An 802.1X access control method based on ONU

By adopting the ONU-based 802.1X access control method in the PON passive optical network system, the network bandwidth occupation problem caused by excessive rough or fine management in the prior art is solved, and more detailed network access control and bandwidth management are achieved.

CN117353819BActive Publication Date: 2025-05-16SHENZHEN C-DATA TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202311317110.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-10-11
Publication Date
2025-05-16
Estimated Expiration
2043-10-11

AI Technical Summary

Technical Problem

The existing 802.1X protocol is too rough or finely managed in the PON passive optical network system, resulting in the network bandwidth being occupied by a large number of users at the same time to initiate access request packets.

Method used

The 802.1X access control method based on ONU is adopted, and the remote RADIUS server IP address information and the 802.1x access control method are configured on the OLT as ONU access control, and the 802.1x function is enabled on the OLT, so that user authentication and dynamic management of service channels are realized.

Benefits of technology

In the PON passive optical network system, the network access control with a granularity between the port and the MAC is realized, reducing the access request packets initiated by a large number of users at the same time, and avoiding the problem of network bandwidth occupied.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117353819B_ABST
    Figure CN117353819B_ABST
Patent Text Reader

Abstract

The present invention discloses an 802.1X access control method based on ONU, relates to the technical field of communication equipment, and includes a message interaction process and the following implementation steps, step one: configure remote RADIUS server IP address information on OLT, step two: configure 802.1x access control mode on OLT as ONU-based access control, step three: enable 802.1x function on OLT, so that protocol data message can be sent to CPU for processing, step four: user opens 802.1X client program, inputs applied user name and password, initiates authentication request to OLT, step five: OLT sends user information to remote RADIUS authentication server for authentication. The present invention discloses an 802.1X access control method based on ONU, and its control granularity is between port and MAC, which can not only meet the application scenario of network access control with ONU as the object in PON passive optical network system, but also solve the problem of a large number of users initiating access request messages at the same time and solving the problem of network bandwidth being occupied.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of communication equipment, and in particular to an 802.1X access control method based on ONU. Background Art

[0002] The 802.1X protocol is an access control and authentication protocol based on Client / Sever. 802.1X authenticates users or devices connected to the switch port. Before the authentication is passed, 802.1X only allows EAPOL (Extended Authentication Protocol over LAN) data to pass through the device to connect to the switch port. After the authentication is passed, the business data can pass through the Ethernet port.

[0003] On existing switch devices, the 802.1X protocol generally only provides two access control methods: port-based and MAC-based. For the PON port-based access control method, once the authentication is passed, all users under the port can access the network, and the management is too rough. For the MAC-based access control method, the management is too fine, and there may be a large number of users initiating access request messages at the same time, occupying the network bandwidth.

[0004] Therefore, a new ONU-based 802.1X access control method is proposed to solve the above problems. Summary of the invention

[0005] The main purpose of the present invention is to provide an 802.1X access control method based on ONU to solve the problems raised in the above background.

[0006] To achieve the above object, the technical solution adopted by the present invention is: an 802.1X access control method based on ONU, the method comprising a message interaction process and the following implementation steps:

[0007] Step 1: Configure the remote RADIUS server IP address information on the OLT;

[0008] Step 2: Configure the 802.1x access control mode on the OLT to be based on ONU access control;

[0009] Step 3: Enable the 802.1x function on the OLT so that protocol data packets can be sent to the CPU for processing;

[0010] Step 4: The user opens the 802.1X client program, enters the username and password that have been applied for, and initiates an authentication request to the OLT;

[0011] Step 5: OLT sends user information to the remote RADIUS authentication server for authentication;

[0012] Step 6: The remote RADIUS authentication server compares the received user information with the user name in the database. If they are consistent, it sends an authentication success message to the OLT. Otherwise, it sends an authentication failure message to the OLT.

[0013] Step 7: Determine whether the authentication is successful. If the OLT device receives the authentication success message, it sends an authentication success message to the client program and opens the service channel of the ONU where the user is located, allowing the user's service flow to access the network through the ONU. Otherwise, keep the ONU service channel closed and only allow authentication information data to pass, but not service data.

[0014] The message interaction process is as follows:

[0015] Step 1: Configure the remote RADIUS server IP address information on the OLT;

[0016] Step 2: Configure the 802.1x access control mode on the OLT to be based on ONU access control;

[0017] Step 3: Enable the 802.1x switch on the OLT so that protocol data packets can be sent to the CPU for processing;

[0018] Step 4: When the user has a network connection request, open the 802.1X client program, enter the user name and password that have been applied for, and initiate a connection request to the OLT. The connection request is an EAPOLSTART message.

