AODF access device integrated with encryption function, diverse management method and storage medium

By integrating encryption into the AODF access device, the compatibility issues of accessing and managing devices from multiple vendors in fiber optic communication networks are resolved. This achieves standardized access and high-security management, reduces integration and maintenance costs, and provides high flexibility and scalability.

CN120856451APending Publication Date: 2025-10-28ZHONGSHAN XINTONG COMM CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511210889.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-27
Publication Date
2025-10-28

AI Technical Summary

Technical Problem

The lack of a unified AODF equipment access standard in existing fiber optic communication networks leads to differences in physical interfaces, communication protocols, and data formats among different manufacturers' equipment. This necessitates the development of a customized upper-level management platform, resulting in poor system compatibility and the formation of 'information silos'.

Method used

An AODF access device with integrated encryption function is provided, including a main control and southbound adaptation module, a northbound secure communication module and a unified data management module. Through protocol conversion and data normalization, it realizes standardized, secure and transparent access and management of AODF devices from multiple manufacturers and models.

Benefits of technology

It enables plug-and-play and hybrid networking of devices from multiple vendors, breaks down 'information silos', improves the security and compatibility of network management, significantly reduces integration and maintenance costs, and has high flexibility and scalability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120856451A_ABST
    Figure CN120856451A_ABST
Patent Text Reader

Abstract

The invention discloses AODF access equipment integrated with an encryption function, a diverse management method and a storage medium, and belongs to the technical field of optical fiber communication equipment access management. The equipment comprises a master control and southbound adaptation module, a northbound security communication module and a unified data management and forwarding module. Wherein the master control and southbound adaptation module adapts and unifies private protocols and data formats of AODF equipment of different manufacturers through a pluggable protocol driver library and a data normal form engine; an IPSec encryption tunnel is established between the northbound security communication module and an upper management platform, so that the data transmission security is ensured; the unified data management and forwarding module is responsible for routing data and instructions between the south module and the north module. According to the scheme, the technical problems that heterogeneous AODF equipment is difficult to access, poor in compatibility and lack of safety guarantee due to different protocols are solved, and safe, standardized and low-cost unified access management of equipment of multiple manufacturers is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of optical network communication access and security management technology. Specifically, it relates to an AODF access device with integrated encryption function, various management methods, and storage media. Background Technology

[0002] With the rapid development of information technology and the in-depth advancement of the "new infrastructure" strategy, fiber optic communication networks, as the cornerstone of the modern information superhighway, are growing in scale and complexity at an unprecedented rate. Within the infrastructure of fiber optic networks, optical distribution units (ODFs) undertake core functions such as cable termination, fiber optic splicing, fiber core allocation, and line management, serving as key nodes to ensure the connectivity, flexibility, and reliability of network physical links. To adapt to the development needs of automated and intelligent network operation and maintenance, intelligent optical distribution units (AODFs) integrating status monitoring and remote management functions have emerged. Through built-in electronic units, they achieve real-time acquisition and reporting of port connection status, greatly improving the efficiency and accuracy of network resource management.

[0003] In the current construction and operation and maintenance of optical communication networks, the application of AODF (Optical Optical Fiber Reflectometer) devices has become increasingly widespread. Numerous equipment suppliers in the market have launched AODF products with varying specifications and functions to meet the needs of different application scenarios (such as data centers, telecom equipment rooms, and access networks). These products differ significantly in port density, functional integration (e.g., some devices integrate an Optical Time Domain Reflectometer (OTDR) module), and physical form. During deployment, these AODF devices are typically connected to an upper-layer network management system or dedicated gateway through their communication interfaces. The management system is responsible for collecting the status data reported by each device, thereby achieving centralized monitoring and scheduling of the entire network's physical optical paths. This deployment method, to a certain extent, achieves automated management of the fiber optic physical layer, providing technical support for quickly locating line faults and optimizing resource allocation.

[0004] However, with the large-scale deployment of AODF devices in networks, the inherent limitations of existing management models based on each vendor's proprietary architecture are becoming increasingly apparent. The fundamental reason lies in the lack of a unified AODF device access technology standard in the industry, leading to significant technical barriers at the access layer for products from different vendors. This inconsistency manifests itself in several ways: First, at the physical interface level, the communication interfaces of devices from different vendors differ in connector types and sizes; second, at the communication protocol level, multiple protocols such as Modbus, UDP, and MQTT coexist, and even when using the same protocol, different vendors have different implementation methods and data definitions; third, at the data format level, the data structures for status information, alarm information, and other data reported by devices vary. This fragmented access method necessitates that upper-layer management platforms develop specialized protocol and data adaptations for each vendor's devices, resulting in poor system compatibility and severely hindering the interconnection of devices from different brands within the same network environment.

