All-optical networking device authentication processing method, device, system, network device, storage medium and program product
By working collaboratively with the all-optical master device and the authentication acquisition and control platform, the authentication process for all-optical network slave devices is performed based on the authentication mode of identity information. This solves the problems of low device authentication efficiency and insufficient security in all-optical networks, and achieves efficient and unified authentication and security control.
Patent Information
- Application Number
- CN202411870268.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-18
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2044-12-18
AI Technical Summary
In existing technologies, all-optical networking equipment has low authentication processing efficiency and insufficient network security, which affects the efficiency of equipment management, service activation and operation and maintenance of commercial all-optical networking, and poses access security risks.
The all-optical master device responds to the authentication request of the slave device, performs authentication based on the authentication mode of identity information, generates an authentication identifier and sends it to the authentication collection and management platform for legality verification, and forwards the service according to the verification result.
It enables efficient and unified authentication processing for slave devices accessing the all-optical network, improving the flexibility and compatibility of all-optical networking, and enhancing network security and authentication processing efficiency.
Smart Images

Figure CN119814404B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of optical access network, in particular to a device authentication processing method, device, system, network device, computer readable storage medium and computer program product of all-optical networking. BACKGROUND
[0002] Fiber broadband is an important part of communication network. Under the promotion of innovative business and application demand, fiber network further extends to users to realize full coverage of fiber network.
[0003] The all-optical networking scheme is based on fiber medium networking. A main device of all-optical networking is deployed at the user information network access point position. The main device of all-optical networking is taken as the center to build an all-optical network. The slave devices can be extended to each area required by the user according to the internal structure of the subject such as enterprise, which is used to realize the comprehensive service bearing of related users and realize high-quality broadband.
[0004] In the current network environment, the demand for all-optical networking of users is increasing. All-optical networking can provide higher bandwidth, lower delay and more stable network performance. With the increase of the number of devices and the complexity of network architecture, it is necessary to effectively authenticate the slave devices accessing the all-optical network.
[0005] To this end, the current technology needs a cumbersome device authentication process to authenticate the slave devices accessing the all-optical network, which has the technical problems of low authentication processing efficiency and network security. SUMMARY
[0006] Therefore, it is necessary to provide a device authentication processing method, device, system, network device, computer readable storage medium and computer program product of all-optical networking to solve the above technical problems.
[0007] In a first aspect, the present application provides a device authentication processing method of all-optical networking, comprising:
[0008] In response to the authentication request of the slave device, the slave device is authenticated based on the authentication mode corresponding to the identity information of the slave device;
[0009] If the authentication is passed, the authentication identifier of the slave device is sent to an authentication collection management platform; the authentication collection management platform is used to verify the legality of the authentication identifier;
[0010] According to the legality verification result, the slave device is subjected to corresponding service forwarding processing.
[0011] In one of the embodiments, before authenticating the slave device based on the authentication mode corresponding to the identity information of the slave device, the method further comprises: obtaining the identity information of the slave device; the identity information comprises one or more of a device manufacturer, a device type and an operator version of the slave device; and determining the authentication mode according to the identity information.
[0012] In one of the embodiments, before sending the authentication identifier of the slave device to the authentication collection management platform, the method further comprises: obtaining one or more of an organization unique identifier, a serial number, a region code and a device type of the slave device; and obtaining the authentication identifier of the slave device according to one or more of the organization unique identifier, the serial number, the region code and the device type.
[0013] In one of the embodiments, the authentication collection management platform is configured to determine whether the organization unique identifier in the authentication identifier exists in a registration database; and / or, the authentication collection management platform is configured to confirm whether the serial number is unique; and / or, the authentication collection management platform is configured to verify whether the combination of the region code and the device type matches.
[0014] In one of the embodiments, the corresponding service forwarding processing of the slave device according to the legality verification result comprises: if the legality verification result is passed, opening the service forwarding channels of the slave device in the north-south direction and the east-west direction; and if the legality verification result is not passed, opening the service forwarding channel of the slave device in the east-west direction.
[0015] In one of the embodiments, the authentication identifier comprises an organization unique identifier, a serial number, a region code and a device type of the slave device; the authentication collection management platform is configured to return a passed legality verification result if the legality verification of the organization unique identifier, the serial number, the region code and the device type are all passed; and the authentication collection management platform is configured to return a not passed legality verification result if the legality verification of the organization unique identifier, the serial number, the region code and the device type are not all passed.
