Configuration method and device of optical communication equipment, authentication method and device of optical communication equipment, optical communication equipment and system

CN120419205AActive Publication Date: 2025-08-01HUAWEI TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202480005551.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-09-08
Filing Date
2024-08-20
Publication Date
2025-08-01
Estimated Expiration
2044-08-20

AI Technical Summary

Technical Problem

In a passive optical network, the second optical communication device cannot send data during a silent window, resulting in a large data transmission delay.

Method used

The broadcast message is sent to the plurality of second optical communication devices through the first optical communication device, carrying configuration information to configure the random delay parameters so as to be less than 48 μs, thereby reducing the length of the silent window.

Benefits of technology

The data transmission delay of the certified second optical communication device is reduced and the data transmission efficiency is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120419205A_ABST
    Figure CN120419205A_ABST
Patent Text Reader

Abstract

The invention discloses an optical communication device configuration and authentication method and device, an optical communication device and an optical communication system, and belongs to the technical field of optical communication. The configuration method comprises the following steps: a first optical communication device determines a random time delay parameter, wherein the random time delay parameter is less than 48 [mu] s; and sending a broadcast message to a plurality of second optical communication devices, the broadcast message carrying configuration information, and the configuration information being used for configuring a random time delay parameter. The first optical communication device can flexibly configure the random time delay parameter of the second optical communication device through the broadcast message.
Need to check novelty before this filing date? Find Prior Art

Description

Configuration, authentication method and device of optical communication equipment, optical communication equipment and system

[0001] This application claims priority to Chinese patent application No. 202311164116.4 filed on September 8, 2023, entitled “Configuration, authentication method and device of optical communication equipment, optical communication equipment and system”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of optical communication technology, and in particular to a configuration and authentication method and apparatus for optical communication equipment, as well as optical communication equipment and a system. Background Art

[0003] A passive optical network (PON) is a point-to-multipoint, single-fiber, bidirectional optical access network. A PON system typically includes a first optical communication device, an optical distribution network (ODN), and multiple second optical communication devices. The first optical communication device is connected to the multiple second optical communication devices via the ODN.

[0004] When a second optical communication device comes online, the first optical communication device needs to authenticate the second optical communication device. Only after the second optical communication device has completed authentication can it transmit data with the first optical communication device. Typically, the authentication process for the second optical communication device includes the first optical communication device sending a sequence number request message to the second optical communication device during a silent window; the second optical communication device responds to the received sequence number request message by sending a sequence number response message to the second optical communication device based on a random delay parameter; and the first optical communication device authenticates the second optical communication device based on the sequence number response message.

[0005] The length of the quiet window is greater than the sum of the random delay parameter and the round-trip propagation delay. The random delay parameter defaults to 48μs. When the maximum differential distance between the first optical communication device and the second optical communication device is 20km, the round-trip propagation delay is 200μs. When the maximum differential distance between the first optical communication device and the second optical communication device is 40km, the round-trip propagation delay is 400μs. Therefore, the length of the quiet window is relatively large. Since the second optical communication device that has completed authentication cannot send data during the quiet window, the long quiet window length will result in a large data transmission delay for the second optical communication device.

[0006] Summary of the Invention

[0007] The present application provides a configuration method and apparatus for optical communication equipment, optical communication equipment, and a system, which are conducive to reducing the data transmission delay of a second optical communication device.

[0008] In a first aspect, the present application provides a configuration method for an optical communication device, which may include: a first optical communication device determines a random delay parameter, wherein the random delay parameter is less than 48 μs; the first optical communication device sends a broadcast message to multiple second optical communication devices, wherein the broadcast message carries configuration information, and the configuration information is used to configure the random delay parameter.

[0009] In this application, a first optical communication device can flexibly configure the random delay parameters of a second optical communication device by sending a broadcast message carrying configuration information for configuring the random delay parameters. Furthermore, the random delay parameters configured in the configuration information are less than 48 μs, meaning they are less than the default random delay parameters used in related art. This allows the length of the quiet window to be reduced, given a constant round-trip propagation delay, thereby reducing the data transmission delay of the authenticated second optical communication device.

[0010] Optionally, the first optical communication device may determine the random delay parameter in any one of the following ways:

[0011] Method 1: receiving the input random delay parameter.

[0012] In the first method, the random delay parameter can be directly configured by a staff member, which is simple to implement and requires less changes to the execution logic of the first optical communication device.

[0013] Method 2: Determine the random delay parameter based on the maximum differential distance between the first optical communication device and the plurality of second optical communication devices, wherein the random delay parameter is proportional to the maximum differential distance. Optionally, the maximum differential distance may be received by the first optical communication device, for example, a parameter configured by a staff member via a configuration interface.

[0014] In the second method, since the smaller the maximum differential distance is, the smaller the length of the silent window needs to be set, the default random delay parameter can be converted according to the maximum differential distance, which is simple to calculate and easy to implement.

[0015] Method 3: Determine the random delay parameter based on the remaining bandwidth, where the remaining bandwidth is the bandwidth that is not allocated to the second optical communication device in a bandwidth allocation cycle, wherein the random delay parameter is less than the length of the remaining bandwidth minus the difference between the round-trip propagation delay and the change in the response time of the second optical communication device.

[0016] In this third approach, the remaining bandwidth can be used for windowing to avoid affecting the data transmission of already authenticated second optical communication devices. Furthermore, when the random delay parameter is determined based on the remaining bandwidth, since each authenticated second optical communication device can normally transmit data during each bandwidth allocation cycle, the frequency of windowing can be increased. For example, a window of 1ms or 2ms can be set. This allows for timely detection of newly online second optical communication devices and rapid authentication of these devices.

[0017] In a second aspect, the present application provides a configuration method for an optical communication device. The configuration method includes: a second optical communication device receiving a broadcast message sent by a first optical communication device, the broadcast message carrying configuration information, the configuration information being used to configure a random delay parameter, the random delay parameter being less than 48 μs; and the second optical communication device storing the configuration information.

[0018] In this application, a first optical communication device can flexibly configure the random delay parameters of a second optical communication device by sending a broadcast message carrying configuration information for configuring the random delay parameters. Furthermore, the random delay parameters configured in the configuration information are less than 48 μs, meaning they are less than the default random delay parameters used in related art. This allows the length of the quiet window to be reduced, given a constant round-trip propagation delay, thereby reducing the data transmission delay of the authenticated second optical communication device.

[0019] In a third aspect, the present application provides an authentication method for an optical communication device. The authentication method includes: a first optical communication device sending a broadcast message to multiple second optical communication devices, the broadcast message carrying configuration information, the configuration information being used to configure a random delay parameter, the random delay parameter being less than 48 μs; the first optical communication device sending a sequence number request message to the multiple second optical communication devices; and the first optical communication device receiving a sequence number response message sent by a second optical communication device, the sequence number response message being sent by the second optical communication device based on the random delay parameter configured according to the configuration information.

[0020] Optionally, the first optical communication device sending the sequence number request message to the plurality of second optical communication devices includes: sending the sequence number request message to the plurality of second optical communication devices during a quiet window, where the quiet window is less than 125 μs. A shorter quiet window has a smaller impact on data transmission of the authenticated second optical communication devices.

[0021] Optionally, the length of the silent window is determined based on the maximum differential distance between the first optical communication device and the plurality of second optical communication devices, and the maximum differential distance is less than 12.5 km. Therefore, the method provided in this application is particularly suitable for scenarios where the first optical communication device and the second optical communication device are relatively close.

[0022] In a fourth aspect, the present application provides an authentication method for an optical communication device. The authentication method includes: a second optical communication device receiving a broadcast message sent by a first optical communication device, the broadcast message carrying configuration information, the configuration information being used to configure a random delay parameter, the random delay parameter being less than 48 μs; the second optical communication device receiving a sequence number request message sent by the first optical communication device; and the second optical communication device responding to the sequence number request message by sending a sequence number response message to the first optical communication device based on the random delay parameter.

