Data transmission method and apparatus

By introducing a data transmission device into the broadband access network and using CPE and an optional second OLT for encryption encapsulation and decryption authentication, the problem of users being unable to access the internet during optical cable failures is solved, ensuring service continuity and data transmission security during failures.

CN115802214BActive Publication Date: 2025-12-02CHINA UNITED NETWORK COMM GRP CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211406204.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-10
Publication Date
2025-12-02
Estimated Expiration
2042-11-10

AI Technical Summary

Technical Problem

In existing troubleshooting methods, users are unable to access the internet during emergency repairs of faulty optical cables, resulting in the inability to process related services and causing adverse effects on users.

Method used

A data transmission device, including a first customer front-end equipment (CPE) and an optional second OLT, is introduced into the broadband access network to process the raw data packets of user terminals through encryption encapsulation and decryption authentication, and send them to the broadband access server through the base station to ensure uninterrupted communication during optical cable failures.

Benefits of technology

During fiber optic cable failures, users can continue to access the internet and communicate, ensuring the continuity of business processing. After the failure is resolved, the system switches back to the normal path, ensuring the security and reliability of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115802214B_ABST
    Figure CN115802214B_ABST
Patent Text Reader

Abstract

This application provides a data transmission method and apparatus, wherein the apparatus includes: a first Customer Pre-installation Equipment (CPE); if a fault occurs in the optical cable between the broadband access server and the first optical line terminal (OLT) in the broadband access network, the first CPE is used to obtain a first raw data packet sent by a user terminal from the first OLT, and to encrypt and encapsulate the first raw data packet to obtain a first encrypted data packet; the first CPE is also used to send the first encrypted data packet to the broadband access server through a base station, so that the broadband access server decrypts and authenticates the first encrypted data packet before sending it to the Internet. The method of this application solves the problem in existing fault-solving methods where users cannot access the Internet during emergency repairs of faulty optical cables.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a data transmission method and apparatus. Background Technology

[0002] Internet communication has broken the traditional geographical and spatial limitations on information transmission and interaction, enabling information to be transmitted to its destination quickly.

[0003] like Figure 1 As shown, the user's terminal 11 accesses the Internet through a broadband access network to achieve Internet communication. The network architecture of the broadband access network includes: an access gateway 12, an optical splitter 13, a first optical line terminal (OLT) 14, and a broadband access server 15. The access gateway 12 is like an optical modem. The user terminal 11 is connected to the access gateway 12 via wired or wireless connection. The access gateway 12 is connected to the optical splitter 13 via optical fiber. The first OLT 14 is connected to both the optical splitter 13 and the broadband access server 15 via optical fiber. The broadband access server 15 is connected to the Internet. If the optical fiber between the OLT 14 and the broadband access server 15 fails, the user terminal 11 will be unable to access the Internet. The current solution to this problem is for communication maintenance personnel to perform emergency repairs on the faulty optical fiber.

[0004] Existing troubleshooting methods have the problem that users cannot access the internet during emergency repairs of faulty optical cables, and services related to internet access cannot be processed, which adversely affects users' business operations. Summary of the Invention

[0005] This application provides a data transmission method and apparatus to solve the problem that existing fault solutions prevent users from accessing the internet during emergency repairs of faulty optical cables.

[0006] In a first aspect, this application provides a data transmission apparatus, the apparatus comprising: a first customer pre-installation device (CPE);

[0007] If the optical cable between the broadband access server and the first optical line terminal (OLT) in the broadband access network fails, the first CPE is used to obtain the first raw data packet sent by the user terminal from the first OLT and to encrypt and encapsulate the first raw data packet to obtain the first encrypted data packet.

[0008] The first CPE is further configured to send the first encrypted data packet to the broadband access server via a base station, so that the broadband access server decrypts and authenticates the first encrypted data packet before sending it to the Internet.

[0009] Optionally, the device further includes: a second OLT;

[0010] If the optical cable between the first OLT and the optical splitter in the broadband access network fails, the second OLT is used to obtain the first raw data packet sent by the user terminal from the optical splitter and send the first raw data packet to the first CPE.

[0011] The first CPE is used to encrypt and encapsulate the first original data packet to obtain a first encrypted data packet;

[0012] The first CPE is further configured to send the first encrypted data packet to the broadband access server via a base station, so that the broadband access server decrypts and authenticates the first encrypted data packet before sending it to the Internet.

[0013] Optionally, the device further includes: a first optical fiber disk;

[0014] The first fiber optic panel is used to connect the first CPE and the first OLT.

[0015] Optionally, the device further includes: a second fiber optic disk;

[0016] The second fiber optic disk is used to connect the second OLT and the splitter.

[0017] Optionally, the device further includes: a power supply component;

[0018] The power supply component is used to supply power to the device.

[0019] Secondly, this application provides a data transmission method applied to a data transmission device, the method comprising:

[0020] If the optical cable between the broadband access server and the first optical line terminal (OLT) in the broadband access network fails, the first customer front-end device (CPE) of the data transmission device obtains the first raw data packet sent by the user terminal from the first OLT and performs encryption and encapsulation processing on the first raw data packet to obtain the first encrypted data packet.

[0021] The first CPE sends the first encrypted data packet to the broadband access server through the base station, so that the broadband access server decrypts and authenticates the first encrypted data packet before sending it to the Internet.