[0016] In a second aspect, the application further provides a device authentication processing apparatus for full-optical networking, comprising:
[0017] An authentication module is configured to authenticate a slave device based on an authentication mode corresponding to identity information of the slave device in response to an authentication request of the slave device.
[0018] A sending module is configured to send an authentication identifier of the slave device to an authentication collection management platform if the authentication is passed; and the authentication collection management platform is configured to verify the legality of the authentication identifier.
[0019] The processing module is configured to perform corresponding service forwarding processing on the slave device according to the legality verification result.
[0020] In a third aspect, the present application further provides a device authentication processing system for all-optical networking, comprising: an all-optical master device and an authentication collection management platform; wherein
[0021] The all-optical master device is configured to perform authentication on the slave device based on an authentication mode corresponding to identity information of the slave device in response to an authentication request of the slave device.
[0022] The all-optical master device is further configured to send an authentication identifier of the slave device to the authentication collection management platform if the authentication is passed.
[0023] The authentication collection management platform is configured to verify the legality of the authentication identifier and feed back a legality verification result to the all-optical master device.
[0024] The all-optical master device is further configured to perform corresponding service forwarding processing on the slave device according to the legality verification result.
[0025] In a fourth aspect, the present application further provides a network device, comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements the following steps when executing the computer program:
[0026] In response to an authentication request of a slave device, the all-optical master device performs authentication on the slave device based on an authentication mode corresponding to identity information of the slave device; if the authentication is passed, the all-optical master device sends an authentication identifier of the slave device to an authentication collection management platform; the authentication collection management platform verifies the legality of the authentication identifier; and according to a legality verification result, the all-optical master device performs corresponding service forwarding processing on the slave device.
[0027] In a fifth aspect, the present application further provides a computer readable storage medium, which stores a computer program, and the computer program implements the following steps when executed by a processor:
[0028] In response to an authentication request of a slave device, the all-optical master device performs authentication on the slave device based on an authentication mode corresponding to identity information of the slave device; if the authentication is passed, the all-optical master device sends an authentication identifier of the slave device to an authentication collection management platform; the authentication collection management platform verifies the legality of the authentication identifier; and according to a legality verification result, the all-optical master device performs corresponding service forwarding processing on the slave device.
[0029] In a sixth aspect, the present application further provides a computer program product, comprising a computer program, and the computer program implements the following steps when executed by a processor:
[0030] In response to an authentication request from the slave device, the slave device is authenticated based on an authentication mode corresponding to identity information of the slave device; if the authentication is passed, an authentication identifier of the slave device is sent to an authentication collection management platform; the authentication collection management platform is configured to verify the legality of the authentication identifier; and according to the verification result of the legality, the slave device is subjected to corresponding service forwarding processing.
[0031] The device authentication processing method, device, system, network device, computer readable storage medium and computer program product of the all-optical networking, in response to an authentication request from the slave device, the slave device is authenticated based on an authentication mode corresponding to identity information of the slave device; if the authentication is passed, an authentication identifier of the slave device is sent to an authentication collection management platform; the authentication collection management platform is configured to verify the legality of the authentication identifier; and according to the verification result of the legality, the slave device is subjected to corresponding service forwarding processing. The scheme can authenticate the slave device based on the authentication mode corresponding to the identity information of the slave device, send the authentication identifier of the slave device to the authentication collection management platform for verifying the legality of the authentication identifier after the authentication is passed, and finally subject the slave device to corresponding service forwarding processing according to the verification result of the legality, so as to realize efficient and unified authentication processing of the slave device accessing the all-optical network, improve the flexibility and compatibility of the all-optical networking, and improve the authentication processing efficiency and network security of the slave device of the all-optical networking. BRIEF DESCRIPTION OF DRAWINGS
[0032] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the related art, the drawings needed to be used in the description of the embodiments of the present application or the related art will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and for those skilled in the art, other related drawings can also be obtained without creative labor.
