Method, equipment, device and medium for passive optical network activation
By transmitting key control messages and reports through the PLOAM channel, the problem of key and encryption algorithm mismatch in passive optical networks is solved, ensuring the stability and reliability of communication, achieving key and encryption algorithm matching after encryption algorithm changes, and improving network performance.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ALCATEL LUCENT SHANGHAI BELL CO LTD
- Filing Date
- 2024-10-28
- Publication Date
- 2026-05-08
AI Technical Summary
In passive optical networks, existing technologies suffer from a mismatch between keys and encryption algorithms, leading to unstable and unreliable communication. In particular, when encryption algorithms are changed or devices are powered off, the OMCI channel cannot be updated in a timely manner, resulting in inconsistencies between keys and encryption algorithms.
By transmitting key control messages and key reports through the PLOAM channel, it is ensured that the first and second devices can match and generate keys using the new encryption algorithm when the encryption algorithm is changed. The key control message is used to instruct the generation and confirmation of the key, the integrity key is generated using the new encryption algorithm, and the message integrity is checked through the PLOAM message to ensure communication stability.
This technology enables the matching of keys and encryption algorithms after the encryption algorithm is changed in passive optical networks, improving the stability and reliability of communication and avoiding communication failures caused by key and encryption algorithm mismatch.
Smart Images

Figure CN122002153A_ABST
Abstract
Description
Technical Field
[0001] The exemplary embodiments of this disclosure relate to the field of communication technology, and more particularly to methods, apparatuses, devices, and computer-readable media for activation of passive optical networks. Background Technology
[0002] With the rapid development of modern communication technologies, the construction and optimization of network infrastructure have become crucial factors driving the development of the information society. Optical fiber communication, as a high-bandwidth, low-loss transmission medium, has been widely applied and promoted. Among numerous optical fiber communication technologies, Passive Optical Networks (PONs) have become the primary choice for broadband access networks such as Fiber to the Home (FTTH) due to their high efficiency and cost-effectiveness.
[0003] Passive optical networks (PONs) are designed to reduce the number of active devices in the network, distributing signals to multiple users through fiber optic distribution networks, thus lowering construction and maintenance costs. With continuous technological advancements, novel PON technologies and activation methods have been proposed. These technologies not only improve network performance and stability but also offer more possibilities for future network development. Therefore, researching and optimizing the activation process of PONs is of great significance for enhancing overall network performance. Summary of the Invention
[0004] In a first aspect of this disclosure, a first apparatus for activating a passive optical network is provided. The first apparatus includes: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the first apparatus to at least: receive a key control message from a second apparatus during a key exchange, the key control message instructing the first apparatus to: generate and send a key by employing an encryption algorithm to be used; or confirm a key corresponding to the currently used encryption algorithm; generate a key report based on the key control message; and send the key report to the second apparatus.
[0005] In a second aspect of this disclosure, a second apparatus for activating a passive optical network is provided. The second apparatus includes: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the second apparatus to at least: send a key control message to a first apparatus during a key exchange process, the key control message instructing the first apparatus to: generate and send a key by employing an encryption algorithm to be used; or confirm a key corresponding to the currently used encryption algorithm; and receive a key report from the first apparatus, the key report being generated by the first apparatus based on the key control message.
[0006] In a third aspect of this disclosure, a communication system is provided. The communication system includes: a first device according to a first aspect of this disclosure, or a second device according to a second aspect of this disclosure.
[0007] In a fourth aspect of this disclosure, a communication method is provided. The communication method includes: receiving a key control message from a second device during a key exchange process, the key control message instructing a first device to: generate and send a key by employing an encryption algorithm to be used; or confirm the key corresponding to the currently used encryption algorithm; generating a key report based on the key control message; and sending the key report to the second device.
[0008] In a fifth aspect of this disclosure, a communication method is provided. The communication method includes: sending a key control message to a first device during a key exchange process, the key control message instructing the first device to: generate and send a key by employing an encryption algorithm to be used; or confirm a key corresponding to the currently used encryption algorithm; and receiving a key report from the first device, the key report being generated by the first device based on the key control message.
[0009] In a sixth aspect of this disclosure, an apparatus for communication is provided. The apparatus includes: a component for receiving a key control message from a second device during a key exchange process, the key control message instructing a first device to: generate and send a key by employing an encryption algorithm to be used; or confirm a key corresponding to the currently used encryption algorithm; generate a key report based on the key control message; and send the key report to the second device.
[0010] In a seventh aspect of this disclosure, an apparatus for communication is provided. The apparatus includes: a component for sending a key control message to a first device during a key exchange process, the key control message instructing the first device to: generate and send a key by employing an encryption algorithm to be used; or confirm a key corresponding to the currently used encryption algorithm; and to receive a key report from the first device, the key report being generated by the first device based on the key control message.
[0011] In an eighth aspect of this disclosure, a first apparatus for a passive optical network (PON) is provided. The first apparatus includes: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the first apparatus to at least: regenerate at least one first integrity key (IK) based on the new encryption algorithm to be used if it is determined that an encryption algorithm change has occurred in the first apparatus and a second apparatus communicating with the first apparatus in the PON; immediately begin using at least one first IK; or begin using at least one first IK after satisfying at least one of the following conditions: completing a specific message exchange between the first and second apparatus using a target IK; or receiving a specific downlink frame by the first apparatus.
[0012] In a ninth aspect of this disclosure, a second apparatus for a passive optical network (PON) is provided. The second apparatus includes: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the second apparatus to at least: regenerate at least one second integrity key (IK) based on the new encryption algorithm to be used if it is determined that an encryption algorithm change has occurred in the second apparatus and a first apparatus communicating with the second apparatus in the PON; immediately begin using the at least one second IK; or begin using the at least one second IK after conditions are met, including at least one of the following: a specific message exchange is completed between the first and second apparatuses using the target IK; or a specific downlink frame is transmitted by the second apparatus.
[0013] In a tenth aspect of this disclosure, a communication method is provided. The communication method includes: if it is determined that an encryption algorithm change has occurred in a first device and a second device communicating with the first device in a PON, regenerating at least one first integrity key (IK) based on the new encryption algorithm to be used; immediately initiating use of the at least one first IK; or initiating use of the at least one first IK after satisfying conditions, said conditions including at least one of the following: completing a specific message exchange between the first device and the second device using a target IK; or receiving a specific downlink frame by the first device.
[0014] In the eleventh aspect of this disclosure, a communication method is provided. The communication method includes: if it is determined that a first device communicating with the second device in a PON has changed its encryption algorithm, at least one second integrity key (IK) is regenerated based on the new encryption algorithm to be used; the at least one second IK is immediately used; or the at least one second IK is used after certain conditions are met, the conditions including at least one of the following: a specific message exchange is completed between the first and second devices using a target IK; or a specific downlink frame is sent by the second device.
[0015] In a twelfth aspect of this disclosure, an apparatus for communication is provided. The apparatus includes: components for regenerating at least one first integrity key (IK) based on a new encryption algorithm to be used if a second device, in which a first device is communicating with the first device in a PON, undergoes an encryption algorithm change; components for immediately initiating use of the at least one first IK; or components for initiating use of the at least one first IK after conditions are met, said conditions including at least one of: completing a specific message exchange between the first and second devices using a target IK; or receiving a specific downlink frame by the first device.
