A method of optical network communication and a communication device

By receiving authentication and encryption capabilities from slave devices and instructing them to use a unified authentication and encryption mode, the security and energy consumption issues caused by slave devices using different encryption modes in FTTR scenarios are resolved, thereby improving network security and configuration efficiency.

CN120601983BActive Publication Date: 2026-05-12HUAWEI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HUAWEI TECH CO LTD
Filing Date
2025-02-18
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

In FTTR scenarios, slave devices determine the authentication and encryption mode based on pre-configured information during the initialization phase. This results in multiple slave devices managed by the same master device using different authentication and encryption modes, affecting network security, power consumption of terminal devices, and service stability.

Method used

The master device receives the authentication and encryption capability information from the slave device and instructs it to use a unified authentication and encryption mode. It supports multiple compatible combinations of authentication and encryption modes, ensuring that the master and slave devices use the same authentication and encryption method. The unified configuration of the authentication and encryption mode is achieved through WMCI message interaction.

Benefits of technology

It improves network security and configuration reliability, reduces configuration conflicts, and enhances the security and energy efficiency of terminal devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120601983B_ABST
    Figure CN120601983B_ABST
Patent Text Reader

Abstract

The application provides an optical network communication method and a communication device. The method is applied to an optical fiber network, and the optical fiber network comprises a master device and at least one slave device, and the at least one slave device comprises a first slave device. In an initialization stage, after receiving an authentication encryption capability of the slave device, the master device can indicate a determined authentication encryption mode (for example, a first authentication encryption mode) to the slave device, so that in a subsequent process (for example, in a roaming parameter configuration process), the master device does not need to configure the authentication encryption mode and other security-related parameters for the slave device, thereby improving the configuration efficiency and saving the configuration overhead.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application. The original application, with application number 202510179612.X and original filing date of February 18, 2025, is incorporated herein by reference in its entirety. The original application claims priority to Chinese Patent Application No. 202510039018.0, filed with the State Intellectual Property Office of China on January 9, 2025, entitled "An Optical Network Communication Method and Communication Device," the entirety of which is incorporated herein by reference. Technical Field

[0002] This application relates to the field of optical communication, and more particularly to an optical network communication method and communication device. Background Technology

[0003] Fiber to the room (FTTR) refers to a technology that uses fiber optic cables instead of network cables to provide fiber optic media access to a room via optical network equipment (e.g., an optical network terminal, ONT). In this FTTR scenario, the fiber optic network includes a master device and one or more slave devices (also called sub-devices). A management channel can be established between the master and slave devices, allowing the master device to send management or control-related messages to the slave devices, thereby enabling the master device to manage or control some of the slave devices' functions.

[0004] In the current standard, slave devices can determine a specific authentication and encryption mode based on pre-configured information during the initialization phase to provide security authentication for terminal devices accessing the network. This implementation may result in multiple slave devices managed by the same master device using different authentication and encryption modes. In other words, the authentication and encryption modes across the entire network may be inconsistent, potentially affecting not only the security of some devices (e.g., terminal devices accessing the network through slave devices) but also increasing the processing complexity of terminal devices accessing the network through slave devices, impacting energy consumption and service stability. Summary of the Invention

[0005] This application provides an optical network communication method and communication device for improving device security.

[0006] In a first aspect, this application provides an optical network communication method applied to an optical fiber network, which includes a master device and at least one slave device. The optical network communication method provided in this aspect can be executed by the master device in the optical fiber network, or by a portion of a functional module or chip within the master device. Taking execution by the master device as an example, the master device receives at least one first message, each from at least one slave device. The first message includes first indication information, which indicates at least one authentication and encryption mode supported by the corresponding slave device. Then, the master device sends at least one second message, each corresponding to one of the at least one slave device. The second message includes second indication information, which instructs the corresponding slave device to use the first authentication and encryption mode.

[0007] In traditional technologies, slave devices do not report authentication and encryption capabilities; they only enable pre-configured authentication and encryption modes. This can lead to multiple slave devices managed by the same master device using different authentication and encryption modes, potentially affecting the security of some devices (e.g., terminal devices accessing the network through slave devices). In this invention, after receiving authentication and encryption capabilities from at least one slave device, the master device can indicate a specific authentication and encryption mode (e.g., a first authentication and encryption mode) to the aforementioned slave devices. This ensures that all slave devices managed by the master device uniformly use a single authentication and encryption mode, thereby improving network security.

[0008] In one possible implementation, at least one authentication encryption mode includes at least one of the following modes:

[0009] 64-bit wired equivalent security WEP-64 mode; or 128-bit wired equivalent security WEP-128 mode; or user-facing Wi-Fi protected access WPA-Personal mode; or WPA2-Personal mode; or WPA-WPA2-Personal mode; or WPA3-SAE; or WPA2-WPA3-PSK-SAE; or enterprise-facing Wi-Fi protected access WPA-Enterprise; or WPA2-Enterprise; or WPA-WPA2-Enterprise; or WPA3-Enterprise.

[0010] This embodiment provides a combination of multiple compatible authentication and encryption modes, which improves system compatibility and the flexibility of the master device in configuring authentication and encryption modes for multiple slave devices. Furthermore, the authentication and encryption mode indicated by the first indication information in this embodiment is a combination of authentication (i.e., authentication method) and encryption method, not just one or the other. That is, given an authentication and encryption mode, the device (master or slave) can determine which authentication method and encryption method to use. Compared to traditional methods that configure authentication and encryption methods separately, this avoids configuration conflicts (e.g., incompatibility between authentication and encryption methods), improving the reliability and efficiency of configuring authentication and encryption modes. For example, WPA3 authentication can only be combined with the Advanced Encryption Standard (AES) algorithm. Using WPA3 authentication but employing the Temporal Key Integrity Protocol (TKIP) algorithm will result in a configuration conflict due to incompatibility between the authentication and encryption methods.

[0011] In one possible implementation, the first authentication encryption mode is an authentication encryption mode supported by at least one slave device.

[0012] If a slave device lacks reported authentication and encryption capabilities, and the master device blindly configures an authentication and encryption mode for it, it may configure an encryption method that the slave device does not support, or configure an encryption method with a low level of security. In this embodiment, the master device can select an authentication and encryption mode supported by the slave device as the authentication and encryption mode used by the slave device, increasing the probability of successful configuration and thus improving network security. Furthermore, the master device determines an authentication and encryption mode supported by all slave devices based on their authentication and encryption capabilities, using this mode as the authentication and encryption mode for all slave devices. This further increases the probability of successfully configuring the authentication and encryption mode for multiple slave devices, thereby improving network security.

[0013] In one possible implementation, the first authentication encryption mode is the same as the authentication encryption mode used by the master device.

[0014] For example, if the master device has a wireless local area network (WLAN) function, the authentication encryption mode used by the slave device is the same as that used by the master device. That is, the first authentication encryption mode determined by the master device is the authentication encryption mode supported by the master device, and both the master device and the slave device use the first authentication encryption mode.

[0015] In one possible implementation, the first message further includes third indication information, which indicates a first frequency band supported by the slave device, the first frequency band being one of at least one frequency band supported by the slave device.

[0016] In this embodiment, since the first message includes first indication information and third indication information, the first indication information can also be understood as indicating the authentication and encryption modes supported by the slave device when operating in the first frequency band. For example, if the authentication and encryption modes indicated by the first indication information are "WEP-64" and "WEP-128", and the first frequency band indicated by the third indication information is "2.4GHz", it means that when the slave device operates in 2.4GHz, the slave device supports both "WEP-64" and "WEP-128" authentication and encryption modes. The master device configures the slave device with either "WEP-64" or "WEP-128" encryption, and the slave device can operate normally and obtain security protection in 2.4GHz. In other words, the slave device reports its authentication and encryption capabilities according to frequency band. When the slave device supports two or more frequency bands, it reports the authentication and encryption modes corresponding to different frequency bands to the master device through different messages. Therefore, it is evident that reporting authentication and encryption capabilities by frequency band allows the master device to accurately determine which authentication and encryption modes are supported when the slave device operates in a specific frequency band. This, in turn, enables the master device to configure the appropriate authentication and encryption modes for the slave device operating in that frequency band, improving the adaptability of the configured authentication and encryption modes and enhancing system security. Furthermore, the electronic components and software algorithms of the processing chips for different frequency bands within the slave device are relatively independent; that is, authentication and encryption algorithms for different frequency bands are generally encapsulated in processing chips for different frequency bands. Reporting authentication and encryption capabilities for different frequency bands in separate messages allows for the independent enabling of authentication and encryption methods operating in different frequency bands. For example, it allows the master device to configure different authentication and encryption methods for different operating frequency bands of the same slave device, increasing the flexibility of the slave device in authenticating and encrypting terminal devices.

[0017] In one possible implementation, the second message further includes third indication information. Since the second message includes both second and third indication information, the second indication information can be understood as indicating that the corresponding slave device uses the first authentication encryption mode when operating in the first frequency band. The second indication information can also be understood as indicating that the indicated first authentication encryption mode corresponds to the first frequency band indicated by the third indication information.

[0018] In one possible implementation, at least one slave device includes a first slave device and a second slave device; the method further includes:

[0019] After the master device determines that the second slave device is offline, the master device sends a third message to the first slave device. The third message includes a fourth instruction message, which instructs the first slave device to use the second authentication encryption mode. The second authentication encryption mode is an authentication encryption mode supported by the first slave device and is different from the first authentication encryption mode.

[0020] For example, if the master device receives a disconnection notification from the second slave device, or if the master device cannot detect the optical signal from the second slave device, the master device determines the second authentication encryption mode based on at least one authentication encryption mode supported by the first slave device, and the second authentication encryption mode is an authentication encryption mode supported by the first slave device; or, the master device determines the second authentication encryption mode based on at least one authentication encryption mode supported by the first slave device and at least one authentication encryption mode supported by the master device, and the second authentication encryption mode is an authentication encryption mode supported by both the first slave device and the master device.

[0021] In this implementation, when the second slave device goes offline, the master device no longer considers the authentication and encryption capabilities of the offline second slave device. It determines whether to update the authentication and encryption mode used by the slave device solely based on the authentication and encryption capabilities of the first slave device (and the master device). This facilitates the immediate configuration of appropriate authentication and encryption modes for slave devices, improving system security.

[0022] In one possible implementation, at least one slave device includes a first slave device and a second slave device; the method further includes:

[0023] The master device receives a fourth message from the third slave device, the fourth message including fifth indication information, the fifth indication information being used to indicate at least one authentication encryption mode supported by the third slave device; then, the master device sends a fifth message to the first slave device, the second slave device and the third slave device respectively, the fifth message including sixth indication information, the sixth indication information being used to indicate the use of a third authentication encryption mode, the third authentication encryption mode being an authentication encryption mode supported by the first slave device, the second slave device and the third slave device, and the third authentication encryption mode being different from the first authentication encryption mode.

[0024] For example, the master device determines a third authentication encryption mode based on at least one authentication encryption mode supported by the first slave device, at least one authentication encryption mode supported by the second slave device, at least one authentication encryption mode supported by the third slave device, and at least one authentication encryption mode supported by the master device. The third authentication encryption mode is one that is supported by all three slave devices (first, second, third, and master devices). In this embodiment, when the third slave device comes online, the master device determines whether to update the authentication encryption mode based on the authentication encryption capabilities of the first, second, and third slave devices (and the master device). This facilitates timely configuration of appropriate authentication encryption modes for slave devices, improving system security.

[0025] In one possible implementation, the third message further includes third instruction information; and / or, the fifth message further includes third instruction information.

[0026] Since the third message includes both third and fourth indication information, the fourth indication information can be understood as instructing the first slave device to use the second authentication encryption mode when operating in the first frequency band. Since the fifth message includes both third and sixth indication information, the sixth indication information can be understood as instructing the slave device to use the third authentication encryption mode when operating in the first frequency band.

[0027] In one possible implementation, the first message is a WLAN management and control interface (WMCI) message, and the second message is a WMCI message. The WMCI message is used to manage or control the wireless local area network (WLAN) function of the slave device.

[0028] In one possible implementation, the first message further includes a seventh indication information, which indicates the device capability parameter set of the slave device's WLAN, including the slave device's authentication encryption mode parameters and the slave device's frequency band parameters.

[0029] In one possible implementation, the seventh indication information is located in the message type identifier field of the first message.

[0030] In one possible implementation, the second message further includes an eighth indication message, which indicates the WLAN operating parameter configuration parameter set of the slave device, including the slave device's authentication encryption mode parameters and the slave device's frequency band parameters.

[0031] In one possible implementation, the eighth indication information is located in the message type identifier field of the second message.

[0032] In one possible implementation, the message content field of the first message further includes a parameter mask field, and the message content field of the second message further includes a parameter mask field. The parameter mask field includes a ninth indication information and a tenth indication information. The ninth indication information is used to indicate the authentication encryption mode parameter of the slave device, and the tenth indication information is used to indicate the frequency band parameter of the slave device.

[0033] In one possible implementation, the message content field of the first message further includes first instruction information and third instruction information; the message content field of the second message further includes second instruction information and third instruction information.

[0034] In one possible implementation, the first message is encapsulated in the payload field of an FTTR Encapsulation Method (FEM) frame, and the FEM port identifier in the frame header of the FEM frame is used to indicate the slave device corresponding to the first message.

[0035] In this embodiment, the FEM port ID in the FEM frame header is assigned by the master device. This FEM port ID not only indicates that the first message is a WMCI message, but also indicates the sender and receiver of the WMCI message (i.e., the first message), that is, it indicates that the WMCI message (i.e., the first message) corresponds to the first slave device and not other slave devices. Therefore, the FEM port ID can be used to distinguish WMCI messages from other control messages in the FTTR system, which is beneficial to improving the control efficiency of WLAN functions.

[0036] In one possible implementation, the FEM frame is encapsulated in the payload field of a data link layer (DLL) frame.

[0037] In one possible implementation, the master device is a main FTTR unit (MFU), and the slave device is a sub FTTR unit (SFU).

[0038] Secondly, this application provides an optical network communication method applied to an optical fiber network, which includes a master device and at least one slave device. The optical network communication method provided in this aspect can be executed by the slave device in the optical fiber network, or by a portion of a functional module or chip within the slave device. Taking execution by the slave device as an example, the slave device sends a first message to the master device, the first message including first indication information, which indicates at least one authentication encryption mode supported by the slave device; then, the slave device receives a second message from the master device, the second message including second indication information, which instructs the slave device to use a first authentication encryption mode, the first authentication encryption mode being one of at least one authentication encryption modes supported by the slave device.