[0033] Figure 1 An application environment diagram of the device authentication processing method of the all-optical networking in an embodiment;
[0034] Figure 2 A flowchart of the device authentication processing method of the all-optical networking in an embodiment;
[0035] Figure 3 A flowchart of the authentication flow mechanism of the master-slave device in an embodiment;
[0036] Figure 4 A structural block diagram of the device authentication processing device of the all-optical networking in an embodiment;
[0037] Figure 5 An internal structure diagram of the network device in an embodiment. DETAILED DESCRIPTION
[0038] In order to make the purposes, technical solutions and advantages of the present application clearer, the present application will be further described in detail below in combination with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and not intended to limit the present application.
[0039] Due to the rich user types of subjects such as institutions, enterprises, etc., the business scenarios and business needs cover a wide range, and according to the industry nature and business needs, in actual deployment and application, according to the user attributes and scale, the number of access points of full-optical networking is generally more than 4, and the authentication collection control platform and the master device need to complete the networking and authentication with a large number of slave devices, and the current slave devices have the conditions of multiple manufacturers, multiple types and multiple versions, etc., therefore, the current device authentication process which needs to authenticate the slave devices accessing the full-optical network has the technical problems of low authentication processing efficiency and network security, and will affect the device management, business opening and operation and maintenance efficiency of FTTR-B of commercial full-optical networking, and there is a certain access security risk.
[0040] To this end, the embodiments of the present application provide a device authentication processing method for full-optical networking, which can be applied in the application environment as shown in Figure 1 , can realize efficient and unified authentication processing of slave devices accessing the full-optical network, can improve the flexibility and compatibility of full-optical networking, and improve the authentication processing efficiency and network security of slave devices of full-optical networking.
[0041] The device authentication processing method for full-optical networking of the present application will be described below based on the application environment as shown in Figure 1 and in combination with various embodiments and corresponding drawings.
[0042] In an exemplary embodiment, as shown in Figure 2 , a device authentication processing method for full-optical networking is provided, which can be applied to the full-optical master device in Figure 1 , and the method can include the following steps:
[0043] Step S201, in response to the authentication request of the slave device, authenticating the slave device based on the authentication mode corresponding to the identity information of the slave device.
[0044] In this step, the slave device can send an authentication request to the all-optical master device when accessing the all-optical network. The all-optical master device receives the authentication request sent by the slave device. In response to the authentication request, the all-optical master device can authenticate the slave device based on an authentication mode corresponding to the identity information of the slave device. The identity information of the slave device can include relevant information indicating the identity of the slave device. For example, the identity information of the slave device can include, but is not limited to, the model of the slave device, a unique identifier (such as a MAC address, i.e., a media access control address), a device manufacturer, a device type, and an operator version. The all-optical master device can be preconfigured with multiple authentication modes, which can include various combinations and can correspond to the identity information of the slave device to ensure that different security requirements and network environments can be adapted. Thus, the all-optical master device can authenticate the slave device based on an authentication mode corresponding to the identity information of the slave device to flexibly adapt to different slave devices and security requirements and network environments. For a specific authentication process, no limitation is made herein to ensure flexibility and efficiency of the authentication process. For example, in the authentication process, the all-optical master device can negotiate with the slave device, and the all-optical master device can automatically obtain attribute field information (such as a device type and a supported protocol version) required for authentication for authentication processing.
[0045] In step S202, if the authentication is passed, the authentication identifier of the slave device is sent to the authentication collection management platform. The authentication collection management platform is used to verify the legality of the authentication identifier.
[0046] The all-optical master device authenticates the slave device based on an authentication mode corresponding to the identity information of the slave device to obtain an authentication result, which can be an authentication result indicating a link layer authentication. In this step, if the authentication is passed, the all-optical master device can send the authentication identifier of the slave device to the authentication collection management platform. The authentication identifier can be generated according to a unified coding rule, which can be a pre-defined coding rule. The coding rule is a rule for specifying which code, field, or combination thereof is used to form the authentication identifier. The authentication collection management platform can serve as a data processing and management center of a device authentication processing system of the all-optical network and can be responsible for receiving, verifying, and feeding back a verification result. The authentication collection management platform can be used to verify the legality of the authentication identifier.
[0047] In this step, after the full-optical master device sends the authentication identifier of the slave device to the authentication collection management platform, the authentication collection management platform can verify the legality of the authentication identifier. Specifically, the legality of each code or field contained in the authentication identifier can be verified, and the legality verification result is fed back to the full-optical master device. The legality verification can be used to verify whether the slave device is a legal slave device, and the specific verification form is not limited here. As an example, the serial number of the slave device can be carried in the authentication identifier, so that the authentication collection management platform can verify the legality of the serial number, and the legality verification result is fed back to the full-optical master device.