[0016] In a thirteenth aspect of this disclosure, an apparatus for communication is provided. The apparatus includes: components for regenerating at least one second integrity key (IK) based on a new encryption algorithm to be used if it is determined that an encryption algorithm change has occurred in a second device and a first device communicating with the second device in a PON; components for immediately initiating use of the at least one second IK; or components for initiating use of the at least one second IK after a condition is met, the condition including at least one of the following: the components for initiating use of the at least one second IK after a condition is met, the condition including at least one of the following; or a specific downlink frame being transmitted by the second device.
[0017] In a fourteenth aspect of this disclosure, a computer-readable medium is provided. The computer-readable medium stores instructions that, when executed by at least one processing unit, configure the at least one processing unit to perform the method according to the fourth, fifth, tenth, or eleventh aspect.
[0018] It should be understood that the description in the Summary of the Invention is not intended to limit the key or essential features of the embodiments of this disclosure, nor is it intended to restrict the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description
[0019] Exemplary embodiments of this disclosure are presented by way of example, and their advantages are explained in more detail below with reference to the accompanying drawings, wherein
[0020] Figures 1A to 1C Some example communication processes in a passive optical network are shown;
[0021] Figure 2 A schematic diagram of an environment in which the example embodiments described in this disclosure may be implemented is shown;
[0022] Figure 3 Signaling diagrams for key exchange in a passive optical network according to some example embodiments of the present disclosure are shown;
[0023] Figure 4 Signaling diagrams for key exchange in a passive optical network according to some example embodiments of the present disclosure are shown;
[0024] Figure 5A A signaling diagram for message integrity checking in a passive optical network is shown according to some example embodiments of the present disclosure;
[0025] Figure 5B An example process for generating MIC information according to some example embodiments of this disclosure is shown;
[0026] Figure 6A flowchart illustrating a communication method for a passive optical network according to some example embodiments of the present disclosure is shown;
[0027] Figure 7 A flowchart illustrating a communication method for a passive optical network according to some example embodiments of the present disclosure is shown;
[0028] Figure 8 A flowchart illustrating a communication method for a passive optical network according to some example embodiments of the present disclosure is shown;
[0029] Figure 9 A flowchart illustrating a communication method for a passive optical network according to some example embodiments of the present disclosure is shown;
[0030] Figure 10 A simplified block diagram of a device suitable for implementing example embodiments of the present disclosure is shown; and
[0031] Figure 11 A schematic diagram of a computer-readable medium according to some example embodiments of the present disclosure is shown.
[0032] In all the accompanying drawings, the same or similar reference numerals denote the same or similar elements. Detailed Implementation
[0033] The principles and spirit of this disclosure will now be described with reference to several exemplary embodiments illustrated in the accompanying drawings. It should be understood that these specific exemplary embodiments are described only to enable those skilled in the art to better understand and implement this disclosure, and are not intended to limit the scope of this disclosure in any way.
[0034] As used herein, the term "comprising" and similar expressions should be understood as open-ended inclusion, i.e., "including but not limited to". The term "based on" should be understood as "at least partially based on". The term "an embodiment" or "the embodiment" should be understood as "at least one embodiment". The terms "first", "second", etc., may refer to different or the same objects. Other explicit and implicit definitions may also be included below.
[0035] As used herein, the term "determine" encompasses a wide variety of actions. For example, "determine" can include calculation, computation, processing, derivation, investigation, searching (e.g., looking in a table, database, or other data structure), ascertainment, etc. Furthermore, "determine" can include receiving (e.g., receiving information), accessing (e.g., accessing data in memory), etc. Additionally, "determine" can include parsing, selecting, choosing, building, etc.
[0036] In this document, unless explicitly stated otherwise, performing a step in response to A does not mean that the step is performed immediately after A, but may include one or more intermediate steps.
[0037] As used herein, the term “circuit device” / “circuit” means one or more of the following: (a) a hardware circuit implementation only (such as an implementation of analog and / or digital circuits only); and (b) a combination of hardware circuits and software, such as (if applicable): (i) a combination of analog and / or digital hardware circuits with software / firmware; and (ii) any part of a hardware processor with software (including digital signal processors, software, and memory that work together to enable devices such as optical communication devices or other computing devices to perform various functions); and (c) a hardware circuit and / or processor, such as a microprocessor or a part of a microprocessor, which requires software (e.g., firmware) for operation, but may be without software when it is not required for operation.
[0038] The definition of "circuit device" / "circuit" applies to all uses of this term in this application (including any claim). As another example, the term "circuit device" / "circuit" as used herein also covers only hardware circuitry or a processor (or processors), or a portion of hardware circuitry or a processor, or an implementation thereof with accompanying software or firmware. For example, if applicable to a particular claim element, the term "circuit device" also covers baseband integrated circuits or processor integrated circuits or similar integrated circuits in an OLT or other computing device.
[0039] As used herein, the term "Passive Optical Network (PON)" refers to a fiber optic communication network architecture that does not use any active electronic devices or power supplies during transmission. Instead, it distributes optical signals from the Optical Line Terminal (OLT) to multiple Optical Network Units (ONUs) through a Passive Optical Distribution Network (ODN). PONs utilize optical splitters to distribute optical signals, allowing multiple users to share a single fiber optic link, thereby achieving efficient and economical broadband access.
[0040] As used herein, the term "Optical Network Unit (ONU)" refers to a device located at the user end in a Passive Optical Network (PON) architecture. The ONU is responsible for converting optical signals transmitted through optical fibers into electrical signals for use by user terminal equipment, and is one of the key devices for enabling user access to the optical fiber network. The ONU is typically connected to an Optical Line Terminal (OLT) and communicates through an Optical Distribution Network (ODN). It should be understood that the ONU is not limited to home user access but can also be used in various application scenarios such as enterprises and campuses. Given the rapid development in the communications field, there will certainly be future types of communication devices that can be used to implement this disclosure. This should not be construed as limiting the scope of this disclosure to only the aforementioned devices.
[0041] As used herein, the term "Optical Line Terminal (OLT)" refers to a device located at the service provider's end in a Passive Optical Network (PON) architecture. The OLT is responsible for managing and controlling the entire PON network, including communication with Optical Network Units (ONUs). The OLT converts electrical signals from the core network into optical signals, which are then transmitted to multiple ONUs via the Optical Distribution Network (ODN). It is also responsible for converting optical signals from the ONUs back into electrical signals and transmitting them to the core network. It should be understood that the OLT performs not only signal conversion but also network management, bandwidth allocation, fault detection, and other functions. Given the rapid development of the communications field, there will naturally be future types of communication devices that can be used to implement this disclosure. This should not be construed as limiting the scope of this disclosure to only the aforementioned devices.
[0042] As used herein, the term "Physical Layer Operation, Management and Maintenance (PLOAM)" refers to a set of protocols and functions used for physical layer operation, management and maintenance in a Passive Optical Network (PON) system. PLOAM information is transmitted between the OLT and ONUs, responsible for managing various operations of the PON network, including bandwidth allocation, fault detection, performance monitoring, and status reporting. Through the PLOAM channel, the OLT can send various management and control commands to the ONUs, and the ONUs can also report their status and performance information to the OLT through this channel. It should be understood that PLOAM is not limited to basic management and maintenance functions; it can also include some extended functions to meet the needs of different network environments.
