Authentication method, authentication device and storage medium
By comparing the first data of the device to be authenticated with its historical data in the optical network, the activation of devices with identical data is terminated, thus solving the authentication failure problem caused by duplicate serial numbers and ensuring the uniqueness and legitimacy of the devices.
Patent Information
- Application Number
- CN202410633555.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-21
- Publication Date
- 2025-11-21
AI Technical Summary
In existing optical networks, when the serial numbers of devices to be authenticated are duplicated, there is a lack of effective authentication mechanisms, leading to device authentication failures or confusion.
By obtaining the first data report message from the device to be authenticated and comparing it with historical data, if they are the same, the activation of the current device is terminated to ensure the uniqueness of the device data.
It enables accurate identification and termination of illegal device activation in the case of duplicate serial numbers, ensuring the normal activation of legitimate devices and improving the authentication accuracy and device management uniqueness of optical networks.
Smart Images

Figure CN121000992A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, such as an authentication method, authentication device, and storage medium. Background Technology
[0002] An optical network is a communication network that uses optical fiber as the primary transmission medium. In an optical network, the characteristics of light transmission through optical fibers are utilized to achieve high-speed, high-capacity data transmission. Through a series of optical devices and equipment, such as optical line terminals (OLTs) and optical network units (ONUs), a complete network architecture is constructed, providing users with high-quality communication services.
[0003] In an optical network, the initial data required for authentication of a device, such as a serial number, must be unique. However, there is currently no authentication method that addresses devices using the same initial data. Summary of the Invention
[0004] This application provides an authentication method, authentication device, and storage medium.
[0005] In a first aspect, embodiments of this application provide an authentication method, including:
[0006] Obtain a first data reporting message, the first data reporting message includes first data, the first data is the data required for the current device to be certified before the working stage, the current device to be certified includes the device currently to be certified in the optical network;
[0007] If the first data is found to be the same as the previously obtained second data, the activation of the current device to be authenticated is terminated. The second data is the data required for the authentication of historical devices to be authenticated.
[0008] Secondly, embodiments of this application provide an authentication device, including:
[0009] One or more processors;
[0010] Storage device for storing one or more programs;
[0011] When the one or more programs are executed by the one or more processors, the one or more processors implement the methods provided in the embodiments of this application.
[0012] Thirdly, embodiments of this application provide a storage medium storing a computer program, which, when executed by a processor, implements the method provided in embodiments of this application.
[0013] Further details regarding the above embodiments and other aspects of this application, as well as their implementations, are provided in the accompanying drawings, detailed description, and claims. Attached Figure Description
[0014] Figure 1 A flowchart illustrating an authentication method provided in an embodiment of this application;
[0015] Figure 2 This is a schematic diagram of the structure of an authentication system provided in an embodiment of this application;
[0016] Figure 3 A flowchart illustrating another authentication method provided in an embodiment of this application;
[0017] Figure 4 A flowchart illustrating another authentication method provided in an embodiment of this application;
[0018] Figure 5 This is a schematic diagram of the structure of an authentication device provided in an embodiment of this application;
[0019] Figure 6 This is a schematic diagram of the structure of an authentication device provided in an embodiment of this application. Detailed Implementation
[0020] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in detail below with reference to the accompanying drawings. It should be noted that, unless otherwise specified, the embodiments and features described in these embodiments can be arbitrarily combined with each other.
[0021] The steps illustrated in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases the steps shown or described may be performed in a different order than that shown here.
[0022] In this application, the terms "first," "second," etc., are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.
[0023] Passive Optical Networks (PONs) use Serial Numbers (SNs) for authentication. The standard specifies that the SN of an optical network user equipment (ONU), also known as the device to be authenticated, must remain unique within an Optical Distribution Network (ODN). An ONU can be an Optical Network Unit (ONU) in a PON system or a Sub-Fiber Unit (SFU) in a Fiber to the Room (FTTR) system using G.Fin technology. Currently, there are no regulations on how to handle situations where connected ONUs have the same SN in Optical Line Terminals (OLTs), nor are there regulations on how to handle situations where connected SFUs have the same SN in FTTRs.
[0024] PON technology is a crucial technology for home broadband. In PON, the ONU performs initial device authentication through the SN, which assigns a unique identifier, ONU-ID (Optical Network Unique Identifier), to standardize the device. The ONU-ID is then used to interact with subsequent management and control messages, such as test messages. The ONU-ID can be an encoding or tag used to uniquely identify the ONU.