[0048] In step S203, the slave device is subjected to corresponding service forwarding processing according to the legality verification result.
[0049] In this step, the full-optical master device can perform corresponding service forwarding processing on the slave device according to the legality verification result fed back by the authentication collection management platform, for example, open or limit the service forwarding channel of the slave device in a corresponding direction, etc., to control the traffic of the slave device.
[0050] The device authentication processing method of the full-optical networking of the embodiment responds to the authentication request of the slave device, authenticates the slave device based on the authentication mode corresponding to the identity information of the slave device, sends the authentication identifier of the slave device to the authentication collection management platform if the authentication is passed, and the authentication collection management platform is used to verify the legality of the authentication identifier. According to the legality verification result, the slave device is subjected to corresponding service forwarding processing. This scheme can authenticate the slave device based on the authentication mode corresponding to the identity information of the slave device, send the authentication identifier of the slave device to the authentication collection management platform after the authentication is passed to verify the legality of the authentication identifier, and finally perform corresponding service forwarding processing on the slave device according to the legality verification result. Efficient and unified authentication processing of the slave device accessing the full-optical network is realized, which can improve the flexibility and compatibility of the full-optical networking, and improve the authentication processing efficiency and network security of the slave device of the full-optical networking.
[0051] In an exemplary embodiment, before the authentication of the slave device based on the authentication mode corresponding to the identity information of the slave device in step S201, the following steps can also be included:
[0052] The identity information of the slave device is obtained. The identity information can include one or more of the device manufacturer, device type and operator version of the slave device. The authentication mode is determined according to the identity information.
[0053] As Figure 1As shown, the slave devices accessing the network can have different device manufacturers, device types, and operator versions. In this embodiment, the all-optical master device can obtain the identity information of the slave device according to the authentication request. The identity information of the slave device obtained by the all-optical master device can include one or more of the device manufacturer, device type, and operator version of the slave device. Thus, the corresponding authentication mode can be determined in combination with one or more of the device manufacturer, device type, and operator version, to adapt to the access requirements and security requirements of different slave devices, and to improve the flexibility and compatibility of the device authentication processing system of the all-optical network.
[0054] In an exemplary embodiment, before the step of sending the authentication identifier of the slave device to the authentication collection management platform in step S202, the following steps can be further included:
[0055] Obtaining one or more of the organization unique identifier, serial number, region code, and device type of the slave device; and obtaining the authentication identifier of the slave device according to one or more of the organization unique identifier, serial number, region code, and device type.
[0056] Wherein, the organization unique identifier can be denoted as OUI, the serial number can be denoted as Serial Number, the region code can be denoted as Province Code, and the device type can be denoted as Device Type.
[0057] In this embodiment, the all-optical master device can obtain one or more of the organization unique identifier, serial number, region code, and device type of the slave device. The all-optical master device can generate the authentication identifier of the slave device according to one or more of the organization unique identifier, serial number, region code, and device type according to a unified coding rule, for the authentication collection management platform to perform legality verification.
[0058] Further, in an exemplary embodiment, the authentication collection management platform can be used to determine whether the organization unique identifier in the authentication identifier exists in the registration database; and / or, the authentication collection management platform can be used to confirm whether the serial number is unique; and / or, the authentication collection management platform can be used to verify whether the combination of the region code and the device type matches.
[0059] In the embodiment, the authentication identifier can include one or more of the organization unique identifier, the serial number, the region code and the device type of the slave device, so that the authentication collection and control platform can check one or more of the organization unique identifier, the serial number, the region code and the device type of the slave device according to the authentication identifier. The authentication collection and control platform can determine whether the organization unique identifier in the authentication identifier exists in a registration database, thereby obtaining a legality check result for the organization unique identifier, wherein the registration database can be used to record the organization unique identifiers of various network devices. The authentication collection and control platform can confirm whether the serial number is unique, thereby obtaining a legality check result for the serial number. The authentication collection and control platform can check whether the combination of the region code and the device type matches, thereby obtaining a legality check result for the region code and the device type. Thus, the authentication collection and control platform can complete the legality check of the authentication identifier.