[0022] Optionally, before the first customer front-end device (CPE) of the data transmission apparatus obtains the first raw data packet sent by the user terminal from the first OLT, the method further includes:

[0023] The first CPE receives a first fault message sent by the first OLT; the first fault message indicates that a fault has occurred in the optical cable between the first OLT and the broadband access server in the broadband access network.

[0024] Optionally, before the first CPE sends the first encrypted data packet to the broadband access server via the base station, the method further includes:

[0025] If the optical cable between the first OLT and the splitter in the broadband access network fails, the second OLT of the data transmission device obtains the first raw data packet sent by the user terminal from the splitter and sends the first raw data packet to the first CPE.

[0026] The first CPE performs encryption and encapsulation processing on the first original data packet to obtain the first encrypted data packet.

[0027] Optionally, before the second OLT of the data transmission device obtains the first raw data packet sent by the user terminal from the optical splitter, the method further includes:

[0028] The second OLT of the data transmission device receives a second fault message sent by the optical splitter; the second fault message indicates that a fault has occurred in the optical cable between the first OLT and the optical splitter in the broadband access network.

[0029] Optionally, after the first CPE sends the first encrypted data packet to the broadband access server via the base station, the method further includes:

[0030] The first CPE receives a second encrypted data packet sent by the broadband access server; the second encrypted data packet contains the identifier of the destination user terminal;

[0031] The first CPE performs decryption and authentication processing on the second encrypted data packet to obtain the second original data packet that has passed authentication;

[0032] The first CPE sends the second raw data packet to the first OLT or the second OLT of the data transmission device, so that the first OLT or the second OLT sends the second raw data packet to the destination user terminal through the optical splitter.

[0033] The data transmission method and apparatus provided in this application address the issue of optical cable failure between a broadband access server and a first optical line terminal (OLT) in a broadband access network. In this case, the first CPE of the data transmission apparatus obtains a first raw data packet sent by a user terminal from the first OLT, encrypts and encapsulates the raw data packet to obtain a first encrypted data packet, and then sends the encrypted data packet to the broadband access server via a base station. The broadband access server then decrypts and authenticates the encrypted data packet before sending it to the internet, ensuring that users can still access the internet during emergency repairs of faulty optical cables. This application solves the problem of existing fault-solving methods where users cannot access the internet during emergency repairs of faulty optical cables. Attached Figure Description

[0034] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0035] Figure 1 This is a network architecture diagram of the existing broadband access network;

[0036] Figure 2 Data transmission system architecture provided in the embodiments of this application Figure 1 ;

[0037] Figure 3 A flowchart illustrating the data transmission method provided in this application embodiment;

[0038] Figure 4 Data transmission system architecture provided in the embodiments of this application Figure 2 ;

[0039] Figure 5 Data transmission system architecture provided in the embodiments of this application Figure 3 .

[0040] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0041] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this invention, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0042] like Figure 1 As shown, the network architecture of the operator's broadband access network includes: access gateway 12, optical splitter 13, first optical line terminal (OLT) 14, and broadband access server 15. Access gateway 12 is like an optical modem. User terminal 11 is connected to access gateway 12 via wired or wireless connection. Access gateway 12 and optical splitter 13 can be deployed in the same building, and are connected in close proximity via optical fiber to achieve information exchange. Optical splitter 13 and first OLT 14, and first OLT 14 and broadband access server 15, are all connected remotely via optical fiber to achieve information exchange. Broadband access server 15 is connected to the Internet. The Internet is, for example, the Internet. Thus, user terminal 11 accesses the Internet through the broadband access network to achieve internet communication.

[0043] The optical cables between the splitter 13 and the first OLT 14, and between the first OLT 14 and the broadband access server 15, are typically laid underground or overhead. If the optical cable between the first OLT 14 and the broadband access server 15 fails, data packets sent by the user terminal 11 will not reach the broadband access server 15, and the user terminal 11 will be unable to access the internet. Optical cable failures can occur due to human factors (such as construction) or environmental factors (such as high temperatures or animal damage). Current solutions involve emergency repairs by communication maintenance personnel. Emergency repairs are time-consuming, typically taking at least an hour. During these repairs, users are unable to access the internet, and related services cannot be processed, negatively impacting user operations, especially for government and enterprise users.

[0044] To address the issue of existing fault-finding methods that prevent users from accessing the internet during emergency repairs of faulty optical cables, this application proposes a data transmission device. This device includes a first Customer Pre-Equipment (CPE). If a fault occurs in the optical cable between the broadband access server and the first Optical Line Terminal (OLT) in the broadband access network, the first CPE retrieves a first raw data packet sent by a user terminal from the first OLT and encrypts and encapsulates it to obtain a first encrypted data packet. The first CPE also transmits the first encrypted data packet to the broadband access server via a base station, enabling the broadband access server to decrypt and authenticate the first encrypted data packet before sending it to the internet, thus ensuring users can access the internet. This solves the problem of existing fault-finding methods that prevent users from accessing the internet during emergency repairs of faulty optical cables.

[0045] The data transmission apparatus provided in this application will be described below with reference to some embodiments.