[0023] In a fifth aspect, the present application provides a method for authenticating an optical communication device, the method comprising:

[0024] The first optical communication device sends a serial number request message to the plurality of second optical communication devices;

[0025] The first optical communication device receives a serial number response message sent by the second optical communication device, where the serial number response message carries a random delay parameter and a serial number of the second optical communication device;

[0026] The first optical communication device authenticates the second optical communication device according to the serial number and the random delay parameter;

[0027] After passing the authentication, the first optical communication device sends a key generation message to the second optical communication device. The key generation message carries key parameters, and the key parameters are used to generate a new key.

[0028] In this application, a first optical communication device can authenticate a second optical communication device using a serial number and random delay parameters sent by the second optical communication device. Furthermore, by sending a key generation message to the second optical communication device, the first optical communication device can facilitate the second optical communication device to generate a new key based on the key parameters in the message. The new key can then be used to encrypt data transmission between the first and second optical communication devices, thereby improving communication security between the first and second optical communication devices.

[0029] In one possible solution, the new key is a key pair, including a sending key and a receiving key.

[0030] In one possible solution, the key generation message carries (includes) the identifier and key parameters of the second optical communication device. After receiving the key generation message carrying the identifier, the second optical communication device generates a new key based on the key parameters to use or replace the old key.

[0031] In a possible solution, the key generation message carries a key index, which may point to the new key.

[0032] In one possible solution, the key parameters include one or more random numbers generated by the first optical communication device. In this application, by using random numbers as key parameters, the security of the generated key can be enhanced.

[0033] In one possible solution, the key generation message carries an integrity check bit, which is used by the second optical communication device to perform integrity verification on the key generation message, thereby enhancing the security of the key generation message. The first optical communication device can use a default integrity key to generate the integrity check bit in a broadcast scenario, or use an integrity key shared between the first optical communication device and the second optical communication device in a unicast scenario.

[0034] In a possible solution, the key generation message carries the key length, indicating the length of the new key (eg, 256 bytes).

[0035] In a possible solution, the first optical communication device starts a first key waiting timer when sending a key generation message to the second optical communication device;

[0036] When the first key waiting timer times out and the first optical communication device has not received a new key reporting message sent by the second optical communication device, the first optical communication device sends a new key generation message to the second optical communication device.

[0037] In a possible solution, after the first optical communication device successfully authenticates the second optical communication device, the first optical communication device is in a key-inactivated state, that is, there is no valid key for service data transmission between the first optical communication device and the second optical communication device.

[0038] In a possible solution, when the first optical communication device determines that a key exchange process needs to be initiated, it enters a key request state. In the key request state, the first optical communication device sends a key generation message to the second optical communication device.

[0039] In one possible solution, the authentication method provided by this application further includes:

[0040] The first optical communication device receives a new key reporting message sent by the second optical communication device. The new key reporting message carries the new key generated by the second optical communication device. Furthermore, the second optical communication device can also obtain the new key generated by the second optical communication device. The first optical communication device can decrypt data sent by the second optical communication device using the new key. The first optical communication device can also send encrypted data to the second optical communication device using the new key, thereby enhancing communication security.

[0041] In a possible solution, after receiving the new key reporting message, the first optical communication device enters the key confirmation state from the current key request state.

[0042] In a possible solution, the new key reporting message includes an identifier of the second optical communication device to identify the source of the new key reporting message.

[0043] In one possible solution, the new key reporting message includes a reporting type (new key reporting or current key reporting). In this embodiment, the reporting type included in the new key reporting message is new key reporting, that is, the second optical communication device reports a generated new key.

[0044] In one possible solution, the new key reporting message includes the new key encrypted with the shared key. The first optical communication device decrypts the new key reporting message using the shared key to obtain the new key carried therein, thereby enhancing the security of the new key transmission and preventing the new key from being leaked.

[0045] In one possible solution, the new key reporting message includes the index of the new key (key index). After obtaining the new key, the first optical communication device saves the corresponding relationship between the new key and the key index so as to subsequently obtain the new key generated by the second optical communication device based on the key index.

[0046] In one possible solution, the new key report message carries an integrity check bit, which is used by the first optical communication device to perform integrity verification on the new key report message, thereby enhancing the security of the new key report message. The first optical communication device can generate the integrity check bit using an integrity key shared between the first optical communication device and the second optical communication device.

[0047] In one possible solution, the above authentication method further includes:

[0048] The first optical communication device sends a key confirmation message to the second optical communication device, wherein the key confirmation message carries the index of the new key and is used to confirm that the first optical communication device has received the new key sent by the second optical communication device.

[0049] In a possible solution, the key confirmation message also carries parameters such as the identifier of the second optical communication device, key length, integrity check bit, etc. The functions of the relevant parameters are consistent with those in the key generation message.

[0050] In a possible solution, after the first optical communication device sends a key confirmation message to the second optical communication device, it enters a key confirmation waiting state from a key confirmation state.

[0051] In one possible solution, the above authentication method further includes:

[0052] The first optical communication device receives a current key report message sent by the second optical communication device, and the first optical communication device enters a key-enabled state. The current key report message carries the key index. Upon receiving the current key report message, the first optical communication device confirms that the second optical communication device has activated the new key corresponding to the key index. The first optical communication device then transitions from a key confirmation wait state to a key-enabled state, activating the new key to communicate with the second optical communication device (e.g., transmit service data).

[0053] In a possible solution, the first optical communication device starts a second key waiting timer when sending a key confirmation message to the second optical communication device;

[0054] When the second key waiting timer times out and the first optical communication device has not received the current key reporting message sent by the second optical communication device, the first optical communication device sends a new key confirmation message to the second optical communication device, thereby avoiding long waiting for the current key reporting message sent by the second optical communication device and improving the reliability of the authentication method.

[0055] In a possible solution, the first optical communication device sending a serial number request message to the plurality of second optical communication devices includes:

[0056] The sequence number request message is sent to the plurality of second optical communication devices in a silent window, wherein the length of the silent window is less than or equal to 250 μs. Sending the sequence number request message in the silent window can avoid affecting the reception of service data by the second optical communication devices and improve communication reliability.

[0057] In a possible solution, before the first optical communication device sends the serial number request message to the plurality of second optical communication devices, the method further includes:

[0058] The first optical communication device sends a broadcast message to the plurality of second optical communication devices, wherein the broadcast message carries configuration profile information. The second optical communication device can construct an uplink data frame based on the configuration information and send it to the first optical communication device.

[0059] In a possible solution, the first optical communication device sending a serial number request message to the plurality of second optical communication devices includes:

[0060] The serial number request message is sent to the plurality of second optical communication devices in a silent window, where the length of the silent window is less than or equal to 250 μs.

[0061] In a sixth aspect, the present application provides a method for authenticating an optical communication device, the method comprising:

[0062] The second optical communication device receives the serial number request message sent by the first optical communication device;

[0063] In response to the serial number request message, the second optical communication device generates a random delay parameter;

[0064] The second optical communication device sends a serial number response message to the first optical communication device according to the random delay parameter, where the serial number response message carries the random delay parameter and the serial number of the second optical communication device;

[0065] The second optical communication device receives a key generation message sent by the first optical communication device, where the key generation message carries key parameters, and the key parameters are used to generate a new key;

[0066] The second optical communication device generates a new key according to the key parameters in the key generation message.

[0067] In the authentication method provided by this application, a second optical communication device can send a sequence number response message to a first optical communication device based on a random delay parameter. Because different second optical communication devices have different random delays, this application can avoid conflicts caused by sequence number response messages sent by multiple second optical communication devices simultaneously reaching the first optical communication device, thereby improving communication stability. Furthermore, the second optical communication device can generate a new key based on a key generation message sent by the first optical communication device. The second optical communication device can then send encrypted data to the second optical communication device based on the new key, thereby improving the security of communications between the second and first optical communication devices.

[0068] In a possible solution, the second optical communication device sending a sequence number response message to the first optical communication device according to the random delay parameter includes:

[0069] The second optical communication device generates a sequence number response message, and sends the sequence number response message to the first optical communication device after a delay corresponding to a random delay parameter is satisfied.

[0070] In a possible solution, after receiving the key generation message, the second optical communication device enters the key generation state from the key disabled state.

[0071] In a possible solution, the second optical communication device generating a new key according to the key parameters in the key generation message includes:

[0072] The second optical communication device generates an intermediate key based on the key parameters and shared key sent by the first optical communication device. It then generates a new key based on the shared key, the intermediate key, and the key parameters generated by the second optical communication device. This solution improves the security of the generated new keys (the sending key and the receiving key) by adding the intermediate key.

