Control method, authentication method, device and system of access equipment and medium

By obtaining the authentication result information from the OLT through the main gateway, unified authentication and control of access devices are achieved, which solves the problem of poor network security caused by the OLT only managing the main gateway, and realizes more efficient authentication and more secure network management.

CN121968251APending Publication Date: 2026-05-01HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HUAWEI TECH CO LTD
Filing Date
2024-10-29
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

In existing technologies, the OLT only authenticates and manages the main gateway, resulting in poor network security.

Method used

The authentication result information of the OLT is obtained through the main gateway to perform unified authentication and control of the access devices, including obtaining the authentication information of the access devices and controlling the network functions based on the authentication result information.

Benefits of technology

It improves network security, increases the authentication efficiency of access devices, saves network resources, and reduces reliance on staff.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121968251A_ABST
    Figure CN121968251A_ABST
Patent Text Reader

Abstract

The invention discloses a control method, an authentication method, a device and a system of access equipment, and a medium, and belongs to the technical field of optical communication. The control method comprises the steps that a main gateway obtains authentication result information from an OLT, the authentication result information is used for indicating whether to-be-accessed access equipment passes authentication or not, and the to-be-accessed access equipment is in communication connection with the main gateway; and controlling the access device to be accessed according to the authentication result information. And the access equipment connected with the main gateway is authenticated through the OLT, so that the network security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of optical communication technology, and in particular to a control method, authentication method, apparatus, system and medium for an access device. Background Technology

[0002] As internet access demands increase, multiple access point (AP) devices are deployed in a physical space. These AP devices are distributed across different areas of that space; for example, one AP device might be placed in the living room, study, and bedroom of a home. This allows users to access the network through the AP devices located in their respective areas.

[0003] Multiple access point (AP) devices consist of a main gateway and multiple access devices. Depending on the different environments within the physical space, these access point devices can employ different networking methods, such as fiber optic cables, network cables, etc. Each access device can communicate with the optical line terminal (OLT) through the main gateway.

[0004] In related technologies, the OLT only authenticates and manages the main gateway, resulting in poor network security. Summary of the Invention

[0005] This application provides a control method, authentication method, apparatus, system, and medium for access devices, which helps to improve network security.

[0006] Firstly, this application provides a control method for an access device. This control method is executed by a main gateway. The control method includes: obtaining authentication result information from an OLT, the authentication result information indicating whether an access device to be accessed has passed authentication, the access device to be accessed being communicatively connected to the main gateway; and controlling the access device to be accessed based on the authentication result information.

[0007] In this application, the main gateway controls the access devices based on the authentication result information from the OLT. That is, the OLT performs unified authentication on the access devices connected to the main gateway, which helps to improve network security.

[0008] In one possible implementation, the method further includes: a primary gateway sending an authentication request to the OLT, the authentication request including authentication information of the access device to be accessed. In this case, the primary gateway obtaining authentication result information from the OLT includes: the primary gateway receiving the authentication result information sent by the OLT according to the authentication request.

[0009] In this implementation, the main gateway first obtains the authentication information of the access device, and then sends the authentication information of the access device to the OLT through an authentication request. The OLT then sends the corresponding authentication result information based on the authentication request. In this way, the OLT only authenticates the access device corresponding to the authentication information.

[0010] In another possible implementation, obtaining authentication result information from the OLT includes: receiving an authentication list sent by the OLT, the authentication list including the identity information of at least one authenticated access device, and / or the identity information of at least one unauthenticated access device.

[0011] In this implementation, the OLT sends an authentication list in advance. This allows the main gateway to directly authenticate and control access devices based on the authentication list without waiting for interaction between the main gateway and the OLT. This improves the authentication efficiency of access devices and helps save network resources.

[0012] Optionally, the main gateway can obtain the authentication information of the access device to be accessed in the following way: the main gateway sends a query message to the access device to be accessed, the query message instructing the access device to send authentication information; after receiving the query message, the access device sends authentication information to the main gateway; the main gateway receives the authentication information sent by the access device. Through query messages and query response messages, the main gateway can automatically obtain the authentication information of the access device, which is convenient and efficient.

[0013] Optionally, both the query message and the query response message are easymesh messages.

[0014] Optionally, the query message includes an authentication type, and the type of the authentication information matches the authentication type. This allows the main gateway to flexibly select the required authentication type and obtain the authentication information corresponding to that type.

[0015] Optionally, the method further includes: receiving configuration information sent by the OLT, the configuration information being used to indicate the control method for unauthenticated access devices. In one possible implementation, the configuration information is used to indicate the control method for all unauthenticated access devices connected to the main gateway. In another possible implementation, the configuration information is used to indicate the control method for a subset of the unauthenticated access devices connected to the main gateway. In this way, the OLT can select the control method for the unauthenticated access devices according to the actual situation.

[0016] Optionally, controlling the access device includes, but is not limited to, controlling the network functions of the access device.

[0017] Optionally, controlling the access device to be accessed based on the authentication result information includes: allowing the access device to be accessed to use network functions when the authentication result information indicates that the access device to be accessed has passed authentication; or restricting or disabling the network functions of the access device to be accessed when the authentication result information indicates that the access device to be accessed has failed authentication.

[0018] By restricting or disabling the network functions of the access device to be accessed if the device fails to be authenticated, network security is improved.

[0019] Secondly, this application also provides an authentication method for access devices. This authentication method is performed by an OLT. The authentication method includes: the OLT sending authentication result information to a main gateway. The authentication result information is used to indicate whether the access device to be accessed has passed authentication, and the access device to be accessed is communicatively connected to the main gateway.