[0046] Figure 2 Data transmission system architecture provided in the embodiments of this application Figure 1 .like Figure 2 As shown, the system includes: a user terminal 11, a broadband access network, the Internet, a data transmission device 21, and a base station 22. The broadband access network includes an access gateway 12, an optical splitter 13, a first OLT 14, and a broadband access server 15. The access gateway 12 can be an optical modem. The broadband access server 15 is, for example, a BRAS platform from an operator.

[0047] User terminal 11 is connected to access gateway 12 via wired or wireless means. Optical splitter 13 and access gateway 12 can be deployed in the same building, with optical splitter 13 and access gateway 12 connected via a short-range optical cable for information exchange. Optical splitter 13 is connected to the first OLT 14, and the first OLT 14 is connected to the broadband access server 15, both via remote optical cable connections for information exchange. The optical cables between optical splitter 13 and the first OLT 14, and between the first OLT 14 and the broadband access server 15, can be laid underground or overhead. Broadband access server 15 is connected to the Internet.

[0048] The data transmission device 21 includes a first Customer Premise Equipment (CPE) 211. If a fault occurs in the optical cable between the broadband access server 15 and the first OLT 14 in the broadband access network, the first CPE 211 is used to obtain a first raw data packet sent by the user terminal 11 from the first OLT 14, and to encrypt and encapsulate the first raw data packet to obtain a first encrypted data packet. The first CPE 211 is also used to send the first encrypted data packet to the broadband access server 15 via the base station 22, so that the broadband access server 15 can decrypt and authenticate the first encrypted data packet before sending it to the Internet, thereby enabling the user terminal 11 to access the Internet and solve the problem of users being unable to access the Internet during emergency repairs of the faulty optical cable when a fault occurs between the broadband access server 15 and the first OLT 14, ensuring that users can continue their business normally during the repair process.

[0049] For example, after receiving the first encrypted data packet sent by the first CPE 211, the broadband access server 15 performs decryption and authentication processing on the first encrypted data packet to obtain the first original data packet that has passed authentication. The broadband access server 15 then sends the first original data packet that has passed authentication to the Internet to enable the user terminal 11 to access the Internet.

[0050] The first CPE encrypts and encapsulates the first raw data packet sent by the user terminal, and then sends the encrypted data packet to the broadband access server through the base station. This ensures the data security of the first raw data packet sent by the user terminal during wireless transmission while enabling the user to access the Internet.

[0051] For example, the data transmission device 21 can be pre-deployed with the first OLT 14. Alternatively, after a failure in the optical cable between the broadband access server 15 and the first OLT 14 in the broadband access network, the data transmission device 21 can be manually deployed near the first OLT 14 in a timely manner. Preferably, before a failure occurs in the optical cable between the broadband access server 15 and the first OLT 14 in the broadband access network, the data transmission device 21 is pre-deployed with the first OLT 14 so that after a failure in the optical cable between the broadband access server 15 and the first OLT 14, the user's internet communication can be quickly restored through the data transmission device 21, ensuring the user's service processing.

[0052] Optionally, such as Figure 2 As shown, the data transmission device 21 also includes a second OLT 212. If the optical cable between the first OLT 14 and the splitter 13 in the broadband access network fails, the second OLT 212 is used to obtain the first raw data packet sent by the user terminal 11 from the splitter 13 and send the first raw data packet to the first CPE 211. The first CPE 211 is used to encrypt and encapsulate the first raw data packet to obtain a first encrypted data packet. The first CPE 211 is also used to send the first encrypted data packet to the broadband access server 15 through the base station 22, so that the broadband access server 15 can decrypt and authenticate the first encrypted data packet and send it to the Internet, thereby enabling the user corresponding to the user terminal 11 to access the Internet. This can solve the problem of users being unable to access the Internet during emergency repair of the faulty optical cable when the optical cable between the broadband access server 15 and the first OLT 14 fails, and / or when the optical cable between the first OLT 14 and the splitter 13 fails, ensuring that users can access the Internet and perform business processing normally during the repair of the faulty optical cable.

[0053] For example, the data transmission device 21 can be pre-deployed with the optical splitter 13. Alternatively, the data transmission device 21 can be manually deployed near the optical splitter 13 promptly after a failure occurs in the optical cable between the first OLT 14 and the optical splitter 13 in the broadband access network, and / or after a failure occurs in the optical cable between the broadband access server 15 and the first OLT 14. Preferably, the data transmission device 21 can be pre-deployed with the optical splitter 13 before a failure occurs in the optical cable between the first OLT 14 and the optical splitter 13 in the broadband access network, and / or before a failure occurs in the optical cable between the broadband access server 15 and the first OLT 14. This ensures that after a failure occurs in the optical cable between the first OLT 14 and the optical splitter 13, and / or after a failure occurs in the optical cable between the broadband access server 15 and the first OLT 14, the user can quickly access the internet through the data transmission device 21, ensuring user service processing and improving the user's network experience.

[0054] Optionally, such as Figure 2 As shown, the data transmission device 21 also includes a first optical fiber disk 213. The first optical fiber disk 213 is used to connect the first CPE 211 and the first OLT 14, so that the first CPE 211 and the first OLT 14 are connected by optical fiber to ensure fast information exchange between the first CPE 211 and the first OLT 14, and to ensure the security of data transmission between the first CPE 211 and the first OLT 14.

