Optical network communication method and communication device

By receiving the authentication and encryption capability information of the slave device through the master device and indicating a unified authentication and encryption mode, the security and stability issues caused by the slave devices using different authentication and encryption modes in the FTTR scenario are solved, and the security and compatibility of the optical network are improved.

CN120601982AActive Publication Date: 2025-09-05HUAWEI TECH CO LTD

Patent Information

Application Number
CN202510728654.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2025-01-09
Filing Date
2025-02-18
Publication Date
2025-09-05
Estimated Expiration
2045-02-18

AI Technical Summary

Technical Problem

In fiber-to-the-room (FTTR) scenarios, slave devices determine the authentication and encryption mode based on pre-configured information during initialization. This results in multiple slave devices managed by the same master device using different authentication and encryption modes, impacting network security, energy consumption, and service stability of terminal devices.

Method used

The master device receives the authentication and encryption capability information of the slave device and indicates a unified authentication and encryption mode to the slave device. It supports multiple compatible authentication and encryption mode combinations to ensure that the master and slave devices use the same authentication and encryption method. The matching configuration of frequency band reporting and authentication and encryption mode is achieved through WMCI message interaction.

Benefits of technology

It improves the security and compatibility of optical networks, reduces configuration conflicts, improves configuration efficiency and network security, and ensures that slave devices work normally and are protected in different frequency bands.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120601982A_ABST
    Figure CN120601982A_ABST
Patent Text Reader

Abstract

The invention provides an optical network communication method and a communication device, the method is applied to an optical fiber network, the optical fiber network comprises a master device and at least one slave device, and the at least one slave device comprises a first slave device. Wherein in the initialization phase, after receiving the authentication encryption capability of the slave device, the master device can indicate a determined authentication encryption mode (e.g., a first authentication encryption mode) to the slave device, so that the authentication encryption capability of the slave device is enhanced in a subsequent process (e.g., a roaming parameter configuration process). The master device does not need to configure security-related parameters such as an authentication encryption mode for the slave device, so that the configuration efficiency is improved, and the configuration overhead is saved.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application. The application number of the original application is 202510179612.X, and the original application date is February 18, 2025. The entire contents of the original application are incorporated by reference into this application; and the original application claims priority to the Chinese patent application filed with the State Intellectual Property Office of China on January 9, 2025, with application number 202510039018.0 and application name “A Method and Device for Optical Network Communication”, all contents of which are incorporated by reference into this application. Technical Field

[0002] The embodiments of the present application relate to the field of optical communications, and in particular to an optical network communication method and a communication device. Background Art

[0003] Fiber to the room (FTTR) refers to a technology that uses optical fiber instead of network cables to provide fiber media access to rooms downstream of optical network devices (e.g., optical network terminals (ONTs)). The fiber optic network in this FTTR scenario includes a master device and one or more slave devices (also called sub-devices). A management channel can be established between the master and slave devices, allowing the master device to send management or control-related messages to the slave devices via the management channel, enabling the master device to manage or control some of the slave device's functions.

[0004] In the current standard, a slave device can determine a certain authentication and encryption mode to use based on pre-configured information during the initialization phase to provide security authentication for terminal devices accessing the network. This implementation method may result in multiple slave devices managed by the same master device using different authentication and encryption modes. In other words, the authentication and encryption modes of the entire network may be inconsistent, which may not only affect the security of some devices (for example, terminal devices accessing the network through slave devices), but may also increase the processing complexity of terminal devices accessing the network through slave devices, affecting the energy consumption and service stability of terminal devices. Summary of the Invention

[0005] The present application provides an optical network communication method and a communication device for improving the security of equipment.

[0006] In a first aspect, the present application provides an optical network communication method, which is applied to an optical fiber network, and the optical fiber network includes a master device and at least one slave device. The optical network communication method provided in this aspect can be executed by the master device in the optical fiber network, or it can be executed by some functional modules or chips in the master device. Taking the execution of the master device as an example, the master device receives at least one first message, and the at least one first message comes from at least one slave device respectively. The first message includes first indication information, and the first indication information is used to indicate at least one authentication encryption mode supported by the corresponding slave device; then, the master device sends at least one second message, and the at least one second message corresponds one-to-one to at least one slave device. The second message includes second indication information, and the second indication information is used to indicate that the corresponding slave device uses the first authentication encryption mode.

[0007] In conventional technology, slave devices do not report authentication and encryption capabilities, and only enable pre-configured authentication and encryption modes. This may cause multiple slave devices managed by the same master device to use different authentication and encryption modes. This may affect the security of some devices (for example, terminal devices that access the network through slave devices). In the present invention, after receiving the authentication and encryption capabilities of at least one slave device, the master device can indicate a specific authentication and encryption mode (for example, a first authentication and encryption mode) to the aforementioned at least one slave device, so that the slave devices managed by the master device uniformly use one authentication and encryption mode, which is beneficial to improving the security of the network.

[0008] In one possible implementation, the at least one authenticated encryption mode includes at least one of the following modes:

[0009] 64-bit Wired Equivalent Privacy (WEP-64); or 128-bit Wired Equivalent Privacy (WEP-128); or Wi-Fi Protected Access (WPA-Personal) for consumers; or WPA2-Personal; or WPA-WPA2-Personal; or WPA3-SAE; or WPA2-WPA3-PSK-SAE; or Wi-Fi Protected Access (WPA-Enterprise) for enterprises; or WPA2-Enterprise; or WPA-WPA2-Enterprise; or WPA3-Enterprise.

[0010] This embodiment provides a combination of multiple compatible authentication and encryption modes, which is beneficial to improving the compatibility of the system and increasing the flexibility of the master device when configuring authentication and encryption modes for multiple slave devices. In addition, the authentication and encryption mode indicated by the first indication information in this embodiment is a combination of an authentication method (i.e., an identity authentication method) and an encryption method, rather than simply an authentication method or an encryption method. That is, when an authentication and encryption mode is known, the device (master device or slave device) can determine which authentication method and encryption method to use for the authentication and encryption mode. Compared with the solution of configuring the authentication and encryption methods separately in traditional technologies, it can avoid configuration conflicts (for example, incompatibility between the authentication and encryption methods), which is beneficial to improving the reliability of configuring the authentication and encryption mode and improving the efficiency of configuration. For example, the WPA3 authentication method can only be combined with the Advanced Encryption Standard (AES) algorithm. If the WPA3 authentication method is used but the Temporal Key Integrity Protocol (TKIP) algorithm is used, a configuration conflict will result due to the incompatibility between the authentication and encryption methods.

[0011] In a possible implementation, the first authentication encryption mode is an authentication encryption mode supported by at least one slave device.

[0012] If a slave device fails to report its authentication and encryption capabilities, and the master device blindly configures an authentication and encryption mode for the slave device, it may be configured with an encryption method that the slave device does not support, or the configured encryption method may be of a lower level, resulting in poor security. In this embodiment, the master device can select an authentication and encryption mode from the authentication and encryption modes supported by the slave device as the authentication and encryption mode used by the slave device, which can increase the probability of successfully configuring the authentication and encryption mode and thereby improve network security. Furthermore, the master device determines an authentication and encryption mode supported by multiple slave devices based on their authentication and encryption capabilities, and selects the authentication and encryption mode used by multiple slave devices as the authentication and encryption mode used by multiple slave devices. This increases the probability of successfully configuring the authentication and encryption mode for multiple slave devices and thereby improves network security.

[0013] In a possible implementation, the first authentication encryption mode is the same as the authentication encryption mode used by the master device.

[0014] For example, if the master device has a wireless local area network (WLAN) function, the authentication encryption mode used by the slave device is the same as the authentication encryption mode used by the master device, that is, the first authentication encryption mode determined by the master device is the authentication encryption mode supported by the master device, and both the master device and the slave device use the first authentication encryption mode.

[0015] In a possible implementation, the first message further includes third indication information, where the third indication information is used to indicate a first frequency band supported by the slave device, where the first frequency band is one of at least one frequency band supported by the slave device.

[0016] In this embodiment, since the first message includes the first indication information and the third indication information, the first indication information can also be understood as being used to indicate the authentication and encryption mode supported by the slave device when it operates in the first frequency band. For example, if the authentication and encryption modes indicated by the first indication information are "WEP-64" and "WEP-128", and the first frequency band indicated by the third indication information is "2.4GHz", it means that when the slave device operates at 2.4GHz, the slave device supports both "WEP-64" and "WEP-128" authentication and encryption modes. The master device configures any one of the encryption methods "WEP-64" and "WEP-128" for the slave device, and the slave device can operate normally at 2.4GHz and obtain security protection. In other words, the slave device reports the authentication and encryption capabilities of the slave device by frequency band. When the slave device supports two or more frequency bands, the slave device reports the authentication and encryption modes corresponding to different frequency bands to the master device through different messages. It can be seen from this that reporting the authentication and encryption capabilities of the slave device by frequency band helps the master device accurately know which authentication and encryption modes the slave device supports when operating in a specific frequency band. This in turn helps the master device configure the authentication and encryption mode suitable for the slave device to use when operating in that frequency band based on the frequency band configuration, improving the adaptability of the authentication and encryption mode configured by the master device and helping to improve the security of the system. In addition, the electronic devices and software algorithms of the processing chips for different frequency bands in the slave device are relatively independent, that is, the authentication and encryption algorithms for different frequency bands are generally encapsulated in processing chips for different frequency bands. Reporting the authentication and encryption capabilities for different frequency bands in different messages helps to independently enable authentication and encryption methods operating in different frequency bands. For example, it helps the master device configure different authentication and encryption methods for different operating frequency bands of the same slave device, improving the flexibility of the slave device in performing authentication and encryption on the terminal device.

[0017] In one possible implementation, the second message also includes third indication information. Since the second message includes the second indication information and the third indication information, the second indication information can be understood as instructing the corresponding slave device to use the first authenticated encryption mode when operating in the first frequency band. The second indication information can also be understood as indicating that the first authenticated encryption mode corresponds to the first frequency band indicated by the third indication information.

[0018] In a possible implementation, the at least one slave device includes a first slave device and a second slave device; and the method further includes:

[0019] After the master device determines that the second slave device is offline, the master device sends a third message to the first slave device. The third message includes fourth indication information. The fourth indication information is used to instruct the first slave device to use a second authentication encryption mode. The second authentication encryption mode is an authentication encryption mode supported by the first slave device. The second authentication encryption mode is different from the first authentication encryption mode.

[0020] For example, if the master device receives an offline notification from the second slave device, or the master device cannot detect the optical signal of the second slave device, the master device determines the second authentication encryption mode based on at least one authentication encryption mode supported by the first slave device, and the second authentication encryption mode is an authentication encryption mode supported by the first slave device; or, the master device determines the second authentication encryption mode based on at least one authentication encryption mode supported by the first slave device and at least one authentication encryption mode supported by the master device, and the second authentication encryption mode is an authentication encryption mode supported by both the first slave device and the master device.

[0021] In this implementation, when a second slave device goes offline, the master device no longer considers the authentication and encryption capabilities of the second slave device. Instead, it determines whether to update the authentication and encryption mode used by the slave device based solely on the authentication and encryption capabilities of the first slave device (and the master device). This facilitates instant configuration of the appropriate authentication and encryption mode for the slave device, improving system security.

[0022] In a possible implementation, the at least one slave device includes a first slave device and a second slave device; and the method further includes:

[0023] The master device receives a fourth message from the third slave device, the fourth message includes fifth indication information, and the fifth indication information is used to indicate at least one authentication encryption mode supported by the third slave device; then, the master device sends a fifth message to the first slave device, the second slave device and the third slave device respectively, the fifth message includes sixth indication information, and the sixth indication information is used to indicate the use of the third authentication encryption mode, the third authentication encryption mode is an authentication encryption mode supported by the first slave device, the second slave device and the third slave device, and the third authentication encryption mode is different from the first authentication encryption mode.

[0024] For example, the master device determines a third authentication encryption mode based on at least one authentication encryption mode supported by the first slave device, at least one authentication encryption mode supported by the second slave device, at least one authentication encryption mode supported by the third slave device, and at least one authentication encryption mode supported by the master device. The third authentication encryption mode is an authentication encryption mode supported by the first slave device, the second slave device, the third slave device, and the master device. In this embodiment, when the third slave device comes online, the master device determines whether to update the authentication encryption mode based on the authentication encryption capabilities of the first slave device, the second slave device, the third slave device (and the master device). This is conducive to timely configuring appropriate authentication encryption modes for slave devices and improving system security.

[0025] In a possible implementation manner, the third message further includes third indication information; and / or the fifth message further includes third indication information.

[0026] Since the third message includes both the third indication information and the fourth indication information, the fourth indication information can be understood as instructing the first slave device to use the second authenticated encryption mode when operating in the first frequency band. Since the fifth message includes the third indication information and the sixth indication information, the sixth indication information can be understood as instructing the slave device to use the third authenticated encryption mode when operating in the first frequency band.

[0027] In a possible implementation, the first message is a wireless local area network management and control interface (WLAN management control interface, WMCI) message, and the second message is a WMCI message. The WMCI message is used to manage or control the wireless local area network WLAN function of the slave device.

[0028] In a possible implementation, the first message further includes seventh indication information, where the seventh indication information is used to indicate a device capability parameter set of the WLAN of the slave device, where the device capability parameter set of the WLAN of the slave device includes an authentication encryption mode parameter of the slave device and a frequency band parameter of the slave device.

[0029] In a possible implementation manner, the seventh indication information is located in the message type identification field of the first message.

[0030] In a possible implementation, the second message also includes eighth indication information, where the eighth indication information is used to indicate a working parameter configuration parameter set of the WLAN of the slave device, where the working parameter configuration parameter set of the WLAN of the slave device includes an authentication encryption mode parameter of the slave device and a frequency band parameter of the slave device.

[0031] In a possible implementation manner, the eighth indication information is located in the message type identifier field of the second message.

[0032] In one possible embodiment, the message content field of the first message also includes a parameter mask field, and the message content field of the second message also includes a parameter mask field, the parameter mask field includes ninth indication information and tenth indication information, the ninth indication information is used to indicate the authentication encryption mode parameters of the slave device, and the tenth indication information is used to indicate the frequency band parameters of the slave device.

[0033] In a possible implementation, the message content field of the first message further includes first indication information and third indication information; the message content field of the second message further includes second indication information and third indication information.

[0034] In a possible implementation, the first message is encapsulated in a payload field of an FTTR encapsulation method (FEM) frame, and an FEM port identifier in a frame header of the FEM frame is used to indicate a slave device corresponding to the first message.

[0035] In this embodiment, the FEM port ID in the FEM frame header is assigned by the master device. This FEM port ID not only indicates that the first message is a WMCI message, but also indicates the recipient of the WMCI message (i.e., the first message), that is, the WMCI message (i.e., the first message) is intended for the first slave device rather than other slave devices. Therefore, the FEM port ID can be used to distinguish WMCI messages from other control messages in the FTTR system, which helps improve the control efficiency of WLAN functions.

[0036] In one possible implementation, the FEM frame is encapsulated in a payload field of a data link layer (DLL) frame.

[0037] In a possible implementation, the master device is a main FTTR unit (MFU), and the slave device is a sub FTTR unit (SFU).

