A method of authenticating a communications device module
By implementing a development, testing, certification, and triple verification mechanism for communication modules, the certification process for communication modules is simplified, the flexibility and ease of use of certification are improved, and the problems of cumbersome and inflexible certification in existing technologies are solved. This approach is applicable to the certification of communication modules in optical communication equipment.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-26
- Publication Date
- 2026-04-07
AI Technical Summary
In existing optical communication technologies, the authentication process for communication modules is complex, inflexible, and lacks universality and ease of use. In particular, in scenarios without a unified network management system, the authentication process is complex and inflexible, making it difficult to respond quickly to emergencies.
By developing, testing, and certifying the communication module, a module information table is generated, which is then converted into a license file and imported into the communication device for parsing. Combined with a triple verification mechanism (license file integrity check, information consistency verification, and whitelist permissions), the module's legitimacy is confirmed, simplifying the certification process.
It effectively simplifies the authentication process of communication modules, improves the flexibility, universality and ease of use of authentication, protects the interests of equipment manufacturers, prevents unauthorized module access, and adapts to various scenario requirements.
Smart Images

Figure CN117896161B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of optical communication, and particularly relates to an authentication method of a communication equipment module. BACKGROUND
[0002] The communication module is an indispensable communication component in the communication field of optical transmission, network and communication. At present, the passive optical access network enters the 10GEPON (10 Gb / s) and XGSPON (10G downstream symmetric full optical fiber user interface transmission technology standard) era from Epon (Ethernet-based passive optical network) / Gpon (gigabit passive optical network), the data transmission rate of the PON (optical) module and the uplink module of the OLT (optical line terminal) is higher and higher, especially the technical requirements of the GPON / XGPON / XGSPON three-module-in-one module are very strict, but under the current industrial manufacturing level, these high-speed modules are not universal, such as 10GEPON, XGSPON / GPON COMBO module, 100G QSFP28 (high-speed optical module) uplink module, and the compatibility is poor.
[0003] At present, the cost proportion of the communication module is relatively high compared with the equipment, and the authentication and binding of the communication module can help stimulate the module manufacturers to increase investment, solve technical problems, accelerate the standardization of the communication module, and improve the compatibility of the communication module. In addition, a large amount of testing and experimental verification needs to be carried out on the communication equipment end to adjust the parameters, so as to well adapt to the communication module, therefore, the authentication and binding of the module can not only protect the interests of the communication equipment manufacturers, but also ensure the stability of the overall scheme of the communication equipment. If the communication equipment user purchases a communication module that does not meet the requirements, the communication equipment and the communication module may not be compatible in use, thereby leading to unstable network system or communication failure.
[0004] The prior art proposes a method for preventing illegal optical modules from accessing an OLT, comprising the following steps: after an optical module accesses a local terminal device OLT, the OLT reports the feature code of the optical module to a network management system; the network management system verifies the reported feature code, and if the verification is passed, the optical module is considered to be a legal one that has passed security authentication, and if the verification is not passed, the optical module is considered to be illegal; the network management system checks whether the feature code that has passed the verification is reused, and if not, the optical module is legal, and if yes, all optical modules with the reused feature code are illegal; the network management system saves the feature code of the legal optical module, corresponding OLT information and the accessed PON port position in the network management system; and the network management system issues a message to the OLT, and for an illegal optical module, the laser thereof is turned off and the optical module is prohibited from accessing the OLT device; this scheme can prevent illegal optical modules that have not passed security authentication from accessing the local terminal device OLT, and protect the safety of the network system, but the access authentication is performed by the upper-layer unified network management, which is not applicable to the scenario without the unified network management, and the authentication process is relatively complicated, the authentication of the optical module cannot be performed quickly in an emergency, the flexibility is low, and the scheme is not universal and easy to use. SUMMARY
[0005] To solve the problems of complicated authentication process, low flexibility, non-universality and non-easy-to-use of the communication module in the prior art optical communication technology, the application provides a communication device module authentication method and a computer readable storage medium, which can effectively simplify the complicated authentication process of the communication module, improve the authentication flexibility, universality and easy-to-use of the communication module.
[0006] To achieve the object of the application, the application adopts the following technical scheme:
[0007] A communication device module authentication method, comprising the following steps:
[0008] Developing and testing the communication module, recording the data information of the communication module that has passed the authentication, and forming a module information table;
[0009] Converting the module information table into a license file;
[0010] Importing the license file into the communication device, parsing the license file in the communication device, and restoring the module information table of the communication module;
[0011] Confirming the legality of the communication module according to the restored module information table of the communication module.