[0020] Optionally, the method further includes: receiving an authentication request sent by the main gateway, the authentication request including authentication information of the access device to be accessed; the OLT sending authentication result information to the main gateway, including: the OLT sending the authentication result information to the main gateway according to the authentication request.

[0021] Optionally, the authentication result information includes an authentication list, which includes the identity information of at least one authenticated access device and / or the identity information of at least one unauthenticated access device.

[0022] Optionally, the method further includes: sending configuration information to the main gateway, the configuration information being used to indicate the control method for unauthenticated access devices.

[0023] Optionally, in the first or second aspect, the authentication request further includes at least one of the following: network media type and port identifier, wherein the network media type indicates the connection medium between the main gateway and the access device to be accessed, and the port identifier indicates the downlink port of the main gateway, which is connected to the access device to be accessed. In this way, the OLT can perform more refined authentication of the access device based on the network media type corresponding to the access device and / or the downlink port of the main gateway to which the access device is connected.

[0024] Optionally, in either the first or second aspect, the authentication request is an Optical Network Unit Management and Control Interface (OMCI) message. In this case, the main gateway and the OLT are connected via an optical fiber link, allowing the authentication request to be sent via an OMCI message.

[0025] Optionally, in either the first or second aspect, the authentication result information carries an authentication result message, where the authentication result message is an OMCI message. In this case, the main gateway and the OLT are connected via a fiber optic link, allowing the authentication result information to be sent via an OMCI message.

[0026] Thirdly, this application also provides a control device for an access device. The control device includes an acquisition module and a control module. The acquisition module is used to acquire authentication result information from an optical line terminal, the authentication result information indicating whether the access device to be accessed has passed authentication, and the access device to be accessed is communicatively connected to the main gateway; the control module is used to control the access device to be accessed according to the authentication result information.

[0027] Optionally, the control device further includes: a first sending module, configured to send an authentication request to the optical line terminal, the authentication request including authentication information of the access device to be accessed; correspondingly, the obtaining module is configured to receive the authentication result information sent by the optical line terminal according to the authentication request.

[0028] Optionally, the authentication request may further include at least one of the following: network media type and port identifier, wherein the network media type is used to indicate the connection medium between the main gateway and the access device to be accessed, and the port identifier is used to indicate the downlink port of the main gateway, which is connected to the access device to be accessed.

[0029] Optionally, the authentication request is an OMCI message.

[0030] Optionally, the acquisition module is configured to receive an authentication list sent by the optical line terminal, the authentication list including the identity information of at least one authenticated access device and / or the identity information of at least one unauthenticated access device.

[0031] Optionally, the authentication result information carries an authentication result message, which is an OMCI message.

[0032] Optionally, the apparatus further includes a second sending module and a first receiving module. The second sending module is used to send a query message to the access device to be accessed, the query message being used to instruct the access device to send authentication information; the first receiving module is used to receive the authentication information sent by the access device to be accessed.

[0033] Optionally, the query message includes an authentication type, and the type of the authentication information matches the authentication type.

[0034] Optionally, the control device further includes: a second receiving module, configured to receive configuration information sent by the optical line terminal, the configuration information being used to indicate the control method for unauthenticated access devices.

[0035] Optionally, the control module is configured to allow the access device to use network functions when the authentication result information indicates that the access device to be accessed has passed authentication; or, when the authentication result information indicates that the access device to be accessed has failed authentication, restrict or disable the network functions of the access device to be accessed.

[0036] Fourthly, this application also provides an authentication device for an access device. The authentication device includes a sending module for sending authentication result information to a main gateway; wherein the authentication result information is used to indicate whether the access device to be accessed has passed authentication, and the access device to be accessed is communicatively connected to the main gateway.

[0037] In one possible implementation, the authentication device further includes: a receiving module, configured to receive an authentication request sent by the main gateway, the authentication request including authentication information of the access device to be accessed; and a sending module, configured to send the authentication result information to the main gateway according to the authentication request.

[0038] In another possible implementation, the authentication result information includes an authentication list, which includes the identity information of at least one authenticated access device and / or the identity information of at least one unauthenticated access device.

[0039] Optionally, the sending module is configured to send an authentication result message to the main gateway, wherein the authentication result message is an OMCI message and carries the authentication result information.

[0040] Optionally, the sending module is further configured to send configuration information to the main gateway, the configuration information being used to indicate the control method for unauthenticated access devices.

[0041] Fifthly, this application also provides a communication device, including a connected processor and a communication interface, wherein the processor is used to implement the control method for the access device provided in the first aspect or the authentication method for the access device provided in the second aspect.

[0042] Optionally, the processor may be one or more, and the processor may be a multi-core processor, and the memory may be one or more.

[0043] Optionally, the communication interface includes a transceiver.

[0044] Optionally, the communication device further includes a memory storing program code; the processor is used to read and execute the program code stored in the memory to implement the control method for the access device provided in the first aspect or the authentication method for the access device provided in the second aspect.

[0045] Optionally, the memory may be integrated with the processor, or the memory may be separated from the processor.

[0046] In the specific implementation process, the memory can be a non-transitory memory, such as read-only memory (ROM), which can be integrated with the processor on the same chip or set on different chips. This application does not limit the type of memory or the way the memory and processor are set.

[0047] In a sixth aspect, a computer-readable storage medium is also provided, wherein a software program is stored therein, which, when read and executed by one or more processors, can implement the aforementioned control method for the access device provided in the first aspect or the authentication method for the access device provided in the second aspect.