[0019] Step 5: After receiving the data frame requesting authentication, the OLT device will send a request frame, which is an EAPREQUEST or Identity message, requiring the user's client program to send the input user name;

[0020] Step 6: After receiving the user name request message from the OLT device, the client sends a data frame carrying the user name information to the OLT device. The data frame is an EAPREQUEST or Identity message.

[0021] Step 7: The OLT device encapsulates the data frame sent by the client and sends it to the remote authentication server for processing;

[0022] Step 8: After receiving the user name information forwarded by the OLT device, the remote authentication server compares the information with the user name in the database, finds the password information corresponding to the user name, encrypts it with a randomly generated encryption word, and also sends the encryption word to the OLT device through a RADIUS Access-Challenge message, which is then passed to the client program by the OLT device;

[0023] Step 9: After the client program receives the encrypted word message from the OLT device, it uses the encrypted word to encrypt the password part to generate a data frame. The data frame is an EAPRESPONSE / MD5 Challenge message, which is encapsulated as a RADIUS Access-Request message by the OLT device and transmitted to the remote authentication server;

[0024] Step 10: The authentication server compares the received password information with the local encrypted password information. If they are the same, the user is considered to be a legitimate user, and then sends a RADIUS Access-Accept message to the OLT device indicating that the authentication is successful.

[0025] If they do not match, the user is considered an illegal user, and a RADIUS Access-Reject message indicating authentication failure is sent to the OLT device;

[0026] Step 11: When the OLT device receives the authentication success message, it sends an EAPSUCCESS message to the client program and opens the service channel of the ONU where the user is located, allowing the user's service flow to access the network through the ONU. Otherwise, the ONU service channel remains closed, allowing only authentication information data to pass, but not service data.

[0027] An 802.1X access control method based on ONU includes an OLT device, a client, a remote authentication server, and an ONU device;

[0028] After receiving the data frame requesting authentication, the OLT device is used to request the user's client program to send the input user name.

[0029] After receiving the message requesting the user name from the OLT device, the client sends a data frame carrying the user name information to the OLT device.

[0030] After receiving the user name information forwarded by the OLT device, the remote authentication server is used to compare the information with the user name in the database, find the password information corresponding to the user name, encrypt it with a randomly generated encryption word, and also send the encryption word to the OLT device via a RADIUS Access-Challenge message, which is then transmitted to the client program by the OLT device.

[0031] The client program can also send a message to the OLT device, actively requesting to go offline, and the OLT device closes the ONU service channel;

[0032] The PNU device is used to provide broadband services to users.

[0033] The present invention has the following beneficial effects:

[0034] The present invention is suitable for use in a PON passive optical network system, and its control granularity is between that of a port and a MAC. It can satisfy the application scenario of performing network access control with an ONU as the object in the PON passive optical network system, and realizes that in the PON passive optical network system, only one terminal user needs to be successfully authenticated under one ONU before other terminal devices can access the network, thereby effectively reducing access request messages that may be initiated by a large number of users at the same time, and solving the problem of network bandwidth being occupied. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] Figure 1 This is an overall flow chart of an 802.1X access control method based on ONU of the present invention;

[0036] Figure 2 This is a PON system + 802.1X application networking architecture diagram of an 802.1X access control method based on ONU of the present invention;

[0037] Figure 3 This is a traditional switch + 802.1X application networking architecture diagram of an 802.1X access control method based on ONU of the present invention;

[0038] Figure 4 The present invention is a schematic diagram of a PON system + 802.1X message interaction of an 802.1X access control method based on ONU. DETAILED DESCRIPTION

[0039] In order to make the technical means, creative features, objectives and effects achieved by the present invention easy to understand, the present invention is further explained below in conjunction with specific implementation methods.

[0040] Embodiment 1

[0041] Please refer to Figure 1-2 As shown: an 802.1X access control method based on ONU, the 802.1X control method based on ONU includes the following implementation steps:

[0042] Step 1: Configure the remote RADIUS server IP address information on the OLT;

[0043] Step 2: Configure the 802.1x access control mode on the OLT to be based on ONU access control;

[0044] Step 3: Enable the 802.1x function on the OLT so that protocol data packets can be sent to the CPU for processing;

[0045] Step 4: The user opens the 802.1X client program, enters the username and password that have been applied for, and initiates an authentication request to the OLT;

[0046] Step 5: OLT sends user information to the remote RADIUS authentication server for authentication;

[0047] Step 6: The remote RADIUS authentication server compares the received user information with the user name in the database. If they are consistent, it sends an authentication success message to the OLT. Otherwise, it sends an authentication failure message to the OLT.