[0012] In the technical scheme, the communication module is developed, tested and authenticated to ensure that the communication module can be normally used when needed; the data information of the communication module is formed into a module information table, and the module information table is converted into a license file, which is imported into the communication equipment to simplify the data transmission process in the process of legally authenticating the communication module; the license file is parsed in the communication equipment to restore the module information table of the communication module, and the legality of the communication module is confirmed according to the restored module information table of the communication module, so that the process of legally authenticating the communication module is effectively simplified, and the authentication flexibility, universality and ease of use of the communication module are improved.
[0013] Further, the process of developing, testing and authenticating the communication module includes:
[0014] The communication module is authenticated to determine whether the performance of the communication module meets the standard;
[0015] If the standard is met, the communication module is qualified, and the qualified communication module is retained;
[0016] If the standard is not met, the communication module is unqualified, and the communication module is eliminated.
[0017] Further, the license file is imported into the communication equipment through ftp or web page.
[0018] Further, the specific process of restoring the module information table of the communication module includes:
[0019] The license file is parsed and restored by using a preset algorithm to determine whether the restored license file is an empty file;
[0020] If it is an empty file, the license file is illegal, and the communication module recorded in the license file is disabled;
[0021] If it is not an empty file, it is determined whether the module information table lacks data;
[0022] If the data is missing, the license file is illegal, and the communication module recorded in the license file is disabled;
[0023] If the data is not missing, it means that the complete module information table of the communication module is restored;
[0024] The information in the module information table includes manufacturer information, model information and serial number information of the communication module.
[0025] Further, the specific process of confirming the legality of the communication module includes:
[0026] The communication device stores authentication information of each communication module when the production is completed, and compares the module information in the module information table of the recovered communication module with the authentication information, to determine whether the module information in the module information table is consistent with the information recorded in the authentication information.
[0027] If the information is consistent, it indicates that the communication module recorded in the module information table is legal, and the communication module recorded in the module information table is retained for use.
[0028] If the information is inconsistent, the communication module recorded in the module information table is illegal, and the communication module recorded in the module information table is disabled.
[0029] In the above technical solution, the communication module is developed, tested and authenticated to ensure that the communication module can be normally used when needed; the license file is imported into the communication device through ftp or web page to accelerate the transmission speed of the license file and monitor the progress of data transmission in real time; considering the interests of the equipment manufacturer, a three-verification mechanism is set to authenticate the legality of the communication module, to judge whether the recovered license file is an empty file, whether the module information table lacks data, and whether the module information in the module information table is consistent with the information recorded in the authentication information. Through the three-verification mechanism, it can effectively prevent the communication module accessed by the communication device from being an invalid module or an illegal module, while protecting the interests of the equipment manufacturer, it also improves the authentication flexibility, universality and ease of use of the communication module.
[0030] Further, the method further comprises: detecting information deduplication of the legal communication module, and the specific process comprises:
[0031] A plurality of legal communication modules are accessed to the communication device, and it is determined whether there is a communication module with repeated data information among all legal communication modules.
[0032] If there is, one of the communication modules with repeated data information is retained as a legal communication module, and the remaining communication modules with repeated information are disabled.
[0033] If not, it indicates that all communication modules are legal, and all communication modules are retained for use.
[0034] In the above technical solution, the information deduplication of the legal communication module is detected, which can effectively prevent other merchants from counterfeiting the communication module of the equipment manufacturer by copying the module information, thereby damaging the interests of the equipment manufacturer.
[0035] Further, after the module information table is converted into the license file, the license file is set with anti-modification verification information.
[0036] Furthermore, MD5 or CRC algorithms are used to set anti-tampering verification information for the license file.
[0037] In the above technical solution, setting anti-modification verification information for the license file can effectively protect the integrity of the module information of the communication module. When the anti-modification verification information detects that the license file has been modified, it will destroy the integrity of the license file and make the license file invalid.
[0038] Furthermore, a whitelist permission verification is set up, and the communication module is added to the whitelist after passing the whitelist permission verification.
[0039] All communication modules in the whitelist are legitimate.
[0040] Furthermore, the process of adding a communication module to the whitelist includes:
[0041] An instruction is issued to a communication device to add a communication module to a whitelist, and the communication device performs permission verification on the instruction;
[0042] If the command's permissions are granted, the required communication module will be added to the whitelist.
[0043] If the command's permissions are not met, the verification fails, and the communication module is refused to be added to the whitelist.