[0039] In one possible implementation, at least one authentication encryption mode includes at least one of the following modes:

[0040] WEP-64 mode; or WEP-128 mode; or WPA-Personal mode; or WPA2-Personal mode; or WPA-WPA2-Personal mode; or WPA3-SAE; or WPA2-WPA3-PSK-SAE; or WPA-Enterprise; or WPA2-Enterprise; or WPA-WPA2-Enterprise; or WPA3-Enterprise.

[0041] In one possible implementation, the first authentication encryption mode is the same as the authentication encryption mode used by the master device.

[0042] In one possible implementation, the first message further includes third indication information, which indicates a first frequency band supported by the slave device, the first frequency band being one of at least one frequency band supported by the slave device.

[0043] In one possible implementation, the second message also includes a third instruction message.

[0044] In one possible implementation, the first message is a Wireless LAN Management and Control Interface (WMCI) message, and the second message is a WMCI message.

[0045] In one possible implementation, the first message further includes a seventh indication information, which indicates the device capability parameter set of the slave device's WLAN, including the slave device's authentication encryption mode parameters and the slave device's frequency band parameters.

[0046] In one possible implementation, the seventh indication information is located in the message type identifier field of the first message.

[0047] In one possible implementation, the second message further includes an eighth indication message, which indicates the WLAN operating parameter configuration parameter set of the slave device, including the slave device's authentication encryption mode parameters and the slave device's frequency band parameters.

[0048] In one possible implementation, the eighth indication information is located in the message type identifier field of the second message.

[0049] In one possible implementation, the message content field of the first message further includes a parameter mask field, and the message content field of the second message further includes a parameter mask field. The parameter mask field includes a ninth indication information and a tenth indication information. The ninth indication information is used to indicate the authentication encryption mode parameter of the slave device, and the tenth indication information is used to indicate the frequency band parameter of the slave device.

[0050] In one possible implementation, the message content field of the first message further includes first instruction information and third instruction information; the message content field of the second message further includes second instruction information and third instruction information.

[0051] In one possible implementation, the first message is encapsulated in the payload field of a fiber-to-room encapsulation mode (FEM) frame, and the FEM port identifier in the frame header of the FEM frame is used to indicate the slave device corresponding to the first message.

[0052] In one possible implementation, the FEM frame is encapsulated in the payload field of a data link layer DLL frame.

[0053] In one possible implementation, the master device is the master fiber-to-room FTTR unit (MFU), and the slave device is the slave FTTR unit (SFU).

[0054] It should be noted that there are many other specific implementation methods in this application, and you can refer to the specific implementation methods and their beneficial effects in the first aspect, which will not be repeated here.

[0055] Thirdly, this application provides an optical network communication method applied to an optical fiber network, which includes a master device and at least one slave device. The optical network communication method provided in this aspect can be executed by the master device in the optical fiber network, or by a portion of a functional module or chip within the master device. Taking execution by the master device as an example, the master device receives a first message, the first message including first indication information, the first indication information being used to indicate at least one authentication encryption mode supported by the slave device;

[0056] At least one authentication encryption mode includes at least one of the following modes:

[0057] WEP-64 mode; or WEP-128 mode; or WPA-Personal mode; or WPA2-Personal mode; or WPA-WPA2-Personal mode; or WPA3-SAE; or WPA2-WPA3-PSK-SAE; or WPA-Enterprise; or WPA2-Enterprise; or WPA-WPA2-Enterprise; or WPA3-Enterprise.

[0058] In one possible implementation, the method further includes:

[0059] The master device sends a second message, which includes second indication information. The second indication information is used to instruct the slave device to use a first authentication encryption mode. The first authentication encryption mode is one of at least one authentication encryption modes supported by the slave device.

[0060] In one possible implementation, the master device receives a first message, including:

[0061] The master device receives at least one first message, and the first message comes from at least one slave device. The authentication encryption methods indicated by the first indication information in the different first messages are not exactly the same.

[0062] The master device sends a second message, including:

[0063] The master device sends at least one second message, and each second message corresponds to at least one slave device. The second indication information in different second messages all indicate the use of the first authentication encryption mode.

[0064] In one possible implementation, the first authentication encryption mode is an authentication encryption mode supported by at least one slave device.

[0065] In one possible implementation, the first authentication encryption mode is the same as the authentication encryption mode used by the master device.

[0066] In one possible implementation, the first message further includes third indication information, which indicates a first frequency band supported by the slave device, the first frequency band being one of at least one frequency band supported by the slave device.

[0067] Optionally, the second message may also include a third instruction.

[0068] In one possible implementation, the master device receiving the first message includes: the master device receiving the first message during the initialization configuration phase;

[0069] The master device sends a second message, including: before configuring and enabling the roaming function of the slave device, the master device sends a second message to the slave device.

[0070] In this embodiment, the process of the master device and the slave device exchanging the first and second messages occurs during the initialization configuration phase, that is, before the master device enables the roaming function of the slave device. Since the master device configures the authentication and encryption mode used by the slave device during the initialization phase, there is no need to configure the authentication and encryption mode for the roaming function separately, saving the signaling overhead required for subsequent security configuration of roaming and improving the configuration efficiency of the master device.

[0071] In one possible implementation, the first authentication encryption mode is WPA2-WPA3-PSK-SAE mode. The WPA2-WPA3-PSK-SAE mode is used to indicate that the authentication method is compatible with both WPA2-PSK and WPA3-SAE modes, and the encryption method uses the Advanced Encryption Standard (AES) algorithm.

[0072] In this embodiment, the master device can configure a WPA2 and WPA3 compatible authentication and encryption mode for the slave device, which is beneficial for the slave device to enable WPA2 or WPA3 to perform security verification on the terminal device as needed, and improves the flexibility of the slave device in authenticating the terminal device.

[0073] In one possible implementation, at least one slave device includes a first slave device and a second slave device; the method further includes:

[0074] After the master device determines that the second slave device is offline, the master device sends a third message to the first slave device. The third message includes a fourth instruction message, which instructs the first slave device to use the second authentication encryption mode. The second authentication encryption mode is an authentication encryption mode supported by the first slave device and is different from the first authentication encryption mode.

[0075] In one possible implementation, at least one slave device includes a first slave device and a second slave device; the method further includes:

[0076] The master device receives a fourth message from the third slave device, the fourth message including fifth indication information, the fifth indication information being used to indicate at least one authentication encryption mode supported by the third slave device; then, the master device sends a fifth message to the first slave device, the second slave device and the third slave device respectively, the fifth message including sixth indication information, the sixth indication information being used to indicate the use of a third authentication encryption mode, the third authentication encryption mode being an authentication encryption mode supported by the first slave device, the second slave device and the third slave device, and the third authentication encryption mode being different from the first authentication encryption mode.

[0077] In one possible implementation, the third message further includes third instruction information; and / or, the fifth message further includes third instruction information.

[0078] In one possible implementation, the first message is a Wireless LAN Management and Control Interface (WMCI) message, and the second message is a WMCI message.

[0079] In one possible implementation, the first message further includes a seventh indication information, which indicates the device capability parameter set of the slave device's WLAN, including the slave device's authentication encryption mode parameters and the slave device's frequency band parameters.

[0080] In one possible implementation, the seventh indication information is located in the message type identifier field of the first message.

[0081] In one possible implementation, the second message further includes an eighth indication message, which indicates the WLAN operating parameter configuration parameter set of the slave device, including the slave device's authentication encryption mode parameters and the slave device's frequency band parameters.

[0082] In one possible implementation, the eighth indication information is located in the message type identifier field of the second message.

[0083] In one possible implementation, the message content field of the first message further includes a parameter mask field, and the message content field of the second message further includes a parameter mask field. The parameter mask field includes a ninth indication information and a tenth indication information. The ninth indication information is used to indicate the authentication encryption mode parameter of the slave device, and the tenth indication information is used to indicate the frequency band parameter of the slave device.

[0084] In one possible implementation, the message content field of the first message further includes first instruction information and third instruction information; the message content field of the second message further includes second instruction information and third instruction information.

[0085] In one possible implementation, the first message is encapsulated in the payload field of a fiber-to-room encapsulation mode (FEM) frame, and the FEM port identifier in the frame header of the FEM frame is used to indicate the slave device corresponding to the first message.

[0086] In one possible implementation, the FEM frame is encapsulated in the payload field of a data link layer DLL frame.

[0087] In one possible implementation, the master device is the master fiber-to-room FTTR unit (MFU), and the slave device is the slave FTTR unit (SFU).

[0088] It should be noted that there are many other specific implementation methods in this application, and you can refer to the specific implementation methods and their beneficial effects in the first aspect, which will not be repeated here.

[0089] Fourthly, this application provides an optical network communication method applied to an optical fiber network, which includes a master device and at least one slave device. The optical network communication method provided in this aspect can be executed by the slave device in the optical fiber network, or by a portion of a functional module or chip within the slave device. Taking execution by the slave device as an example, the slave device sends a first message to the master device. The first message includes first indication information, which indicates at least one authentication encryption mode supported by the slave device.

[0090] At least one authentication encryption mode includes at least one of the following modes:

[0091] WEP-64 mode; or WEP-128 mode; or WPA-Personal mode; or WPA2-Personal mode; or WPA-WPA2-Personal mode; or WPA3-SAE; or WPA2-WPA3-PSK-SAE; or WPA-Enterprise; or WPA2-Enterprise; or WPA-WPA2-Enterprise; or WPA3-Enterprise.

[0092] In one possible implementation, the method further includes: receiving a second message from a master device from a slave device, the second message including second indication information, the second indication information being used to instruct the slave device to use a first authentication encryption mode, the first authentication encryption mode being one of at least one authentication encryption modes supported by the slave device.

[0093] In one possible implementation, the first authentication encryption mode is the same as the authentication encryption mode used by the master device.

[0094] In one possible implementation, the first message further includes third indication information, which indicates a first frequency band supported by the slave device, the first frequency band being one of at least one frequency band supported by the slave device.

[0095] In one possible implementation, the second message also includes a third instruction message.

[0096] In one possible implementation, the slave device sends a first message to the master device, including: during the initialization configuration phase, the slave device sends a first message to the master device; the slave device receives a second message from the master device, including: before configuring the roaming function of the slave device to be enabled, the slave device receives a second message from the master device.

[0097] In one possible implementation, the first authentication encryption mode is WPA2-WPA3-PSK-SAE mode. The WPA2-WPA3-PSK-SAE mode is used to indicate that the authentication method is compatible with both WPA2-PSK and WPA3-SAE modes, and the encryption method uses the Advanced Encryption Standard (AES) algorithm.

[0098] It should be noted that there are many other specific implementation methods in this application, and you can refer to the specific implementation methods and their beneficial effects in the first or third aspects, which will not be repeated here.

[0099] Fifthly, this application provides an optical network communication method applied to an optical fiber network, which includes a master device and at least one slave device. The optical network communication method provided in this aspect can be executed by the master device in the optical fiber network, or by a portion of a functional module or chip within the master device. Taking execution by the master device as an example, the master device sends a device capability parameter request message to the slave device. The device capability parameter request message includes ninth indication information, which indicates the authentication and encryption mode parameters supported by the slave device. Then, the master device receives a device capability parameter report message from the slave device. The device capability parameter report message includes first indication information, which indicates at least one authentication and encryption mode supported by the slave device.

[0100] In this embodiment, during the initialization phase, the master device can request the slave device to report authentication and encryption capabilities (i.e., at least one authentication and encryption mode supported by the slave device) through a capability parameter request message. This enables the master device to request capability parameters (e.g., authentication and encryption capabilities) from the slave device on demand, which helps to improve the flexibility of the master device in obtaining capability parameters.

[0101] In one possible implementation, the device capability parameter request message further includes tenth indication information, which indicates the frequency band parameters supported by the device.

[0102] In one possible implementation, the device capability parameter report message further includes third indication information for indicating a first frequency band of the slave device, the first frequency band being one of at least one frequency band supported by the slave device.

[0103] Optionally, the device capability parameter report message may also include the tenth indication information.

[0104] In this embodiment, the master device carries a tenth indication information in the device capability parameter request message to indicate the frequency band parameters supported by the slave device, so that the slave device carries a third indication information indicating the first frequency band in the returned device capability parameter report message. This enables the master device to obtain the authentication and encryption capabilities of the slave device by frequency band, which is beneficial for the master device to configure the authentication and encryption mode of the slave device by frequency band, and for the master device to configure the authentication and encryption mode suitable for the working frequency band. This not only ensures the security of the slave device, but also improves the flexibility of the slave device in authenticating and encrypting terminal devices.

[0105] In one possible implementation, after the master device receives the device capability parameter report message from the slave device, the method further includes:

[0106] The master device sends a working parameter configuration message to the slave device. The working parameter configuration message includes second indication information, which is used to instruct the slave device to use the first authentication encryption method. Then, the master device receives a working parameter configuration report message from the slave device, which is used to indicate whether the first authentication encryption method has been configured successfully.

[0107] In this embodiment, during the initialization phase, after receiving the authentication and encryption capabilities of the slave device, the master device can indicate a specific authentication and encryption mode (e.g., a first authentication and encryption mode) to the slave device. This allows the master device to avoid configuring security-related parameters such as authentication and encryption modes for the slave device in subsequent processes (e.g., roaming parameter configuration processes), thereby improving configuration efficiency and saving configuration overhead.

[0108] In one possible implementation, the operating parameter configuration message further includes third indication information for indicating a first frequency band of the slave device, the first frequency band being one of at least one frequency band supported by the slave device.

[0109] Optionally, the device capability parameter report message may also include the tenth indication information.

[0110] In one possible implementation, after the master device receives the operating parameter configuration report message from the slave device, the method further includes:

[0111] The master device sends a roaming enable message to the slave device, which instructs the slave device to enable the roaming function; then, the master device receives a roaming enable report message from the slave device, which indicates whether the slave device has successfully enabled the roaming function.

[0112] In this embodiment, the master device can configure the authentication and encryption mode for the slave device before notifying the slave device to enable roaming via a roaming activation message. After the slave device enables roaming, the master device can also configure the roaming function via configuration messages (e.g., roaming network configuration messages). Since the master device has already configured a suitable authentication and encryption mode (e.g., the first authentication and encryption mode) for the slave device during the initialization phase, the master device does not need to configure security-related parameters such as the authentication and encryption mode for the slave device again during the roaming function configuration phase. For example, the roaming network configuration message may not carry security-related parameters such as the authentication and encryption mode. This improves configuration efficiency and saves configuration overhead.

[0113] In one possible implementation, at least one authentication encryption mode includes at least one of the following modes:

[0114] WEP-64 mode; or WEP-128 mode; or WPA-Personal mode; or WPA2-Personal mode; or WPA-WPA2-Personal mode; or WPA3-SAE; or WPA2-WPA3-PSK-SAE; or WPA-Enterprise; or WPA2-Enterprise; or WPA-WPA2-Enterprise; or WPA3-Enterprise.