[0073] In one possible approach, the key parameter includes a random number.

[0074] In a possible solution, the key generation message received by the second optical communication device also includes a key index. After generating the new key, the second optical communication device may also locally store the corresponding relationship between the generated new key and the key index.

[0075] In one possible solution, the above authentication method further includes:

[0076] The second optical communication device sends a new key reporting message to the first optical communication device, where the key reporting message carries the new key generated by the second optical communication device.

[0077] In a possible solution, the second optical communication device uses the shared key to encrypt the generated new key, and the key reporting message sent by the second optical communication device includes the encrypted new key.

[0078] In a possible solution, after generating the new key, the second optical communication device enters the key confirmation waiting state from the key generation state. In the key confirmation waiting state, the second optical communication device can send the new key reporting message to the first optical communication device.

[0079] In a possible solution, the second optical communication device starts a third key waiting timer when sending the new key reporting message to the first optical communication device;

[0080] When the third key waiting timer times out and the second optical communication device has not received the key confirmation message sent by the first optical communication device, the second optical communication device resends the new key reporting message to the first optical communication device. By setting the key waiting timer, this solution can avoid the second optical communication device from waiting for the key confirmation message for a long time, thereby improving the reliability of the authentication method.

[0081] Among them, the parameters and beneficial effects carried (included) in the new key reporting message sent by the second optical communication device can be referred to the description of the fifth aspect above, and will not be repeated here.

[0082] In a possible solution, the above authentication method further includes: the second optical communication device receives a key confirmation message sent by the first optical communication device and enters a key confirmation state.

[0083] The key confirmation message received by the second optical communication device carries a key index, and the second optical communication device confirms that the first optical communication device has obtained the new key according to the index.

[0084] After receiving the key confirmation message, the second optical communication device may modify the status of the new key to enabled (enable new key).

[0085] In a possible solution, the above authentication method further includes: the second optical communication device sending a current key reporting message to the first optical communication device, and the second optical communication device enters a key activation state.

[0086] In a possible solution, the current key reporting message carries (includes) an identifier of the second optical communication device to identify the source of the new key reporting message.

[0087] In one possible solution, the current key reporting message includes a reporting type (new key reporting or current key reporting). In this embodiment, the reporting type included in the current key reporting message is current key reporting, that is, the second optical communication device reports a currently existing key (different from a new key reported previously).

[0088] In a possible solution, the current key reporting message includes a key index, and the first optical communication device can obtain the new key generated by the second optical communication device according to the key index.

[0089] In one possible solution, the current key report message carries an integrity check bit, which is used by the first optical communication device to perform integrity verification on the current key report message, thereby enhancing the security of the current key report message. The first optical communication device may use an integrity key shared between the first optical communication device and the second optical communication device to generate the integrity check bit.

[0090] In one possible solution, the second optical communication device generates a key name based on the shared key and the new key, and the current key reporting message includes the key name generated by the second optical communication device. For example, the second optical communication device calculates a hash value (Key_Name) based on the shared key and the new key.

[0091] Correspondingly, after receiving the current key report message, the first optical communication device can verify the previously saved new key based on the key name, further enhancing communication security. For example, the first optical communication device can calculate a key name based on the saved new key and determine whether the calculated key name is consistent with the key name carried in the current key report message. If they are consistent, the previously saved new key is correct, and subsequent communications with the second optical communication device can be encrypted using the new key.

[0092] Optionally, in the first to sixth aspects, the broadcast message is a physical layer operation, administration & maintenance (PLOAM) message, and the PLOAM message includes a field for carrying the configuration information; or, the broadcast message is a GPON transmission convergence (GTC) frame or an Ethernet message.

[0093] When the broadcast message is a PLOAM message, the PLOAM message may be an extended burst length message, an upstream overhead configuration message, or an extended optical network unit (ONU) configuration message. Using existing or newly added PLOAM messages to carry the configuration information reduces protocol changes and facilitates implementation.

[0094] When the broadcast message is a GTC frame, the GTC frame may be a downlink synchronization frame. Optionally, the configuration information may be carried in a frame header or a payload portion of the GTC frame.

[0095] Optionally, the key generation message is a Key_Control(Generate) PLOAM message, the new key reporting message is a Key_Report(Newkey) PLOAM message, the key confirmation message is a Key_Control(Confirm) PLOAM message, and the current key reporting message is a Key_Report(Existingkey) PLOAM message.

[0096] In the first to sixth aspects, the first optical communication device and the second optical communication device are both devices in an optical access network. For example, the first optical communication device is an optical line terminal (OLT) in a PON system, and the second optical communication device is an ONU in the PON system. In another example, the first optical communication device is a master fiber to the room (FTTR), and the second optical communication device is a slave FTTR. Here, the master FTTR refers to the master ONU in the FTTR scenario, also known as the master gateway; the slave FTTR refers to the slave ONU in the FTTR scenario, also known as the slave gateway.

[0097] In a seventh aspect, the present application provides a configuration device for an optical communication device. The configuration device for an optical communication device has the function of implementing the method described in the first aspect or any optional embodiment of the first aspect. The function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more units corresponding to the above-mentioned functions.

[0098] In an eighth aspect, the present application provides a configuration device for an optical communication device. The configuration device for an optical communication device has the function of implementing the method described in the second aspect or any optional embodiment of the second aspect. The function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more units corresponding to the above-mentioned functions.

[0099] In a ninth aspect, embodiments of the present application provide an authentication device for optical communication equipment. The authentication device for optical communication equipment has the function of implementing the method described in the third aspect or any optional embodiment of the third aspect. The function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more units corresponding to the above-mentioned functions.

[0100] In a tenth aspect, embodiments of the present application provide an authentication device for an optical communication device. The authentication device for an optical communication device has the function of implementing the method described in the fourth aspect or any optional embodiment of the fourth aspect. The function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more units corresponding to the above-mentioned functions.

[0101] In an eleventh aspect, an optical communication device is provided. The optical communication device includes a processor and a memory. The memory is used to store software programs and modules. The processor implements the method of the first aspect or any possible implementation of the first aspect by running or executing the software programs and / or modules stored in the memory, or implements the method of the second aspect or any possible implementation of the second aspect; or implements the method of the third aspect or any possible implementation of the third aspect; or implements the method of the fourth aspect or any possible implementation of the fourth aspect; or implements the method of the fifth aspect or any possible implementation of the fifth aspect; or implements the method of the sixth aspect or any possible implementation of the sixth aspect.

[0102] Optionally, there are one or more processors and one or more memories.

[0103] Optionally, the memory may be integrated with the processor, or the memory may be provided separately from the processor.

[0104] In the specific implementation process, the memory can be a non-transitory memory, such as a read-only memory (ROM), which can be integrated on the same chip as the processor or be set on different chips. This application does not limit the type of memory and the setting method of the memory and the processor.

[0105] In a twelfth aspect, a computer program product is provided. The computer program product includes computer program code, which, when executed by a computer, causes the computer to execute the method of the first aspect or any possible implementation of the first aspect, or the method of the second aspect or any possible implementation of the second aspect; or the method of the third aspect or any possible implementation of the third aspect; or the method of the fourth aspect or any possible implementation of the fourth aspect; or the method of the fifth aspect or any possible implementation of the fifth aspect; or the method of the sixth aspect or any possible implementation of the sixth aspect.

[0106] In the thirteenth aspect, the present application provides a computer-readable storage medium, which is used to store program code executed by a processor, and the program code includes instructions for implementing the method in any possible implementation of the above-mentioned first aspect, or implementing the method in the above-mentioned second aspect or any possible implementation of the second aspect; or implementing the method in the above-mentioned third aspect or any possible implementation of the third aspect; or implementing the method in the above-mentioned fourth aspect or any possible implementation of the fourth aspect; or implementing the method in the above-mentioned fifth aspect or any possible implementation of the fifth aspect; or implementing the method in the above-mentioned sixth aspect or any possible implementation of the sixth aspect.