[0048] Step 7: Determine whether the authentication is successful. If the OLT device receives the authentication success message, it sends an authentication success message to the client program and opens the service channel of the ONU where the user is located, allowing the user's service flow to access the network through the ONU. Otherwise, keep the ONU service channel closed and only allow authentication information data to pass, but not service data.

[0049] An 802.1X access control method based on ONU includes an OLT device, a client, a remote authentication server, and an ONU device;

[0050] After receiving the data frame requesting authentication, the ONU-based 802.OLT device requires the user's client program to send the input user name.

[0051] After receiving the user name request message from the OLT device, the ONU-based 802. client sends a data frame carrying the user name information to the OLT device.

[0052] After the ONU-based 802.11 remote authentication server receives the username information forwarded by the OLT device, it compares the information with the username in the database, finds the password information corresponding to the username, encrypts it with a randomly generated encryption word, and also sends the encryption word to the OLT device through the RADIUS Access-Challenge message, which is then transmitted to the client program by the OLT device.

[0053] The ONU-based 802. client program can also send a message to the OLT device to actively request to go offline, and the OLT device will close the ONU service channel;

[0054] ONU-based 802.PNU equipment is used to provide broadband services to users.

[0055] The present invention realizes an 802.1X access control method based on ONU, and the control granularity thereof is between that of port and MAC, which can not only meet the application scenario of performing network access control with ONU as the object in a PON passive optical network system, but also solve the problem that a large number of users may initiate access request messages at the same time, resulting in the occupation of network bandwidth.

[0056] Embodiment 2

[0057] Please refer to Figure 3 As shown: an 802.1X access control method based on ONU, the 802.1X method based on ONU includes the following implementation steps:

[0058] Step 1: Configure the remote RADIUS server IP address information on the OLT;

[0059] Step 2: Configure the 802.1x access control mode on the OLT to be based on ONU access control;

[0060] Step 3: Enable the 802.1x function on the OLT so that protocol data packets can be sent to the CPU for processing;

[0061] Step 4: The user opens the 802.1X client program, enters the username and password that have been applied for, and initiates an authentication request to the OLT;

[0062] Step 5: OLT sends user information to the remote RADIUS authentication server for authentication;

[0063] Step 6: The remote RADIUS authentication server compares the received user information with the user name in the database. If they are consistent, it sends an authentication success message to the OLT. Otherwise, it sends an authentication failure message to the OLT.

[0064] Step 7: Determine whether the authentication is successful. If the OLT device receives the authentication success message, it sends an authentication success message to the client program and opens the service channel of the ONU where the user is located, allowing the user's service flow to access the network through the ONU. Otherwise, keep the ONU service channel closed and only allow authentication information data to pass, but not service data.

[0065] At present, the existing 802.1X authenticates users or devices connected to the switch port. Before the authentication is passed, 802.1X only allows EAPOL-based LAN extended authentication protocol data to pass through the device to connect to the switch port. After the authentication is passed, the business data can pass through the Ethernet port. After the authentication is passed, all users under the port can access the network, which is easy to occupy network bandwidth.

[0066] Embodiment 3

[0067] Please refer to Figure 4 As shown: an 802.1X access control method based on ONU, the 802.1X method based on ONU includes the following implementation steps:

[0068] Step 1: Configure the remote RADIUS server IP address information on the OLT;

[0069] Step 2: Configure the 802.1x access control mode on the OLT to be based on ONU access control;

[0070] Step 3: Enable the 802.1x function on the OLT so that protocol data packets can be sent to the CPU for processing;

[0071] Step 4: The user opens the 802.1X client program, enters the username and password that have been applied for, and initiates an authentication request to the OLT;

[0072] Step 5: OLT sends user information to the remote RADIUS authentication server for authentication;

[0073] Step 6: The remote RADIUS authentication server compares the received user information with the user name in the database. If they are consistent, it sends an authentication success message to the OLT. Otherwise, it sends an authentication failure message to the OLT.

[0074] Step 7: Determine whether the authentication is successful. If the OLT device receives the authentication success message, it sends an authentication success message to the client program and opens the service channel of the ONU where the user is located, allowing the user's service flow to access the network through the ONU. Otherwise, keep the ONU service channel closed and only allow authentication information data to pass, but not service data.