[0025] G.FIN technology also uses point-to-multipoint fiber optic networking, basically following the PON protocol. SFUs also perform initial device authentication through SNs, assigning a unique identifier (SFU-ID) to the device. The SFU-ID is then used to exchange subsequent management and control messages, such as test messages. The SFU-ID can be an encoding or marker used to uniquely identify the SFU.
[0026] This application addresses the technical problem of how to authenticate devices when the authentication data (such as serial number) used by the devices to be authenticated is duplicated, and provides an authentication method. Duplicate authentication data can be considered as multiple devices to be authenticated having identical authentication data.
[0027] In one exemplary implementation Figure 1This is a schematic flowchart illustrating an authentication method provided in an embodiment of this application. The authentication method can be applied to situations where a device to be authenticated is being authenticated, such as authenticating devices using the same first data. The authentication method can be executed by an authentication device, which can be integrated into the authentication device. The authentication device can be considered as the device authenticating the device to be authenticated. The device to be authenticated can be considered as the device to be authenticated, such as a device to be verified for identity and / or legitimacy.
[0028] Figure 2 This is a schematic diagram of an authentication system provided in an embodiment of this application. The authentication system includes an authentication device 1 and multiple devices 2 to be authenticated. There is a corresponding relationship between the authentication device 1 and the devices 2 to be authenticated. In one embodiment, the device 2 to be authenticated is an ONU, and the authentication device 1 is an OLT. In another embodiment, the device 2 to be authenticated is an SFU, and the authentication device 1 is an MFU. The authentication device 1 can authenticate the devices 2 to be authenticated. If the data required for authentication of at least two devices 2 to be authenticated, such as the serial number (SN), is duplicated, the authentication device 1 can authenticate the devices 2 to be authenticated by executing the authentication method provided in this application.
[0029] Authentication device 1 may allow device 2 to be authenticated, which has the same first data, to activate, or it may not allow device 2 to be authenticated, which has the same first data, to activate.
[0030] This application provides an authentication method for a device to be authenticated, solving the problem of authentication when the first data is duplicated. This embodiment takes the example of an authentication device that does not allow activation of devices with the same first data. Figure 1 As shown, the authentication method provided in this application includes the following operations:
[0031] S110, Obtain the first data reporting message.
[0032] The first data reporting message can be considered a message used to report first data. For example, a message from a device to be authenticated to an authenticating device reporting first data. The first data reporting message includes first data, which is the data required for authentication of the corresponding device before the operational phase. The device to be authenticated includes any device currently being authenticated in the optical network. The device to be authenticated can be an SFU or an ONU. The device to be authenticated corresponding to the first data can be the device sending the first data reporting message containing the first data, and this device is currently being authenticated by the device being authenticated.
[0033] During the operation of a device to be certified, it can function in multiple stages, such as the initial stage (O1), the serial number stage (O2, O3), the ranging stage (O4), and the operational stage (O5). The initial stage (O1) is the preparation stage for device startup; the serial number stage (O2, O3) mainly involves confirming and processing the device's serial number and other relevant information to ensure the device's uniqueness and legitimacy; the ranging stage (O4) involves measuring parameters such as distance to prepare for subsequent accurate operation; and in the operational stage (O5), the device enters its formal working state, performing various data transmissions and functional operations. These stages together constitute the complete process and different states of a device in an optical network from startup to normal operation.
[0034] The data required for certification of a device before its operational phase can be understood as the data required for certification at each stage prior to the operational phase. This data may include the data required for certification during the serial number stage and / or the ranging stage. The initial data for different stages may differ, and this is not limited here.
[0035] When the device to be authenticated performs authentication, it transmits a first data reporting message to the authentication device. The authentication device then receives the first data reporting message.
[0036] In one embodiment, the first data includes one or more of the following: a serial number and device identification information. The device identification information can be unique to the device. If the device to be authenticated is an ONU, the device identification information can be the ONU-ID. If the device to be authenticated is an SFU, the device identification information can be the SFU-ID.
[0037] S120. If the first data is found to be the same as the previously obtained second data, the activation of the currently authenticated device is terminated.
[0038] The second data is the data required for authenticating historical devices. Historical devices to be authenticated can be those authenticated before the current device. The second data can be data used to authenticate historical devices. In this application, the first and second data can be data transmitted by different devices of the same type to be authenticated. For example, the second data can be the serial number (SN) transmitted by a historical device to be authenticated, and the first data can be the SN transmitted by the current device to be authenticated. Alternatively, the second data can be device identification information transmitted by a historical device to be authenticated, and the first data can be device identification information transmitted by the current device to be authenticated. The first and second data can be used to distinguish different devices to be authenticated.
