Fixed mobile convergence access terminal, radio frequency unit registration method and device
By introducing an improved MPCP protocol and encrypted verification code mechanism into the fixed-mobile converged access terminal, the problem of poor communication security between the radio frequency unit and the baseband unit is solved, the identity recognition and authorization of the radio frequency unit are realized, and the security and reliability of communication are improved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA TELECOM CORP LTD
- Filing Date
- 2022-11-15
- Publication Date
- 2026-04-14
AI Technical Summary
During the deployment of 5G base stations, the communication security of the radio frequency unit and the baseband unit in the fixed-mobile converged access terminal is poor, especially the communication between the radio frequency unit deployed in the user's home and the baseband unit in the operator's equipment room lacks reliable guarantee.
An improved MPCP protocol is adopted, which introduces an encrypted verification code mechanism between the baseband unit and the radio frequency unit to ensure the security of message interaction. This includes the baseband unit generating and encrypting the first verification code, the radio frequency unit decrypting and verifying it, and assigning and encrypting the radio frequency identification mark after successful verification to achieve identity recognition and authorization.
It effectively improves the security of the registration process of the radio frequency unit in the fixed-mobile converged access terminal, solves the security problem of message interaction between the baseband unit and the radio frequency unit, and ensures the reliability of communication and privacy protection.
Smart Images

Figure CN115776670B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of wireless communication technology, and more specifically, to a fixed-mobile converged access terminal, a radio frequency unit registration method, and an apparatus. Background Technology
[0002] With the large-scale deployment of 5G networks and the widespread application of 5G mobile phones, people are paying increasing attention to 5G signal quality. During the deployment of 5G base stations, due to the complex environment and dense building density in urban residential areas, customers often experience weak 5G signals indoors, relying solely on fixed-line broadband for internet services. This makes it difficult to handle some low-latency applications, and indoor voice calls in these areas are a significant challenge. In response, fixed-mobile converged access terminals have emerged. One type of fixed-mobile converged access terminal deploys the Radio Unit (RU) on the home gateway, while the Baseband Unit (BU) is connected to the optical line terminal equipment's inline port. It utilizes a passive optical fiber network to carry baseband information, enabling signal transmission between the RU and BU devices. However, with this type of fixed-mobile converged access terminal, the RU is located in the user's home, while the BU is in the operator's equipment room, a considerable distance apart, leading to a lack of reliable communication security between the two.
[0003] There is currently no effective solution to the above problems. Summary of the Invention
[0004] This application provides a fixed-mobile converged access terminal, a radio frequency unit registration method and apparatus, to at least solve the technical problem of poor message interaction security between baseband units and radio frequency units when mobile broadband and fixed broadband are converged.
[0005] According to one aspect of the embodiments of this application, a fixed-mobile converged access terminal is provided, comprising: a baseband unit and a radio frequency (RF) unit for message interaction based on a passive optical fiber network, wherein: the baseband unit is configured to send a discovery message to the RF unit; after receiving an identity verification request message sent by the RF unit, send a verification code message to the RF unit, the verification code message including at least a first verification code generated and encrypted by the baseband unit; verify the second verification code in the verification message replied by the RF unit, and upon successful verification, send a verification success message to the RF unit, the verification success message including at least a radio frequency identification (RFID) identifier allocated and encrypted by the baseband unit for the RF unit; send an authorization message to the RF unit, the authorization message including at least a data transmission time slot allocated by the baseband unit for the RF unit; receive a registration confirmation message replied by the RF unit, and complete the registration of the RF unit; the RF unit is configured to send an identity verification request message to the baseband unit after receiving the discovery message; after receiving the verification code message, reply to the baseband unit with a verification message, the verification message including at least a second verification code obtained by the RF unit decrypting the encrypted first verification code; receive the verification success message, and complete identity verification; and after receiving the authorization message, reply to the baseband unit with a registration confirmation message.
[0006] Optionally, the discovery message includes at least the start time and length of the radio frequency unit discovery window; the baseband unit is used to periodically broadcast the discovery message to the radio frequency unit; the radio frequency unit is used to determine its own registration status after receiving the discovery message; when the radio frequency unit has not registered with the baseband unit, it sends an identification request message to the baseband unit at the start time of the radio frequency unit discovery window, wherein the identification request message includes at least the media access control address of the radio frequency unit.
[0007] Optionally, both the baseband unit and the radio frequency unit include a preset encryption component and a decryption component; the baseband unit is used to generate a first verification code after receiving an identity verification request message, and encrypt the first verification code using the encryption component; and send a verification code message containing the encrypted first verification code to the radio frequency unit; the radio frequency unit is used to decrypt the encrypted first verification code using the decryption component after receiving the verification code message to obtain a second verification code; and reply to the baseband unit with a verification message containing the second verification code within a first preset time period.
[0008] Optionally, the baseband unit is configured to, upon receiving a verification message from the radio frequency unit, compare the second verification code with the first verification code; if the second verification code is the same as the first verification code, confirm that the verification is successful; if the second verification code is different from the first verification code, confirm that the verification is unsuccessful. Upon successful verification, the baseband unit generates a radio frequency identification (RFID) identifier based on its baseband identification identifier and binds the RFID identifier to a media access control (MAC) address; encrypts the RFID identifier and sends a successful verification message containing the encrypted RFID identifier to the radio frequency unit based on the MAC address. The radio frequency unit, upon receiving the successful verification message, saves the encrypted RFID identifier to complete the identity verification.