[0055] Optionally, such as Figure 2 As shown, the data transmission device 21 also includes a second fiber optic disk 214. The second fiber optic disk 214 is used to connect the second OLT 212 and the optical splitter 13, so that the second OLT 212 and the optical splitter 13 are connected by optical fiber to ensure fast information exchange between the second OLT 212 and the optical splitter 13, and to ensure the security of data transmission between the second OLT 212 and the optical splitter 13.

[0056] Optionally, such as Figure 2 As shown, the data transmission device 21 also includes a power supply component 215. The power supply component 215 is used to supply power to the data transmission device 21. For example, the power supply component 215 can be used to supply power to the first CPE 211 and the second OLT 212 of the data transmission device 21. Optionally, the power supply component 215 can be a portable power source with energy storage function.

[0057] The data transmission device provided in this application includes a first CPE, a second OLT, a first fiber optic disk, a second fiber optic disk, and a power supply component. In the event of a fault in the optical cable between the broadband access server and the first OLT, the first CPE obtains a first raw data packet sent by a user terminal from the first OLT, encrypts and encapsulates the first raw data packet, and then sends the encrypted first data packet to the broadband access server via a base station. The broadband access server decrypts and authenticates the first encrypted data packet before sending the obtained first raw data packet to the Internet, thus enabling the user terminal to access the Internet. In the event of a fault in the optical cable between the first OLT and the splitter in the broadband access network, and / or a fault in the optical cable between the broadband access server and the first OLT, the second OLT obtains a first raw data packet sent by a user terminal from the splitter and sends it to the first CPE. The first CPE encrypts and encapsulates the first raw data packet and then sends the obtained first encrypted data packet to the broadband access server via a base station. The broadband access server decrypts and authenticates the first encrypted data packet before sending the obtained first raw data packet to the Internet, thus enabling the user terminal to access the Internet. The data transmission device provided in this embodiment solves the problem that users cannot access the Internet during emergency repairs of faulty optical cables when the optical cable between the broadband access server and the first OLT in the broadband access network fails, and / or the optical cable between the first OLT and the splitter fails. This ensures that users can still perform business processing normally during emergency repairs of faulty optical cables.

[0058] This application embodiment also provides a data transmission method, which is applied to, for example... Figure 2 The data transmission device 21 shown below. (The following is in conjunction with...) Figure 2 , Figure 3 , Figure 4 The data transmission method provided in this application is described. Figure 3 A flowchart illustrating the data transmission method provided in this application embodiment. Figure 4 Data transmission system architecture provided in the embodiments of this application Figure 2 . Figure 3 The execution entity of the illustrated embodiment can be Figure 2 or Figure 4 The data transmission device 21 in the illustrated embodiment. For example... Figure 3 As shown, the method includes:

[0059] S101. If the optical cable between the broadband access server 15 and the first optical line terminal (OLT) 14 in the broadband access network fails, the first customer front-end equipment (CPE) 211 of the data transmission device 21 obtains the first raw data packet sent by the user terminal 11 from the first OLT 14, and performs encryption and encapsulation processing on the first raw data packet to obtain the first encrypted data packet.

[0060] Optionally, before the first customer front-end equipment (CPE) 211 of the data transmission device 21 obtains the first raw data packet sent by the user terminal 11 from the first OLT 14, the first CPE 211 receives a first fault message sent by the first OLT 14. The first fault message indicates that a fault has occurred in the optical cable between the first OLT 14 and the broadband access server 15 in the broadband access network.

[0061] Optionally, the first fault message may be a fault message generated by the fault monitoring module built into the first OLT 14, which detects a fault in the optical cable between the first OLT 14 and the broadband access server 15. Optionally, such as... Figure 4 As shown, the first fault message can also be a fault message sent to the first OLT 14 by the fault monitoring device 31 after it detects a fault in the optical cable between the first OLT 14 and the broadband access server 15.

[0062] Optionally, the first raw data packet includes the identifier of the user terminal 11. After the first CPE 211 obtains the first raw data packet sent by the user terminal 11 from the first OLT 14, the first CPE 211 determines the tunnel identifier corresponding to the identifier of the user terminal 11. The first CPE 211 determines the encryption encapsulation configuration corresponding to the tunnel identifier. The first CPE 211 uses the encryption encapsulation configuration corresponding to the tunnel identifier to encrypt and encapsulate the first raw data packet, obtaining the first encrypted data packet. Here, the tunnel is a communication channel established in advance after tunnel configuration is performed on the first CPE 211 and the broadband access server 15 respectively. For example, as shown... Figure 4 As shown, the tunnel can be a communication channel established by the Software-Defined Networking (SDN) controller 32 after pre-configuring tunnels on the first CPE 211 and the broadband access server 15 respectively. For example, the SDN controller 32 pre-configures tunnels on the first CPE 211 and the broadband access server 15 respectively through the base station 22 to establish a tunnel (or communication channel) between the first CPE 211 and the broadband access server 15. Alternatively, the tunnel can be a communication channel established by manually configuring tunnels on the first CPE 211 and the broadband access server 15 respectively.

[0063] Alternatively, the tunnel can be a tunnel established using Virtual Extended Local Area Network (VxLAN) tunneling technology or a tunnel established using Internet Protocol Security (IPSec) tunneling technology.