[0039] In one embodiment, the authentication device obtains a first data reporting message transmitted by the device currently to be authenticated, and the authentication device detects whether it has previously obtained second data that is the same as the first data in the first data reporting message.
[0040] If the detected first data is identical to the second data obtained before obtaining the first data, the activation of the currently authenticated device is terminated to ensure the uniqueness of the first data. Terminating the activation of the currently authenticated device can be considered as stopping or ending the activation process of the currently authenticated device.
[0041] If no data identical to the first data is detected in the second data obtained before the first data is obtained, subsequent operations can be performed on the device to be authenticated. These subsequent operations are not limited here and can be any operations required after the stage corresponding to the first data. For example, if the first data is data transmitted during the sequence number stage, and it is determined that there is no duplicate first data, device identification information can be assigned to the device to be authenticated.
[0042] In one embodiment, when the authentication device does not allow the activation of ONUs with the same SN, if the same SN is detected during the activation process (i.e., the same SN as the previously obtained SN is detected), the activation of the ONU for that SN will be terminated, that is, the activation of the current device to be authenticated will be terminated.
[0043] In one embodiment, if the authentication device does not allow the activation of SFUs with the same SN, the activation of the SFU for that SN will be terminated if the same SN is detected during the activation process.
[0044] This application provides an authentication method in which, when authenticating a device to be authenticated, the authentication device determines whether duplicate data exists based on the first data of the device to be authenticated, i.e., whether the first data is the same as the previously acquired second data. Based on the determination result, it decides whether to terminate the activation process of the device to be authenticated. If the activation process of the device to be authenticated is terminated, the authentication of the device to be authenticated can be considered to have failed. This method achieves authentication of devices to be authenticated that use the same first data.
[0045] Based on the above embodiments, modified embodiments of the above embodiments are proposed. It should be noted that, in order to keep the description brief, only the differences from the above embodiments are described in the modified embodiments.
[0046] In one embodiment, the first data includes a serial number.
[0047] The first data can be the serial number (SN) transmitted during the current authentication phase of the device to be authenticated, or it can be the SN obtained during the working phase of a historical device to be authenticated.
[0048] In one embodiment, the first data reporting message is the data transmitted during the serial number phase of the currently authenticated device.
[0049] In this embodiment, during the serial number stage of the device to be authenticated, the authentication device obtains the first data reporting message transmitted by the device to be authenticated and obtains the first data included in the first data reporting message, so as to realize the authentication of the device to be authenticated during the serial number stage.
[0050] This embodiment compares the first data obtained during the serial number stage with the previously obtained second data to determine if there is a duplicate, and then determines whether to terminate the activation of the current device to be authenticated based on the result. If there is a duplicate, the activation of the current device to be authenticated is terminated.
[0051] There can be multiple second data points obtained previously. As long as there is one second data point that is the same as the first data point, it is considered that the first data point is detected to be the same as the previously obtained second data point.
[0052] When the authentication device does not allow multiple devices with the same serial number (SN) to be activated, if the authentication device finds a report message (i.e., the first data report message) with the same SN during the serial number stage (O2, O3) of the current device to be authenticated, it will terminate the activation process for that device. The device to be authenticated can generate an alarm and send it to the management system connected to the device to be authenticated. The management system can be a system that manages the devices to be authenticated.
[0053] In one embodiment, when the authentication device is an OLT and the device to be authenticated is an ONU, if the OLT does not allow multiple ONUs with the same serial number (SN) to be activated, and if the OLT detects a report message (i.e., the first data report message) with the same SN during the ONU's serial number stage (O2, O3), the OLT terminates the activation process for that ONU. The ONU can generate an alarm and send it to the management system connected to the ONU. The management system can be a system that manages the devices to be authenticated.
[0054] In one embodiment, when the authentication device is an MFU and the device to be authenticated is an SFU, if the MFU does not allow multiple SFUs with the same serial number (SN) to be activated, and if the MFU detects a report message (i.e., the first data report message) with the same SN during the SFU's serial number stage (O2, O3), the MFU terminates the activation process for that SFU. The SFU can then generate an alarm and send it to the management system connected to the SFU. The management system can be a system that manages the devices to be authenticated.
[0055] In one embodiment, the first data reporting message is data transmitted during the working phase of a historical device to be authenticated, and the phase corresponding to the second data is the same as the phase corresponding to the first data.
[0056] In this embodiment, during the working phase of the historical devices to be authenticated, the authentication device obtains the first data reporting message of the current device to be authenticated. The authentication device can detect whether the first data is the same as the previously obtained second data.