[0009] Optionally, the baseband unit is further configured to send a verification failure message to the radio frequency unit when the verification fails; the radio frequency unit is further configured to resend the identity verification request message to the baseband unit after receiving the verification failure message; wherein, when the number of verification attempts by the baseband unit exceeds a preset threshold and the verification result is still a verification failure, the radio frequency unit is prohibited from sending identity verification request messages to the baseband unit for a second preset time period, and the baseband unit refuses to receive all messages sent by the radio frequency unit for the second preset time period.
[0010] Optionally, the authorization message also includes an encrypted RFID tag and a multicast media access control address, wherein the encrypted RFID tag is added as a preamble to the multicast media access control address; the baseband unit is used to send the authorization message to the radio frequency unit; the radio frequency unit is used to reply with a registration confirmation message to the baseband unit when the encrypted RFID tag in the authorization confirmation message is the same as the encrypted RFID tag stored in the radio frequency unit.
[0011] Optionally, the radio frequency unit is also used to send a target message stream to the baseband unit in a data transmission time slot after registration is completed; the baseband unit is also used to receive the target message stream sent by the radio frequency unit in the data transmission time slot.
[0012] According to another aspect of the embodiments of this application, a radio frequency unit (RF) registration method is also provided, comprising: sending a discovery message to an RF unit in a fixed-mobile converged access terminal; after receiving an identity recognition request message sent by the RF unit, sending a verification code message to the RF unit, wherein the verification code message includes at least a first verification code generated and encrypted by a baseband unit; verifying a second verification code in a verification message replied by the RF unit, and sending a verification pass message to the RF unit when the verification is successful, wherein the verification pass message includes at least a radio frequency identification identifier allocated and encrypted by the baseband unit for the RF unit; sending an authorization message to the RF unit, wherein the authorization message includes at least a data transmission time slot allocated by the baseband unit for the RF unit; and receiving a registration confirmation message replied by the RF unit to complete the registration of the RF unit.
[0013] According to another aspect of the embodiments of this application, another radio frequency unit registration method is also provided, including: after receiving a discovery message sent by a baseband unit in a fixed-mobile converged access terminal, sending an identity recognition request message to the baseband unit; after receiving a verification code message, replying to the baseband unit with a verification message, wherein the verification code message includes at least a first verification code generated and encrypted by the baseband unit, and the verification message includes at least a second verification code obtained by the radio frequency unit decrypting the encrypted first verification code; receiving a verification pass message to complete identity recognition, wherein the verification pass message includes at least a radio frequency identification identifier allocated and encrypted by the baseband unit for the radio frequency unit; and after receiving an authorization message, replying to the baseband unit with a registration confirmation message, wherein the authorization message includes at least a data transmission time slot allocated by the baseband unit for the radio frequency unit.
[0014] According to another aspect of the embodiments of this application, an electronic device is also provided, the electronic device including: a memory and a processor, wherein the memory stores a computer program, and the processor is configured to execute the above-described radio frequency unit registration method through the computer program.
[0015] In the fixed-mobile converged access terminal of this application embodiment, the baseband unit sends a discovery message to the radio frequency (RF) unit; after receiving the discovery message, the RF unit sends an identity verification request message to the baseband unit; after receiving the identity verification request message, the baseband unit sends a verification code message to the RF unit, the verification code message including a first verification code generated and encrypted by the baseband unit; after receiving the verification code message, the RF unit replies with a verification message to the baseband unit, the verification message including a second verification code obtained by decrypting the encrypted first verification code; the baseband unit verifies the verification message replied by the RF unit, and when the verification is successful, sends a verification success message to the RF unit, the verification success message including an RFID tag allocated and encrypted by the baseband unit for the RF unit; the RF unit receives the verification success message and completes identity verification; the baseband unit sends an authorization message to the RF unit, the authorization message including a data transmission time slot allocated by the baseband unit for the RF unit; after receiving the authorization message, the RF unit replies with a registration confirmation message to the baseband unit; the baseband unit receives the registration confirmation message and completes the registration of the RF unit. The system uses encrypted verification codes to identify radio frequency (RF) units, and the assigned RF identification identifiers are also encrypted, effectively ensuring the security of the RF unit registration process. This solves the technical problem of poor message interaction security between baseband and RF units when mobile broadband and fixed broadband are integrated. Attached Figure Description
[0016] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0017] Figure 1 This is a schematic diagram of the structure of an optional fixed-mobile converged access terminal according to an embodiment of this application;
[0018] Figure 2 This is a schematic diagram illustrating an optional radio frequency unit registration process in a baseband unit according to an embodiment of this application;
[0019] Figure 3 This is a flowchart illustrating an optional radio frequency unit registration method according to an embodiment of this application;
[0020] Figure 4 This is a flowchart illustrating another optional radio frequency unit registration method according to an embodiment of this application. Detailed Implementation
[0021] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.
[0022] It should be noted that the terms "first," "second," etc., used in the specification, claims, and drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0023] To better understand the embodiments of this application, the following is a translation and explanation of some nouns or terms that appear in the description of the embodiments of this application:
[0024] Passive Optical Network (PON): It includes an Optical Line Terminal (OLT) installed at the central control station and a number of Optical Network Units (ONUs) installed at the user sites. The OLT and ONUs communicate through an Optical Distribution Network (ODN). The ODN does not contain any electronic devices or power supplies, but only contains passive devices such as optical fibers, passive splitters or couplers.