[0107] In the fourteenth aspect, the present application provides a chip comprising a processor, the processor being configured to call and execute instructions stored in a memory from a memory, so that an optical communication device equipped with the chip executes a method in any possible implementation of the first aspect above, or executes a method in any possible implementation of the second aspect above; or executes a method in any possible implementation of the third aspect above or the third aspect; or executes a method in any possible implementation of the fourth aspect above or the fourth aspect; or implements a method in any possible implementation of the fifth aspect or the fifth aspect; or implements a method in any possible implementation of the sixth aspect or the sixth aspect.

[0108] In a fifteenth aspect, the present application provides another chip. The other chip includes an input interface, an output interface, a processor, and a memory. The input interface, the output interface, the processor, and the memory are connected via an internal connection path. The processor is used to execute the code in the memory. When the code is executed, the processor is used to execute the method in any possible implementation of the first aspect above, or to execute the method in any possible implementation of the second aspect above or the second aspect; or to execute the method in any possible implementation of the third aspect above or the third aspect; or to execute the method in any possible implementation of the fourth aspect above or the fourth aspect; or to implement the method in any possible implementation of the fifth aspect or the fifth aspect; or to implement the method in any possible implementation of the sixth aspect or the sixth aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0109] FIG1 is a schematic structural diagram of a PON system provided in an embodiment of the present application;

[0110] FIG2 is a schematic diagram of a configuration method for an optical communication device provided in an embodiment of the present application;

[0111] FIG3 is a schematic diagram of another configuration method for optical communication equipment provided in an embodiment of the present application;

[0112] FIG4 is a schematic diagram of a data transmission process in a PON system provided by an embodiment of the present application;

[0113] FIG5 is a schematic diagram of an authentication method for an optical communication device provided in an embodiment of the present application;

[0114] FIG6 is a block diagram of a configuration device for an optical communication device provided in an embodiment of the present application;

[0115] FIG7 is a block diagram of another configuration device for optical communication equipment provided in an embodiment of the present application;

[0116] FIG8 is a block diagram of an authentication device for an optical communication device provided in an embodiment of the present application;

[0117] FIG9 is a block diagram of another authentication device for optical communication equipment provided in an embodiment of the present application;

[0118] FIG10 is a schematic structural diagram of an optical communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0119] In order to make the objectives, technical solutions and advantages of this application clearer, the implementation methods of this application will be further described in detail below with reference to the accompanying drawings.

[0120] Figure 1 is a schematic diagram of a PON system provided by an embodiment of the present application. As shown in Figure 1, the PON system includes a first optical communication device 110, a second optical communication device 120, and an optical network device (ODN) 130. The first optical communication device 110 is connected to one or more second optical communication devices 120 via the ODN 130. Both the first optical communication device 110 and the second optical communication device 120 are devices in an optical access network.

[0121] For example, the first optical communication device is an OLT, and the second optical communication device is an ONU. Another example is the first optical communication device being the master FTTR, and the second being the slave FTTR. Here, the master FTTR refers to the master ONU in an FTTR scenario, also known as the master gateway; the slave FTTR refers to the slave ONU in an FTTR scenario, also known as the slave gateway. The master FTTR is typically installed in the living room or at a doorway information box. In addition to providing standard ONU network functions, it also manages other ONUs in the home, such as configuration synchronization and channel optimization.

[0122] In the embodiment of the present application, the ONU may also be referred to as an optical network terminal (ONT).

[0123] The first optical communication device 110 is typically located on the network side, such as a central office (CO), and can centrally manage multiple second optical communication devices 120. The first optical communication device 110 can act as an intermediary between the second optical communication devices 120 and an upper-layer network (not shown), forwarding data received from the upper-layer network to the second optical communication device 120 and vice versa. The upper-layer network includes, but is not limited to, the Internet, the public switched telephone network (PSTN), and the community antenna television (CATV).

[0124] Multiple second optical communication devices 120 can be distributedly arranged at the user side. The second optical communication devices 120 can be network devices used to communicate with the first optical communication device 110 and the user equipment. The second optical communication devices 120 can act as an intermediary between the first optical communication device 110 and the user equipment. For example, the second optical communication devices 120 can forward data received from the first optical communication device 110 to the user equipment, and forward data received from the user equipment to the first optical communication device 110.

[0125] ODN 130 is a data distribution / multiplexing system that can include trunk optical fibers, passive optical splitters, and user optical fibers. The passive optical splitters can include a first port and multiple second ports. The first port of the passive optical splitter is connected to a first optical communication device 110 via a trunk optical fiber, and each second port of the passive optical splitter is connected to a second optical communication device 120 via a user optical fiber.

[0126] In a PON system, downlink data flows from a first optical communication device 110 to a second optical communication device 120. The first optical communication device 110 broadcasts downlink data to all second optical communication devices 120, and each second optical communication device 120 receives only data with its own identifier. Conversely, uplink data flows from a second optical communication device 120 to the first optical communication device 110. The first optical communication device 110 allocates time slots to each second optical communication device 120, and each second optical communication device 120 transmits uplink data according to the time slots allocated by the first optical communication device 110. The allocation of time slots by the first optical communication device 110 to each second optical communication device 120 can be called bandwidth allocation or bandwidth authorization.

[0127] In an embodiment of the present application, the first optical communication device 110 is configured to send a broadcast message to the second optical communication device 120 to configure a random delay parameter for the second optical communication device 120. After receiving the broadcast message, the second optical communication device 120 determines the random delay parameter based on the received broadcast message and sends a sequence number response message based on the random delay parameter. For details, see the method embodiment below.

[0128] In the embodiments of the present application, the PON system includes but is not limited to gigabit PON (Gigabit-capable PON, GPON), 10 gigabit per second PON (10 gigabit per second PON, XG-PON), 10-gigabit-capable symmetric passive optical network (10-gigabit-capable symmetric passive optical network, XGS-PON), Ethernet PON (Ethernet PON, EPON), 10 gigabit per second EPON (10 gigabit per second EPON, 10G-EPON), 25 gigabit per second PON (25 gigabit per second PON, 25G-PON), 50 gigabit per second PON (50 gigabit per second PON, 50G-PON), 100 gigabit per second PON (100G-PON), 25 gigabit per second EPON (25 gigabit per second EPON, 25G-EPON), 50 gigabit per second EPON (50G-PON), EPON, 50G-EPON), and other speed GPON, EPON, etc.

[0129] Figure 2 is a flow chart of a configuration method for optical communication equipment provided in an embodiment of the present application. As shown in Figure 2, the method includes the following steps.

[0130] S201: The first optical communication device determines a random delay parameter.

[0131] The random delay parameter is less than 48 μs. In related art, the random delay parameter defaults to 48 μs.

[0132] S202: The first optical communication device sends a broadcast message to multiple second optical communication devices, where the broadcast message carries configuration information, and the configuration information is used to configure a random delay parameter.

[0133] Correspondingly, the second optical communication device receives the broadcast message sent by the first optical communication device.

[0134] S203: The second optical communication device obtains and saves configuration information from the received broadcast message.

[0135] In this way, the second optical communication device can send a response message, such as a sequence number response message, according to the random delay parameter corresponding to the configuration information.

[0136] In this embodiment of the present application, the first optical communication device can send a broadcast message carrying configuration information for configuring a random delay parameter. Therefore, the random delay parameter of the second optical communication device can be flexibly configured as needed. Furthermore, if the random delay parameter configured in the configuration information is less than 48 μs, the length of the quiet window can be reduced while the round-trip propagation delay remains unchanged, thereby reducing the data transmission delay of the authenticated second optical communication device. When the round-trip propagation delay is reduced, the length of the quiet window can be further reduced, also reducing the data transmission delay of the authenticated second optical communication device.

[0137] In some embodiments, the method is performed in a scenario where the maximum differential distance between the first optical communication device and the plurality of second optical communication devices is less than 20 km. When the maximum differential distance between the first optical communication device and the plurality of second optical communication devices is small, it is usually necessary to reduce the length of the silent window in order to improve the transmission performance of the second optical communication device. Therefore, the random delay parameters can be configured using the method in Figure 2. For campus networks or FTTR scenarios, the communication distances between each second optical communication device and the first optical communication device are relatively small, and accordingly, the maximum differential distance is also relatively small. For example, in a campus network scenario, the maximum communication distance between the first optical communication device and the plurality of second optical communication devices is typically less than 10 km. In an FTTR scenario, the maximum communication distance between the first optical communication device and the plurality of second optical communication devices is less than 5 km, and typically less than 1 km.