[0115] In one possible implementation, the first authentication encryption mode is WPA2-WPA3-PSK-SAE mode. The WPA2-WPA3-PSK-SAE mode is used to indicate that the authentication method is compatible with both WPA2-PSK and WPA3-SAE modes, and the encryption method uses the Advanced Encryption Standard (AES) algorithm.

[0116] It should be noted that there are many other specific implementation methods in this application, and you can refer to the specific implementation methods and their beneficial effects in the first or third aspects, which will not be repeated here.

[0117] Sixthly, this application provides an optical network communication method applied to an optical fiber network, the optical fiber network including a master device and at least one slave device. The optical network communication method provided in this aspect can be executed by the slave device in the optical fiber network, or by a portion of a functional module or chip within the slave device. Taking execution by the slave device as an example, the slave device receives a device capability parameter request message from the master device, the device capability parameter request message including ninth indication information, the ninth indication information being used to indicate authentication and encryption mode parameters supported by the slave device; then, the slave device sends a device capability parameter report message to the master device, the device capability parameter report message including first indication information, the first indication information being used to indicate at least one authentication and encryption mode supported by the slave device.

[0118] In one possible implementation, the device capability parameter request message further includes tenth indication information, which indicates the frequency band parameters supported by the device.

[0119] In one possible implementation, the device capability parameter report message further includes third indication information for indicating a first frequency band of the slave device, the first frequency band being one of at least one frequency band supported by the slave device.

[0120] In one possible implementation, after the slave device sends a device capability parameter report message to the master device, the method further includes:

[0121] The slave device receives a working parameter configuration message from the master device. The working parameter configuration message includes second indication information, which is used to instruct the slave device to use the first authentication encryption method. Then, the slave device sends a working parameter configuration report message to the master device, which is used to indicate whether the first authentication encryption method has been configured successfully.

[0122] In one possible implementation, the operating parameter configuration message further includes third indication information for indicating a first frequency band of the slave device, the first frequency band being one of at least one frequency band supported by the slave device.

[0123] In one possible implementation, after the slave device sends the operating parameter configuration report message to the master device, the method further includes:

[0124] The slave device receives a roaming enable message from the master device, which instructs the slave device to enable roaming. Then, the slave device sends a roaming enable report message to the master device, which indicates whether the slave device has successfully enabled roaming.

[0125] In one possible implementation, at least one authentication encryption mode includes at least one of the following modes:

[0126] WEP-64 mode; or WEP-128 mode; or WPA-Personal mode; or WPA2-Personal mode; or WPA-WPA2-Personal mode; or WPA3-SAE; or WPA2-WPA3-PSK-SAE; or WPA-Enterprise; or WPA2-Enterprise; or WPA-WPA2-Enterprise; or WPA3-Enterprise.

[0127] In one possible implementation, the first authentication encryption mode is WPA2-WPA3-PSK-SAE mode. The WPA2-WPA3-PSK-SAE mode is used to indicate that the authentication method is compatible with both WPA2-PSK and WPA3-SAE modes, and the encryption method uses the Advanced Encryption Standard (AES) algorithm.

[0128] It should be noted that there are many other specific implementation methods in this application, and you can refer to the specific implementation methods and their beneficial effects in the first, third or fifth aspects, which will not be repeated here.

[0129] In a seventh aspect, embodiments of this application provide a communication device, which may be a main device as described in the foregoing embodiments, or a chip within the main device. The communication device may include a processing module and a transceiver module. When the communication device is a main device, the processing module may be a processor, and the transceiver module may be a transceiver; the main device may also include a storage module, which may be a memory; the storage module is used to store instructions, and the processing module executes the instructions stored in the storage module to cause the main device to perform the method of the main device in any of the foregoing embodiments. When the communication device is a chip within the main device, the processing module may be a processor, and the transceiver module may be an input / output interface, pin, or circuit, etc.; the processing module executes the instructions stored in the storage module to cause the main device to perform the method of the first aspect or any of the foregoing embodiments; or, to perform the method of the main device in any of the foregoing embodiments. The storage module may be a storage module within the chip (e.g., a register, cache, etc.), or a storage module located outside the chip within the main device (e.g., a read-only memory, random access memory, etc.).

[0130] Eighthly, embodiments of this application provide a communication device, which can be a slave device as described in the foregoing embodiments, or a chip within the slave device. The communication device may include a processing module and a transceiver module. When the communication device is a slave device, the processing module may be a processor, and the transceiver module may be a transceiver. Optionally, the slave device may further include a storage module, which may be a memory; the storage module stores instructions, and the processing module executes the instructions stored in the storage module to cause the slave device to perform the method of the slave device in any of the foregoing embodiments. When the communication device is a chip within the slave device, the processing module may be a processor, and the transceiver module may be an input / output interface, pin, or circuit, etc.; the processing module executes the instructions stored in the storage module to cause the slave device to perform the method of the slave device in any of the foregoing embodiments. The storage module may be a storage module within the chip (e.g., a register, cache, etc.), or a storage module located outside the chip within the slave device (e.g., a read-only memory, random access memory, etc.).

[0131] Ninthly, this application provides a communication device, which may be an integrated circuit chip. The integrated circuit chip includes a processor. The processor is coupled to a memory for storing programs or instructions that, when executed by the processor, cause the communication device to perform the methods described in any of the various embodiments of the foregoing aspects, as well as the foregoing aspects themselves.

[0132] In a tenth aspect, embodiments of this application provide a computer program product containing instructions that, when executed on a computer, cause the computer to perform the methods described in any of the various embodiments of the foregoing aspects.

[0133] Eleventhly, embodiments of this application provide a computer-readable storage medium including instructions that, when executed on a computer, cause the computer to perform the methods described in any of the various embodiments of the foregoing aspects.

[0134] In a twelfth aspect, embodiments of this application provide an optical fiber network, which includes a master device in the first aspect and any embodiment of the first aspect, and a slave device in the second aspect and any embodiment of the second aspect.

[0135] In a thirteenth aspect, embodiments of this application provide an optical fiber network, which includes a master device in the third aspect and any embodiment of the third aspect, and a slave device in the fourth aspect and any embodiment of the fourth aspect.

[0136] In a fourteenth aspect, embodiments of this application provide an optical fiber network including a master device in the fifth aspect and any embodiment of the fifth aspect, and a slave device in the sixth aspect and any embodiment of the sixth aspect. Attached Figure Description

[0137] Figure 1A An example diagram of the network architecture of a fiber optic network;

[0138] Figure 1B Another example diagram of the network architecture of a fiber optic network;

[0139] Figure 1C Here is an example diagram of an FTTR system;

[0140] Figure 1D A schematic diagram of a WLAN network architecture;

[0141] Figure 2A This is a flowchart illustrating the optical network communication method in this application;

[0142] Figure 2B This is a schematic diagram of the initialization process in this application;

[0143] Figure 3 This is another flowchart illustrating the optical network communication method in this application;

[0144] Figure 4 This is another flowchart illustrating the optical network communication method in this application;

[0145] Figure 5A An example diagram of an FEM frame encapsulating WMCI messages;

[0146] Figure 5B An example diagram of an XFEM frame encapsulating a WMCI message;

[0147] Figure 5C An example diagram of a DLL frame that encapsulates an FEM frame;

[0148] Figure 5D An example diagram of a DLL frame that encapsulates an XFEM frame;

[0149] Figure 6 This is a schematic diagram of one embodiment of the communication device in this application;

[0150] Figure 7 This is a schematic diagram of another embodiment of the communication device in this application. Detailed Implementation

[0151] The technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments.

[0152] In the various embodiments of this application, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of different embodiments are consistent and can be referenced by each other. The technical features of different embodiments can be combined to form new embodiments according to their inherent logical relationship.

[0153] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a particular order or sequence. It should be understood that such terms are interchangeable where appropriate so that the embodiments described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0154] It should be understood that the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this article generally indicates that the preceding and following related objects have an "or" relationship.

[0155] The optical network communication method provided in this application is applied to optical fiber networks. Figure 1A This is an example diagram of the architecture of a fiber optic network in traditional technology. (Example:) Figure 1AAs shown, this fiber optic network includes an optical line terminal (OLT), an optical distribution network (ODN), and optical network units (ONUs) (or optical network terminals (ONTs)). The OLT and ONUs are connected and communicate via optical fibers. The OLT is typically connected to the ONU (or ONT) through the ODN. The ODN comprises a network of one or more optical devices, such as optical fibers, optical distribution frames (ODFs), optical splitters (also known as splitters), and combiners. Furthermore, the aforementioned OLT can connect to the operator's network through a network-side interface, and it can also connect to the ODN through a dedicated interface. The ODN, in turn, connects to the ONUs (or ONTs) through a dedicated interface. In the downlink direction, the OLT broadcasts downlink optical signals, which are then distributed to each ONU (or ONT) via the ODN. In the uplink direction, a time division multiple access (TDMA) method is used, with each ONU (or ONT) transmitting uplink optical signals in its assigned uplink time slot by the OLT. It should be noted that this application does not limit the specific type of optical fiber. The optical fiber described in this application can be a single optical fiber, loose-tube optical fiber, optical cable, or optoelectronic composite cable, etc.

[0156] Figure 1B A schematic diagram of the optical fiber network provided in this application. Figure 1B As shown, the fiber optic network provided in this application includes a master device 01 and at least one slave device 02, with the master device 01 connected to the at least one slave device 02 via optical fiber. For example, the master device 01 is connected to the at least one slave device 02 via an optical distribution network. The master device 01 is capable of managing or controlling specific functions of one or more slave devices 02 based on at least one protocol.

[0157] Optionally, the optical network communication method provided in this application can be applied to a fiber-to-the-room (FTTR) scenario. FTTR technology refers to using optical fiber instead of network cables to provide fiber optic media access to the room from the downlink of optical network equipment (e.g., an optical network terminal, ONT). In this case, Figure 1B The main device 01 shown can be referred to as the main FTTR unit (MFU), FTTR master device, or main gateway. Figure 1BThe slave device 02 shown can be referred to as a sub FTTR unit (SFU), an FTTR slave device, or a slave gateway.

[0158] Figure 1C This is an example diagram showing the network locations for FTTR. Figure 1C As shown, FTTR is a network that provides fiber optic coverage within a broadband customer network (e.g., a home or office) based on fiber to the home / office (FTTH / O). Fiber optic connections are used between the FTTR master device and the FTTR slave devices in each room. Both the FTTR master and slave devices can connect to user terminals via wireless or wired interfaces, or via adapters such as set-top boxes. Specifically, the northbound connection of the FTTR master device acts as an access network terminal, connecting to the access node (AN). The southbound connection of the FTTR master device's FTTR transceiver unit connects to the FTTR transceiver units of the slave devices via the indoor fiber distribution network (IFDN), also providing gateway and other network functions. The FTTR transceiver units of the slave devices connect to the TTTP transceiver unit of the FTTR master device via the indoor fiber distribution network, providing terminal access via wireless or wired interfaces. Indoor optical distribution networks are point-to-multipoint fiber optic infrastructures that can be completely passive, typically consisting of interconnected optical cables and passive devices such as optical splitters. They can also provide remote power supply functionality for FTTR slave devices by using hybrid optical-electrical cables and hybrid optical-electrical splitters.

[0159] Optionally, FTTR technology can be combined with wireless local area network (WLAN) technology to extend gigabit-level Wi-Fi network coverage to every corner of the home, meeting internet access needs such as low latency, high bandwidth, multiple connections, and seamless roaming. For example, Figure 1BThe master device 01 shown can establish a WMCI management channel with at least one slave device 02 based on the Wireless Management Control Interface (WMCI) protocol. The master device can then manage or control the WLAN functions of one or more slave devices 02 through WMCI messages. This can be understood as the master device 01 and / or slave device 02 having WLAN functionality; it can also be understood as the master device 01 and / or slave device 02 having Wireless Fidelity (Wi-Fi) functionality. Therefore, the optical network communication method provided in this application can also be applied to WLAN scenarios.

[0160] For example, Figure 1D This is a schematic diagram of a WLAN network architecture. A WLAN network architecture mainly includes a wireless controller (also called a control node), wireless access points (also called network nodes, or simply access points (APs)), and terminal devices (also called stations (STAs)). A station is associated with one wireless access point, and a wireless access point can be associated with multiple stations. Stations access the network through their associated wireless access points. The wireless controller is used to manage and control the wireless access points. Figure 1D In the example shown, the wireless controller can be an FTTR master device, the access point (e.g., AP) can be an FTTR slave device, and the station (e.g., STA) can be a terminal device that accesses the network through an FTTR device (FTTR master device or FTTR slave device).

[0161] It should be noted that the embodiments of this application can be applied not only to FTTR architectures but also to non-FTTR architectures. For example, the architecture of a communication system consisting of a master device and a slave device can be applied to the embodiments of this application. For ease of explanation, the embodiments of this application will mainly use the master device and slave device in an FTTR architecture as an example for description.

[0162] In traditional technologies, slave devices determine a specific authentication and encryption mode based on pre-configured information during the initialization phase to provide security authentication for terminal devices accessing the network. This approach can lead to multiple slave devices managed by the same master device using different authentication and encryption modes. For example, a master device might manage slave device 1 and slave device 2, where slave device 1 uses a higher-security authentication and encryption mode (e.g., Wi-Fi Protected Access (WPA)) while slave device 2 uses a lower-security mode (e.g., Wired Equivalent Privacy (WEP)). This results in varying security capabilities between devices, potentially affecting the security of some devices (e.g., terminal devices accessing the network through slave devices). Furthermore, a terminal device can only access the network through a slave device after the slave device has completed authentication and encryption verification. When a terminal device roams between different slave devices, the use of different authentication and encryption modes necessitates adaptation of roaming procedures for different authentication methods. This increases the processing complexity of the terminal device, impacting its energy consumption and service stability.

[0163] In response, this application provides an optical network communication method and communication device for unifying the network authentication and encryption mode through negotiation between the master device and the slave device. This not only improves network security but also eliminates the need for additional adaptation processing when terminal devices roam between devices, thereby reducing the processing complexity of terminal devices, saving energy consumption, and improving the service stability or reliability of terminal devices.

[0164] The following will combine Figure 2A The main process of the optical network communication method provided in this application is described below:

[0165] like Figure 2A The diagram shown is a flowchart of an embodiment of the optical network communication method provided in this application. In this embodiment, the interaction between a master device and at least one slave device is used as an example. The master device is connected to at least one slave device via optical fiber or composite cable and manages the at least one slave device. Of course, the entity performing the actions of the master device in this method can also be a device, module, or chip in the master device; similarly, the entity performing the actions of the slave device in this method can also be a device, module, or chip in the slave device. This embodiment does not specifically limit this. For example, as shown... Figure 2A As shown, the optical network communication method includes the following steps:

[0166] Step 201: The slave device sends a first message to the master device; correspondingly, the master device receives the first message from the slave device.