[0025] Multi-Point Control Protocol (MPCP): Defines the following message types, referred to as MPCPDUs (MPCP Data Units): PAUSE, GATE, REPORT, REGISTER_RQ, REGISTER, and REGISTER_ACK. These are used for information exchange between the OLT and ONU. All messages are 64-byte MAC (Media Access Control Address) control frames, including the following fields:
[0026] Fields Octets 1 Destination address (DA) 6 2 Source address (SA) 6 3 Length / type = 0x8808 2 4 Opcode 2 5 Timestamp 4 6 Opcode-specific fields / pad 40 7 Frame check sequence (FCS) 4
[0027] 1. DA (Destination Address): All MPCPDUs use a common multicast MAC address, except for REGISTER messages, which use the ONU's actual MAC address;
[0028] 2. SA (Source Address): In the OLT, there are multiple MAC instances corresponding to one GMII (Gigabit Media Independent Interface). Therefore, data sent by different MACs must carry their corresponding SA.
[0029] 3. The type field value is 8808;
[0030] 4. Opcode: Distinguishes MAC control frame type. 0x0001 is PAUSE message, 0x0002 is GATE message, 0x0003 is REPORT message, 0x0004 is REGISTER_REQ message, 0x0005 is REGISTER message, and 0x0006 is REGISTER_ACK message.
[0031] 5. Timestamp; used to synchronize the MPCP CLOCK between the OLT and ONU, with its reference point being the first byte of the DA;
[0032] 6. Opcode-specific fields: Used to transmit specific MPCP functions; set to 0 when not in use.
[0033] 7. FCS (Frame Check Sequence): CRC32 check.
[0034] Example 1
[0035] In related technologies, fixed-mobile converged access terminals are based on PON networks, deploying the radio frequency unit on the home gateway corresponding to the ONU, and the baseband unit is connected to the uplink port of the OLT device. The MPCP protocol is used to realize signal transmission between the radio frequency unit and the baseband unit. However, since the radio frequency unit is in the user's home and the baseband unit is in the operator's equipment room, the two are relatively far apart, and the communication security between them lacks reliable guarantee.
[0036] Taking the ONU registration process with the OLT as an example, the Register message and GATE authorization message are broadcast by the OLT. As a result, all ONUs will receive the Register message and GATE authorization message, which leaves a risk for malicious attacks and eavesdropping. Some ONUs may intercept the MAC address, assigned LLID (Logical Link Identifier), and data transmission time slot of other ONUs by receiving the Register message and GATE authorization message, and use the intercepted information to receive data from other ONUs. They can also impersonate other ONUs to attack the OLT. Therefore, the original registration process based on the MPCP protocol has security vulnerabilities.
[0037] To address the aforementioned issues, this application first improves the existing MPCP protocol, with the following frame structure:
[0038] Fields Octets 1 Destination address (DA) 6 2 Source address (SA) 6 3 Length / type = 0x1008 2 4 Opcode 2 5 Timestamp 4 6 Opcode-specific fields / pad 40 7 Frame check sequence (FCS) 4
[0039] Compared to the existing MPCP protocol, the type field value between OLT-ONU is 0x8808, while the type field value between BU-RU is 0x1008, which avoids mutual interference. Secondly, additional message types have been added for the opcode types: 0x0101 is the PAUSE message, 0x0102 is the GATE message, 0x0103 is the REPORT message, 0x0104 is the REGISTER_REQ message, 0x0105 is the REGISTER message, 0x0106 is the REGISTER_ACK message, 0x0107 is the RU authenticating with the BU, 0x0108 is the BU sending a verification code to the RU, 0x0109 is the RU replying to the BU with a verification code, 0x010A is the BU sending a message to the RU indicating authentication failure, and 0x010B is the BU sending a newly assigned RF unit identifier to the RU.
[0040] Based on the improved MPCP protocol, this application provides a more secure fixed-mobile converged access terminal, such as... Figure 1 As shown, the terminal includes a baseband unit 10 and radio frequency units 11 (a-n) for message interaction based on a passive optical fiber network 12. The passive optical fiber network 12 includes an optical line terminal 121, an optical distribution network 122, and optical network units 123 (a-n). The baseband unit 10 is connected to the optical line terminal 121, and the radio frequency units 11 (a-n) are respectively connected to the optical network units 123 (a-n). Both the baseband unit 10 and the radio frequency units 11 (a-n) are pre-installed with an improved MPCP protocol, with the following specific functions:
[0041] The baseband unit is used to send discovery messages to the radio frequency (RF) unit; upon receiving an identity verification request message from the RF unit, it sends a verification code message to the RF unit, the verification code message including at least a first verification code generated and encrypted by the baseband unit; it verifies the second verification code in the verification message replied by the RF unit, and upon successful verification, sends a verification success message to the RF unit, the verification success message including at least an RFID tag assigned and encrypted by the baseband unit for the RF unit; it sends an authorization message to the RF unit, the authorization message including at least a data transmission time slot assigned by the baseband unit for the RF unit; and it receives a registration confirmation message from the RF unit to complete the registration of the RF unit.
[0042] The radio frequency unit is used to send an identity verification request message to the baseband unit after receiving a discovery message; reply to the baseband unit with a verification message after receiving a verification code message, the verification message including at least a second verification code obtained by the radio frequency unit decrypting the encrypted first verification code; receive a verification pass message to complete identity verification; and reply to the baseband unit with a registration confirmation message after receiving an authorization message.
[0043] The following explains the interaction process and specific functions of the baseband unit and the radio frequency unit:
[0044] First, the baseband unit periodically broadcasts a discovery message (message code 0x0102) to the radio frequency unit. This discovery message includes at least the start time and length of the radio frequency unit's discovery window.
[0045] After receiving a discovery message, the radio frequency unit (RF unit) can first determine whether the target address of the discovery message is the same as its own MAC address. If they are different, the process ends; if they are the same, it continues to determine its own registration status. When the RF unit has registered with the baseband unit, it can directly interact with the baseband unit. When the RF unit has not registered with the baseband unit, it will wait and send an identification request message (message code 0x0107) to the baseband unit at the start of the RF unit discovery window. The identification request message must include at least the RF unit's MAC address.
