Dynamic Negotiation Method, Device, Equipment and Readable Storage Medium for Encryption Algorithm

The FTTR system employs a method for dynamic encryption algorithm negotiation through message exchange of device serial numbers and supported algorithms, addressing the lack of standard negotiation protocols and enhancing encryption flexibility and compatibility.

CN119094127BActive Publication Date: 2025-07-15FIBERHOME TELECOMMUNICATION TECHNOLOGIES CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411385110.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-30
Publication Date
2025-07-15
Estimated Expiration
2044-09-30

AI Technical Summary

Technical Problem

There is a lack of effective multiple encryption algorithm negotiation mechanisms between master and slave devices in the FTTR system, which leads to the inability to uniformly select encryption algorithms, affecting system security and compatibility.

Method used

By extending PLOAM messages in the FTTR system, the dynamic negotiation method of encryption algorithm between master and slave devices is realized, including constructing a target sequence number message from the slave device to inform the master device of the encryption algorithm it supports, the master device decides on the target encryption algorithm and constructs an identifier allocation message to realize the encryption and decryption processing of the service transmission channel.

Benefits of technology

It realizes negotiation of multiple encryption algorithms between master and slave devices, improves system compatibility and flexibility of encryption methods, improves device security, and reduces chip costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119094127B_ABST
    Figure CN119094127B_ABST
Patent Text Reader

Abstract

A method, device, equipment and readable storage medium for dynamic negotiation of encryption algorithms, which relate to the field of PON management of FTTR gateways. When a slave device in the serial number state receives a serial number request message broadcast by a master device, it constructs a target serial number message including the serial number of the slave device and the encryption algorithms supported by the slave device and sends it to the master device, so that the master device can decide a target encryption algorithm from the encryption algorithms supported by the slave device based on the target serial number message, and constructs a target identifier allocation message according to the target encryption algorithm and the target identifier allocated to the slave device; when receiving the target identifier allocation message sent by the master device, it parses the target identifier allocation message to obtain the target encryption algorithm, so as to implement the encryption and decryption processing of the service transmission channel through the target encryption algorithm. Through this application, the negotiation of multiple encryption algorithms between the master and slave devices can be effectively realized, and the existing interaction process does not need to be changed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of FTTR (Fiber to the Room) gateway PON (Passive Optical Network) management, and particularly relates to a method, device, equipment, and readable storage medium for dynamic negotiation of encryption algorithms. Background Art

[0002] Currently, FTTR adopts a mode of 1 master gateway + N slave gateways to realize fiber access in corridors, rooms, etc. Compared with traditional networking methods, it has characteristics such as strong transmission capacity, higher transmission rate, and longer line life, so it is widely used in large residences, hotels, small and medium-sized enterprises and other scenarios. Among them, in the traditional GPON (Gigabit-Capable PON) / 10GPON system, only the AES128 encryption algorithm is supported to encrypt the service transmission channel gemport (GPON Encapsulation Method port); with the rise of FTTR technology and the popularization of national encryption algorithms (such as the SM4 block cipher algorithm), in the FTTR system specification, CCSA (China Communications Standards Association) requires that FTTR devices be able to support other encryption algorithms in addition to the AES128 encryption algorithm. Therefore, considering from the aspects of chips, standards, and industrial reuse, the master and slave devices such as FTTR master and slave gateways need to support multiple encryption algorithms such as AES128 and national encryption algorithms at the same time.

[0003] In the related art, if you want to implement the master and slave devices in FTTR to support multiple encryption algorithms, not only does the PON chip need to support multiple encryption algorithms, but also the software of the FTTR master and slave devices needs to support encryption algorithm negotiation so that both parties can unify the encryption algorithm; however, how the master and slave devices perceive each other's capabilities and complete encryption algorithm negotiation and select a specified encryption algorithm is not defined in the relevant standards. It can be seen that how to implement the negotiation of multiple encryption algorithms between the master and slave devices in the FTTR system is an urgent problem to be solved in the current FTTR system. Summary of the Invention

[0004] This application provides a method, device, equipment, and readable storage medium for dynamic negotiation of encryption algorithms, which can effectively implement the negotiation of multiple encryption algorithms between the master and slave devices.

[0005] In a first aspect, an embodiment of this application provides a method for dynamic negotiation of encryption algorithms. The method for dynamic negotiation of encryption algorithms is applied to a slave device, and the method includes the following steps:

[0006] When a slave device in the serial number state receives a serial number request message broadcast by the master device, it constructs a target serial number message, where the target serial number message includes the serial number of the slave device and the encryption algorithms supported by the slave device;

[0007] Send the target serial number message to the master device for the master device to decide on a target encryption algorithm from the encryption algorithms supported by the slave device based on the target serial number message, and construct a target identifier allocation message according to the target encryption algorithm and the target identifier assigned to the slave device;

[0008] When receiving the target identifier allocation message sent by the master device, parse the target identifier allocation message to obtain the target encryption algorithm, so as to implement the encryption and decryption processing of the service transmission channel through the target encryption algorithm.

[0009] Combined with the first aspect, in one implementation, the constructing the target serial number message includes:

[0010] Perform a write operation on the serial number bytes in the serial number message according to the serial number of the slave device, and perform a write operation on the reserved bytes in the serial number message based on the encryption algorithms supported by the slave device itself to generate a target serial number message;

[0011] Wherein, the master device determines the type of encryption algorithm supported by the slave device through the value of the reserved bytes in the target serial number message.

[0012] Combined with the first aspect, in one implementation, when the slave device is in the running state, the method further includes:

[0013] If receiving a target key message sent by the master device, parse the target key message to obtain an updated encryption algorithm, where the target key message is generated by the master device based on the encryption algorithm expected to be used by the user;

[0014] Generate a new key according to the updated encryption algorithm, and send the new key to the master device to realize the key update between the slave device and the master device.

[0015] Combined with the first aspect, in one implementation, the target key message is generated by the master device based on the encryption algorithm expected to be used by the user, including:

[0016] The master device determines an updated encryption algorithm based on the encryption algorithm expected to be used by the user, and performs a write operation on the reserved bytes in the key message according to the updated encryption algorithm to generate a target key message;

[0017] Wherein, the slave device determines the updated encryption algorithm decided by the master device through the value of the reserved bytes in the target key message.

[0018] Second aspect, an embodiment of the present application provides an encryption algorithm dynamic negotiation device, including a slave device, where the slave device is configured to:

[0019] When the slave device in the serial number state receives the serial number request message broadcast by the master device, construct a target serial number message, where the target serial number message includes the serial number of the slave device and the encryption algorithms supported by the slave device;

[0020] Send the target serial number message to the master device, so that the master device decides a target encryption algorithm from the encryption algorithms supported by the slave device based on the target serial number message, and constructs a target identifier allocation message according to the target encryption algorithm and the target identifier allocated to the slave device;

[0021] When receiving the target identifier allocation message sent by the master device, parse the target identifier allocation message to obtain the target encryption algorithm, so as to implement the encryption and decryption processing of the service transmission channel through the target encryption algorithm.

[0022] Combined with the second aspect, in an implementation manner, the slave device is specifically configured to:

[0023] Perform a write operation on the serial number byte in the serial number message according to the serial number of the slave device, and perform a write operation on the reserved byte in the serial number message based on the encryption algorithms supported by the slave device itself, so as to generate a target serial number message;

[0024] Wherein, the master device determines the type of encryption algorithm supported by the slave device through the value of the reserved byte in the target serial number message.

[0025] Combined with the second aspect, in an implementation manner, when the slave device is in the running state, the slave device is further configured to:

[0026] If receiving the target key message sent by the master device, parse the target key message to obtain the updated encryption algorithm, where the target key message is generated by the master device based on the encryption algorithm expected to be used by the user;

[0027] Generate a new key according to the updated encryption algorithm, and send the new key to the master device to implement the key update between the slave device and the master device.

[0028] Combined with the second aspect, in an implementation manner, the master device is specifically configured to:

[0029] Determine the updated encryption algorithm based on the encryption algorithm expected to be used by the user, and perform a write operation on the reserved byte in the key message according to the updated encryption algorithm, so as to generate a target key message;

[0030] Among them, the slave device determines the updated encryption algorithm decided by the master device according to the value of the reserved byte in the target key message.

[0031] In a third aspect, an embodiment of the present application provides an encryption algorithm dynamic negotiation method, which is applied to a master device, and the method includes the following steps:

[0032] Send a serial number request message to the slave device in a broadcast manner;

[0033] When receiving a target serial number message sent by the slave device in the serial number state based on the serial number request message, determine a target encryption algorithm from the encryption algorithms supported by the slave device based on the serial number message, where the target serial number message is generated by the slave device based on its serial number and the encryption algorithms it supports;

[0034] Construct a target identifier allocation message according to the target encryption algorithm and the target identifier allocated to the slave device, so that the slave device can parse the target encryption algorithm through the target identifier allocation message and implement encryption and decryption processing of the service transmission channel based on the target encryption algorithm.