[0167] For example, the slave device sends a first message to the master device via an optical fiber or composite cable; correspondingly, the master device receives the first message from the slave device via an optical fiber or composite cable.

[0168] The first message includes first indication information, which indicates at least one authentication encryption mode supported by the slave device. This can be understood as the first indication information indicating the slave device's authentication encryption capabilities. Since authentication encryption is used to improve security, authentication encryption modes are also called security modes; therefore, the first indication information indicates the security modes supported by the slave device.

[0169] Optionally, the authentication encryption mode supported by the device can be Wired Equivalent Privacy (WEP), Wi-Fi Protected Access (WPA), Wi-Fi Protected Access 2 (WPA2), or Wi-Fi Protected Access 3 (WPA3). Optionally, WEP can be further divided into WEP-64 (using a 64-bit key) or WEP-128 (using a 128-bit key).

[0170] Optionally, authentication and encryption modes can be further categorized into those for personal users and those for enterprise users. For example, WPA can be divided into WPA-Personal (for personal users) and WPA-Enterprise (for enterprise users). Similarly, WPA2 can be divided into WPA2-Personal (for personal users) and WPA2-Enterprise (for enterprise users). Likewise, WPA3 can be divided into WPA3-SAE (for personal users) and WPA3-Enterprise (for enterprise users).

[0171] Optionally, WPA offers higher security than WPA2, and WPA2 offers higher security than WPA3. Optionally, WPA offers higher security than WEP, with WEP-128 offering higher security than WEP-64.

[0172] Optionally, the slave device may also support compatible authentication and encryption modes, such as WPA-WPA2-Personal, WPA2-WPA3-PSK-SAE, and WPA-WPA2-Enterprise. Specifically, WPA-WPA2-Personal indicates compatibility between user-oriented WPA and user-facing WPA, meaning the slave device supports both WPA-Personal and WPA2-Personal modes; WPA2-WPA3-PSK-SAE indicates compatibility between WPA2-PSK and WPA3-SAE modes, meaning the slave device supports both WPA2-PSK and WPA3-SAE modes; and WPA-WPA2-Enterprise indicates compatibility between WPA-Enterprise and WPA2-Enterprise modes, meaning the slave device supports both WPA-Enterprise and WPA2-Enterprise modes. This embodiment provides a combination of multiple compatible authentication and encryption modes, which helps improve system compatibility and increases the flexibility of the master device when configuring authentication and encryption modes for multiple slave devices.

[0173] For example, the authentication encryption modes supported by the device include at least one of the following:

[0174] WEP-64, WEP-128, WPA-Personal, WPA2-Personal, WPA-WPA2-Personal, WPA3-SAE, WPA2-WPA3-PSK-SAE, WPA-Enterprise, WPA2-Enterprise, WPA-WPA2-Enterprise, or, WPA3-Enterprise.

[0175] Optionally, the device may also support encryption without authentication.

[0176] It should be noted that the authentication encryption mode indicated by the first indication information in this embodiment is a combination of authentication (i.e., authentication method) and encryption method, and not just an authentication method or encryption method alone. That is, given an authentication encryption mode, the device (master or slave device) can determine which authentication method and which encryption method are used. Compared to traditional methods that configure authentication and encryption methods separately, this avoids configuration conflicts (e.g., incompatibility between authentication and encryption methods), improving the reliability and efficiency of configuring authentication encryption modes. For example, WPA3 authentication can only be combined with the AES algorithm; using WPA3 authentication but the TKIP algorithm would lead to configuration conflicts due to incompatibility between the authentication and encryption methods.

[0177] For example, the first indication information carried in the first message may indicate an authentication encryption mode, and the specific authentication method (i.e., the authentication method) and encryption method corresponding to the authentication encryption mode are shown in Table 1 below:

[0178] Table 1

[0179]

[0180] In the example shown in Table 1, if the first indication information indicates "None", it means that the device uses an open authentication and encryption method, that is, it supports a mode without authentication and encryption.

[0181] If the first indication information indicates "WEP-64", it means that the authentication method supported by the device is "Shared", which means shared key authentication. That is, the client (e.g., terminal device) needs to provide a key that matches the key pre-stored by the access point (e.g., the slave device); the supported encryption method is "WEP-64", which means encryption is performed using a 64-bit key.

[0182] If the first indication information indicates "WEP-128", it means that the authentication method supported by the device is "Shared", which means shared key authentication; the encryption method supported is "WEP-128", which means encryption is performed using a 128-bit key.

[0183] If the first indication information indicates "WPA-Personal", it means that the authentication method supported by the device is "WPA-PSK", which is the pre-shared key (PSK) mode of WAP; and the encryption method supported is "TKIP", which is the temporary key integrity protocol (TKIP) algorithm.

[0184] If the first indication message indicates "WPA2-Personal", it means that the authentication method supported by the device is "WPA2-PSK", which is the pre-shared key (PSK) mode of WPA2; and the encryption method supported is "AES", which is the advanced encryption standard (AES) algorithm.

[0185] If the first indication information indicates "WPA-WPA2-Personal", it means that the device supports authentication methods "WPA-PSK" and "WPA2-PSK"; and encryption methods "TKIP" and "AES". For example, if the authentication method is "WPA-PSK", the encryption method is "TKIP"; or, if the authentication method is "WPA2-PSK", the encryption method is "AES".

[0186] If the first indication information indicates "WPA3-SAE", it means that the authentication method supported by the device is "WPA3-SAE", which is the simultaneous authentication of equals (SAE) method of WPA3; and the encryption method supported is "AES", which is the AES algorithm.

[0187] If the first indication information indicates "WPA2-WPA3-PSK-SAE", it means that the authentication methods supported by the device are "WPA2-PSK" and "WPA3-SAE"; the supported encryption method is "AES".

[0188] If the first indication information indicates "WPA-Enterprise", it means that the authentication method supported by the device is "WPA-Enterprise" and the encryption method is "TKIP", that is, the TKIP algorithm.

[0189] If the first indication information indicates "WPA2-Enterprise", it means that the authentication method supported by the device is "WPA2-Enterprise" and the encryption method is "AES", that is, the AES algorithm.

[0190] If the first indication information indicates "WPA-WPA2-Enterprise", it means that the device supports authentication methods of "WPA-Enterprise" and "WPA2-Enterprise"; and encryption methods of "TKIP" and "AES". For example, if the authentication method is "WPA-Enterprise", the encryption method is "TKIP"; or, if the authentication method is "WPA2-Enterprise", the encryption method is "AES".

[0191] If the first indication information indicates "WPA3-Enterprise", it means that the authentication method supported by the device is "WPA3-Enterprise" and the encryption method is "AES", that is, the AES algorithm.

[0192] It should be noted that the first indication information in the first message may indicate only one of the authentication and encryption modes shown in Table 1, or it may indicate multiple authentication and encryption modes in Table 1. This embodiment does not limit this.

[0193] Optionally, the first message further includes third indication information, which indicates a first frequency band supported by the slave device, wherein the first frequency band is one of at least one frequency band supported by the slave device. In one example, the frequency bands supported by the slave device may include 2.4 GHz and 5 GHz, and the first frequency band is any one of 2.4 GHz and 5 GHz. In another example, the frequency bands supported by the slave device may include at least one of 2.4 GHz, 5 GHz, and 6 GHz, and the first frequency band is any one of 2.4 GHz, 5 GHz, and 6 GHz. In yet another example, the frequency bands supported by the slave device may include at least one of 2.4 GHz, 5 GHz, 5 GHz low frequency (5G-Low), and 5 GHz high frequency (5G-High), and the first frequency band is any one of 2.4 GHz, 5 GHz, 5 GHz low frequency (5G-Low), and 5 GHz high frequency (5G-High). In yet another example, the slave device only supports 2.4 GHz, and the first frequency band is 2.4 GHz. In yet another example, the slave device only supports 5 GHz, and the first frequency band is 5 GHz. It should be noted that with the development of communication technology, the types of frequency bands supported by the equipment can be expanded, and examples will not be listed here.

[0194] It should be noted that, since the first message includes both first and third indication information, the first indication information can also be understood as indicating the authentication and encryption modes supported by the slave device when operating in the first frequency band. For example, if the first indication information indicates authentication and encryption modes as "WEP-64" and "WEP-128", and the third indication information indicates the first frequency band as "2.4GHz", it means that when the slave device operates in 2.4GHz, it supports both "WEP-64" and "WEP-128" authentication and encryption modes. The master device configures the slave device with either "WEP-64" or "WEP-128" encryption, and the slave device can operate normally and obtain security protection in 2.4GHz. In other words, the slave device reports its authentication and encryption capabilities by frequency band. When the slave device supports two or more frequency bands, it reports the corresponding authentication and encryption modes for each frequency band to the master device through different messages. For example, if the slave device supports two frequency bands (e.g., 2.4GHz and 5GHz), it reports its authentication and encryption capabilities to the master device through two messages. For example, the slave device sends a first message #1 to the master device. The first message #1 includes a first indication information #1 and a third indication information #1. The first indication information #1 indicates that the supported authentication encryption modes are "WEP-64" and "WEP-128". The third indication information #1 indicates that the first frequency band is "2.4GHz", meaning that when the slave device operates at 2.4GHz, the slave device supports both "WEP-64" and "WEP-128" authentication encryption modes. The slave device then sends a first message #2 to the master device. The first message #2 includes a first indication information #2 and a third indication information #2. The first indication information #2 indicates that the supported authentication encryption modes are "WPA-Personal" and "WPA2-Personal". The third indication information #2 indicates that the first frequency band is "5GHz", meaning that when the slave device operates at 5GHz, the slave device supports both "WPA-Personal" and "WPA2-Personal" authentication encryption modes.

[0195] Therefore, it is evident that reporting authentication and encryption capabilities by frequency band allows the master device to accurately determine which authentication and encryption modes are supported when the slave device operates in a specific frequency band. This, in turn, enables the master device to configure the appropriate authentication and encryption modes for the slave device operating in that frequency band, improving the adaptability of the configured authentication and encryption modes and enhancing system security. Furthermore, the electronic components and software algorithms of the processing chips for different frequency bands within the slave device are relatively independent; that is, authentication and encryption algorithms for different frequency bands are generally encapsulated in processing chips for different frequency bands. Reporting authentication and encryption capabilities for different frequency bands in separate messages allows for the independent enabling of authentication and encryption methods operating in different frequency bands. For example, it allows the master device to configure different authentication and encryption methods for different operating frequency bands of the same slave device, increasing the flexibility of the slave device in authenticating and encrypting terminal devices.

[0196] It should be noted that a master device can manage at least one slave device simultaneously. Therefore, each slave device managed by the master device can send a first message to the master device, and correspondingly, the master device receives at least one first message, each originating from at least one slave device. Each first message sent by the at least one slave device contains first indication information, although the authentication and encryption modes indicated by the first indication information sent by different slave devices are not entirely the same. For example, the master device may receive a first message #1 from slave device 1 and a first message #2 from slave device 2. The first indication information #1 in first message #1 indicates that slave device 1 supports three authentication and encryption modes: "WEP-64", "WEP-128", and "WPA-Personal". The first indication information #2 in first message #2 indicates that slave device 2 supports two authentication and encryption modes: "WPA-Personal" and "WPA2-Personal".

[0197] Optionally, each slave device may also send a first message including third indication information. For example, the master device may receive a first message #1 from slave device 1 and a first message #2 from slave device 2. In the first message #1, the first indication information #1 indicates that slave device 1 supports three authentication and encryption modes: "WEP-64", "WEP-128", and "WPA-Personal". The third indication information #1 in the first message #1 indicates the 2.4 GHz frequency band. In the first message #2, the first indication information #2 indicates that slave device 2 supports two authentication and encryption modes: "WPA-Personal" and "WPA2-Personal". The third indication information #2 in the first message #2 also indicates the 2.4 GHz frequency band.

[0198] It should also be noted that the first message can be a message sent proactively by the slave device to the master device, or a message sent by the slave device to the master device based on a request from the master device. Examples are given below for each:

[0199] In one possible implementation, the slave device sends a first message to the master device in response to a request from the master device. For example, during the initialization phase, the master device sends a device capability parameter request message to the slave device, requesting the slave device to report its capability parameters (e.g., the slave device's authentication and encryption capabilities, i.e., at least one authentication and encryption method supported by the slave device). In response to the capability parameter request from the master device, the slave device sends a device capability report to the master device, which carries the capability parameters (e.g., the slave device's authentication and encryption capabilities) that the master device expects to obtain. In this example, the device capability report is the first message described in this embodiment. The master device's on-demand request for capability parameters (e.g., authentication and encryption capabilities) from the slave device improves the flexibility of obtaining capability parameters.

[0200] In another possible implementation, the slave device proactively sends a first message to the master device. For example, after the slave device comes online, during the initialization phase, the slave device proactively sends a first message to the master device. This first message carries first indication information indicating the slave device's authentication and encryption capabilities. This allows the master device to know the slave device's authentication and encryption capabilities as soon as it comes online, thereby improving the efficiency of the master device in managing slave devices.

[0201] Step 202: The master device sends a second message to the slave device; correspondingly, the slave device receives the second message from the master device.

[0202] In this embodiment, step 202 is an optional step.

[0203] For example, the master device sends a second message to the slave device via an optical fiber or composite cable; correspondingly, the slave device receives the second message from the master device via an optical fiber or composite cable.

[0204] The second message includes a second instruction, which instructs the slave device to use the first authentication encryption mode. This can be understood as the second instruction instructing the master device to configure the slave device to enable an authentication encryption mode. Upon receiving the second instruction, the slave device configures and activates the first authentication encryption mode. When a terminal device requests network access through the slave device, the slave device uses this first authentication encryption mode to authenticate the terminal device and verify its key.

[0205] It should be noted that the master device can manage at least one slave device simultaneously. Therefore, the master device can send at least one second message, with each second message corresponding one-to-one with at least one slave device. That is, each of the at least one slave device receives the second message and obtains the second indication information carried in it, thus enabling at least one slave device to configure and activate the first authentication encryption mode. Consequently, at least one slave device performs identity authentication and key verification on the terminal devices awaiting network access based on the first authentication encryption mode. Therefore, by negotiating the use of the first authentication encryption mode through signaling between the master device and at least one slave device, at least one slave device can uniformly use a single authentication encryption mode. This not only improves network security but also eliminates the need for additional adaptation processing when terminal devices roam between devices, reducing processing complexity, saving energy, and improving service stability and reliability.