[0005] Therefore, how to solve the problem of "difficult access and management" of heterogeneous AODF devices caused by the lack of unified standards, break through the "information silos" formed by the isolation of the technical systems of various manufacturers, and design a universal solution that can shield the differences of underlying devices and realize standardized, transparent access and management of AODF devices from multiple manufacturers and models has become a technical problem that needs to be tackled by those skilled in the art in promoting the intelligent operation and maintenance of optical networks. Summary of the Invention

[0006] The technical problem this invention aims to solve is to overcome the technical barrier of "information silos" caused by the lack of a unified access standard for intelligent optical distribution equipment (AODF) in the existing technology. This leads to significant differences in physical interfaces, communication protocols, and data formats among devices from different manufacturers, requiring targeted development of upper-layer management platforms, resulting in poor system compatibility, high integration costs, and ultimately, the formation of such silos. To address this, this invention provides an AODF access device with integrated encryption functions and various management methods. It aims to achieve standardized, secure, transparent access and centralized management of heterogeneous AODF devices from multiple manufacturers and models by constructing a standard middleware with protocol conversion, data standardization, and security encryption capabilities.

[0007] To achieve the above-mentioned objectives, the present invention provides a technical solution: an AODF access device with integrated encryption function, the device comprising: a power module, a main control and southbound adaptation module, a northbound secure communication module, and a unified data management and forwarding module.

[0008] The main control and southbound adaptation module serves as the core control hub of the device. Southbound, it handles communication and protocol adaptation with various heterogeneous AODF devices, while northbound, it interacts with other modules within the device. The module's input receives data reported from AODF devices from different vendors via its physical interface (e.g., a Gigabit Ethernet port). This data may follow various protocols such as Modbus, proprietary UDP, or MQTT, and the data formats may differ. Its output transmits a unified data model, processed through protocol parsing and data format standardization, to the unified data management and forwarding module.

[0009] The northbound secure communication module establishes a highly reliable encrypted data transmission channel between the access device and the upper-layer network management system or central gateway. This module receives data intended for transmission to the upper-layer platform from the unified data management and forwarding module and encrypts it. Simultaneously, it receives encrypted command data from the upper-layer platform, decrypts it, and then transmits it to the unified data management and forwarding module. This process is completely transparent to the application logic of the AODF device and the upper-layer management platform.

[0010] The unified data management and forwarding module is the core data processing unit of this invention. Its function is to receive standardized data from the main control and southbound adaptation modules, cache and log it, and forward it to the northbound secure communication module according to a preset routing strategy. Conversely, it also receives decrypted instructions from the northbound secure communication module and forwards them to the main control and southbound adaptation modules, which then convert them into a protocol and instruction format recognizable by the specific AODF device. This module is crucial for realizing the north-south data flow.

[0011] The power module's function is to provide a continuous and reliable power supply for the stable operation of the entire connected device. This module converts the externally input AC or DC power into DC power of a specific voltage level required by the various electronic components inside the device, and has overvoltage, overcurrent, and short-circuit protection functions to ensure that the device can still operate safely in complex power grid environments.

[0012] Furthermore, the main control and southbound adaptation module specifically includes: a multi-protocol physical interface, a pluggable protocol adaptation driver library, and a data paradigm engine.

[0013] A multi-protocol physical interface is used for physically connecting different AODF devices. This interface is preferably an RJ45 Ethernet interface supporting 10 / 100 / 1000Mbps adaptive rates to ensure compatibility with the network connection methods of current mainstream AODF devices. In another embodiment, this interface can also be a pluggable optical module interface (SFP) to accommodate fiber optic direct connection applications.

[0014] A pluggable protocol adapter driver library is the core component for achieving compatibility with heterogeneous devices. This module pre-loads or dynamically loads dedicated protocol drivers for different manufacturers and models of AODF devices via the network. For example, for devices from manufacturer A, its dedicated Modbus-TCP driver is loaded; for devices from manufacturer B, its proprietary UDP-based message parsing driver is loaded. When an AODF device is connected, the system can automatically identify its model and load the corresponding driver through a handshake protocol or preset configuration. This modular, pluggable design allows for support of future AODF device models by adding new drivers without modifying the core system, providing extremely high scalability.

[0015] The data normalization engine's function is to uniformly transform the diverse data parsed from different protocol adapter drivers into a predefined, vendor-independent internal standard data model. For example, vendor A reports port connection status via binary bitmaps, while vendor B reports via JSON format {"port_id": 10, "link_status": "up"}. The engine will uniformly convert both into a standardized internal structure, such as an object containing standard fields like device ID, chassis number, port number, connection status, and timestamp. This normalization lays the foundation for unified management by upper-layer applications.

[0016] In a preferred embodiment of the present invention, the northbound secure communication module is implemented based on IPSec VPN technology to provide end-to-end security protection at the network layer. This module specifically includes: an IPSec processing engine, a key exchange and authentication unit, and a security policy database.

