.itu.int/11.1002/1000/14000"&gt;ITU-T G.984.2 (08/2019) - Gigabit-capable Passive Optical Networks (G-PON): Physical Media Dependent (PMD) layer specification&lt;/a&gt;&amp;nbsp;&lt;a class="footnote-backref" href="#fnref:itutG9842" title="Jump back to footnote 3 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:itutG9843"&gt;
&lt;p&gt;&lt;a href="https://handle.itu.int/11.1002/1000/16552"&gt;ITU-T G.984.3 (2014) Amd. 2 (11/2025) - Gigabit-capable passive optical networks (G-PON): Transmission convergence layer specification&lt;/a&gt;&amp;nbsp;&lt;a class="footnote-backref" href="#fnref:itutG9843" title="Jump back to footnote 4 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;a class="footnote-backref" href="#fnref2:itutG9843" title="Jump back to footnote 4 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;a class="footnote-backref" href="#fnref3:itutG9843" title="Jump back to footnote 4 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:itutG9844"&gt;
&lt;p&gt;&lt;a href="https://handle.itu.int/11.1002/1000/9161"&gt;ITU-T G.984.4 (02/2008) - Gigabit-capable passive optical networks (G-PON): ONT management and control interface specification&lt;/a&gt;&amp;nbsp;&lt;a class="footnote-backref" href="#fnref:itutG9844" title="Jump back to footnote 5 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:itutG987"&gt;
&lt;p&gt;&lt;a href="https://handle.itu.int/11.1002/1000/11640"&gt;ITU-T G.987 (06/2012) - 10-Gigabit-capable passive optical network (XG-PON) systems: Definitions, abbreviations and acronyms&lt;/a&gt;&amp;nbsp;&lt;a class="footnote-backref" href="#fnref:itutG987" title="Jump back to footnote 6 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:itutG987.1"&gt;
&lt;p&gt;&lt;a href="https://handle.itu.int/11.1002/1000/14190"&gt;ITU-T G.987.1 (2016) Cor. 1 (03/2020) - 10-Gigabit-capable passive optical networks (XG-PON): General requirements&lt;/a&gt;&amp;nbsp;&lt;a class="footnote-backref" href="#fnref:itutG987.1" title="Jump back to footnote 7 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:itutG987.2"&gt;
&lt;p&gt;&lt;a href="https://handle.itu.int/11.1002/1000/15562"&gt;ITU-T G.987.2 (2023) Amd. 1 (06/2023) - 10-Gigabit-capable passive optical networks (XG-PON): Physical media dependent (PMD) layer specification&lt;/a&gt;&amp;nbsp;&lt;a class="footnote-backref" href="#fnref:itutG987.2" title="Jump back to footnote 8 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:itutG987.3"&gt;
&lt;p&gt;&lt;a href="https://handle.itu.int/11.1002/1000/16337"&gt;ITU-T G.987.3 (05/2025) - 10-Gigabit-capable passive optical networks (XG-PON): Transmission convergence (TC) layer specification&lt;/a&gt;&amp;nbsp;&lt;a class="footnote-backref" href="#fnref:itutG987.3" title="Jump back to footnote 9 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;a class="footnote-backref" href="#fnref2:itutG987.3" title="Jump back to footnote 9 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;a class="footnote-backref" href="#fnref3:itutG987.3" title="Jump back to footnote 9 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;a class="footnote-backref" href="#fnref4:itutG987.3" title="Jump back to footnote 9 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;a class="footnote-backref" href="#fnref5:itutG987.3" title="Jump back to footnote 9 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;a class="footnote-backref" href="#fnref6:itutG987.3" title="Jump back to footnote 9 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;a class="footnote-backref" href="#fnref7:itutG987.3" title="Jump back to footnote 9 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:itutG9807.1"&gt;
&lt;p&gt;&lt;a href="https://handle.itu.int/11.1002/1000/16365"&gt;ITU-T G.9807.1 (2023) Amd. 1 (05/2025) - 10-Gigabit-capable symmetric passive optical network (XGS-PON)&lt;/a&gt;&amp;nbsp;&lt;a class="footnote-backref" href="#fnref:itutG9807.1" title="Jump back to footnote 10 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;a class="footnote-backref" href="#fnref2:itutG9807.1" title="Jump back to footnote 10 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:itutG989"&gt;