[0038] In a second aspect, the present application provides an optical network communication method, which is applied to an optical fiber network, and the optical fiber network includes a master device and at least one slave device. The optical network communication method provided in this aspect can be executed by a slave device in the optical fiber network, or it can be executed by some functional modules or chips in the slave device. Taking the execution of the slave device as an example, the slave device sends a first message to the master device, and the first message includes first indication information, and the first indication information is used to indicate at least one authentication encryption mode supported by the slave device; then, the slave device receives a second message from the master device, and the second message includes second indication information, and the second indication information is used to instruct the slave device to use a first authentication encryption mode, and the first authentication encryption mode is one of the at least one authentication encryption mode supported by the slave device.

[0039] In one possible implementation, the at least one authenticated encryption mode includes at least one of the following modes:

[0040] WEP-64 mode; or WEP-128 mode; or WPA-Personal mode; or WPA2-Personal mode; or WPA-WPA2-Personal mode; or WPA3-SAE; or WPA2-WPA3-PSK-SAE; or WPA-Enterprise; or WPA2-Enterprise; or WPA-WPA2-Enterprise; or WPA3-Enterprise.

[0041] In a possible implementation, the first authentication encryption mode is the same as the authentication encryption mode used by the master device.

[0042] In a possible implementation, the first message further includes third indication information, where the third indication information is used to indicate a first frequency band supported by the slave device, where the first frequency band is one of at least one frequency band supported by the slave device.

[0043] In a possible implementation manner, the second message further includes third indication information.

[0044] In a possible implementation, the first message is a wireless local area network management control interface WMCI message, and the second message is a WMCI message.

[0045] In a possible implementation, the first message further includes seventh indication information, where the seventh indication information is used to indicate a device capability parameter set of the WLAN of the slave device, where the device capability parameter set of the WLAN of the slave device includes an authentication encryption mode parameter of the slave device and a frequency band parameter of the slave device.

[0046] In a possible implementation manner, the seventh indication information is located in the message type identification field of the first message.

[0047] In a possible implementation, the second message also includes eighth indication information, where the eighth indication information is used to indicate a working parameter configuration parameter set of the WLAN of the slave device, where the working parameter configuration parameter set of the WLAN of the slave device includes an authentication encryption mode parameter of the slave device and a frequency band parameter of the slave device.

[0048] In a possible implementation manner, the eighth indication information is located in the message type identifier field of the second message.

[0049] In one possible embodiment, the message content field of the first message also includes a parameter mask field, and the message content field of the second message also includes a parameter mask field, the parameter mask field includes ninth indication information and tenth indication information, the ninth indication information is used to indicate the authentication encryption mode parameters of the slave device, and the tenth indication information is used to indicate the frequency band parameters of the slave device.

[0050] In a possible implementation, the message content field of the first message further includes first indication information and third indication information; the message content field of the second message further includes second indication information and third indication information.

[0051] In a possible implementation, the first message is encapsulated in a payload field of a fiber-to-the-room encapsulation mode FEM frame, and the FEM port identifier in the frame header of the FEM frame is used to indicate the slave device corresponding to the first message.

[0052] In a possible implementation, the FEM frame is encapsulated in the payload field of the data link layer DLL frame.

[0053] In a possible implementation, the master device is a master fiber-to-the-room FTTR unit MFU, and the slave device is a slave FTTR unit SFU.

[0054] It should be noted that there are many other specific implementation methods of the embodiments of the present application. Please refer to the specific implementation methods and beneficial effects of the first aspect for details, which will not be repeated here.

[0055] In a third aspect, the present application provides an optical network communication method, which is applied to an optical fiber network, wherein the optical fiber network includes a master device and at least one slave device. The optical network communication method provided in this aspect can be executed by the master device in the optical fiber network, or it can be executed by some functional modules or chips in the master device. Taking the master device execution as an example, the master device receives a first message, the first message includes first indication information, and the first indication information is used to indicate at least one authentication encryption mode supported by the slave device;

[0056] The at least one authentication encryption mode includes at least one of the following modes:

[0057] WEP-64 mode; or WEP-128 mode; or WPA-Personal mode; or WPA2-Personal mode; or WPA-WPA2-Personal mode; or WPA3-SAE; or WPA2-WPA3-PSK-SAE; or WPA-Enterprise; or WPA2-Enterprise; or WPA-WPA2-Enterprise; or WPA3-Enterprise.

[0058] In one possible implementation, the method further includes:

[0059] The master device sends a second message including second indication information, where the second indication information is used to instruct the slave device to use a first authentication encryption mode, where the first authentication encryption mode is one of at least one authentication encryption mode supported by the slave device.

[0060] In a possible implementation, the master device receives the first message, including:

[0061] The master device receives at least one first message, where the at least one first message comes from at least one slave device respectively, and the authentication encryption modes indicated by the first indication information in different first messages are not completely the same;

[0062] The master device sends a second message including:

[0063] The master device sends at least one second message, the at least one second message corresponds to at least one slave device, and the second indication information in different second messages all indicates the use of the first authentication encryption mode.

[0064] In a possible implementation, the first authentication encryption mode is an authentication encryption mode supported by at least one slave device.

[0065] In a possible implementation, the first authentication encryption mode is the same as the authentication encryption mode used by the master device.

[0066] In a possible implementation, the first message further includes third indication information, where the third indication information is used to indicate a first frequency band supported by the slave device, where the first frequency band is one of at least one frequency band supported by the slave device.

[0067] Optionally, the second message also includes third indication information.

[0068] In a possible implementation, the master device receiving the first message includes: the master device receiving the first message during an initialization configuration phase;

[0069] The master device sends the second message, including: before configuring and enabling the roaming function of the slave device, the master device sends the second message to the slave device.

[0070] In this embodiment, the master device and the slave device exchange the first and second messages during the initialization configuration phase, that is, before the master device enables the roaming function of the slave device. Because the master device configures the authentication and encryption mode used by the slave device during the initialization phase, there is no need to reconfigure the authentication and encryption mode for roaming. This saves the signaling overhead required for subsequent roaming security configuration and improves the master device's configuration efficiency.

[0071] In a possible implementation, the first authentication encryption mode is the WPA2-WPA3-PSK-SAE mode, and the WPA2-WPA3-PSK-SAE mode is used to indicate that the authentication method adopts the WPA2-PSK mode compatible with the WPA3-SAE mode, and the encryption method adopts the Advanced Encryption Standard AES algorithm.

[0072] In this embodiment, the master device can configure a WPA2 and WPA3 compatible authentication and encryption mode for the slave device, which is beneficial for the slave device to enable WPA2 or WPA3 as needed to perform security verification on the terminal device, thereby improving the flexibility of the slave device in authenticating the terminal device.

[0073] In a possible implementation, the at least one slave device includes a first slave device and a second slave device; and the method further includes:

[0074] After the master device determines that the second slave device is offline, the master device sends a third message to the first slave device. The third message includes fourth indication information. The fourth indication information is used to instruct the first slave device to use a second authentication encryption mode. The second authentication encryption mode is an authentication encryption mode supported by the first slave device. The second authentication encryption mode is different from the first authentication encryption mode.

[0075] In a possible implementation, the at least one slave device includes a first slave device and a second slave device; and the method further includes:

[0076] The master device receives a fourth message from the third slave device, the fourth message includes fifth indication information, and the fifth indication information is used to indicate at least one authentication encryption mode supported by the third slave device; then, the master device sends a fifth message to the first slave device, the second slave device and the third slave device respectively, the fifth message includes sixth indication information, and the sixth indication information is used to indicate the use of the third authentication encryption mode, the third authentication encryption mode is an authentication encryption mode supported by the first slave device, the second slave device and the third slave device, and the third authentication encryption mode is different from the first authentication encryption mode.

[0077] In a possible implementation manner, the third message further includes third indication information; and / or the fifth message further includes third indication information.

[0078] In a possible implementation, the first message is a wireless local area network management control interface WMCI message, and the second message is a WMCI message.

[0079] In a possible implementation, the first message further includes seventh indication information, where the seventh indication information is used to indicate a device capability parameter set of the WLAN of the slave device, where the device capability parameter set of the WLAN of the slave device includes an authentication encryption mode parameter of the slave device and a frequency band parameter of the slave device.

[0080] In a possible implementation manner, the seventh indication information is located in the message type identification field of the first message.

[0081] In a possible implementation, the second message also includes eighth indication information, where the eighth indication information is used to indicate a working parameter configuration parameter set of the WLAN of the slave device, where the working parameter configuration parameter set of the WLAN of the slave device includes an authentication encryption mode parameter of the slave device and a frequency band parameter of the slave device.

[0082] In a possible implementation manner, the eighth indication information is located in the message type identifier field of the second message.

[0083] In one possible embodiment, the message content field of the first message also includes a parameter mask field, and the message content field of the second message also includes a parameter mask field, the parameter mask field includes ninth indication information and tenth indication information, the ninth indication information is used to indicate the authentication encryption mode parameters of the slave device, and the tenth indication information is used to indicate the frequency band parameters of the slave device.

[0084] In a possible implementation, the message content field of the first message further includes first indication information and third indication information; the message content field of the second message further includes second indication information and third indication information.

[0085] In a possible implementation, the first message is encapsulated in a payload field of a fiber-to-the-room encapsulation mode FEM frame, and the FEM port identifier in the frame header of the FEM frame is used to indicate the slave device corresponding to the first message.

[0086] In a possible implementation, the FEM frame is encapsulated in the payload field of the data link layer DLL frame.

[0087] In a possible implementation, the master device is a master fiber-to-the-room FTTR unit MFU, and the slave device is a slave FTTR unit SFU.

[0088] It should be noted that there are many other specific implementation methods of the embodiments of the present application. Please refer to the specific implementation methods and beneficial effects of the first aspect for details, which will not be repeated here.

[0089] In a fourth aspect, the present application provides an optical network communication method, which is applied to an optical fiber network, wherein the optical fiber network includes a master device and at least one slave device. The optical network communication method provided in this aspect can be executed by a slave device in the optical fiber network, or can be executed by some functional modules or chips in the slave device. Taking the execution of the slave device as an example, the slave device sends a first message to the master device, the first message including first indication information, and the first indication information is used to indicate at least one authentication encryption mode supported by the slave device;

[0090] The at least one authentication encryption mode includes at least one of the following modes:

[0091] WEP-64 mode; or WEP-128 mode; or WPA-Personal mode; or WPA2-Personal mode; or WPA-WPA2-Personal mode; or WPA3-SAE; or WPA2-WPA3-PSK-SAE; or WPA-Enterprise; or WPA2-Enterprise; or WPA-WPA2-Enterprise; or WPA3-Enterprise.

[0092] In a possible embodiment, the method also includes: receiving a second message from the master device from the slave device, the second message including second indication information, the second indication information being used to instruct the slave device to use a first authentication encryption mode, the first authentication encryption mode being one of at least one authentication encryption mode supported by the slave device.

[0093] In a possible implementation, the first authentication encryption mode is the same as the authentication encryption mode used by the master device.

[0094] In a possible implementation, the first message further includes third indication information, where the third indication information is used to indicate a first frequency band supported by the slave device, where the first frequency band is one of at least one frequency band supported by the slave device.

[0095] In a possible implementation manner, the second message further includes third indication information.

[0096] In one possible implementation, sending a first message from a slave device to a master device includes: sending the first message from the slave device to the master device during the initialization configuration phase; and receiving a second message from the master device from the slave device includes: receiving the second message from the master device before configuring and enabling the roaming function of the slave device.

[0097] In a possible implementation, the first authentication encryption mode is the WPA2-WPA3-PSK-SAE mode, and the WPA2-WPA3-PSK-SAE mode is used to indicate that the authentication method adopts the WPA2-PSK mode compatible with the WPA3-SAE mode, and the encryption method adopts the Advanced Encryption Standard AES algorithm.

[0098] It should be noted that there are many other specific implementations of the embodiments of the present application. Please refer to the specific implementations and beneficial effects of the first or third aspects for details, which will not be repeated here.

[0099] In a fifth aspect, the present application provides an optical network communication method, which is applied to an optical fiber network, wherein the optical fiber network includes a master device and at least one slave device. The optical network communication method provided in this aspect can be executed by the master device in the optical fiber network, or it can be executed by some functional modules or chips in the master device. Taking the execution of the master device as an example, the master device sends a device capability parameter request message to the slave device, and the device capability parameter request message includes ninth indication information, and the ninth indication information is used to indicate the authentication encryption mode parameters supported by the slave device; then, the master device receives a device capability parameter report message from the slave device, and the device capability parameter report message includes first indication information, and the first indication information is used to indicate at least one authentication encryption mode supported by the slave device.

[0100] In this embodiment, during the initialization phase, the master device can request the slave device to report authentication and encryption capabilities (i.e., at least one authentication and encryption mode supported by the slave device) through a capability parameter request message, thereby enabling the master device to request capability parameters (e.g., authentication and encryption capabilities) from the slave device on demand, which is conducive to improving the flexibility of the master device in obtaining capability parameters.

[0101] In a possible implementation manner, the device capability parameter request message further includes tenth indication information, where the tenth indication information is used to indicate frequency band parameters supported by the slave device.

[0102] In a possible implementation, the device capability parameter report message further includes third indication information, where the third indication information is used to indicate a first frequency band of the slave device, where the first frequency band is one of at least one frequency band supported by the slave device.

[0103] Optionally, the device capability parameter report message also includes the tenth indication information.

[0104] In this embodiment, the master device carries tenth indication information in the device capability parameter request message, indicating the frequency band parameters supported by the slave device, so that the slave device carries third indication information indicating the first frequency band in the returned device capability parameter report message. This enables the master device to obtain the authentication and encryption capabilities of the slave device by frequency band, facilitating the master device to configure the authentication and encryption mode for the slave device by frequency band, and facilitating the master device to configure the authentication and encryption mode appropriate for the operating frequency band for the slave device. This not only ensures the security of the slave device, but also increases the flexibility of the slave device in authenticating and encrypting terminal devices.

[0105] In a possible implementation, after the master device receives the device capability parameter report message from the slave device, the method further includes:

[0106] The master device sends a working parameter configuration message to the slave device, where the working parameter configuration message includes second indication information, and the second indication information is used to instruct the slave device to use the first authentication encryption method; then, the master device receives a working parameter configuration report message from the slave device, where the working parameter configuration report message is used to indicate whether the first authentication encryption method is configured successfully.

[0107] In this embodiment, during the initialization phase, after receiving the authentication encryption capability of the slave device, the master device can indicate a certain authentication encryption mode (for example, the first authentication encryption mode) to the aforementioned slave device, so that in subsequent processes (for example, in the roaming parameter configuration process), the master device no longer needs to configure security-related parameters such as the authentication encryption mode for the slave device, which is conducive to improving configuration efficiency and saving configuration overhead.

[0108] In a possible implementation, the working parameter configuration message further includes third indication information, where the third indication information is used to indicate a first frequency band of the slave device, where the first frequency band is one of at least one frequency band supported by the slave device.

[0109] Optionally, the device capability parameter report message also includes the tenth indication information.

[0110] In a possible implementation, after the master device receives the working parameter configuration report message from the slave device, the method further includes:

[0111] The master device sends a roaming function enable message to the slave device, which is used to instruct the slave device to enable the roaming function; then, the master device receives a roaming function enable report message from the slave device, which is used to indicate whether the slave device has successfully enabled the roaming function.