[0017] The IPSec processing engine is responsible for executing the Encapsulated Security Payload (ESP) protocol within the IPSec protocol suite. This engine captures all IP packets destined for the upper-layer management platform, encrypts the packet payload using a pre-shared key or a session key negotiated with a digital certificate, appends an authentication header, and finally generates an encrypted ESP packet for transmission.

[0018] The key exchange and authentication unit is responsible for implementing the Internet Key Exchange (IKEv1 or IKEv2) protocol. It is used to automatically negotiate a Security Association (SA) between the access device and the central VPN security gateway, generating and refreshing the keys required for encryption and authentication. Optionally, this unit connects to the main control module via a separate USB authentication interface. The main control module stores digital certificates or credentials used for authentication. Before establishing a VPN tunnel, it provides identity information to the security module through this USB interface, achieving tight coupling authentication between the device and security functions.

[0019] The security policy database stores security policies that define which data streams need to be encrypted, what encryption algorithms (such as AES-256) are used, what authentication algorithms (such as SHA-256) are used, and the peer VPN gateway address. In another embodiment, the northbound secure communication module can also be implemented based on the Transport Layer Security (TLS) protocol, establishing a secure TLS connection between the local device and the upper-layer platform, suitable for application layer data stream encryption scenarios.

[0020] Specifically, the core hardware platform of this invention is supported by a main control unit and a southbound adapter module, preferably using a high-performance, low-power embedded system-on-a-chip (SoC), such as Rockchip's RK3568. This platform is equipped with a large-capacity DDR memory (e.g., 4GB) and eMMC flash memory (e.g., 16GB). The large-capacity DDR memory supports the operating system, concurrently processes data streams from multiple southbound AODF devices, and provides ample runtime space for the protocol adapter driver and data paradigm engine. The large-capacity eMMC flash memory is used to permanently store the embedded operating system, protocol adapter driver library, security policy configuration, and cache up to 30 days of historical data and operation logs according to business needs. To ensure high system reliability, the hardware platform also features a specially designed hardware watchdog circuit and routes the SoC's hardware reset signal to a physical button, enabling rapid, uninterrupted recovery in the event of a system crash. Furthermore, the platform also provides a standard debug serial port (e.g., a DB9 interface converted from RS-232 level) and a USB interface for firmware burning, greatly facilitating device development, debugging, and on-site maintenance.

[0021] To achieve the aforementioned objectives, another technical solution provided by this invention is: an AODF diversity management method integrating encryption functionality. This method closely corresponds to the aforementioned device and includes the following steps: Step S1: Device Initialization and Configuration Loading. After the connected device is powered on, the power module supplies power to each unit, the main control module starts the embedded operating system, and loads the system configuration from the internal eMMC flash memory, including the list of supported AODF devices, the corresponding protocol adapter drivers, the northbound secure communication policy, and the data management rules.

[0022] Step S2: Establish a northbound secure channel. Based on the loaded policy, the northbound secure communication module actively or passively initiates IKE negotiation with the VPN security gateway of the upper-layer management platform to complete two-way authentication and key exchange, successfully establishing an IPSec VPN tunnel. Thereafter, all northbound and southbound business data will be transmitted through this encrypted tunnel.

[0023] Step S3: Dynamic Access and Adaptation of Southbound Devices. When an AODF device connects to the device via an Ethernet port, the main controller and the southbound adaptation module identify the manufacturer and model of the AODF through a preset discovery protocol (such as LLDP) or based on static configuration. Subsequently, the corresponding driver is called and run from the protocol adaptation driver library.

[0024] Step S4: Uplink Data Acquisition, Conversion, and Secure Forwarding. The southbound adapter driver actively collects data from AODF according to a specific vendor's protocol (such as Modbus polling) or passively receives data reported by it. The data normalization engine converts the received raw data into a unified internal standard data model. The unified data management and forwarding module caches and records the normalized data, and then forwards it to the northbound secure communication module, which encrypts the data and sends it to the upper-layer management platform through an established VPN tunnel.

[0025] Step S5: Downlink Command Reception, Conversion, and Precise Distribution. Management commands issued by the upper-layer platform (such as querying specific port status, modifying device configuration, etc.) are encrypted and transmitted to this device via a VPN tunnel. The northbound secure communication module receives and decrypts the commands, then hands them over to the unified data management and forwarding module. This module forwards the standardized commands to the corresponding main control and southbound adapter module instances based on the target device information in the commands. The protocol adapter driver then translates the standard commands into a private protocol command format that the specific AODF device can recognize, and precisely distributes them through the physical interface.

[0026] Step S6: Device Status Monitoring and Maintenance. The device continuously monitors its own operating status, including CPU load, memory usage, VPN connection status, etc., and supports log querying, configuration updates, and firmware upgrades through the reserved debugging serial port or a secure remote management channel.