[0043] G.9804.2 specifies five encryption algorithms: AES128, AES-256, Camellia-128, Camellia-256, and SM4-128. Other keys can be configured via OMCI. Key exchange is performed through PLOAM messages. When the encryption algorithm changes, the key needs to be updated. Therefore, timely communication between the OMCI and PLOAM modules in the OLT is required. Otherwise, key mismatches between the OLT and ONU may occur in the following situations.
[0044] Before configuring OMCI, the default key AES-128 can be used. The ONU reports its security capabilities to the OLT via the security capability attributes of the ONU2-G ME, and the OLT sets the current security mode of the ONU via the security mode attributes of the ONU2-G ME (specified by G.988 9.1.2 ONU2-G). For example, the OLT can request the ONU to use AES-256, and then the OLT and ONU switch to AES-256.
[0045] In G.988, a MIB reset operation is defined. Its purpose is to clear the MIB, reinitialize it to its default values, and reset the MIB data synchronization counter to 0. This means that the MIB reset operation will remove all configurations from the ONU in the OLT, and the ONU will set the security mode to 1, i.e., the default AES-128. However, the OLT may not switch to AES-128 in time and may still be using its configured encryption algorithm, such as SM4-128. When the periodic key exchange PLOAM is completed, a key and encryption algorithm mismatch may occur. This situation is particularly likely to occur in vOMCI scenarios because the vOMCI module is not in the physical OLT, while other encryption functions are still implemented in the physical OLT, which will cause communication between the vOMCI module and other encryption functions to be untimely.
[0046] If the ONU receives both a key exchange message and a MIB reset message at the same time, the ONU and OLT may not know whether the key exchange is for the old encryption algorithm or the new encryption algorithm, resulting in a key-encryption algorithm mismatch.
[0047] In other cases, key and encryption algorithm mismatch may also occur. For example, a power outage may occur during encryption algorithm configuration of the OLT or ONU. This can also lead to key and encryption algorithm mismatches, such as the OLT using AES-256 while the ONU uses AES-128. This will cause the OMCI channel to malfunction, as reconfiguration is difficult because it depends on the OMCI channel. The following will combine... Figures 1A to 1C This section introduces some situations where the key and encryption algorithm may mismatch.
[0048] Figures 1A to 1C This illustrates some example communication processes in a passive optical network. Figure 1A In the first communication process 100A shown, the optical network unit (ONU) 110 uses the default AES-128 after activation. In some example embodiments, the ONU 110 may report (102) its security capabilities to the OLT 120 to indicate that the default AES-128 is used for this ONU 110.
[0049] Furthermore, the Optical Line Terminal (OLT) 120 can set the security mode of the ONU 110 (104) to use SM4-128. After a new key exchange, both the ONU 110 and the OLT 120 use SM4-128. In some example embodiments, the OLT 120 can send a (106) MIB reset message to the ONU 110 to remove all configurations from the OLT 120. Based on the MIB reset message, the ONU 110 can switch the encryption algorithm to the default AES-128. However, the key of the ONU 110 is still used for SM4-128 at this time. In addition, the OLT 120 continues to use SM4-128 after the new key exchange. In this case, when the ONU 110 and the OLT 120 perform a (108) key exchange, an (110) encryption algorithm mismatch will occur.
[0050] exist Figure 1B In the second communication process 100B shown, similar to the first communication process 100A, the default AES-128 can also be used after activation on the ONU 110 side. The ONU 110 can also report (102) its security capabilities to the OLT 120 to indicate that the default AES-128 is used for this ONU 110. On the OLT 120 side, the security mode of the ONU 110 can be set (104) to use SM4-128. After the new key exchange, both the ONU 110 and the OLT 120 use SM4-128.
[0051] In some example embodiments, ONU 110 may simultaneously receive (112) both a key exchange message and a MIB reset message. In such a case, ONU 110 and OLT 120 will be unsure whether the key exchange is for SM4-128 or AES-128.
[0052] exist Figure 1C In the third communication process 100C shown, similar to the first communication process 100A, the default AES-128 can also be used after activation on the ONU 110 side. The ONU 110 can also report (102) its security capabilities to the OLT 120 to indicate that the default AES-128 is used for this ONU 110. On the OLT 120 side, the security mode of the ONU 110 can be set (104) to use SM4-128. After a new key exchange, both the ONU 110 and the OLT 120 use SM4-128. The OLT 120 can send a (106) MIB reset message to the ONU 110 to remove all configurations from the OLT 120.
[0053] In some example embodiments, based on the MIB reset message, ONU 110 and OLT 120 can simultaneously switch the encryption algorithm to the default AES-128. However, at this time, the keys of ONU 110 and OLT 120 are still for SM4-128. Further, ONU 110 and OLT 120 can perform (114) a key exchange for AES-128. After the new key exchange, both ONU 110 and OLT 120 use AES-128.
[0054] In some example embodiments, the OLT 120 can set the security mode of the ONU 110 (116) to use AES-256. Then, the ONU 110 and OLT 120 can perform (118) a key exchange for AES-256. After the new key exchange, both the ONU 110 and OLT 120 use AES-256.
[0055] During the aforementioned process, the ONU 110 and OLT 120 switched encryption algorithms multiple times based on the MIB reset message. This switching requires continuous message exchange between the OMCI and PLOAM channels to configure the encryption algorithm and generate new keys. This process may lead to inconsistencies in the encryption algorithm and keys between the ONU 110 and OLT 120. To avoid this problem, the PLOAM channel can be used to transmit the encryption algorithm.
[0056] The principles and exemplary embodiments of this disclosure will be further described in detail below with reference to the accompanying drawings.
[0057] Figure 2 A schematic diagram of an example communication environment 200 in which exemplary embodiments described herein may be implemented is shown. The communication environment 200 may be part of a communication network. The communication environment 200 includes a first device 210 and a second device 220. The communication environment 200 may include any number of first devices 210 and second devices 220. In embodiments of this disclosure, the first device 210 and the second device 220 are interchangeable; that is, the methods / steps implemented at the first device 210 described in the embodiments may also be implemented at the second device 220. It should be understood that the communication environment 200 is merely exemplary and is not intended to limit the scope of this disclosure in any way. In some example embodiments, the first device may include an optical network unit (ONU), and the second device may include an optical line terminal (OLT).
[0058] It should be understood that the communication environment 200 is described for illustrative purposes only and does not imply any limitation on the scope of this disclosure. For example, the exemplary embodiments of this disclosure can also be applied to systems different from the communication environment 200. The number of elements or entities shown is merely illustrative and not limiting. Moreover, elements or entities can communicate with each other using any communication technology currently known and developed in the future. As an example, in a passive optical network, the OLT is responsible for managing and controlling the entire passive optical network and distributing signals to multiple ONUs through an optical distribution network (ODN). Each ONU is responsible for converting the received optical signals into electrical signals for use by user terminal equipment. In this case, the communication environment 200 may include more than one ONU. A single OLT may be associated with one or more ONUs.
[0059] It should be understood that the number of devices and their connections shown in Figure 1 is merely illustrative and not limiting. The communication environment 200 may include any suitable number of devices configured to implement the exemplary embodiments of this disclosure. Although not shown, it should be understood that one or more other devices may be deployed in the communication environment 200.