[0075] The 802.1X message interaction process based on ONU is as follows:

[0076] Step 1: Configure the remote RADIUS server IP address information on the OLT;

[0077] Step 2: Configure the 802.1x access control mode on the OLT to be based on ONU access control;

[0078] Step 3: Enable the 802.1x switch on the OLT so that protocol data packets can be sent to the CPU for processing;

[0079] Step 4: When the user has a network connection request, open the 802.1X client program, enter the user name and password that have been applied for, and initiate a connection request to the OLT. The connection request is an EAPOLSTART message.

[0080] Step 5: After receiving the data frame requesting authentication, the OLT device will send a request frame, which is an EAPREQUEST or Identity message, requiring the user's client program to send the input user name;

[0081] Step 6: After receiving the user name request message from the OLT device, the client sends a data frame carrying the user name information to the OLT device. The data frame is an EAPREQUEST or Identity message.

[0082] Step 7: The OLT device encapsulates the data frame sent by the client and sends it to the remote authentication server for processing;

[0083] Step 8: After receiving the user name information forwarded by the OLT device, the remote authentication server compares the information with the user name in the database, finds the password information corresponding to the user name, encrypts it with a randomly generated encryption word, and also sends the encryption word to the OLT device through a RADIUS Access-Challenge message, which is then passed to the client program by the OLT device;

[0084] Step 9: After the client program receives the encrypted word message from the OLT device, it uses the encrypted word to encrypt the password part to generate a data frame. The data frame is an EAPRESPONSE / MD5 Challenge message, which is encapsulated as a RADIUS Access-Request message by the OLT device and transmitted to the remote authentication server;

[0085] Step 10: The authentication server compares the received password information with the local encrypted password information. If they are the same, the user is considered to be a legitimate user, and then sends a RADIUS Access-Accept message to the OLT device indicating that the authentication is successful.

[0086] If they do not match, the user is considered an illegal user, and a RADIUS Access-Reject message indicating authentication failure is sent to the OLT device;

[0087] Step 11: When the OLT device receives the authentication success message, it sends an EAPSUCCESS message to the client program and opens the service channel of the ONU where the user is located, allowing the user's service flow to access the network through the ONU. Otherwise, the ONU service channel remains closed, allowing only authentication information data to pass, but not service data.

[0088] An 802.1X access control method based on ONU includes an OLT device, a client, a remote authentication server, and an ONU device;

[0089] After receiving the data frame requesting authentication, the OLT device requires the user's client program to send the input user name.

[0090] After receiving the user name request message from the OLT device, the client sends a data frame carrying the user name information to the OLT device.

[0091] After receiving the user name information forwarded by the OLT device, the remote authentication server compares the information with the user name in the database, finds the password information corresponding to the user name, encrypts it with a randomly generated encryption word, and also sends the encryption word to the OLT device through a RADIUS Access-Challenge message, which is then transmitted to the client program by the OLT device.

[0092] The client program can also send a message to the OLT device to actively request to go offline, and the OLT device will close the ONU service channel;

[0093] PNU equipment is used to provide broadband services to users.

[0094] The message interaction process realizes the 802.1X access control method based on ONU in the PON passive optical network system, and only one terminal user needs to be successfully authenticated under one ONU before other terminal devices can access the network, effectively reducing the access request messages that may be initiated by a large number of users at the same time.

[0095] In the present invention, an 802.1X access control method based on ONU is provided. First, the IP address information of the remote RASIUS server of the OLT is configured, and the 802.1x access control based on the ONU is configured. The 802.1x function is enabled on the OLT so that the protocol data message can be sent to the CPU for processing. The user opens the 802.1X client program, enters the user name and password that have been applied for, and initiates an authentication request to the OLT. The OLT sends the user information to the remote RADIUS authentication server for authentication. The remote RADIUS authentication server compares the received user information with the user name in the database. If they are consistent, an authentication success message is sent to the OLT. Otherwise, send an authentication failure message to the OLT to determine whether the authentication is successful. If the OLT device receives the authentication success message, it sends an authentication success message to the client program and opens the service channel of the ONU where the user is located, allowing the user's service flow to access the network through the ONU. Otherwise, keep the ONU service channel closed, only allow authentication information data to pass, and do not allow service data to pass. The application scenario of network access control is based on ONU. Only one terminal user needs to be authenticated successfully under one ONU, and other terminal devices can access the network, effectively reducing the possible access request messages initiated by a large number of users at the same time, and solving the problem of network bandwidth being occupied. The whole method is simple and efficient.