&lt;p&gt;&lt;a href="https://handle.itu.int/11.1002/1000/12561"&gt;ITU-T G.989 (10/2015) - 40-Gigabit-capable passive optical networks (NG-PON2): Definitions, abbreviations and acronyms&lt;/a&gt;&amp;nbsp;&lt;a class="footnote-backref" href="#fnref:itutG989" title="Jump back to footnote 11 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:itutG989.1"&gt;
&lt;p&gt;&lt;a href="https://handle.itu.int/11.1002/1000/11810"&gt;ITU-T G.989.1 (03/2013) - 40-Gigabit-capable passive optical networks (NG-PON2): General requirements&lt;/a&gt;&amp;nbsp;&lt;a class="footnote-backref" href="#fnref:itutG989.1" title="Jump back to footnote 12 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:itutG989.2"&gt;
&lt;p&gt;&lt;a href="https://handle.itu.int/11.1002/1000/14492"&gt;ITU-T G.989.2 (2019) Amd. 1 (10/2020) - 40-Gigabit-capable passive optical networks 2 (NG-PON2): Physical media dependent (PMD) layer specification&lt;/a&gt;&amp;nbsp;&lt;a class="footnote-backref" href="#fnref:itutG989.2" title="Jump back to footnote 13 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:itutG989.3"&gt;
&lt;p&gt;&lt;a href="https://handle.itu.int/11.1002/1000/16349"&gt;ITU-T G.989.3 (2021) Amd. 2 (05/2025) - 40-Gigabit-capable passive optical networks (NG-PON2): Transmission convergence layer specification&lt;/a&gt;&amp;nbsp;&lt;a class="footnote-backref" href="#fnref:itutG989.3" title="Jump back to footnote 14 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;a class="footnote-backref" href="#fnref2:itutG989.3" title="Jump back to footnote 14 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;a class="footnote-backref" href="#fnref3:itutG989.3" title="Jump back to footnote 14 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;a class="footnote-backref" href="#fnref4:itutG989.3" title="Jump back to footnote 14 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:itutG988"&gt;
&lt;p&gt;&lt;a href="https://handle.itu.int/11.1002/1000/16348"&gt;ITU-T G.988 (2022) Amd. 2 (05/2025) - ONU management and control interface (OMCI) specification&lt;/a&gt;&amp;nbsp;&lt;a class="footnote-backref" href="#fnref:itutG988" title="Jump back to footnote 15 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;a class="footnote-backref" href="#fnref2:itutG988" title="Jump back to footnote 15 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;a class="footnote-backref" href="#fnref3:itutG988" title="Jump back to footnote 15 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;a class="footnote-backref" href="#fnref4:itutG988" title="Jump back to footnote 15 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:itutG9804.1"&gt;
&lt;p&gt;&lt;a href="https://handle.itu.int/11.1002/1000/16364"&gt;ITU-T G.9804.1 (2019) Amd. 3 (05/2025): Higher speed passive optical networks - Requirements&lt;/a&gt;&amp;nbsp;&lt;a class="footnote-backref" href="#fnref:itutG9804.1" title="Jump back to footnote 16 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:itutG9804.2"&gt;
&lt;p&gt;&lt;a href="https://handle.itu.int/11.1002/1000/16561"&gt;ITU-T G.9804.2 (2021) Amd. 3 (11/2025): Higher speed passive optical networks - Common transmission convergence layer specification&lt;/a&gt;&amp;nbsp;&lt;a class="footnote-backref" href="#fnref:itutG9804.2" title="Jump back to footnote 17 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;a class="footnote-backref" href="#fnref2:itutG9804.2" title="Jump back to footnote 17 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;a class="footnote-backref" href="#fnref3:itutG9804.2" title="Jump back to footnote 17 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;a class="footnote-backref" href="#fnref4:itutG9804.2" title="Jump back to footnote 17 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;a class="footnote-backref" href="#fnref5:itutG9804.2" title="Jump back to footnote 17 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:itutG9804.3"&gt;
&lt;p&gt;&lt;a href="https://handle.itu.int/11.1002/1000/16562"&gt;ITU-T G.9804.3 (2021) Amd. 3 (02/2026): 50-Gigabit-capable passive optical networks (50G-PON): Physical media dependent (PMD) layer specification&lt;/a&gt;&amp;nbsp;&lt;a class="footnote-backref" href="#fnref:itutG9804.3" title="Jump back to footnote 18 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:itutG9805"&gt;