[0048] In a seventh aspect, a computer program (product) is provided, the computer program (product) comprising: computer program code, wherein when the computer program code is run by a computer device, the computer device executes the aforementioned control method for the access device provided in the first aspect or the authentication method for the access device provided in the second aspect.

[0049] Eighthly, a chip is provided, the chip including a connected processor and a communication interface. The processor is configured to execute instructions to cause the chip to perform the aforementioned control method for the access device provided in the first aspect or the authentication method for the access device provided in the second aspect.

[0050] In a ninth aspect, a communication system is provided, including an OLT, a main gateway, and at least one access device, wherein the main gateway is used to implement the control method of any access device provided in the first aspect, and the OLT is used to implement the authentication method of any access device provided in the second aspect. Attached Figure Description

[0051] Figure 1 This is a schematic diagram of the structure of an optical communication system provided in an embodiment of this application;

[0052] Figure 2 This is a flowchart illustrating a control method for an access device provided in an embodiment of this application;

[0053] Figure 3 This is a flowchart illustrating a control and authentication method for an access device provided in an embodiment of this application;

[0054] Figure 4 This is a flowchart illustrating another control and authentication method for an access device provided in an embodiment of this application;

[0055] Figure 5 This is a schematic diagram of the structure of a control device for an access device provided in an embodiment of this application;

[0056] Figure 6 This is a schematic diagram of the structure of an authentication device for an access device provided in an embodiment of this application;

[0057] Figure 7 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application. Detailed Implementation

[0058] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings.

[0059] Figure 1 This is a schematic diagram of the structure of an optical communication system provided in an embodiment of this application. For example... Figure 1 As shown, the optical communication system includes an OLT, a main gateway, and at least one access device. The main gateway is an optical network unit (ONU). The OLT is connected to one or more main gateways via an optical distribution network (ODN). Each main gateway communicates with its corresponding access device via one or more of the following methods: optical fiber, power line, wireless, or network cable.

[0060] For example, the main gateway and access devices can be networked in a mesh or tree structure. It should be noted that this application embodiment does not limit the networking method between the main gateway and access devices; the method can be selected as needed.

[0061] For illustrative purposes, Figure 1 The diagram illustrates three main gateways and three access devices connected to one of the main gateways. It should be noted that this embodiment does not limit the number of main gateways connected to one passive optical network (PON) port of the OLT or the number of access devices connected to one main gateway; each can be one or more. Furthermore, in addition to connecting to the main gateways, the OLT can also connect to ordinary ONUs (i.e., ONUs not connected to access devices) in non-home networking scenarios.

[0062] In this application embodiment, the main gateway may also be referred to as the home networking main gateway, main node, or main access point device, and the access device may also be referred to as the home networking terminal, slave node, or slave access point device.

[0063] Optionally, the main gateway can be located in the center of the home or near the entrance. Multiple access devices can be placed in different rooms, such as the living room, study, and bedrooms. When the main gateway and the corresponding access devices are networked via fiber optic cables, a fiber-to-the-room (FTTR) network or a home fiber optic network is formed. Optionally, the main gateway is a multi-access point controller (Multi-AP Controller), and the access devices are multi-access point agents (Multi-AP Agents).

[0064] To improve network security, this application provides a method for authenticating and managing access devices connected to each main gateway through an OLT.

[0065] Figure 2 This is a flowchart illustrating a control and authentication method for an access device provided in an embodiment of this application. Figure 2 As shown, the method includes the following steps 201-202.

[0066] In 201, the main gateway obtains the authentication result information from the OLT.

[0067] The authentication result information indicates whether the access device to be connected has passed authentication. This access device communicates with the main gateway. For example, the access device is... Figure 1 Any of the access devices in the system.

[0068] In one possible implementation, step 201 includes receiving authentication result information sent by the OLT. In another possible implementation, step 201 includes retrieving the authentication result information from the local storage of the main gateway, the authentication result information being stored in the local storage after being received by the main gateway.

[0069] In 202, the main gateway controls the access devices based on the authentication result information.

[0070] In some examples, controlling access devices includes controlling the network functions of the access devices.

[0071] Network functions refer to functions related to network communication, including but not limited to allowing access devices to access the network (i.e., using all network functions), restricting access devices' network functions (i.e., prohibiting access devices from using certain network services), and disabling access devices' network functions. For example, disabling access devices' network functions includes interrupting the access device's link-layer connection or maintaining the link-layer connection but prohibiting all network services of the access device; restricting network functions means prohibiting the use of certain network services, such as prohibiting the use of interactive personality television (IPTV) services or voice services.

[0072] In other examples, controlling the access device includes controlling other functions of the access device, such as turning a certain function of the access device on or off, or controlling the access device to enter a specified working mode.

[0073] In this embodiment, the main gateway controls the access devices based on the authentication result information, and the authentication result information comes from the OLT. That is, the OLT performs unified authentication on the access devices connected to the main gateway, which is beneficial to improving network security.

[0074] Furthermore, in FTTR networks, the main gateway can authenticate access devices based on configuration information directly entered by staff. However, this requires staff to physically visit the main gateway location to operate it. In this embodiment, staff can centrally control the main gateway from the OLT side, eliminating the need for individual configuration at each main gateway location, effectively saving labor and improving efficiency.

[0075] Figure 3 This is a flowchart illustrating a control and authentication method for an access device provided in an embodiment of this application. In this embodiment, an example is provided using a main gateway as a multi-access point proxy and the access device as a multi-access point proxy. Figure 3 As shown, the method includes:

[0076] In 301, the multi-access point controller sends a query message to the multi-access point agent.