[0064] One tunnel corresponds to one tunnel configuration. A tunnel configuration includes encryption and encapsulation configuration and decryption and authentication configuration. The two ends of the tunnel are the first CPE 211 and the broadband access server 15, respectively. The tunnel configurations on the first CPE 211 and the broadband access server 15 within the same tunnel are identical. The decryption and authentication configuration is used to perform decryption and authentication processing on encrypted data packets to obtain either authenticated decrypted data packets or original data packets.

[0065] S102, the first CPE 211 sends the first encrypted data packet to the broadband access server 15 through the base station 22, so that the broadband access server 15 decrypts and authenticates the first encrypted data packet and sends it to the Internet.

[0066] For example, the first CPE 211 sends the first encrypted data packet to the broadband access server 15 through the tunnel between the first CPE 211 and the broadband access server 15, so that the broadband access server 15 performs decryption authentication processing on the first encrypted data packet using the decryption authentication configuration corresponding to the tunnel, and then sends the obtained authenticated first decrypted data packet or first original data packet to the Internet.

[0067] The first CPE encrypts and encapsulates the first original data packet, and sends the encrypted first data packet to the broadband access server through the base station, or through the tunnel between the first CPE and the broadband access server. The broadband access server 15 then decrypts and authenticates the first encrypted data packet, and sends the authenticated first decrypted data packet or the first original data packet to the Internet. This not only enables users to access the Internet, but also ensures the security of data transmission between the user terminal and the broadband access server.

[0068] Optionally, before the first CPE 211 sends the first encrypted data packet to the broadband access server 15 via the base station 22, if a fault occurs in the optical cable between the first OLT 14 and the optical splitter 13 in the broadband access network, the second OLT 212 of the data transmission device 21 obtains the first raw data packet sent by the user terminal 11 from the optical splitter 13 and sends the first raw data packet to the first CPE 211. The first CPE 211 performs encryption and encapsulation processing on the first raw data packet to obtain the first encrypted data packet.

[0069] For example, after receiving the first raw data packet sent by the second OLT 212, the first CPE 211 determines the tunnel identifier corresponding to the identifier of the user terminal 11. The first CPE 211 determines the encryption encapsulation configuration corresponding to the tunnel identifier. The first CPE 211 uses the encryption encapsulation configuration corresponding to the tunnel identifier to encrypt and encapsulate the first raw data packet to obtain an encrypted data packet.

[0070] Optionally, before the second OLT 212 of the data transmission device 21 obtains the first raw data packet sent by the user terminal 11 from the optical splitter 13, the second OLT 212 of the data transmission device 21 receives a second fault message sent by the optical splitter 13. The second fault message indicates that a fault has occurred in the optical cable between the first OLT 14 and the optical splitter 13 in the broadband access network.

[0071] Optionally, the second fault message can be a fault message generated by the fault monitoring module built into the optical splitter 13, which detects a fault in the optical cable between the first OLT 14 and the optical splitter 13. Optionally, such as... Figure 4 As shown, the second fault message can also be a fault message sent to the optical splitter 13 by the fault monitoring device 31 after it detects a fault in the optical cable between the first OLT 14 and the optical splitter 13.

[0072] Optionally, after the first CPE 211 sends the first encrypted data packet to the broadband access server 15 via the base station 22, the first CPE 211 receives the second encrypted data packet sent by the broadband access server 15. The second encrypted data packet contains the identifier of the destination user terminal 11. The first CPE 211 performs decryption and authentication processing on the second encrypted data packet to obtain an authenticated second original data packet or a second decrypted data packet. The first CPE 211 sends the second original data packet to the first OLT 14 or the second OLT 212 of the data transmission device 21, so that the first OLT 14 or the second OLT 212 sends the second original data packet to the destination user terminal 11 via the optical splitter 13. The second encrypted data packet is obtained by the broadband access server 15 after encrypting and encapsulating the second original data packet obtained from the Internet.

[0073] The second original data packet can be a data packet returned by the destination user terminal 11 of the first original data packet. The second original data packet contains the sender identifier and the receiver identifier. The sender identifier can be the identifier of the user terminal 11 that sent the data packet. The receiver identifier can be the identifier of the destination user terminal 11 of the data packet. The second encrypted data packet also contains the sender identifier and the receiver identifier of the second original data packet. The tunnel corresponding to the sender identifier and the tunnel corresponding to the receiver identifier in the same data packet are the same tunnel.

[0074] For example, after the broadband access server 15 obtains the second raw data packet from the Internet, it can encrypt and encapsulate the second raw data packet using the encryption encapsulation configuration corresponding to the tunnel identified by the sender of the second raw data packet, thus obtaining a second encrypted data packet. The broadband access server 15 sends the second encrypted data packet to the first CPE 211 through the tunnel between the first CPE 211 and the broadband access server 15. The first CPE 211 performs decryption and authentication processing on the second encrypted data packet, thus obtaining an authenticated second raw data packet. For example, the first CPE 211 performs decryption and authentication processing on the second encrypted data packet using the decryption and authentication configuration corresponding to the tunnel identified by the receiver, thus obtaining an authenticated second decrypted data packet or a second raw data packet. The first CPE 211 sends the second raw data packet to the first OLT 14 or the second OLT 212, so that the first OLT 14 or the second OLT 212 sends the second raw data packet to the destination user terminal 11 of the second raw data packet through the optical splitter 13.