[0060] In some example embodiments, the first device 210 may include an optical network unit (ONU) and the second device 220 may include an optical line terminal (OLT). Hereinafter, for illustrative purposes, some example embodiments are described with the first device 210 as an optical network unit (ONU) and the second device 220 as an optical line terminal (OLT) as examples. However, in some example embodiments, the operations described in connection with the first device or ONU can also be implemented at the second device or OLT. Similarly, the operations described in connection with the second device or OLT can also be implemented at the first device or ONU.
[0061] Communication in communication environment 200 can be implemented according to any appropriate communication protocol(s). Examples of communication protocols include, but are not limited to, cellular communication protocols such as first generation (1G), second generation (2G), 2.5G, 2.75G, third generation (3G), fourth generation (4G), 4.5G, fifth generation (5G), and sixth generation (6G), wireless local area network communication protocols such as the Institute of Electrical and Electronics Engineers (IEEE) 802.11, and / or any other protocols currently known or to be developed in the future.
[0062] Furthermore, communication may utilize any suitable wireless communication technology, including but not limited to: Code Division Multiple Access (CDMA), Frequency Division Multiple Access (FDMA), Time Division Multiple Access (TDMA), Frequency Division Duplex (FDD), Time Division Duplex (TDD), Multiple Input Multiple Output (MIMO), Orthogonal Frequency Division Multiplexing (OFDM), Spread Spectrum Orthogonal Frequency Division Multiplexing Based on Discrete Fourier Transform (DFT-s-OFDM), and / or any other technology currently known or to be developed in the future.
[0063] The principles and exemplary embodiments of this disclosure will be further described in detail below with reference to the accompanying drawings.
[0064] Figure 3 A signaling diagram of a key exchange 300 for a passive optical network according to some example embodiments of the present disclosure is shown. Reference will be made to this diagram for discussion purposes. Figure 2 and Figure 3 A signaling diagram is described for key exchange 300 for a passive optical network. In some example embodiments, the first device 210 may include an optical network unit (ONU), and the second device 220 may include an optical line terminal (OLT). It should be understood that, although Figure 3 Only a single first device 210 and a single second device 220 are shown in the diagram, but multiple first devices 210 and second devices 220 may also be involved in the signaling diagram 300.
[0065] like Figure 3 As shown, in some example embodiments, the first device 210 may report (302) its security capabilities to the second device 220 to indicate the default encryption algorithm used by the first device 210. The default encryption algorithm may be, for example, AES-128. In some example embodiments, the first device 210 may report its security capabilities to the second device 220 via the security capability attributes of the ONU2-G ME.
[0066] Furthermore, the second device 220 can set (304) the security mode to use the first encryption algorithm. In some example embodiments, the second device 220 can set the current security mode of the first device 210 through the security mode attribute of ONU2-G ME. For example, the second device 220 requests the first device 210 to use AES-256 as the first encryption algorithm. Then, the first device 210 and the second device 220 switch to AES-256. Subsequently, the first device 210 uses (306) the first key corresponding to the first encryption algorithm.
[0067] During the key exchange process, the first device 210 may receive a key control message (308) from the second device 220. The key control message instructs the generation and transmission of a second key using the second encryption algorithm to be used. The second encryption algorithm may be the same as or different from the first encryption algorithm. In some example embodiments, the key control message may be as shown in Table 1:
[0068] Table 1
[0069]
[0070]
[0071]
[0072] As shown in Table 1, the key control message indicating the generation and transmission of a second key using the second encryption algorithm to be used can be indicated in the control flag field. In "0000AAAC", "AAA" indicates the second encryption algorithm to be used, and "C" indicates the generation and transmission of a new key using the second encryption algorithm. In this case, "C" can be set to 0, for example.
[0073] In some example implementations, key control messages can be received within physical layer operation, management, and maintenance PLOAM messages.
[0074] Further, the first device 210 can generate a second key using the second encryption algorithm and generate (310) a key report. This key report indicates the generation of the second key using the second encryption algorithm and the second encryption algorithm used. Then, the first device 210 can send (312) the key report to the second device 220. In some example embodiments, the key report may be as shown in Table 2:
[0075] Table 2
[0076]
[0077]
[0078] As shown in Table 2, the new second key generated using the second encryption algorithm, as indicated in the key report, and the second encryption algorithm itself, can be indicated in the report type field. In "0000AAAR", "AAA" indicates the second encryption algorithm used to generate the new key, and "R" confirms that the second key is a newly generated key using the second encryption algorithm. In this case, "R" can be set to 0, for example.
[0079] It should be understood that the examples shown in Tables 1 and 2 are merely exemplary and are not intended to limit the scope of this disclosure.
[0080] In some other example embodiments, the first device 210 may receive (314) another key control message from the second device 220. The other key control message indicates confirmation of a second key generated using the currently used second encryption algorithm. Further, the first device 210 may generate (316) a key report using the confirmed second key and the second encryption algorithm. This key report indicates the currently used second encryption algorithm and the second key generated using it. Then, the first device 210 and the second device 220 may begin communicating using the (320) second key.
[0081] In this case, another key control message sent by the second device 220 and the corresponding key report sent by the first device 210 can still be indicated by the examples shown in Tables 1 and 2.
[0082] For example, confirmation of a second key generated using the currently used second encryption algorithm, as indicated by another key control message, can be indicated in the control flag field, where "AAA" in "0000AAAC" can indicate the second encryption algorithm to be used, and "C" can indicate confirmation of the second key generated by that second encryption algorithm. In this case, "C" can be set to 1, for example.
[0083] For example, the second encryption algorithm currently in use, as indicated in the key report, and the second key generated using the currently used second encryption algorithm can be indicated in the report type field. In "0000AAAR", "AAA" indicates the second encryption algorithm currently in use, and "R" confirms that the second key corresponds to the currently used second encryption algorithm. In this case, "R" can be set to 1, for example.
[0084] Figure 4 Signaling diagrams for a key exchange 400 for a passive optical network according to some example embodiments of this disclosure are shown. Reference will be made to these diagrams for discussion purposes. Figure 2 and Figure 4 A signaling diagram is described for key exchange 400 for a passive optical network. In some example embodiments, the first device 210 may include an optical network unit (ONU), and the second device 220 may include an optical line terminal (OLT). It should be understood that, although Figure 4 Only a single first device 210 and a single second device 220 are shown in the diagram, but multiple first devices 210 and second devices 220 may also be involved in the signaling diagram 400.
[0085] like Figure 4As shown, the first device 210 and the second device 220 can communicate using (402) a first key corresponding to the first encryption algorithm. In some example embodiments, the first encryption algorithm may be, for example, AES-256. The first device 210 can receive a (404) MIB reset message from the second device 220. In some example embodiments, the MIB reset message may be as shown in Table 3:
[0086] Table 3
[0087]
[0088] In some example embodiments, if a Management Information Base (MIB) reset message is received, the first device 210 may remove (406) the configuration associated with the Optical Network Unit Management and Control Interface (OMCI) while maintaining the use of the first key. In some example embodiments, the MIB reset message may be received via the Control Interface (OMCI).
[0089] In some example embodiments, the first device 210 may receive (408) key control information from the second device 220. This key control information may instruct the generation and transmission of a second key corresponding to a second encryption algorithm. The second encryption algorithm may be the same as or different from the first encryption algorithm. For example, the second encryption algorithm may still be AES-256. Alternatively, the second encryption algorithm may be AES-128. In some other embodiments, the second encryption algorithm may be a default encryption algorithm. In some example embodiments, the key control message may be received within a physical layer operation, management, and maintenance PLOAM message.