[0035] Combined with the third aspect, in an implementation manner, the constructing a target identifier allocation message according to the target encryption algorithm and the target identifier allocated to the slave device includes:

[0036] Perform a write operation on the identifier byte in the identifier allocation message according to the target identifier allocated to the slave device, and perform a write operation on the reserved byte in the identifier allocation message according to the target encryption algorithm, so as to generate a target identifier allocation message;

[0037] Among them, the slave device determines the target encryption algorithm decided by the master device according to the value of the reserved byte in the target identifier allocation message.

[0038] Combined with the third aspect, in an implementation manner, the target serial number message is generated by the slave device based on its serial number and the encryption algorithms it supports, including:

[0039] The slave device performs a write operation on the serial number byte in the serial number message according to its serial number, and performs a write operation on the reserved byte in the serial number message based on the encryption algorithms it supports, so as to generate a target serial number message;

[0040] Among them, the master device determines the type of encryption algorithm supported by the slave device according to the value of the reserved byte in the target serial number message.

[0041] Combined with the third aspect, in an implementation manner, the method further includes:

[0042] Determine the updated encryption algorithm based on the encryption algorithm expected to be used by the user, and perform a write operation on the reserved bytes in the key message according to the updated encryption algorithm to generate a target key message;

[0043] Send the target key message to the slave device, so that the slave device in the running state can determine the updated encryption algorithm decided by the master device through the value of the reserved bytes in the target key message, and generate a new key according to the updated encryption algorithm;

[0044] When receiving the new key sent by the slave device, perform key update based on the new key.

[0045] In a fourth aspect, an embodiment of the present application provides an encryption algorithm dynamic negotiation device, including a master device, and the master device is used for:

[0046] Send a serial number request message to the slave device in a broadcast manner;

[0047] When receiving a target serial number message sent by the slave device in the serial number state based on the serial number request message, determine a target encryption algorithm from the encryption algorithms supported by the slave device based on the serial number message, and the target serial number message is generated by the slave device based on its serial number and the encryption algorithms it supports;

[0048] Construct a target identifier allocation message according to the target encryption algorithm and the target identifier allocated to the slave device, so that the slave device can parse the target encryption algorithm through the target identifier allocation message and perform encryption and decryption processing on the service transmission channel based on the target encryption algorithm.

[0049] Combined with the fourth aspect, in an embodiment, the master device is specifically used for:

[0050] Perform a write operation on the identifier bytes in the identifier allocation message according to the target identifier allocated to the slave device, and perform a write operation on the reserved bytes in the identifier allocation message according to the target encryption algorithm to generate a target identifier allocation message;

[0051] Wherein, the slave device determines the target encryption algorithm decided by the master device through the value of the reserved bytes in the target identifier allocation message.

[0052] Combined with the fourth aspect, in an embodiment, the slave device is specifically used for:

[0053] Perform a write operation on the serial number bytes in the serial number message according to its serial number, and perform a write operation on the reserved bytes in the serial number message based on the encryption algorithms it supports to generate a target serial number message;

[0054] Among them, the master device determines the type of encryption algorithm supported by the slave device according to the value of the reserved byte in the target serial number message.

[0055] Combined with the fourth aspect, in an implementation, the master device is further configured to:

[0056] Determine the updated encryption algorithm based on the encryption algorithm expected to be used by the user, and perform a write operation on the reserved byte in the key message according to the updated encryption algorithm to generate a target key message;

[0057] Send the target key message to the slave device, so that the slave device in the running state can determine the updated encryption algorithm decided by the master device according to the value of the reserved byte in the target key message, and generate a new key according to the updated encryption algorithm;

[0058] When receiving the new key sent by the slave device, perform key update based on the new key.

[0059] In a fifth aspect, an embodiment of the present application provides an encryption algorithm dynamic negotiation device, which includes a processor, a memory, and an encryption algorithm dynamic negotiation program stored on the memory and executable by the processor. When the encryption algorithm dynamic negotiation program is executed by the processor, the steps of the encryption algorithm dynamic negotiation method as described above are implemented.

[0060] In a sixth aspect, an embodiment of the present application provides a computer-readable storage medium, on which an encryption algorithm dynamic negotiation program is stored. When the encryption algorithm dynamic negotiation program is executed by a processor, the steps of the encryption algorithm dynamic negotiation method as described above are implemented.

[0061] The beneficial effects brought by the technical solution provided by the embodiment of the present application at least include:

[0062] The slave device in the serial number state constructs a target serial number message including the serial number of the slave device and the encryption algorithms supported by the slave device to inform the master device of the multiple encryption algorithms it supports, so that the master device can decide the target encryption algorithm from the multiple encryption algorithms it supports based on this target serial number message, and construct a target identifier allocation message according to this target encryption algorithm to inform the slave device of the encryption algorithm it decides through this identifier allocation message, so that the slave device can learn the target encryption algorithm decided by the master device after parsing the identifier allocation message, and use this target encryption algorithm as the result of the negotiation between the two parties to encrypt and decrypt the service transmission channel. Through the present application, the negotiation of multiple encryption algorithms between the master and slave devices can be effectively realized without changing the existing interaction process. Description of the Drawings

[0063] Figure 1Schematic flowchart of the first embodiment of the encryption algorithm dynamic negotiation method of the present application;

[0064] Figure 2 Schematic flowchart of the second embodiment of the encryption algorithm dynamic negotiation method of the present application;

[0065] Figure 3 Schematic flowchart of the encryption algorithm negotiation process involved in the embodiment solution of the present application;

[0066] Figure 4 Schematic flowchart of the key update process involved in the embodiment solution of the present application;

[0067] Figure 5 Schematic hardware structure diagram of the encryption algorithm dynamic negotiation device involved in the embodiment solution of the present application. Detailed implementation manners

[0068] In order to enable those skilled in the art to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0069] To make the purpose, technical solution and advantages of the present application clearer, the following will further describe the embodiments of the present application in detail with reference to the accompanying drawings.

[0070] In a first aspect, an embodiment of the present application provides an encryption algorithm dynamic negotiation method.

[0071] In one embodiment, referring to Figure 1 , Figure 1 is the schematic flowchart of the first embodiment of the encryption algorithm dynamic negotiation method of the present application. As Figure 1 shown, the encryption algorithm dynamic negotiation method is applied to a slave device, and the method includes the following steps:

[0072] Step S10: When the slave device in the serial number state receives the serial number request message broadcast by the master device, construct a target serial number message, where the target serial number message includes the serial number of the slave device and the encryption algorithms supported by the slave device.

[0073] Exemplary, it should be noted that the encryption algorithm dynamic negotiation method provided in this embodiment is not only applicable to the dynamic negotiation of encryption algorithms between the Main FTTR Unit (MFU) and the Sub FTTR Unit (SFU) of the GPON / 10GPON system in the FTTR, but also applicable to the GPON / 10GPON system based on the Optical Line Terminal (OLT) and the Optical Network Unit (ONU) to achieve the dynamic negotiation of encryption algorithms between the OLT and the ONU; therefore, the slave device in this embodiment can be either the SFU or the ONU. Similarly, the master device can be either the MFU or the OLT; however, it should be understood that if the master device is the MFU, the slave device should be the SFU, and if the master device is the OLT, the slave device should be the ONU. In addition, since the processes and principles of the encryption algorithm dynamic negotiation in the above two scenarios are similar, for the sake of simplicity of description, the subsequent embodiments will take the master device as the MFU and the slave device as the SFU as an example to illustrate the processes and principles of the encryption algorithm dynamic negotiation between the master and slave devices.

[0074] It can be understood that the FTTR GPON / 10GPON system protocol stack is mainly composed of the Physical Layer (PHY) and the Data Link Layer (DLL), and the DLL layer includes two sub-layers: the framing sub-layer and the service adaptation sub-layer; among them, the service adaptation sub-layer is responsible for the encapsulation, multiplexing, and delimit of the upper-layer user services and management messages, and the framing sub-layer is responsible for the processing of PLOAM (Physical Layer OAM, which is a kind of Physical Layer OAM (Operation, Administration and Maintenance) message) messages, performance monitoring, key management, energy-saving management, and the framing of DLL frames or DLL bursts.

[0075] In this embodiment, for the MFU and SFU of the GPON / 10GPON system in the FTTR, the encryption algorithm negotiation between the master and slave gateways will be achieved by extending the PLOAM messages between the GPON / 10GPON master and slave gateways, and the gemport channel will be encrypted and decrypted based on the negotiated encryption algorithm. Among them, when extending the PLOAM messages of the framing sub-layer in this embodiment, the extended messages include the Serial_Number_SFU corresponding to the upstream message (i.e., the message sent by the SFU to the MFU) and the Assign_SFU-ID corresponding to the downstream message (i.e., the message sent by the MFU to the SFU).

[0076] It should be understood that the slave gateway SFU will go through the following seven states from power-on: O1 Initial State, O2 Standby State, O3 Serial Number State, O4 Ranging State, O5 Operating State, O6 POPUP State, and O7 Emergency Stop State; the activation of the slave gateway SFU includes three stages: downlink synchronization stage, serial number acquisition stage (i.e., SFU discovery stage), and ranging stage (optional), so the activation of the slave gateway SFU involves the four states of O1 Initial State, O2 Standby State, O3 Serial Number State, and O4 Ranging State. Among them, in this embodiment, the negotiation of the encryption algorithm will be implemented in the serial number acquisition stage (that is, when the slave gateway SFU is in the O3 Serial Number State).