[0046] Optionally, both the baseband unit and the radio frequency unit include pre-installed encryption and decryption components, typically custom encryption schemes and corresponding keys.
[0047] After receiving the identity verification request message, the baseband unit generates a first verification code, which is usually 16-bit bytes. Then, it encrypts the first verification code using a preset encryption component. It then sends a verification code message (message code 0x0108) containing the encrypted first verification code to the radio frequency unit. The encrypted first verification code is placed in the Opcode-specific field.
[0048] After receiving the verification code message, the radio frequency unit (RF unit) decrypts the encrypted first verification code using a preset decryption component to obtain the second verification code. Then, within a first preset time period, it replies to the baseband unit with a verification message containing the second verification code (message code 0x0109). The first preset time period is a reply time period specified by the baseband unit; the specific time can be adjusted as needed and is not limited here. The second verification code replied by the RF unit to the baseband unit is in plaintext and is placed in the Opcode-specific field.
[0049] After receiving the verification message from the radio frequency unit, the baseband unit compares the second verification code with the first verification code. If the second verification code is the same as the first verification code, the verification is confirmed to be successful. If the second verification code is different from the first verification code, the verification is confirmed to be unsuccessful.
[0050] Upon successful verification, the baseband unit generates an RFID tag corresponding to the RF unit based on its own baseband identification tag and binds the RFID tag to the MAC address of the RF unit. Then, the RFID tag is encrypted, and a successful verification message (message code 0x010B) containing the encrypted RFID tag is sent to the RF unit based on the MAC address. The encrypted RFID tag is placed in the Opcode-specific field.
[0051] For example, the baseband identification identifier of the baseband unit is gNBId. When assigning RFID identifiers to the radio frequency unit, multiple radio frequency units that have passed authentication can be sorted and then multiple RFID identifiers such as gNBId+1, gNBId+2, ... can be generated in sequence. At the same time, each RFID identifier is bound to the MAC address of the corresponding radio frequency unit. When sending an authentication pass message to the target radio frequency unit, the destination address of the authentication pass message is the MAC address of the target radio frequency unit.
[0052] After receiving the verification message, the radio frequency unit saves the encrypted radio frequency identification mark to complete the identity verification.
[0053] Optionally, the baseband unit will send an authentication failure message (message code 0x010A) to the radio frequency unit when the authentication fails; after receiving the authentication failure message, the radio frequency unit will resend the identity verification request message (message code 0x0107) to the baseband unit to perform authentication again.
[0054] Specifically, if the number of authentication attempts by the baseband unit exceeds a preset threshold and the authentication result is still unsuccessful, the radio frequency unit (RF unit) will be prohibited from sending authentication request messages to the baseband unit for a second preset time period. The baseband unit will also refuse to receive any messages sent by the RF unit during this second preset time period. For example, if the preset threshold is set to 3 and the second preset time period is set to 2 hours, if the RF unit fails authentication three times consecutively, it will not send any more authentication request messages for 2 hours, and the baseband unit will lock the RF unit for 2 hours.
[0055] After successful authentication, the baseband unit sends an authorization message (message code 0x0102) to the radio frequency unit. The authorization message includes: the data transmission time slot allocated by the baseband unit to the radio frequency unit, the encrypted radio frequency identification identifier, and the multicast MAC address. The encrypted radio frequency identification identifier is added as a preamble to the multicast MAC address.
[0056] After receiving the authorization message, the radio frequency unit confirms that the encrypted radio frequency identification in the authorization message is the same as the encrypted radio frequency identification stored in the radio frequency unit, and then replies to the baseband unit with a registration confirmation message (message code 0x0106).
[0057] Specifically, when the baseband unit sends an authorization message to the target radio frequency unit, the destination address of the authorization message is a multicast MAC address, preceded by a preamble. The preamble is the encrypted radio frequency identification (RFID) identifier corresponding to the target radio frequency unit. When the target radio frequency unit receives the authorization message, it finds that the preamble before the destination address of the authorization message is the encrypted RFID identifier assigned to it by the baseband unit, and then replies with a registration confirmation message to the baseband unit. When the baseband unit receives the registration confirmation message from the target radio frequency unit, it indicates that the target radio frequency unit has registered with the baseband unit.
[0058] Optionally, after registration, the radio frequency unit can send the target message stream to the baseband unit in the data transmission time slot; the baseband unit can receive the target message stream sent by the radio frequency unit in the data transmission time slot.
[0059] The fixed-mobile converged access terminal provided in this application embodiment is widely applicable to comprehensive wireless coverage scenarios, especially weak signal coverage scenarios such as indoor homes, supermarkets, and basements. It is easy to install and can automatically activate the radio frequency unit while installing broadband, which can solve the problems of long construction cycles and high maintenance costs associated with traditional macro base stations and spot-type installations.
[0060] Figure 2 The complete interaction flow for an optional RF unit to register with a baseband unit is shown, including the following steps:
[0061] Step 1: The baseband unit broadcasts a discovery message (0x0102) to the radio frequency unit;
[0062] Step 2: The radio frequency unit receives the discovery message and determines whether the target address of the discovery message is the same as its own MAC address. If they are different, the process ends; if they are the same, the process continues to step 3.
[0063] Step 3: The radio frequency unit determines its own registration status. If it has registered with the baseband unit, it directly interacts with the baseband unit; if it has not registered with the baseband unit, it continues to step 4.
[0064] Step 4: The radio frequency unit sends an identification request message (0x0107) to the baseband unit;
[0065] Step 5: The baseband unit receives the identity verification request message, generates and encrypts the first verification code, and sends the verification code message (0x0108) to the radio frequency unit.
