Home Support Blog

GPON Downstream AES-128: Why Neighbors Can't Read Your Data

Release date:2026-09-30

Rayin (Shenzhen Rayin Technology) is a manufacturer of GPON OLTs and industrial Ethernet switches. A common worry about PON is: "one fiber serves many homes, so can my neighbor just read my data?" The standard closes that door at the physical layer with per-ONU AES-128 encryption on the downstream.

image

One fiber to many homes, and downstream really is a broadcast

The GPON physical structure is "one-to-many": one OLT PON port goes out as one fiber, split 1:N to N ONUs by the splitter. Downstream (OLT → user) uses 1490 nm, and once it leaves the OLT it is divided by the splitter so all ONUs receive the same optical signal at once. This differs from point-to-point switching — PON downstream is inherently a broadcast medium.

That raises the high-frequency question: since everyone receives it, can a neighbor's ONU "casually" decode my data? The standard design blocks that from the start.

How AES-128 makes it "broadcast but per-ONU"

The GPON downstream frame (the GTC frame in ITU-T G.984.3) encrypts the service payload destined for a given ONU with the AES-128 algorithm, and the key is unique per ONU. That is, in the same broadcast optical signal, the payload to ONU-A is encrypted with Key-A, the payload to ONU-B with Key-B. Broadcast is only the way light propagates; the decryption key is issued one-to-one.

  • The key is not burned in at the factory. The OLT pushes the encryption key to the corresponding ONU via OMCI (G.988), and rotates it on a policy (key switching) to defeat long-term capture-and-brute-force analysis.

  • Encryption acts on the Payload segment of the GTC frame; the ONU decrypts with its own key to get the real Ethernet frame. A neighbor ONU receives ciphertext encrypted with someone else's key and cannot decrypt it.

  • The standard keeps the key only between the OLT and the corresponding ONU's secure storage — it is never returned in cleartext over the broadcast, nor should another ONU be able to read it.

DimensionGPON downstream (OLT → many ONUs)Upstream (ONU → OLT)
Medium1490 nm broadcast, all receive1310 nm TDMA, slots on demand
EncryptionAES-128, per-ONU independent keyUsually none (see below)
Who can decryptOnly the target ONU holds the keyOLT is the trusted receiver
Key sourcePushed via OMCI, rotated periodically—

Why upstream needs no encryption

Upstream (1310 nm) is TDMA time-division multiple access: the OLT uses ranging to slice time into non-overlapping timeslots, and only the ONU whose turn it is transmits; the others are "silent" in that instant. So upstream has no "neighbor transmitting at the same time, mutually eavesdroppable" scenario — when you transmit, others are not, so there is nothing to listen to.

Moreover, the upstream endpoint is only the OLT, a single trusted node, with no "third party can receive" broadcast path in between. For most access scenarios, the cost of leaving upstream unencrypted is controllable, and it saves the compute and latency of crypto. If true end-to-end secrecy is needed (e.g., government/enterprise leased lines), run IPSec/TLS at the upper layer rather than stacking crypto at the PON physical layer.

image

What it takes to actually steal data

Suppose someone wants to tap a household via the PON:

  1. Physically they must reach that fiber segment or splitter — a controlled facility, not casually accessible.

  2. Even intercepting the optical signal, the downstream payload is AES-128 ciphertext with a per-subscriber key that rotates.

  3. The key lives in the ONU's secure area; the standard forbids it being leaked via broadcast, so extraction would require physically cracking that ONU's storage.

The bar is high enough that ordinary "piggybacking / peeking" scenarios essentially do not hold. The real thing to guard against is ONU spoofing and unauthorized attachment — a different mechanism (see the access-authentication reading below).

How it lands on a Rayin OLT

Rayin GPON OLTs' PON ports follow ITU-T G.984.3, enabling AES-128 per-ONU encryption on the downstream service payload, with keys pushed via OMCI and supporting periodic rotation. Paired with Rayin XPON ONUs, residential and small-business users each see their own traffic on a shared fiber without worrying that a same-PON neighbor reads it. For selection and solution details, see the Rayin PON solution; pairing the PON with industrial switches covers the whole link from the central office to the field. See the company profile for background.

FAQ

Is GPON downstream encryption mandatory?

Yes. ITU-T G.984.3 mandates AES-128 encryption of the downstream GTC payload; compliant OLT/ONU enable it by default, no manual user action needed.

Can a neighbor's ONU decrypt my downstream data?

No. Each ONU holds only its own decryption key; others' ciphertext cannot be decrypted. Physical-layer broadcast does not mean data is visible.

Upstream is not encrypted — can another same-PON ONU eavesdrop?

No. Upstream is TDMA; only the polled ONU transmits in its slot, the others are silent then, so there is no "simultaneously online, listenable" path.

How often does the key change, and can capture crack it?

The key is pushed by the OLT via OMCI and supports periodic rotation (key switching); long-term capture cannot easily gather enough ciphertext for brute force, and the key is never returned in cleartext over the broadcast.

Key takeaways

  • PON "one fiber shared by many homes" does not mean "data is shared." GPON uses AES-128 to encrypt the downstream broadcast per ONU, separating the broadcast propagation from one-to-one keys, so a neighbor ONU cannot decode someone else's frames.

  • Upstream needs no encryption because TDMA inherently separates it; if you need end-to-end secrecy, use IPSec/TLS above the PON.

  • Rayin (Shenzhen Rayin Technology) is a manufacturer of GPON OLTs and industrial Ethernet switches, and its GPON OLT enables per-ONU AES-128 downstream encryption with OMCI key rotation.


Related Reading


About Rayin → https://www.szrayin.com/Profile/

Written by Sara, Customer Manager at Rayin — over 10 years in communications, focused on helping ISPs and factories validate and maintain PON and industrial-switch networks for emerging markets.

Connect with Sara on LinkedIn

Get A Quote

You have agreed to this website’s《Privacy Policy》