[0077] Specifically, the master gateway MFU will periodically broadcast a serial number request message to the slave gateway SFU; and the serial number message Serial_Number_SFU is used by the slave gateway SFU in the serial number state to respond to the serial number request periodically broadcast by the master gateway MFU. This message contains the serial number of the slave gateway SFU, so that after receiving the Serial_Number_SFU message, the master gateway MFU can obtain the serial number of the slave gateway SFU and allocate an unused identifier SFU-ID to the slave gateway SFU. Therefore, when the slave gateway SFU receives the serial number request message broadcast by the master gateway MFU in the serial number acquisition stage, it will respond to the serial number request periodically broadcast by the master gateway MFU by sending the serial number message Serial_Number_SFU, that is, announce its existence in the FTTR system by responding to the serial number authorization to notify the master gateway MFU that it expects to join the FTTR network. It should be noted that the serial number authorization is an allocation structure whose purpose is to broadcast the Alloc-ID and mark the PLOAMu identification set; where Alloc-ID (Allocation Identifier) represents the allocation identifier, which is used to identify the service-bearing entity that is the receiver of the uplink bandwidth allocation within the slave gateway SFU; PLOAMu represents the uplink PLOAM message.

[0078] It should be understood that when the slave gateway SFU writes its serial number into the serial number message Serial_Number_SFU to respond to the serial number request broadcast by the master gateway MFU, it also needs to write the encryption algorithm supported by itself into the serial number message Serial_Number_SFU to construct the target serial number message; and send the target serial number message to the master gateway MFU, so that the master gateway MFU can learn about the encryption algorithm supported by the slave gateway SFU through the target serial number message. It should be noted that the encryption algorithms supported by the slave gateway SFU include but are not limited to the AES128 encryption algorithm, national cryptography SM1, SM2, SM3, SM4, and homomorphic encryption.

[0079] Further, in one embodiment, the constructing of the target serial number message includes:

[0080] Performing a write operation on the serial number bytes in the serial number message according to the serial number of the slave device, and performing a write operation on the reserved bytes in the serial number message based on the encryption algorithm supported by the slave device itself, to generate a target serial number message;

[0081] Wherein, the master device determines the type of encryption algorithm supported by the slave device through the value of the reserved bytes in the target serial number message.

[0082] Exemplarily, in this embodiment, the slave gateway SFU will report the encryption algorithm it supports to the master gateway MFU through the target serial number message. Specifically, after the slave gateway SFU receives the serial number authorization broadcast message sent by the master gateway MFU in the O2 - O3 state, it writes its own serial number into the serial number message Serial_Number_SFU to announce its existence to the master gateway MFU by replying the serial number message Serial_Number_SFU; at the same time, it needs to write the encryption algorithm it supports into the reserved bytes in the serial number message Serial_Number_SFU to generate a target serial number message, that is, in this embodiment, the reserved bytes in the serial number message Serial_Number_SFU will be extended for use to report the encryption algorithm currently supported by the slave gateway SFU to the master gateway MFU.

[0083] It should be noted that if FTTR is a GPON system, refer to Table 1, it is preferable to extend the last two bit positions of the 12th byte reserved in the serial number message Serial_Number_SFU. That is, the two extended bits are used to report the encryption algorithm currently supported by the slave gateway SFU, and each bit represents an encryption algorithm. Therefore, 2 encryption algorithms E1 and E2 can be extended; for example, "01" means supporting encryption algorithm E1, "10" means supporting encryption algorithm E2, "11" means supporting both encryption algorithms E1, E2 and the default AES128 encryption algorithm, and "00" means only supporting the default AES128 encryption algorithm.

[0084] Table 1 Serial_Number_SFU Message Extension in GPON System

[0085]

[0086] Therefore, as shown in Table 1, the gateway SFU can set the values of the last two bits of the 12th byte in the serial number message Serial_Number_SFU according to the encryption algorithms it supports. For example, if the gateway SFU only extends one encryption algorithm E1, the last two bits of the 12th byte take the value "01"; if two encryption algorithms E1 and E2 need to be extended, the last two bits of the 12th byte take the value "11"; and if no extension of the encryption algorithm is required, that is, the main gateway MFU and the slave gateway SFU use the default AES128 algorithm for encryption and decryption, the last two bits of the 12th byte take the value "00". Then, the target serial number message is generated, enabling the main gateway MFU to determine the type of encryption algorithm supported by the slave gateway SFU based on the values of the two bits in the reserved byte of the target serial number message.

[0087] If the FTTR is a 10GPON system, as shown in Table 2, it is preferable to extend the 8 bits of any one of the reserved bytes in the serial number message Serial_Number_SFU from the 17th to the 36th and from the 38th to the 40th. And each bit represents an encryption algorithm, so 8 encryption algorithms E1 - E8 can be extended. And the corresponding bit set to 1 indicates that the slave gateway SFU supports this encryption algorithm. Therefore, if all the extended bits are set to 1, it means that the slave gateway SFU can extend the support for 8 encryption algorithms while supporting the default AES128 encryption algorithm. For example, "0000001" indicates support for encryption algorithm E1, "00000011" indicates support for encryption algorithms E1 and E2, and so on. "11111111" indicates support for encryption algorithms E1 to E8 and the default AES128 encryption algorithm, while "00000000" indicates support only for the default AES128 encryption algorithm.

[0088] Table 2 Serial_Number_SFU Message Extension in 10GPON System

[0089]

[0090]

[0091] Therefore, as shown in Table 2, the gateway SFU can set the values of 8 bits of the reserved bytes in the serial number message Serial_Number_SFU according to the encryption algorithms it supports; for example, if the gateway SFU only extends one encryption algorithm E1, the 40th byte is set to "00000001", if two encryption algorithms E1 and E2 need to be extended, the 40th byte is set to "00000011", and so on. If E1 to E8 need to be extended, the 40th byte is set to "11111111". If no extension of the encryption algorithm is required, that is, the main gateway MFU and the slave gateway SFU use the default AES128 algorithm for encryption and decryption, the 40th byte is set to "00000000", and then the target serial number message is generated, so that the main gateway MFU can determine the type of encryption algorithm supported by the slave gateway SFU through the values of 8 bits of the reserved bytes in the target serial number message.

[0092] Step S20: Send the target serial number message to the master device, so that the master device can decide the target encryption algorithm from the encryption algorithms supported by the slave device based on the target serial number message, and construct a target identifier allocation message according to the target encryption algorithm and the target identifier assigned to the slave device.

[0093] Exemplarily, in this embodiment, after the slave gateway SFU completes the construction of the target serial number message, it will send the target serial number message to the main gateway MFU, so that the main gateway MFU can learn the encryption algorithms supported by the slave gateway SFU after parsing the target serial number message; then the main gateway MFU will randomly select one of the encryption algorithms supported by the slave gateway SFU or select the corresponding encryption algorithm from the encryption algorithms supported by the slave gateway SFU according to the pre-specified requirements as the target encryption algorithm for both parties; then set the values of the reserved bytes in the identifier allocation message Assign_SFU-ID according to the type of the determined target encryption algorithm, and at the same time write the unique target identifier assigned to the slave gateway SFU into the identifier allocation message Assign_SFU-ID to generate a target identifier allocation message, and send the target identifier allocation message to the slave gateway SFU.

[0094] Step S30: When receiving the target identifier allocation message sent by the master device, parse the target identifier allocation message to obtain the target encryption algorithm, so as to implement the encryption and decryption processing of the service transmission channel through the target encryption algorithm.

[0095] Exemplarily, in this embodiment, after receiving the target identifier allocation message sent by the master gateway MFU from the gateway SFU, the corresponding reserved bytes in the target identifier allocation message will be parsed to obtain the negotiated encryption algorithm (i.e., the target encryption algorithm) returned by the master gateway MFU, so that the subsequent gateway SFU and the master gateway MFU can use this encryption algorithm to encrypt and decrypt the gemport channel. It can be seen that this embodiment can effectively implement the negotiation of multiple encryption algorithms between the master and slave gateways without changing the existing interaction process.

[0096] Further, in one embodiment, when the slave device is in the running state, the method further includes:

[0097] When receiving the target key message sent by the master device, parse the target key message to obtain the updated encryption algorithm, where the target key message is generated by the master device based on the encryption algorithm expected to be used by the user;

[0098] Generate a new key according to the updated encryption algorithm and send the new key to the master device to achieve key update between the slave device and the master device.

[0099] Exemplarily, during the connection lifetime of the gateway SFU, that is, when the gateway SFU is in the running state, if the user modifies the encryption method through configuration, this embodiment will change the encryption algorithm between the master gateway MFU and the gateway SUF by extending the key message regularly sent by the master gateway MFU, so as to trigger the gateway SFU to generate a new key and send the new key to the master gateway MFU.