[0075] Optionally, after the first CPE 211 sends the first encrypted data packet to the broadband access server 15 through the base station 22, if the first CPE 211 receives the first fault recovery message sent by the first OLT 14, the first CPE 211 sends a first confirmation message to the first OLT 14 and stops obtaining the first raw data packet sent by the user terminal 11 from the first OLT 14, so that the user terminal 11 can communicate via broadband internet through the broadband access network.

[0076] Optionally, after the first CPE 211 sends the first encrypted data packet to the broadband access server 15 through the base station 22, if the second OLT 212 receives the second fault recovery message sent by the optical splitter 13, the second OLT 212 sends a second confirmation message to the optical splitter 13 and stops obtaining the first raw data packet sent by the user terminal 11 from the optical splitter 13, so that the user terminal 11 can conduct broadband Internet communication through the broadband access network.

[0077] The data transmission method provided in this application embodiment is applied to a data transmission device. When a fault occurs in the optical cable between the broadband access server and the first OLT, the first CPE of the data transmission device obtains a first raw data packet sent by the user terminal from the first OLT, encrypts and encapsulates the first raw data packet, and then sends the encrypted first data packet to the broadband access server via a base station, or via a tunnel between the first CPE and the broadband access server, to enable internet communication for the user terminal and ensure the security of data transmission between the user terminal and the internet. When a fault occurs in the optical cable between the first OLT and the splitter in the broadband access network, and / or in the optical cable between the broadband access server and the first OLT, the second OLT of the data transmission device obtains a first raw data packet sent by the user terminal from the splitter and sends the first raw data packet to the first CPE. The first CPE encrypts and encapsulates the first raw data packet and then sends the encrypted first data packet to the broadband access server via a base station, or via a tunnel between the first CPE and the broadband access server, to enable internet communication for the user terminal and ensure the security of data transmission between the user terminal and the internet. The data transmission device provided in this embodiment solves the problem that existing fault solutions prevent users from accessing the internet during emergency repairs of faulty optical cables when the optical cable between the broadband access server and the first OLT fails, and / or the optical cable between the first OLT and the splitter fails. This ensures that users can continue to process services normally during emergency repairs of faulty optical cables while guaranteeing data transmission security.

[0078] This application also provides a data transmission system. Figure 5 Data transmission system architecture provided in the embodiments of this application Figure 3 .like Figure 5 As shown, the system includes: an access gateway 12, an optical splitter 13, a first OLT 14, a broadband access server 15, a first data transmission device 41, a second data transmission device 42, a fault monitoring device 31, an SDN controller 32, and a base station 22. The first data transmission device 41 includes a first fiber optic panel 411, a first CPE 412, and a power supply unit 413. The second data transmission device 42 includes a second fiber optic panel 421, a second OLT 422, a power supply unit 423, and a second CPE 424. The access gateway 12 can be an optical modem. The broadband access server 15 is, for example, a carrier's BRAS platform. The second CPE 424 can be the first CPE 412. The power supply unit 413 and the power supply unit 423 can be the same.

[0079] User terminal 11 accesses the Internet through the data transmission system provided in this application. Specifically, user terminal 11 is connected to access gateway 12 via wired or wireless means. Optical splitter 13 and access gateway 12 are connected via a short-range optical cable for information exchange. Optical splitter 13 and first OLT 14, and first OLT 14 and broadband access server 15 are connected via remote optical cables for information exchange. The optical cables between optical splitter 13 and first OLT 14, and between first OLT 14 and broadband access server 15, can be laid underground or overhead. Broadband access server 15 is connected to the Internet. First data transmission device 41 is deployed together with first OLT 14. First OLT 14 and first CPE 412 are connected via optical fiber through first optical fiber tray 411. First CPE 412 is connected to power supply unit 413. Second data transmission device 42 is deployed together with optical splitter 13. Optical splitter 13 and second OLT 422 are connected via optical fiber through second optical fiber tray 421. The second OLT 422 is connected to the second CPE 424. The second OLT 422 and the second CPE 424 are respectively connected to the power supply unit 423. The SDN controller 32 pre-configures tunnels on the first CPE 412 and the broadband access server 15, establishing a communication channel between them. The SDN controller 32 can also pre-configure tunnels on the second CPE 424 and the broadband access server 15, establishing a communication channel between them. The tunnels between the first CPE 412 and the broadband access server 15, and between the second CPE 424 and the broadband access server 15, are both established through the base station 22.

[0080] The fault monitoring device 31 monitors the communication link between the optical splitter 13, the first OLT 14, and the broadband access server 15.

[0081] If the fault monitoring device 31 detects a fault in the optical cable between the first OLT 14 and the broadband access server 15, the fault monitoring device 31 sends a first fault message to the first OLT 14. The first OLT 14 sends the first fault message to the first CPE 412 via the first fiber optic disk 411. The first CPE 412 obtains the first raw data packet sent by the user terminal 11 from the first OLT 14. The first raw data packet contains the identifier of the user terminal 11. The first CPE 412 uses the encryption encapsulation configuration of the tunnel corresponding to the identifier of the user terminal 11 to encrypt and encapsulate the first raw data packet, obtaining a first encrypted data packet. The first CPE 412 sends the first encrypted data packet to the broadband access server 15 corresponding to the tunnel through the identifier of the user terminal 11. The broadband access server 15 uses the decryption authentication configuration of the tunnel corresponding to the identifier of the user terminal 11 in the first encrypted data packet to decrypt and authenticate the first encrypted data packet, obtaining an authenticated first decrypted data packet or a first raw data packet. Broadband access server 15 sends the first raw data packet to the Internet to enable the user terminal 11 to maintain normal Internet communication even if the optical cable between the first OLT 14 and broadband access server 15 fails. Specifically, broadband access server 15 sends the first raw data packet to its destination on the Internet based on the destination identifier in the first raw data packet. The destination identifier can be the address of the destination user terminal 11 that receives the first raw data packet.