[0066] Step 6: The radio frequency unit receives the verification code message, decrypts the first verification code to obtain the second verification code, and replies with a verification message (0x0109) to the baseband unit.
[0067] Step 7: The baseband unit receives the verification message and verifies the second verification code. If the verification fails, proceed to step 8; if the verification passes, proceed to step 9.
[0068] Step 8: The baseband unit sends a verification failure message (0x010A) to the radio frequency unit. The radio frequency unit receives the verification failure message and re-executes step 4.
[0069] Step 9: The baseband unit assigns an RFID tag to the radio frequency unit and sends a verification pass message (0x010B) to the radio frequency unit;
[0070] Step 10: The radio frequency unit receives the verification message, saves the encrypted radio frequency identification mark, and completes the identity verification.
[0071] Step 11: The baseband unit allocates a data transmission time slot to the radio frequency unit and sends an authorization message (0x0102) to the radio frequency unit;
[0072] Step 12: The radio frequency unit receives the authorization message and replies with a registration confirmation message (0x0106) to the baseband unit;
[0073] Step 13: The baseband unit receives the registration confirmation message, and the radio frequency unit registration is completed.
[0074] In the fixed-mobile converged access terminal of this application embodiment, the baseband unit sends a discovery message to the radio frequency (RF) unit; after receiving the discovery message, the RF unit sends an identity verification request message to the baseband unit; after receiving the identity verification request message, the baseband unit sends a verification code message to the RF unit, the verification code message including a first verification code generated and encrypted by the baseband unit; after receiving the verification code message, the RF unit replies with a verification message to the baseband unit, the verification message including a second verification code obtained by decrypting the encrypted first verification code; the baseband unit verifies the verification message replied by the RF unit, and when the verification is successful, sends a verification success message to the RF unit, the verification success message including an RFID tag allocated and encrypted by the baseband unit for the RF unit; the RF unit receives the verification success message and completes identity verification; the baseband unit sends an authorization message to the RF unit, the authorization message including a data transmission time slot allocated by the baseband unit for the RF unit; after receiving the authorization message, the RF unit replies with a registration confirmation message to the baseband unit; the baseband unit receives the registration confirmation message and completes the registration of the RF unit. The system uses encrypted verification codes to identify radio frequency (RF) units, and the assigned RF identification identifiers are also encrypted, effectively ensuring the security of the RF unit registration process. This solves the technical problem of poor message interaction security between baseband and RF units when mobile broadband and fixed broadband are integrated.
[0075] Example 2
[0076] Based on the fixed-mobile converged access terminal provided in Embodiment 1, this application embodiment also provides a radio frequency unit registration method implemented by a baseband unit. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0077] Figure 3 This is a flowchart illustrating an optional radio frequency unit registration method according to an embodiment of this application, as shown below. Figure 3 As shown, the method includes at least steps S302-S310, wherein:
[0078] Step S302: Send a discovery message to the radio frequency unit in the fixed-mobile converged access terminal.
[0079] The baseband unit periodically broadcasts a discovery message (message code 0x0102) to the radio frequency unit. This discovery message includes at least the start time and length of the radio frequency unit discovery window.
[0080] After receiving a discovery message, the radio frequency unit (RF unit) can first determine whether the target address of the discovery message is the same as its own MAC address. If they are different, the process ends; if they are the same, it continues to determine its own registration status. When the RF unit has registered with the baseband unit, it can directly interact with the baseband unit. When the RF unit has not registered with the baseband unit, it will wait and send an identification request message (message code 0x0107) to the baseband unit at the start of the RF unit discovery window. The identification request message must include at least the RF unit's MAC address.
[0081] Step S304: After receiving the identity verification request message sent by the radio frequency unit, a verification code message is sent to the radio frequency unit. The verification code message includes at least a first verification code generated and encrypted by the baseband unit.
[0082] After receiving the identity verification request message, the baseband unit generates a first verification code, which is usually 16-bit bytes. Then, it encrypts the first verification code using a preset encryption component. It then sends a verification code message (message code 0x0108) containing the encrypted first verification code to the radio frequency unit. The encrypted first verification code is placed in the Opcode-specific field.
[0083] After receiving the verification code message, the radio frequency unit (RF unit) decrypts the encrypted first verification code using a preset decryption component to obtain the second verification code. Then, within a first preset time period, it replies to the baseband unit with a verification message containing the second verification code (message code 0x0109). The first preset time period is a reply time period specified by the baseband unit; the specific time can be adjusted as needed and is not limited here. The second verification code replied by the RF unit to the baseband unit is in plaintext and is placed in the Opcode-specific field.
[0084] Step S306: Verify the second verification code in the verification message replied by the radio frequency unit, and send a verification pass message to the radio frequency unit when the verification is successful. The verification pass message includes at least the radio frequency identification identifier assigned and encrypted by the baseband unit for the radio frequency unit.
[0085] After receiving the verification message from the radio frequency unit, the baseband unit compares the second verification code with the first verification code. If the second verification code is the same as the first verification code, the verification is confirmed to be successful. If the second verification code is different from the first verification code, the verification is confirmed to be unsuccessful.
[0086] Upon successful verification, the baseband unit generates an RFID tag corresponding to the RF unit based on its own baseband identification tag and binds the RFID tag to the MAC address of the RF unit. Then, the RFID tag is encrypted, and a successful verification message (message code 0x010B) containing the encrypted RFID tag is sent to the RF unit based on the MAC address. The encrypted RFID tag is placed in the Opcode-specific field.