[0100] Specifically, when the user pre-sets the encryption algorithm used for the gemport channel in the FTTR GPON / 10GPON system (this encryption algorithm is the encryption algorithm expected to be used by the user) through configuration on the master gateway MFU, the master gateway MFU writes the encryption algorithm expected to be used by the user as the updated encryption algorithm into the key message (such as the Request_Key in the GPON system or the Key_Control message in the 10GPON system) to generate the target key message; then sends the target key message to the gateway SFU, so that the gateway SFU can, after parsing the target key message, learn the updated encryption algorithm newly determined by the master gateway MFU, generate a new key according to the updated encryption algorithm, and reply to the master gateway MFU with the new key through a message, thereby realizing the key update between the gateway and the master gateway, so that the master and slave gateways use the new encryption algorithm and key for encryption and decryption subsequently.

[0101] It should be noted that for the 10GPON system, the slave gateway SFU can reply with a new key to the master gateway MFU through the Key_Report message; while for the GPON system, the slave gateway SFU can reply with a new key to the master gateway MFU through the Encryption_Key message.

[0102] Furthermore, in one embodiment, the target key message is generated by the master device based on the encryption algorithm expected to be used by the user, and includes:

[0103] The master device determines the updated encryption algorithm based on the encryption algorithm expected to be used by the user, and performs a write operation on the reserved bytes in the key message according to the updated encryption algorithm to generate the target key message;

[0104] Among them, the slave device determines the updated encryption algorithm decided by the master device through the value of the reserved bytes in the target key message.

[0105] Exemplarily, in this embodiment, since the encryption algorithm expected to be used by the user may be the same as or different from the encryption algorithm currently used by the system, when the master gateway MFU receives the encryption algorithm expected to be used by the user configured by the user, it needs to match it with the encryption algorithm currently used by the system; if they are the same, the key update process is not triggered; if they are different, the encryption algorithm expected to be used by the user is written into the reserved bytes of the key message as the updated encryption algorithm to generate the target key message, that is, in this embodiment, the reserved bytes in the key message are extended for use to inform the slave gateway SFU of the updated encryption algorithm of the master gateway MFU.

[0106] It should be noted that in the GPON system, as shown in Table 3, it is preferable to extend the lower 2 bits of the 3rd byte of the key message Request_Key, that is, the extended lower 2 bits are used to inform the slave gateway SFU of the currently selected updated encryption algorithm; for example, "01" means the master gateway MFU selects the encryption algorithm E1, "10" means the master gateway MFU selects the encryption algorithm E2, and "00" means the master gateway MFU selects the default AES128 encryption algorithm.

[0107] Table 3 Extension of the Request_Key message in the GPON system

[0108]

[0109] Therefore, the master gateway MFU can set the values of the lower 2 bits of the 3rd byte in the key message Request_Key according to the updated encryption algorithm determined, so as to generate a target key message, enabling the slave gateway SFU to determine the updated encryption algorithm that both parties need to use jointly through the values of the lower 2 bits of the reserved bytes in the target key message. That is, after the slave gateway SFU receives the Request_Key message, it parses the new encryption method from the message. If the encryption algorithm changes, it uses the new encryption algorithm to generate a new key and replies to the master gateway MFU through the Encryption Key message.

[0110] In the 10GPON system, as shown in Table 4, it is preferable to extend the lower 4 bits of the 5th byte of the key message Key_Control. That is, the extended lower 4 bits are used to inform the slave gateway SFU of the currently selected updated encryption algorithm. Among them, different values can be assigned to the lower 4 bits in binary to represent different selected encryption algorithms. However, the specific correspondence between the actual values of the lower 4 bits and different encryption algorithms can be determined according to actual requirements and is not limited here. For example, "0001" means the master gateway MFU selects the encryption algorithm E1, "0010" means the master gateway MFU selects the encryption algorithm E2, "0011" means the master gateway MFU selects the encryption algorithm E3, "0100" means the master gateway MFU selects the encryption algorithm E4, "0101" means the master gateway MFU selects the encryption algorithm E5, "0110" means the master gateway MFU selects the encryption algorithm E6, "0111" means the master gateway MFU selects the encryption algorithm E7, "1000" means the master gateway MFU selects the encryption algorithm E8, and "0000" means the master gateway MFU selects the default AES128 encryption algorithm.

[0111] It should be noted that the extended lower 4 bits need to be used in conjunction with the value of byte 6 in the key message Key_Control. There are the following two cases for the value of the 6th byte: (1) Generate and send a new key; (2) Confirm the existing key. If the master gateway MFU needs to modify the existing encryption algorithm, the 6th byte takes the value "Generate and send a new key", that is, C = 0, to request the slave gateway SFU to generate a new key according to the encryption algorithm of the 5th extended byte, and inform the slave gateway SFU of the new encryption algorithm through the extended byte. If the master gateway MFU does not need to modify the existing encryption algorithm, the 6th byte takes the value "Confirm the existing key", that is, C = 1, so that the slave gateway SFU does not need to generate a new key according to the encryption algorithm of the 5th extended byte, but only needs to inform the slave gateway SFU of the new encryption algorithm through the extended byte. Therefore, after receiving the Key_Control message, the slave gateway SFU can parse the new encryption method from the message. If the encryption algorithm changes, it uses the new encryption algorithm to generate a new key and replies to the master gateway MFU through the Encryption Key message.

[0112] Table 4 Key Control Message Extension in 10GPON System

[0113]

[0114] In a second aspect, an embodiment of the present application further provides an encryption algorithm dynamic negotiation device.

[0115] In one embodiment, the encryption algorithm dynamic negotiation device includes a slave device, and the slave device is used for:

[0116] When the slave device in the serial number state receives the serial number request message broadcast by the master device, construct a target serial number message, where the target serial number message includes the serial number of the slave device and the encryption algorithms supported by the slave device;

[0117] Send the target serial number message to the master device for the master device to decide the target encryption algorithm from the encryption algorithms supported by the slave device based on the target serial number message, and construct a target identifier allocation message according to the target encryption algorithm and the target identifier allocated to the slave device;

[0118] When receiving the target identifier allocation message sent by the master device, parse the target encryption algorithm from the target identifier allocation message to implement the encryption and decryption processing of the service transmission channel through the target encryption algorithm.

[0119] Further, in one embodiment, the slave device is specifically used for:

[0120] Write the serial number bytes in the serial number message according to the serial number of the slave device, and write the reserved bytes in the serial number message based on the encryption algorithm supported by the slave device itself to generate a target serial number message;

[0121] Among them, the master device determines the type of encryption algorithm supported by the slave device according to the value of the reserved bytes in the target serial number message.

[0122] Further, in an embodiment, when the slave device is in an operating state, the slave device is further configured to:

[0123] If a target key message sent by the master device is received, parse the target key message to obtain an updated encryption algorithm, where the target key message is generated by the master device based on the encryption algorithm expected to be used by the user;

[0124] Generate a new key according to the updated encryption algorithm, and send the new key to the master device to implement key update between the slave device and the master device.

[0125] Further, in an embodiment, the master device is specifically configured to:

[0126] Determine an updated encryption algorithm based on the encryption algorithm expected to be used by the user, and write the reserved bytes in the key message according to the updated encryption algorithm to generate a target key message;

[0127] Among them, the slave device determines the updated encryption algorithm decided by the master device according to the value of the reserved bytes in the target key message.

[0128] Among them, the function implementation of each module in the above encryption algorithm dynamic negotiation device corresponds to each step in the above encryption algorithm dynamic negotiation method embodiment, and its function and implementation process will not be described in detail here.

[0129] In a third aspect, the embodiments of the present application further provide another encryption algorithm dynamic negotiation method.

[0130] In an embodiment, refer to Figure 2 , Figure 2 is a schematic flowchart of the second embodiment of the encryption algorithm dynamic negotiation method of the present application. As Figure 2 shown, the encryption algorithm dynamic negotiation method is applied to the master device, and the method includes the following steps:

[0131] Step N10: Send a serial number request message to the slave device in a broadcast manner.

[0132] Exemplarily, it should be noted that the encryption algorithm dynamic negotiation method provided in this embodiment is applicable not only to the dynamic negotiation of encryption algorithms between the FTTR master gateway and the slave gateway in the GPON / 10GPON system, but also to the GPON / 10GPON system based on the OLT and ONU to achieve the dynamic negotiation of encryption algorithms between the OLT and the ONU. Therefore, the slave device in this embodiment can be either the slave gateway or the ONU. Similarly, the master device can be either the master gateway or the OLT. However, it should be understood that if the master device is the master gateway, the slave device should be the slave gateway, and if the master device is the OLT, the slave device should be the ONU. In addition, since the processes and principles of the encryption algorithm dynamic negotiation in the above two scenarios are similar, for the sake of simplicity of description, the subsequent embodiments will take the master device as the master gateway MFU and the slave device as the slave gateway SFU as an example to illustrate the process and principle of the encryption algorithm dynamic negotiation between the master and slave devices.

[0133] It should be understood that when the slave gateway SFU is in the serial number state, if the user does not configure the encryption algorithm on the master gateway MFU, the encryption algorithm negotiation process does not need to be triggered. However, if the user pre-configures the encryption algorithm used by the gemport channel in the FTTR GPON / 10GPON system on the master gateway MFU, the master gateway MFU will periodically send a serial number request message to the slave gateway SFU in the form of a broadcast message, so that the slave gateway SFU in the serial number state can receive this message.