[0138] In the embodiments of the present application, the communication distance between the second optical communication device and the first optical communication device may refer to the length of the optical fiber connecting the second optical communication device and the first optical communication device. The differential distance, also known as the fiber differential distance, may refer to the difference in communication distances between any two second optical communication devices and the first optical communication device. The maximum differential distance refers to the difference between the maximum and minimum communication distances between the first optical communication device and each of the second optical communication devices.

[0139] In a possible implementation, the configuration information is an index value corresponding to the random delay parameter. Different values ​​of the random delay parameter correspond to different index values.

[0140] In some examples, several random delay parameter point values ​​can be spaced apart within the range of 0 to 48 μs, with each random delay parameter point value corresponding to an index value. The intervals between adjacent random delay parameter point values ​​can be equal or unequal. In this manner, fewer bits can be used to indicate the random delay parameter.

[0141] For example, 10 μs, 20 μs, 30 μs, and 40 μs may be selected as random delay parameter point values, corresponding to index values ​​00, 01, 10, and 11, respectively. In this way, only 2 bits are needed to indicate the random delay parameter.

[0142] In other examples, more random delay parameter point values ​​may be arranged within the range of 0 to 48 μs, and this application does not impose any restrictions on this. The number of random delay parameter point values ​​is related to the number of bearer bits of the configuration information (i.e., the bits used to indicate the random delay parameter). For example, if the number of bearer bits of the configuration information is n, then the number of random delay parameter point values ​​is less than or equal to 2 to the power of n.

[0143] In another possible implementation, the configuration information is directly the value of the random delay parameter. In this case, there are more possibilities for configuring the random delay parameter, even up to the order of 0.1 μs, for example, 2.1 μs, 3.8 μs, etc.

[0144] In the following, an example will be given in which the first optical communication device is an OLT and the second optical communication device is an ONU. It will be appreciated by those skilled in the art that the OLT in the following may also be a master FTTR and the ONU may also be a slave FTTR.

[0145] Figure 3 is a flow chart of a configuration method for optical communication equipment provided in an embodiment of the present application. As shown in Figure 3, the method includes the following steps.

[0146] S301: The OLT receives a random delay parameter.

[0147] For example, the OLT receives random delay parameters entered through the configuration interface. These parameters are set by staff based on the PON system's networking requirements. For example, they may be determined based on the maximum differential distance between the OLT and multiple ONUs. Directly configuring these parameters by staff simplifies implementation and requires minimal changes to the OLT's execution logic.

[0148] Alternatively, in other embodiments, the OLT may also determine the random delay parameter in the following two ways.

[0149] The first method is to determine a random delay parameter based on the maximum differential distance between the OLT and multiple ONUs. The random delay parameter is proportional to the maximum differential distance. In some examples, the maximum differential distance can be received by the OLT through a configuration interface. The operator inputs this maximum differential distance into the OLT based on the PON system's networking configuration.

[0150] In some examples, the OLT determines the random delay parameter as the product of a default random delay parameter (i.e., 48 μs) and a first ratio value. For example, the first ratio value may be equal to the ratio of the maximum differential distance to 20 km. Assuming the maximum differential distance is 2 km, the first ratio value is equal to 0.1, and the random delay parameter is 4.8 μs.

[0151] In the first method, since the smaller the maximum differential distance is, the smaller the length of the silent window needs to be set, the default random delay parameter can be converted according to the maximum differential distance, which is simple to calculate and easy to implement.

[0152] The second method determines the random delay parameter based on the remaining bandwidth. The remaining bandwidth is the bandwidth not allocated to the ONU during a bandwidth allocation cycle. The random delay parameter is less than the remaining bandwidth minus the difference between the round-trip propagation delay and the change in ONU response time.

[0153] Exemplarily, one bandwidth allocation period is 125 μs.

[0154] Assuming the allocated bandwidth is 85 μs, the remaining bandwidth is 40 μs. If the maximum differential distance is 1 km, the corresponding round-trip propagation delay is 10 μs, and the ONU response variation is 2 μs, then the random delay parameter is less than or equal to 28 μs.

[0155] Exemplarily, the OLT may determine the remaining bandwidth by first determining the allocated bandwidth in each bandwidth allocation cycle based on the bandwidth of each authenticated ONU connected to the OLT; and then determining the remaining bandwidth as the difference between the bandwidth allocation cycle and the allocated bandwidth. The allocated bandwidth is equal to the sum of the bandwidths of each authenticated ONU. The bandwidth of each authenticated ONU can be obtained based on the contract information of each authenticated ONU. Based on this contract information, the time slot length required to be allocated to each ONU in each bandwidth allocation cycle can be determined.

[0156] Figure 4 is a schematic diagram of the data transmission process in a PON system provided by an embodiment of the present application. As shown in Figure 4, ONU1 and ONU2 are authenticated ONUs. In each bandwidth allocation period (i.e., 125 μs), upstream bandwidth is allocated to both ONU1 and ONU2. ONU1 sends data 1 within the allocated upstream bandwidth, and ONU2 sends data 2 within the allocated upstream bandwidth. ONUx is a newly powered-on ONU. ONUx sends a sequence number response message X within the silent window. As can be seen from Figure 4, the silent window is less than 125 μs in length and falls within the remaining bandwidth, which does not affect data transmission between ONU1 and ONU2.

[0157] This second approach allows for windowing using the remaining bandwidth, avoiding impacts on data transmission by already authenticated ONUs. Furthermore, when the random delay parameter is determined based on the remaining bandwidth, since each authenticated ONU can transmit data normally during each bandwidth allocation cycle, the frequency of windowing can be increased. For example, a window of 1ms or 2ms can be set. This allows for timely detection and rapid authentication of newly online ONUs.

[0158] S302: The OLT sends a broadcast message to multiple ONUs.

[0159] In some examples, the broadcast message may be a PLOAM message.

[0160] In a possible implementation, a field for carrying the configuration information may be added to an existing PLOAM message.

[0161] Optionally, the existing PLOAM message may be an extended burst length message or an upstream overhead configuration (upstream_overhead) message.

[0162] The formats of these two PLOAM messages are described below.

[0163] Table 1 Format of the extended burst length message

[0164] As shown in Table 1, the extended burst length message includes 12 bytes, of which the fifth byte is used to carry the random delay parameter. Bytes 6-12 are reserved bytes. In other words, the fifth byte is a field used to carry the configuration information. In other embodiments, other reserved bytes may also be used to carry the random delay parameter.

[0165] When the extended burst length message is used to carry the configuration information, the number of bits used to carry the configuration information is relatively large, so the configuration information may be the index value corresponding to the aforementioned random delay parameter, or the configuration information may directly be the value of the random parameter delay.

[0166] Table 2 upstream_overhead message format

[0167] As shown in Table 2, the upstream_overhead message consists of 12 bytes, with some bits in the 10th byte reserved. Therefore, the reserved bits can be used to carry configuration information. In other words, the 10th byte is the field used to carry this configuration information. Because the number of bits available for carrying configuration information in this method is relatively small, this configuration information can be the index value corresponding to the aforementioned random delay parameter.

[0168] In another possible implementation, a new PLOAM message may be added, and the new PLOAM message includes a field for carrying the configuration information. Exemplarily, the new PLOAM message may be called an extended ONU configuration message.

[0169] Table 3 Format of the extended ONU config message

[0170] As shown in Table 3, the newly added PLOAM message includes 12 bytes. The first byte is used to indicate that the message type is a broadcast message sent to all ONUs. The second byte is used to indicate that the message identifier of the message is an extended ONU configuration message. The third byte is used to carry the random delay parameter. Bytes 4-12 are reserved bytes. In other words, the third byte is a field used to carry this configuration information. In other embodiments, other reserved bytes may also be used to carry the random delay parameter.

[0171] When the newly added PLOAM message is used to carry the configuration information, the number of bits used to carry the configuration information is relatively large, so the configuration information can be the index value corresponding to the aforementioned random delay parameter, or the configuration information can directly be the value of the random parameter delay.