[0060] In an exemplary embodiment, the corresponding service forwarding processing of the slave device according to the legality check result in step S203 can include the following steps:
[0061] If the legality check result is passed, the north-south and east-west service forwarding channels of the slave device are opened; if the legality check result is not passed, the east-west service forwarding channel of the slave device is opened.
[0062] In the embodiment, if the legality check result fed back by the authentication collection and control platform is passed, the all-optical master device can determine that the slave device is a legal slave device, and the all-optical master device can open the north-south and east-west service forwarding channels of the slave device, thereby ensuring that the slave device can normally perform network communication. If the legality check result fed back by the authentication collection and control platform is not passed, the all-optical master device can determine that the slave device is an illegal slave device, and the all-optical master device can close the north-south service forwarding channel of the slave device and reserve the east-west service forwarding channel of the slave device, to ensure the basic local area network communication capability of the slave device. In some embodiments, the all-optical master device can also start an authentication polling mechanism for the illegal slave device, thereby further monitoring and processing the illegal slave device. In some embodiments, if the legality state of the slave device changes, the all-optical master device can automatically update the device database, which can be used to record the related data of the slave device, such as the legality state data, to maintain the consistency and accuracy of system data.
[0063] Further, in an example embodiment, the authentication identifier can include an organization unique identifier, a serial number, a region code and a device type of the slave device; the authentication collection management platform is configured to return a passed legality verification result if the legality of the organization unique identifier, the serial number, the region code and the device type are all passed; and the authentication collection management platform is configured to return a failed legality verification result if the legality of the organization unique identifier, the serial number, the region code and the device type are not all passed.
[0064] In the embodiment, the all-optical master device can form the authentication identifier according to the following unified coding rule: [OUI]-[Serial Number]-[Province Code]-[Device Type]. Wherein, OUI represents the organization unique identifier, Serial Number represents the serial number, Province Code represents the region code, and Device Type represents the device type. Thus, the authentication collection management platform can perform legality verification on the organization unique identifier, the serial number, the region code and the device type, return a passed legality verification result to the all-optical master device if the legality of the organization unique identifier, the serial number, the region code and the device type are all passed, and return a failed legality verification result to the all-optical master device if the legality of one or more of the organization unique identifier, the serial number, the region code and the device type are not passed.
[0065] In an example embodiment, an all-optical networking device authentication processing system is also provided, as shown in Figure 1 The system can include an all-optical master device and an authentication collection management platform; wherein:
[0066] The all-optical master device can be configured to authenticate the slave device based on an authentication mode corresponding to identity information of the slave device in response to an authentication request of the slave device.
[0067] The all-optical master device can also be configured to send the authentication identifier of the slave device to the authentication collection management platform if the authentication is passed.
[0068] The authentication collection management platform can be configured to verify the legality of the authentication identifier and feed back a legality verification result to the all-optical master device.
[0069] The all-optical master device can also be configured to perform corresponding service forwarding processing on the slave device according to the legality verification result.
[0070] In the embodiment, the all-optical master device can authenticate the slave device accessing the all-optical network by means of the authentication collection management platform according to the all-optical networking device authentication processing method of any one of the above embodiments.
[0071] As a specific example, when the slave device accesses the network, the slave device can send an authentication request to the all-optical master device, and the all-optical master device can obtain the identity information of the slave device, which can include the device manufacturer, device type, operator version, unique identifier (such as MAC address), model number, and the like of the slave device. The all-optical master device can dynamically select the corresponding authentication mode according to the device type and operator version, and the authentication modes can include various combinations to ensure that different security requirements and network environments can be adapted. As an authentication example, as shown in FIG. 8, in the authentication process, the all-optical master device and the slave device negotiate to automatically obtain the required attribute field information, such as the device type and supported protocol version. The process can be self-adaptive in combination with the device type and operator version to ensure the flexibility, compatibility, efficiency, and accuracy of the authentication process. Figure 3
[0072] After the link layer authentication is completed, the all-optical master device can integrate the link layer authentication state (which can be used to represent the authentication result) of the slave device, the authentication mode, and the authentication identifier to form a unified authentication information record to ensure the integrity and traceability of the information. The all-optical master device can generate the authentication identifier of each slave device according to a predefined encoding rule. The all-optical master device can combine the organization unique identifier, serial number, region code, and device type of the slave device into the authentication identifier and report the authentication identifier to the authentication collection management platform to realize standardized management of the authentication identifier of the slave device and ensure uniqueness and identifiability.