[0077] The query message is used to instruct the multi-access point agent (MIPA) to send authentication information. The MIPA then receives this query message.

[0078] Optionally, the query message includes an authentication type that matches the type of authentication information sent by the multi-access point agent. Authentication types include, but are not limited to, device identifier authentication and medium access control (MAC) address authentication. This allows the multi-access point controller to flexibly select the required authentication type and obtain the corresponding authentication information.

[0079] In other embodiments, the query message may not include an authentication type, and authentication may be performed using the default authentication type.

[0080] For example, the query message could be an easymesh message. In this case, both the multi-access point controller (MIBDC) and the MIB agent support the easymesh protocol. After a physical connection (such as a fiber optic connection, wireless connection, or wireless local area network (WLAN) connection) is established between the MIBDC and the MIB agent, they can communicate using the easymesh protocol.

[0081] For example, the message format of a query message can be shown in Table 1 below. In Table 1, the 12th byte is used to indicate that the message is a query message. For example, when the value of the 12th byte is 0xF0, it indicates that the message is a query message; the 13th byte is used to indicate the authentication type. For example, when the value of the 13th byte is 0x00, it indicates that the authentication type is device identifier authentication, and when the value of the 13th byte is 0x01, it indicates that the authentication type is MAC authentication.

[0082] Table 1 Query Messages

[0083]

[0084] In Table 1, tlv represents type-length-value.

[0085] In a 302 response, the multi-access point agent sends authentication information to the multi-access point controller.

[0086] Accordingly, the multi-access point controller receives authentication information sent by one or more multi-access point agents.

[0087] Optionally, the authentication information may include the identity information of the multi-access point agent (MAPA). The MAPA's identity information includes, but is not limited to, at least one of the MAPA's device identifier and its MAC address. For example, the device identifier may be the MAPA's serial number (SN). Optionally, the identity information may be pre-configured in the MAPA at the factory.

[0088] When the query message includes an authentication type, the type of authentication information sent by the multi-access point agent matches that authentication type. For example, when the authentication type is device identifier authentication, the authentication information includes the device identifier of the multi-access point agent; as another example, when the authentication type is MAC address authentication, the authentication information includes the MAC address of the multi-access point agent.

[0089] When the query message does not include an authentication type, the multi-access point agent sends authentication information for the default authentication type. The default authentication type can be device identifier authentication or MAC address authentication, etc.

[0090] Optionally, the authentication information is carried in a query response message, which can be an EasyMesh message. For example, the message format of the query response message can be as shown in Table 2 below. In Table 2, the 12th byte is used to indicate that the message is a query response message; for example, when the value of the 12th byte is 0xF1, it indicates that the message is a query response message. The 13th byte is used to indicate the authentication type; for example, when the value of the 13th byte is 0x00, it indicates that the authentication type is device identifier authentication; when the value of the 13th byte is 0x01, it indicates that the authentication type is MAC authentication. The 16th byte onwards contains the authentication information. In this embodiment, the number of bytes occupied by the authentication information is determined by the actual data volume of the authentication information.

[0091] Table 2 Query Response Messages

[0092]

[0093] By using steps 301 and 302, the multi-access point controller can automatically obtain the authentication information of the multi-access point agent, which is convenient and efficient.

[0094] Optionally, when the multi-access point controller and the multi-access point agent are connected via optical fiber, the multi-access point controller and the multi-access point agent communicate with each other via FTTR messages or PON messages. The aforementioned easymesh message can be encapsulated as a payload in the FTTR or PON message structure.

[0095] It should be noted that in other embodiments, the method by which the multi-access point controller obtains the authentication information of the multi-access point agent can be replaced by: the multi-access point controller not sending a query message, but the multi-access point agent actively reporting the authentication information to the multi-access point controller after going online; or, the multi-access point controller receiving the authentication information of the multi-access point agent directly input.

[0096] It should also be noted that the names of the query message and query response message are just examples. In actual applications, they can be modified to other message names as needed.

[0097] In 303, the multi-access point controller sends an authentication request to the OLT.

[0098] Accordingly, the OLT receives the authentication request.

[0099] Optionally, the authentication request includes authentication information sent by a multi-access point agent (MAPA). In some embodiments, the authentication request includes authentication information sent by one MAPA. In other embodiments, the authentication request includes authentication information sent by multiple MAPAs.

[0100] Optionally, the authentication request may also include the network media type. This network media type indicates the connection medium between the multi-access point agent and the multi-access point controller. Optionally, the network media type includes, but is not limited to, fiber optic, network cable, wireless, and powerline cables. In this way, in addition to authentication information, the OLT can perform fine-grained authentication of the multi-access point agent based on its corresponding network media type. For example, only multi-access point agents with certain media types may be allowed to pass authentication.

[0101] Optionally, the authentication request may also include a port identifier indicating the downlink port of the multi-access point controller (MIPC) connected to the MIPC agent to be accessed. In this way, in addition to authentication information, the OLT can perform fine-grained authentication of the MIPC agent based on the port identifier of the downlink port corresponding to the MIPC agent. For example, only MIPC agents connected to certain downlink ports may be allowed to pass authentication.

[0102] Optionally, the authentication request can also include both the network media type and port identifier. This allows the OLT to perform fine-grained authentication of the multi-access point agent (MAPA) based on the port identifier of the downlink port and the corresponding network media type, in addition to authentication information. For example, only MAPAs connected via a specified network media type on certain downlink ports can be authorized for authentication.