[0082] If the fault monitoring device 31 detects a fault in the optical cable between the first OLT 14 and the optical splitter 13, the fault monitoring device 31 sends a second fault message to the optical splitter 13. The optical splitter 13 sends the second fault message to the second OLT 422 via the second fiber optic disk 421. The second OLT 422 obtains the first raw data packet sent by the user terminal 11 from the optical splitter 13 and sends the first raw data packet to the second CPE 424. The second CPE 424 uses the encryption encapsulation configuration of the tunnel corresponding to the identifier of the user terminal 11 in the first raw data packet to encrypt and encapsulate the first raw data packet, obtaining a first encrypted data packet. The second CPE 424 sends the first encrypted data packet to the broadband access server 15 corresponding to the tunnel through the identifier of the user terminal 11. The broadband access server 15 uses the decryption authentication configuration of the tunnel corresponding to the identifier of the user terminal 11 in the first encrypted data packet to decrypt and authenticate the first encrypted data packet, obtaining an authenticated first decrypted data packet or a first raw data packet. The broadband access server 15 sends the first raw data packet to the Internet so that the user terminal 11 can still communicate normally online even if the optical cable between the first OLT 14 and the splitter 13 fails.

[0083] Optionally, after the faulty optical cable is restored to normal, if the fault monitoring device 31 detects that the optical cable between the first OLT 14 and the broadband access server 15 is fault-free, the fault monitoring device 31 sends a first fault recovery message to the first OLT 14. The first OLT 14 sends the first fault recovery message to the first CPE 412 through the first fiber optic disk 411. After receiving the first fault recovery message, the first CPE 412 stops acquiring the first raw data packet sent by the user terminal 11 from the first OLT 14, and sends a first tunnel closure message to the broadband access server 15 through the tunnel between the first CPE 412 and the broadband access server 15.

[0084] Optionally, after fault recovery, if the fault monitoring device 31 detects no fault in the optical cable between the splitter 13 and the first OLT 14, the fault monitoring device 31 sends a second fault recovery message to the splitter 13. The splitter 13 sends the second fault recovery message to the second OLT 422 via the second fiber optic disk 421. Upon receiving the second fault recovery message, the second OLT 422 stops acquiring the first raw data packet sent by the user terminal 11 from the splitter 13 and sends the second fault recovery message to the second CPE 424. Based on the second fault recovery message, the second CPE 424 sends a second tunnel closure message to the broadband access server 15 through the tunnel between the second CPE 424 and the broadband access server 15.

[0085] Optionally, after the faulty optical cable is restored to normal, if the first OLT 14 receives the first fault recovery message, it will send the first raw data packet sent by the user terminal 11 to the broadband access server 15 to realize broadband Internet communication for the user corresponding to the user terminal 11.

[0086] Optionally, after the faulty optical cable is restored to normal, if the splitter 13 receives the second fault recovery message sent by the fault monitoring device 31, it will send the first raw data packet sent by the user terminal 11 to the first OLT 14, so that the first OLT 14 will send the received first raw data packet to the broadband access server 15, thereby realizing broadband Internet communication for the user corresponding to the user terminal 11.

[0087] The specific implementation principle and technical effects of the data transmission system provided in this embodiment are similar to those of... Figure 3 The specific implementation principles and technical effects of the embodiments shown are similar, and will not be repeated here.

[0088] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A data transmission device, characterized in that, The device includes: a first customer pre-installation equipment (CPE); If the optical cable between the broadband access server and the first optical line terminal (OLT) in the broadband access network fails, the first customer front-end equipment (CPE) is used to obtain the first raw data packet sent by the user terminal from the first optical line terminal (OLT) and to encrypt and encapsulate the first raw data packet to obtain the first encrypted data packet. The first customer pre-installed device (CPE) is also used to send the first encrypted data packet to the broadband access server via the base station, so that the broadband access server can decrypt and authenticate the first encrypted data packet and then send it to the Internet. The first raw data packet contains the identifier of the user terminal, and the first customer front-end device (CPE) is further used for: After obtaining the first raw data packet sent by the user terminal from the first optical line terminal (OLT), the tunnel identifier corresponding to the identifier of the user terminal is determined; Determine the encryption encapsulation configuration corresponding to the tunnel identifier; The first original data packet is encrypted and encapsulated using the encryption and encapsulation configuration corresponding to the tunnel identifier used, to obtain the first encrypted data packet; wherein, the tunnel is a communication channel established in advance by the software-defined network (SDN) controller through the base station on the first customer front-end device (CPE) and the broadband access server respectively after tunnel configuration, and the tunnel configuration includes the encryption and encapsulation configuration and the decryption and authentication configuration; The broadband access server is further configured to: perform decryption and authentication processing on the first encrypted data packet using the decryption and authentication configuration corresponding to the tunnel identifier, and then send the obtained authenticated first decrypted data packet or first original data packet to the Internet.