[0027] The present invention also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements all the steps of the aforementioned method.

[0028] The present invention also provides a computer program product, including instructions that, when executed on a computer, cause the computer to perform all the steps of the aforementioned method.

[0029] Compared with the prior art, the present invention has the following beneficial effects: Standardized access and high compatibility: This invention, through innovative southbound protocol adaptation and data paradigmization mechanisms, shields the implementation differences of underlying heterogeneous AODF devices, providing a unified and standardized northbound interface for the upper-layer management platform. This fundamentally solves the problem of "difficult access" for devices from multiple vendors, breaks down "information silos," and enables plug-and-play devices and hybrid networking.

[0030] Built-in end-to-end security: By integrating the IPSec VPN security module, this invention builds an encrypted communication tunnel with the management platform at the access layer, realizing two-way identity authentication, data confidentiality and integrity protection at the network layer, which greatly improves the security of optical network infrastructure management and makes up for the shortcomings of existing AODF devices that generally lack native security capabilities.

[0031] Significantly reduces integration and maintenance costs: The upper-layer management platform only needs to develop the interface logic with the access device of this invention once to manage all AODFs accessed through this device, eliminating the need for repeated protocol adaptation development for each new device. This greatly shortens the integration cycle and reduces the cost and complexity of development and long-term maintenance.

[0032] Excellent flexibility and scalability: The pluggable protocol adapter driver architecture makes it easy and quick to support new AODF models. Only a new driver plugin needs to be developed and loaded, without any changes to the hardware or core software, ensuring the long-term viability of the solution and its adaptability to future technologies. Attached Figure Description

[0033] Figure 1 This is a schematic diagram of the application environment of an AODF access device with integrated encryption function in one embodiment of the present invention.

[0034] Figure 2 This is a block diagram of the module structure of an AODF access device integrating encryption function in one embodiment of the present invention.

[0035] Figure 3 yes Figure 2 A specific structural block diagram of the main control module and the southbound adapter module.

[0036] Figure 4 This is a flowchart of an AODF diversity management method integrating encryption function in one embodiment of the present invention.

[0037] Figure 5 This is a schematic diagram of signaling interaction for data uplink processing in one embodiment of the present invention.

[0038] Figure 6 This is a circuit diagram of the access device integrating security encryption according to the present invention. Detailed Implementation

[0039] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of the embodiments of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0040] Please see Figure 1 , Figure 2 and Figure 6 This invention provides an AODF access device with integrated encryption functionality, aiming to overcome the problems of poor compatibility, high integration costs, and "information silos" caused by the lack of a unified intelligent fiber distribution equipment (AODF) access standard in existing technologies. This invention achieves standardized, secure, transparent access and centralized management of heterogeneous AODF devices from multiple vendors and models by constructing a standard middleware device with protocol conversion, data paradigming, and secure encryption capabilities. Logically, the device includes: a main control and southbound adaptation module, a northbound secure communication module, a unified data management and forwarding module, and a power supply module. These four modules work together to form a complete bridge connecting the underlying AODF devices and the upper-level management platform.

[0041] Specifically, the core function of the main control and southbound adaptation module is to act as the core control hub of the device. Southbound, it is responsible for communication connections and protocol adaptation with various heterogeneous AODF devices, while northbound, it interacts with other modules within the device. The module's input receives reported data from AODF devices from different manufacturers through its physical interface. This data may follow various protocols such as Modbus, proprietary UDP, or MQTT, and the data formats may differ. Its output transmits a unified data model, after protocol parsing and data format standardization, to the unified data management and forwarding module.

[0042] The function of the northbound secure communication module is to establish a highly reliable encrypted data transmission channel between the access device and the upper-layer network management system or central gateway. It receives data intended for transmission to the upper-layer platform from the unified data management and forwarding module and encrypts it. Simultaneously, this module also receives encrypted command data from the upper-layer platform, decrypts it, and then transmits it to the unified data management and forwarding module. This encryption and decryption process is completely transparent to the application logic of the AODF device and the upper-layer management platform, ensuring end-to-end security of data transmission.

[0043] The unified data management and forwarding module is the core data processing unit of this invention. Its function is to receive standardized data from the main control and southbound adaptation modules, cache and log it, and forward it to the northbound secure communication module according to a preset routing strategy. Conversely, it also receives decrypted instructions from the northbound secure communication module and forwards them to the main control and southbound adaptation modules, which then convert them into protocols and instruction formats recognizable by specific AODF devices. This module is crucial for facilitating north-south data flow.

[0044] The function of the power module is to provide a continuous and reliable power supply for the stable operation of the entire connected device. This module converts the external AC or DC power input into DC power of a specific voltage level required by the various electronic components inside the device, and has overvoltage, overcurrent, and short-circuit protection functions to ensure that the device can still operate safely in complex power grid environments.