[0206] Optionally, the first authentication encryption mode is an authentication encryption mode supported by at least one slave device. Optionally, the first authentication encryption mode is determined by the master device based on first indication information in a first message from at least one slave device. For example, the master device may receive a first message #1 from slave device 1 and a first message #2 from slave device 2, wherein the first indication information #1 in the first message #1 indicates that slave device 1 supports three authentication encryption modes: "WEP-64", "WEP-128", and "WPA-Personal", and the first indication information #2 in the first message #2 indicates that slave device 2 supports two authentication encryption modes: "WPA-Personal" and "WPA2-Personal". The master device can determine that the authentication encryption mode supported by both slave device 1 and slave device 2 (i.e., "WPA-Personal") is the first authentication encryption mode. Then, the master device sends a second message #1 and a second message #2 to slave device 1 and slave device 2 respectively, both of which carry a second indication information indicating "WPA-Personal". Therefore, it is evident that if the master device blindly configures an authentication and encryption mode for a slave device when the slave device lacks reported authentication and encryption capabilities, it may configure an encryption method that the slave device does not support, or configure an encryption method with a low level of security. In this embodiment, the master device can select an authentication and encryption mode supported by the slave device as the authentication and encryption mode used by the slave device, increasing the probability of successful configuration and thus improving network security. Furthermore, by determining an authentication and encryption mode supported by multiple slave devices based on their authentication and encryption capabilities, and using this mode for all slave devices, the master device increases the probability of successful configuration of the authentication and encryption mode for multiple slave devices, thereby further improving network security.

[0207] Optionally, the first authentication encryption mode is the same as the authentication encryption mode used by the master device. For example, if the master device has WLAN functionality, the authentication encryption mode used by the slave device is the same as that used by the master device. That is, the first authentication encryption mode determined by the master device is the authentication encryption mode supported by the master device, and both the master device and the slave device use the first authentication encryption mode. For example, if the authentication encryption modes supported by the master device are "WPA-Personal" and "WPA2-Personal", the authentication encryption modes supported by slave device 1 are "WEP-64", "WEP-128" and "WPA-Personal", and the authentication encryption modes supported by slave device 2 are "WPA-Personal" and "WPA2-Personal", then the master device can determine "WPA-Personal" as the first authentication encryption mode. This is beneficial for achieving a unified authentication encryption mode across the entire network. Even if the terminal device roams between the master device and the slave device, the terminal device does not need to adapt to roaming processes with various authentication methods, which helps reduce the complexity of the terminal device and saves its energy consumption.

[0208] Optionally, when multiple authentication and encryption modes are available, the master device can select based on security level from highest to lowest, or based on a preset priority level from highest to lowest. For example, if multiple devices support WPA3, the master device determines that the aforementioned devices use WPA3-Enterprise, and there is no mixed EAP authentication; if some devices support WPA2 and some devices support WPA3, or all devices support WPA2, the master device determines that the aforementioned devices use WPA2-Enterprise; if some devices support WPA2 and some devices support WPA, or all devices support WPA, the master device determines that the aforementioned devices use WPA-Enterprise. These multiple devices can all be slave devices, or they can include both a master device and slave devices.

[0209] Optionally, the second message may also include third indication information. For an explanation of the third indication information, please refer to the relevant description in step 201 above; it will not be repeated here. It should be noted that, since the second message includes both second and third indication information, the second indication information can also be understood as instructing the slave device to use the first authentication encryption mode when operating in the first frequency band. Alternatively, it can be understood that the first authentication encryption mode indicated by the second indication information corresponds to the first frequency band indicated by the third indication information. For example, the slave device activates the first authentication encryption mode based on the second indication information in the received second message, and configures the first authentication encryption mode to be used when operating in the first frequency band based on the third indication information in the second message.

[0210] It should also be noted that the second message can be a message sent proactively by the master device to the slave device, or a message sent by the master device to the slave device in response to the first message. Examples are given below for each:

[0211] In one possible implementation, the master device proactively sends a second message to the slave device. For example, after the master device knows the authentication and encryption modes supported by the slave device, it sends a working parameter configuration (Config) message to the slave device. This Config message carries working parameter configuration information configured by the master device for the slave device (e.g., second indication information indicating the first authentication and encryption mode, third indication information indicating the first frequency band, etc.). The slave device completes parameter configuration according to the working parameter configuration information in the Config message (e.g., activating the first authentication and encryption mode and configuring the first authentication and encryption mode to be used when operating in the first frequency band). Optionally, after completing parameter configuration, the slave device sends a working parameter configuration report (Report) message to the master device. The Working Parameter Configuration Report (Report) message is used to provide feedback on the configuration results. In this example, the working parameter configuration (Config) message is the second message described in this embodiment.

[0212] In another possible implementation, the master device sends a second message to the slave device in response to the first message. For example, after receiving at least one first message from at least one slave device, the master device sends a response message (i.e., the second message) to at least one slave device.

[0213] In this embodiment, the master device and at least one slave device negotiate the use of a first authentication and encryption mode via signaling. This enables at least one slave device to uniformly use a single authentication and encryption mode, which not only improves network security but also eliminates the need for additional adaptation processing when terminal devices roam between devices. This reduces the processing complexity of terminal devices (e.g., lowers the requirements for roaming processes with different security levels), saves energy consumption, and improves service stability and reliability. Furthermore, the master device can select an authentication and encryption mode from those supported by the slave devices, increasing the probability of successful configuration and further enhancing network security.

[0214] It should be noted that the embodiments provided in this application (e.g., Figure 2A Corresponding embodiments, Figure 3 Corresponding embodiments and Figure 4In the corresponding embodiment, when applied to an FTTR scenario, the signaling interaction described in the aforementioned embodiment occurs during the initialization phase. During the initialization phase, the master device obtains the basic capability information of the slave device (including supported authentication and encryption modes and supported frequency bands) through the initialization process and completes the configuration of the slave device's basic operating parameters. For example, it completes the configuration of the authentication and encryption mode used by the slave device and the corresponding frequency band.

[0215] like Figure 2B As shown, taking the master device as MFU and the slave device as SFU as an example, the initialization process mainly includes the following steps:

[0216] a) The MFU sends a Device Capability Parameter (Request) message, requesting the SFU to report the relevant device capability parameters.

[0217] b) After receiving the SFU, it feeds back the parameters through the equipment capability (Report).

[0218] c) After receiving the equipment capability parameters, the MFU sends the basic operating parameter configuration information of the SFU through the operating parameter configuration (Config).

[0219] d) After receiving the message, SFU completes the parameter configuration according to the parameters in the message and provides feedback on the configuration results through the working parameter configuration report.

[0220] After receiving feedback, the MFU completes the initialization process.

[0221] Since the master device completes the configuration of authentication and encryption modes for the slave device according to frequency band during the initialization phase, it does not need to configure the authentication and encryption modes for the slave device again in subsequent feature configuration processes. For example, if the slave device has roaming capabilities, the master device does not need to configure authentication and encryption modes for roaming capabilities when configuring the slave device's roaming functionality, saving the signaling overhead required for subsequent roaming security configuration and improving the configuration efficiency of the master device.

[0222] It should be noted that when the optical communication method provided in this application is applied to an FTTR scenario, the first message and the second message can be WMCI messages. WMCI messages are used to manage or control the WLAN function of the slave device. The first message and the second message are described below with reference to examples:

[0223] In one possible implementation, the first message is a message for reporting slave device capability parameters, that is, reporting parameters from the slave device capability parameter set. The slave device's authentication encryption mode and frequency band are parameters from the slave device's WLAN capability parameter set.

[0224] Optionally, in addition to the first indication information and the third indication information, the first message also includes a seventh indication information, which is used to indicate the device capability parameter set of the slave device's WLAN. The device capability parameter set of the slave device's WLAN includes the slave device's authentication encryption mode parameters and the slave device's frequency band parameters.

[0225] Optionally, the seventh indication information is located in the message type identifier field of the first message.

[0226] Optionally, the message content field of the first message also includes a parameter mask field, which includes a ninth indication information and a tenth indication information. The ninth indication information indicates the authentication encryption mode parameters of the slave device; that is, the ninth indication information indicates that the first message carries parameters related to the authentication encryption mode of the slave device. The tenth indication information indicates the frequency band parameters of the slave device; that is, the tenth indication information indicates that the first message carries parameters related to the frequency band of the slave device.

[0227] Optionally, the message content field of the first message may also include first instruction information and third instruction information. For an explanation of the first instruction information and third instruction information, please refer to the relevant introduction in step 201 above; it will not be repeated here.

[0228] For example, Table 2-1 below is an example of a first message.

[0229] Table 2-1

[0230]

[0231]

[0232] As shown in Table 2-1, the first byte is the message type identifier field (also called the message type ID field), used to indicate the type of message and define the semantics of the message content. The message type identifier field can carry a seventh indication, indicating that the message type is a message related to the slave device's capability parameter set. The second byte is the sequence number (SeqNo) field, containing a sequence number counter used to ensure the robustness of the WMCI message delivery channel. In the downlink direction, the sequence number field is filled with the value of the corresponding master device's sequence number counter. The master device maintains a separate sequence number counter for each slave device's unicast and broadcast WMCI message stream. Each sequence number counter rolls from 255 to 1, and the value 0 is not used in the downlink. In the uplink direction, when an uplink WMCI message is a response to a downlink WMCI message, the value of the SeqNo field is equal to the value of the SeqNo field in the downlink WMCI message. If the WMCI message is initiated by the slave device, then SeqNo = 0 is used. The 3rd and 4th bytes are the message length and processing requirement fields, consisting of three fields: message priority (i.e., message processing requirement), operation type, and message content length. Specifically, X (the most significant bit of the 3rd byte) indicates the priority of processing this message. When X=1, the message has a high priority; when X=0, the message has a low priority. C indicates the operation type of this message. In the downlink direction, when C=1, it indicates that the operation type of this message is a parameter request type, meaning the master device requests the slave device to send the slave device's parameters to the master device; when C=0, it indicates that the operation type of this message is a parameter configuration type, meaning the master device sends the slave device's configuration parameters to the slave device. In the uplink direction, when C=1, the operation type of this message is a scheduling request, indicating that the slave device requests the master device to send parameters for scheduling the slave device, i.e., the master device requests the slave device to send scheduling parameters for the slave device. When C=0, the operation type of this message is a parameter reporting or alarm type, indicating that the slave device reports its parameters or alarm information to the master device. LL LLLL LLLL: indicates the length of the message content, ranging from 0 to 1023. The remaining 4 bits RRRR are reserved. In addition, bytes 5 to N are the message content field, used to carry the specific content of the message, which is related to the specific message. Among them, bytes 5 and 6 are used to carry the parameter mask (called the parameter mask field), which is used to indicate the parameters in the parameter set corresponding to the first message.For example, the parameter mask field is used to indicate which parameters in the parameter set need to be requested, configured, or reported. It should be noted that since the parameter mask is 16 bits (2 bytes), a parameter set can contain a maximum of 16 parameters, and each parameter set message type can carry a maximum of 16 parameters. Furthermore, bytes 7 through N are used to carry the parameter content of the parameters indicated by the parameter mask. The parameter content should be filled into the message content in the order indicated by the parameter mask. For downlink request messages, the parameter mask represents the parameters the master device wants to obtain. For uplink messages, the parameter mask represents the parameters reported and replied to. Here, N is an integer greater than 7. Bytes (N+1) through (N+4) are message integrity check fields, 4 bytes in size, used to verify the sender's identity and prevent forged WMCI message attacks. This field follows the cyclic redundancy check (CRC) function.

[0233] In this example, the parameter mask field carries ninth and tenth indication information. The ninth indication information corresponds to a specific bit in the parameter mask field, and the tenth indication information corresponds to the other bit. The position of the ninth indication information in the parameter mask field is related to the order of the slave device's authentication encryption mode parameters in the device capability parameter set, and the position of the tenth indication information in the parameter mask field is related to the order of the slave device's frequency band parameters in the device capability parameter set. For ease of understanding, a specific example will be provided below:

[0234] In one example, the slave device WLAN includes a set of device capability parameters, which comprises parameters related to the slave device's WLAN capabilities. These parameters include, for example, WMCI version number, WMCI feature, IEEE 802.11 version number, supported security modes (i.e., supported authentication and encryption modes), number of frequency bands, and the capability of the frequency band. The capability of the frequency band includes: band number, frequency band, number of supported service set identifiers (SSIDs), supported transmission power level, number of supported transmission power level, and frequency bandwidth.

[0235] For example, the meanings of the various parameters included in the device capability parameter set of the device WLAN are shown in Table 3 below:

[0236] Table 3

[0237]

[0238]

[0239] It should be noted that the order of the authentication and encryption modes included in the supported authentication and encryption mode parameters listed in Serial Number 4 of Table 3 is used as an example. For instance, if the supported authentication and encryption mode parameter set includes None, WEP-64, WEP-128, WPA-Personal, WPA2-Personal, WPA-WPA2-Personal, WPA3-SAE, WPA2-WPA3-PSK-SAE, WPA-Enterprise, WPA2-Enterprise, WPA-WPA2-Enterprise, and WPA3-Enterprise in sequence, then the bit map of the supported authentication and encryption modes in Table 2-2 may include: Bit 0: Whether authentication and encryption are not supported; Bit 1: Whether WEP-64 is supported; Bit 2: Whether WEP-64 is supported; Bit 3: Whether WEP-64 is supported; Bit 4: Whether WEP-64 is supported; Bit 5: Whether WEP-64 is supported; Bit 6: Whether WEP-64 is supported; Bit 7: Whether WEP-64 is supported; Bit 8: Whether WEP-64 is supported; Bit 9: Whether WEP-64 is supported; Bit 1: Whether WEP-64 is supported; Bit 1: Whether WEP-64 is supported; Bit 1: Whether WEP-64 is supported; Bit 1: Whether WEP-64 is supported; Bit 1: Whether WEP-64 is supported; Bit 1: Whether WEP-64 is supported; Bit 1: Whether WEP-64 is supported; Bit 1: Whether WEP-64 is supported; Bit 2 ... Bit 2: Whether WEP-128 is supported; Bit 3: Whether WPA-Personal is supported; Bit 4: Whether WPA2-Personal is supported; Bit 5: Whether WPA-WPA2-Personal is supported; Bit 6: Whether WPA3-SAE is supported; Bit 7: Whether WPA2-WPA3-PSK-SAE is supported; Bit 8: Whether WPA-Enterprise is supported; Bit 9: Whether WPA2-Enterprise is supported; Bit 10: Whether WPA-WPA2-Enterprise is supported; Bit 11: Whether WPA3-Enterprise is supported. Other bitmap examples may exist as the specific methods included in the supported authentication encryption modes change, or the order of the parameters included in the supported authentication encryption modes changes; these will not be listed here.