[0090] Furthermore, the first device 210 may generate (410) a second key based on key control information. In some example embodiments, the first device 210 may send (418) a key report to the second device. The key report indicates the second key generated using the second encryption algorithm and the second encryption algorithm used to generate the second key.
[0091] In other embodiments, the first device 210 may receive (414) key control information from the second device 220. This key control information may indicate confirmation of the key corresponding to the currently used encryption algorithm. In some example embodiments, the first device 210 may send (416) a key report to the second device 220, indicating a first key corresponding to the currently used first encryption algorithm and the currently used first encryption algorithm. Subsequently, the first device 210 may maintain (418) communication between the first device 210 and the second device 220 using the first key.
[0092] In the manner described above, key control messages and key reports can be used to indicate the encryption algorithms and corresponding keys used by the first device 210 and the second device 220, so that the keys used by the first device and the second device 220 match, thereby improving the stability and reliability of communication.
[0093] After the encryption algorithm is changed, the first device 210 and the second device 220 need to update their keys. Specifically, the first device 210 and the second device 220 are able to regenerate at least one integrity key (IK) based on the new encryption algorithm to be used. The first device 210 and the second device 220 need to verify each other's updated IK.
[0094] In G.9804.2, five cryptographic algorithms are specified: AES-128, AES-256, Camellia-128, Camellia-256, and SM4(-128). Before OMCI configuration, the first device 210 and the second device 220 can use the default encryption algorithm AES-128 to generate PLOAM IK for PLOAM message integrity checking and OMCI IK for OMCI message integrity checking.
[0095] Taking the first device 210 including an optical network unit (ONU) and the second device 220 including an optical line terminal (OLT) as an example, after the ONU is activated, it can report its security capabilities to the OLT through the security function attributes of the ONU2-G ME. The OLT can set the current security mode of the ONU through the security mode attributes of the ONU2-G ME.
[0096] The following will combine Figure 5A and Figure 5B The process of message integrity checking by the first device 210 and the second device 220 is described.
[0097] Figure 5A Signaling diagrams for message integrity checking in a passive optical network according to some example embodiments of this disclosure are shown. For discussion purposes, reference will be made to... Figure 2 and Figure 5A This describes a signaling diagram for message integrity checking 500 in a passive optical network. In some example embodiments, the first device 210 may include an optical network unit (ONU), and the second device 220 may include an optical line terminal (OLT). It should be understood that, although Figure 5A Only a single first device 210 and a single second device 220 are shown in the diagram, but multiple first devices 210 and second devices 220 may also be involved in the signaling diagram 500.
[0098] When the first device 210 joins the PON, both the first device 210 and the second device 220 can use some PLOAM messages to activate the first device 210. The PLOAM message structure is shown in Table 4:
[0099] Table 4
[0100]
[0101] like Figure 5A As shown, before the encryption algorithm switch occurs (508) between the first device 210 and the second device 220, the first device 210 and the second device 220 are in the registration phase. During this phase, the first device 210 can generate (502) a PLOAM IK and / or an OMCI IK for message integrity checking, and the second device 220 can also generate (504) a PLOAM IK and / or an OMCI IK for message integrity checking. The first device 210 and the second device 220 can mutually verify (506) each other's PLOAM IK and OMCI IK.
[0102] After the first device 210 and the second device 220 switch encryption algorithms (508), the first device 210 can use the new encryption algorithm to generate (510) a new PLOAM IK and / or OMCI IK, and the second device 220 can also use the new encryption algorithm to generate (512) a new PLOAM IK and / or OMCI IK.
[0103] In some example embodiments, the first device 210 and the second device 220 can immediately begin using the newly generated PLOAM IK and / or OMCI IK. In other example embodiments, the first device 210 and the second device 220 can begin using the newly generated PLOAM IK and / or OMCI IK after certain conditions are met. These conditions may include: completing a specific message exchange between the first device 210 and the second device 220 using the target IK, or receiving a specific downlink frame from the second device 220 by the first device 210.
[0104] Continue to refer to Figure 5A In some example embodiments, the first device 210 may generate Message Integrity Check (MIC) information based on the newly generated PLOAM IK and / or OMCI IK, and may transmit (514) a message including the MIC information to the second device 220. For example, the message may include a specific message for querying the security mode OMCI message, or a PLOAM message for querying the registration identifier.
[0105] Figure 5B An example process for generating MIC information according to some example embodiments of this disclosure is illustrated. In some example embodiments, such as Figure 5B As shown, the MIC field of PLOAM message 540 can be constructed using the AES-128 encryption algorithm. PLOAM message 540 can be sent to AES-CMAC-64 engine 570 by adding direction code 550. AES-CMAC-64 engine 570 can generate MIC information based on PLOAM message 540 and PLOAM IK 560, and add the MIC information as a field to PLOAM message 540.
[0106] In some example embodiments, a default PLOAM_IK value, such as (0x55)16, can be used for downlink broadcast PLOAM messages 540 and unicast PLOAM messages exchanged during the activation process of the first device 210 prior to the availability of a registered MSK, where the subscript 16 indicates the repetition multiple of the specified hexadecimal pattern.
[0107] In some example embodiments, once the first device 210 communicates its Registration_ID to the second device 220, a basic MSK can be established according to the following formula (1):
[0108] MSK = AES-CMAC((0x55) 16 , Registration_ID, 128) (1)
[0109] All derived shared keys can be obtained based on the following formulas (2), (3) and (4):
[0110] SK = BC-ECMAC(MSK, (SN | PON-TAG | PON-TAG | SN), Tlen) (2)
[0111] OMCI_IK=BC-ECMAC(SK,"OMCIIntegrityKeyMakeOMCImoreSafe",Tlen)(3)
[0112] PLOAM_IK=AES-CMAC(SK,0x504c4f414d496e7465677274794b6579,128)(4)
[0113] From the formulas shown above, it is easy to see that SK and OMCI-IK are related to encryption algorithms, while PLOAM-IK is usually calculated using the AES-128 encryption algorithm. After completing the above process, the first device 210 and the second device 220 begin using the PLOAM-IK Ranging_time PLOAM message, and the first device 210 completes activation.
[0114] In some example embodiments, if it is determined that a message containing MIC information has been received from the first device 210, the second device 220 may determine whether the MIC information can be verified using its newly generated PLOAM IK and / or OMCI IK. If it is determined that the MIC information can be verified using its newly generated PLOAM IK and / or OMCI IK, the second device 220 may verify (516) the message using its newly generated PLOAM IK and / or OMCI IK to generate another message including another MIC information, and send (518) the other message to the first device 210. Subsequently, the second device 220 may discard (520) the previously used old PLOAM IK and / or OMCI IK.
[0115] In other example embodiments, if it is determined that the MIC information cannot be verified using the newly generated PLOAM IK and / or OMCI IK, the second device 220 can verify (522) the message using the old PLOAM IK and / or OMCI IK previously used by the second device.
[0116] In some example embodiments, the first device 210 may use the target IK to generate (524) a specific message and transmit (526) the specific message to the second device 220. Accordingly, the second device 220 may also use the target IK to generate (528) a specific message and transmit (530) the specific message to the first device 210.