[0134] Step N20: When receiving the target serial number message sent by the slave device in the serial number state based on the serial number request message, determine the target encryption algorithm from the encryption algorithms supported by the slave device based on the serial number message. The target serial number message is generated by the slave device based on its serial number and the encryption algorithms it supports.

[0135] Exemplarily, it can be understood that the serial number message Serial_Number_SFU is used by the slave gateway SFU in the serial number state to respond to the serial number request periodically broadcast by the master gateway MFU. This message contains the serial number of the slave gateway SFU, so that after receiving the Serial_Number_SFU message, the master gateway MFU can obtain the serial number of the slave gateway SFU and allocate an unused identifier SFU-ID to the slave gateway SFU. Therefore, when the slave gateway SFU receives the serial number request message broadcast by the master gateway MFU during the serial number acquisition phase, it will respond to the serial number request periodically broadcast by the master gateway MFU by sending the serial number message Serial_Number_SFU, that is, announce its existence in the FTTR system by responding to the serial number authorization to notify the master gateway MFU that it expects to join the FTTR network.

[0136] It should be noted that when the slave gateway SFU writes its serial number into the serial number message Serial_Number_SFU to respond to the serial number request broadcast by the master gateway MFU, it also needs to write the encryption algorithm supported by itself into the serial number message Serial_Number_SFU to construct the target serial number message and send the target serial number message to the master gateway MFU; when the master gateway receives the target serial number message, it will parse the target serial number message to learn the encryption algorithm supported by the slave gateway SFU; then the master gateway MFU will randomly select one of the encryption algorithms supported by the slave gateway SFU or select the corresponding encryption algorithm from the encryption algorithms supported by the slave gateway SFU according to the pre-specified requirements as the target encryption algorithm for both parties. It should be understood that the encryption algorithms supported by the slave gateway SFU include but are not limited to the AES128 encryption algorithm, national cryptography SM1, SM2, SM3, SM4, and homomorphic encryption.

[0137] Further, in one embodiment, the target serial number message is generated by the slave device based on its serial number and the encryption algorithm it supports, including:

[0138] The slave device performs a write operation on the serial number bytes in the serial number message according to its serial number and performs a write operation on the reserved bytes in the serial number message based on the encryption algorithm it supports to generate the target serial number message;

[0139] Among them, the master device determines the type of encryption algorithm supported by the slave device through the value of the reserved bytes in the target serial number message.

[0140] Exemplarily, in this embodiment, the slave gateway SFU will report the encryption algorithm it supports to the master gateway MFU through the target serial number message. Specifically, after the slave gateway SFU receives the serial number authorization broadcast message sent by the master gateway MFU in the O2 - O3 state, it writes its own serial number into the serial number message Serial_Number_SFU to declare its existence to the master gateway MFU by replying to the serial number message Serial_Number_SFU; at the same time, it writes the encryption algorithm it supports into the reserved bytes in the serial number message Serial_Number_SFU to generate the target serial number message, that is, in this embodiment, the reserved bytes in the serial number message Serial_Number_SFU are extended for use to report the encryption algorithm currently supported by the slave gateway SFU to the master gateway MFU.

[0141] It should be noted that if FTTR is a GPON system, refer to Table 1 mentioned above. It is preferable to extend the last two bits of the 12th byte reserved in the Serial_Number_SFU message. The two extended bits are used to report the encryption algorithms currently supported by the gateway SFU. Each bit represents an encryption algorithm. Therefore, 2 encryption algorithms, E1 and E2, can be extended. For example, "01" indicates support for encryption algorithm E1, "10" indicates support for encryption algorithm E2, "11" indicates support for both encryption algorithms E1 and E2 as well as the default AES128 encryption algorithm, and "00" indicates support only for the default AES128 encryption algorithm.

[0142] Therefore, the gateway SFU can set the values of the last two bits of the 12th byte in the Serial_Number_SFU message according to the encryption algorithms it supports. For example, if the gateway SFU only extends one encryption algorithm E1, the last two bits of the 12th byte are set to "01". If two encryption algorithms E1 and E2 need to be extended, the last two bits of the 12th byte are set to "11". If no encryption algorithm extension is required, that is, the main gateway MFU and the gateway SFU use the default AES128 algorithm for encryption and decryption, the last two bits of the 12th byte are set to "00". Then, the target serial number message is generated, enabling the main gateway MFU to determine the type of encryption algorithm supported by the gateway SFU based on the values of the two bits in the reserved byte of the target serial number message.

[0143] If FTTR is a 10GPON system, refer to Table 2 mentioned above. It is preferable to extend 8 bits of any reserved byte in the range of the 17th to 36th and 38th to 40th bytes in the Serial_Number_SFU message. Each bit represents an encryption algorithm, so 8 encryption algorithms, E1 to E8, can be extended. And setting the corresponding bit to 1 indicates that the gateway SFU supports this encryption algorithm. Therefore, if all the extended bits are set to 1, it means that the gateway SFU can extend the support for 8 encryption algorithms while supporting the default AES128 encryption algorithm. For example, "0000001" indicates support for encryption algorithm E1, "00000011" indicates support for encryption algorithms E1 and E2, and so on. "11111111" indicates support for encryption algorithms E1 to E8 and the default AES128 encryption algorithm, while "00000000" indicates support only for the default AES128 encryption algorithm.

[0144] Therefore, the gateway SFU can set the values of the 8-bit reserved bytes in the Serial_Number_SFU message according to the encryption algorithms it supports. For example, if the gateway SFU only extends one encryption algorithm E1, the 40th byte is set to "00000001". If two encryption algorithms E1 and E2 need to be extended, the 40th byte is set to "00000011", and so on. If E1 to E8 need to be extended, the 40th byte is set to "11111111". If no extension of the encryption algorithm is required, that is, the main gateway MFU and the slave gateway SFU use the default AES128 algorithm for encryption and decryption, the 40th byte is set to "00000000", and then the target serial number message is generated, enabling the main gateway MFU to determine the type of encryption algorithm supported by the slave gateway SFU based on the values of the 8-bit reserved bytes in the target serial number message.

[0145] Step N30: Construct a target identifier allocation message according to the target encryption algorithm and the target identifier allocated to the slave device, so that the slave device can parse the target encryption algorithm through the target identifier allocation message and implement encryption and decryption processing of the service transmission channel based on the target encryption algorithm.

[0146] Exemplarily, in this embodiment, the main gateway MFU will set the values of the reserved bytes in the Assign_SFU-ID message according to the type of the target encryption algorithm it determines, and at the same time write the unique target identifier it allocates to the slave gateway SFU into the Assign_SFU-ID message to generate a target identifier allocation message, and send the target identifier allocation message to the slave gateway SFU. After the slave gateway SFU receives the target identifier allocation message sent by the main gateway MFU, it will parse the corresponding reserved bytes in the target identifier allocation message to obtain the negotiated encryption algorithm (i.e., the target encryption algorithm) returned by the main gateway MFU, and subsequently use this target encryption algorithm to encrypt and decrypt the gemport channel. It can be seen that this embodiment can effectively implement the negotiation of multiple encryption algorithms between the master and slave gateways without changing the existing interaction process.

[0147] In summary, in the PLOAM message interaction process between the existing master gateway MFU and slave gateway SFU of FTTR in this embodiment, the negotiation of encryption algorithms in the FTTR system is realized by expanding the existing messages. It not only does not require changing the existing interaction process, but also adds the support for multiple encryption algorithms and dynamic negotiation of encryption algorithms for gemport channels, realizes the requirement of coexistence of multiple keys, and further improves the compatibility of the product and the flexibility of encryption method selection. In addition, by negotiating the encryption algorithm and starting the encryption function before activating the slave gateway, the device security is improved; at the same time, this embodiment realizes that a chip can take into account the different encryption requirements of traditional PON gateways and FTTR gateways, which can maximize the protection of investment and reduce the chip cost.

[0148] Further, in one embodiment, constructing the target identifier allocation message according to the target encryption algorithm and the target identifier allocated to the slave device includes:

[0149] Performing a write operation on the identifier bytes in the identifier allocation message according to the target identifier allocated to the slave device, and performing a write operation on the reserved bytes in the identifier allocation message according to the target encryption algorithm to generate the target identifier allocation message;

[0150] Wherein, the slave device determines the target encryption algorithm decided by the master device through the value of the reserved bytes in the target identifier allocation message.