2. The apparatus according to claim 1, characterized in that, The device further includes: a second optical line terminal (OLT); If the optical cable between the first optical line terminal (OLT) and the optical splitter in the broadband access network fails, the second optical line terminal (OLT) is used to obtain the first raw data packet sent by the user terminal from the optical splitter and send the first raw data packet to the first customer front-end equipment (CPE). The first customer front-end device (CPE) is used to encrypt and encapsulate the first original data packet to obtain a first encrypted data packet. The first customer pre-installed device (CPE) is also used to send the first encrypted data packet to the broadband access server via the base station, so that the broadband access server can decrypt and authenticate the first encrypted data packet before sending it to the Internet.

3. The apparatus according to claim 1, characterized in that, The device further includes: a first optical fiber disk; The first fiber optic panel is used to connect the first customer front-end equipment (CPE) and the first optical line terminal (OLT).

4. The apparatus according to claim 2, characterized in that, The device further includes: a second optical fiber disk; The second fiber optic disk is used to connect the second optical line terminal (OLT) and the splitter.

5. The apparatus according to any one of claims 1-4, characterized in that, The device further includes: a power supply component; The power supply component is used to supply power to the device.

6. A data transmission method, characterized in that, Applied to a data transmission device, the method includes: If the optical cable between the broadband access server and the first optical line terminal (OLT) in the broadband access network fails, the first customer front-end device (CPE) of the data transmission device obtains the first raw data packet sent by the user terminal from the first optical line terminal (OLT) and performs encryption and encapsulation processing on the first raw data packet to obtain the first encrypted data packet. The first customer pre-installed device (CPE) sends the first encrypted data packet to the broadband access server via the base station, so that the broadband access server decrypts and authenticates the first encrypted data packet before sending it to the Internet. Wherein, the first original data packet contains the identifier of the user terminal, and the method further includes: After the first customer front-end equipment (CPE) obtains the first raw data packet sent by the user terminal from the first optical line terminal (OLT), it determines the tunnel identifier corresponding to the identifier of the user terminal. The first customer front-end device (CPE) determines the encryption encapsulation configuration corresponding to the tunnel identifier; The first customer front-end device (CPE) uses the encryption encapsulation configuration corresponding to the tunnel identifier to encrypt and encapsulate the first original data packet to obtain the first encrypted data packet; wherein, the tunnel is a communication channel established in advance by the software-defined network (SDN) controller through the base station on the first customer front-end device (CPE) and the broadband access server respectively after tunnel configuration, and the tunnel configuration includes the encryption encapsulation configuration and the decryption authentication configuration. The broadband access server is further configured to: perform decryption and authentication processing on the first encrypted data packet using the decryption and authentication configuration corresponding to the tunnel identifier, and then send the obtained authenticated first decrypted data packet or first original data packet to the Internet.

7. The method according to claim 6, characterized in that, Before the first customer front-end equipment (CPE) of the data transmission device obtains the first raw data packet sent by the user terminal from the first optical line terminal (OLT), the method further includes: The first customer front-end equipment (CPE) receives a first fault message sent by the first optical line terminal (OLT); the first fault message indicates that a fault has occurred in the optical cable between the first optical line terminal (OLT) and the broadband access server in the broadband access network.

8. The method according to claim 6, characterized in that, Before the first customer front-end device (CPE) sends the first encrypted data packet to the broadband access server via the base station, the method further includes: If the optical cable between the first optical line terminal (OLT) and the optical splitter in the broadband access network fails, the second optical line terminal (OLT) of the data transmission device obtains the first raw data packet sent by the user terminal from the optical splitter and sends the first raw data packet to the first customer front-end equipment (CPE). The first customer pre-installation device (CPE) performs encryption and encapsulation processing on the first original data packet to obtain the first encrypted data packet.

9. The method according to claim 8, characterized in that, Before the second optical line terminal (OLT) of the data transmission device obtains the first raw data packet sent by the user terminal from the optical splitter, the method further includes: The second optical line terminal (OLT) of the data transmission device receives a second fault message sent by the optical splitter; the second fault message indicates that a fault has occurred in the optical cable between the first optical line terminal (OLT) and the optical splitter in the broadband access network.

10. The method according to any one of claims 6-9, characterized in that, After the first customer pre-installed device (CPE) sends the first encrypted data packet to the broadband access server via the base station, the method further includes: The first customer pre-installation device (CPE) receives a second encrypted data packet sent by the broadband access server; the second encrypted data packet contains the identifier of the destination user terminal. The first customer pre-installation device (CPE) decrypts and authenticates the second encrypted data packet to obtain the authenticated second original data packet. The first customer pre-installation equipment (CPE) sends the second raw data packet to the first optical line terminal (OLT) or the second optical line terminal (OLT) of the data transmission device, so that the first or second OLT sends the second raw data packet to the destination user terminal via a splitter.

Citation Information

Patent Citations

  • Method, system and device for realizing passive optical network optical fiber protection

    CN101867411A

  • Intelligent switching system for power optical fiber private network and 5G public network

    CN113517940A