[0112] In this embodiment, after configuring the authentication and encryption mode for the slave device, the master device can notify the slave device to enable the roaming function through a roaming function activation message. After the slave device enables the roaming function, the master device can also configure the roaming function through a configuration message (e.g., a roaming network configuration message). Because the master device has already configured the appropriate authentication and encryption mode (e.g., the first authentication and encryption mode) for the slave device during the initialization phase, the master device does not need to configure security-related parameters such as the authentication and encryption mode for the slave device during the roaming function configuration phase. For example, the roaming network configuration message may not carry security-related parameters such as the authentication and encryption mode. This helps improve configuration efficiency and saves configuration overhead.

[0113] In one possible implementation, the at least one authenticated encryption mode includes at least one of the following modes:

[0114] WEP-64 mode; or WEP-128 mode; or WPA-Personal mode; or WPA2-Personal mode; or WPA-WPA2-Personal mode; or WPA3-SAE; or WPA2-WPA3-PSK-SAE; or WPA-Enterprise; or WPA2-Enterprise; or WPA-WPA2-Enterprise; or WPA3-Enterprise.

[0115] In a possible implementation, the first authentication encryption mode is the WPA2-WPA3-PSK-SAE mode, and the WPA2-WPA3-PSK-SAE mode is used to indicate that the authentication method adopts the WPA2-PSK mode compatible with the WPA3-SAE mode, and the encryption method adopts the Advanced Encryption Standard AES algorithm.

[0116] It should be noted that there are many other specific implementations of the embodiments of the present application. Please refer to the specific implementations and beneficial effects of the first or third aspects for details, which will not be repeated here.

[0117] In a sixth aspect, the present application provides an optical network communication method, which is applied to an optical fiber network, wherein the optical fiber network includes a master device and at least one slave device. The optical network communication method provided in this aspect can be executed by a slave device in the optical fiber network, or it can be executed by some functional modules or chips in the slave device. Taking the execution of the slave device as an example, the slave device receives a device capability parameter request message from the master device, and the device capability parameter request message includes ninth indication information, and the ninth indication information is used to indicate the authentication encryption mode parameters supported by the slave device; then, the slave device sends a device capability parameter report message to the master device, and the device capability parameter report message includes first indication information, and the first indication information is used to indicate at least one authentication encryption mode supported by the slave device.

[0118] In a possible implementation manner, the device capability parameter request message further includes tenth indication information, where the tenth indication information is used to indicate frequency band parameters supported by the slave device.

[0119] In a possible implementation, the device capability parameter report message further includes third indication information, where the third indication information is used to indicate a first frequency band of the slave device, where the first frequency band is one of at least one frequency band supported by the slave device.

[0120] In a possible implementation, after the slave device sends the device capability parameter report message to the master device, the method further includes:

[0121] The slave device receives a working parameter configuration message from the master device, where the working parameter configuration message includes second indication information, and the second indication information is used to instruct the slave device to use the first authentication encryption method; then, the slave device sends a working parameter configuration report message to the master device, where the working parameter configuration report message is used to indicate whether the first authentication encryption method is configured successfully.

[0122] In a possible implementation, the working parameter configuration message further includes third indication information, where the third indication information is used to indicate a first frequency band of the slave device, where the first frequency band is one of at least one frequency band supported by the slave device.

[0123] In a possible implementation, after the slave device sends the operating parameter configuration report message to the master device, the method further includes:

[0124] The slave device receives a roaming function activation message from the master device, which is used to instruct the slave device to activate the roaming function; then, the slave device sends a roaming function activation report message to the master device, which is used to indicate whether the slave device has successfully activated the roaming function.

[0125] In one possible implementation, the at least one authenticated encryption mode includes at least one of the following modes:

[0126] WEP-64 mode; or WEP-128 mode; or WPA-Personal mode; or WPA2-Personal mode; or WPA-WPA2-Personal mode; or WPA3-SAE; or WPA2-WPA3-PSK-SAE; or WPA-Enterprise; or WPA2-Enterprise; or WPA-WPA2-Enterprise; or WPA3-Enterprise.

[0127] In a possible implementation, the first authentication encryption mode is the WPA2-WPA3-PSK-SAE mode, and the WPA2-WPA3-PSK-SAE mode is used to indicate that the authentication method adopts the WPA2-PSK mode compatible with the WPA3-SAE mode, and the encryption method adopts the Advanced Encryption Standard AES algorithm.

[0128] It should be noted that there are many other specific implementations of the embodiments of the present application. Please refer to the specific implementations and beneficial effects of the first aspect, the third aspect, or the fifth aspect, which will not be repeated here.

[0129] In a seventh aspect, an embodiment of the present application provides a communication device, which can be a main device in the aforementioned embodiment or a chip within the main device. The communication device may include a processing module and a transceiver module. When the communication device is a main device, the processing module may be a processor and the transceiver module may be a transceiver; the main device may further include a storage module, which may be a memory; the storage module is used to store instructions, and the processing module executes the instructions stored in the storage module to cause the main device to execute the method of the main device in any of the embodiments of any of the aforementioned aspects. When the communication device is a chip within the main device, the processing module may be a processor and the transceiver module may be an input / output interface, a pin, or a circuit; the processing module executes the instructions stored in the storage module to cause the main device to execute the method of the first aspect or any of the embodiments of the first aspect; or, execute the method of the main device in any of the embodiments of any of the aforementioned aspects. The storage module may be a storage module within the chip (e.g., a register, a cache, etc.) or a storage module within the main device located outside the chip (e.g., a read-only memory, a random access memory, etc.).

[0130] In an eighth aspect, an embodiment of the present application provides a communication device, which may be a slave device in the aforementioned embodiment or a chip within the slave device. The communication device may include a processing module and a transceiver module. When the communication device is a slave device, the processing module may be a processor and the transceiver module may be a transceiver. Optionally, the slave device may further include a storage module, which may be a memory; the storage module is used to store instructions, and the processing module executes the instructions stored in the storage module so that the slave device executes the method of the slave device in any of the embodiments in any of the aforementioned aspects. When the communication device is a chip within a slave device, the processing module may be a processor, and the transceiver module may be an input / output interface, a pin, or a circuit, etc.; the processing module executes the instructions stored in the storage module so that the slave device executes the method of the slave device in any of the embodiments in any of the aforementioned aspects. The storage module may be a storage module within the chip (e.g., a register, a cache, etc.) or a storage module within the slave device that is located outside the chip (e.g., a read-only memory, a random access memory, etc.).

[0131] In a ninth aspect, the present application provides a communication device, which may be an integrated circuit chip. The integrated circuit chip includes a processor. The processor is coupled to a memory, which stores programs or instructions. When the program or instructions are executed by the processor, the communication device performs the method described in any of the various embodiments of the aforementioned aspects, as well as the aforementioned aspects.

[0132] In a tenth aspect, an embodiment of the present application provides a computer program product comprising instructions, which, when the aforementioned instructions are run on a computer, enables the computer to execute the method introduced in any one of the various implementations of the aforementioned aspects.

[0133] In the eleventh aspect, an embodiment of the present application provides a computer-readable storage medium comprising instructions, which, when executed on a computer, enable the computer to execute a method as described in any one of the various embodiments of the aforementioned aspects.

[0134] In a twelfth aspect, an embodiment of the present application provides a fiber optic network, which includes the master device in the above-mentioned first aspect and any one of the embodiments of the first aspect, and the slave device in the above-mentioned second aspect and any one of the embodiments of the second aspect.

[0135] In a thirteenth aspect, an embodiment of the present application provides a fiber optic network, which includes the master device in the third aspect and any one of the embodiments of the third aspect, and the slave device in the fourth aspect and any one of the embodiments of the fourth aspect.

[0136] In a fourteenth aspect, an embodiment of the present application provides a fiber optic network, which includes the master device in the fifth aspect and any one of the embodiments of the fifth aspect, and the slave device in the sixth aspect and any one of the embodiments of the sixth aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0137] Figure 1A A diagram showing an example of a network architecture for a fiber optic network;

[0138] Figure 1B Another example diagram of the network architecture of a fiber optic network;

[0139] Figure 1C This is an example diagram of an FTTR system;

[0140] Figure 1D A schematic diagram of a WLAN network architecture;

[0141] Figure 2A A flow chart of the optical network communication method in this application;

[0142] Figure 2B A schematic diagram of the initialization process in this application;

[0143] Figure 3 Another flowchart of the optical network communication method in this application;

[0144] Figure 4 Another flowchart of the optical network communication method in this application;

[0145] Figure 5A An example diagram of a FEM frame encapsulating a WMCI message;

[0146] Figure 5B An example diagram of an XFEM frame encapsulating a WMCI message;

[0147] Figure 5C An example diagram of a DLL frame that encapsulates a FEM frame;

[0148] Figure 5D An example diagram of a DLL frame that encapsulates an XFEM frame;

[0149] Figure 6 A schematic diagram of an embodiment of a communication device in this application;

[0150] Figure 7 This is a schematic diagram of another embodiment of the communication device in this application. DETAILED DESCRIPTION

[0151] The technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments.

[0152] In the various embodiments of the present application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.

[0153] The terms "first," "second," "third," "fourth," and the like (if any) in the specification and claims of this application and in the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a particular order or sequential sequence. It should be understood that the terms used in this manner are interchangeable where appropriate so that the embodiments described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "including" and "having," and any variations thereof, are intended to cover non-exclusive inclusions, e.g., a process, method, system, product, or apparatus comprising a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such process, method, product, or apparatus.

[0154] It should be understood that the term "and / or" in this document simply describes a relationship between related objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A exists alone, A and B exist simultaneously, or B exists alone. Furthermore, the character " / " in this document generally indicates that the related objects are in an "or" relationship.

[0155] The optical network communication method provided in this application is applied to optical fiber networks. Figure 1A The following is an example diagram of the architecture of a fiber optic network in traditional technology. Figure 1AAs shown, the fiber optic network includes an optical line terminal (OLT), an optical distribution network (ODN) and an optical network unit (ONU) (or optical network terminal (ONT)). The OLT and the ONU are connected and communicated through optical fibers. The OLT is generally connected to the ONU (or ONT) through the ODN. The ODN includes a network composed of one or more optical devices such as optical fibers, optical distribution frames (ODFs), optical splitters (also known as splitters), and combiners. In addition, the aforementioned OLT can be connected to the operator network through a network side interface, and the OLT can be connected to the ODN through a dedicated interface, and the ODN is connected to the ONU (or ONT) through a dedicated interface. In the downstream direction, the OLT broadcasts the downstream optical signal, and the downstream optical signal is distributed to each ONU (or ONT) through the ODN. In the upstream direction, a time division multiple access (TDMA) method is adopted, and each ONU (or ONT) sends an upstream optical signal in its respective upstream time slot allocated by the OLT. It should be noted that the present application does not limit the specific type of optical fiber. The optical fiber described in the present application can be a single optical fiber, a loose-tube optical fiber, an optical cable or an optoelectronic composite cable, etc.

[0156] Figure 1B A schematic diagram of the structure of the optical fiber network provided in this application. Figure 1B As shown, the fiber optic network provided in this application includes a master device 01 and at least one slave device 02. The master device 01 is connected to the at least one slave device 02 via an optical fiber. For example, the master device 01 is connected to the at least one slave device 02 via an optical distribution network. The master device 01 can manage or control specific functions of one or more slave devices 02 based on at least one protocol.

[0157] Optionally, the optical network communication method provided in this application is applied to a fiber-to-the-room (FTTR) scenario. The FTTR technology refers to a technology that uses optical fiber instead of network cables to provide optical fiber media access to the room in the downlink of an optical network device (e.g., an optical network terminal (ONT)). Figure 1B The main device 01 shown can be called a main FTTR unit (MFU), a FTTR main device or a main gateway. Figure 1BThe slave device 02 shown may be referred to as a slave FTTR unit (SFU), a FTTR slave device, or a slave gateway.

[0158] Figure 1C An example diagram of the network location of FTTR is shown in Figure 1. Figure 1C As shown, FTTR is a network that provides fiber coverage within the broadband customer network (for example, a home or office) based on fiber to the home / office (FTTH / O). Fiber optic connections are used between the FTTR master device and the FTTR slave devices in each room. Both the FTTR master device and the FTTR slave devices can be connected to user terminals through wireless or wired interfaces, or can be connected to user terminal devices through adapter devices such as set-top boxes. The FTTR master device's northbound connection serves as an access network terminal connected to the access node (AN) device, and the southbound FTTR transceiver unit of the FTTR master device connects to the FTTR transceiver unit of the FTTR slave device through the indoor fiber distribution network (IFDN), and also provides gateway functions and other network functions. The FTTR transceiver unit of the FTTR slave device is connected to the TTTP transceiver unit of the FTTR master device through the indoor optical distribution network, and provides terminal access through wireless or wired interfaces. The indoor optical distribution network is a point-to-multipoint fiber optic infrastructure that can be completely passive, usually consisting of interconnected optical cables and passive components such as optical splitters. It can also provide remote feeding capabilities for FTTR slave equipment by using optical-electrical hybrid cables and optical-electrical hybrid splitters.

[0159] Optionally, FTTR technology can be combined with wireless local area network (WLAN) technology to extend the ultra-gigabit wireless fidelity (Wi-Fi) network coverage to every corner of the home, meeting Internet access needs such as low latency, high bandwidth, multiple connections, and seamless roaming. Figure 1BThe master device 01 shown is capable of establishing a WMCI management channel with at least one slave device 02 based on the WLAN management control interface (WMCI) protocol. The master device can then manage or control the WLAN functions of one or more slave devices 02 via WMCI messages. This can be understood as meaning that the master device 01 and / or the slave device 02 have WLAN functionality; it can also be understood as meaning that the master device 01 and / or the slave device 02 have wireless fidelity (Wi-Fi) functionality. Therefore, the optical network communication method provided in this application can also be applied to WLAN scenarios.

[0160] For example, Figure 1D This is a schematic diagram of the WLAN network architecture. The WLAN network architecture mainly includes wireless controllers (also called control nodes), wireless access points (also called network nodes, or simply access points (AP)) and terminal devices (also called stations (STA)). A station is associated with a wireless access point, and a wireless access point can be associated with multiple stations. The station accesses the network through the associated wireless access point. The wireless controller is used to manage or control the wireless access point. Figure 1D In the example shown, the wireless controller can be an FTTR master device, the access point (e.g., AP) can be an FTTR slave device, and the station (e.g., STA) can be a terminal device that accesses the network through the FTTR device (FTTR master device or FTTR slave device).

[0161] It should be noted that the embodiments of the present application can be applied not only to FTTR architectures but also to non-FTTR architectures. For example, any architecture of a communication system consisting of a master device and slave devices is applicable to the embodiments of the present application. For ease of description, the embodiments of the present application will primarily use the master and slave devices in an FTTR architecture as an example.

[0162] In traditional technology, a slave device can determine to use a certain authentication and encryption mode based on pre-configured information during the initialization phase to provide security authentication for terminal devices accessing the network. This implementation method may cause multiple slave devices managed by the same master device to use different authentication and encryption modes. For example, the master device manages slave device 1 and slave device 2, where slave device 1 uses an authentication and encryption mode with higher security performance (for example, Wi-Fi Protected Access (WPA)), while slave device 2 uses an authentication and encryption mode with lower security performance (for example, Wired Equivalent Privacy (WEP)). This results in different security capabilities of different devices, which may affect the security of some devices (for example, terminal devices accessing the network through slave devices). In addition, the terminal device can only access the network through the slave device after the slave device completes the authentication and encryption verification. When the terminal device roams between different slave devices, since different slave devices use different authentication and encryption modes, the terminal device needs to adapt to the roaming processes corresponding to different authentication methods. Therefore, the processing complexity of the terminal device affects the energy consumption and service stability of the terminal device.