[0103] Optionally, the authentication request is an OMCI message. For example, the message format of the authentication request is shown in Table 3 below. In Table 3, bytes 5-8 are used to indicate that the message is an authentication request. For example, when the value of bytes 5-8 is FFE50000, it indicates that the message is an authentication request. In Table 3, part of the bits in the 9th byte is the port identifier, and the other part is the network media type. For example, bits 0 to 4 are the port identifier, bits 5 to 7 are the network media type; the 10th byte is the multi-access point agent identifier, which can be assigned to the multi-access point agent by the multi-access point controller when the multi-access point agent comes online, and can be a numerical number, etc. In Table 3, bytes 11 to 42 are used to carry authentication information.

[0104] Table 3 Authentication Request

[0105]

[0106] Authentication request message content

[0107] property Size (bytes) describe Attribute mask 2 Multi-access point agent authentication identifier

[0108] In a 304 error, the OLT sends an authentication result message to the multi-access point controller.

[0109] The authentication result message includes authentication result information indicating whether the multi-access point agent has passed authentication. Accordingly, the multi-access point controller receives the authentication result message and can retrieve the authentication result information from it.

[0110] Optionally, the authentication result message may also include configuration information that indicates the control method for a multi-access point agent that has failed authentication.

[0111] Optionally, the authentication result message is an OMCI message. For example, the message format of the authentication result message is shown in Table 4 below. In Table 4, bytes 5-8 are used to indicate that the message is an authentication result message corresponding to an authentication request. For example, when the value of bytes 5-8 is FFE50001, it indicates that the message is an authentication result message corresponding to an authentication request. Bytes 9-42 are used to carry authentication result information. The authentication result information includes authentication information and authentication result, so that the multi-access point controller can determine which multi-access point agent the corresponding authentication result belongs to based on the authentication information.

[0112] Optionally, the authentication result message also includes information type indication information, which indicates the type of information carried in the authentication result message. For example, the information types include authentication information, authentication result, and configuration information of the multi-access point agent. For instance, in Table 4, bytes 9-42 contain two bytes representing an attribute mask (i.e., the information type indication information). Optionally, the attribute mask can be bytes 9 and 10. The first bit in the attribute mask (e.g., Bit 0 in Table 4) indicates whether the message content of the authentication result message carries authentication information of the multi-access point agent; the second bit in the attribute mask (e.g., Bit 1 in Table 4) indicates whether the message content of the authentication result message carries the authentication result of the multi-access point agent; and the third bit in the attribute mask (e.g., Bit 2 in Table 4) indicates whether the message content of the authentication result message carries a control method indicating a multi-access point agent that failed authentication.

[0113] Optionally, each bit in the attribute mask is associated with a portion of the bytes corresponding to the message content, and different bits are associated with different bytes. For example, suppose the attribute mask consists of bytes 9 and 10. The first bit is associated with bytes 11 and 12. If the first bit has a first value, it indicates that the authentication result message carries authentication information of the multi-access point agent, and the corresponding authentication information of the multi-access point agent can be obtained from the bytes associated with the first bit.

[0114] Alternatively, the second bit in the attribute mask can directly indicate the authentication result of the multi-access point agent (MIPA), and / or the third bit can be used to directly indicate the control method for an unauthenticated MIPA. For example, when the second bit is the first value, it indicates that the MIPA has been authenticated; when the second bit is the second value, it indicates that the MIPA has not been authenticated. As another example, when the third bit is the first value, it indicates that the network functions of the unauthenticated MIPA are restricted; when the third bit is the second value, it indicates that the network functions of the unauthenticated MIPA are disabled. Here, the first value is 0 and the second value is 1; or, the first value is 1 and the second value is 0.

[0115] Table 4 Authentication Result Message

[0116] Byte number Size Use 1..2 2 Transaction correlation identifier 3 1 Message type: Set (MT=8) 4 1 Device identifier: 0x0A 5..8 4 Message identifier: FFE50001 9..42 34 Message contents 43..48 8 OMCI trailer

[0117] Message content of authentication result message

[0118]

[0119] It should be noted that in this embodiment, the configuration information is carried in the authentication result message. In other embodiments, the configuration information can be sent using a message other than the authentication result message. For example, the configuration information can be sent by the OLT to the multi-access point controller immediately after the multi-access point controller comes online; or the multi-access point controller can store it in advance.

[0120] It should be noted that the names of the authentication request and authentication result messages are just examples. In actual applications, they can be modified to other message names as needed.

[0121] In 305, the multi-access point controller controls the multi-access point agent based on the authentication result information.

[0122] Optionally, controlling the multi-access point agent includes controlling the network functions of the multi-access point agent.

[0123] Optionally, the 305 includes:

[0124] When the authentication result indicates that the multi-access point agent has passed authentication, the multi-access point agent is allowed to access the network; or, when the authentication result indicates that the multi-access point agent has failed authentication, the network functions of the multi-access point agent are restricted or disabled.

[0125] Optionally, disabling network functions includes interrupting link-layer connections or maintaining link-layer connections but prohibiting the use of all network services. Restricting network functions means prohibiting the use of some network services, such as prohibiting the use of IPTV services or voice services.

[0126] In this embodiment, the multi-access point controller first obtains the authentication information of the multi-access point agent, and then sends the authentication information of the multi-access point agent to the OLT through an authentication request. The OLT then sends the corresponding authentication result information based on the authentication request. In this way, the OLT only performs authentication on the multi-access point agent corresponding to the authentication information.