[0240] For example, if the supported authentication encryption modes are in the order shown in Table 3, then an example of the first message can be shown in Table 2-2 below:

[0241] Table 2-2

[0242]

[0243]

[0244] In the first message shown in Table 2-2, the message type identifier field carries the seventh indication information, indicating that the first message is used to carry parameters from the device capability parameter set of the slave device's WLAN. In the message length and processing requirement fields, bit 7 is 0, indicating that the first message in uplink transmission is used to report parameters. Bit A (i.e., bit 5 of the 5th byte) in the parameter mask field is the ninth indication information; when bit A is 1, it indicates that the first message carries the authentication and encryption mode parameters supported by the device capability parameter set of the slave device's WLAN. Bit B (i.e., bit 3 of the 5th byte) in the parameter mask field is the tenth indication information; when bit B is 1, it indicates that the first message carries the frequency band parameters supported by the device capability parameter set of the slave device's WLAN. Furthermore, in the parameter content field, two bytes (e.g., bytes 7-8) carry the first indication information, indicating the specific mode of the authentication and encryption mode supported by the slave device, represented by a bitmap; a bit of 1 indicates support for the authentication and encryption mode, and a bit of 0 indicates no support for the authentication and encryption mode. For example, if the device supports "WEP-64" and "WEP-128", then only bits 1 and 2 in bytes 7 and 8 are set to 1, and the remaining bits are set to 0. Another byte of the parameter content field (e.g., byte 9) carries third indication information, indicating a frequency band supported by the device, specifically the frequency band used when the device supports the aforementioned authentication and encryption modes (e.g., "WEP-64" and "WEP-128"). For example, if byte 9 is 0, it indicates that the device supports 2.4GHz, and the first message indicates that when the device operates at 2.4GHz, it supports "WEP-64" and "WEP-128" authentication and encryption modes, and other authentication and encryption modes are not supported. As another example, if byte 9 is 1, it indicates that the device supports 5GHz, and the first message indicates that when the device operates at 5GHz, it supports "WEP-64" and "WEP-128" authentication and encryption modes, and other authentication and encryption modes are not supported. The same logic applies to other frequency bands; examples are not listed here. For explanations of the remaining fields in the example shown in Table 2-2, please refer to the relevant introduction in the example shown in Table 2-1 above; they will not be repeated here.

[0245] In this embodiment, the slave device reports the authentication and encryption modes supported by a certain frequency band to the master device through a message (e.g., a first message). This allows the master device to know the authentication and encryption capabilities of the slave device when operating in a certain frequency band, and thus enables the master device to configure an authentication and encryption mode suitable for use in that operating frequency band, achieving frequency band-based on-demand protection. Furthermore, it reduces the probability of the master device configuring an inappropriate authentication and encryption mode, thereby improving the security of both the slave device and the terminal device.

[0246] In one possible implementation, the second message is a message for configuring the operating parameters of the slave device, that is, configuring parameters in the slave device's operating parameter configuration parameter set. The slave device's authentication encryption mode and frequency band are parameters in the slave device's WLAN operating parameter configuration parameter set.

[0247] Optionally, in addition to the second indication information and the third indication information, the second message also includes an eighth indication information, which is used to indicate the WLAN operating parameter configuration parameter set of the slave device. The WLAN operating parameter configuration parameter set of the slave device includes the authentication encryption mode parameter and the frequency band parameter of the slave device.

[0248] Optionally, the eighth indication information is located in the message type identifier field of the second message.

[0249] Optionally, the message content field of the second message also includes a parameter mask field, which includes a ninth indication information and a tenth indication information. The ninth indication information indicates the authentication encryption mode parameters of the slave device; that is, the ninth indication information indicates that the second message carries parameters related to the authentication encryption mode of the slave device. The tenth indication information indicates the frequency band parameters of the slave device; that is, the tenth indication information indicates that the second message carries parameters related to the frequency band of the slave device.

[0250] Optionally, the message content field of the second message may also include second instruction information and third instruction information. For an explanation of the second and third instruction information, please refer to the relevant descriptions in steps 201 and 202 above; they will not be repeated here.

[0251] For example, Table 4-1 below is an example of a second message.

[0252] Table 4-1

[0253]

[0254] As shown in Table 4-1, the first byte is the message type identifier field, used to indicate the message type and define the semantics of the message content. The message type identifier field can carry the eighth indication information, indicating that the message type is a message related to the working parameter configuration parameter set. The second byte is the sequence number (SeqNo) field. Bytes 3 and 4 are the message length and processing requirement fields, consisting of three fields: message priority (i.e., message processing requirement), operation type, and message content length. Please refer to the relevant introduction in the example shown in Table 2-1 above for details, which will not be repeated here. In addition, bytes 5 to N are the message content fields, used to carry the specific content of the message, which is related to the specific message. Among them, bytes 5 and 6 are used to carry the parameter mask (called the parameter mask field), which is used to indicate the parameters in the parameter set corresponding to the first message. In addition, bytes 7 to N are used to carry the parameter content of the parameters indicated by the parameter mask, and the parameter content should be filled into the message content according to the order indicated by the parameter mask. For downlink request messages, the parameter mask represents the parameters the master device wants to obtain. For uplink messages, the parameter mask represents the parameters reported and replied to. Here, N is an integer greater than 7. Bytes (N+1) to (N+4) are message integrity check fields.

[0255] In this example, the parameter mask field carries ninth and tenth indication information. The ninth indication information corresponds to a specific bit in the parameter mask field, and the tenth indication information corresponds to the other bit. The position of the ninth indication information in the parameter mask field is related to the order of the slave device's authentication encryption mode parameters in the working parameter configuration parameter set, and the position of the tenth indication information in the parameter mask field is related to the order of the slave device's frequency band parameters in the working parameter configuration parameter set. For ease of understanding, a specific example will be provided below:

[0256] In one example, the slave device WLAN operating parameter configuration parameter set includes parameters related to the slave device's WLAN operating parameter configuration. These parameters include, for example, frequency band number, SSID length, SSID, password length, password, security modes, frequency band selection, frequency channel, channel width, and transmission power level.

[0257] For example, the meanings of the various parameters included in the device WLAN operating parameter configuration parameter set are shown in Table 5-1 or Table 5-2 below:

[0258] Table 5-1

[0259]

[0260]

[0261] In the example shown in Table 5-1, the security mode of the slave device (i.e., the authentication encryption mode used by the slave device) is defined in the form of a bitmap.

[0262] Table 5-2

[0263]

[0264]

[0265] In the example shown in Table 5-2, the security mode of the slave device (i.e., the authentication encryption mode used by the slave device) is defined in the form of an enumeration value.

[0266] For example, if the supported authentication encryption modes are in the order shown in Table 5-1, and the security mode of the slave device (i.e., the authentication encryption mode used by the slave device) is defined in the form of a bitmap, then an example of the second message can be shown in Table 4-2 below:

[0267] Table 4-2

[0268]

[0269]

[0270] In the second message shown in Table 4-2, the message type identifier field carries the eighth indication information, indicating that the second message is used to carry parameters from the slave device's WLAN operating parameter configuration parameter set. In the message length and processing requirement fields, bit 7 is 0, indicating that the second message in downlink transmission is used to configure parameters for the slave device. Bit E (i.e., bit 3 of the 5th byte) in the parameter mask field is the ninth indication information; bit E is 1, indicating that the second message carries the authentication and encryption mode parameters used in the slave device's WLAN operating parameter configuration parameter set. Bit F (i.e., bit 2 of the 5th byte) in the parameter mask field is the tenth indication information; bit F is 1, indicating that the second message carries the frequency band parameters used in the slave device's WLAN operating parameter configuration parameter set. Furthermore, in the parameter content field, two bytes (e.g., bytes 7-8) carry the second indication information, indicating an authentication and encryption mode configured by the master device for the slave device (e.g., the first authentication and encryption mode described above), represented by a bitmap, as shown in the 6th field of Table 5-1. Bit 1 indicates that the authentication and encryption mode is used or configured, and bit 0 indicates that the authentication and encryption mode is not used or configured. For example, if the master device configures the slave device with "WEP-128", then only bit 2 in bytes 7 and 8 is 1, and the rest are 0. Another byte of the parameter content field (e.g., byte 9) carries third indication information, indicating the frequency band used by the slave device, specifically the frequency band used when the slave device uses the aforementioned authentication and encryption mode (e.g., "WEP-128"). For example, if byte 9 is 0, it indicates that the slave device uses 2.4GHz, and the second message indicates that the master device configures the slave device to use the "WEP-128" authentication and encryption mode when operating at 2.4GHz, and not other authentication and encryption modes. As another example, if byte 9 is 1, it indicates that the slave device uses 5GHz, and the second message indicates that the master device configures the slave device to use the "WEP-128" authentication and encryption mode when operating at 5GHz, and not other authentication and encryption modes. The same logic applies to other frequency bands; examples are not listed here. For explanations of the remaining fields in the examples shown in Table 4-2, please refer to the relevant introductions in the examples shown in Table 2-1, Table 2-2, or Table 4-1 above; they will not be repeated here.

[0271] For example, if the supported authentication encryption modes are in the order shown in Table 5-2, and the security mode of the slave device (i.e., the authentication encryption mode used by the slave device) is defined in the form of an enumeration value, then an example of the second message can be shown in Table 4-3 below:

[0272] Table 4-3

[0273]

[0274]

[0275] The difference between the example shown in Table 4-3 and the example shown in Table 4-2 lies in the parameter content field. In the parameter content field, two bytes (e.g., bytes 7-8) carry second indication information, indicating the authentication encryption mode configured by the master device for the slave device (e.g., the first authentication encryption mode described earlier). This is represented by an enumeration value, as shown in the sixth field of Table 5-2: a byte value of 0 indicates None, meaning no authentication encryption is performed; a byte value of 1 indicates the use of "WEP-64"; a byte value of 2 indicates the use of "WEP-128"; and so on. For example, if the master device configures "WEP-128" for the slave device, then bytes 7-8 will have a value of 2. The other byte of the parameter content field (e.g., byte 9) carries third indication information, indicating a frequency band used by the slave device, i.e., the frequency band used when the slave device uses the aforementioned authentication encryption mode (e.g., "WEP-128"). For example, if byte 9 has a value of 0, it indicates that the slave device uses 2.4GHz. The second message carries the message that the master device configures the slave device to use the "WEP-128" authentication and encryption mode when operating at 2.4GHz, and not to use other authentication and encryption modes. As another example, if byte 9 has a value of 1, it indicates that the slave device uses 5GHz. The second message carries the message that the master device configures the slave device to use the "WEP-128" authentication and encryption mode when operating at 5GHz, and not to use other authentication and encryption modes. The same logic applies to other frequency bands; examples will not be listed here. For explanations of the remaining fields in the examples shown in Table 4-3, please refer to the relevant descriptions in Tables 2-1, 2-2, 4-1, or the examples shown in Table 4-2 above; they will not be repeated here.

[0276] In this embodiment, the master device can configure an authentication and encryption mode for a specific frequency band for the slave device. This allows the master device to configure an authentication and encryption mode suitable for use in that operating frequency band, achieving on-demand protection based on the frequency band. Furthermore, it reduces the likelihood of the master device configuring an inappropriate authentication and encryption mode, thus improving the security of the slave device and the terminal device.

[0277] The parameters in Table 3 above (such as WMCI version number, WMCI feature parameter set, IEEE 802.11 version number, supported security modes, number of frequency bands, frequency band number, frequency band, number of supported SSIDs, supported transmit power, class, number of antennas, channel width, and capability of another frequency band), as well as the parameters in Tables 5-1 and 5-2 (such as frequency band number, SSID length, SSID, password length, password, security mode, frequency band selection, frequency domain channel, channel width, and transmit power class), can be represented in the message not only in the masked form shown in 5-N bytes in Table 2-1, but also in other forms. For example, one or more of the above parameters can be represented in the message using the type-length-value (TLV) format. Each TLV can carry one parameter or multiple parameters. If a TLV carries multiple parameters, these parameters can be used as the "value" of the TLV, or multiple parameters can be carried as sub-TLVs. For example, the “value” of a TLV can include two parameters: Password and Password length, or the TLV can include at least two sub-TLVs, one of which has the “value” of Password and the other has the “value” of Password length.

[0278] Furthermore, each parameter can be carried by one message or by multiple messages. If a parameter is carried by multiple different messages, it can be an optional parameter in one or some messages, or a required parameter in another or some messages.

[0279] If the above parameters are represented in TLV format, the format of the WMCI message can be shown in Table 5 below:

[0280] Table 5

[0281]

[0282]

[0283] like Figure 3The diagram shows a flowchart of another embodiment of the optical network communication method provided in this application. In this embodiment, the interaction between a master device and a first slave device and a second slave device is used as an example. When some slave devices managed by the master device (e.g., the second slave device) go offline, the master device will determine whether to update the authentication and encryption mode used by the remaining active slave devices (e.g., the first slave device) based on their authentication and encryption capabilities. Of course, the entity executing the master device's actions in this method can also be a device, module, or chip within the master device; the entity executing the slave device's (e.g., the first or second slave device) actions in this method can also be a device, module, or chip within the slave device (e.g., the first or second slave device), and this embodiment does not specifically limit this. For example, as shown... Figure 3 As shown, the optical network communication method includes the following steps:

[0284] Step 301: The first slave device sends a first message 1 to the master device; correspondingly, the master device receives the first message 1 from the first slave device.

[0285] The first message 1 includes a first indication information 1, which is used to indicate at least one authentication encryption mode supported by the first slave device, that is, to indicate the authentication encryption capability of the first slave device.

[0286] Optionally, the first message 1 may also include third instruction information. For an explanation of the first and third instruction information, please refer to the relevant description in step 201 above; it will not be repeated here.

[0287] Step 302: The first slave device sends a first message 2 to the master device; correspondingly, the master device receives the first message 2 from the first slave device.

[0288] The first message 2 includes a first indication information 2, which is used to indicate at least one authentication encryption mode supported by the second slave device, that is, to indicate the authentication encryption capability of the second slave device.

[0289] Optionally, the first message 2 may also include a third instruction message.

[0290] Step 303: The master device sends a second message 1 to the first slave device; correspondingly, the first slave device receives the second message 1 from the master device.

[0291] The second message 1 includes a second instruction message, which is used to indicate the use of the first authentication encryption mode.

[0292] Optionally, the second message 1 may also include a third instruction. For an explanation of the second and third instruction, please refer to the relevant descriptions in steps 201 and 202 above; they will not be repeated here.

[0293] Step 304: The master device sends a second message 2 to the second slave device; correspondingly, the second slave device receives the second message 2 from the master device.

[0294] The second message 2 includes a second instruction message, which is used to indicate the use of the first authentication encryption mode.

[0295] Optionally, the second message 2 may also include a third instruction message.