[0163] In this regard, the present application provides an optical network communication method and a communication device, which are used to unify the authentication and encryption mode of the entire network through negotiation between the master device and the slave device. This is not only beneficial to improving the security of the network, but also enables the terminal device to roam between devices without the need for additional adaptation processing, which is beneficial to reducing the processing complexity of the terminal device, saving the energy consumption of the terminal device, and improving the service stability or reliability of the terminal device.

[0164] The following will be combined Figure 2A The main process of the optical network communication method provided by this application is introduced:

[0165] like Figure 2A As shown, it is a flow chart of an embodiment of the optical network communication method provided by the present application. In this embodiment, the interaction between a master device and at least one slave device is taken as an example for explanation. The master device is connected to at least one slave device via an optical fiber or a composite cable and manages the at least one slave device. Of course, the subject that executes the master device action in the method can also be a device, module or chip in the master device; the subject that executes the slave device action in the method can also be a device, module or chip in the slave device, and this embodiment does not make specific limitations on this. For example, as Figure 2A As shown, the optical network communication method includes the following steps:

[0166] Step 201: The slave device sends a first message to the master device; correspondingly, the master device receives the first message from the slave device.

[0167] For example, the slave device sends a first message to the master device through the optical fiber or composite cable; correspondingly, the master device receives the first message from the slave device through the optical fiber or composite cable.

[0168] The first message includes first indication information, and the first indication information is used to indicate at least one authenticated encryption mode supported by the slave device. It can be understood that the first indication information is used to indicate the authenticated encryption capability of the slave device. Since authenticated encryption is intended to improve security, the authenticated encryption mode is also called a security mode (Security Modes), that is, the first indication information is used to indicate the security mode (Security Modes Supported) supported by the slave device.

[0169] Optionally, the authentication encryption mode supported by the slave device may be Wired Equivalent Privacy (WEP), Wi-Fi Protected Access (WPA), Wi-Fi Protected Access 2 (WPA2), or Wi-Fi Protected Access 3 (WPA3). Optionally, WEP may be further divided into WEP-64 (i.e., WEP using a 64-bit key) or WEP-128 (i.e., WEP using a 128-bit key).

[0170] Optionally, the scenarios in which authenticated encryption mode is used can be further divided into authenticated encryption mode for individual users (Personal) and authenticated encryption mode for enterprise users (Enterprise). For example, WPA can be divided into WPA-Personal (i.e., WPA for individual users) and WPA-Enterprise (i.e., WPA for enterprise users). For another example, WPA2 can be divided into WPA2-Personal (i.e., WPA2 for individual users) and WPA2-Enterprise (i.e., WPA2 for enterprise users). For another example, WPA3 can be divided into WPA3-SAE (i.e., WPA3 for individual users) and WPA3-Enterprise (i.e., WPA3 for enterprise users).

[0171] Optionally, WPA has higher security than WPA2, and WPA2 has higher security than WPA3. Optionally, WPA has higher security than WEP, and WEP-128 has higher security than WEP-64.

[0172] Optionally, the slave device may also support compatible authentication and encryption modes, such as WPA-WPA2-Personal, WPA2-WPA3-PSK-SAE, and WPA-WPA2-Enterprise. Among them, WPA-WPA2-Personal means that user-oriented WPA is compatible with user-oriented WPA, that is, the slave device supports both WPA-Personal mode and WPA2-Personal mode; WPA2-WPA3-PSK-SAE means that WPA2-PSK mode is compatible with WPA3-SAE mode, that is, the slave device supports both WPA2-PSK mode and WPA3-SAE mode; WPA-WPA2-Enterprise means that WPA-Enterprise mode is compatible with WPA2-Enterprise mode, that is, the slave device supports both WPA-Enterprise mode and WPA2-Enterprise mode. This embodiment provides a combination of multiple compatible authentication and encryption modes, which is conducive to improving the compatibility of the system and improving the flexibility of the master device in configuring authentication and encryption modes for multiple slave devices.

[0173] Exemplarily, the authenticated encryption mode supported by the slave device includes at least one of the following:

[0174] WEP-64, WEP-128, WPA-Personal, WPA2-Personal, WPA-WPA2-Personal, WPA3-SAE, WPA2-WPA3-PSK-SAE, WPA-Enterprise, WPA2-Enterprise, WPA-WPA2-Enterprise, or, WPA3-Enterprise.

[0175] Optionally, the slave device may also support encryption without authentication.

[0176] It should be noted that the authentication encryption mode indicated by the first indication information in this embodiment is a combination of an authentication method (i.e., identity authentication (Authentication) method) and an encryption (Encryption) method, and does not refer to a single authentication method or an encryption method. That is to say, when an authentication encryption mode is known, the device (master device or slave device) can determine which authentication method is used for the authentication encryption mode, and which encryption method is used. Compared with the solution of configuring the authentication method and the encryption method separately in the traditional technology, it can avoid configuration conflicts (for example, the authentication method and the encryption method are incompatible), which is conducive to improving the reliability of configuring the authentication encryption mode and improving the efficiency of the configuration. For example, the WPA3 authentication method can only be combined with the AES algorithm. If the WPA3 authentication method is used but the TKIP algorithm is used, a configuration conflict will result due to the incompatibility between the authentication method and the encryption method.

[0177] Exemplarily, the first indication information carried by the first message may indicate an authentication encryption mode, and the specific authentication method (i.e., identity authentication method) and encryption method corresponding to the authentication encryption mode are shown in Table 1 below:

[0178] Table 1

[0179]

[0180] In the example shown in Table 1, if the first indication information indicates "None", it means that the slave device adopts an open authentication and encryption method, that is, supports a mode without authentication and encryption.

[0181] If the first indication information indicates "WEP-64", it means that the authentication method supported by the slave device is "Shared", which means shared key authentication, that is, the client (for example, the terminal device) needs to provide a key that matches the pre-stored key of the access point (for example, the slave device); the supported encryption method is "WEP-64", that is, encryption using a 64-bit key.

[0182] If the first indication information indicates "WEP-128", it means that the authentication method supported by the slave device is "Shared", which means shared key authentication; the supported encryption method is "WEP-128", that is, encryption using a 128-bit key.

[0183] If the first indication information indicates "WPA-Personal", it means that the authentication method supported by the slave device is "WPA-PSK", that is, the pre-shared key (PSK) mode of WAP; the supported encryption method is "TKIP", that is, the temporal key integrity protocol (TKIP) algorithm.

[0184] If the first indication information indicates "WPA2-Personal", it means that the authentication method supported by the slave device is "WPA2-PSK", that is, the pre-shared key (PSK) mode of WPA2; the supported encryption method is "AES", that is, the Advanced Encryption Standard (AES) algorithm.

[0185] If the first indication information indicates "WPA-WPA2-Personal," the slave device supports the following authentication methods: "WPA-PSK" and "WPA2-PSK," and the following encryption methods: "TKIP" and "AES." For example, if the authentication method is "WPA-PSK," the encryption method is "TKIP," or if the authentication method is "WPA2-PSK," the encryption method is "AES."

[0186] If the first indication information indicates "WPA3-SAE", it means that the authentication method supported by the slave device is "WPA3-SAE", that is, the simultaneous authentication of equals (SAE) method of WPA3; the supported encryption method is "AES", that is, the AES algorithm.

[0187] If the first indication information indicates "WPA2-WPA3-PSK-SAE", it means that the authentication methods supported by the slave device are "WPA2-PSK" and "WPA3-SAE"; and the supported encryption method is "AES".

[0188] If the first indication information indicates "WPA-Enterprise", it means that the authentication method supported by the slave device is "WPA-Enterprise"; the supported encryption method is "TKIP", that is, the TKIP algorithm.

[0189] If the first indication information indicates "WPA2-Enterprise", it means that the authentication method supported by the slave device is "WPA2-Enterprise"; the supported encryption method is "AES", that is, the AES algorithm.

[0190] If the first indication information indicates "WPA-WPA2-Enterprise", it means that the slave device supports the authentication methods "WPA-Enterprise" and "WPA2-Enterprise" and the encryption methods "TKIP" and "AES". For example, if the authentication method is "WPA-Enterprise", the encryption method is "TKIP"; or if the authentication method is "WPA2-Enterprise", the encryption method is "AES".

[0191] If the first indication information indicates "WPA3-Enterprise", it means that the authentication method supported by the slave device is "WPA3-Enterprise"; the supported encryption method is "AES", that is, the AES algorithm.

[0192] It should be noted that the first indication information in the first message may indicate only one authentication encryption mode shown in Table 1, or may indicate multiple authentication encryption modes in Table 1, which is not limited in this embodiment.

[0193] Optionally, the first message also includes a third indication information, and the third indication information is used to indicate the first frequency band supported by the slave device, and the first frequency band is a frequency band in at least one frequency band supported by the slave device. In one example, the frequency band supported by the slave device may include 2.4 GHz and 5 GHz, and the first frequency band is any one of 2.4 GHz and 5 GHz. In another example, the frequency band supported by the slave device may include at least one of 2.4 GHz, 5 GHz and 6 GHz, and the first frequency band is any one of 2.4 GHz, 5 GHz and 6 GHz. In another example, the frequency band supported by the slave device may include at least one of 2.4 GHz, 5 GHz, 5 GHz low frequency (5G-Low) and 5 GHz high frequency (5G-High), and the first frequency band is any one of 2.4 GHz, 5 GHz, 5 GHz low frequency (5G-Low) and 5 GHz high frequency (5G-High). In another example, the slave device only supports 2.4 GHz, and the first frequency band is 2.4 GHz. In another example, the slave device only supports 5 GHz, and the first frequency band is 5 GHz. It should be noted that with the development of communication technology, the types of frequency bands supported by the device can be further expanded, and examples are not listed one by one here.

[0194] It should be noted that since the first message includes the first indication information and the third indication information, the first indication information can also be understood as indicating the authentication and encryption modes supported by the slave device when operating in the first frequency band. For example, if the first indication information indicates "WEP-64" and "WEP-128" as the authentication and encryption modes, and the third indication information indicates "2.4 GHz" as the first frequency band, this indicates that when the slave device operates in 2.4 GHz, it supports both "WEP-64" and "WEP-128" authentication and encryption modes. If the master device configures either "WEP-64" or "WEP-128" encryption mode for the slave device, the slave device will be able to operate normally and securely in 2.4 GHz. In other words, the slave device reports its authentication and encryption capabilities by frequency band. If the slave device supports two or more frequency bands, it reports the authentication and encryption modes corresponding to the different frequency bands to the master device via separate messages. For example, if the slave device supports two frequency bands (e.g., 2.4 GHz and 5 GHz), the slave device reports its authentication and encryption capabilities to the master device via two messages. For example, the slave device sends a first message #1 to the master device, and the first message #1 includes first indication information #1 and third indication information #1, wherein the first indication information #1 indicates that the supported authentication and encryption modes are "WEP-64" and "WEP-128", and the third indication information #1 indicates that the first frequency band is "2.4GHz", indicating that when the slave device operates at 2.4GHz, the slave device supports the two authentication and encryption modes of "WEP-64" and "WEP-128"; the slave device sends a first message #2 to the master device, and the first message #2 includes first indication information #2 and third indication information #2, wherein the first indication information #2 indicates that the supported authentication and encryption modes are "WPA-Personal" and "WPA2-Personal", and the third indication information #2 indicates that the first frequency band is "5GHz", indicating that when the slave device operates at 5GHz, the slave device supports the two authentication and encryption modes of "WPA-Personal" and "WPA2-Personal".

[0195] It can be seen from this that reporting the authentication and encryption capabilities of the slave device by frequency band helps the master device accurately know which authentication and encryption modes the slave device supports when operating in a specific frequency band. This in turn helps the master device configure the authentication and encryption mode suitable for the slave device to use when operating in that frequency band based on the frequency band configuration, improving the adaptability of the authentication and encryption mode configured by the master device and helping to improve the security of the system. In addition, the electronic devices and software algorithms of the processing chips for different frequency bands in the slave device are relatively independent, that is, the authentication and encryption algorithms for different frequency bands are generally encapsulated in processing chips for different frequency bands. Reporting the authentication and encryption capabilities for different frequency bands in different messages helps to independently enable authentication and encryption methods operating in different frequency bands. For example, it helps the master device configure different authentication and encryption methods for different operating frequency bands of the same slave device, improving the flexibility of the slave device in performing authentication and encryption on the terminal device.

[0196] It should be noted that the master device can manage at least one slave device at the same time. Therefore, at least one slave device managed by the master device can send a first message to the master device respectively. Accordingly, the master device receives at least one first message, and the at least one first message comes from at least one slave device. The first message sent by each of the at least one slave device contains first indication information, except that the authentication and encryption modes indicated by the first indication information sent by different slave devices are not exactly the same. For example, the master device may receive a first message #1 from slave device 1 and a first message #2 from slave device 2, wherein the first indication information #1 in the first message #1 indicates that slave device 1 supports three authentication and encryption modes: "WEP-64", "WEP-128", and "WPA-Personal", and the first indication information #2 in the first message #2 indicates that slave device 2 supports two authentication and encryption modes: "WPA-Personal" and "WPA2-Personal".

[0197] Optionally, the first message sent by each slave device also includes third indication information. For example, the master device may receive a first message #1 from slave device 1 and a first message #2 from slave device 2, wherein the first indication information #1 in the first message #1 indicates that slave device 1 supports three authentication and encryption modes: "WEP-64", "WEP-128", and "WPA-Personal", and the third indication information #1 in the first message #1 indicates the 2.4 GHz frequency band; the first indication information #2 in the first message #2 indicates that slave device 2 supports two authentication and encryption modes: "WPA-Personal" and "WPA2-Personal", and the third indication information #2 in the first message #2 indicates the 2.4 GHz frequency band.

[0198] It should also be noted that the first message can be a message sent by the slave device to the master device on its own initiative, or it can be a message sent by the slave device to the master device based on a request from the master device. The following examples are given:

[0199] In one possible implementation, the slave device sends a first message to the master device in response to a request from the master device. For example, in the initialization phase, the master device sends a device capability parameter request (Request) message to the slave device, requesting the slave device to report the capability parameters of the slave device (for example, the authentication and encryption capability of the slave device, i.e., at least one authentication and encryption method supported by the slave device); the slave device responds to the capability parameter request (Request) sent by the master device and sends a device capability report (Report) to the master device, and the device capability report (Report) carries the capability parameters of the slave device that the master device expects to obtain (for example, the authentication and encryption capability of the slave device). In this example, the device capability report (Report) is the first message introduced in this embodiment. The master device requests capability parameters (for example, authentication and encryption capability) from the slave device on demand, which helps to improve the flexibility of the master device in obtaining capability parameters.

[0200] In another possible implementation, the slave device proactively sends a first message to the master device. For example, after the slave device goes online, during the initialization phase, the slave device proactively sends a first message to the master device. The first message carries first indication information indicating the authentication and encryption capabilities of the slave device. This facilitates the master device to learn about the authentication and encryption capabilities of the slave device as soon as the slave device goes online, thereby improving the efficiency of the master device in managing the slave device.

[0201] Step 202: The master device sends a second message to the slave device; correspondingly, the slave device receives the second message from the master device.

[0202] In this embodiment, step 202 is an optional step.

[0203] For example, the master device sends the second message to the slave device through the optical fiber or composite cable; correspondingly, the slave device receives the second message from the master device through the optical fiber or composite cable.