[0172] In other examples, the broadcast message may be a GTC frame. In this case, the PON system to which the OLT and ONU belong may be a GPON system of various rates. GTC frames include, but are not limited to, downlink synchronization frames (DS frames with valid PSync). Optionally, the configuration information may be carried in the frame header or payload field of the GTC frame.

[0173] In some other examples, the broadcast message is an Ethernet message. In this case, the PON system to which the OLT and the ONU belong is an EPON system of various rates.

[0174] Correspondingly, the ONU receives the broadcast message sent by the OLT.

[0175] S303: The ONU obtains and saves configuration information from the received broadcast message.

[0176] Figure 5 is a flow chart of an optical communication device authentication method provided in an embodiment of the present application. As shown in Figure 5, the method includes the following steps.

[0177] S501: The OLT sends a broadcast message.

[0178] The broadcast message carries configuration information for configuring a random delay parameter, which is less than 48 μs. The broadcast message is a PLOAM message. The relevant content of the PLOAM message is described in the embodiment shown in FIG3 and is not further described here. The method for the OLT to obtain the random delay parameter is described in the embodiment shown in FIG3 and is not further described here.

[0179] S502: The OLT sends a sequence number request message to multiple ONUs.

[0180] Correspondingly, the first ONU receives the sequence number request message.

[0181] Optionally, the OLT sends a sequence number request message to the ONU in a silent window. In the silent window, the authenticated ONU cannot send upstream data.

[0182] Optionally, the length of the silent window is less than 125 μs. The shorter the silent window, the less impact it has on data transmission of authenticated ONUs. Compared to the typical 250 μs in related art, reducing the silent window length to less than 125 μs can significantly reduce the impact on data transmission of authenticated ONUs.

[0183] The length of the silent window is determined by the maximum differential distance between the OLT and multiple ONUs. When the silent window length is less than 125μs, the maximum differential distance between the OLT and ONUs is less than 12.5km. This is because, according to the standard, when the maximum differential distance between the OLT and ONU is 20km, the corresponding round-trip propagation delay is 200μs. Assuming that the 125μs is the round-trip propagation delay, the corresponding maximum differential distance is 12.5km. Since the length of the silent window is equal to the sum of the round-trip propagation delay, the variation in the ONU response time (default is 2μs), and the random delay parameter, when the silent window length is 125μs, the maximum differential distance between the OLT and ONUs is less than 12.5km.

[0184] In some embodiments, the length of the silent window is less than 48 μs, for example, greater than or equal to 4 μs and less than 48 μs. In this way, the impact on the data transmission of the authenticated ONU can be further reduced.

[0185] S503: The first ONU responds to the sequence number request message and sends a sequence number response message to the OLT according to the random delay parameter.

[0186] The first ONU is any ONU that receives the serial number request message.

[0187] In S503, the first ONU selects a random number within the random delay parameter as a target delay value, and sends a sequence number response message after delaying by the target delay value. Different ONUs are less likely to determine the same target delay value. Therefore, the OLT is less likely to receive sequence number response messages sent by different ONUs at the same time, thereby reducing conflicts between sequence number response messages sent by different ONUs.

[0188] The sequence number response message carries the sequence number of the first ONU. Accordingly, the OLT receives the sequence number response message.

[0189] S504: The OLT authenticates the first ONU according to the received sequence number response message.

[0190] The sequence number in the sequence number response message is compared with the sequence number of the first ONU stored in advance. If the sequence number in the sequence number response message is different from the sequence number of the first ONU stored in advance, the first ONU cannot pass the authentication. If the sequence number in the sequence number response message is identical to the sequence number of the first ONU stored in advance, subsequent authentication process is carried out. Subsequent authentication process includes ranging process, etc., and specific process can be referred to related art.

[0191] In this embodiment, if the ONU successfully executes the subsequent authentication process, the ONU enters the operational state. When entering the operational state, there is no key between the ONU and the OLT that can be used to encrypt the payload, and both the OLT and the ONU are in a key-inactive state. The authentication method provided in this embodiment also includes the following steps:

[0192] S505: The OLT sends a key generation message to the ONU, which carries a key index and key parameters.

[0193] In this embodiment, the OLT can enter the key requesting state from the key unavailable state. The OLT in the key requesting state can send a key generation message to the ONU in the key unavailable state, which carries a key index and key parameters. In addition, the OLT can also start the key waiting timer 1.

[0194] Specifically, a channel termination (CT) module in the OLT may send a PLOAM message to the ONU, such as a Key_Control (Generate) PLOAM message.

[0195] In this embodiment, the Key_Control(Generate) PLOMA message sent by the OLT carries the index of the new key and the random number R1 generated by the OLT. When the OLT sends the PLOMA message to the ONU, it starts the key waiting timer 2.

[0196] S506: The ONU generates a new key according to the key generation message.

[0197] In this embodiment, the ONU in the key-inactive state enters the key-generating state after receiving the key-generating message sent by the OLT. When entering the key-generating state, the ONU may start the key-waiting timer 4.

[0198] In the key generation state, the ONU generates a new key according to the key generation message. For example, the ONU generates a new key (which may include a sending key and a receiving key) according to the random number R1 in the PLOAM message and a random number R2 generated by itself.

[0199] S507: The ONU sends a new key reporting message to the OLT, which carries the new key generated by the ONU.

[0200] In this embodiment, the ONU can send a PLOAM message to the OLT to send the new key. For example, the ONU sends a key report (new key) Key_Report (Newkey) PLOAM message to the OLT. After the ONU sends the Key_Report (Newkey) PLOAM message to the OLT, the ONU enters the key confirmation wait state and starts the key wait timer 5.

[0201] The new key can be encrypted using a shared key between the OLT and the ONU, i.e., the Key_Report(Newkey) PLOAM message carries the new key encrypted with the shared key. After receiving the encrypted new key, the OLT can decrypt it using the shared key to obtain the new key.

[0202] After receiving the Key_Report(Newkey) PLOAM message, the OLT enters the Key Confirmation state from the current Key Request state and executes step S508. If the OLT's local Key Wait Timer 2 times out and the OLT has not received the Key_Report(Newkey) PLOAM message, the OLT again initiates a Key_Control(Generate) PLOAM message to the ONU.

[0203] S508: The OLT saves the new key generated by the ONU and carried in the new key reporting message.

[0204] After receiving the new key reporting message, the OLT may decrypt the Key_Report (Newkey) PLOAM message (eg, using a shared key to decrypt), obtain the new key carried therein, and then save the corresponding relationship between the decrypted new key and the key index.

[0205] S509: The OLT sends a key confirmation message to the ONU, which carries the key index.

[0206] The OLT may send a PLOAM message, such as a Key_Control(Confirm) PLOAM message, to the ONU to confirm that the new key has been received. After sending the Key_Control(Confirm) PLOAM message to the ONU, the OLT may start a key waiting timer 3.

[0207] After receiving the Key_Control (Confirm) PLOAM message sent by the OLT, the ONU enters the key confirmation state from the key confirmation waiting state.

[0208] If the ONU has not received the Key_Control(Confirm)PLOAM message sent by the OLT when the Key Wait Timer 5 times out, the ONU executes step S507 and resends the Key_Report(Newkey)PLOAM message. If the ONU receives a new Key_Control(Generate)PLOAM message, the ONU executes step S507 again and resends the Key_Report(Newkey)PLOAM message to the OLT.

[0209] S510: The ONU modifies the status of the new key and sends a current key reporting message to the OLT.

[0210] The ONU changes the state of the new key from the unused state to the enabled state and then sends a Key_Report(Existingkey) PLOAM message to the OLT. After the ONU sends the Key_Report(Existingkey) PLOAM message, the ONU enters the key enabled state from the key confirmation state, completing the new key activation process.

[0211] Correspondingly, after receiving the Key_Report (Existingkey) PLOAM message, the OLT enters the Key-Enabled state. The payload in subsequent downstream physical frames sent to the ONU will be encrypted using the new key. Furthermore, if the OLT has not received the Key_Report (Existingkey) PLOAM message before Key Wait Timer 3 expires, the OLT sends a new Key_Control (Confirm) PLOAM message to the ONU to confirm the new key.