&lt;p&gt;&lt;a href="https://handle.itu.int/11.1002/1000/16563"&gt;ITU-T G.9805 (2022) Amd. 2 (11/2025) : Coexistence of passive optical network systems&lt;/a&gt;&amp;nbsp;&lt;a class="footnote-backref" href="#fnref:itutG9805" title="Jump back to footnote 19 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:itutsuppl81"&gt;
&lt;p&gt;&lt;a href="https://handle.itu.int/11.1002/1000/16570"&gt;G Suppl. 81 (ex G Suppl.PONsec) - Practical aspects of PON security - Revision 1&lt;/a&gt;&amp;nbsp;&lt;a class="footnote-backref" href="#fnref:itutsuppl81" title="Jump back to footnote 20 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;a class="footnote-backref" href="#fnref2:itutsuppl81" title="Jump back to footnote 20 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;a class="footnote-backref" href="#fnref3:itutsuppl81" title="Jump back to footnote 20 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:tripleoxygen"&gt;
&lt;p&gt;&amp;ldquo;GPON - OMCI MIB [O3 Labs].&amp;rdquo; Available: https://www.tripleoxygen.net/wiki/misc/gpon/omci-mib#privados&amp;nbsp;&lt;a class="footnote-backref" href="#fnref:tripleoxygen" title="Jump back to footnote 21 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:nistsp800_38a"&gt;
&lt;p&gt;M. J. Dworkin, &amp;ldquo;Recommendation for block cipher modes of operation : methods and techniques,&amp;rdquo; National Institute of Standards and Technology, Gaithersburg, MD, NIST SP 800-38a, 2001. doi: 10.6028/NIST.SP.800-38a.&amp;nbsp;&lt;a class="footnote-backref" href="#fnref:nistsp800_38a" title="Jump back to footnote 22 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;a class="footnote-backref" href="#fnref2:nistsp800_38a" title="Jump back to footnote 22 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:eap"&gt;
&lt;p&gt;J. Vollbrecht, J. D. Carlson, L. Blunk, B. D. Aboba, and H. Levkowetz, &amp;ldquo;Extensible Authentication Protocol (EAP),&amp;rdquo; Internet Engineering Task Force, Request for Comments RFC 3748, Jun. 2004. doi: 10.17487/RFC3748.&amp;nbsp;&lt;a class="footnote-backref" href="#fnref:eap" title="Jump back to footnote 23 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;a class="footnote-backref" href="#fnref2:eap" title="Jump back to footnote 23 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:eap_gpsk"&gt;
&lt;p&gt;C. Clancy and H. Tschofenig, &amp;ldquo;Extensible Authentication Protocol - Generalized Pre-Shared Key (EAP-GPSK) Method,&amp;rdquo; Internet Engineering Task Force, Request for Comments RFC 5433, Feb. 2009. doi: 10.17487/RFC5433.&amp;nbsp;&lt;a class="footnote-backref" href="#fnref:eap_gpsk" title="Jump back to footnote 24 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:eap_tls"&gt;
&lt;p&gt;D. Simon, R. Hurst, and B. D. Aboba, &amp;ldquo;The EAP-TLS Authentication Protocol,&amp;rdquo; Internet Engineering Task Force, Request for Comments RFC 5216, Mar. 2008. doi: 10.17487/RFC5216.&amp;nbsp;&lt;a class="footnote-backref" href="#fnref:eap_tls" title="Jump back to footnote 25 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:anssipqc"&gt;
&lt;p&gt;&amp;ldquo;ANSSI views on the Post-Quantum Cryptography transition&amp;rdquo;. Available: https://messervices.cyber.gouv.fr/guides/en-anssi-views-post-quantum-cryptography-transition&amp;nbsp;&lt;a class="footnote-backref" href="#fnref:anssipqc" title="Jump back to footnote 26 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:enisapqc"&gt;
&lt;p&gt;&amp;ldquo;Post-Quantum Cryptography: Current state and quantum mitigation | ENISA.&amp;rdquo;. Available: https://www.enisa.europa.eu/publications/post-quantum-cryptography-current-state-and-quantum-mitigation&amp;nbsp;&lt;a class="footnote-backref" href="#fnref:enisapqc" title="Jump back to footnote 27 in the text"&gt;&amp;larrhk;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;</content><category term="Networks"></category><category term="2026"></category><category term="PON"></category><category term="Cryptography"></category><category term="ONU"></category><category term="ONT"></category><category term="OLT"></category><category term="FTTH"></category><category term="FTTx"></category><category term="GPON"></category><category term="XG-PON"></category><category term="XGS-PON"></category><category term="NG-PON2"></category><category term="50G-PON"></category><category term="HSP"></category><category term="IOT"></category></entry></feed>