[0204] The second message includes second instruction information, which is used to instruct the slave device to use the first authenticated encryption mode. This can be understood as instructing the master device to configure an authenticated encryption mode enabled by the slave device. After receiving the second instruction information, the slave device configures and takes effect in the first authenticated encryption mode. When a terminal device requests network access through the slave device, the slave device uses the first authenticated encryption mode to authenticate the terminal device and verify its key.

[0205] It should be noted that the master device can manage at least one slave device at the same time, so the master device can send at least one second message, and the at least one second message corresponds to the at least one slave device one-to-one. That is to say, each of the at least one slave device receives the second message and obtains the second indication information carried by the second message, so that the at least one slave device is configured to take effect in the first authentication encryption mode, and then the at least one slave device performs identity authentication and key verification on the terminal device to be connected to the network based on the first authentication encryption mode. It can be seen that the use of the first authentication encryption mode through signaling negotiation between the master device and at least one slave device can enable at least one slave device to uniformly use an authentication encryption mode, which is not only conducive to improving the security of the network, but also enables the terminal device to roam between devices without the need for additional adaptation processing, which is conducive to reducing the processing complexity of the terminal device, saving the energy consumption of the terminal device, and improving the service stability or reliability of the terminal device.

[0206] Optionally, the first authentication encryption mode is an authentication encryption mode supported by at least one slave device. Optionally, the first authentication encryption mode is determined by the master device based on the first indication information in the first message from at least one slave device. For example, the master device may receive a first message #1 from slave device 1 and a first message #2 from slave device 2, wherein the first indication information #1 in the first message #1 indicates that slave device 1 supports three authentication encryption modes, namely "WEP-64", "WEP-128" and "WPA-Personal", and the first indication information #2 in the first message #2 indicates that slave device 2 supports two authentication encryption modes, namely "WPA-Personal" and "WPA2-Personal". The master device can determine that the authentication encryption mode supported by both slave device 1 and slave device 2 (i.e., "WPA-Personal") is the first authentication encryption mode, and then the master device sends a second message #1 and a second message #2 to slave device 1 and slave device 2, respectively, and the second message #1 and the second message #2 both carry the second indication information indicating "WPA-Personal". This shows that if the slave device does not report its authentication and encryption capabilities, and the master device blindly configures an authentication and encryption mode for the slave device, it may be configured with an encryption method that the slave device does not support, or the configured encryption method may be of a lower level, resulting in poor security. In this embodiment, the master device can select an authentication and encryption mode from the authentication and encryption modes supported by the slave device as the authentication and encryption mode used by the slave device, which can increase the probability of successfully configuring the authentication and encryption mode, thereby helping to improve the security of the network. In addition, the master device determines an authentication and encryption mode supported by multiple slave devices based on their authentication and encryption capabilities, and uses it as the authentication and encryption mode used by multiple slave devices. This helps to increase the probability of successfully configuring the authentication and encryption mode for multiple slave devices, thereby helping to improve the security of the network.

[0207] Optionally, the first authentication encryption mode is the same as the authentication encryption mode used by the master device. For example, if the master device has WLAN functionality, the authentication encryption mode used by the slave device is the same as the authentication encryption mode used by the master device. That is, the first authentication encryption mode determined by the master device is the authentication encryption mode supported by the master device, and both the master and slave devices use the first authentication encryption mode. For example, if the master device supports "WPA-Personal" and "WPA2-Personal" authentication encryption modes, slave device 1 supports "WEP-64," "WEP-128," and "WPA-Personal," and slave device 2 supports "WPA-Personal" and "WPA2-Personal," the master device may determine "WPA-Personal" as the first authentication encryption mode. This facilitates unified authentication encryption modes across the entire network. Even when a terminal device roams between the master and slave devices, the terminal device does not need to adapt to roaming processes for various authentication methods, which helps reduce the complexity of the terminal device and saves energy consumption.

[0208] Optionally, when there are multiple optional authentication and encryption modes, the master device can select based on security from high to low, or based on a preset priority from high to low. For example, if multiple devices all support WPA3, the master device determines that the aforementioned multiple devices use WPA3-Enterprise, and there is no mixed EAP authentication; if some devices support WPA2 and some devices support WPA3, or all devices support WPA2, the master device determines that the aforementioned multiple devices use WPA2-Enterprise; if some devices support WPA2 and some devices support WPA, or all devices support WPA, the master device determines that the aforementioned multiple devices use WPA-Enterprise. Among them, the multiple devices can all be slave devices, or can include a master device and slave devices.

[0209] Optionally, the second message also includes third indication information. For an explanation of the third indication information, please refer to the relevant introduction in the previous step 201, which will not be repeated here. It should be noted that, since the second message includes the second indication information and the third indication information, the second indication information can also be understood as being used to indicate that the first authentication encryption mode is used when the slave device operates in the first frequency band. It can also be understood that the first authentication encryption mode indicated by the second indication information corresponds to the first frequency band indicated by the third indication information. For example, the slave device activates the first authentication encryption mode based on the second indication information in the received second message, and the first authentication encryption mode is configured based on the third indication information in the second message for use when operating in the first frequency band.

[0210] It should also be noted that the second message can be a message sent by the master device to the slave device, or a message sent by the master device to the slave device in response to the first message. The following examples are given:

[0211] In one possible implementation, the master device actively sends a second message to the slave device. For example, after the master device knows the authentication encryption mode supported by the slave device, the master device sends a working parameter configuration (Config) message to the slave device, and the working parameter configuration (Config) message carries the working parameter configuration information configured by the master device for the slave device (for example, the second indication information indicating the first authentication encryption mode, the third indication information indicating the first frequency band, etc.). The slave device completes the parameter configuration according to the working parameter configuration information in the working parameter configuration (Config) message (for example, takes effect the first authentication encryption mode, and configures the first authentication encryption mode to be used when working in the first frequency band). Optionally, after the slave device completes the parameter configuration, the slave device sends a working parameter configuration report (Report) message to the master device, and the working parameter configuration report (Report) message is used to feedback the configuration result. In this example, the working parameter configuration (Config) message is the second message introduced in this embodiment.

[0212] In another possible implementation, the master device sends a second message to the slave device in response to the first message. For example, after receiving at least one first message from at least one slave device, the master device sends a response message (i.e., the second message) to the first message to at least one slave device.

[0213] In this embodiment, the master device and at least one slave device use a first authentication encryption mode through signaling negotiation, which enables at least one slave device to uniformly use one authentication encryption mode. This not only helps improve network security, but also enables the terminal device to roam between devices without the need for additional adaptation processing, which helps reduce the processing complexity of the terminal device (for example, reducing the requirement for the terminal device to be compatible with roaming processes with different security levels), saves energy consumption of the terminal device, and improves the service stability or reliability of the terminal device. In addition, the master device can select an authentication encryption mode from the authentication encryption modes supported by the slave device as the authentication encryption mode used by the slave device, which can increase the probability of successfully configuring the authentication encryption mode, thereby helping to improve network security.

[0214] It should be noted that the embodiments provided in this application (for example, Figure 2A Corresponding embodiments, Figure 3 Corresponding embodiments and Figure 4When applied to FTTR scenarios, the signaling interactions described in the aforementioned embodiments occur during the initialization phase. During this phase, the master device obtains the slave device's basic capability information (including supported authentication and encryption modes and supported frequency bands) through the initialization process and configures the slave device's basic operating parameters. For example, the master device configures the authentication and encryption mode used by the slave device and the frequency band corresponding to that authentication and encryption mode.

[0215] like Figure 2B As shown in the figure, taking the master device as MFU and the slave device as SFU as an example, the initialization process mainly includes the following steps:

[0216] a) The MFU sends a device capability parameter (Request) message to request the SFU to report relevant device capability parameters.

[0217] b) After receiving the data, the SFU will feedback the parameters through the device capability (Report).

[0218] c) After receiving the device capability parameters, the MFU sends the basic working parameter configuration information of the SFU through the working parameter configuration (Config).

[0219] d) After receiving the message, the SFU completes the parameter configuration according to the parameters in the message and feedbacks the configuration results through the working parameter configuration report (Report).

[0220] After receiving the feedback, the MFU completes the initialization process.

[0221] Because the master device configures the authentication and encryption mode for the slave device by frequency band during initialization, it does not need to reconfigure the authentication and encryption mode for the slave device during subsequent feature configuration. For example, if the slave device has roaming capabilities, the master device does not need to reconfigure the authentication and encryption mode for that feature when configuring the slave device's roaming capabilities. This saves the signaling overhead required for subsequent roaming security configuration and improves master device configuration efficiency.

[0222] It should be noted that when the optical communication method provided in the embodiments of the present application is applied to an FTTR scenario, the first message and the second message may be WMCI messages, which are used to manage or control the WLAN function of the slave device. The first message and the second message are respectively described with reference to examples below:

[0223] In a possible implementation, the first message is a message for reporting slave device capability parameters, that is, reporting parameters in a slave device capability parameter set. The authentication encryption mode and the frequency band of the slave device are parameters in the WLAN device capability parameter set of the slave device.

[0224] Optionally, in addition to the first indication information and the third indication information, the first message also includes seventh indication information, where the seventh indication information is used to indicate a device capability parameter set of the WLAN of the slave device, and the device capability parameter set of the WLAN of the slave device includes an authentication encryption mode parameter of the slave device and a frequency band parameter of the slave device.

[0225] Optionally, the seventh indication information is located in the message type identifier field of the first message.

[0226] Optionally, the message content field of the first message also includes a parameter mask field, and the parameter mask field includes ninth indication information and tenth indication information. The ninth indication information is used to indicate authentication and encryption mode parameters of the slave device, i.e., the ninth indication information indicates that the first message carries parameters related to the authentication and encryption mode of the slave device. The tenth indication information is used to indicate frequency band parameters of the slave device, i.e., the tenth indication information indicates that the first message carries parameters related to the frequency band of the slave device.

[0227] Optionally, the message content field of the first message further includes first indication information and third indication information. For explanations of the first indication information and the third indication information, please refer to the relevant introduction in the above step 201, which will not be repeated here.

[0228] For example, the following Table 2-1 is an example of the first message.

[0229] Table 2-1

[0230]

[0231]

[0232] As shown in Table 2-1, the first byte is the message type identification field (also called the message type ID field), which indicates the message type and defines the semantics of the message content. The message type identification field can carry a seventh indication, indicating that the message type is related to the capability parameter set of the slave device. The second byte is the sequence number (SeqNo) field, which contains a sequence number counter to ensure the robustness of the WMCI message delivery channel. In the downstream direction, the sequence number field is populated with the value of the sequence number counter of the corresponding master device. The master device maintains a separate sequence number counter for each slave device unicast and broadcast WMCI message flow. Each sequence number counter rolls over from 255 to 1, and the value 0 is not used in the downstream direction. In the upstream direction, when an upstream WMCI message is a response to a downstream WMCI message, the value of the SeqNo field is equal to the value of the SeqNo field in the downstream WMCI message. If the WMCI message is initiated by the slave device, SeqNo = 0 is used. The third and fourth bytes are the message length and processing requirement fields, which consist of three fields: the message priority (i.e., the message processing requirement), the operation type, and the length of the message content. Among them, X (the most significant bit of the third byte) is used to indicate the priority of processing this message. When X=1, it means that the message has a high priority; when X=0, it means that the message has a lower priority. C is used to indicate the operation type of this message. In the downlink direction, when C=1, it indicates that the operation type of this message is a parameter request type, indicating that the master device requests the slave device to send the slave device's parameters to the master device, that is, it requires the slave device to send the slave device's parameters to the master device; when C=0, it indicates that the operation type of this message is a parameter configuration type, indicating that the master device sends the slave device's configuration parameters to the slave device. In the uplink direction, when C=1, it identifies the operation type of the message as a scheduling request type, indicating that the slave device requests the master device to send parameters for scheduling the slave device to the slave device, that is, requests the master device to send scheduling parameters for the slave device to the slave device; when C=0, it identifies the operation type of the message as a parameter reporting or alarm type, indicating that the slave device reports the parameters of the slave device to the master device or reports alarm information. LL LLLL LLLL: indicates the length of the message content, with a value range of 0 to 1023. The remaining 4 bits RRRR are reserved. In addition, bytes 5 to N are the message content field, which is used to carry the specific content of the message and is related to the specific message. Among them, bytes 5 to 6 are used to carry a parameter mask (called a parameter mask field), and the parameter mask field is used to indicate the parameters in the parameter set corresponding to the first message.For example, the parameter mask field is used to indicate which parameters in a parameter set need to be requested, configured, or reported. It should be noted that since the parameter mask is 16 bits (i.e., 2 bytes), a parameter set can contain up to 16 parameters, and each parameter set message type can carry up to 16 parameters. Furthermore, bytes 7 through N carry the parameter content of the parameters indicated by the parameter mask. The parameter content should be entered into the message in the order indicated by the parameter mask. For downlink request messages, the parameter mask indicates the parameters the master device wants to obtain. For uplink messages, the parameter mask indicates the parameters to be reported and replied to. N is an integer greater than 7. Bytes (N+1) through (N+4) are the message integrity check field, 4 bytes in size, used to verify the sender's identity and prevent forged WMCI message attacks. This field functions in accordance with the cyclic redundancy check (CRC) function.

[0233] In this example, the parameter mask field carries ninth and tenth indication information. The ninth indication information corresponds to a certain bit in the parameter mask field, and the tenth indication information corresponds to another bit in the parameter mask field. The position of the ninth indication information in the parameter mask field is related to the order of the authentication encryption mode parameters of the slave device in the device capability parameter set, and the position of the tenth indication information in the parameter mask field is related to the order of the frequency band parameters of the slave device in the device capability parameter set. For ease of understanding, the following will be introduced with specific examples:

[0234] In one example, a device capability parameter set of a WLAN of a slave device includes parameters related to the WLAN capability of the slave device. For example, WMCI version number (WMCI Version), WMCI feature (WMCI feature), IEEE 802.11 version number (IEEE 802.11Version), supported security modes (Security Modes Supported) (i.e., supported authentication and encryption modes), number of frequency bands (Number of Frequency bands), capability of the frequency band (Capability of the Frequency band), etc. Among them, the capability of the frequency band includes: band number (Band No.), frequency band (Frequency band), number of supported service set identifiers (SSIDs), supported transmission power level (Supported transmission power level), number of antennas (Supported transmission power level), and channel width (Frequency bandwidth), etc.

[0235] Exemplarily, the meanings of the parameters included in the device capability parameter set of the slave device WLAN are shown in Table 3 below:

[0236] Table 3

[0237]

[0238]

[0239] It should be noted that the order of the authentication and encryption modes included in the supported authentication and encryption mode parameters listed in sequence number 4 in Table 3 is used as an example for introduction. For example, if the supported authentication and encryption mode parameter set includes None, WEP-64, WEP-128, WPA-Personal, WPA2-Personal, WPA-WPA2-Personal, WPA3-SAE, WPA2-WPA3-PSK-SAE, WPA-Enterprise, WPA2-Enterprise, WPA-WPA2-Enterprise, and WPA3-Enterprise, then the bit map of the supported authentication and encryption modes in Table 2-2 may include: Bit0: whether to support authentication and encryption; Bit1: whether to support WEP-64; B Bit2: Whether WEP-128 is supported; Bit3: Whether WPA-Personal is supported; Bit4: Whether WPA2-Personal is supported; Bit5: Whether WPA-WPA2-Personal is supported; Bit6: Whether WPA3-SAE is supported; Bit7: Whether WPA2-WPA3-PSK-SAE is supported; Bit8: Whether WPA-Enterprise is supported; Bit9: Whether WPA2-Enterprise is supported; Bit10: Whether WPA-WPA2-Enterprise is supported; Bit11: Whether WPA3-Enterprise is supported. As the specific methods included in the supported authentication and encryption modes change, or the order of the parameters included in the supported authentication and encryption modes changes, other bitmap examples may be possible and are not listed here.