[0045] Furthermore, to achieve the above functions, the internal structure and working mechanism of each module have been designed to be more specific and refined. Please refer to [link / reference]. Figure 3 It illustrates a specific structural block diagram of the main control and southbound adaptation module. This module internally includes: a multi-protocol physical interface, a pluggable protocol adaptation driver library, and a data paradigm engine.

[0046] A multi-protocol physical interface is used for physically connecting different AODF devices. This interface is preferably an RJ45 Ethernet interface supporting 10 / 100 / 1000Mbps adaptive rates to ensure compatibility with the network connection methods of current mainstream AODF devices. In another embodiment, this interface can also be a pluggable optical module interface (SFP) to adapt to fiber-optic direct connection applications, providing greater flexibility.

[0047] A pluggable protocol adapter driver library is the core component for achieving compatibility with heterogeneous devices. This module pre-loads or dynamically loads dedicated protocol drivers for different manufacturers and models of AODF devices via the network. For example, for devices from manufacturer A, its dedicated Modbus-TCP driver is loaded; for devices from manufacturer B, its proprietary UDP-based message parsing driver is loaded. When an AODF device is connected, the system can automatically identify its model and load the corresponding driver through a handshake protocol or preset configuration. This modular, pluggable design allows for support of future AODF device models by adding new drivers without modifying the core system, providing extremely high scalability.

[0048] The data normalization engine's function is to uniformly convert data parsed from different protocol adapter drivers, which vary in format, into a predefined, vendor-independent internal standard data model. For example, vendor A reports port connection status via binary bitmaps, while vendor B reports via JSON format {"port_id": 10, "link_status": "up"}. The engine will uniformly convert both into a standardized internal structure, such as an object containing standard fields like device ID, chassis number, port number, connection status, and timestamp. This normalization lays the foundation for unified management by upper-layer applications, shielding the implementation differences of underlying devices.

[0049] In a preferred embodiment of the present invention, the northbound secure communication module is implemented based on IPSec VPN technology to provide end-to-end security protection at the network layer. This module specifically includes: an IPSec processing engine, a key exchange and authentication unit, and a security policy database.

[0050] The IPSec processing engine is responsible for executing the Encapsulated Security Payload (ESP) protocol within the IPSec protocol suite. This engine captures all IP packets destined for the upper-layer management platform, encrypts the payload of the packets using a pre-shared key or a session key negotiated with a digital certificate, appends an authentication header, and finally generates encrypted ESP packets for transmission, thereby ensuring data confidentiality and integrity.

[0051] The key exchange and authentication unit is responsible for implementing the Internet Key Exchange (IKEv1 or IKEv2) protocol. It is used to automatically negotiate a Security Association (SA) between the access device and the central VPN security gateway, generating and refreshing the keys required for encryption and authentication. Optionally, to achieve tight coupling authentication between the device and security functions, this unit connects to the main control module via a separate USB authentication interface. The main control module stores digital certificates or credentials used for identity authentication. Before establishing the VPN tunnel, it provides identity information to the security module through this USB interface, enhancing the reliability of authentication.

[0052] The security policy database stores security policies that define which data streams need to be encrypted, what encryption algorithms (such as AES-256) are used, what authentication algorithms (such as SHA-256) are used, and the peer VPN gateway address. In another embodiment, the northbound secure communication module can also be implemented based on the Transport Layer Security (TLS) protocol, establishing a secure TLS connection between the local device and the upper-layer platform, suitable for application layer data stream encryption scenarios.

[0053] Specifically, the core hardware platform of this invention is supported by a main control unit and a southbound adapter module, preferably using a high-performance, low-power embedded system-on-a-chip (SoC), such as Rockchip's RK3568. This platform is configured with large-capacity DDR memory (e.g., 4GB) and eMMC flash memory (e.g., 16GB). The large-capacity DDR memory supports the operation of the embedded operating system, concurrently processes data streams from multiple southbound AODF devices, and provides ample runtime space for the protocol adapter driver library and data paradigm engine. The large-capacity eMMC flash memory is used to permanently store the embedded operating system, pluggable protocol adapter driver library, northbound security policy configuration, and cache up to 30 days of historical data and operation logs according to business needs. To ensure high system reliability, the hardware platform also features a specially designed hardware watchdog circuit and routes the SoC's hardware reset signal to a physical button, enabling uninterrupted and rapid recovery in the event of a system crash due to unforeseen circumstances. In addition, the platform also provides a standard debugging serial port (such as the DB9 interface after RS-232 level conversion) and a USB interface for firmware burning, which greatly facilitates the development, debugging and field maintenance of the equipment.