[0057] The stage corresponding to the second data can be the stage that the historical device to be authenticated was in when the second data was obtained. The stage corresponding to the first data can be the stage that the current device to be authenticated was in when the first data was obtained.
[0058] In one embodiment, the first data may be authentication data transmitted by the current device to be authenticated during the serial number stage, such as a serial number (SN). The previously acquired second data may be authentication data transmitted by a previous device to be authenticated during the serial number stage, such as a serial number (SN).
[0059] In one embodiment, the first data may be authentication data transmitted by the current device to be authenticated during the ranging phase, such as device identification information. The previously acquired second data may be authentication data transmitted by a previous device to be authenticated during the ranging phase, such as device identification information.
[0060] This embodiment can report the first data transmitted during the serial number stage of the current device to be authenticated, obtained from the working stage of a historical device to be authenticated. Then, the first data is compared with the second data required for authentication during the serial number stage of the historical device to be authenticated.
[0061] This embodiment can report the first data transmitted during the ranging phase of the current device to be authenticated, obtained from the working phase of a historical device to be authenticated. Then, the first data is compared with the second data required for authentication during the ranging phase of the historical device to be authenticated.
[0062] When the authentication device does not allow multiple devices with the same SN to be activated, if the authentication device finds a new current device with the same SN being activated during the working phase (O5) of the historical devices to be authenticated, it will terminate the activation process of the new current device to be authenticated. The current device to be authenticated can generate an alarm and send it to the management system.
[0063] In one embodiment, when the authentication device is an OLT, the historical device to be authenticated is an ONU, and the current device to be authenticated is an ONU, if the OLT detects a new ONU with the same SN being activated during the ONU's working phase (O5), the activation process of the new ONU will be terminated, and the OLT can generate an alarm and send it to the management system.
[0064] In one embodiment, when the authentication device is an MFU, the historical device to be authenticated is an SFU, and the current device to be authenticated is an SFU, if the MFU discovers a new SFU with the same SN being activated during the SFU's working phase (O5), the MFU terminates the activation process of the new SFU, and the MFU can generate an alarm and send it to the management system.
[0065] In one embodiment, the first data includes the device identification information of the device currently to be authenticated.
[0066] The first data can be the device identification information transmitted during the ranging phase of the device to be authenticated.
[0067] In one embodiment, the first data reporting message is data transmitted during the ranging phase of the device currently being authenticated.
[0068] In this embodiment, during the ranging phase of the current device to be authenticated, the authentication device obtains the first data reporting message transmitted by the current device to be authenticated, and obtains the first data included in the first data reporting message, so as to realize the authentication of the current device to be authenticated during the ranging phase.
[0069] This embodiment can compare the first data transmitted during the ranging phase of the current device to be authenticated with the second data transmitted during the ranging phase of historical devices to be authenticated to determine whether there is a duplication, and based on the determined result, determine whether to terminate the activation of the current device to be authenticated.
[0070] When the authentication device does not allow multiple devices with the same SN to be activated, if the authentication device finds the same device identification information during the ranging phase (O4) of the device to be authenticated, it will terminate the activation process for that device to be authenticated. The device to be authenticated can generate an alarm and send it to the management system.
[0071] In one embodiment, when the authentication device is an OLT and the device to be authenticated is an ONU, if the OLT detects a duplicate ONU-ID during the ONU ranging phase (O4), it terminates the activation process for that ONU. The OLT can generate an alarm and send it to the management system.
[0072] In one embodiment, when the authentication device is an MFU and the device to be authenticated is an SFU, if the MFU finds an identical SFU-ID during the SFU ranging phase (O4), it terminates the activation process for that SFU, and the MFU can generate an alarm and send it to the management system.
[0073] In one example, when at least three devices to be authenticated are sending first data indication messages to the authentication device, if two devices send conflicting first data indication messages, the authentication device may not receive the first data indication message, but it will receive the first data indication messages from the remaining devices. The authentication device will then authenticate the devices based on the first data indication information. After successful authentication, it will broadcast device identification information, which will be associated with the first data. The devices that sent the first data (including the conflicting devices) will then obtain the device identification information and proceed to the next stage, such as stage O4, based on it. This can lead to multiple devices with the same device identification information transmitting data to the authentication device. Therefore, this embodiment solves the above problem and achieves authentication accuracy by authenticating the first data during the ranging stage.
[0074] In one embodiment, the authentication method further includes:
[0075] If the device to be authenticated is in an operational phase, authenticate the device to be authenticated.
[0076] If the current device to be authenticated fails to authenticate, then the current device to be authenticated is deactivated.