[0240] For example, if the supported authentication encryption modes adopt the order shown in Table 3, an example of the first message may be shown in Table 2-2 below:

[0241] Table 2-2

[0242]

[0243]

[0244] In the first message shown in Table 2-2, the message type identifier field carries the seventh indication information, indicating that the first message is used to carry parameters from the device capability parameter set of the device WLAN. In the message length and processing requirement fields, bit 7 is set to 0, indicating that the first message in uplink transmission is used to report parameters. Bit A in the parameter mask field (i.e., bit 5 of the fifth byte) is the ninth indication information. Bit A is set to 1, indicating that the first message carries the supported authentication encryption mode parameters from the device capability parameter set of the device WLAN. Bit B in the parameter mask field (i.e., bit 3 of the fifth byte) is the tenth indication information. Bit B is set to 1, indicating that the first message carries the supported frequency band parameters from the device capability parameter set of the device WLAN. In addition, in the parameter content field, two bytes (e.g., bytes 7 to 8) carry the first indication information, indicating the specific authentication encryption mode supported by the device, represented by a bitmap. A bit set to 1 indicates support for the authentication encryption mode, and a bit set to 0 indicates non-support of the authentication encryption mode. For example, if the slave device supports "WEP-64" and "WEP-128," only bits 1 and 2 of bytes 7 to 8 are set to 1, and the remaining bits are set to 0. Another byte of the parameter content field (e.g., byte 9) carries third indication information, indicating a frequency band supported by the slave device, i.e., the frequency band used when the slave device supports the aforementioned authentication and encryption modes (e.g., "WEP-64" and "WEP-128"). For example, if the value of byte 9 is 0, it means that the slave device supports 2.4 GHz. The content carried by the first message indicates that when the slave device operates at 2.4 GHz, it supports the two authentication and encryption modes "WEP-64" and "WEP-128," and does not support other authentication and encryption modes. For another example, if the value of byte 9 is 1, it means that the slave device supports 5 GHz. The content carried by the first message indicates that when the slave device operates at 5 GHz, it supports the two authentication and encryption modes "WEP-64" and "WEP-128," and does not support other authentication and encryption modes. The same applies to the remaining frequency bands, and examples are not listed here one by one. For explanations of the remaining fields in the example shown in Table 2-2, refer to the description of the example shown in Table 2-1 above and are not repeated here.

[0245] In this embodiment, the slave device reports the authentication and encryption modes supported by a particular frequency band to the master device via a message (e.g., a first message). This facilitates the master device to learn the authentication and encryption capabilities of the slave device when operating in a particular frequency band, and further facilitates the master device to configure an authentication and encryption mode suitable for the operating frequency band for the slave device, thereby achieving frequency band-based on-demand protection. Furthermore, this reduces the probability of the master device configuring an inappropriate authentication and encryption mode, thereby improving the security of both the slave device and the terminal device.

[0246] In a possible implementation, the second message is a message for configuring operating parameters of the slave device, that is, configuring parameters in a working parameter configuration parameter set of the slave device. The authentication encryption mode of the slave device and the frequency band of the slave device are parameters in the working parameter configuration parameter set of the WLAN of the slave device.

[0247] Optionally, in addition to the second indication information and the third indication information, the second message also includes eighth indication information, where the eighth indication information is used to indicate a working parameter configuration parameter set of the WLAN of the slave device, and the working parameter configuration parameter set of the WLAN of the slave device includes an authentication encryption mode parameter of the slave device and a frequency band parameter of the slave device.

[0248] Optionally, the eighth indication information is located in the message type identifier field of the second message.

[0249] Optionally, the message content field of the second message also includes a parameter mask field, and the parameter mask field includes ninth indication information and tenth indication information. The ninth indication information is used to indicate authentication and encryption mode parameters of the slave device, i.e., the ninth indication information indicates that the second message carries parameters related to the authentication and encryption mode of the slave device. The tenth indication information is used to indicate frequency band parameters of the slave device, i.e., the tenth indication information indicates that the second message carries parameters related to the frequency band of the slave device.

[0250] Optionally, the message content field of the second message further includes second indication information and third indication information. For explanations of the second indication information and the third indication information, please refer to the relevant introduction in the above steps 201 and 202, which will not be repeated here.

[0251] For example, the following Table 4-1 is an example of the second message.

[0252] Table 4-1

[0253]

[0254] As shown in Table 4-1, the first byte is the message type identifier field, which indicates the message type and defines the semantics of the message content. The message type identifier field can carry the eighth indicator, indicating that the message type is a message related to an operating parameter configuration parameter set. The second byte is the sequence number (SeqNo) field. Bytes 3 to 4 are the message length and processing requirement field, which consists of three fields: the message priority (i.e., the message processing requirement), the operation type, and the length of the message content. For details, please refer to the description of the example shown in Table 2-1 above; this description is not repeated here. Furthermore, bytes 5 to N are the message content field, which carries the specific message content. Bytes 5 to 6 carry the parameter mask (referred to as the parameter mask field), which indicates the parameters in the parameter set corresponding to the first message. Bytes 7 to N carry the parameter content of the parameters indicated by the parameter mask. The parameter content should be entered into the message content in the order indicated by the parameter mask. For downlink request messages, the parameter mask indicates the parameters the master device wants to obtain. For uplink messages, the parameter mask indicates the parameters reported and replied to. N is an integer greater than 7. Bytes (N+1) to (N+4) are the message integrity check fields.

[0255] In this example, the parameter mask field carries ninth and tenth indication information. The ninth indication information corresponds to a certain bit in the parameter mask field, and the tenth indication information corresponds to another bit in the parameter mask field. The position of the ninth indication information in the parameter mask field is related to the order of the authentication and encryption mode parameters of the slave device in the working parameter configuration parameter set, and the position of the tenth indication information in the parameter mask field is related to the order of the frequency band parameters of the slave device in the working parameter configuration parameter set. For ease of understanding, the following will be introduced with specific examples:

[0256] In one example, a WLAN operating parameter configuration parameter set of a slave device includes parameters related to the WLAN operating parameter configuration of the slave device, such as frequency band number, SSID length, SSID, password length, password, security mode, frequency band selection, frequency channel, channel width, and transmission power level.

[0257] For example, the meanings of the parameters included in the WLAN operating parameter configuration parameter set of the slave device are shown in Table 5-1 or Table 5-2 below:

[0258] Table 5-1

[0259]

[0260]

[0261] In the example shown in Table 5-1, the security mode of the slave device (that is, the authentication encryption mode used by the slave device) is defined in the form of a bitmap.

[0262] Table 5-2

[0263]

[0264]

[0265] In the example shown in Table 5-2, the security mode of the slave device (that is, the authentication and encryption mode used by the slave device) is defined in the form of an enumeration value.

[0266] For example, if the supported authentication encryption modes are in the order shown in Table 5-1, and the security mode of the slave device (i.e., the authentication encryption mode used by the slave device) is defined in the form of a bitmap, an example of the second message may be as shown in Table 4-2 below:

[0267] Table 4-2

[0268]

[0269]

[0270] In the second message shown in Table 4-2, the Message Type Identifier field carries eighth indication information, indicating that the second message carries parameters from the slave device's WLAN operating parameter configuration parameter set. In the Message Length and Processing Requirements field, bit 7 is set to 0, indicating that the second message in downlink transmission is used to configure parameters for the slave device. Bit E in the Parameter Mask field (i.e., bit 3 of the fifth byte) carries ninth indication information. Bit E is set to 1, indicating that the second message carries the authentication and encryption mode parameters used in the slave device's WLAN operating parameter configuration parameter set. Bit F in the Parameter Mask field (i.e., bit 2 of the fifth byte) carries tenth indication information. Bit F is set to 1, indicating that the second message carries the frequency band parameters used in the slave device's WLAN operating parameter configuration parameter set. Furthermore, in the Parameter Content field, two bytes (e.g., bytes 7-8) carry second indication information, indicating an authentication and encryption mode configured by the master device for the slave device (e.g., the first authentication and encryption mode described above). This is represented by a bitmap, as shown in field 6 of Table 5-1. A bit set to 1 indicates that the authentication and encryption mode is used or configured, while a bit set to 0 indicates that the authentication and encryption mode is not used or configured. For example, if the master device configures "WEP-128" for the slave device, only bit 2 in bytes 7 to 8 is set to 1, and the remaining bits are set to 0. Another byte of the parameter content field (for example, byte 9) carries third indication information, indicating a frequency band used by the slave device, that is, the frequency band used when the slave device uses the aforementioned authentication and encryption mode (for example, "WEP-128"). For example, if the value of byte 9 is 0, it means that the slave device uses 2.4GHz. The content carried by the second message indicates that when the master device configures the slave device to operate at 2.4GHz, it uses the "WEP-128" authentication and encryption mode and does not use other authentication and encryption modes. For another example, if the value of byte 9 is 1, it means that the slave device uses 5GHz. The content carried by the second message indicates that when the master device configures the slave device to operate at 5GHz, it uses the "WEP-128" authentication and encryption mode and does not use other authentication and encryption modes. The same applies to the remaining frequency bands, and examples are not listed here one by one. For explanations of the remaining fields in the example shown in Table 4-2, refer to the relevant introductions to Table 2-1, Table 2-2, or the example shown in Table 4-1 above and are not repeated here.

[0271] For example, if the supported authentication encryption modes are in the order shown in Table 5-2, and the security mode of the slave device (i.e., the authentication encryption mode used by the slave device) is defined in the form of an enumerated value, then an example of the second message can be shown in Table 4-3 below:

[0272] Table 4-3

[0273]

[0274]

[0275] The difference between the example shown in Table 4-3 and the example shown in Table 4-2 lies in the parameter content field. In the parameter content field, two bytes (e.g., bytes 7-8) carry second indication information, indicating the authentication and encryption mode configured by the master for the slave (e.g., the first authentication and encryption mode described above). This information is represented by an enumerated value. As shown in the sixth field of Table 5-2, a byte value of 0 indicates "None," meaning no authentication and encryption; a byte value of 1 indicates "WEP-64"; a byte value of 2 indicates "WEP-128," and so on. For example, if the master configures "WEP-128" for the slave, the values ​​of bytes 7-8 are 2. Another byte (e.g., byte 9) in the parameter content field carries third indication information, indicating the frequency band used by the slave, namely, the frequency band used when the slave uses the aforementioned authentication and encryption mode (e.g., "WEP-128"). For example, if the value of Byte 9 is 0, indicating that the slave device is operating at 2.4 GHz, the second message carries the message indicating that the master device is configuring the slave device to use WEP-128 authentication and encryption mode when operating at 2.4 GHz, and not to use other authentication and encryption modes. For another example, if the value of Byte 9 is 1, indicating that the slave device is operating at 5 GHz, the second message carries the message indicating that the master device is configuring the slave device to use WEP-128 authentication and encryption mode when operating at 5 GHz, and not to use other authentication and encryption modes. The same applies to other frequency bands, and examples are not listed here. For explanations of the remaining fields in the example shown in Table 4-3, refer to the descriptions of the examples shown in Table 2-1, Table 2-2, Table 4-1, or Table 4-2 above, and are not detailed here.

[0276] In this implementation, the master device can configure a slave device with an authentication and encryption mode specifically for a specific frequency band. This facilitates the master device configuring a slave device with an authentication and encryption mode suitable for that frequency band, enabling on-demand protection based on the frequency band. Furthermore, this reduces the likelihood of the master device configuring an inappropriate authentication and encryption mode, thereby improving the security of both the slave and terminal devices.

[0277] The parameters in Table 3 (e.g., WMCI version number, WMCI feature parameter set, IEEE 802.11 version number, supported security modes, number of frequency bands, frequency band sequence number, frequency band, number of supported SSIDs, supported transmit power, level, number of antennas, channel width, and capabilities of another frequency band), as well as the parameters in Tables 5-1 and 5-2 (e.g., frequency band sequence number, SSID length, SSID, password length, password, security mode, frequency band selection, frequency domain channel, channel width, and transmit power level), can be represented in messages in other formats besides the masked format shown in byte 5-N in Table 2-1. For example, one or more of these parameters can be represented in a message using a type-length-value (TLV) format. Each TLV can carry one or more parameters. If a TLV carries multiple parameters, these parameters can be used as the "value" of the TLV, or multiple parameters can be carried as sub-TLVs. For example, the "value" of a TLV may include two parameters: Password and Password length, or the TLV may include at least two sub-TLVs, the "value" of one sub-TLV includes Password, and the "value" of another sub-TLV includes Password length.

[0278] In addition, each parameter can be carried by one message or by multiple messages. If a parameter is carried by multiple different messages, the parameter can be an optional parameter in one or some messages and a mandatory parameter in another or some messages.

[0279] If the above parameters are expressed in TLV form, the format of the WMCI message can be as shown in Table 5 below:

[0280] Table 5

[0281]

[0282]

[0283] like Figure 3As shown, it is a flow chart of another embodiment of the optical network communication method provided by the present application. In this embodiment, the interaction between the master device and the first slave device and the second slave device is taken as an example for explanation. When some of the slave devices managed by the master device (for example, the second slave device) go offline, the master device will determine whether to update the authentication encryption mode used by the remaining slave devices (for example, the first slave device) based on the authentication encryption capabilities of the remaining slave devices (for example, the first slave device). Of course, the subject that executes the actions of the master device in this method can also be a device, module or chip in the master device; the subject that executes the actions of the slave device (for example, the first slave device or the second slave device) in this method can also be a device, module or chip in the slave device (for example, the first slave device or the second slave device), which is not specifically limited in this embodiment. For example, as Figure 3 As shown, the optical network communication method includes the following steps:

[0284] Step 301: A first slave device sends a first message 1 to a master device; correspondingly, the master device receives the first message 1 from the first slave device.

[0285] The first message 1 includes first indication information 1, and the first indication information 1 is used to indicate at least one authentication encryption mode supported by the first slave device, that is, to indicate the authentication encryption capability of the first slave device.

[0286] Optionally, the first message 1 further includes third indication information. For explanations of the first indication information and the third indication information, please refer to the relevant introduction in the above step 201, which will not be repeated here.

[0287] Step 302: The first slave device sends a first message 2 to the master device; correspondingly, the master device receives the first message 2 from the first slave device.

[0288] The first message 2 includes first indication information 2, and the first indication information 2 is used to indicate at least one authentication encryption mode supported by the second slave device, that is, to indicate the authentication encryption capability of the second slave device.

[0289] Optionally, the first message 2 also includes third indication information.

[0290] Step 303: The master device sends a second message 1 to the first slave device; correspondingly, the first slave device receives the second message 1 from the master device.

[0291] The second message 1 includes second indication information, and the second indication information is used to indicate the use of the first authentication encryption mode.

[0292] Optionally, the second message 1 further includes third indication information. For explanations of the second indication information and the third indication information, please refer to the relevant introductions in the above steps 201 and 202, which will not be repeated here.

[0293] Step 304: The master device sends a second message 2 to the second slave device; accordingly, the second slave device receives the second message 2 from the master device.