[0044] In the above technical solution, considering the possibility that other communication modules may need to be added temporarily during actual engineering use, a whitelist of communication modules is set up, and permission verification is set for the whitelist. After the permission verification is passed, the temporarily needed communication modules can be added to the whitelist and directly used by the communication device. There is no need to perform legality authentication and deduplication detection on the communication modules. This can meet the needs of temporary use cases or scenarios with low requirements for performance and stability, and improve the authentication flexibility, universality and ease of use of the communication modules.
[0045] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0046] This invention discloses an authentication method for communication device modules. First, the communication module undergoes development testing and authentication, recording the data information of authenticated modules to form a module information table, ensuring the communication module can be used normally when needed. Then, the module information table is converted into a license file, which is imported into the communication device. The license file is parsed in the communication device to restore the module information table, simplifying the data transmission process during the legal authentication of the communication module. Finally, the legality of the communication module is confirmed based on the restored module information table. This invention effectively simplifies the legal authentication process for communication modules, improving the flexibility, universality, and ease of use of the authentication process. Attached Figure Description
[0047] Figure 1 A flowchart illustrating an authentication method for a communication device module provided in this application embodiment;
[0048] Figure 2 A flowchart for deduplication detection of legitimate communication modules provided in this application embodiment;
[0049] Figure 3 A flowchart illustrating the process of adding a whitelist to the communication module provided in this embodiment. Detailed Implementation
[0050] To facilitate understanding of the present invention, a more complete description will be given below with reference to the accompanying drawings. Preferred embodiments of the invention are shown in the drawings. However, the invention can be implemented in many different forms and is not limited to the embodiments described herein. Rather, these embodiments are provided to provide a thorough and complete understanding of the disclosure of the invention.
[0051] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. The terminology used herein in the description of the invention is for the purpose of describing particular embodiments only and is not intended to be limiting of the invention. The term "and / or" as used herein includes any and all combinations of one or more of the associated listed items.
[0052] Example 1:
[0053] This embodiment provides an authentication method for a communication device module, see [link to relevant documentation]. Figure 1 This includes the following steps:
[0054] S1: Conduct development, testing and certification of communication modules, record the data information of certified communication modules, and form a module information table;
[0055] S2: Convert the module information table into a license file;
[0056] S3: Import the license file into the communication device, parse the license file in the communication device, and restore the module information table of the communication module;
[0057] S4: Confirm the legitimacy of the communication module based on the module information table of the recovered communication module.
[0058] The process of developing, testing, and certifying the communication module described in step S1 includes:
[0059] The communication module is certified to determine whether its performance meets the standards.
[0060] If the standard is met, it means that the communication module is qualified, and the qualified communication module will be retained.
[0061] If the standard is not met, it means that the communication module is unqualified and should be discarded.
[0062] For example, during the equipment design and development phase, the equipment manufacturer selects a communication module that meets the requirements for interfacing development and testing. The testing checks whether the functions and performance of the communication module meet the requirements. The communication modules that pass the test are retained, and the manufacturer information (vendor id), model information (model id), and module serial number information (serial number) of the communication module are recorded. The recorded information is used to form a module information table, and the module serial numbers in the module information table are a specified number of serial numbers or a range of serial numbers.
[0063] The module information table is in the form shown in Table 1 below:
[0064] Table 1:
[0065] Vendor ID Module ID Serial Number ID Communication Module A PRO_A MOD_A SN0000A Communication Module B PRO_B MOD_B SN0000B - SN00100 Communication Module C PRO_C MOD_C SN0000C - SN10000
[0066] Certified modules can be individual, in batches, or as part of an entire series, as determined by the equipment manufacturer.
[0067] The algorithm is designed to convert the module information table into a license file (i.e., a license file). After converting the module information table into a license file, anti-modification verification information is set for the license file.
[0068] In setting anti-tampering verification information for license documents, MD5 or CRC algorithms are used to set the anti-tampering verification information for the license documents.
[0069] It is understandable that setting anti-modification verification information for license files can effectively protect the integrity of the module information of the communication module. When the anti-modification verification information detects that the license file has been modified, it will destroy the integrity of the license file and make the license file invalid.
[0070] In a preferred embodiment, the license file is imported into the communication device via FTP or a web page.
[0071] The specific process of restoring the module information table of the communication module in step S3 includes:
[0072] The system uses a preset algorithm to parse and recover the license file, and then determines whether the recovered license file is empty.
[0073] If the file is empty, the license file is invalid, and the communication module recorded in the license file will be disabled.
[0074] If the file is not empty, then check if the module information table is missing data;
[0075] If data is missing, the license file is invalid, and the communication modules recorded in the license file will be disabled.