[0077] When the device to be authenticated is in operation, the authentication device can further authenticate the device to be authenticated, such as by authenticating the device to be authenticated based on the device's password and / or certificate, to ensure the legitimacy of the device to be authenticated.
[0078] If the current device to be authenticated fails to authenticate, the activation of the current device to be authenticated can be cancelled, that is, the current device to be authenticated is deactivated, so that the current device to be authenticated loses its activation state.
[0079] In one embodiment, the OLT can continue to authenticate the ONU that is in the working phase. If the authentication fails, the ONU will be activated and the OLT can generate an alarm and send it to the management system.
[0080] In one embodiment, the MFU can continue to authenticate the SFU that is working. If authentication fails, the SFU is deactivated, and the MFU can generate an alarm and send it to the management system.
[0081] When the authentication device allows multiple devices with the same serial number (SN) to be activated, the third data report information transmitted by the devices to be authenticated to the authentication device includes third data and target identification information. The authentication device authenticates the devices to be authenticated based on the third data and target identification information, and generates device identification information for the devices to be authenticated.
[0082] The third data can be data required for the certification of the corresponding device before the operational phase, such as the serial number (SN) and / or device identification information. Target identification information can be considered as data that assists the third data in certifying the device.
[0083] In one embodiment, when multiple ONUs with the same SN are allowed to activate, the ONU needs to carry other identification information (i.e., target identification information) when reporting the SN. The OLT performs authentication based on the SN and other identification information and assigns different ONU-IDs to complete the ONU activation process.
[0084] In one embodiment, when multiple SFUs with the same SN are allowed to activate, the SFU needs to carry other identification information of the SFU when reporting the SN. The MFU performs authentication based on the SN and other identification information and assigns different SFU-IDs to complete the SFU activation process.
[0085] If the authentication device allows devices with the same serial number to be activated, the authentication device can continue to authenticate the devices in the working stage after the devices have finished their working stage. If the authentication fails, the authentication device will deactivate the devices in the working stage that failed to be authenticated.
[0086] When an ONU with the same SN is allowed to be activated, after the ONU's working phase (O5), the OLT can continue to further authenticate the ONU that is working. If the authentication fails, the OLT will activate the ONU and generate an alarm to send to the management system.
[0087] When an SFU with the same SN is allowed to activate, after the SFU's working phase (O5), the MFU can continue to further authenticate the SFU that is working. If the authentication fails, the MFU will activate the SFU and generate an alarm to send to the management system.
[0088] The following is an exemplary description of this application. The authentication method provided in this application can also be considered as an activation method for the device to be authenticated. It solves the problem of ensuring the activation of a legitimate device when the serial number (SN) of the device to be authenticated is duplicated. In this embodiment, if the first data of the current device to be authenticated is identical to previously acquired second data, the current device to be authenticated is terminated.
[0089] Figure 3 A flowchart illustrating another authentication method provided in this application embodiment; as shown Figure 3 As shown, when the authentication device does not support activation of multiple ONUs with the same SN, the OLT workflow is as follows:
[0090] 1) When the OLT sends a sequence number request for bandwidth allocation, the ONU in the sequence number stage will respond with the SN's reporting message (Serial_Number_ONU), which is the first data reporting message.
[0091] 2) If the OLT receives multiple identical reporting messages from multiple SNs within the time range corresponding to the bandwidth allocation requested for this sequence number, the OLT will terminate the activation process for the ONU of this SN and may further generate an alarm to be sent to the management system.
[0092] In this embodiment, after the bandwidth allocation for the OLT sequence number request, the first data reporting message from the ONU in the sequence number phase can be obtained. If the first data included in the received first data reporting message is the same as the previously obtained second data (it can be considered that multiple reporting messages with the same SN are received), then the activation of the ONU that sent the first data reporting message is terminated, such as terminating the activation of the ONU that is not the first to send the SN.
[0093] 3) If the OLT does not receive multiple reporting messages with the same SN within the time range corresponding to the bandwidth allocation requested by this sequence number, and receives a reporting message of SN carrying the SN, the OLT will continue to send the message to allocate ONU-ID, and the ONU will enter the ranging stage (O4).
[0094] 4) When the ONU is in the ranging phase, the OLT sends a bandwidth allocation request for ranging, and the ONU will respond to the ranging request; the Gigabit Passive Optical Network (GPON) ONU responds to the SN's reporting message (Serval_Number_ONU), and the 10G Passive Optical Network (XG PON) responds to the registration message (Registration).