[0087] Optionally, the baseband unit will send a verification failure message (message code 0x010A) to the radio frequency unit when verification fails. Upon receiving the verification failure message, the radio frequency unit will resend an identity verification request message (message code 0x0107) to the baseband unit for re-authentication. Specifically, if the baseband unit's verification attempts exceed a preset threshold and the verification result is still a failure, the radio frequency unit will be prohibited from sending identity verification request messages to the baseband unit for a second preset time period, and the baseband unit will refuse to receive any messages sent by the radio frequency unit during this second preset time period.
[0088] Step S308: Send an authorization message to the radio frequency unit. The authorization message includes at least the data transmission time slot allocated by the baseband unit to the radio frequency unit.
[0089] After successful authentication, the baseband unit sends an authorization message (message code 0x0102) to the radio frequency unit. The authorization message includes: the data transmission time slot allocated by the baseband unit to the radio frequency unit, the encrypted radio frequency identification identifier, and the multicast MAC address. The encrypted radio frequency identification identifier is added as a preamble to the multicast MAC address.
[0090] After receiving the authorization message, the radio frequency unit confirms that the encrypted radio frequency identification in the authorization message is the same as the encrypted radio frequency identification stored in the radio frequency unit, and then replies to the baseband unit with a registration confirmation message (message code 0x0106).
[0091] Step S310: Receive the registration confirmation message from the radio frequency unit to complete the registration of the radio frequency unit.
[0092] When the baseband unit receives a registration confirmation message from the destination radio frequency unit, it indicates that the destination radio frequency unit has been registered with the baseband unit.
[0093] Optionally, after registration, the radio frequency unit can send the target message stream to the baseband unit in the data transmission time slot; the baseband unit can receive the target message stream sent by the radio frequency unit in the data transmission time slot.
[0094] In this embodiment, the radio frequency unit is identified by an encrypted verification code, and the assigned radio frequency identification mark is also encrypted, which effectively ensures the security of the radio frequency unit registration process, thereby solving the technical problem of poor message interaction security between the baseband unit and the radio frequency unit when mobile broadband and fixed broadband are integrated.
[0095] Example 3
[0096] Based on the fixed-mobile converged access terminal provided in Embodiment 1, this application embodiment also provides a radio frequency unit registration method implemented by a radio frequency unit. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0097] Figure 4 This is a flowchart illustrating an optional radio frequency unit registration method according to an embodiment of this application, as shown below. Figure 4 As shown, the method includes at least steps S402-S408, wherein:
[0098] Step S402: After receiving the discovery message sent by the baseband unit in the fixed-mobile converged access terminal, send an identity recognition request message to the baseband unit.
[0099] The baseband unit periodically broadcasts a discovery message (message code 0x0102) to the radio frequency unit. This discovery message includes at least the start time and length of the radio frequency unit discovery window.
[0100] After receiving a discovery message, the radio frequency unit (RF unit) can first determine whether the target address of the discovery message is the same as its own MAC address. If they are different, the process ends; if they are the same, it continues to determine its own registration status. When the RF unit has registered with the baseband unit, it can directly interact with the baseband unit. When the RF unit has not registered with the baseband unit, it will wait and send an identification request message (message code 0x0107) to the baseband unit at the start of the RF unit discovery window. The identification request message must include at least the RF unit's MAC address.
[0101] Step S404: After receiving the verification code message, reply with a verification message to the baseband unit. The verification code message includes at least a first verification code generated and encrypted by the baseband unit, and the verification message includes at least a second verification code obtained by the radio frequency unit decrypting the encrypted first verification code.
[0102] After receiving the identity verification request message, the baseband unit generates a first verification code, which is usually 16-bit bytes. Then, it encrypts the first verification code using a preset encryption component. It then sends a verification code message (message code 0x0108) containing the encrypted first verification code to the radio frequency unit. The encrypted first verification code is placed in the Opcode-specific field.
[0103] After receiving the verification code message, the radio frequency unit (RF unit) decrypts the encrypted first verification code using a preset decryption component to obtain the second verification code. Then, within a first preset time period, it replies to the baseband unit with a verification message containing the second verification code (message code 0x0109). The first preset time period is a reply time period specified by the baseband unit; the specific time can be adjusted as needed and is not limited here. The second verification code replied by the RF unit to the baseband unit is in plaintext and is placed in the Opcode-specific field.
[0104] Step S406: Receive the verification pass message to complete identity recognition. The verification pass message includes at least the radio frequency identification identifier assigned and encrypted by the baseband unit to the radio frequency unit.
[0105] After receiving the verification message from the radio frequency unit, the baseband unit compares the second verification code with the first verification code. If the second verification code is the same as the first verification code, the verification is confirmed to be successful. If the second verification code is different from the first verification code, the verification is confirmed to be unsuccessful.
[0106] Upon successful verification, the baseband unit generates an RFID tag corresponding to the RF unit based on its own baseband identification tag and binds the RFID tag to the MAC address of the RF unit. Then, the RFID tag is encrypted, and a successful verification message (message code 0x010B) containing the encrypted RFID tag is sent to the RF unit based on the MAC address. The encrypted RFID tag is placed in the Opcode-specific field.
[0107] After receiving the verification message, the radio frequency unit saves the encrypted radio frequency identification mark to complete the identity verification.
[0108] Optionally, the baseband unit will send a verification failure message (message code 0x010A) to the radio frequency unit when verification fails. Upon receiving the verification failure message, the radio frequency unit will resend an identity verification request message (message code 0x0107) to the baseband unit for re-authentication. Specifically, if the baseband unit's verification attempts exceed a preset threshold and the verification result is still a failure, the radio frequency unit will be prohibited from sending identity verification request messages to the baseband unit for a second preset time period, and the baseband unit will refuse to receive any messages sent by the radio frequency unit during this second preset time period.