[0127] Figure 4 This is a flowchart illustrating a control and authentication method for an access device provided in an embodiment of this application. In this embodiment, an example is provided using a main gateway as a multi-access point proxy and the access device as a multi-access point proxy. Figure 4 As shown, the method includes:

[0128] In 401, the OLT sends an authentication whitelist to the multi-access point controller.

[0129] This authentication whitelist is used to indicate which multi-access point agents have been authenticated. For example, the authentication whitelist includes the identity information of at least one authenticated multi-access point agent. Here, the authentication whitelist is the authentication result information. The relevant content of the identity information is described in step 302 above and will not be repeated here.

[0130] Accordingly, the multi-access point controller receives the authentication whitelist. After receiving the authentication whitelist, the multi-access point controller can store the whitelist in local memory for use when multiple access point agents need to access the network later.

[0131] In this embodiment, the OLT can send the authentication whitelist after the multi-access point controller (MIB) comes online. The authentication whitelist is generated based on the authentication configuration information obtained by the OLT. This authentication configuration information can be input via an input device or obtained by importing a configuration file. The authentication configuration information may include the identifier of at least one MIB and the authentication whitelist corresponding to each MIB.

[0132] Optionally, the authentication result information is carried in an authentication result message, which is an OMCI message.

[0133] For example, the message format of the authentication result message carrying the authentication whitelist is shown in Table 5 below.

[0134] In Table 5, bytes 5-8 are used to indicate that the message is an authentication result message carrying an authentication whitelist. For example, when the value of bytes 5-8 is FFE50002, it means that the message is an authentication result message carrying an authentication whitelist.

[0135] In Table 5, bytes 9-42 are used to carry the authentication whitelist. In implementation, a portion of bytes 9-42 is used as an attribute mask. This attribute mask indicates the number of multi-access point (MAP) agents in the authentication whitelist, facilitating quick determination of the total number of MAP agents in the whitelist. For example, the attribute mask may consist of 2 bytes (16 bits). When a bit has the first value, it indicates the presence of a corresponding MAP agent; when a bit has the second value, it indicates the absence of a corresponding MAP agent. Thus, the number of bits with the first value in the attribute mask represents the number of MAP agents in the authentication whitelist. Optionally, the first value can be 1 and the second value 0; or the first value can be 0 and the second value 1.

[0136] For example, each bit in the attribute mask is associated with multiple consecutive bytes in the message content, and each bit is associated with a different byte. For instance, when the attribute mask consists of 2 bytes, each bit in the attribute mask is associated with 2 consecutive bytes. When a bit in the attribute mask has a first value, the identity information of a multi-access point agent can be obtained from the byte corresponding to that bit.

[0137] Table 5 Authentication Result Message

[0138] Byte number Size Use 1..2 2 Transaction correlation identifier 3 1 Message type:Set(MT=8) 4 1 Device identifier: 0x0A 5..8 4 Message identifier: FFE50002 9..42 34 Message contents 43..48 8 OMCI trailer

[0139] Message content

[0140]

[0141] In step 402, the multi-access point controller sends a query message to the multi-access point agent.

[0142] For related information, please refer to 301; detailed descriptions are omitted here.

[0143] In a 403 error, the multi-access point agent sends authentication information to the multi-access point controller.

[0144] For related information, please refer to 302; detailed descriptions are omitted here.

[0145] In a 404 error, the multi-access point controller controls the network functions of the multi-access point agent based on an authentication whitelist.

[0146] In a 404 error, if the authentication whitelist contains identity information that matches the received authentication information, it means that the multi-access point agent has been authenticated and is allowed to access the network; or, if the authentication whitelist does not contain identity information that matches the received authentication information, it means that the multi-access point agent has not been authenticated and its network functions are restricted or disabled.

[0147] By using the 402-404 errors mentioned above, it is possible to control the multi-access point proxy based on the authentication result information.

[0148] Optionally, the method further includes: the OLT sending configuration information to the multi-access point controller (MIB), the configuration information indicating the control method for unauthenticated MIBs. In this case, the MIB controls the network functions of the MIB based on the authentication whitelist and the configuration information. In one possible implementation, both the configuration information and the authentication whitelist are sent to the MIB via an authentication result message. In another possible implementation, the configuration information is sent to the MIB via a separate message (i.e., a message other than the authentication result message).

[0149] In other embodiments, the authentication whitelist can be replaced by an authentication blacklist, which includes the identity information of at least one multi-access point agent (MIPA) that has failed authentication. Accordingly, 404 is replaced with: if the authentication blacklist does not contain identity information identical to the received authentication information, it indicates that the MIPA has passed authentication, and the MIPA is allowed to access the network; or, if the authentication blacklist contains identity information identical to the received authentication information, it indicates that the MIPA has failed authentication, and the network functions of the MIPA are restricted or disabled.

[0150] It should be noted that in other embodiments, the authentication whitelist can be replaced by an authentication list, which includes the identity information of at least one authenticated multi-access point agent and the identity information of at least one unauthenticated multi-access point agent. Accordingly, 404 is replaced with: when the identity information of an authenticated multi-access point agent in the authentication list includes the authentication information of that multi-access point agent, it indicates that the multi-access point agent is authenticated and is allowed to access the network; or, when the identity information of an unauthenticated multi-access point agent in the authentication list includes the authentication information of that multi-access point agent, it indicates that the multi-access point agent is unauthenticated, and the network functions of the multi-access point agent are restricted or disabled.

[0151] In this embodiment, authentication result information is sent in the form of an authentication list, eliminating the need for the multi-access point controller (MIB) to send authentication requests to the OLT, thus saving network resources. Furthermore, the OLT pre-sends the authentication list, so when the MIB agent needs to access the network, the MIB can directly authenticate the MIB agent and control its network functions based on this list, without waiting for interaction between the MIB and the OLT, thereby improving the authentication efficiency of the MIB agent.