[0095] 5) If the OLT receives multiple reporting messages with the same ONU-ID or receives conflicting messages within the time range corresponding to the bandwidth allocation of this ranging request (e.g., the received messages may be incorrect, such as due to format errors, or they may be messages sent simultaneously), the OLT will terminate the activation process for the ONU with this ONU-ID and may further generate an alarm to be sent to the management system.
[0096] 6) If the OLT receives only one reporting message with the same ONU-ID within this bandwidth, the OLT will continue to send the message configuring the ranging time (Ranging_Time), and the ONU will enter the working phase (O5).
[0097] 7) You can choose to continue to authenticate the ONU entering O5, such as password or certificate authentication. If the authentication fails, you can activate the ONU and generate an alarm to send to the management system.
[0098] like Figure 3 As shown, when multiple SFUs with the same SN are not supported for activation, the MFU workflow is as follows:
[0099] 1) When the MFU sends a sequence number request for bandwidth allocation, the SFU in the sequence number stage will respond to the SN's reporting message (Serial_Number_SFU), which is the first data reporting message.
[0100] 2) If the MFU receives the same reporting message from multiple SNs in this bandwidth, the MFU will terminate the SFU activation process for this SN and may further generate an alarm to be sent to the management system.
[0101] 3) If the MFU does not receive multiple reporting messages with the same SN within the time range corresponding to the bandwidth allocation requested for this sequence number, and receives a reporting message with the SN carrying the SN, the MFU will continue to send the message to allocate SFU-ID, and the ONU will enter the ranging phase (O4).
[0102] 4) When the SFU is in the ranging phase, the MFU sends a bandwidth allocation request for ranging, and the SFU will respond to the ranging request; the SFU responds to the SN's reporting message (Servil_Number_SFU).
[0103] 5) If the MFU receives multiple reports with the same SFU-ID or receives conflicting messages within the time range corresponding to the bandwidth allocation of this ranging request, the MFU will terminate the activation process of the MFU for this SFU-ID and may further generate an alarm to be sent to the management system.
[0104] 6) If the MFU receives only one report message with the same SFU-ID in this bandwidth, the MFU will continue to send the message configuring the ranging time (Ranging_Time), and the SFU will enter the working phase (O5).
[0105] 7) You can choose to continue to authenticate the SFU entering O5, such as password or certificate authentication. If the authentication fails, you can activate the SFU and generate an alarm to send to the management system.
[0106] Figure 4 A flowchart illustrating another authentication method provided in this application embodiment; as follows: Figure 4 As shown, when multiple ONUs with the same SN are supported for activation, the workflow of the OLT and ONU is as follows:
[0107] 1) When the OLT sends a bandwidth allocation request for a sequence number, the ONU in the O2-O3 stage will respond with a report message (i.e., third data) containing the SN (i.e., third data) and other identification information (i.e., target identification information) (i.e., third data report information) (the Serial_Number_ONU message needs to be redefined, as shown in Table 1). The SN can be the same, but the other identification information is different, ensuring that the SN plus the other identification information forms information that uniquely identifies the ONU.
[0108] 2) After successful OLT authentication, a corresponding ONU-ID will be assigned based on the SN and other identification information. If the SN is the same but the other identification information is different, the ONU-ID will also be different. To prevent the activation of the same SN at the same time, the SN encrypted with other identification information can be included in the ONU-ID message. This ensures that ONUs with the same SN will not interfere with each other. Upon receiving this message, the ONU enters the ranging phase and completes the subsequent activation process. If authentication fails, the OLT will terminate the activation of the ONU. The ONU will not receive the ONU-ID assignment message and will return to the initial phase (O1) after a period of time.
[0109] 3) You can choose to continue further authentication of the ONU entering O5, such as password or certificate authentication. If the authentication fails, you can activate the ONU and generate an alarm to send to the management system.
[0110] When multiple SFUs with the same SN are supported for activation, the SFU workflow is as follows:
[0111] 1) When the MFU sends a bandwidth allocation request for a sequence number, the SFU in the O2-O3 phase will respond with a report message (i.e., third data) of SN (i.e., third data) and other identification information (i.e., target identification information) (i.e., third data report information) (for example, using a format similar to Table 1, redefining the Serial_Number_SFU message). The SN can be the same, but the other identification information is different, ensuring that the SN plus the other identification information forms information that uniquely identifies the SFU.
[0112] 2) After successful MFU authentication, a corresponding SFU-ID will be assigned based on the SN and other identification information. At this point, if the SN is the same but the other identification information is different, the SFU-ID will also be different. To prevent the activation of the same SN at the same time, the SN encrypted with other identification information can be included in the SFU-ID message. This ensures that SFUs with the same SN will not interfere with each other. Upon receiving this message, the SFU enters the ranging phase and completes the subsequent activation process. If authentication fails, the MFU will terminate the activation of that SFU. The SFU will not receive the SFU-ID assignment message and will return to the initial phase (O1) after a period of time.