[0076] If no data is missing, it means that the complete module information table of the communication module has been recovered;
[0077] The information in the module information table includes the manufacturer information, model information, and serial number information of the communication module.
[0078] For example, the communication device uses a designed algorithm to reverse the process of the license file to recover the module information table. During the process of recovering the module information table, it checks whether the license file is empty or incomplete. If the license file is empty or incomplete, it is determined to be an invalid license file, and the communication device will not accept the access of any communication module recorded in the license file and will give a prompt. If the license file is not empty and the data is complete, the complete module information table of the communication modules is recovered.
[0079] The specific process for verifying the legitimacy of the communication module in step S4 includes:
[0080] The communication device stores the authentication information of each communication module when it is completed. The module information in the module information table of the recovered communication module is compared with the authentication information to determine whether the module information in the module information table is consistent with the information recorded in the authentication information.
[0081] If the information matches, it means that the communication module recorded in the module information table is valid, and the communication module recorded in the module information table will be retained for use.
[0082] If the information is inconsistent, the communication module recorded in the module information table is invalid, and the communication module recorded in the module information table is disabled.
[0083] For example, after the license file passes the verification, the communication module legality verification stage begins. The communication device stores the authentication information of each communication module when it was manufactured. The communication device compares the module information in the recovered module information table with the authentication information. If the data in the module information table matches the data in the authentication information, it means that the connected communication module is a legal communication module and can be used normally by connecting to the communication device. If the data in the module information table does not match the data in the authentication information, it means that the connected communication module is illegal. The communication device disables the communication module recorded in the license file by powering off or disabling the configuration software and provides a prompt.
[0084] It's understandable that developing, testing, and certifying communication modules ensures they function correctly when needed. Importing license files into communication devices via FTP or web pages speeds up file transfer and allows for real-time monitoring of data transmission progress. To protect the rights of equipment manufacturers, a triple verification mechanism is implemented to authenticate the communication module's legitimacy. This mechanism checks if the recovered license file is empty, if the module information table is missing data, and if the module information matches the information recorded in the certification information. This triple verification effectively prevents invalid or illegitimate communication modules from being connected to the communication device. While protecting the interests of equipment manufacturers, it also improves the flexibility, universality, and ease of use of the communication module's authentication process.
[0085] In some preferred embodiments, when there is a communication module that is actually legal (i.e., a communication module that has been developed, tested and certified) but is not recorded in the module information table, the user can report it to the equipment manufacturer. After the equipment manufacturer verifies and confirms it, the module information table for the communication module will be regenerated and converted into a license. The user can then repeat the steps described in steps S2 to S4.
[0086] In this embodiment, considering the possibility that the communication module may malfunction or lack functionality, the communication module undergoes development, testing, and certification to ensure it can function properly when needed. The communication module's data information is compiled into a module information table, which is then converted into a license file. Importing the license file into the communication device simplifies the data transmission process during the legal authentication of the communication module. The license file is parsed within the communication device to restore the communication module's module information table. Based on the restored module information table, the legality of the communication module is confirmed, effectively simplifying the legal authentication process and improving the flexibility, universality, and ease of use of the communication module's authentication.
[0087] Example 2:
[0088] Based on Example 1, this embodiment provides a method for detecting duplicates in legitimate modules, as detailed below:
[0089] See Figure 2 The process of deduplicating information from legitimate communication modules includes:
[0090] To connect a communication device to several legitimate communication modules, determine whether there are any communication modules with duplicate data among all the legitimate communication modules.
[0091] If they exist, one of the communication modules with duplicate data information will be retained as a valid communication module, and the remaining communication modules with duplicate information will be disabled.
[0092] If it does not exist, it means that all communication modules are valid, and all communication modules will be reserved for use.
[0093] For example, several legitimate communication modules are connected to a communication device. The communication device verifies the information of each communication module based on the authentication information and checks whether there are communication modules with identical data. If there are communication modules with identical information, only one of the communication modules is allowed to be connected to the communication device for normal use, while the other communication modules with duplicate information are disabled and a prompt is given. This prevents unscrupulous merchants from counterfeiting the same group of communication modules by copying the communication module information.
[0094] In this embodiment, information deduplication detection is performed on legitimate communication modules to effectively prevent other vendors from counterfeiting the equipment manufacturer's communication modules by copying module information, thereby harming the equipment manufacturer's rights and interests.
[0095] Example 3:
[0096] Based on Embodiment 1, this embodiment provides a method for eliminating authentication for a communication module, as detailed below:
[0097] See Figure 3 Configure a whitelist of communication modules and add communication modules to the whitelist according to actual needs;
[0098] Configure whitelist permission verification, and add the communication module to the whitelist after passing the whitelist permission verification.