[0151] Exemplarily, it can be understood that the master gateway MFU discovers a newly added slave gateway SFU through the serial number of the slave gateway SFU and assigns a unique identifier SFU-ID to this slave gateway SFU; wherein, the SFU-ID is an 8-bit or 10-bit identifier assigned by the master gateway MFU to the slave gateway SFU using the identifier allocation message Assign_SFU-ID during the activation of the slave gateway SFU, and it is unique in a specific optical distribution network; when the slave gateway SFU enters the initial state of the activation state machine, it discards the previously assigned SFU-ID and all related data link layer configuration assignments. It can be seen that the identifier allocation message Assign_SFU-ID is a message triggered when the master gateway MFU discovers the serial number of a certain slave gateway SFU, that is, after receiving the Serial_Number_SFU message sent by the slave gateway SFU, which will cause the master gateway MFU to assign an unused target identifier SFU-ID to the slave gateway SFU and bind it to the serial number of the slave gateway SFU. Therefore, in this embodiment, the encryption algorithm used between the master gateway MFU and the slave gateway SFU will be confirmed by expanding the identifier allocation message Assign_SFU-ID, that is, the master gateway MFU will reply to the slave gateway SFU with the target encryption algorithm decided by both parties that they need to use together through the target identifier allocation message.

[0152] Specifically, after receiving the target sequence number message sent by the slave gateway SFU, the master gateway MFU will allocate a unique target identifier for the slave gateway SFU and write this target identifier into the identifier allocation message Assign_SFU-ID. At the same time, it is necessary to write the target encryption algorithm determined by it into the reserved bytes in the identifier allocation message Assign_SFU-ID to generate the target identifier allocation message. That is, in this embodiment, the reserved bytes in the identifier allocation message Assign_SFU-ID will be extended for use to inform the slave gateway SFU of the target encryption algorithm jointly used by the master gateway MFU.

[0153] It should be noted that when the extended identifier allocation message Assign_SFU-ID confirms the encryption algorithm used between the master gateway MFU and the slave gateway SFU, if FTTR is a GPON system, refer to Table 5 and preferably extend the lower 2 bits of the 12th reserved byte in the identifier allocation message Assign_SFU-ID to reply to the slave gateway SFU, that is, the extended lower 2 bits are used to inform the slave gateway SFU of the currently selected target encryption algorithm. For example, "01" means the master gateway MFU selects encryption algorithm E1, "10" means the master gateway MFU selects encryption algorithm E2, and "00" means the master gateway MFU selects the default AES128 encryption algorithm. Therefore, the master gateway MFU can set the value of the lower 2 bits of the 12th byte in the identifier allocation message Assign_SFU-ID according to the determined target encryption algorithm to generate the target identifier allocation message, so that the slave gateway SFU can determine the target encryption algorithm jointly required by both parties through the value of the lower 2 bits of the reserved bytes in the target identifier allocation message.

[0154] Table 5 Extension of Assign_SFU-ID Message in GPON System

[0155]

[0156] If the FTTR is a 10GPON system, refer to the lower 4 bits of the 16th byte reserved in the Assign_SFU-ID message of the preferred extended identifier allocation to reply to the slave gateway SFU. That is, the lower 4 bits are used to inform the slave gateway SFU of the currently selected target encryption algorithm. Among them, different values can be assigned to the lower 4 bits in binary to represent different selected encryption algorithms. However, the specific correspondence between the actual values of the lower 4 bits and different encryption algorithms can be determined according to actual requirements and is not limited here. For example, "0001" means the master gateway MFU selects encryption algorithm E1, "0010" means the master gateway MFU selects encryption algorithm E2, "0011" means the master gateway MFU selects encryption algorithm E3, "0100" means the master gateway MFU selects encryption algorithm E4, "0101" means the master gateway MFU selects encryption algorithm E5, "0110" means the master gateway MFU selects encryption algorithm E6, "0111" means the master gateway MFU selects encryption algorithm E7, "1000" means the master gateway MFU supports encryption algorithm E8, and "0000" means the master gateway MFU selects the default AES128 encryption algorithm. Therefore, the master gateway MFU can set the value of the lower 4 bits of the 16th byte in the identifier allocation message Assign_SFU-ID according to the determined target encryption algorithm to generate a target identifier allocation message, so that the slave gateway SFU can determine the target encryption algorithm that both parties need to use jointly through the value of the lower 4 bits of the reserved byte in the target identifier allocation message.

[0157] Table 6 Extension of Assign_SFU-ID Message in 10GPON System

[0158]

[0159]

[0160] Further, in one embodiment, the method further includes:

[0161] Determine the updated encryption algorithm based on the encryption algorithm expected to be used by the user, and perform a write operation on the reserved byte in the key message to generate a target key message;

[0162] Send the target key message to the slave device, so that the slave device in the running state can determine the updated encryption algorithm determined by the master device through the value of the reserved byte in the target key message, and generate a new key according to the updated encryption algorithm;

[0163] When receiving the new key sent by the slave device, perform key update based on the new key.

[0164] Exemplarily, during the connection lifetime of the gateway SFU, that is, when the gateway SFU is in the running state, if the user modifies the encryption method through configuration, in this embodiment, the encryption algorithm between the master gateway MFU and the slave gateway SUF will be changed by extending the key message regularly sent by the master gateway MFU, so as to trigger the slave gateway SFU to generate a new key and send the new key to the master gateway MFU.

[0165] It should be understood that since the encryption algorithm expected to be used by the user may be the same as or different from the encryption algorithm currently used by the system, when the master gateway MFU receives the encryption algorithm expected to be used by the user configured by the user, it needs to match it with the encryption algorithm currently used by the system; if they are the same, the key update process is not triggered; if they are different, the encryption algorithm expected to be used by the user is written into the reserved byte of the key message as the updated encryption algorithm to generate a target key message and send it to the slave gateway SFU, that is, in this embodiment, the reserved byte in the key message is extended for use to inform the slave gateway SFU of the updated encryption algorithm of the master gateway MFU. After receiving the target key message, the slave gateway SFU will parse it to learn the updated encryption algorithm newly determined by the master gateway MFU, generate a new key according to the updated encryption algorithm, and at the same time reply to the master gateway MFU with the new key through a message, thereby realizing the key update between the slave gateway and the master gateway, so that the master and slave gateways will use the new encryption algorithm and key for encryption and decryption subsequently.

[0166] It should be noted that in the GPON system, as shown in the aforementioned Table 3, it is preferable to extend the lower 2 bits of the 3rd byte of the key message Request_Key, that is, the extended lower 2 bits are used to inform the slave gateway SFU of the currently selected updated encryption algorithm; for example, "01" means that the master gateway MFU selects the encryption algorithm E1, "10" means that the master gateway MFU selects the encryption algorithm E2, and "00" means that the master gateway MFU selects the default AES128 encryption algorithm.

[0167] Therefore, in the scenario where the master gateway MFU specifies the usage scenario of the encryption method through configuration, if the master gateway MFU modifies the configuration to switch the encryption method, it will send a target key message to the slave gateway SFU to inform the modified encryption method. That is, the master gateway MFU can set the low 2 bits of the 3rd byte in the key message Request_Key according to the updated encryption algorithm determined, that is, set the low 2 bits of the 3rd byte of the key message Request_Key to the updated encryption algorithm. For example, if the master gateway MFU selects the encryption algorithm E1 as the updated encryption algorithm, the low 2 bits of the 3rd byte take the value of "01", and the value of "10" indicates that the encryption algorithm E2 is selected as the updated encryption algorithm, and the value of "00" indicates the use of the default encryption algorithm AES128, and then generate a target key message, so that the slave gateway SFU in the running state can determine the updated encryption algorithm that both parties need to use together through the value of the low 2 bits of the reserved byte in the target key message. Therefore, when the slave gateway SFU receives the Request_Key message, it will parse the new encryption method from the message. If the encryption algorithm changes, it will generate a new key using the new encryption algorithm and reply to the master gateway MFU through the Encryption Key message.

[0168] In a 10GPON system, the key message Key_Control is used for the master gateway MFU to instruct the slave gateway SFU to generate a new data encryption key with a specified length or confirm an existing data encryption key; as shown in Table 4 above, in this embodiment, it is preferable to extend the low 4 bits of the 5th byte of the key message Key_Control, that is, the extended low 4 bits are used to inform the slave gateway SFU of the currently selected updated encryption algorithm; among them, different values can be taken for the low 4 bits in binary to represent different selected encryption algorithms. However, the specific correspondence between the actual values of the low 4 bits and different encryption algorithms can be determined according to actual needs and is not limited here. For example, "0001" means that the master gateway MFU selects the encryption algorithm E1, "0010" means that the master gateway MFU selects the encryption algorithm E2, "0011" means that the master gateway MFU selects the encryption algorithm E3, "0100" means that the master gateway MFU selects the encryption algorithm E4, "0101" means that the master gateway MFU selects the encryption algorithm E5, "0110" means that the master gateway MFU selects the encryption algorithm E6, "0111" means that the master gateway MFU selects the encryption algorithm E7, "1000" means that the master gateway MFU selects the encryption algorithm E8, and "0000" means that the master gateway MFU selects the default AES128 encryption algorithm.

[0169] It should be noted that the extended lower 4 bits need to be used in conjunction with the value of byte 6 in the key message Key_Control. There are the following two cases for the value of the 6th byte: (1) Generate and send a new key; (2) Confirm the existing key. If the master gateway MFU needs to modify the existing encryption algorithm, the 6th byte takes the value of "Generate and send a new key" to require the slave gateway SFU to generate a new key according to the encryption algorithm of the 5th extended byte, and inform the slave gateway SFU of the new encryption algorithm through the extended byte. If the master gateway MFU does not need to modify the existing encryption algorithm, the 6th byte takes the value of "Confirm the existing key" so that the slave gateway SFU does not need to generate a new key according to the encryption algorithm of the 5th extended byte, but only inform the slave gateway SFU of the new encryption algorithm through the extended byte.