[0113] 3) You can choose to continue further authentication of the SFU entering O5, such as password or certificate authentication. If the authentication fails, you can activate the SFU and generate an alarm to send to the management system.
[0114] Table 1 is a schematic table of reporting messages provided by an embodiment of this application in a scenario that supports the activation of multiple devices to be authenticated with the same SN.
[0115]
[0116] This application can be applied to distributed multi-link network devices and multi-link terminal devices.
[0117] In one exemplary embodiment, this application also provides an authentication device that can be integrated into an authentication equipment. Figure 5 This is a schematic diagram of the structure of an authentication device provided in an embodiment of this application, as shown below. Figure 5 As shown, the authentication device includes:
[0118] The acquisition module 510 is configured to acquire a first data reporting message, the first data reporting message including first data, the first data being the data required for the current device to be authenticated before the working phase, the current device to be authenticated including the device currently to be authenticated in the optical network;
[0119] The termination module 520 is configured to terminate the activation of the current device to be authenticated if the first data is detected to be the same as the previously obtained second data, wherein the second data is the data required for the authentication of a historical device to be authenticated.
[0120] The authentication device provided in this embodiment is used to implement the authentication method of this application embodiment. The implementation principle and technical effect of the authentication device provided in this embodiment are similar to those of the authentication method of this application embodiment, and will not be repeated here.
[0121] Based on the above embodiments, modified embodiments of the above embodiments are proposed. It should be noted that, in order to keep the description brief, only the differences from the above embodiments are described in the modified embodiments.
[0122] In one embodiment, the first data includes a serial number.
[0123] In one embodiment, the first data reporting message is the data transmitted during the serial number phase of the currently authenticated device.
[0124] In one embodiment, the first data reporting message is data transmitted during the working phase of a historical device to be authenticated, and the working phase corresponding to the second data is the same as the working phase corresponding to the first data.
[0125] In one embodiment, the first data includes the device identification information of the device currently to be authenticated.
[0126] In one embodiment, the first data reporting message is data transmitted during the ranging phase of the device currently being authenticated.
[0127] In one embodiment, the authentication device further includes:
[0128] The deactivation module is configured to authenticate the current device to be authenticated when the current device to be authenticated is in the working phase.
[0129] If the current device to be authenticated fails to authenticate, then the current device to be authenticated is deactivated.
[0130] In one exemplary embodiment, this application also provides an authentication device. Figure 6 This is a schematic diagram of the structure of an authentication device provided in an embodiment of this application. Figure 6 As shown, the authentication device provided in this application includes one or more processors 61 and a storage device 62; the processors 61 in the authentication device may be one or more. Figure 6 Taking a processor 61 as an example; storage device 62 is used to store one or more programs; the one or more programs are executed by the one or more processors 61, so that the one or more processors 61 implement the authentication method as described in the embodiments of this application.
[0131] The authentication equipment also includes: a communication device 63, an input device 64, and an output device 65.
[0132] The processor 61, storage device 62, communication device 63, input device 64, and output device 65 in the authentication device can be connected via a bus or other means. Figure 6 Taking the example of a connection between China and Israel via a bus.
[0133] Input device 64 can be used to receive input digital or character information, and to generate key signal inputs related to user settings and function control of the authentication device. Output device 65 may include display devices such as a display screen.
[0134] The communication device 63 may include a receiver and a transmitter. The communication device 63 is configured to perform information transmission and reception communication under the control of the processor 61. The information includes, but is not limited to, a first data reporting message.
[0135] Storage device 62, as a computer-readable storage medium, can be configured to store software programs, computer-executable programs, and modules, such as program instructions / modules corresponding to the authentication method described in the embodiments of this application (e.g., the acquisition module 510 and termination module 520 in the authentication device). Storage device 62 may include a program storage area and a data storage area, wherein the program storage area may store the operating system and at least one application program required for a function; the data storage area may store data created based on the use of the authentication device, etc. Furthermore, storage device 62 may include high-speed random access memory and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other non-volatile solid-state storage device. In some instances, storage device 62 may further include memory remotely located relative to processor 61, and these remote memories can be connected to the authentication device via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0136] In one exemplary embodiment, this application also provides a storage medium storing a computer program that, when executed by a processor, implements any of the methods described in this application. The storage medium stores a computer program that, when executed by a processor, implements the authentication method provided in this application, wherein the authentication method includes:
[0137] The data required for the authentication of the device to be authenticated before the operational phase, wherein the current device to be authenticated includes the device currently to be authenticated in the optical network;
[0138] If the first data is found to be the same as the previously obtained second data, the activation of the current device to be authenticated is terminated. The second data is the data required for the authentication of historical devices to be authenticated.