[0073] The authentication collection management platform receives the authentication identifier sent by the all-optical master device and can compare the authentication identifier with a predefined authentication identifier list to verify its legality. The verification can include: determining whether the organization unique identifier in the authentication identifier exists in the registration database, confirming whether the serial number is unique, and verifying whether the combination of the region code and the device type matches. The authentication collection management platform can feed back the legality verification result to the all-optical master device for the all-optical master device to decide the subsequent processing steps.
[0074] The all-optical master device can perform different service forwarding processing on the slave device according to the legality verification result fed back by the authentication collection management platform. For a legal slave device, the all-optical master device can open the north-south and east-west service forwarding channels to ensure that the device can normally perform network communication. For an illegal slave device, the all-optical master device can close the north-south service forwarding channel and keep the east-west service forwarding channel to ensure the basic LAN communication capability of the slave device. Thus, the security and traffic control of the network can be ensured. Meanwhile, the all-optical master device can start the authentication polling mechanism to further monitor and process the illegal slave device, so as to timely discover and process potential security risks and maintain the overall security of the network. When the legality state of the slave device changes, the all-optical master device can automatically update the legality state of the slave device to the device database to maintain the consistency and accuracy of the system data. If the illegal slave device meets the access conditions (such as passing the authentication of the corresponding authentication mode and the legality verification of the authentication identifier) in the subsequent authentication process, the slave device can be dynamically adjusted and allowed to access the network again according to the new legality verification result.
[0075] The scheme of the embodiment can realize the intensive and standardized management and control of the authentication collection management platform and the all-optical master device on each access point slave device. Based on the existing networking architecture and scheme, the all-optical master device with multiple authentication modes can realize link layer authentication based on the adaptation of authentication modes for various slave devices (different device manufacturers, device types and operator versions), improve the flexibility and compatibility of the system, adapt to different slave devices, and initiate service layer authentication to the authentication collection management platform according to the unified authentication identifier, reduce authentication time and resource consumption, improve operation and maintenance efficiency, and make different service forwarding mechanisms for the slave devices according to the legality verification result, so that the slave devices meeting the requirements can access the network, effectively prevent security risks, and meet the LAN communication needs of related users, thereby realizing efficient and standardized authentication of the access slave device and improving the security and management efficiency of the network.
[0076] It should be understood that although each step in the flowchart involved in each embodiment as described above is displayed in sequence according to the arrow, these steps are not necessarily executed in sequence according to the arrow. Unless otherwise specified herein, the execution of these steps is not strictly limited in sequence, and these steps can be executed in other sequences. Moreover, at least part of the steps in the flowchart involved in each embodiment as described above can include multiple steps or stages, which are not necessarily executed at the same time but can be executed at different times, and the execution sequence of these steps or stages is not necessarily sequential but can be executed in rotation or alternation with at least part of other steps or steps or stages in other steps.
[0077] Based on the same inventive concept, the embodiments of the present application also provide a device authentication processing apparatus for implementing the all-optical networking device authentication processing method described above. The solution provided by the apparatus is similar to the implementation described in the above method, so the specific limitations in one or more device authentication processing apparatus embodiments provided below can refer to the limitations of the all-optical networking device authentication processing method described above, and will not be repeated here.
[0078] In one exemplary embodiment, as shown in Figure 4 An all-optical networking device authentication processing apparatus is provided, which can include:
[0079] An authentication module 401 is configured to authenticate a slave device based on an authentication mode corresponding to identity information of the slave device in response to an authentication request from the slave device.
[0080] A sending module 402 is configured to send an authentication identifier of the slave device to an authentication collection management platform if the authentication is passed, and the authentication collection management platform is configured to verify the legality of the authentication identifier.
[0081] A processing module 403 is configured to perform corresponding service forwarding processing on the slave device according to the legality verification result.
[0082] In one embodiment, the authentication module 401 is further configured to obtain identity information of the slave device, wherein the identity information includes one or more of a device manufacturer, a device type, and an operator version of the slave device, and determine the authentication mode according to the identity information.
[0083] In one embodiment, the sending module 402 is further configured to obtain one or more of an organization unique identifier, a serial number, a region code, and a device type of the slave device, and obtain the authentication identifier of the slave device according to one or more of the organization unique identifier, the serial number, the region code, and the device type.