[0152] Figure 5 This is a schematic diagram of the structure of a control device for an access device provided in an embodiment of this application. For example... Figure 5 As shown, the control device 500 includes an acquisition module 501 and a control module 502. The acquisition module 501 is used to acquire authentication result information from the optical line terminal, which indicates whether the access device to be accessed has passed authentication and is communicatively connected to the main gateway. The control module 502 is used to control the access device to be accessed based on the authentication result information.

[0153] Optionally, the control device 500 further includes a first sending module 503. The first sending module 503 is used to send an authentication request to the OLT, the authentication request including the aforementioned authentication information. In this case, the acquisition module 501 is used to receive authentication result information sent by the OLT according to the authentication request.

[0154] Optionally, the acquisition module 501 is used to receive an authentication list sent by the OLT, which includes the identity information of at least one authenticated access device and / or the identity information of at least one unauthenticated access device.

[0155] Optionally, the control module 502 is configured to allow the access device to use network functions when the authentication result information indicates that the access device to be accessed has passed authentication; or, when the authentication result information indicates that the access device to be accessed has failed authentication, restrict or disable the network functions of the access device to be accessed.

[0156] Optionally, the control device 500 further includes a second sending module 504 and a first receiving module 505. The second sending module 504 is used to send a query message to the access device to be accessed, the query message being used to instruct the access device to send authentication information. The first receiving module 505 is used to receive the authentication information sent by the access device to be accessed.

[0157] Optionally, the control device 500 further includes a second receiving module 506. The second receiving module 506 is used to receive configuration information sent by the OLT, which is used to indicate the control method for unauthenticated access devices.

[0158] It should be noted that the control device for the access device provided in the above embodiments is only illustrated by the division of the above functional modules. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the control device for the access device provided in the above embodiments and the control method embodiments for the access device belong to the same concept, and the specific implementation process can be found in the method embodiments, which will not be repeated here.

[0159] Figure 6 This is a schematic diagram of the structure of an authentication device for an access device provided in an embodiment of this application. For example... Figure 6 As shown, the authentication device 600 includes a sending module 601, which is used to send authentication result information to the main gateway. The authentication result information indicates whether the access device to be accessed has passed authentication, and the access device to be accessed is communicatively connected to the main gateway.

[0160] The authentication device 600 further includes a receiving module 602. The receiving module 602 is used to receive an authentication request sent by the main gateway, the authentication request including authentication information of the access device to be accessed; the sending module 601 is used by the OLT to send authentication result information to the main gateway according to the authentication request.

[0161] Optionally, the sending module 601 is used to send an authentication result message to the main gateway. The authentication result message is an OMCI message and carries authentication result information.

[0162] Optionally, the sending module 601 is also used to send configuration information to the main gateway, which is used to indicate the control method for unauthenticated access devices.

[0163] It should be noted that the authentication device for the access device provided in the above embodiments is only illustrated by the division of the above functional modules. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the authentication device for the access device provided in the above embodiments and the authentication method embodiments for the access device belong to the same concept, and the specific implementation process can be found in the method embodiments, which will not be repeated here.

[0164] The descriptions of the processes corresponding to the above-mentioned figures each have their own emphasis. For parts of a process that are not described in detail, please refer to the relevant descriptions of other processes.

[0165] This application also provides a communication device 700. For example... Figure 7 As shown, the communication device 700 includes a bus 702, a processor 704, and a communication interface 708. The processor 704 and the communication interface 708 communicate via the bus 702.

[0166] The 702 bus can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of representation, Figure 7 The bus 702 may be represented by a single line, but this does not mean that there is only one bus or one type of bus. The bus 702 may include a path for transmitting information between various components of the communication device 700 (e.g., memory 706, processor 704, communication interface 708).

[0167] Processor 704 may include any one or more processors such as a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).

[0168] Optionally, the communication device 700 further includes a memory 706, and the memory 706, the processor 704, and the communication interface 708 communicate with each other via a bus 702.

[0169] The memory 706 may include volatile memory, such as random access memory (RAM). The processor 704 may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid state drive (SSD).

[0170] The memory 706 stores executable program code, and the processor 704 executes the executable program code to implement the functions of the aforementioned modules, thereby realizing the control method or authentication method for the access device. That is, the memory 706 stores program code for the control method or authentication method for the access device.

[0171] The communication interface 708 uses transceiver modules such as, but not limited to, network interface cards and transceivers to enable communication between the communication device 700 and other devices or communication networks.

[0172] It should be understood that this application does not limit the number of processors in the communication device 700.

[0173] This application also provides a computer program product containing instructions. The computer program product may be a software or program product containing instructions, capable of running on a computer device or stored on any usable medium. When the computer program product is run on at least one computer device, it causes the at least one computer device to execute the aforementioned access device control method or access device authentication method.

[0174] This application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that a computer device can store, or a data storage device such as a data center containing one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive). The computer-readable storage medium includes instructions that instruct the computer device to execute the aforementioned control method or authentication method of the access device.

[0175] This application also provides a chip. The chip includes a processor and a communication interface, the communication interface being connected to the processor; the processor is used to execute instructions so that the chip performs the aforementioned access device control method or access device authentication method.