[0109] Step S408: After receiving the authorization message, reply with a registration confirmation message to the baseband unit, wherein the authorization message includes at least the data transmission time slot allocated by the baseband unit to the radio frequency unit.
[0110] After successful authentication, the baseband unit sends an authorization message (message code 0x0102) to the radio frequency unit. The authorization message includes: the data transmission time slot allocated by the baseband unit to the radio frequency unit, the encrypted radio frequency identification identifier, and the multicast MAC address. The encrypted radio frequency identification identifier is added as a preamble to the multicast MAC address.
[0111] After receiving the authorization message, the radio frequency unit confirms that the encrypted radio frequency identification in the authorization message is the same as the encrypted radio frequency identification stored in the radio frequency unit, and then replies to the baseband unit with a registration confirmation message (message code 0x0106).
[0112] When the baseband unit receives a registration confirmation message from the destination radio frequency unit, it indicates that the destination radio frequency unit has been registered with the baseband unit.
[0113] Optionally, after registration, the radio frequency unit can send the target message stream to the baseband unit in the data transmission time slot; the baseband unit can receive the target message stream sent by the radio frequency unit in the data transmission time slot.
[0114] In this embodiment, the radio frequency unit is identified by an encrypted verification code, and the assigned radio frequency identification mark is also encrypted, which effectively ensures the security of the radio frequency unit registration process, thereby solving the technical problem of poor message interaction security between the baseband unit and the radio frequency unit when mobile broadband and fixed broadband are integrated.
[0115] Example 4
[0116] According to an embodiment of this application, a non-volatile storage medium is also provided, which includes a stored program, wherein the device containing the non-volatile storage medium executes the radio frequency unit registration method in embodiment 2 or embodiment 3 by running the program.
[0117] According to an embodiment of this application, a processor is also provided for running a program, wherein the program executes the radio frequency unit registration method in embodiment 2 or embodiment 3 during runtime.
[0118] According to an embodiment of this application, an electronic device is also provided, comprising: a memory and a processor, wherein the memory stores a computer program, and the processor is configured to execute the radio frequency unit registration method of embodiment 2 or embodiment 3 through the computer program.
[0119] Optionally, the program executes the following steps: sending a discovery message to the radio frequency unit in the fixed-mobile converged access terminal; after receiving the identity recognition request message sent by the radio frequency unit, sending a verification code message to the radio frequency unit, the verification code message including at least a first verification code generated and encrypted by the baseband unit; verifying the second verification code in the verification message replied by the radio frequency unit, and when the verification is successful, sending a verification success message to the radio frequency unit, the verification success message including at least a radio frequency identification identifier allocated and encrypted by the baseband unit for the radio frequency unit; sending an authorization message to the radio frequency unit, the authorization message including at least a data transmission time slot allocated by the baseband unit for the radio frequency unit; receiving a registration confirmation message replied by the radio frequency unit, and completing the registration of the radio frequency unit.
[0120] Optionally, the program executes the following steps: after receiving a discovery message from the baseband unit in the fixed-mobile converged access terminal, it sends an identity verification request message to the baseband unit; after receiving a verification code message, it replies with a verification message to the baseband unit, wherein the verification code message includes at least a first verification code generated and encrypted by the baseband unit, and the verification message includes at least a second verification code obtained by the radio frequency unit decrypting the encrypted first verification code; it receives a verification pass message to complete identity verification, wherein the verification pass message includes at least a radio frequency identification identifier allocated and encrypted by the baseband unit for the radio frequency unit; after receiving an authorization message, it replies with a registration confirmation message to the baseband unit, wherein the authorization message includes at least a data transmission time slot allocated by the baseband unit for the radio frequency unit.
[0121] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0122] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0123] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual couplings, direct couplings, or communication connections may be through some interfaces; indirect couplings or communication connections between units or modules may be electrical or other forms.
[0124] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0125] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0126] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.
[0127] The above are merely preferred embodiments of this application. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of this application, and these improvements and modifications should also be considered within the scope of protection of this application.
Claims
1. A fixed-mobile converged access terminal, characterized in that, include: The baseband unit and radio frequency unit for message interaction based on passive optical fiber networks, wherein: The baseband unit is configured to send a discovery message to the radio frequency unit; upon receiving an identity verification request message from the radio frequency unit, send a verification code message to the radio frequency unit, the verification code message including at least a first verification code generated and encrypted by the baseband unit; verify the second verification code in the verification message replied by the radio frequency unit, and upon successful verification, send a verification success message to the radio frequency unit, the verification success message including at least a radio frequency identification identifier allocated and encrypted by the baseband unit for the radio frequency unit; send an authorization message to the radio frequency unit, the authorization message including at least a data transmission time slot allocated by the baseband unit for the radio frequency unit; and receive a registration confirmation message replied by the radio frequency unit to complete the registration of the radio frequency unit. The radio frequency unit is configured to, upon receiving the discovery message, send the identity verification request message to the baseband unit; upon receiving the verification code message, reply to the baseband unit with the verification message, wherein the verification message includes at least the second verification code obtained by the radio frequency unit decrypting the encrypted first verification code; receive the verification passed message to complete identity verification; and upon receiving the authorization message, reply to the baseband unit with the registration confirmation message. The communication protocol used between the baseband unit and the radio frequency unit is an improved multipoint control protocol. In the improved multipoint control protocol, the type field value is 0x1008, and the opcodes include the opcodes corresponding to the following message types: 0x0101 for the PAUSE message, 0x0102 for the GATE message, 0x0103 for the REPORT message, 0x0104 for the REGISTER_REQ message, 0x0105 for the REGISTER message, 0x0106 for the REGISTER_ACK message, 0x0107 for the message of the radio frequency unit authenticating with the baseband unit, 0x0108 for the message of the baseband unit sending a verification code to the radio frequency unit, 0x0109 for the message of the radio frequency unit replying to the baseband unit with a verification code, 0x010A for the message of the baseband unit sending a message of authentication failure to the radio frequency unit, and 0x010B for the message of the baseband unit sending a newly allocated radio frequency unit identifier to the radio frequency unit.