[0117] In some example embodiments, a specific message may include a request to register a PLOAM message, and the target IK may include a default IK, a previously used old PLOAM IK, or a newly generated PLOAM IK. In other example embodiments, a specific message may include a security mode OMCI message, and the target IK may include a default IK, a previously used old OMCI IK, or a newly generated OMCI IK.
[0118] Furthermore, if it is determined that a response to a lock-specific message has been received from the second device 220, the first device 210 may begin using (532) its newly generated PLOAM IK and / or OMCI IK. Accordingly, if it is determined that a response to a lock-specific message has been received from the first device 210, the second device 220 may also begin using its newly generated PLOAM IK and / or OMCI IK.
[0119] Continue to refer to Figure 5AIn some example embodiments, the second device 220 can transmit (534) a configuration of a frame counter value indicating IK switching to the first device 210 by acquiring a PLOAM setting function message, and start using the newly generated PLOAM IK and / or OMCI IK based on the frame counter value.
[0120] In some example embodiments, the first device 210 may receive a configuration indicating an IK switching frame counter value from the second device 220 via an acquisition setting function PLOAM message. If it is determined that a downlink frame corresponding to the frame counter value has been received from the second device 220, the first device 210 may begin using the newly generated PLOAM IK and / or OMCI IK.
[0121] In some example embodiments, the PLOAM message structure for obtaining settings can be as shown in Table 5:
[0122] Table 5
[0123]
[0124]
[0125]
[0126]
[0127] In some embodiments, the first device 210 and the second device 220 should use the new PLOAM-IK in the PHY frame specified by the SFC.
[0128] Figure 6 A flowchart of a communication method 600 for a passive optical network according to some example embodiments of the present disclosure is shown. Method 600 may be implemented, for example, in a communication environment 200, such as at a first device 210.
[0129] In block 610, the first device 210 receives a key control message from the second device 220 during key exchange. This key control message instructs the first device 210 to either generate and send a key using the encryption algorithm to be used, or to confirm the key corresponding to the currently used encryption algorithm.
[0130] In box 620, the first device 210 generates a key report based on the key control message.
[0131] In box 630, the first device 210 sends a key report to the second device 220.
[0132] In some example embodiments, generating a key report includes: if a key control message instructs the first device 210 to generate a key using the encryption algorithm to be used and to send the key; the first device 210 generates a key report indicating the key and the encryption algorithm used to generate the key.
[0133] In some example embodiments, if it is determined that another key control message is received from the second device 220 instructing the first device to confirm the key corresponding to the currently used encryption algorithm, the first device 210 reports the key and encryption algorithm to the second device 220; and the first device 210 begins to use the key for communication between the first device 210 and the second device 220.
[0134] In some example embodiments, generating a key report includes: if a key control message instructs the first device 210 to confirm a key corresponding to the currently used encryption algorithm, the first device 210 generates a key report indicating the key and the currently used encryption algorithm.
[0135] In some example embodiments, the first device 210 maintains the use of a key for communication between the first device 210 and the second device 220.
[0136] In some example embodiments, the first device 210 uses a first key corresponding to a first encryption algorithm, and generating a key report further includes: if it is determined that a Management Information Base (MIB) reset message has been received, the first device 210 removes the configuration associated with the Optical Network Unit Management and Control Interface (OMCI) while maintaining the use of the first key; if it is determined that a key control message has been received instructing the first device 210 to generate and send a second key corresponding to a second encryption algorithm, the first device 210 generates a second key based on the key control message, the second encryption algorithm being the same as or different from the first encryption algorithm; and the first device 210 sends a key report to the second device 220, the key report indicating the second key and the second encryption algorithm.
[0137] In some example implementations, the second encryption algorithm is the default encryption algorithm.
[0138] In some example embodiments, the first device 210 uses a first key corresponding to a first encryption algorithm, and the instructions, when executed by at least one processor, also cause the first device 210 to: if it is determined that a Management Information Base (MIB) reset message has been received, remove the configuration associated with the Optical Network Unit Management and Control Interface (OMCI) while continuing to use the first key; if it is determined that a key control message has been received instructing the first device 210 to confirm the first key corresponding to the currently used first encryption algorithm, continue to use the first key for communication between the first device 210 and the second device 220; and the first device 210 sends a key report to the second device 220, the key report indicating the first key and the first encryption algorithm.
[0139] In some example implementations, key control messages are received in physical layer operation, management, and maintenance PLOAM messages.
[0140] In some example implementations, the MIB reset message is received via the control interface OMCI.
[0141] In some example embodiments, the first device 210 includes an optical network unit (ONU), and the second device 220 includes an optical line terminal (OLT).
[0142] Figure 7 A flowchart of a communication method 700 for a passive optical network according to some example embodiments of the present disclosure is shown. Method 700 may be implemented, for example, in a communication environment 200, or at a second device 220.
[0143] In block 710, during the key exchange process, the second device 220 sends a key control message to the first device 210, which instructs the first device 210 to: generate and send a key by using the encryption algorithm to be used; or confirm the key corresponding to the encryption algorithm currently being used.
[0144] In box 620, the second device 220 receives a key report from the first device 210, the key report being generated by the first device 210 based on a key control message.
[0145] In some example implementations, key control messages are sent within physical layer operation, management, and maintenance PLOAM messages.
[0146] In some example embodiments, the second device 220 receives the key report, which indicates the key generated by employing the encryption algorithm and the encryption algorithm to be used.
[0147] In some example embodiments, the second device 220 receives the key report, which indicates the key corresponding to the currently used encryption algorithm and the currently used encryption algorithm.
[0148] In some example embodiments, the first device 210 includes an optical network unit (ONU), and the second device 220 includes an optical line terminal (OLT).
[0149] In some example embodiments, an apparatus for a passive optical network (e.g., first apparatus 210) may include components for performing the corresponding steps of method 600. These components may be implemented in any suitable manner. For example, components may be implemented as circuit devices or software modules.
[0150] In some example embodiments, the first device 210 may include components for receiving a key control message from the second device 220 during a key exchange process. The key control message instructs the first device 210 to: generate and send a key by employing the encryption algorithm to be used; or confirm the key corresponding to the currently used encryption algorithm; generate a key report based on the key control message; and send the key report to the second device 220.
[0151] In some example embodiments, the first device 210 further includes: a component for generating the key using the encryption algorithm to be used if a key control message instructs the first device 210 to generate and send the key by employing the encryption algorithm to be used; and a component for generating a key report indicating the key and the encryption algorithm used to generate the key.
[0152] In some example embodiments, the first device 210 further includes: a component for reporting the key and encryption algorithm to the second device 220 if it is determined that another key control message is received from the second device 220 instructing the first device 210 to confirm the key corresponding to the currently used encryption algorithm; and a component for initiating the use of the key for communication between the first device 210 and the second device 220.
[0153] In some example embodiments, the first device 210 further includes a component for generating a key report if a determined key control message instructs the first device 210 to confirm a key corresponding to the currently used encryption algorithm, the key report indicating the key and the currently used encryption algorithm.
[0154] In some example embodiments, the first device 210 further includes: a component for removing the configuration associated with the Optical Network Unit Management and Control Interface (OMCI) while maintaining the use of the first key if a Management Information Base (MIB) reset message is received; a component for generating the second key based on the key control message if a key control message instructs the first device 210 to generate and send a second key corresponding to the second encryption algorithm, wherein the second encryption algorithm is the same as or different from the first encryption algorithm; and a component for sending a key report to the second device 220, wherein the key report indicates the second key and the second encryption algorithm.