[0139] The computer storage medium in this application embodiment can be any combination of one or more computer-readable media. The computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. For example, a computer-readable storage medium can be, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of computer-readable storage media (a non-exhaustive list) include: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), flash memory, optical fiber, portable CD-ROM, optical storage device, magnetic storage device, or any suitable combination thereof. The computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0140] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media may also be any computer-readable medium other than computer-readable storage media, which can send, propagate, or transmit programs for use by or in connection with an instruction execution system, apparatus, or device.
[0141] Program code contained on a computer-readable medium may be transmitted using any suitable medium, including but not limited to: wireless, wire, optical fiber, radio frequency (RF), etc., or any suitable combination thereof.
[0142] Computer program code for performing the operations of this application can be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smallport, and C++, as well as conventional procedural programming languages such as C or similar languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0143] The above description is merely an exemplary embodiment of this application and is not intended to limit the scope of protection of this application.
[0144] Those skilled in the art will understand that the term "terminal equipment" encompasses any suitable type of wireless user equipment, such as mobile phones, portable data processing devices, portable web browsers, or vehicle-mounted mobile stations.
[0145] Generally, the various embodiments of this application can be implemented in hardware or dedicated circuitry, software, logic, or any combination thereof. For example, some aspects can be implemented in hardware, while others can be implemented in firmware or software that can be executed by a controller, microprocessor, or other computing device, although this application is not limited thereto.
[0146] Embodiments of this application can be implemented by executing computer program instructions through the data processor of a mobile device, for example, in a processor entity, or through hardware, or through a combination of software and hardware. The computer program instructions can be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, status setting data, or source code or object code written in any combination of one or more programming languages.
[0147] Any block diagram of logical flow in the accompanying drawings of this application may represent program steps, or may represent interconnected logic circuits, modules, and functions, or may represent a combination of program steps and logic circuits, modules, and functions. The computer program may be stored on memory. Memory may be of any type suitable to the local technical environment and may be implemented using any suitable data storage technology, such as, but not limited to, read-only memory (ROM), random access memory (RAM), optical storage devices and systems (Digital Video Disc (DVD) or Compact Disc (CD)), etc. Computer-readable media may include non-transitory storage media. The data processor may be of any type suitable to the local technical environment, such as, but not limited to, general-purpose computers, special-purpose computers, microprocessors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), and processors based on multi-core processor architectures.
[0148] A detailed description of exemplary embodiments of this application has been provided above through exemplary and non-limiting examples. However, various modifications and adjustments to the above embodiments will be apparent to those skilled in the art when considered in conjunction with the accompanying drawings and claims, without departing from the scope of this application. Therefore, the proper scope of this application will be determined by the claims.
Claims
1. An authentication method, characterized in that, include: Obtain a first data reporting message, the first data reporting message includes first data, the first data is the data required for the current device to be certified before the working stage, the current device to be certified includes the device currently to be certified in the optical network; If the first data is found to be the same as the previously obtained second data, the activation of the current device to be authenticated is terminated. The second data is the data required for the authentication of historical devices to be authenticated.
2. The method according to claim 1, characterized in that, The first data includes a serial number.
3. The method according to claim 2, characterized in that, The first data reporting message is the data transmitted during the serial number stage of the device currently to be authenticated.
4. The method according to claim 2, characterized in that, The first data reporting message is data transmitted during the working phase of the historical device to be authenticated, and the phase corresponding to the second data is the same as the phase corresponding to the first data.
5. The method according to claim 1, characterized in that, The first data includes the device identification information of the device currently to be authenticated.
6. The method according to claim 5, characterized in that, The first data reporting message is the data transmitted during the ranging phase of the device currently being authenticated.
7. The method according to claim 1, characterized in that, Also includes: If the device to be authenticated is in an operational phase, authenticate the device to be authenticated. If the current device to be authenticated fails to authenticate, then the current device to be authenticated is deactivated.
8. An authentication device, characterized in that, include: One or more processors; Storage device for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the method as described in any one of claims 1-7.
9. The authentication device according to claim 8, characterized in that, The authentication device is an optical network terminal or a main device in a fiber-to-the-room scenario.
10. A storage medium, characterized in that, The storage medium stores a computer program that, when executed by a processor, implements the method described in any one of claims 1-7.