[0296] Step 305: First slave device configuration activates the first authentication encryption mode.

[0297] For example, the first slave device obtains the second instruction information from the second message 1, and configures and activates the first authentication encryption mode based on the second instruction information. The first slave device uses the first authentication encryption mode to perform identity authentication and key authentication on terminal devices accessing the network through the first slave device, which helps to improve the security of the terminal devices.

[0298] Step 306: The second device configuration activates the first authentication encryption mode.

[0299] Step 307: The second slave device sends an offline notification message to the master device; correspondingly, the master device receives the offline notification message from the second slave device.

[0300] In this embodiment, step 307 is an optional step.

[0301] In one implementation, when the second slave device performs step 307, the master device can receive a shutdown notification message from the second slave device and know that the second slave device is about to go offline based on the shutdown notification message.

[0302] In another implementation, the master device can periodically detect the optical power of the optical signal at the port corresponding to the second slave device. When the master device cannot detect the optical signal at the port corresponding to the second slave device, or when the detected optical power is less than a preset value, the master device determines that the second slave device has gone offline or is about to go offline.

[0303] After the master device determines that the second slave device is offline, the master device can re-determine the authentication and encryption mode used by the remaining slave devices (e.g., the first slave device). For example, the master device determines a second authentication and encryption mode based on at least one authentication and encryption mode supported by the first slave device and at least one authentication and encryption mode supported by the master device. The second authentication and encryption mode is one that both the first slave device and the master device support. Optionally, the second authentication and encryption mode is one that both the first slave device and the master device support.

[0304] If the second authentication encryption mode determined by the master device is different from the first authentication encryption mode, that is, if the master device determines that the first slave device is more suitable for using the second authentication encryption mode than the first authentication encryption mode, then the master device will execute step 308, and the first slave device will execute step 309. If, after the master device determines the authentication method, it finds that the first slave device is still suitable for using the first authentication encryption mode, then the master device will not execute step 308, and the first slave device will not execute step 309.

[0305] Step 308: The master device sends a third message to the first slave device; correspondingly, the first slave device receives the third message from the master device.

[0306] The third message includes a fourth instruction message, which instructs the first slave device to use a second authentication encryption mode. The second authentication encryption mode is an authentication encryption mode supported by the first slave device and is different from the first authentication encryption mode.

[0307] Optionally, the third message may also include third indication information. The fourth indication information is further used to instruct the first slave device to use the second authentication encryption mode when operating in the first frequency band.

[0308] Step 309: First, the device configuration takes effect; second, the authentication encryption mode is activated.

[0309] In this embodiment, when the second slave device goes offline, the master device no longer considers the authentication and encryption capabilities of the offline second slave device, but only determines whether to update the authentication and encryption mode used by the slave device based on the authentication and encryption capabilities of the first slave device (and the master device). This facilitates the timely configuration of appropriate authentication and encryption modes for slave devices, thereby improving system security.

[0310] like Figure 4 The diagram shows a flowchart of another embodiment of the optical network communication method provided in this application. In this embodiment, the interaction between a master device and a first slave device, a second slave device, and a third slave device is used as an example. When the master device detects a newly connected slave device (e.g., the third slave device), the master device will determine whether to update the authentication and encryption modes used by each slave device based on the authentication and encryption capabilities of the existing slave devices (e.g., the first and second slave devices) and the newly connected slave device (e.g., the third slave device). Of course, the entity executing the master device's actions in this method can also be a device, module, or chip within the master device; the entity executing the slave device's (e.g., the first, second, or third slave device) actions in this method can also be a device, module, or chip within the slave device (e.g., the first, second, or third slave device), and this embodiment does not specifically limit this. For example, as shown... Figure 4 As shown, the optical network communication method includes the following steps:

[0311] Step 401: The first slave device sends a first message 1 to the master device; correspondingly, the master device receives the first message 1 from the first slave device.

[0312] Step 402: The first slave device sends a first message 2 to the master device; correspondingly, the master device receives the first message 2 from the first slave device.

[0313] Step 403: The master device sends a second message 1 to the first slave device; correspondingly, the first slave device receives the second message 1 from the master device.

[0314] Step 404: The master device sends a second message 2 to the second slave device; correspondingly, the second slave device receives the second message 2 from the master device.

[0315] Step 405: First slave device configuration activates the first authentication encryption mode.

[0316] Step 406: The second device configuration activates the first authentication encryption mode.

[0317] In this embodiment, steps 401 to 406 are the same as those described above. Figure 3 Steps 301 to 306 in the corresponding embodiment are similar. Please refer to the relevant descriptions of steps 301 to 306 above. They will not be repeated here.

[0318] Step 407: The third slave device sends a fourth message to the master device; correspondingly, the master device receives the fourth message from the third slave device.

[0319] The fourth message can be an online notification message or a response message to a capability reporting request sent by the master device.

[0320] The fourth message includes a fifth instruction message, which indicates at least one authentication encryption mode supported by the third slave device;

[0321] Optionally, the master device determines a third authentication encryption mode based on at least one authentication encryption mode supported by the first slave device, at least one authentication encryption mode supported by the second slave device, at least one authentication encryption mode supported by the third slave device, and at least one authentication encryption mode supported by the master device. The third authentication encryption mode is an authentication encryption mode supported by the first slave device, the second slave device, the third slave device, and the master device.

[0322] The master device sends a fifth message to the first slave device, the second slave device, and the third slave device, as shown in steps 408, 409, and 410 respectively.

[0323] Step 408: The master device sends a fifth message 1 to the first slave device; correspondingly, the first slave device receives the fifth message 1 from the master device.

[0324] Step 409: The master device sends a fifth message 2 to the second slave device; correspondingly, the second slave device receives the fifth message 2 from the master device.

[0325] Step 410: The master device sends a fifth message 3 to the third slave device; correspondingly, the third slave device receives the fifth message 3 from the master device.

[0326] The fifth message includes a sixth instruction message, which is used to indicate the use of a third authentication encryption mode. The third authentication encryption mode is an authentication encryption mode supported by the first slave device, the second slave device, and the third slave device. The third authentication encryption mode is different from the first authentication encryption mode.

[0327] Optionally, the fifth message may also include third indication information. The sixth indication information is further used to indicate that the slave device uses the third authentication encryption mode when operating in the first frequency band.

[0328] Step 411: First, the third authentication encryption mode is activated from the device configuration.

[0329] Step 412, the second device configuration takes effect, and the third authentication encryption mode is activated.

[0330] Step 413: The third slave device configuration activates the third authentication encryption mode.

[0331] In this embodiment, when the third slave device comes online, the master device determines whether to update the authentication and encryption mode based on the authentication and encryption capabilities of the first, second, and third slave devices (and the master device). This facilitates timely configuration of appropriate authentication and encryption modes for slave devices, thereby improving system security.

[0332] It should also be noted that the master and slave devices exchange the messages described above (e.g., the first message, the second message, the third message, the fourth message, the fifth message, etc.) through the WMCI management channel. Taking the second message as an example, the remaining messages are similar to the first message. The slave device sends the first message to the master device through the WMCI management channel; correspondingly, the master device receives the first message from the slave device through the WMCI management channel. Here, the management channel refers to the logical channel established between the master and slave devices for transmitting messages. The WMCI management channel is a logical channel established between the master and slave devices for transmitting WMCI messages. Generally, different management channels correspond to different logical port identifiers (port IDs). Different logical port identifiers may correspond to the same physical transceiver port, or they may correspond to different physical transceiver ports; this is not limited here. For example, the first management channel corresponds to the master device's Port ID1 and the first slave device's Port ID1, while other management channels correspond to the master device's Port ID2 and the first slave device's Port ID2. Port ID1 and Port ID2 may correspond to the same physical transceiver port, or they may correspond to different physical transceiver ports.

[0333] In addition, such as Figure 5A As shown, if the master device's rate level is 2.5G, the first message is encapsulated in the payload field of an FTTR Encapsulation Method (FEM) frame. The FEM port ID in the FEM frame header is assigned by the master device. This FEM port ID not only indicates that the first message is a WMCI message, but also indicates the sender and receiver of the WMCI message (i.e., the first message), that is, it indicates that the WMCI message (i.e., the first message) corresponds to the first slave device and not other slave devices. Therefore, the FEM port ID can be used to distinguish WMCI messages from other control messages in the FTTR system (e.g., FMCI messages or OMCI messages). It should be noted that when the master device's rate class is 2.5G, the downlink rate of the master device is 2.48832 Gbit / s; the uplink rate of the master device can be 1.24416 Gbit / s, or 2.48832 Gbit / s, and can support both simultaneously. The slave device's downlink rate is 2.48832 Gbit / s, and its uplink rate is 1.24416 Gbit / s or 2.48832 Gbit / s. It should also be noted that the payload length L of the FEM frame is equal to the length L of the WMCI message, where L is a positive integer.

[0334] In addition, such as Figure 5BAs shown, if the master device's rate class is 10G, the first message is encapsulated in the payload field of a 10G-FTTR Encapsulation Method (XFEM) frame. The XFEM port ID in the XFEM frame header is assigned by the master device. This XFEM port ID not only indicates that the first message is a WMCI message, but also indicates the sender and receiver of the WMCI message (i.e., the first message), that is, it indicates that the WMCI message (i.e., the first message) corresponds to the first slave device and not other slave devices. Therefore, the XFEM port ID can be used to distinguish WMCI messages from other control messages in the FTTR system. It should be noted that when the master device's rate class is 10G, the downlink rate of the master device is 9.95328 Gbit / s; the uplink rate of the master device can be 9.95328 Gbit / s, 2.48832 Gbit / s, or both simultaneously. The slave device's downlink rate is 9.95328 Gbit / s, and its uplink rate is either 9.95328 Gbit / s or 2.48832 Gbit / s. It should also be noted that the payload length P of the XFEM frame is an integer multiple of 4 bytes, but the length of the WMCI message may not be an integer multiple of 4 bytes. Therefore, the XFEM payload may need to include 0 to 3 bytes of padding fields while carrying the WMCI message.

[0335] In addition, such as Figure 5C As shown, the FEM frame is encapsulated in the payload field of the data link layer (DLL) frame. For example... Figure 5D As shown, XFEM frames are encapsulated in the payload field of DLL frames. A DLL frame consists of a DLL frame header and a DLL frame payload. The DLL payload is formed on the transmitting side and processed by the service adaptation sublayer on the receiving side. The DLL frame header consists of three fixed-size partitions (PLOAMd, BIP, Plend) and one variable-size partition: a bandwidth mapping partition (BWmap). The bandwidth mapping (BWmap) indicates the uplink transmission position in the corresponding uplink physical frame (PHY frame) for different slave devices.

[0336] It should be noted that, in Figure 5C The example shown only illustrates that the payload of the DLL frame contains three FEM frames. In practical applications, the payload of the DLL frame can contain other numbers of FEM frames; this is not limited here. Figure 5D In the example shown, the payload of the DLL frame contains 3 XFEM frames. In actual applications, the payload of the DLL frame can contain other numbers of XFEM frames, which is not limited here.

[0337] Furthermore, embodiments of this application also provide a communication device 60, such as... Figure 6 As shown, Figure 6 This is a schematic diagram of the structure of a communication device 60 provided in an embodiment of this application. Figure 2A , Figure 3 or Figure 4 The specific implementation of the master and slave devices in the flowchart shown can be found in [reference]. Figure 6 The internal structure of the communication device 60 shown. When the communication device 60 is used to implement... Figure 2A , Figure 3 or Figure 4 When the communication device 60 is used to implement the function of the master device in the method shown, it can be a master gateway or an MFU. Figure 2A , Figure 3 or Figure 4 When the method shown uses the slave device function, the communication device 60 can be a slave gateway or SFU.

[0338] like Figure 6 As shown, the communication device 60 may include a processor 601 and a transceiver 602, with the processor 601 coupled to the transceiver 602. The processor 601 may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The PLD may be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. The processor 601 may refer to a single processor or may include multiple processors; no specific limitation is made here.

[0339] The aforementioned transceiver 602 can also be referred to as a transceiver unit, transceiver, transceiver device, etc. Optionally, the device in the transceiver unit that performs the receiving function can be regarded as the receiving unit, and the device in the transceiver unit that performs the transmitting function can be regarded as the transmitting unit. That is, the transceiver unit includes a receiving unit and a transmitting unit. The receiving unit can also be referred to as a receiver, input port, receiving circuit, etc., and the transmitting unit can be referred to as a transmitter, transmitter, or transmitting circuit, etc.

[0340] Optionally, the communication device 60 further includes a memory 603. The processor 601 is coupled to the memory 603. The memory 603 is primarily used to store software programs and data. The memory 603 can exist independently, connected to the processor 601. Optionally, the memory 603 can be integrated with the processor 601, for example, integrated within one or more chips. The memory 603 can store program code executing the technical solutions of the embodiments of this application, and its execution is controlled by the processor 601. The various types of computer program code being executed can also be considered as drivers for the processor 601. The memory 603 can include volatile memory, such as random-access memory (RAM); the memory can also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid-state drive (SSD); the memory 603 can also include combinations of the above types of memory. Memory 603 can refer to a single memory or may include multiple memories. For example, memory 603 is used to store various types of data.

[0341] In one implementation, the communication device 60 is used to implement Figure 2A The corresponding method embodiment describes the function of the master device. Specifically, the transceiver 602 is used to receive at least one first message, which comes from at least one slave device. The first message includes first indication information, which indicates at least one authentication encryption mode supported by the corresponding slave device. The processor 601 is used to generate at least one second message. The transceiver 602 is also used to send at least one second message, which corresponds one-to-one with at least one slave device. The second message includes second indication information, which indicates that the corresponding slave device uses the first authentication encryption mode.

[0342] Wherein, at least one authentication encryption mode includes at least one of the following modes: 64-bit wired equivalent confidentiality WEP-64 mode; or, 128-bit wired equivalent confidentiality WEP-128 mode; or, user-oriented Wi-Fi protected access WPA-Personal mode; or, WPA2-Personal mode; or, WPA-WPA2-Personal mode; or, WPA3-SAE; or, WPA2-WPA3-PSK-SAE; or, enterprise-oriented Wi-Fi protected access WPA-Enterprise; or, WPA2-Enterprise; or, WPA-WPA2-Enterprise; or, WPA3-Enterprise.

[0343] In one possible implementation, the first authentication encryption mode is an authentication encryption mode supported by at least one slave device.

[0344] In one possible implementation, the first authentication encryption mode is the same as the authentication encryption mode used by the master device.

[0345] In one possible implementation, the first message further includes third indication information, which indicates a first frequency band supported by the slave device, wherein the first frequency band is one of at least one frequency band supported by the slave device. Optionally, the second message also includes the third indication information.