2. The fixed-mobile converged access terminal according to claim 1, characterized in that, The discovery message includes at least the start time and length of the radio frequency unit discovery window; The baseband unit is used to periodically broadcast the discovery message to the radio frequency unit; The radio frequency unit is used to determine its own registration status after receiving the discovery message; When the radio frequency unit is not registered to the baseband unit, the identification request message is sent to the baseband unit at the start time of the radio frequency unit discovery window, wherein the identification request message includes at least the media access control address of the radio frequency unit.
3. The fixed-mobile converged access terminal according to claim 2, characterized in that, Both the baseband unit and the radio frequency unit include a pre-installed encryption component and a decryption component; The baseband unit is used to generate the first verification code after receiving the identity recognition request message, and to encrypt the first verification code using the encryption component. Send a verification code message containing the encrypted first verification code to the radio frequency unit; The radio frequency unit is configured to, upon receiving the verification code message, use the decryption component to decrypt the encrypted first verification code to obtain the second verification code; and reply to the baseband unit with the verification message containing the second verification code within a first preset time period.
4. The fixed-mobile converged access terminal according to claim 2, characterized in that, The baseband unit is configured to, upon receiving the verification message from the radio frequency unit, compare the second verification code with the first verification code; if the second verification code is the same as the first verification code, the verification is confirmed to be successful; if the second verification code is different from the first verification code, the verification is confirmed to be unsuccessful; if the verification is successful, the radio frequency identification identifier is generated based on the baseband identification identifier of the baseband unit, and the radio frequency identification identifier is bound to the media access control address. The RFID tag is encrypted, and an authentication pass message containing the encrypted RFID tag is sent to the radio frequency unit based on the media access control address; The radio frequency unit is used to save the encrypted radio frequency identification identifier after receiving the verification pass message, thereby completing the identity verification.
5. The fixed-mobile converged access terminal according to claim 4, characterized in that, The baseband unit is also used to send a verification failure message to the radio frequency unit when the verification fails. The radio frequency unit is also configured to resend the identity recognition request message to the baseband unit after receiving the verification failure message; Specifically, when the number of verification attempts by the baseband unit exceeds a preset threshold and the verification result is still "verification failed", the radio frequency unit is prohibited from sending the identity verification request message to the baseband unit for a second preset time period, and the baseband unit refuses to receive all messages sent by the radio frequency unit for the second preset time period.
6. The fixed-mobile converged access terminal according to claim 4, characterized in that, The authorization message also includes the encrypted radio frequency identification (RFID) identifier and the multicast media access control (MACC) address, wherein the encrypted RFID identifier is added as a preamble to the MACC address. The baseband unit is used to send the authorization message to the radio frequency unit; The radio frequency unit is configured to reply with the registration confirmation message to the baseband unit when it confirms that the encrypted radio frequency identification in the authorization message is the same as the encrypted radio frequency identification stored in the radio frequency unit.
7. The fixed-mobile converged access terminal according to claim 1, characterized in that, The radio frequency unit is also used to send a target message stream to the baseband unit in the data transmission time slot after registration is completed; The baseband unit is also configured to receive the target message stream transmitted by the radio frequency unit in the data transmission time slot.
8. A radio frequency unit registration method, applied to the baseband unit in the fixed-mobile converged access terminal according to any one of claims 1 to 7, characterized in that, include: Send a discovery message to the radio frequency unit in the fixed-mobile converged access terminal; After receiving the identity verification request message sent by the radio frequency unit, a verification code message is sent to the radio frequency unit, wherein the verification code message includes at least a first verification code generated and encrypted by the baseband unit; The second verification code in the verification message replied by the radio frequency unit is verified, and when the verification is successful, a verification success message is sent to the radio frequency unit. The verification success message includes at least the radio frequency identification identifier assigned and encrypted by the baseband unit for the radio frequency unit. Send an authorization message to the radio frequency unit, the authorization message including at least the data transmission time slot allocated by the baseband unit to the radio frequency unit; The registration of the radio frequency unit is completed by receiving the registration confirmation message from the radio frequency unit.
9. A radio frequency unit registration method, applied to a radio frequency unit in a fixed-mobile converged access terminal according to any one of claims 1 to 7, characterized in that, include: After receiving the discovery message sent by the baseband unit in the fixed-mobile converged access terminal, an identity recognition request message is sent to the baseband unit; After receiving the verification code message, a verification message is sent back to the baseband unit. The verification code message includes at least a first verification code generated and encrypted by the baseband unit, and the verification message includes at least a second verification code obtained by the radio frequency unit by decrypting the encrypted first verification code. Upon receiving a verification pass message, identity verification is completed, wherein the verification pass message includes at least a radio frequency identification identifier assigned and encrypted by the baseband unit for the radio frequency unit; Upon receiving the authorization message, the baseband unit replies with the registration confirmation message, wherein the authorization message includes at least the data transmission time slot allocated by the baseband unit to the radio frequency unit.
10. An electronic device, characterized in that, include: A memory and a processor, wherein the memory stores a computer program, and the processor is configured to execute the radio frequency unit registration method of claim 8 or 9 through the computer program.
Citation Information
Patent Citations
Equipment authentication method of Ethernet passive optical network (EPON) and system thereof
CN101662705A
Security registration method and equipment for implementing ONU in EPON
CN105592040A