[0099] All communication modules in the whitelist are legitimate.
[0100] The process of adding a communication module to the whitelist includes:
[0101] An instruction is issued to a communication device to add a communication module to a whitelist, and the communication device performs permission verification on the instruction;
[0102] If the command's permissions are granted, the required communication module will be added to the whitelist.
[0103] If the command's permissions are not met, the verification fails, the communication module is refused to be added to the whitelist, and the communication device provides a prompt.
[0104] In this embodiment, considering the possibility that other communication modules may need to be added temporarily during actual engineering use, a whitelist of communication modules is set up, and permission verification is set for the whitelist. After passing the permission verification, the temporarily needed communication modules can be added to the whitelist and directly used by the communication device. There is no need to perform legality authentication and deduplication detection on the communication modules. This can meet the needs of temporary use cases or scenarios with low requirements for performance and stability, and improve the authentication flexibility, universality and ease of use of the communication modules.
[0105] The above description is merely an embodiment of the present invention and does not limit the patent scope of the present invention. Any equivalent structural or procedural transformations made based on the content of the present invention's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of the present invention.
Claims
1. An authentication method for a communication device module, characterized in that, Includes the following steps: During the equipment design and development phase, the equipment manufacturer conducts development, testing and certification of the communication module, records the data information of the certified communication module, and forms a module information table. Convert the module information table into a license file; Import the license file into the communication device, parse the license file in the communication device, and restore the module information table of the communication module; Based on the module information table of the recovered communication module, confirm the legitimacy of the communication module; The specific process of restoring the module information table of the communication module includes: The system uses a preset algorithm to parse and recover the license file, and determines whether the recovered license file is empty. If the file is empty, the license file is invalid, and the communication module recorded in the license file will be disabled. If the file is not empty, then check if the module information table is missing data; If data is missing, the license file is invalid, and all communication modules recorded in the license file will be disabled. If no data is missing, it means that the complete module information table of the communication module has been recovered; The information in the module information table includes the manufacturer information, model information, and serial number information of the communication module. The method further includes: performing information deduplication detection on legitimate communication modules, the specific process of which includes: To connect a communication device to several legitimate communication modules, determine whether there are any communication modules with duplicate data among all the legitimate communication modules. If they exist, one of the communication modules with duplicate data information will be retained as a valid communication module, and the remaining communication modules with duplicate information will be disabled. If it does not exist, it means that all communication modules are valid, and all communication modules will be reserved for use.
2. The authentication method for a communication device module according to claim 1, characterized in that, The process of developing, testing, and certifying a communication module includes: The communication module is certified to determine whether its performance meets the standards. If the standard is met, it means that the communication module is qualified, and the qualified communication module will be retained. If the standard is not met, it means that the communication module is unqualified and should be discarded.
3. The authentication method for a communication device module according to claim 2, characterized in that, Import the license file into the communication device via FTP or a web page.
4. The authentication method for a communication device module according to claim 3, characterized in that, The specific process for verifying the legitimacy of the communication module includes: The communication device stores the authentication information of each communication module when it is completed. The module information in the module information table of the recovered communication module is compared with the authentication information to determine whether the module information in the module information table is consistent with the information recorded in the authentication information. If the information matches, it means that the communication module recorded in the module information table is valid, and the communication module recorded in the module information table will be retained for use. If the information is inconsistent, the communication module recorded in the module information table is invalid, and the communication module recorded in the module information table is disabled.
5. The authentication method for a communication device module according to claim 1, characterized in that, After converting the module information table into a license file, set anti-modification verification information for the license file.
6. The authentication method for a communication device module according to claim 5, characterized in that, Use MD5 or CRC algorithms to set anti-tampering verification information for license files.
7. The authentication method for a communication device module according to claim 1, characterized in that, The method further includes: setting a whitelist permission verification, and adding the communication module to the whitelist through the whitelist permission verification; All communication modules in the whitelist are legitimate.
8. The authentication method for a communication device module according to claim 7, characterized in that, The process of adding a communication module to the whitelist includes: An instruction is issued to a communication device to add a communication module to a whitelist, and the communication device performs permission verification on the instruction; If the command's permissions are granted, the required communication module will be added to the whitelist. If the command's permissions are not met, the verification fails, and the communication module is refused to be added to the whitelist.
Citation Information
Patent Citations
Method for carrying out optical module two-step verification through utilization of data interface
CN107566048A