[0346] In one possible implementation, at least one slave device includes a first slave device and a second slave device;

[0347] The processor 601 is also configured to, after determining that the second slave device is offline, control the transceiver 602 to send a third message to the first slave device. The third message includes fourth indication information, which is used to instruct the first slave device to use a second authentication encryption mode. The second authentication encryption mode is an authentication encryption mode supported by the first slave device and is different from the first authentication encryption mode.

[0348] In one possible implementation, at least one slave device includes a first slave device and a second slave device;

[0349] The transceiver 602 is also configured to receive a fourth message from the third slave device, the fourth message including fifth indication information, the fifth indication information being used to indicate at least one authentication encryption mode supported by the third slave device; the processor 601 is also configured to generate a fifth message and control the transceiver 602 to send the fifth message to the first slave device, the second slave device and the third slave device respectively, the fifth message including a sixth indication information, the sixth indication information being used to indicate the use of a third authentication encryption mode, the third authentication encryption mode being an authentication encryption mode supported by the first slave device, the second slave device and the third slave device, the third authentication encryption mode being different from the first authentication encryption mode.

[0350] In one possible implementation, the third message further includes third instruction information; and / or, the fifth message further includes third instruction information.

[0351] In one possible implementation, the first message is a Wireless LAN Management and Control Interface (WMCI) message, and the second message is a WMCI message.

[0352] In one possible implementation, the first message further includes seventh indication information, which indicates the device capability parameter set of the slave device's WLAN. The slave device's WLAN device capability parameter set includes the slave device's authentication encryption mode parameters and the slave device's frequency band parameters. Optionally, the seventh indication information is located in the message type identifier field of the first message.

[0353] In one possible implementation, the second message further includes eighth indication information, which indicates the WLAN operating parameter configuration parameter set of the slave device. The slave device's WLAN operating parameter configuration parameter set includes the slave device's authentication encryption mode parameters and the slave device's frequency band parameters. Optionally, the eighth indication information is located in the message type identifier field of the second message.

[0354] In one possible implementation, the message content field of the first message further includes a parameter mask field, and the message content field of the second message further includes a parameter mask field. The parameter mask field includes a ninth indication information and a tenth indication information. The ninth indication information is used to indicate the authentication encryption mode parameter of the slave device, and the tenth indication information is used to indicate the frequency band parameter of the slave device.

[0355] In one possible implementation, the message content field of the first message further includes first instruction information and third instruction information; the message content field of the second message further includes second instruction information and third instruction information.

[0356] In one possible implementation, the first message is encapsulated in the payload field of a Fiber to the Room (FEM) frame, and the FEM port identifier in the frame header of the FEM frame is used to indicate the slave device corresponding to the first message. Optionally, the FEM frame is encapsulated in the payload field of a Data Link Layer (DLL) frame.

[0357] In another implementation, the communication device 60 is used to implement Figure 2A The corresponding method embodiment describes the function of the slave device. Specifically, the processor 601 is used to generate a first message; the transceiver 602 is used to send the first message to the master device, the first message including first indication information, the first indication information being used to indicate at least one authentication encryption mode supported by the slave device; the transceiver 602 is also used to receive a second message from the master device, the second message including second indication information, the second indication information being used to instruct the slave device to use a first authentication encryption mode, the first authentication encryption mode being one of at least one authentication encryption modes supported by the slave device;

[0358] At least one authentication encryption mode includes at least one of the following modes:

[0359] WEP-64 mode; or WEP-128 mode; or, user-oriented Wi-Fi protected access WPA-Personal mode; or, WPA2-Personal mode; or, WPA-WPA2-Personal mode; or, WPA3-SAE; or, WPA2-WPA3-PSK-SAE; or, enterprise-oriented Wi-Fi protected access WPA-Enterprise; or, WPA2-Enterprise; or, WPA-WPA2-Enterprise; or, WPA3-Enterprise.

[0360] In one possible implementation, the first authentication encryption mode is the same as the authentication encryption mode used by the master device.

[0361] In one possible implementation, the first message further includes third indication information, which indicates a first frequency band supported by the slave device, wherein the first frequency band is one of at least one frequency band supported by the slave device. Optionally, the second message also includes the third indication information.

[0362] In one possible implementation, the first message is a Wireless LAN Management and Control Interface (WMCI) message, and the second message is a WMCI message.

[0363] In one possible implementation, the first message further includes seventh indication information, which indicates the device capability parameter set of the slave device's WLAN. The slave device's WLAN device capability parameter set includes the slave device's authentication encryption mode parameters and the slave device's frequency band parameters. Optionally, the seventh indication information is located in the message type identifier field of the first message.

[0364] In one possible implementation, the second message further includes eighth indication information, which indicates the WLAN operating parameter configuration parameter set of the slave device. The slave device's WLAN operating parameter configuration parameter set includes the slave device's authentication encryption mode parameters and the slave device's frequency band parameters. Optionally, the eighth indication information is located in the message type identifier field of the second message.

[0365] In one possible implementation, the message content field of the first message further includes a parameter mask field, and the message content field of the second message further includes a parameter mask field. The parameter mask field includes a ninth indication information and a tenth indication information. The ninth indication information is used to indicate the authentication encryption mode parameter of the slave device, and the tenth indication information is used to indicate the frequency band parameter of the slave device.

[0366] In one possible implementation, the message content field of the first message further includes first instruction information and third instruction information; the message content field of the second message further includes second instruction information and third instruction information.

[0367] In one possible implementation, the first message is encapsulated in the payload field of a Fiber to the Room (FEM) frame, and the FEM port identifier in the frame header of the FEM frame indicates the slave device corresponding to the first message. Optionally, the FEM frame is encapsulated in the payload field of a Data Link Layer (DLL) frame.

[0368] Please refer to the preceding text for details. Figure 2A , Figure 3 or Figure 4 The relevant descriptions in the corresponding embodiments will not be repeated here.

[0369] like Figure 7 As shown, this application also provides a communication device 70. The communication device 70 can be a slave device or a master device, or a component of a slave device or master device (e.g., an integrated circuit, a chip, etc.). The communication device 70 can also be other communication modules used to implement the methods in the method embodiments of this application.

[0370] The communication device 70 may include a processing module 701 (or processing unit). Optionally, it may also include an interface module 702 (or transceiver unit or transceiver module) and a storage module 703 (or storage unit). The interface module 702 is used to enable communication with other devices. The interface module 702 may be, for example, a transceiver module or an input / output module.

[0371] In one possible design, such as Figure 7 One or more modules may be implemented by one or more processors, or by one or more processors and memory; or by one or more processors and transceivers; or by one or more processors, memory, and transceivers. This application does not limit the implementation in this way. The processors, memory, and transceivers can be configured individually or integrated into one unit.

[0372] The communication device 70 is equipped to implement the functions of the slave device described in the embodiments of this application. For example, the communication device 70 includes modules, units, or means corresponding to the steps involved in the slave device described in the embodiments of this application. These functions, units, or means can be implemented by software, hardware, or hardware executing corresponding software, or a combination of software and hardware. Further details can be found in the corresponding descriptions in the foregoing method embodiments. Please refer to the preceding text for specific details. Figure 6 The corresponding embodiment is the communication device 60.

[0373] Alternatively, the communication device 70 may have the functions of the main device described in the embodiments of this application. For example, the communication device 70 includes modules, units, or means corresponding to the steps involved in the main device described in the embodiments of this application. These functions, units, or means can be implemented by software, hardware, or hardware executing corresponding software, or a combination of software and hardware. Further details can be found in the corresponding descriptions in the foregoing method embodiments. Please refer to the preceding text for specific details. Figure 6 The corresponding embodiment is the communication device 60.

[0374] Furthermore, this application provides a computer program product comprising one or more computer instructions. When these computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. For example, implementing the aforementioned... Figure 2A , Figure 3 or Figure 4 The methods related to the slave device. For example, implementing the methods described above. Figure 2A , Figure 3 or Figure 4The method relates to the main device in the process. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can store or a data storage device such as a server or data center that integrates one or more available media. The available medium can be magnetic media (e.g., floppy disk, hard disk, magnetic tape), optical media (e.g., digital versatile disc (DVD)), or semiconductor media (e.g., solid-state disk (SSD)).

[0375] Furthermore, this application also provides a computer-readable storage medium storing a computer program that is executed by a processor to perform the aforementioned functions. Figure 2A , Figure 3 or Figure 4 Methods related to the device in the process.

[0376] Furthermore, this application also provides a computer-readable storage medium storing a computer program that is executed by a processor to perform the aforementioned functions. Figure 2A , Figure 3 or Figure 4 Methods related to the master device in the process.

[0377] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0378] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.

Claims

1. An optical network communication method, the optical network comprising a master device and at least one slave device, the at least one slave device comprising a first slave device, characterized in that, include: The master device receives a first message from the first slave device. The first message includes first indication information, which occupies two bytes. The first indication information indicates in bitmap form whether the first slave device supports each of the multiple security modes. Each security mode corresponds to a first bit, and the value of the first bit indicates whether the first slave device supports the security mode corresponding to the first bit. The various security modes include: User-oriented Wi-Fi protected access WPA-Personal mode; WPA2-Personal mode; WPA-WPA2-Personal mode; WPA3-SAE; WPA2-WPA3-PSK-SAE; WPA-Enterprise, a Wi-Fi protected access solution for enterprises; WPA2-Enterprise; WPA-WPA2-Enterprise; WPA3-Enterprise.

2. The method according to claim 1, characterized in that, The method further includes: The master device sends a second message to the first slave device. The second message includes second indication information, which instructs the first slave device to use a first security mode, which is one of the multiple security modes.

3. The method according to claim 2, characterized in that, After the master device sends the second message to the first slave device, the method further includes: The master device receives a third message from the first slave device, the third message being used to provide feedback on the configuration result.

4. The method according to claim 2 or 3, characterized in that, The second message also includes third indication information, used to indicate the operating frequency band configuration of the first slave device in bitmap form.

5. The method according to claim 4, characterized in that, Each of the multiple frequency bands corresponds to a second bit, and the value of the second bit indicates whether the first slave device turns the frequency band corresponding to the second bit on or off. The multiple frequency bands include: 2.4GHz, 5GHz, 5G-Low, 5G-High and 6GHz.

6. The method according to any one of claims 2 to 5, characterized in that, The second message also includes a Supported Service Set Identifier (SSID) field, a password length field, and a password field, wherein the SSID field is used to indicate the content of the SSID, the password length field is used to indicate the length of the password, and the password field is used to indicate the content of the password, and the lengths of the SSID field and the password field are variables.

7. The method according to any one of claims 2 to 6, characterized in that, The second message also includes a transmit power level field and a channel width field, wherein the transmit power level field is used to indicate the transmit power level of the first slave device, and the channel width field is used to indicate the width of the operating frequency of the first slave device.

8. The method according to any one of claims 1 to 7, characterized in that, When the value of the first bit is 0, the first slave device does not support the security mode corresponding to the first bit; when the value of the first bit is 1, the first slave device supports the security mode corresponding to the first bit.

9. The method according to any one of claims 1 to 8, characterized in that, Before the master device receives the first message, the method further includes: The master device sends a fourth message to the first slave device, wherein the fourth message is used to request the first slave device to report the capability parameters of the first slave device.

10. The method according to any one of claims 1 to 9, characterized in that, The first message also includes a Wireless LAN Management and Control Interface (WMCI) version number field, wherein the WMCI version number field is used to indicate the WMCI version supported by the first slave device.

11. The method according to any one of claims 1 to 10, characterized in that, The first message also includes a Wireless LAN Management and Control Interface (WMCI) feature field, wherein the WMCI feature field indicates in bitmap form whether the first slave device supports cooperative time-domain transmission and whether it supports power management.

12. The method according to any one of claims 1 to 11, characterized in that, The first message also includes an IEEE 802.11 version number field, which indicates in bitmap form whether the first slave device supports each version of various IEEE 802.11 versions. Each version corresponds to a third bit, and the value of the third bit indicates whether the first slave device supports the version corresponding to the third bit.

13. The method according to claim 12, characterized in that, The various IEEE 802.11 versions include: 802.11AX, 802.11BE, and 802.11BN.

14. The method according to any one of claims 1 to 13, characterized in that, The first message also includes fourth indication information for indicating the capability parameters of the first slave device in a frequency band, the capability parameters including transmit power level and / or channel width.

15. The method according to claim 14, characterized in that, The first message also includes a fifth indication message for indicating the capability parameters of the first slave device in another frequency band, the capability parameters including transmit power level and / or channel width.

16. The method according to claim 14 or 15, characterized in that, The fourth indication information includes a transmit power field, used to indicate whether at least one of the following transmit powers is supported: Transmission power of 0-20%, 20-40%, 40-60%, 60-80%, and 80-100%.

17. The method according to any one of claims 14 to 16, characterized in that, The fourth indication information includes a channel width field, used to indicate whether at least one of the following channel widths is supported: 20MHz channel width, 40MHz channel width, 80MHz channel width, 160MHz channel width, and two non-consecutive 80MHz channel widths.

18. The method according to any one of claims 1 to 17, characterized in that, The first message is a Wireless LAN Management and Control Interface (WMCI) message.

19. The method according to claim 18, characterized in that, The first message also includes a sixth indication, which includes a first value or a second value. The first value indicates that the operation type is a parameter request type, and the second value indicates that the operation type is a parameter configuration type.

20. The method according to claim 18 or 19, characterized in that, The first message also includes a message content field, and the first indication information is located in the message content field of the first message.

21. The method according to any one of claims 1 to 20, characterized in that, The master device and the at least one slave device are connected via optical fiber or composite cable.

22. The method according to any one of claims 2 to 7, characterized in that, The at least one slave device includes a first slave device and a second slave device; The method further includes: After determining that the second slave device is offline, the master device sends a fifth message to the first slave device. The fifth message includes a sixth instruction, which instructs the first slave device to use a second security mode. The second security mode is a security mode supported by the first slave device and is different from the first security mode.

23. A communication device, characterized in that, include: A processor and a transceiver, the processor being connected to the transceiver, the processor being configured to implement the method as described in any one of claims 1 to 22.

24. A communication device, characterized in that, The communication device is used to implement the method as described in any one of claims 1 to 22.

25. A communication system, characterized in that, It includes a master device and at least one slave device, the master device being used to perform the method as described in claims 1-22, the master device being connected to the at least one slave device.

26. A chip, characterized in that, The chip is used to perform the method as described in any one of claims 1 to 22.

27. A computer program product, characterized in that, The computer program product includes instructions that, when executed on a computer, cause the computer to perform the method as described in any one of claims 1 to 22.

28. A computer-readable storage medium, characterized in that, Used to store instructions, which, when executed on a computer, cause the computer to perform the method as described in any one of claims 1 to 22.