[0170] Therefore, in the scenario where the master gateway MFU specifies the use of an encryption method through configuration, if the master gateway MFU modifies the configuration to switch the encryption method, it will send a target key message to the slave gateway SFU to inform the modified encryption method, that is, the master gateway MFU can set the value of the lower 4 bits of the 5th byte in the key message Key_Control according to the updated encryption algorithm determined, that is, set the lower 4 bits of the 5th byte in the key message Key_Control to the updated encryption algorithm, and at the same time set the 6th byte to the value of "Generate and send a new key", and then generate the target key message. When the slave gateway SFU receives the target key message, it can parse the new encryption method from the message. If the encryption algorithm changes, it will use the new encryption algorithm to generate a new key and reply to the master gateway MFU through the Encryption Key message.

[0171] The following takes the master device as the master gateway MFU and the slave device as the slave gateway SFU as an example and combines Figure 3 to explain the overall process of encryption algorithm negotiation in the FTTR GPON / 10GPON system.

[0172] (1) The control encryption algorithm negotiation process is carried out when the slave gateway SFU is in the serial number state (i.e., the O3 state); first, the user pre-sets the encryption algorithm used by the gemport channel in the FTTR GPON / 10GPON system on the master gateway MFU through configuration. It should be noted that if the user does not configure the encryption algorithm, the key negotiation process will not be triggered.

[0173] (2) The master gateway MFU periodically sends a serial number request message to the slave gateway SFU in the form of a broadcast message, so that the slave gateway SFU in the serial number state receives the message.

[0174] (3) When receiving a serial number request message from the gateway SFU, send a Serial_Number_SFU message to reply to the master gateway MFU; it should be noted that the Serial_Number_SFU message not only needs to carry the serial number of the gateway SFU, but also needs to inform the master gateway MFU of the encryption algorithms supported by the gateway SFU through message extension; for the specific extension method and principle of the Serial_Number_SFU message, refer to the foregoing embodiments and will not be elaborated herein.

[0175] (4) After the master gateway MFU receives the Serial_Number_SFU sent by the gateway SFU, if the user has pre-set an encryption algorithm, directly use the pre-set encryption algorithm as the target encryption algorithm, and if the user has not pre-set an encryption algorithm, randomly specify an encryption algorithm from the encryption algorithms recorded in the Serial_Number_SFU as the target encryption algorithm; it should be noted that the encryption algorithm pre-set by the user is derived from the encryption algorithms supported by the gateway SFU, that is, the encryption algorithms supported by the gateway SFU must cover the encryption algorithms pre-set by the user.

[0176] (5) After the master gateway MFU confirms the currently used target encryption algorithm, extend the Assign_SFU-ID message sent to the gateway SFU to specify the target encryption algorithm as the encryption algorithm between the master gateway MFU and the gateway SFU, so that the gateway SFU can encrypt and decrypt the Gemport channel through the target encryption algorithm specified by the Assign_SFU-ID message; it should be noted that for the specific extension method and principle of the Assign_SFU-ID message, refer to the foregoing embodiments and will not be elaborated herein.

[0177] The following takes the master device as the master gateway MFU and the slave device as the gateway SFU as an example and combines Figure 4 to explain the overall process of key update in the FTTR GPON / 10GPON system.

[0178] (1) The control key update process is carried out when the gateway SFU is in the running state (i.e., the O5 state); first, within the connection lifetime of the gateway SFU, the user modifies the encryption algorithm on the master gateway MFU to generate the encryption algorithm expected to be used.

[0179] (2) The master gateway MFU compares whether the encryption algorithm expected to be used by the user is the same as the encryption algorithm currently used by the system. If they are the same, no processing is performed; if they are different, the master gateway MFU will inform the slave gateway SFU of the encryption algorithm update. Among them, in the GPON system, the master gateway MFU will inform the slave gateway SFU of the encryption algorithm update by extending the Request_Key message, that is, the updated encryption algorithm is carried in this message; while in the 10GPON system, the master gateway MFU will inform the slave gateway SFU of the encryption algorithm update by extending the Key_Control message, that is, the updated encryption algorithm is carried in this message, and the slave gateway SFU is required to generate and send a new key. It should be noted that the specific extension methods and principles of the Request_Key message and the Key_Control message can be referred to the foregoing embodiments and will not be elaborated here.

[0180] (3) After receiving the Request_Key / Key_Control message, the slave gateway SFU will obtain the updated encryption algorithm from it, generate a new key based on the updated encryption algorithm, and reply with a message to inform the master gateway MFU of the new key. Among them, in the GPON system, the slave gateway SFU can reply to the master gateway MFU with the new key through the Encryption_Key message; while in the 10GPON system, the slave gateway SFU can reply to the master gateway MFU with the new key through the Key_Report message.

[0181] Fourthly, the embodiment of the present application also provides another encryption algorithm dynamic negotiation device.

[0182] In one embodiment, another encryption algorithm dynamic negotiation device includes a master device, and the master device is used for:

[0183] Sending a sequence number request message to a slave device in a broadcast manner;

[0184] When receiving a target sequence number message sent by the slave device in the sequence number state based on the sequence number request message, determining a target encryption algorithm from the encryption algorithms supported by the slave device based on the sequence number message, where the target sequence number message is generated by the slave device based on its sequence number and the encryption algorithms it supports;

[0185] Constructing a target identifier allocation message according to the target encryption algorithm and the target identifier allocated to the slave device, so that the slave device can parse the target encryption algorithm through the target identifier allocation message and perform encryption and decryption processing on the service transmission channel based on the target encryption algorithm.

[0186] Further, in one embodiment, the master device is specifically used for:

[0187] Write the identifier bytes in the identifier allocation message according to the target identifier allocated to the slave device, and write the reserved bytes in the identifier allocation message according to the target encryption algorithm to generate a target identifier allocation message;

[0188] Among them, the slave device determines the target encryption algorithm decided by the master device through the value of the reserved bytes in the target identifier allocation message.

[0189] Further, in an embodiment, the slave device is specifically used for:

[0190] Write the serial number bytes in the serial number message according to its serial number, and write the reserved bytes in the serial number message based on the encryption algorithm supported by itself to generate a target serial number message;

[0191] Among them, the master device determines the type of encryption algorithm supported by the slave device through the value of the reserved bytes in the target serial number message.

[0192] Further, in an embodiment, the master device is further used for:

[0193] Determine the updated encryption algorithm based on the encryption algorithm expected to be used by the user, and write the reserved bytes in the key message according to the updated encryption algorithm to generate a target key message;

[0194] Send the target key message to the slave device, so that the slave device in the running state determines the updated encryption algorithm decided by the master device through the value of the reserved bytes in the target key message, and generates a new key according to the updated encryption algorithm;

[0195] When receiving the new key sent by the slave device, perform key update based on the new key.

[0196] Among them, the function implementation of each module in the above encryption algorithm dynamic negotiation device corresponds to each step in the above encryption algorithm dynamic negotiation method embodiment, and its function and implementation process will not be described in detail here.

[0197] In a fifth aspect, an embodiment of the present application provides an encryption algorithm dynamic negotiation device, and the encryption algorithm dynamic negotiation device may be a device with data processing functions such as a personal computer (PC), a notebook computer, a server, etc.

[0198] Refer to Figure 5 , Figure 5 This is a schematic diagram of the hardware structure of the encryption algorithm dynamic negotiation device involved in the solution of the embodiment of the present application. In the embodiment of the present application, the encryption algorithm dynamic negotiation device may include a processor, a memory, a communication interface, and a communication bus.

[0199] Among them, the communication bus can be of any type and is used to interconnect the processor, the memory, and the communication interface.

[0200] The communication interface includes input / output (I / O) interfaces, physical interfaces, and logical interfaces, etc., which are used to implement the interconnection of components inside the device for dynamic negotiation of encryption algorithms, as well as interfaces for implementing the interconnection between the device for dynamic negotiation of encryption algorithms and other devices (such as other computing devices or user devices). The physical interface can be an Ethernet interface, a fiber optic interface, an ATM interface, etc.; the user device can be a display, a keyboard, etc.

[0201] The memory can be various types of storage media, such as random access memory (RAM), read-only memory (ROM), non-volatile RAM (NVRAM), flash memory, optical memory, hard disk, programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), etc.

[0202] The processor can be a general-purpose processor, and the general-purpose processor can call the encryption algorithm dynamic negotiation program stored in the memory and execute the encryption algorithm dynamic negotiation method provided by the embodiments of the present application. For example, the general-purpose processor can be a central processing unit (CPU). Among them, the method executed when the encryption algorithm dynamic negotiation program is called can refer to the various embodiments of the encryption algorithm dynamic negotiation method of the present application, which will not be elaborated here.

[0203] Those skilled in the art can understand that Figure 5 the hardware structure shown in [[ ]] does not constitute a limitation to the present application, and it may include more or fewer components than shown in the figure, or combine some components, or have different component arrangements.