[0212] In the present embodiment, by setting timers (key wait timers 1, 2, 3, 4, and 5) at the OLT and the ONU, it is possible to avoid the above-mentioned authentication process from being in a long wait, thereby improving the efficiency of authentication. In addition, the OLT can flexibly set the duration of the key wait timer 1 to control the total time of the above-mentioned key-enabled process. That is, before the OLT is in the key-enabled state, if the key wait timer 1 times out, the OLT enters the key-unenabled state and restarts the above-mentioned step S505. Correspondingly, the ONU can also flexibly set the duration of the key wait timer 4 to control the total time of the above-mentioned key-enabled process. That is, before the ONU is in the key-enabled state, if the key wait timer 4 times out, the ONU enters the key-unenabled state, waits for receiving the key generation message sent by the OLT, and then restarts the above-mentioned step S506.

[0213] In the authentication method provided in this embodiment, the new key can be used for communication between the ONU and the OLT. That is, the data transmission and reception processes between the OLT and the ONU can be encrypted or decrypted using the new key, thereby improving the security of communication between the ONU and the OLT.

[0214] In the authentication method provided in this embodiment, the ONU can first generate an intermediate key based on the random number R1 sent by the OLT and the shared key. Then, the intermediate key, the shared key, and the random number R2 generated by the ONU itself are used to generate a new key. By adding the intermediate key, the security of the generated new keys (the sending key and the receiving key) can be improved.

[0215] In the authentication method provided in this embodiment, the current key report message sent by the ONU can include a key name generated by the ONU based on the new key, allowing the OLT to verify the local key based on this key name. For example, the OLT calculates a key name (Key_name) based on the key stored in step S508. If the key name calculated by the OLT matches the key name in the current key report message, the key verification is successful. The OLT performs encrypted communication with the ONU based on the locally stored key. For example, Key_Name = AES_CMAC(Shared Key, New Key | 0x33313431353932363533353839373933, 128).

[0216] Figure 6 is a block diagram of a configuration device for optical communication equipment provided in an embodiment of the present application. This configuration device can be implemented as all or part of an optical communication device (e.g., an OLT or a master FTTR) through software, hardware, or a combination of both. As shown in Figure 6 , the configuration device 600 includes a determining unit 601 and a sending unit 602.

[0217] The determining unit 601 is configured to determine a random delay parameter, the random delay parameter being less than 48 μs. The sending unit 602 is configured to send a broadcast message to multiple second optical communication devices, the broadcast message carrying configuration information, the configuration information being used to configure the random delay parameter.

[0218] Optionally, the determining unit 601 is configured to determine the random delay parameter in any one of the following ways:

[0219] An input random delay parameter is received; or the random delay parameter is determined based on a maximum differential distance between the first optical communication device and a plurality of second optical communication devices, wherein the random delay parameter is proportional to the maximum differential distance; or the random delay parameter is determined based on a residual bandwidth, wherein the residual bandwidth is a bandwidth that is not allocated to the second optical communication device in a bandwidth allocation cycle, wherein the random delay parameter is less than a difference between a length of the residual bandwidth minus a round-trip propagation delay and a change in a response time of the second optical communication device.

[0220] Figure 7 is a block diagram of a configuration device for optical communication equipment provided in an embodiment of the present application. This configuration device can be implemented as all or part of an optical communication device (e.g., an ONU or slave FTTR) through software, hardware, or a combination of both. As shown in Figure 7 , the configuration device 700 includes a receiving unit 701 and a storage unit 702.

[0221] The receiving unit 701 is used to receive a broadcast message sent by a first optical communication device, the broadcast message carrying configuration information, the configuration information being used to configure a random delay parameter, the random delay parameter being less than 48 μs. The storage unit 702 is used to store the configuration information.

[0222] It should be noted that the configuration apparatus for optical communication equipment provided in the above embodiments only uses the division of the above-mentioned functional units as an example to illustrate the configuration of the optical communication equipment. In actual applications, the above-mentioned functions can be assigned to different functional units as needed, that is, the internal structure of the equipment can be divided into different functional units to complete all or part of the functions described above. In addition, the configuration apparatus for optical communication equipment provided in the above embodiments and the configuration method embodiment of optical communication equipment are based on the same concept. The specific implementation process is detailed in the method embodiment and will not be repeated here.

[0223] Figure 8 is a block diagram of an optical communication device authentication apparatus provided in an embodiment of the present application. This configuration apparatus can be implemented as all or part of an optical communication device (e.g., an OLT or a master FTTR) through software, hardware, or a combination of both. As shown in Figure 8 , the authentication apparatus 800 includes a transmitting unit 801 and a receiving unit 802.

[0224] The sending unit 801 is configured to send a broadcast message to multiple second optical communication devices, the broadcast message carrying configuration information, the configuration information being used to configure a random delay parameter, the random delay parameter being less than 48 μs; and to send a sequence number request message to the multiple second optical communication devices. The receiving unit 802 is configured to receive a sequence number response message sent by the second optical communication device, the sequence number response message being sent by the second optical communication device based on the random delay parameter configured in the configuration information.

[0225] Figure 9 is a block diagram of an optical communication device authentication device 900 provided in an embodiment of the present application. This device can be implemented as all or part of an optical communication device (e.g., an ONU or slave FTTR) through software, hardware, or a combination of both. As shown in Figure 9, the authentication device 900 includes a receiving unit 901 and a sending unit 902.

[0226] The receiving unit 901 is configured to receive a broadcast message sent by a first optical communication device, the broadcast message carrying configuration information used to configure a random delay parameter, the random delay parameter being less than 48 μs, and receive a sequence number request message sent by the first optical communication device. The sending unit 902 is configured to respond to the sequence number request message and send a sequence number response message to the first optical communication device based on the random delay parameter.

[0227] It should be noted that the authentication apparatus for optical communication equipment provided in the above embodiments only uses the division of the aforementioned functional units as an example for authenticating optical communication equipment. In actual applications, the aforementioned functions can be assigned to different functional units as needed, i.e., the internal structure of the equipment can be divided into different functional units to perform all or part of the functions described above. Furthermore, the authentication apparatus for optical communication equipment provided in the above embodiments and the authentication method for optical communication equipment provided in the above embodiments are based on the same concept. The specific implementation process is detailed in the method embodiments and will not be further described here.

[0228] The descriptions of the processes corresponding to the above figures have different focuses. For parts that are not described in detail in a certain process, please refer to the relevant descriptions of other processes.

[0229] FIG10 is a schematic diagram of the structure of an optical communication device 1000 provided in an embodiment of the present application. As shown in FIG10 , the optical communication device 1000 includes at least one processor 1001 , a memory 1002 , and at least one network interface 1003 .

[0230] The processor 1001 is, for example, a general-purpose central processing unit (CPU), a network processor (NP), a graphics processing unit (GPU), a neural-network processing unit (NPU), a data processing unit (DPU), a microprocessor, or one or more integrated circuits for implementing the solution of the present application. For example, the processor 1001 includes an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The PLD is, for example, a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.

[0231] The memory 1002 is, for example, a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, an optical disc storage (including a compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. Optionally, the memory 1002 exists independently and is connected to the processor 1001 via the internal connection 1004. Alternatively, the memory 1002 and the processor 1001 are optionally integrated together.

[0232] The network interface 1003 uses any transceiver-like device for communicating with other devices or communication networks. For example, the network interface 1003 includes at least one of a wired network interface and a wireless network interface. For example, the wired network interface is an Ethernet interface. For example, the Ethernet interface is an optical interface, an electrical interface, or a combination thereof. For example, the wireless network interface is a wireless local area network (WLAN) interface, a cellular network interface, or a combination thereof.

[0233] In some embodiments, processor 1001 includes one or more CPUs, such as CPU0 and CPU1 shown in FIG. 10 .

[0234] In some embodiments, the optical communication device 1000 may optionally include multiple processors, such as processor 1001 and processor 1005 shown in FIG10 . Each of these processors may be, for example, a single-core processor (single-CPU) or a multi-core processor (multi-CPU). A processor herein may optionally refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).