[0084] In one embodiment, the authentication collection management platform is configured to determine whether the organization unique identifier in the authentication identifier exists in a registration database, and / or the authentication collection management platform is configured to confirm whether the serial number is unique, and / or the authentication collection management platform is configured to verify whether a combination of the region code and the device type matches.
[0085] In one embodiment, the processing module 403 is configured to open the north-south and east-west traffic forwarding channels of the slave device if the legitimacy verification result is passed; and open the east-west traffic forwarding channel of the slave device if the legitimacy verification result is not passed.
[0086] In one embodiment, the authentication identifier includes an organization unique identifier, a serial number, a region code and a device type of the slave device; the authentication collection management platform is configured to return a passed legitimacy verification result if the legitimacy verification of the organization unique identifier, the serial number, the region code and the device type are all passed; and return a not passed legitimacy verification result if the legitimacy verification of the organization unique identifier, the serial number, the region code and the device type are not all passed.
[0087] Each module in the above-mentioned all-optical networking device authentication processing apparatus can be realized by software, hardware or a combination thereof, in whole or in part. Each module can be embedded in or independent of a processor in the network device in hardware form, or stored in a memory in the network device in software form, so as to be called and executed by the processor to perform the operations corresponding to each module.
[0088] In one exemplary embodiment, a network device is provided, which can be an all-optical master device, and an internal structure diagram thereof can be as shown in Figure 5The network device includes a processor, a memory, an input / output interface, a communication interface, a display unit and an input device. The processor, the memory and the input / output interface are connected through a system bus, and the communication interface, the display unit and the input device are connected to the system bus through the input / output interface. The processor of the network device is configured to provide computing and control capabilities. The memory of the network device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operating system and the computer program in the non-volatile storage medium to run. The input / output interface of the network device is configured to exchange information between the processor and external devices. The communication interface of the network device is configured to perform wired or wireless communication with external terminals. The wireless communication can be achieved through WIFI, mobile cellular network, Near Field Communication (NFC) or other technologies. The computer program is executed by the processor to implement a device authentication processing method for full-optical networking. The display unit of the network device can be used to form a visually visible picture, which can be a display screen, a projection device or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen. The input device of the network device can be a touch layer overlaid on the display screen, or a key, trackball or touchpad arranged on the network device shell, or an external keyboard, touchpad or mouse, etc.
[0089] Those skilled in the art can understand that Figure 5 The skilled in the art can understand that
[0090] In one embodiment, a network device is also provided, including a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the steps in the above method embodiments.
[0091] In one embodiment, a computer readable storage medium is provided, storing a computer program, and the computer program is executed by a processor to implement the steps in the above method embodiments.
[0092] In one embodiment, a computer program product is provided, including a computer program, and the computer program is executed by a processor to implement the steps in the above method embodiments.
[0093] It should be noted that the user information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties, and the collection, use and processing of related data need to comply with relevant regulations.
[0094] It can be understood by those skilled in the art that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing related hardware through a computer program. The computer program can be stored in a non-volatile computer readable storage medium. When the computer program is executed, it can include the processes of the above-mentioned embodiments of each method. In the embodiments provided in the present application, any reference to memory, database or other medium can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical storage, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration but not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The database involved in the embodiments provided in the present application can include at least one of a relational database and a non-relational database. The non-relational database can include a distributed database based on a block chain, etc., without being limited thereto. The processor involved in the embodiments provided in the present application can be a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, an artificial intelligence (AI) processor, etc., without being limited thereto.
[0095] Any technical features in the above embodiments can be combined, and for the sake of brevity, not all possible combinations are described above, however, any combination of these technical features is deemed to be within the scope of the present application.
[0096] The above embodiments only express several implementation manners of the present application, and the description is relatively specific and detailed, but it should not be understood as a limitation on the patent scope of the present application. It should be pointed out that, for ordinary skilled persons in the art, several modifications and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.