[0054] To achieve the aforementioned objectives, another technical solution provided by this invention is: an AODF diversity management method integrating encryption functionality. Please refer to... Figure 4 This method closely corresponds to the aforementioned device and includes the following steps: Step S1: Device Initialization and Configuration Loading. After the connected device is powered on, the power module supplies power to each unit, the main control module starts the embedded operating system, and loads the system configuration from the internal eMMC flash memory, including the list of supported AODF devices, the corresponding protocol adapter drivers, the northbound secure communication policy, and the data management rules.

[0055] Step S2: Establish a northbound secure channel. Based on the loaded security policy, the northbound secure communication module actively or passively initiates IKE negotiation with the VPN security gateway of the upper-layer management platform to complete two-way authentication and key exchange, successfully establishing an IPSec VPN tunnel. Thereafter, all northbound and southbound business data will be transmitted through this encrypted tunnel.

[0056] Step S3: Dynamic Access and Adaptation of Southbound Devices. When an AODF device connects to this device via an Ethernet port, the main controller and the southbound adaptation module identify the manufacturer and model of the AODF through a preset discovery protocol (such as LLDP) or based on static configuration. Subsequently, the corresponding driver instance is called and run from the pluggable protocol adapter driver library.

[0057] Step S4: Uplink data acquisition, conversion, and secure forwarding. Please refer to [link / reference]. Figure 5The diagram illustrates the uplink data processing flow. The southbound adapter driver actively collects data from AODF according to vendor-specific protocols (such as Modbus polling) or passively receives data reported by AODF. The data normalization engine converts the received raw data into a unified internal standard data model. The unified data management and forwarding module caches and logs the normalized data before forwarding it to the northbound secure communication module. The northbound module encapsulates and encrypts the data using ESP and sends it to the upper-layer management platform through an established VPN tunnel.

[0058] Step S5: Downlink Command Reception, Conversion, and Precise Distribution. Management commands issued by the upper-layer platform (such as querying specific port status, modifying device configuration, etc.) are encrypted and transmitted to this device via a VPN tunnel. After receiving and decrypting the commands, the northbound secure communication module hands them over to the unified data management and forwarding module. This module forwards the standardized commands to the corresponding driver instances running in the main control and southbound adaptation modules based on the target device information in the commands. The protocol adaptation driver then translates the standard commands into a private protocol command format that the specific AODF device can recognize, and precisely distributes them to the target AODF device through the physical interface.

[0059] Step S6: Device Status Monitoring and Maintenance. The device continuously monitors its own operating status, including CPU load, memory usage, VPN connection status, and the status of each southbound connection. It also supports log querying, configuration updates, and firmware upgrades via the reserved debugging serial port or a secure remote management channel, ensuring the manageability and maintainability of the device.

[0060] The present invention also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements all the steps of the aforementioned method.

[0061] The present invention also provides a computer program product, including instructions that, when executed on a computer, cause the computer to perform all the steps of the aforementioned method.

[0062] Example 1 This embodiment aims to illustrate the application of the device and method described in this invention in a specific large-scale data center optical network centralized management and control application scenario. Specifically, the access device hardware platform in this embodiment is built on an embedded system-on-a-chip (SoC), which integrates a quad-core 64-bit central processing unit with a main frequency of 1.8GHz, and is configured with 4GB of DDR4 main memory and 16GB of eMMC non-volatile memory. The operating system is a Linux distribution containing kernel version 5.4. In this scenario, it is necessary to simultaneously access and manage intelligent optical distribution devices (AODFs) from two different manufacturers. Manufacturer A's device communicates using an industrial bus protocol based on a master-slave polling mode, while Manufacturer B's device reports its status using a proprietary message format based on User Datagram Protocol (UDP). In the implementation process, the access device of this invention connects to the two AODFs respectively through its two RJ45 Ethernet interfaces supporting a rate of 1000Mbps. The main control and southbound adapter modules load and run the corresponding protocol drivers for the two devices respectively from their internal pluggable protocol adapter driver libraries. The data paradigm engine uniformly converts binary bitmap state data received from Manufacturer A and JSON-formatted data received from Manufacturer B into a standardized internal data model containing unique device identifiers, port numbers, connection status, and timestamps. The northbound secure communication module employs IPSec technology, negotiating a VPN tunnel with the data center's central management platform security gateway via Internet Key Exchange Version 2 (IKEv2), and encrypts all outbound data using the Advanced Encryption Standard 256 (AES-256) algorithm. To verify the technical effectiveness of this embodiment, the focus was on testing the new device integration time, uplink data unification success rate, and northbound communication security level. Testing showed that this embodiment exhibits efficient integration capabilities and a high level of security; specific performance data is shown in Table 1 below.