[0294] The second message 2 includes second indication information, and the second indication information is used to indicate the use of the first authentication encryption mode.

[0295] Optionally, the second message 2 also includes third indication information.

[0296] Step 305: The first slave device configures and activates the first authentication encryption mode.

[0297] For example, the first slave device obtains the second indication information from the second message 1 and configures the first authentication encryption mode to take effect based on the second indication information. The first slave device uses the first authentication encryption mode to perform identity authentication and key authentication on a terminal device that accesses the network through the first slave device, which is beneficial to improving the security of the terminal device.

[0298] Step 306: The second slave device configures and activates the first authentication encryption mode.

[0299] Step 307: The second slave device sends a offline notification message to the master device; correspondingly, the master device receives the offline notification message from the second slave device.

[0300] In this embodiment, step 307 is an optional step.

[0301] In one implementation, when the second slave device executes step 307 , the master device can receive a logoff notification message from the second slave device, and learns that the second slave device is about to go offline based on the logoff notification message.

[0302] In another implementation, the master device can periodically detect the optical power of the optical signal at the port corresponding to the second slave device. When the master device cannot detect the optical signal at the port corresponding to the second slave device, or the optical power of the detected optical signal is less than a preset value, the master device determines that the second slave device has gone offline or is about to go offline.

[0303] After the master device determines that the second slave device is offline, the master device may re-determine the authentication encryption mode used by the remaining slave devices (e.g., the first slave device). For example, the master device determines the second authentication encryption mode based on at least one authentication encryption mode supported by the first slave device and at least one authentication encryption mode supported by the master device, where the second authentication encryption mode is an authentication encryption mode supported by both the first slave device and the master device. Optionally, the second authentication encryption mode is an authentication encryption mode supported by both the first slave device and the master device.

[0304] If the second authenticated encryption mode re-determined by the master device is different from the first authenticated encryption mode, that is, the master device determines that the first slave device is more suitable for using the second authenticated encryption mode rather than the first authenticated encryption mode, the master device will execute step 308 and the first slave device will execute step 309. If the master device finds that the first slave device is still suitable for using the first authenticated encryption mode after re-determining the authentication mode, the master device will not execute step 308 and the first slave device will not execute step 309.

[0305] Step 308: The master device sends a third message to the first slave device; correspondingly, the first slave device receives the third message from the master device.

[0306] Among them, the third message includes fourth indication information, and the fourth indication information is used to instruct the first slave device to use the second authentication encryption mode. The second authentication encryption mode is an authentication encryption mode supported by the first slave device, and the second authentication encryption mode is different from the first authentication encryption mode.

[0307] Optionally, the third message further includes third indication information. The fourth indication information is further used to instruct the first slave device to use the second authentication encryption mode when operating in the first frequency band.

[0308] Step 309: The first slave device configures and activates the second authentication encryption mode.

[0309] In this embodiment, when a second slave device goes offline, the master device no longer considers the authentication and encryption capabilities of the second slave device. Instead, it determines whether to update the authentication and encryption mode used by the slave device based solely on the authentication and encryption capabilities of the first slave device (and the master device). This facilitates instant configuration of the appropriate authentication and encryption mode for the slave device, improving system security.

[0310] like Figure 4 As shown, it is a flow chart of another embodiment of the optical network communication method provided by the present application. In this embodiment, the interaction between the master device and the first slave device, the second slave device and the third slave device is taken as an example for explanation. When the master device detects a newly online slave device (for example, the third slave device), the master device will determine whether to update the authentication encryption mode used by each slave device based on the authentication encryption capabilities of the existing slave devices (for example, the first slave device and the second slave device) and the newly online slave device (for example, the third slave device). Of course, the subject that executes the action of the master device in this method can also be a device, module or chip in the master device; the subject that executes the action of the slave device (for example, the first slave device, the second slave device or the third slave device) in this method can also be a device, module or chip in the slave device (for example, the first slave device, the second slave device or the third slave device), and this embodiment does not make specific limitations on this. For example, as Figure 4 As shown, the optical network communication method includes the following steps:

[0311] Step 401: A first slave device sends a first message 1 to a master device; correspondingly, the master device receives the first message 1 from the first slave device.

[0312] Step 402: The first slave device sends a first message 2 to the master device; accordingly, the master device receives the first message 2 from the first slave device.

[0313] Step 403: The master device sends a second message 1 to the first slave device; correspondingly, the first slave device receives the second message 1 from the master device.

[0314] Step 404: The master device sends a second message 2 to the second slave device; accordingly, the second slave device receives the second message 2 from the master device.

[0315] Step 405: The first slave device configures and activates the first authentication encryption mode.

[0316] Step 406: The second slave device configures and activates the first authentication encryption mode.

[0317] In this embodiment, steps 401 to 406 are the same as those in the previous Figure 3 Steps 301 to 306 in the corresponding embodiment are similar. Please refer to the relevant introduction in the above steps 301 to 306 for details, which will not be repeated here.

[0318] Step 407: The third slave device sends a fourth message to the master device; accordingly, the master device receives the fourth message from the third slave device.

[0319] The fourth message may be an online notification message, or may be a response message corresponding to the capability reporting request sent by the master device.

[0320] The fourth message includes fifth indication information, where the fifth indication information is used to indicate at least one authentication encryption mode supported by the third slave device;

[0321] Optionally, the master device determines a third authenticated encryption mode based on at least one authenticated encryption mode supported by the first slave device, at least one authenticated encryption mode supported by the second slave device, at least one authenticated encryption mode supported by the third slave device, and at least one authenticated encryption mode supported by the master device, where the third authenticated encryption mode is an authenticated encryption mode supported by the first slave device, the second slave device, the third slave device, and the master device;

[0322] The master device sends a fifth message to the first slave device, the second slave device, and the third slave device, respectively, as shown in steps 408 , 409 , and 410 .

[0323] Step 408: The master device sends a fifth message 1 to the first slave device; accordingly, the first slave device receives the fifth message 1 from the master device.

[0324] Step 409 : The master device sends a fifth message 2 to the second slave device; correspondingly, the second slave device receives the fifth message 2 from the master device.

[0325] In step 410 , the master device sends a fifth message 3 to the third slave device; accordingly, the third slave device receives the fifth message 3 from the master device.

[0326] Among them, the fifth message includes sixth indication information, and the sixth indication information is used to indicate the use of the third authentication encryption mode. The third authentication encryption mode is an authentication encryption mode supported by the first slave device, the second slave device and the third slave device. The third authentication encryption mode is different from the first authentication encryption mode.

[0327] Optionally, the fifth message further includes third indication information. The sixth indication information is further used to instruct the slave device to use the third authentication encryption mode when operating in the first frequency band.

[0328] Step 411: The first slave device configures and activates the third authentication encryption mode.

[0329] Step 412: The second slave device configures and activates the third authentication encryption mode.

[0330] Step 413: The third slave device configures and activates the third authentication encryption mode.

[0331] In this embodiment, when the third slave device comes online, the master device determines whether to update the authentication and encryption mode based on the authentication and encryption capabilities of the first, second, and third slave devices (and the master device). This helps to timely configure the appropriate authentication and encryption mode for the slave device and improve system security.

[0332] It should also be noted that the master and slave devices exchange the previously described messages (e.g., the first message, the second message, the third message, the fourth message, the fifth message, etc.) via the WMCI management channel. The second message is used as an example for explanation; the remaining messages are similar to the first message. The slave device sends the first message to the master device via the WMCI management channel; correspondingly, the master device receives the first message from the slave device via the WMCI management channel. A management channel refers to a logical channel established between the master and slave devices for message transmission. A WMCI management channel is a logical channel established between the master and slave devices for transmitting WMCI messages. Generally, different management channels correspond to different logical port identifiers (port IDs). Different logical port identifiers may correspond to the same physical transceiver port or to different physical transceiver ports, without limitation. For example, the first management channel corresponds to Port ID1 of the master device and Port ID1 of the first slave device, while other management channels correspond to Port ID2 of the master device and Port ID2 of the first slave device. Port ID1 and Port ID2 may correspond to the same physical transceiver port or to different physical transceiver ports.

[0333] In addition, if Figure 5A As shown, if the master device's rate level is 2.5G, the first message is encapsulated in the payload field of an FTTR Encapsulation Method (FEM) frame. The FEM port ID in the FEM frame header is assigned by the master device. This FEM port ID not only indicates that the first message is a WMCI message, but also indicates the recipient of the WMCI message (i.e., the first message), that is, the WMCI message (i.e., the first message) is for the first slave device rather than other slave devices. Therefore, the FEM port ID can be used to distinguish WMCI messages from other control messages in the FTTR system (e.g., FMCI messages or OMCI messages). It should be noted that when the master device's rate level is 2.5G, the master device's downlink rate is 2.48832 Gbit / s; the master device's uplink rate can be 1.24416 Gbit / s, 2.48832 Gbit / s, or both. The slave device's downlink rate is 2.48832 Gbit / s, and the uplink rate is either 1.24416 Gbit / s or 2.48832 Gbit / s. It should be noted that the FEM frame's payload length, L, is equal to the WMCI message length, L, where L is an integer greater than 0.

[0334] In addition, if Figure 5BAs shown, if the master device's rate level is 10G, the first message is encapsulated in the payload field of a 10G-FTTR encapsulation method (XFEM) frame. The XFEM port ID in the frame header of the XFEM frame is assigned by the master device. The XFEM port ID not only indicates that the first message is a WMCI message, but also indicates the sender and receiver of the WMCI message (i.e., the first message), that is, the WMCI message (i.e., the first message) corresponds to the first slave device rather than other slave devices. Therefore, the XFEM port ID can be used to distinguish WMCI messages from other control messages in the FTTR system. It should be noted that when the master device's rate level is 10G, the master device's downlink rate is 9.95328 Gbit / s; the master device's uplink rate can be 9.95328 Gbit / s, 2.48832 Gbit / s, or both. The slave device's downlink rate is 9.95328 Gbit / s, and the uplink rate is either 9.95328 Gbit / s or 2.48832 Gbit / s. It should be noted that the XFEM frame's payload length, P, is an integer multiple of 4 bytes, but the length of a WMCI message may not be an integer multiple of 4 bytes. Therefore, the XFEM payload carrying the WMCI message may require a padding field of 0 to 3 bytes.

[0335] In addition, if Figure 5C As shown in FIG, the FEM frame is encapsulated in the payload field of the data link layer (DLL) frame. Figure 5D As shown, the XFEM frame is encapsulated in the payload field of the DLL frame. The DLL frame consists of a DLL frame header and a DLL frame payload. The DLL payload is formed on the transmitting side and processed by the service adaptation sublayer on the receiving side. The DLL frame header consists of three fixed-size partitions (i.e., PLOAMd, BIP, and Plend) and one variable-size partition: the bandwidth map partition (BWmap). A bandwidth map (BWmap) is used to indicate the uplink transmission position of different slave devices in their corresponding uplink physical frame (PHY frame).

[0336] It should be noted that in Figure 5C In the example shown, the payload of the DLL frame only includes 3 FEM frames. In actual applications, the payload of the DLL frame can include other numbers of FEM frames, which is not limited here. Figure 5D In the example shown, the payload of the DLL frame includes three XFEM frames. In actual applications, the payload of the DLL frame may include other numbers of XFEM frames, which is not limited here.

[0337] In addition, the embodiment of the present application further provides a communication device 60, such as Figure 6 As shown, Figure 6 A schematic structural diagram of a communication device 60 provided in an embodiment of the present application. Figure 2A 、 Figure 3 or Figure 4 The specific implementation of the master device and slave device in the flowchart shown can refer to Figure 6 The internal structure of the communication device 60 is shown. Figure 2A 、 Figure 3 or Figure 4 When the communication device 60 is used to implement the function of the master device in the method shown, the communication device 60 can be a master gateway or MFU. Figure 2A 、 Figure 3 or Figure 4 When the communication device 60 functions as a slave device in the method shown, the communication device 60 may be a slave gateway or an SFU.

[0338] like Figure 6 As shown, the communication device 60 may include a processor 601 and a transceiver 602, wherein the processor 601 is coupled to the transceiver 602. The processor 601 may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The PLD may be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. The processor 601 may refer to a single processor or may include multiple processors, which is not specifically limited here.

[0339] The transceiver 602 may also be referred to as a transceiver unit, a transceiver, a transceiver device, etc. Optionally, a device in the transceiver unit that implements a receiving function may be referred to as a receiving unit, and a device in the transceiver unit that implements a transmitting function may be referred to as a transmitting unit. That is, the transceiver unit includes a receiving unit and a transmitting unit. The receiving unit may also be referred to as a receiver, an input port, a receiving circuit, etc., and the transmitting unit may be referred to as a transmitter, a transmitter, or a transmitting circuit, etc.

[0340] Optionally, the communication device 60 further includes a memory 603. The processor 601 is coupled to the memory 603. The memory 603 is mainly used to store software programs and data. The memory 603 may exist independently and be connected to the processor 601. Optionally, the memory 603 may be integrated with the processor 601, for example, integrated into one or more chips. The memory 603 can store program codes for executing the technical solutions of the embodiments of the present application, and is controlled by the processor 601 for execution. The various types of computer program codes executed can also be regarded as drivers for the processor 601. The memory 603 may include volatile memory, such as random-access memory (RAM); the memory may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD) or solid-state drive (SSD); the memory 603 may also include a combination of the above types of memory. The memory 603 may refer to a single memory or may include multiple memories. Exemplarily, the memory 603 is used to store various data.

[0341] In one implementation, the communication device 60 is used to implement Figure 2A Functions of the master device in the corresponding method embodiment. Specifically, the transceiver 602 is configured to receive at least one first message, the at least one first message being from at least one slave device, the first message including first indication information, the first indication information being used to indicate at least one authentication encryption mode supported by the corresponding slave device; the processor 601 is configured to generate at least one second message; the transceiver 602 is further configured to send at least one second message, the at least one second message corresponding to at least one slave device, the second message including second indication information, the second indication information being used to instruct the corresponding slave device to use the first authentication encryption mode;

[0342] Among them, at least one authentication and encryption mode includes at least one of the following modes: 64-bit Wired Equivalent Privacy (WEP-64) mode; or 128-bit Wired Equivalent Privacy (WEP-128) mode; or user-oriented Wi-Fi Protected Access (WPA-Personal) mode; or WPA2-Personal mode; or WPA-WPA2-Personal mode; or WPA3-SAE; or WPA2-WPA3-PSK-SAE; or enterprise-oriented Wi-Fi Protected Access (WPA-Enterprise); or WPA2-Enterprise; or WPA-WPA2-Enterprise; or WPA3-Enterprise.

[0343] In a possible implementation, the first authentication encryption mode is an authentication encryption mode supported by at least one slave device.

[0344] In a possible implementation, the first authentication encryption mode is the same as the authentication encryption mode used by the master device.

[0345] In a possible implementation, the first message further includes third indication information, where the third indication information is used to indicate a first frequency band supported by the slave device, where the first frequency band is one of at least one frequency band supported by the slave device. Optionally, the second message further includes the third indication information.

[0346] In one possible implementation, the at least one slave device includes a first slave device and a second slave device;

[0347] The processor 601 is also used to control the transceiver 602 to send a third message to the first slave device after determining that the second slave device is offline. The third message includes fourth indication information. The fourth indication information is used to instruct the first slave device to use a second authentication encryption mode. The second authentication encryption mode is an authentication encryption mode supported by the first slave device, and the second authentication encryption mode is different from the first authentication encryption mode.