[0204] In a sixth aspect, the embodiments of the present application further provide a computer-readable storage medium.

[0205] An encryption algorithm dynamic negotiation program is stored on the readable storage medium of the present application. When the encryption algorithm dynamic negotiation program is executed by a processor, the steps of the encryption algorithm dynamic negotiation method as described above are implemented.

[0206] Among them, the method implemented when the encryption algorithm dynamic negotiation program is executed can refer to the various embodiments of the encryption algorithm dynamic negotiation method of this application, which will not be elaborated here.

[0207] It should be noted that the terms "including" and "having" in the specification, claims and above-mentioned drawings of this application, and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally further include steps or units not listed, or may optionally further include other steps or units inherent to these processes, methods, products or devices. The descriptions of "first", "second", "third", etc. are used to distinguish different objects, etc., and do not represent a sequence, nor do they limit that "first", "second", and "third" are different types.

[0208] In the description of the embodiments of this application, "exemplary", "for example" or "for instance" are used to give examples, illustrations or explanations. Any embodiment or design solution described as "exemplary", "for example" or "for instance" in the embodiments of this application should not be construed as more preferred or more advantageous than other embodiments or design solutions. Rather, the use of words such as "exemplary", "for example" or "for instance" is intended to present relevant concepts in a specific manner.

[0209] In some processes described in the embodiments of this application, multiple operations or steps appear in a specific order. However, it should be understood that these operations or steps may not be executed in the order in which they appear in the embodiments of this application or may be executed in parallel. The serial numbers of the operations are only used to distinguish different operations, and the serial numbers themselves do not represent any execution order. In addition, these processes may include more or fewer operations, and these operations or steps may be executed in order or in parallel, and these operations or steps may be combined.

[0210] The above are only the preferred embodiments of this application, and do not limit the patent scope of this application accordingly. Any equivalent structural or equivalent process transformation made using the content of the specification and drawings of this application, or directly or indirectly applied in other related technical fields, shall be equally included in the patent protection scope of this application.

Claims

1. A method for dynamically negotiating an encryption algorithm, characterized in that, The encryption algorithm dynamic negotiation method is applied to a slave device, and the method includes the following steps: When the slave device in the serial number state receives the serial number request message broadcast by the master device, a target serial number message is constructed, and the target serial number message includes the serial number of the slave device and the encryption algorithms supported by the slave device; The target serial number message is sent to the master device for the master device to decide on a target encryption algorithm from the encryption algorithms supported by the slave device based on the target serial number message, and construct a target identifier allocation message according to the target encryption algorithm and the target identifier allocated to the slave device; When receiving the target identifier allocation message sent by the master device, parse the target identifier allocation message to obtain the target encryption algorithm, so as to implement the encryption and decryption processing of the service transmission channel through the target encryption algorithm; The construction of the target serial number message includes: Perform a write operation on the serial number byte in the serial number message according to the serial number of the slave device, and perform a write operation on the reserved byte in the serial number message based on the encryption algorithm supported by the slave device itself, so as to generate a target serial number message; Wherein, the master device determines the type of encryption algorithm supported by the slave device through the value of the reserved byte in the target serial number message.

2. The dynamic negotiation method for encryption algorithms according to claim 1, characterized in that When the slave device is in the running state, the method further includes: If receiving the target key message sent by the master device, parse the target key message to obtain the updated encryption algorithm, and the target key message is generated by the master device based on the encryption algorithm expected to be used by the user; Generate a new key according to the updated encryption algorithm, and send the new key to the master device to realize the key update between the slave device and the master device.

3. The dynamic negotiation method of the encryption algorithm according to claim 2, wherein The target key message is generated by the master device based on the encryption algorithm expected to be used by the user, including: The master device determines the updated encryption algorithm based on the encryption algorithm expected to be used by the user, and performs a write operation on the reserved byte in the key message according to the updated encryption algorithm, so as to generate a target key message; Wherein, the slave device determines the updated encryption algorithm decided by the master device through the value of the reserved byte in the target key message.

4. An encryption algorithm dynamic negotiation device, characterized in that, Including a slave device, the slave device is used for: When the slave device in the serial number state receives the serial number request message broadcast by the master device, a target serial number message is constructed, and the target serial number message includes the serial number of the slave device and the encryption algorithms supported by the slave device; The target serial number message is sent to the master device for the master device to decide on a target encryption algorithm from the encryption algorithms supported by the slave device based on the target serial number message, and construct a target identifier allocation message according to the target encryption algorithm and the target identifier allocated to the slave device; When receiving the target identifier allocation message sent by the master device, parse the target identifier allocation message to obtain the target encryption algorithm, so as to implement the encryption and decryption processing of the service transmission channel through the target encryption algorithm; The slave device is specifically used to perform a write operation on the serial number byte in the serial number message according to the serial number of the slave device, and perform a write operation on the reserved byte in the serial number message based on the encryption algorithm supported by the slave device itself, so as to generate a target serial number message; Among them, the master device determines the type of encryption algorithm supported by the slave device according to the value of the reserved byte in the target serial number message.

5. A method for dynamically negotiating an encryption algorithm, characterized in that The encryption algorithm dynamic negotiation method is applied to the master device, and the method includes the following steps: Send a serial number request message to the slave device in a broadcast manner; When receiving a target serial number message sent by the slave device in the serial number state based on the serial number request message, determine a target encryption algorithm from the encryption algorithms supported by the slave device based on the serial number message. The target serial number message is generated by the slave device based on its serial number and the encryption algorithms it supports; Construct a target identifier allocation message according to the target encryption algorithm and the target identifier allocated to the slave device, so that the slave device can parse the target encryption algorithm through the target identifier allocation message and implement encryption and decryption processing of the service transmission channel based on the target encryption algorithm; The constructing the target identifier allocation message according to the target encryption algorithm and the target identifier allocated to the slave device includes: Perform a write operation on the identifier byte in the identifier allocation message according to the target identifier allocated to the slave device, and perform a write operation on the reserved byte in the identifier allocation message according to the target encryption algorithm to generate a target identifier allocation message; Among them, the slave device determines the target encryption algorithm determined by the master device according to the value of the reserved byte in the target identifier allocation message.

6. The dynamic negotiation method for encryption algorithms as described in claim 5, wherein, The target serial number message is generated by the slave device based on its serial number and the encryption algorithms it supports, including: The slave device performs a write operation on the serial number byte in the serial number message according to its serial number, and performs a write operation on the reserved byte in the serial number message based on the encryption algorithms it supports to generate a target serial number message; Among them, the master device determines the type of encryption algorithm supported by the slave device according to the value of the reserved byte in the target serial number message.

7. The dynamic negotiation method of encryption algorithm according to claim 5, wherein, The method further includes: Determine an updated encryption algorithm based on the encryption algorithm expected to be used by the user, and perform a write operation on the reserved byte in the key message according to the updated encryption algorithm to generate a target key message; Send the target key message to the slave device, so that the slave device in the running state can determine the updated encryption algorithm determined by the master device according to the value of the reserved byte in the target key message, and generate a new key according to the updated encryption algorithm; When receiving the new key sent by the slave device, perform key update based on the new key.

8. An encryption algorithm dynamic negotiation device, characterized in that, Including a master device, the master device is used for: Send a serial number request message to the slave device in a broadcast manner; When receiving a target serial number message sent by the slave device in the serial number state based on the serial number request message, determine a target encryption algorithm from the encryption algorithms supported by the slave device based on the serial number message. The target serial number message is generated by the slave device based on its serial number and the encryption algorithms it supports; Construct a target identifier allocation message according to the target encryption algorithm and the target identifier allocated to the slave device, so that the slave device can parse the target encryption algorithm through the target identifier allocation message and implement encryption and decryption processing of the service transmission channel based on the target encryption algorithm; The master device is specifically configured to perform a write operation on the identifier byte in the identifier allocation message according to the target identifier allocated to the slave device, and perform a write operation on the reserved byte in the identifier allocation message according to the target encryption algorithm, so as to generate a target identifier allocation message; Wherein, the slave device determines the target encryption algorithm decided by the master device according to the value of the reserved byte in the target identifier allocation message.

9. An encryption algorithm dynamic negotiation device, characterized in that The encryption algorithm dynamic negotiation device includes a processor, a memory, and an encryption algorithm dynamic negotiation program stored on the memory and executable by the processor. When the encryption algorithm dynamic negotiation program is executed by the processor, the steps of the encryption algorithm dynamic negotiation method described in any one of claims 1 to 3, 5 to 7 are implemented.

10. A computer-readable storage medium, characterized in that, An encryption algorithm dynamic negotiation program is stored on the computer-readable storage medium. When the encryption algorithm dynamic negotiation program is executed by a processor, the steps of the encryption algorithm dynamic negotiation method described in any one of claims 1 to 3, 5 to 7 are implemented.

Citation Information

Patent Citations

  • A method and system for negotiating an encryption algorithm in a passive optical network system

    CN109039600A

  • Service encryption method of passive optical network system, electronic equipment and storage medium

    CN117579182A