[0063] Example 2 This embodiment aims to illustrate the application of the present invention under another technical solution, particularly in the scenario of a metropolitan area network aggregation node requiring direct fiber optic connection and application layer encryption. Specifically, the access device in this embodiment adopts the same core hardware platform configuration as in Embodiment 1. The difference lies in that its southbound multi-protocol physical interface uses a pluggable optical module interface (SFP), which directly connects to a high-density AODF deployed at a remote location by inserting a 1000BASE-SX multimode optical module. This AODF device communicates using a message transmission protocol based on a publish-subscribe model. The main control and southbound adaptation modules load the corresponding protocol drivers to parse and normalize the received messages. Furthermore, the northbound secure communication module in this embodiment uses Transport Layer Security (TLS) version 1.3 for secure communication, instead of IPSec. This module actively initiates a TLS handshake with the application server of the upper-layer management platform to establish an end-to-end encrypted socket connection, through which all standardized uplink data and downlink commands are transmitted. To verify the technical effect of this embodiment, the same test items as in Embodiment 1 are used for evaluation. Tests have shown that this embodiment also achieves rapid integration and high-standard data security protection, demonstrating the flexibility of the technical solution of this invention and its adaptability to different physical links and security protocols. Its specific performance data is shown in Table 1 below.

[0064] Example 3 This embodiment aims to illustrate the excellent dynamic scalability of the device and method described in this invention. Its application scenario is a cloud service provider rapidly expanding its business and needing to introduce a new model of AODF device without interrupting existing services. Specifically, the initial system state is the same as in Embodiment 1; the access device of this invention is already stably managing two AODF devices from Manufacturer A and Manufacturer B. At this point, support for a new AODF device from Manufacturer C needs to be added. During implementation, maintenance personnel upload the new protocol adaptation driver for Manufacturer C's device to the device's eMMC storage via the device's reserved secure remote management channel. Upon receiving the instruction, the unified data management and forwarding module dynamically loads and starts the new driver in the main control and southbound adaptation modules. The entire process is extremely short and does not affect the running driver instances for Manufacturers A and B, causing no service interruption. The newly accessed AODF device from Manufacturer C is automatically identified and successfully managed by the system. To verify the technical effectiveness of this embodiment, the integration time of the new device and the service interruption time during the loading of the new driver were tested. Tests have shown that this embodiment demonstrates extremely high operational efficiency and business continuity assurance capabilities, and its specific performance data is shown in Table 1 below.

[0065] Comparative Example 1 This comparative example is used to compare with Example 1, aiming to highlight the necessity of the core technical feature of the data paradigmization engine in this invention. The only difference between this comparative example and Example 1 is that the data paradigmization engine functional module is missing in its software implementation. Specifically, although the main control and southbound adaptation modules can successfully receive binary bitmap data from Manufacturer A and private JSON format data from Manufacturer B by loading different protocol drivers, due to the lack of a unified conversion step, it directly forwards these raw, heterogeneous data formats to the northbound secure communication module. Apart from this difference, the hardware platform, southbound protocol adaptation, northbound IPSec secure communication, and performance testing methods used in this comparative example are completely consistent with Example 1. Testing showed that although the data could be securely transmitted to the upper-layer management platform, the platform could not perform unified parsing and processing due to receiving two completely different data structures, resulting in the inability to achieve centralized control of heterogeneous devices, and the invention's objective was not achieved. Its uplink data unification success rate was zero; specific performance data can also be found in Table 1 below.

[0066] Comparative Example 2 This comparative example is used to compare with Example 1 to illustrate the significant advantages of the present invention over the prior art. This comparative example adopts the management scheme in the prior art where the upper-layer management platform directly connects to each AODF device, i.e., it does not use the AODF access device with integrated encryption function described in this invention. In this scenario, the upper-layer management platform needs to develop two independent communication adapter programs, one for connecting to Manufacturer A's AODF via the industrial bus protocol, and the other for connecting to Manufacturer B's AODF via a private UDP protocol. Since AODF devices in the prior art generally lack native encrypted communication capabilities, all management data and status information are transmitted in plaintext over the network. Apart from this difference, the AODF device models, network environment, and performance test items involved in this comparative example are consistent with Example 1. Testing revealed that this scheme not only requires a significant investment of R&D resources to specifically develop and maintain multiple protocol stacks, resulting in extremely long integration times for new devices, but also poses a huge security risk due to plaintext data transmission, with its northbound communication security level score being extremely poor. Specific performance data can also be found in Table 1 below.

[0067] Effect verification To more intuitively demonstrate the beneficial effects of the present invention, the key performance test data of the above embodiments and comparative examples are summarized in Table 1.

[0068] Table 1 Performance Comparison Data Table

[0069] The above are merely preferred embodiments of the present invention and are not intended to limit the present invention in any other way. Any person skilled in the art may make changes or modifications to the above-disclosed technical content to create equivalent embodiments that can be applied to other fields. However, any simple modifications, equivalent changes, and modifications made to the above embodiments based on the technical essence of the present invention without departing from the scope of the present invention shall still fall within the protection scope of the present invention.