[0155] In some example implementations, the second encryption algorithm is the default encryption algorithm.
[0156] In some example embodiments, the first device 210 further includes: a component for removing the configuration associated with the Optical Network Unit Management and Control Interface (OMCI) while maintaining the use of the first key if a Management Information Base (MIB) reset message is received; a component for maintaining the use of the first key for communication between the first device 210 and the second device 220 if a key control message instructing the first device 210 to confirm the first key corresponding to the currently used first encryption algorithm is received; and a component for sending a key report to the second device 220, the key report indicating the first key and the first encryption algorithm.
[0157] In some example embodiments, the first device 210 includes an optical network unit (ONU), and the second device 220 includes an optical line terminal (OLT).
[0158] In some example embodiments, an apparatus for a passive optical network (e.g., second apparatus 220) may include components for performing the corresponding steps of method 700. These components may be implemented in any suitable manner. For example, the components may be implemented as circuit devices or software modules.
[0159] In some example embodiments, the second device 220 may include components for sending a key control message to the first device 210 during a key exchange process. The key control message instructs the first device 210 to: generate and send a key by employing the encryption algorithm to be used; or to confirm the key corresponding to the encryption algorithm currently used; and to receive a key report from the first device 210, the key report being generated by the first device 210 based on the key control message.
[0160] In some example implementations, key control messages are sent within physical layer operation, management, and maintenance PLOAM messages.
[0161] In some example embodiments, the second device 220 further includes a component for receiving the key report, which indicates the key generated by employing the encryption algorithm and the encryption algorithm to be used.
[0162] In some example embodiments, the second device 220 further includes a component for receiving the key report, the key report indicating the key corresponding to the currently used encryption algorithm and the currently used encryption algorithm.
[0163] In some example embodiments, the first device 210 includes an optical network unit (ONU), and the second device 220 includes an optical line terminal (OLT).
[0164] The above is in conjunction with Figures 1 to 12. Figure 6 Several examples of the first device 210 and the second device 220 are described. In some example embodiments, the first device 210 and the second device 220 may be combined into a communication system. Any other suitable components or devices may also be included in the communication system.
[0165] Figure 8 A flowchart of a communication method 800 for a passive optical network according to some example embodiments of the present disclosure is shown. Method 800 may be implemented, for example, in a communication environment 200, such as at a first device 210.
[0166] In block 810, if it is determined that an encryption algorithm change has occurred in the first device 210 and the second device 220 communicating with the first device 210 in the PON, in block 820, the first device 210 regenerates at least one first integrity key (IK) based on the new encryption algorithm to be used.
[0167] In block 830, the first device 210 immediately begins to use at least one first IK; or the first device 210 begins to use at least one first IK after a condition is met, the condition including at least one of the following: a specific message exchange is completed between the first device 210 and the second device 220 using the target IK; or a specific downlink frame is received by the first device 210.
[0168] In some example embodiments, the first device 210 generates message integrity check (MIC) information based on at least one first IK; the first device 210 transmits a message including the MIC information to the second device; if it is determined that another message including another MIC information is received from the second device, the first device 210 determines whether the other MIC information can be verified using at least one first IK; and if it is determined that the other MIC information can be verified using at least one first IK, the first device 210 discards at least one original IK previously used by the first device 210.
[0169] In some example embodiments, if it is determined that a message containing MIC information is received from the second device 220, the first device 210 determines whether the MIC information can be verified using at least one first IK; if it is determined that the MIC information can be verified using at least one first IK, the first device 210 generates another message containing another MIC information using at least one first IK; and the first device 210 transmits the other message to the second device.
[0170] In some example embodiments, if it is determined that the MIC information cannot be verified using at least one first IK, the first device 210 uses at least one original IK previously used by the first device for verification.
[0171] In some example embodiments, the messages include specific messages for querying the security mode OMCI message, or PLOAM messages for querying the registration identifier.
[0172] In some example embodiments, if it is determined that a specific message generated by the second device 220 using the target IK has been received, the first device 210 generates a response for the specific message using the target IK; and after transmitting the response for the specific message to the second device 220, the first device 210 begins to use at least one first IK.
[0173] In some example embodiments, a specific message may include a request to register a PLOAM message and the target IK may include a default IK, a previously used original PLOAM IK, or a first PLOAM IK; or a specific message may include a security mode OMCI message and the target IK may include a default IK, a previously used original OMCI IK, or a first OMCI IK.
[0174] In some example embodiments, the first device 210 receives a configuration indicating an IK switching frame counter value from the second device via an acquisition setting function PLOAM message; and if it is determined that a downlink frame corresponding to the frame counter value has been received from the second device, the first device 210 begins using at least one first IK. In some example embodiments, at least one first IK includes at least one of the following: a first OMCI IK, or a first PLOAM IK.
[0175] In some example embodiments, the first device 210 starts using the first OMCI IK and the first PLOAM IK simultaneously, or the first device 210 starts using the first OMCI IK and the first PLOAM IK separately.
[0176] In some example embodiments, the first device 210 includes an optical network unit (ONU), and the second device 220 includes an optical line terminal (OLT).
[0177] In some example embodiments, an apparatus for a passive optical network (e.g., first apparatus 210) may include components for performing the corresponding steps of method 800. These components may be implemented in any suitable manner. For example, the components may be implemented as circuit devices or software modules.
[0178] In some example embodiments, the first device 210 may include components for generating message integrity check (MIC) information based on at least one first IK; components for transmitting a message including the MIC information to the second device; components for determining whether another MIC information can be verified using at least one first IK if it is determined that another message including another MIC information is received from the second device; and components for discarding at least one original IK previously used by the first device 210 if it is determined that another MIC information can be verified using at least one first IK.
[0179] In some example embodiments, the first device 210 may include components for determining whether the MIC information can be verified using at least one first IK if it is determined that a message containing MIC information has been received from the second device 220; components for generating another message containing another MIC information using at least one first IK if it is determined that the MIC information can be verified using at least one first IK; and components for transmitting the other message to the second device.
[0180] In some example embodiments, the first device 210 may include a component for verifying the MIC information using at least one original IK previously used by the first device if it is determined that the MIC information cannot be verified using at least one first IK.
[0181] In some example embodiments, the messages include specific messages for querying the security mode OMCI message, or PLOAM messages for querying the registration identifier.
[0182] In some example embodiments, the first device 210 may include components for generating a response for the specific message using the target IK if it is determined that a specific message generated by the second device 220 using the target IK has been received; and components for the first device 210 to begin using at least one first IK after the response for the specific message has been transmitted to the second device 220.
[0183] In some example embodiments, a specific message may include a request to register a PLOAM message and the target IK may include a default IK, a previously used original PLOAM IK, or a first PLOAM IK; or a specific message may include a security mode OMCI message and the target IK may include a default IK, a previously used original OMCI IK, or a first OMCI IK.
[0184] In some example embodiments, the first device 210 may include components for configuring to receive a frame counter value indicating IK switching from the second device by acquiring a setting function PLOAM message; and components for starting to use at least one first IK if it is determined that a downlink frame corresponding to the frame counter value has been received from the second device.