[0176] Unless otherwise defined, the technical or scientific terms used herein shall have the ordinary meaning as understood by one of ordinary skill in the art to which this application pertains. The terms “first,” “second,” “third,” and similar terms used in this patent application specification and claims do not indicate any order, quantity, or importance, but are merely used to distinguish different components. Similarly, the terms “an” or “a” and similar terms do not indicate a quantity limitation, but rather indicate the presence of at least one. The terms “comprising” or “including” and similar terms mean that the elements or objects preceding “comprising” or “including” encompass the elements or objects listed following “comprising” or “including” and their equivalents, and do not exclude other elements or objects. The “multiple” mentioned in the embodiments of this application refers to two or more. A and / or B indicate three possibilities: A; B; and A and B.

[0177] The above is merely one embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.

Claims

1. A control method for an access device, characterized in that, include: The main gateway obtains authentication result information from the optical line terminal. The authentication result information is used to indicate whether the access device to be accessed has passed authentication. The access device to be accessed communicates with the main gateway. Based on the authentication result information, the access device to be accessed is controlled.

2. The method according to claim 1, characterized in that, The method further includes: Send an authentication request to the optical line terminal, the authentication request including the authentication information of the access device to be accessed; The main gateway obtains authentication result information from the optical line terminal, including: Receive the authentication result information sent by the optical line terminal according to the authentication request.

3. The method according to claim 2, characterized in that, The authentication request also includes at least one of the following: network media type and port identifier, wherein the network media type is used to indicate the connection medium between the main gateway and the access device to be accessed, and the port identifier is used to indicate the downlink port of the main gateway, which is connected to the access device to be accessed.

4. The method according to claim 1, characterized in that, The acquisition of authentication result information from the optical line terminal includes: The system receives an authentication list sent by the optical line terminal, the authentication list including the identity information of at least one authenticated access device and / or the identity information of at least one unauthenticated access device.

5. The method according to claim 2 or 3, characterized in that, The authentication request is an Optical Network Unit Management and Control Interface (OMCI) message.

6. The method according to any one of claims 1 to 5, characterized in that, The authentication result information carries an authentication result message, which is an OMCI message.

7. The method according to any one of claims 1 to 6, characterized in that, The method further includes: Send a query message to the access device to be accessed, the query message being used to instruct the access device to send authentication information; The system receives a query response message from the access device to be accessed, the query response message including the authentication information.

8. The method according to claim 7, characterized in that, The query message includes an authentication type, and the type of the authentication information matches the authentication type.

9. The method according to claim 7 or 8, characterized in that, The query message and the query response message are EasyMesh messages.

10. The method according to any one of claims 1 to 9, characterized in that, The method further includes: The system receives configuration information sent by the optical line terminal, which is used to indicate the control method for unauthenticated access devices.

11. The method according to any one of claims 1 to 10, characterized in that, The step of controlling the access device to be accessed based on the authentication result information includes: When the authentication result information indicates that the access device to be accessed has passed authentication, the access device to be accessed is allowed to use network functions; or, When the authentication result information indicates that the access device to be accessed has failed authentication, the network functions of the access device to be accessed are restricted or disabled.

12. An authentication method for an access device, characterized in that, include: The optical line terminal sends the authentication result information to the main gateway; The authentication result information is used to indicate whether the access device to be accessed has passed authentication, and the access device to be accessed communicates with the main gateway.

13. The method according to claim 12, characterized in that, The method further includes: Receive an authentication request sent by the main gateway, the authentication request including the authentication information of the access device to be accessed; The optical line terminal sends authentication result information to the main gateway, including: The optical line terminal sends the authentication result information to the main gateway according to the authentication request.

14. The method according to claim 13, characterized in that, The authentication request also includes at least one of the following: network media type and port identifier, wherein the network media type is used to indicate the connection medium between the main gateway and the access device to be accessed, and the port identifier is used to indicate the downlink port of the main gateway, which is connected to the access device to be accessed.

15. The method according to claim 12, characterized in that, The authentication result information includes an authentication list, which includes the identity information of at least one authenticated access device and / or the identity information of at least one unauthenticated access device.

16. The method according to claim 13 or 14, characterized in that, The authentication request is an OMCI message.

17. The method according to any one of claims 11 to 16, characterized in that, The optical line terminal sends authentication result information to the main gateway, including: The optical line terminal sends an authentication result message to the main gateway. The authentication result message is an OMCI message and carries the authentication result information.

18. The method according to any one of claims 11 to 17, characterized in that, The method further includes: The system sends configuration information to the main gateway, which is used to indicate the control method for unauthenticated access devices.

19. A control device for an access device, characterized in that, include: The acquisition module is used to acquire authentication result information from the optical line terminal. The authentication result information is used to indicate whether the access device to be accessed has passed authentication. The access device to be accessed is communicatively connected to the main gateway. The control module is used to control the network functions of the access device to be accessed based on the authentication result information.

20. An authentication device for an access device, characterized in that, include: The sending module is used to send authentication result information to the main gateway; The authentication result information is used to indicate whether the access device to be accessed has passed authentication, and the access device to be accessed communicates with the main gateway.

21. A communication device, characterized in that, The device includes a processor and a transceiver connected to the processor, wherein the processor is configured to implement the method as claimed in any one of claims 1 to 10, or to implement the method as claimed in any one of claims 11 to 17.

22. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a software program that, when read and executed by one or more processors, implements the method as described in any one of claims 1 to 10, or implements the method as described in any one of claims 11 to 17.

23. An optical communication system, characterized in that, include: The system comprises an optical line terminal, a main gateway, and at least one access device, wherein the main gateway is configured to implement the method as described in any one of claims 1 to 10, and the optical line terminal is configured to implement the method as described in any one of claims 11 to 17.