Claims

1. An AODF access device with integrated encryption function, characterized in that, include: The main control and southbound adapter module is used to establish communication and protocol adaptation with heterogeneous automatic fiber optic distribution equipment in the southbound direction, and outputs the data after protocol parsing and data format standardization processing upwards. The northbound secure communication module is used to establish an encrypted data transmission channel between the access device and the upper-layer network management system, encrypt the data sent from the access device to the upper-layer network management system, and decrypt the instruction data from the upper-layer network management system. The unified data management and forwarding module is used to receive standardized data from the main control and southbound adaptation module and forward it to the northbound secure communication module, and to receive decrypted instructions from the northbound secure communication module and forward them to the main control and southbound adaptation module. The power module is used to provide power to the main control and southbound adapter module, the northbound secure communication module and the unified data management and forwarding module.

2. The device according to claim 1, characterized in that, The main control and southbound adaptation module specifically includes: A multi-protocol physical interface is used to establish a physical connection with the heterogeneous automated fiber optic distribution equipment. A pluggable protocol adapter driver library for storing or dynamically loading dedicated protocol drivers for automated fiber optic distribution equipment from different manufacturers or models. A data paradigm engine is used to uniformly convert the data parsed by the dedicated protocol driver into a predefined internal standard data model.

3. The device according to claim 1, characterized in that, The northbound secure communication module is implemented based on IPSec technology and specifically includes: The IPSec processing engine is used to execute the Encapsulation Security Payload Protocol to encrypt the payload of data packets sent to the upper-layer network management system. The key exchange and authentication unit is used to execute the Internet key exchange protocol to automatically negotiate secure associations and generate and refresh keys; The security policy database stores security policies that define the data streams to be encrypted, encryption algorithms, authentication algorithms, and peer gateway addresses.

4. The device according to claim 2, characterized in that, The hardware platform for the main control and southbound adapter modules includes: Embedded system-on-a-chip (SoC); DDR memory used to support the operation of the operating system and the concurrent processing of data streams; eMMC flash memory for storing embedded operating systems, the pluggable protocol adapter driver library, and historical data; and Hardware watchdog circuit.

5. A method for managing AODF with integrated encryption, characterized in that, The following steps are involved: Establish a secure northbound channel by creating an encrypted data transmission channel between the access device and the upper-level management platform; Perform southbound device adaptation. When an automatic fiber optic distribution device is connected, identify the model of the automatic fiber optic distribution device and load the corresponding dedicated protocol driver for it. The system processes the uplink data stream by collecting data from the automatic fiber optic distribution equipment through the dedicated protocol driver, converting the collected data into a unified internal standard data model, and then encrypting it through the northbound secure channel before forwarding it to the upper-layer management platform. The system processes downlink command streams, receives encrypted commands from the upper-layer management platform via the northbound secure channel, decrypts the commands, and converts the decrypted standard commands into a command format recognizable by the automatic fiber optic distribution equipment through the dedicated protocol driver before sending them out.

6. The method according to claim 5, characterized in that, The specific steps for establishing a safe northbound passage include: According to the loaded policy, the northbound secure communication module actively or passively initiates IKE negotiation with the VPN security gateway of the upper-layer management platform to complete two-way identity authentication and key exchange, and establishes an IPSec VPN tunnel. From then on, all north-south business data will be transmitted through this encrypted tunnel.

7. The method according to claim 5, characterized in that, The steps for performing southbound device adaptation specifically include: Identify the manufacturer and model of the access automated fiber distribution equipment by discovering protocols or static configurations. Based on the identified manufacturer and model, the corresponding dedicated protocol driver is called and run from a pre-built pluggable protocol adapter driver library.

8. The method according to claim 5, characterized in that, The steps for processing the upstream data stream specifically include: The dedicated protocol driver actively polls or passively receives data from the automatic fiber optic distribution equipment according to a specific protocol. A data normalization engine converts the received data into an object containing standard fields such as device ID, port number, and connection status; The unified data management and forwarding module caches the normalized data and forwards it to a northbound secure communication module for encryption and transmission.

9. The method according to claim 5, characterized in that, The steps for processing the downlink command stream specifically include: A northbound secure communication module receives and decrypts the encrypted command; A unified data management and forwarding module forwards standardized instructions to the corresponding dedicated protocol driver based on the target device information in the instructions; The dedicated protocol driver translates the standardized instructions into proprietary protocol instructions that the automated fiber optic distribution equipment can recognize.

10. A computer-readable storage medium, characterized in that, It stores a computer program that, when executed by a processor, implements the method as described in any one of claims 5 to 9.