[0235] In some embodiments, optical communication device 1000 further includes internal connections 1004. Processor 1001, memory 1002, and at least one network interface 1003 are connected via internal connections 1004. Internal connections 1004 include pathways that transmit information between the aforementioned components. Optionally, internal connections 1004 are boards or buses. Optionally, internal connections 1004 are divided into address buses, data buses, control buses, and the like.

[0236] In some embodiments, the optical communication device 1000 further includes an input / output interface 1006 . The input / output interface 1006 is connected to the internal connection 1004 .

[0237] In some embodiments, the input / output interface 1006 is configured to connect to an input device and receive commands or data related to the above method embodiments, such as random delay parameters or maximum differential distance, inputted by a user through the input device. Input devices include, but are not limited to, a keyboard, a touch screen, a microphone, a mouse, or a sensor device.

[0238] In some embodiments, the input / output interface 1006 is further configured to connect to an output device. The input / output interface 1006 outputs intermediate and / or final results, such as random delay parameters, generated by the processor 1001 executing the above method embodiments via the output device. Output devices include, but are not limited to, displays, printers, projectors, and the like.

[0239] Optionally, the processor 1001 implements the method in the above embodiment by reading the program code 1010 stored in the memory 1002, or the processor 1001 implements the method in the above embodiment by using the program code stored internally. In the case where the processor 1001 implements the method in the above embodiment by reading the program code 1010 stored in the memory 1002, the memory 1002 stores the program code that implements the method provided in the embodiment of the present application.

[0240] For more details on how the processor 1001 implements the above functions, please refer to the descriptions in the previous method embodiments, which will not be repeated here.

[0241] In some embodiments, a computer-readable storage medium is also provided, which stores computer instructions. When the computer instructions stored in the computer-readable storage medium are executed by an optical communication device, the optical communication device executes the configuration method of the optical communication device or the authentication method of the optical communication device provided in the above method embodiment.

[0242] In some embodiments, a computer program product is also provided, which includes one or more computer program instructions. When the computer program instructions are loaded and run by a computer, the computer executes the configuration method of the optical communication device or the authentication method of the optical communication device provided in the above method embodiment.

[0243] In some embodiments, a chip is also provided, including a memory and a processor, wherein the memory is used to store computer instructions, and the processor is used to call and run the computer instructions from the memory to execute the configuration method of the optical communication device or the authentication method of the optical communication device provided in the above method embodiment.

[0244] Unless otherwise defined, the technical or scientific terms used herein shall have the usual meaning understood by persons of ordinary skill in the field to which this application belongs. The words “first”, “second”, “third” and similar terms used in the patent application specification and claims of this application do not indicate any order, quantity or importance, but are only used to distinguish different components. Similarly, words such as “a” or “an” do not indicate a quantitative limitation, but rather indicate the presence of at least one. Words such as “include” or “comprising” and similar words mean that the elements or objects appearing before “include” or “comprising” cover the elements or objects listed after “include” or “comprising” and their equivalents, and do not exclude other elements or objects.

[0245] The above is only one embodiment of the present application and is not intended to limit the present application. The scope of protection of the present application shall be subject to the scope of protection of the claims.

Claims

1. A method for authenticating an optical communication device, characterized in that: The method comprises: The first optical communication device sends a serial number request message to the plurality of second optical communication devices; The first optical communication device receives a sequence number response message sent by the second optical communication device, where the sequence number response message carries a random delay parameter and a sequence number of the second optical communication device; The first optical communication device authenticates the second optical communication device according to the serial number and the random delay parameter; After passing the authentication, the first optical communication device sends a key generation message to the second optical communication device, wherein the key generation message carries key parameters, and the key parameters are used to generate a new key.

2. The method according to claim 1, characterized in that Also includes: The first optical communication device receives a new key reporting message sent by the second optical communication device, where the key reporting message carries the new key generated by the second optical communication device.

3. The method according to claim 1, characterized in that When the first optical communication device sends a key generation message to the second optical communication device, the first optical communication device starts a first key waiting timer; When the first key waiting timer times out and the first optical communication device has not received a new key reporting message sent by the second optical communication device, the first optical communication device sends a new key generation message to the second optical communication device.

4. The method according to claim 1, characterized in that: Also includes: When receiving the new key reporting message, the first optical communication device enters the key confirmation state from the key request state.

5. The method according to claim 1, characterized in that Also includes: The first optical communication device sends a key confirmation message to the second optical communication device, where the key confirmation message carries the index of the new key.

6. The method according to claim 5, characterized in that Also includes: The first optical communication device receives the current key reporting message sent by the second optical communication device, and the first optical communication device enters a key enabling state.

7. The method according to claim 5, characterized in that When the first optical communication device sends a key confirmation message to the second optical communication device, a second key waiting timer is started; When the second key waiting timer times out and the first optical communication device has not received a current key reporting message sent by the second optical communication device, the first optical communication device sends a new key confirmation message to the second optical communication device.

8. The method according to claim 1, characterized in that The first optical communication device sends a sequence number request message to the plurality of second optical communication devices, comprising: sending the sequence number request message to the plurality of second optical communication devices in a silent window, wherein the length of the silent window is less than or equal to 250 μs.

9. The method according to claim 1, characterized in that: Before the first optical communication device sends a serial number request message to the plurality of second optical communication devices, the method further includes: The first optical communication device sends a broadcast message to the plurality of second optical communication devices, wherein the broadcast message carries configuration information.

10. The method according to claim 9, characterized in that The broadcast message is a physical layer operation management and maintenance PLOAM message, and the PLOAM message includes a field for carrying the configuration information; Alternatively, the broadcast message is a Gigabit Passive Optical Network Transmission Convergence GTC frame or an Ethernet message.

11. The method according to claim 10, characterized in that The PLOAM message is an extended burst length message, an upstream_overhead configuration message, or an extended optical network unit ONU configuration message.

12. A method for authenticating an optical communication device, characterized in that: The method comprises: The second optical communication device receives the serial number request message sent by the first optical communication device; In response to the sequence number request message, the second optical communication device generates a random delay parameter; The second optical communication device sends a sequence number response message to the first optical communication device according to the random delay parameter, wherein the sequence number response message carries the random delay parameter and the sequence number of the second optical communication device; The second optical communication device receives a key generation message sent by the first optical communication device, wherein the key generation message carries a key parameter, and the key parameter is used to generate a new key; The second optical communication device generates a new key according to the key parameters in the key generation message.

13. The method according to claim 12, characterized in that Also includes: The second optical communication device sends a new key reporting message to the first optical communication device, where the key reporting message carries the new key generated by the second optical communication device.

14. The method according to claim 13, characterized in that When the second optical communication device sends the new key reporting message to the first optical communication device, the second optical communication device starts a third key waiting timer; When the third key waiting timer times out and the second optical communication device does not receive the key confirmation message sent by the first optical communication device, the second optical communication device sends the new key reporting message to the first optical communication device again.

15. The method according to claim 12, characterized in that Also includes: The second optical communication device receives the key confirmation message sent by the first optical communication device and enters a key confirmation state.

16. The method according to claim 15, characterized in that Also includes: The second optical communication device sends a current key reporting message to the first optical communication device, and the second optical communication device enters a key enabling state.

17. The method according to claim 12, characterized in that The second optical communication device generates a new key according to the key parameter in the key generation message, comprising: The second optical communication device generates a new key according to the random number in the key generation message.

18. The method according to claim 13, characterized in that The new key carried in the key reporting message is encrypted using a shared key between the second optical communication device and the first optical communication device.

19. An optical communication device, characterized in that: The optical communication device includes a processor and a memory, the memory is used to store a software program, and the processor runs or executes the software program stored in the memory so that the optical communication device implements the method according to any one of claims 1 to 11, or implements the method according to any one of claims 12 to 18.

20. A computer-readable storage medium, characterized in that: The computer-readable storage medium is used to store program codes executed by a processor, wherein the program codes include instructions for implementing the method according to any one of claims 1 to 11, or implementing the method according to any one of claims 12 to 18.

Citation Information

Patent Citations

  • Method and device for encrypting broadcast message

    CN106817352A

  • Secure communication method and device in passive optical network

    CN114302264A

  • Authentication method and device of optical network unit, electronic equipment and storage medium

    CN116405807A

  • Hybrid ranging using an out of band signal in optical networks

    US9048946B1