[0096] The above shows and describes the basic principles and main features of the present invention and the advantages of the present invention. It should be understood by those skilled in the art that the present invention is not limited to the above embodiments. The above embodiments and descriptions are only for explaining the principles of the present invention. Without departing from the spirit and scope of the present invention, the present invention may have various changes and improvements, which fall within the scope of the present invention to be protected. The scope of protection of the present invention is defined by the attached claims and their equivalents.

Claims

1. An 802.1X access control method based on ONU, characterized in that: The method includes a message interaction process and the following implementation steps: Step A1: Configure the remote RADIUS server IP address information on the OLT; Step A2: Configure the 802.1x access control mode on the OLT to be based on ONU access control; Step A3: Enable the 802.1x function on the OLT to allow protocol data packets to be sent to the CPU for processing; Step A4: The user opens the 802.1X client program, enters the user name and password that have been applied for, and initiates an authentication request to the OLT; Step A5: OLT sends the user information to the remote RADIUS authentication server for authentication; Step A6: The remote RADIUS authentication server compares the received user information with the user name in the database. If they are consistent, it sends an authentication success message to the OLT. Otherwise, it sends an authentication failure message to the OLT. Step A7: Determine whether the authentication is successful. If the OLT device receives the authentication success message, it sends an authentication success message to the client program and opens the service channel of the ONU where the user is located, allowing the user's service flow to access the network through the ONU. Otherwise, keep the ONU service channel closed, only allow authentication information data to pass, and do not allow service data to pass; The message interaction process is as follows: Step B1: Configure the remote RADIUS server IP address information on the OLT; Step B2: Configure the 802.1x access control mode on the OLT to be based on ONU access control; Step B3: Enable the 802.1x switch on the OLT to allow protocol data packets to be sent to the CPU for processing; Step B4: When the user has a network connection request, the user opens the 802.1X client program, enters the user name and password that have been applied for, and initiates a connection request to the OLT. The connection request is an EAPOLSTART message. Step B5: After receiving the data frame requesting authentication, the OLT device will send a request frame as an EAPREQUEST or Identity message, requiring the user's client program to send the input user name; Step B6: After receiving the user name request message from the OLT device, the client sends a data frame carrying the user name information to the OLT device. The data frame is an EAPREQUEST or Identity message. Step B7: The OLT device encapsulates the data frame sent by the client and sends it to the remote authentication server for processing; Step B8: After receiving the user name information forwarded by the OLT device, the remote authentication server compares the information with the user name in the database, finds the password information corresponding to the user name, encrypts it with a randomly generated encryption word, and also sends the encryption word to the OLT device via a RADIUS Access-Challenge message, which is then transmitted to the client program by the OLT device; Step B9: After receiving the encrypted word message from the OLT device, the client program encrypts the password part with the encrypted word to generate a data frame, which is an EAPRESPONSE / MD5 Challenge message, and is encapsulated as a RADIUS Access-Request message by the OLT device and transmitted to the remote authentication server; Step B10: The authentication server compares the received password information with the local encrypted password information. If they are the same, the user is considered to be a legitimate user, and then sends a RADIUS Access-Accept message to the OLT device indicating that the authentication is successful. If they do not match, the user is considered an illegal user, and a RADIUS Access-Reject message indicating authentication failure is sent to the OLT device; Step B11: When the OLT receives the authentication success message, it sends an EAPSUCCESS message to the client program and opens the service channel of the ONU where the user is located, allowing the user's service flow to access the network through the ONU. Otherwise, the ONU service channel is kept closed, and only authentication information data is allowed to pass, but service data is not allowed to pass; The ONU-based 802.1X access control method includes an OLT device, a client, a remote authentication server, and an ONU device; After receiving the data frame requesting authentication, the OLT device is used to request the user's client program to send the input user name; After receiving the user name request message from the OLT device, the client sends a data frame carrying the user name information to the OLT device; After receiving the user name information forwarded by the OLT device, the remote authentication server is used to compare the information with the user name in the database, find the password information corresponding to the user name, encrypt it with a randomly generated encryption word, and also send the encryption word to the OLT device via a RADIUS Access-Challenge message, which is then transmitted to the client program by the OLT device; The client program sends a message to the OLT device, actively requests to go offline, and the OLT device closes the ONU service channel; The ONU device is used to provide broadband services to users.

Citation Information

Patent Citations

  • Method for implementing IEEE802.1x user port authentication in ethernet passive optical network

    CN101141448A