[0348] In one possible implementation, the at least one slave device includes a first slave device and a second slave device;

[0349] The transceiver 602 is also used to receive a fourth message from the third slave device, the fourth message includes fifth indication information, and the fifth indication information is used to indicate at least one authentication encryption mode supported by the third slave device; the processor 601 is also used to generate a fifth message and control the transceiver 602 to send the fifth message to the first slave device, the second slave device and the third slave device respectively, the fifth message includes sixth indication information, and the sixth indication information is used to indicate the use of the third authentication encryption mode, the third authentication encryption mode is an authentication encryption mode supported by the first slave device, the second slave device and the third slave device, and the third authentication encryption mode is different from the first authentication encryption mode.

[0350] In a possible implementation manner, the third message further includes third indication information; and / or the fifth message further includes third indication information.

[0351] In a possible implementation, the first message is a wireless local area network management control interface WMCI message, and the second message is a WMCI message.

[0352] In one possible implementation, the first message further includes seventh indication information, where the seventh indication information is used to indicate a WLAN device capability parameter set of the slave device, where the WLAN device capability parameter set of the slave device includes an authentication encryption mode parameter of the slave device and a frequency band parameter of the slave device. Optionally, the seventh indication information is located in a message type identifier field of the first message.

[0353] In one possible implementation, the second message further includes eighth indication information, where the eighth indication information is used to indicate a WLAN operating parameter configuration parameter set of the slave device, where the WLAN operating parameter configuration parameter set of the slave device includes an authentication and encryption mode parameter of the slave device and a frequency band parameter of the slave device. Optionally, the eighth indication information is located in a message type identifier field of the second message.

[0354] In one possible embodiment, the message content field of the first message also includes a parameter mask field, and the message content field of the second message also includes a parameter mask field, the parameter mask field includes ninth indication information and tenth indication information, the ninth indication information is used to indicate the authentication encryption mode parameters of the slave device, and the tenth indication information is used to indicate the frequency band parameters of the slave device.

[0355] In a possible implementation, the message content field of the first message further includes first indication information and third indication information; the message content field of the second message further includes second indication information and third indication information.

[0356] In one possible implementation, the first message is encapsulated in a payload field of a fiber-to-the-room encapsulation mode FEM frame, and the FEM port identifier in the FEM frame header is used to indicate that the first message corresponds to a slave device. Optionally, the FEM frame is encapsulated in a payload field of a data link layer DLL frame.

[0357] In another implementation, the communication device 60 is used to implement Figure 2A The function of the slave device in the corresponding method embodiment. Specifically, the processor 601 is used to generate a first message; the transceiver 602 is used to send the first message to the master device, the first message including first indication information, the first indication information being used to indicate at least one authenticated encryption mode supported by the slave device; the transceiver 602 is further used to receive a second message from the master device, the second message including second indication information, the second indication information being used to instruct the slave device to use a first authenticated encryption mode, the first authenticated encryption mode being one of the at least one authenticated encryption mode supported by the slave device;

[0358] The at least one authentication encryption mode includes at least one of the following modes:

[0359] WEP-64 mode; or WEP-128 mode; or Wi-Fi Protected Access (WPA-Personal) mode for consumers; or WPA2-Personal mode; or WPA-WPA2-Personal mode; or WPA3-SAE; or WPA2-WPA3-PSK-SAE; or Wi-Fi Protected Access (WPA-Enterprise) for enterprises; or WPA2-Enterprise; or WPA-WPA2-Enterprise; or WPA3-Enterprise.

[0360] In a possible implementation, the first authentication encryption mode is the same as the authentication encryption mode used by the master device.

[0361] In a possible implementation, the first message further includes third indication information, where the third indication information is used to indicate a first frequency band supported by the slave device, where the first frequency band is one of at least one frequency band supported by the slave device. Optionally, the second message further includes the third indication information.

[0362] In a possible implementation, the first message is a wireless local area network management control interface WMCI message, and the second message is a WMCI message.

[0363] In one possible implementation, the first message further includes seventh indication information, where the seventh indication information is used to indicate a WLAN device capability parameter set of the slave device, where the WLAN device capability parameter set of the slave device includes an authentication encryption mode parameter of the slave device and a frequency band parameter of the slave device. Optionally, the seventh indication information is located in a message type identifier field of the first message.

[0364] In one possible implementation, the second message further includes eighth indication information, where the eighth indication information is used to indicate a WLAN operating parameter configuration parameter set of the slave device, where the WLAN operating parameter configuration parameter set of the slave device includes an authentication and encryption mode parameter of the slave device and a frequency band parameter of the slave device. Optionally, the eighth indication information is located in a message type identifier field of the second message.

[0365] In one possible embodiment, the message content field of the first message also includes a parameter mask field, and the message content field of the second message also includes a parameter mask field, the parameter mask field includes ninth indication information and tenth indication information, the ninth indication information is used to indicate the authentication encryption mode parameters of the slave device, and the tenth indication information is used to indicate the frequency band parameters of the slave device.

[0366] In a possible implementation, the message content field of the first message further includes first indication information and third indication information; the message content field of the second message further includes second indication information and third indication information.

[0367] In one possible implementation, the first message is encapsulated in the payload field of a fiber-to-the-room encapsulation mode FEM frame, and the FEM port identifier in the FEM frame header is used to indicate the slave device corresponding to the first message. Optionally, the FEM frame is encapsulated in the payload field of a data link layer DLL frame.

[0368] Please refer to the previous article for details Figure 2A 、 Figure 3 or Figure 4 The relevant descriptions in the corresponding embodiments are not repeated here.

[0369] like Figure 7 As shown, the present application further provides a communication device 70. The communication device 70 can be a slave device or a master device, or a component of a slave device or a master device (e.g., an integrated circuit, a chip, etc.). The communication device 70 can also be other communication modules for implementing the method in the method embodiment of the present application.

[0370] The communication device 70 may include a processing module 701 (or processing unit). Optionally, it may also include an interface module 702 (or transceiver unit or transceiver module) and a storage module 703 (or storage unit). The interface module 702 is used to implement communication with other devices. The interface module 702 may be, for example, a transceiver module or an input / output module.

[0371] In one possible design, Figure 7 One or more modules may be implemented by one or more processors, or by one or more processors and memories, or by one or more processors and transceivers, or by one or more processors, memories, and transceivers, and this is not limited in the present application. The processors, memories, and transceivers may be provided separately or integrated.

[0372] The communication device 70 has the function of implementing the slave device described in the embodiment of the present application. For example, the communication device 70 includes a module or unit or means (means) corresponding to the slave device step described in the embodiment of the present application. The function or unit or means (means) can be implemented by software, or by hardware, or by hardware executing the corresponding software implementation, or by a combination of software and hardware. For details, please refer to the corresponding description in the aforementioned corresponding method embodiment. Please refer to the above for details. Figure 6 This corresponds to the communication device 60 in the embodiment.

[0373] Alternatively, the communication device 70 has the function of implementing the main device described in the embodiment of the present application. For example, the communication device 70 includes a module or unit or means (means) corresponding to the main device step described in the embodiment of the present application for the main device to execute. The function or unit or means (means) can be implemented by software, or by hardware, or by hardware executing the corresponding software implementation, or by a combination of software and hardware. For details, please refer to the corresponding description in the aforementioned corresponding method embodiment. Please refer to the above for details. Figure 6 This corresponds to the communication device 60 in the embodiment.

[0374] In addition, the present application provides a computer program product, which includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function according to the embodiment of the present application is generated in whole or in part. For example, the aforementioned Figure 2A 、 Figure 3 or Figure 4 For example, the method related to the slave device is implemented as described above. Figure 2A 、 Figure 3 or Figure 4Methods related to the main device in the computer. The computer can be a general-purpose computer, a special-purpose computer, a computer network or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center by wired (for example, coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (for example, infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can store or a data storage device such as a server or data center that includes one or more available media integrated. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a digital versatile disc (DVD)), or a semiconductor medium (for example, a solid state disk (SSD)), etc.

[0375] In addition, the present application also provides a computer-readable storage medium, which stores a computer program, which is executed by a processor to implement the above Figure 2A 、 Figure 3 or Figure 4 Slave device related methods in .

[0376] In addition, the present application also provides a computer-readable storage medium, which stores a computer program, which is executed by a processor to implement the above Figure 2A 、 Figure 3 or Figure 4 Methods related to the master device in.

[0377] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0378] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. An optical network communication method, wherein the optical network comprises a master device and at least one slave device, wherein the at least one slave device comprises a first slave device, characterized in that: include: The first slave device sends a first message to the master device, where the first message includes first indication information, where the first indication information indicates, in bitmap form, whether the first slave device supports each of the multiple security modes, where each security mode corresponds to a first bit, and a value of the first bit indicates whether the first slave device supports the security mode corresponding to the first bit; The multiple security modes include: Wi-Fi Protected Access WPA-Personal mode for users; WPA2-Personal mode; WPA-WPA2-Personal mode; WPA3-SAE; WPA2-WPA3-PSK-SAE; Wi-Fi Protected Access WPA-Enterprise for enterprises; WPA2-Enterprise; WPA-WPA2-Enterprise; WPA3-Enterprise.

2. The method according to claim 1, characterized in that The method further comprises: The first slave device receives a second message from the master device, where the second message includes second indication information, and the second indication information is used to instruct the first slave device to use a first security mode, where the first security mode is one of the multiple security modes.

3. The method according to claim 2, characterized in that After the first slave device receives the second message from the master device, the method further includes: The first slave device sends a third message to the master device, where the third message is used to feed back a configuration result.

4. The method according to claim 2 or 3, characterized in that The second message also includes third indication information, which is used to indicate the operating frequency band configuration of the first slave device in the form of a bitmap.

5. The method according to claim 4, characterized in that Each of the multiple frequency bands corresponds to a second bit, and the value of the second bit indicates whether the first slave device turns off or on the frequency band corresponding to the second bit, and the multiple frequency bands include: 2.4GHz, 5GHz, 5G-Low, 5G-High and 6GHz.

6. The method according to any one of claims 2 to 5, characterized in that The second message also includes a supported service set identifier (SSID) field, a password length field, and a password field, wherein the SSID field is used to indicate the content of the SSID, the password length field is used to indicate the length of the password, and the password field is used to indicate the content of the password, and the lengths of the SSID field and the password field are both variables.

7. The method according to any one of claims 2 to 6, characterized in that The second message further includes a transmission power level field and a channel width field, wherein the transmission power level field is used to indicate the transmission power level of the first slave device, and the channel width field is used to indicate the width of the operating frequency of the first slave device.

8. The method according to any one of claims 1 to 7, characterized in that When the value of the first bit is 0, the first slave device does not support the security mode corresponding to the first bit; when the value of the first bit is 1, the first slave device supports the security mode corresponding to the first bit.

9. The method according to any one of claims 1 to 8, characterized in that Before the first slave device sends the first message to the master device, the method further includes: The first slave device receives a fourth message from the master device, wherein the fourth message is used to request the first slave device to report capability parameters of the first slave device.

10. The method according to any one of claims 1 to 9, characterized in that The first message further includes a Wireless Local Area Network Management Control Interface (WMCI) version number field, wherein the WMCI version number field is used to indicate a WMCI version supported by the first slave device.

11. The method according to any one of claims 1 to 10, characterized in that The first message further includes a wireless local area network management control interface WMCI characteristic field, wherein the WMCI characteristic field indicates in a bitmap form whether the first slave device supports coordinated time domain transmission and whether it supports energy consumption management.

12. The method according to any one of claims 1 to 11, characterized in that The first message also includes an IEEE 802.11 version number field, which indicates in bitmap form whether the first slave device supports each of multiple IEEE 802.11 versions, wherein each version corresponds to a third bit, and the value of the third bit indicates whether the first slave device supports the version corresponding to the third bit.

13. The method according to claim 12, characterized in that The various IEEE 802.11 versions include 802.11AX, 802.11BE, and 802.11BN.

14. The method according to any one of claims 1 to 13, characterized in that The first message also includes fourth indication information, which is used to indicate capability parameters of the first slave device in a frequency band, where the capability parameters include a transmit power level and / or a channel width.

15. The method according to claim 14, characterized in that The first message also includes fifth indication information, which is used to indicate capability parameters of the first slave device in another frequency band, where the capability parameters include a transmit power level and / or a channel width.

16. The method according to claim 14 or 15, characterized in that The fourth indication message includes a transmit power field, used to indicate whether at least one of the following transmit powers is supported: 0% to 20% of the transmission power, 20% to 40% of the transmission power, 40% to 60% of the transmission power, 60% to 80% of the transmission power, and 80% to 100% of the transmission power.

17. The method according to any one of claims 14 to 16, characterized in that The fourth indication message includes a channel width field, which is used to indicate whether at least one of the following channel widths is supported: 20MHz channel width, 40MHz channel width, 80MHz channel width, 160MHz channel width, 2 discontinuous 80MHz channel widths.

18. The method according to any one of claims 1 to 17, characterized in that The first message is a wireless local area network management control interface WMCI message.

19. The method according to claim 18, characterized in that The first message also includes sixth indication information, and the sixth indication information includes a first value or a second value. The first value is used to indicate that the operation type is a parameter request type, and the second value is used to indicate that the operation type is a parameter configuration type.

20. The method according to claim 18 or 19, characterized in that The first message also includes a message content field, and the first indication information is located in the message content field of the first message.

21. The method according to any one of claims 1 to 20, characterized in that The master device and the at least one slave device are connected via an optical fiber or a composite cable.

22. The method according to any one of claims 2 to 7, characterized in that The at least one slave device includes a first slave device and a second slave device; The method further comprises: After the master device determines that the second slave device is offline, the first slave device receives a fifth message from the master device, where the fifth message includes sixth indication information, and the sixth indication information is used to instruct the first slave device to use a second security mode, where the second security mode is a security mode supported by the first slave device, and the second security mode is different from the first security mode.

23. A communication device, characterized in that: include: A processor and a transceiver, wherein the processor is connected to the transceiver, and the processor is configured to implement the method according to any one of claims 1 to 22.

24. A communication device, characterized in that: The communication device is used to implement the method according to any one of claims 1 to 22.

25. A communication system, characterized in that: The method comprises a master device and at least one slave device, wherein the at least one slave device comprises a first slave device, wherein the first slave device is configured to execute the method according to claims 1-22, and the master device is connected to the at least one slave device.

26. A chip, characterized in that: The chip is configured to execute the method according to any one of claims 1 to 22.

27. A computer program product, characterized in that The computer program product comprises instructions, which, when executed on a computer, cause the computer to perform the method according to any one of claims 1 to 22.

28. A computer-readable storage medium, characterized in that Used to store instructions, when the instructions are run on a computer, so that the computer performs the method according to any one of claims 1 to 22.

Citation Information

Patent Citations

  • Multi-frequency wireless hotspot configuration method, configuration device and processor

    CN115002758A

  • Optical fiber to room (FTTR) master-slave device communication method, storage medium and electronic device

    CN117241165A

  • Service encryption method of passive optical network system, electronic equipment and storage medium

    CN117579182A

  • Optical network communication method and communication device

    CN120601983A

  • A method and system for negotiating encryption algorithm in passive optical network system

    WO2007124658A1

Cited By

  • Communication method and apparatus, and storage medium

    WO2026091894A1

  • Optical network communication method and communication apparatus

    WO2026149093A1