Claims
1. A method for device authentication processing in an all-optical networking, characterized by, The method comprises: in response to an authentication request from a slave device, authenticating the slave device based on an authentication mode corresponding to identity information of the slave device; before the authentication based on the authentication mode corresponding to the identity information of the slave device, the method further comprises: obtaining the identity information of the slave device; the identity information comprises one or more of a device manufacturer, a device type and an operator version of the slave device; and determining the authentication mode according to the identity information; if the authentication is passed, sending an authentication identifier of the slave device to an authentication collection management platform; the authentication collection management platform is used to verify the legality of the authentication identifier; before the sending of the authentication identifier of the slave device to the authentication collection management platform, the method further comprises: obtaining one or more of an organization unique identifier, a serial number, a region code and a device type of the slave device; and obtaining the authentication identifier of the slave device according to one or more of the organization unique identifier, the serial number, the region code and the device type; according to the legality verification result, opening or limiting a north-south service forwarding channel of the slave device.
2. The method of claim 1, wherein, The authentication collection management platform is used to determine whether the organization unique identifier in the authentication identifier exists in a registration database; and / or, the authentication collection management platform is used to confirm whether the serial number is unique; and / or, the authentication collection management platform is used to verify whether the combination of the region code and the device type matches.
3. The method of any one of claims 1-2, wherein, The opening or limiting of the north-south service forwarding channel of the slave device according to the legality verification result comprises: if the legality verification result is passed, opening a north-south and an east-west service forwarding channel of the slave device; if the legality verification result is not passed, opening an east-west service forwarding channel of the slave device.
4. The method of claim 3, wherein, The authentication identifier contains the organization unique identifier, the serial number, the region code and the device type of the slave device; the authentication collection management platform is used to return a passed legality verification result in the case that the legality verification of the organization unique identifier, the serial number, the region code and the device type are all passed; The authentication collection management platform is used to return a not-passed legality verification result in the case that the legality verification of the organization unique identifier, the serial number, the region code and the device type are not all passed.
5. An all-optical networking device authentication processing apparatus characterized by comprising: The device comprises: an authentication module configured to authenticate a slave device based on an authentication mode corresponding to identity information of the slave device in response to an authentication request from the slave device; before the authentication based on the authentication mode corresponding to the identity information of the slave device, the authentication module is further configured to obtain the identity information of the slave device; the identity information comprises one or more of a device manufacturer, a device type and an operator version of the slave device; and determine the authentication mode according to the identity information. The sending module is configured to send the authentication identifier of the slave device to an authentication collection management platform if the authentication is passed; the authentication collection management platform is configured to verify the legality of the authentication identifier; before the sending of the authentication identifier of the slave device to the authentication collection management platform, the method further includes: obtaining one or more of an organization unique identifier, a serial number, a region code and a device type of the slave device; and obtaining the authentication identifier of the slave device according to the one or more of the organization unique identifier, the serial number, the region code and the device type. The processing module is configured to open or limit a north-south service forwarding channel of the slave device according to the legality verification result.
6. An all-optical networking device authentication processing system characterized by comprising: The system includes: an all-optical master device and an authentication collection management platform; wherein The all-optical master device is configured to authenticate the slave device based on an authentication mode corresponding to identity information of the slave device in response to an authentication request of the slave device; before the authentication of the slave device based on the authentication mode corresponding to the identity information of the slave device, the method further includes: obtaining the identity information of the slave device; the identity information includes one or more of a device manufacturer, a device type and an operator version of the slave device; and determining the authentication mode according to the identity information. The all-optical master device is further configured to send an authentication identifier of the slave device to the authentication collection management platform if the authentication is passed; before the sending of the authentication identifier of the slave device to the authentication collection management platform, the method further includes: obtaining one or more of an organization unique identifier, a serial number, a region code and a device type of the slave device; and obtaining the authentication identifier of the slave device according to the one or more of the organization unique identifier, the serial number, the region code and the device type. The authentication collection management platform is configured to verify the legality of the authentication identifier and feed back a legality verification result to the all-optical master device. The all-optical master device is further configured to open or limit a north-south service forwarding channel of the slave device according to the legality verification result. 7.A network device, comprising a memory and a processor, wherein the memory stores a computer program, and the network device is configured to perform the method according to any one of claims 1-6. The processor executes the computer program to implement the steps of the method of any one of claims 1 to 4.
8. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the method of any one of claims 1 to 4.
9. A computer program product comprising a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the method of any one of claims 1 to 4.
Citation Information
Patent Citations
Internet of Things terminal identity authentication method and system based on dual authentication
CN110535877A
Multi-factor authentication devices
US10360367B1