[0185] In some example embodiments, at least one first IK includes at least one of the following: a first OMCI IK, or a first PLOAM IK.
[0186] In some example embodiments, the first device 210 may include components for simultaneously initiating the use of the first OMCI IK and the first PLOAM IK, or components for initiating the use of the first OMCI IK and the first PLOAM IK separately.
[0187] In some example embodiments, the first device 210 includes an optical network unit (ONU), and the second device 220 includes an optical line terminal (OLT).
[0188] Figure 9 A flowchart of a communication method 900 for a passive optical network according to some example embodiments of the present disclosure is shown. Method 900 may be implemented, for example, in a communication environment 200, or at a second device 220.
[0189] In block 910, if it is determined that an encryption algorithm change has occurred in the second device 220 and the first device communicating with the second device 220 in the PON, in block 920, the second device 220 regenerates at least one second integrity key (IK) based on the new encryption algorithm to be used.
[0190] In box 930, the second device 220 immediately begins to use at least one second IK; or the second device 220 begins to use at least one second IK after a condition is met, the condition including at least one of the following: a specific message exchange is completed between the first device 210 and the second device 220 using the target IK; or a specific downlink frame is sent by the second device 220.
[0191] In some example embodiments, if it is determined that a message containing MIC information has been received from the first device 210, the second device 220 determines whether the MIC information can be verified using at least one second IK; if it is determined that the MIC information can be verified using at least one second IK, the second device 220 generates another message containing another MIC information using at least one second IK; and sends the other message to the first device 210.
[0192] In some example embodiments, if it is determined that the MIC information cannot be verified by using at least one second IK, the second device 220 uses at least one original IK previously used by the second device for verification.
[0193] In some example embodiments, the second device 220 generates message integrity check (MIC) information based on at least one second IK; the second device 220 transmits a message including the MIC information to the first device 210; if it is determined that another message including another MIC information is received from the first device, the second device 220 determines whether the other MIC information can be verified using at least one second IK; and if it is determined that the other MIC information can be verified using at least one second IK, the second device 220 discards at least one original IK previously used by the second device 220.
[0194] In some example embodiments, if it is determined that no response has been received for the message, the second device 220 retransmits the message to the first device 210.
[0195] In some example embodiments, the messages include specific messages for querying the security mode OMCI message, or PLOAM messages for querying the registration identifier.
[0196] In some example embodiments, the second device 220 generates a specific message using the target IK; the second device 220 transmits the specific message to the first device; and if it is determined that a response to the lock-specific message has been received from the first device, the second device 220 begins using at least one second IK.
[0197] In some example embodiments, a specific message may include a request to register a PLOAM message and the target IK may include a default IK, a previously used original PLOAM IK, or a second PLOAM IK; or a specific message may include a security mode OMCI message and the target IK may include a default IK, a previously used original OMCI IK, or a second OMCI IK.
[0198] In some example embodiments, the second device 220 transmits a configuration indicating an IK switching frame counter value to the first device 210 by acquiring a PLOAM setting function message; and the second device 220 starts using at least one second IK based on the frame counter value.
[0199] In some example embodiments, at least one second IK includes at least one of the following: a second OMCI IK, or a second PLOAM IK.
[0200] In some example embodiments, the second device 220 simultaneously starts using the second OMCI IK and the second PLOAM IK, or the second device 220 starts using the second OMCI IK and the second PLOAM IK respectively.
[0201] In some example embodiments, the first device 210 includes an optical network unit (ONU), and the second device 220 includes an optical line terminal (OLT).
[0202] In some example embodiments, an apparatus for a passive optical network (e.g., second apparatus 220) may include components for performing the corresponding steps of method 900. These components may be implemented in any suitable manner. For example, the components may be implemented as circuit devices or software modules.
[0203] In some example embodiments, the second device 220 may include components for determining whether the MIC information can be verified using at least one second IK if it is determined that a message containing MIC information has been received from the first device 210; components for generating another message containing another MIC information using at least one second IK if it is determined that the MIC information can be verified using at least one second IK; and components for sending the other message to the first device 210.
[0204] In some example embodiments, the second device 220 may include a component for verifying the MIC information using at least one original IK previously used by the second device if it is determined that the MIC information cannot be verified using at least one second IK.
[0205] In some example embodiments, the second device 220 may include components for generating message integrity check (MIC) information based on at least one second IK; components for transmitting a message including the MIC information to the first device 210; components for determining whether another MIC information can be verified using at least one second IK if it is determined that another message including another MIC information has been received from the first device; and components for discarding at least one original IK previously used by the second device 220 if it is determined that another MIC information can be verified using at least one second IK.
[0206] In some example embodiments, the second device 220 may include components for retransmitting the message to the first device 210 if it is determined that no response has been received for the message.
[0207] In some example embodiments, the messages include specific messages for querying the security mode OMCI message, or PLOAM messages for querying the registration identifier.
[0208] In some example embodiments, the second device 220 may include components for generating a specific message using the target IK; components for transmitting the specific message to the first device; and components for initiating the use of at least one second IK if it is determined that a response for the lock-specific message has been received from the first device.
[0209] In some example embodiments, a specific message may include a request to register a PLOAM message and the target IK may include a default IK, a previously used original PLOAM IK, or a second PLOAM IK; or a specific message may include a security mode OMCI message and the target IK may include a default IK, a previously used original OMCI IK, or a second OMCI IK.
[0210] In some example embodiments, the second device 220 may include components for transmitting a frame counter value indicating IK switching to the first device 210 via an acquisition setting function PLOAM message; and components for initiating the use of at least one second IK based on the frame counter value.
[0211] In some example embodiments, at least one second IK includes at least one of the following: a second OMCI IK, or a second PLOAM IK.
[0212] In some example embodiments, the second device 220 may include components for simultaneously initiating the use of the second OMCI IK and the second PLOAM IK, or components for initiating the use of the second OMCI IK and the second PLOAM IK separately.
[0213] In some example embodiments, the first device 210 includes an optical network unit (ONU), and the second device 220 includes an optical line terminal (OLT).
[0214] Figure 10 This is a simplified block diagram of a device 1000 suitable for implementing an example embodiment of the present disclosure. The device 1000 can be used to implement a first device 210 and a second device 220 in a communication environment 200. As shown, the device 1000 includes one or more processing units 1010, one or more memories 1020 coupled to the processing units 1010, and a communication module 1040 coupled to the processing units 1010.
[0215] The communication module 1040 is used for bidirectional communication. In some example embodiments, the communication module 1040 may have at least one antenna to facilitate communication. In some example embodiments, the communication module 1040 may have one or more communication interfaces. A communication interface may represent any interface required for communication with other network elements.
[0216] Processing unit 1010 can be any type suitable for a local technology network and can include, but is not limited to, one or more of a general-purpose computer, a special-purpose computer, a microcontroller, a digital signal controller (DSP), and a controller-based multi-core controller architecture. Device 1000 can have multiple processors, such as application-specific integrated circuit chips, which are time-dependent on a clock synchronized with the main processor.
[0217] Memory 1020 may include one or more non-volatile memories and one or more volatile memories. Examples of non-volatile memories include, but are not limited to, read-only memory (ROM) 1024, erasable programmable read-only memory (EPROM), flash memory, hard disk, optical disc (CD), digital video disc (DVD), and other magnetic and / or optical storage. Examples of volatile memories include, but are not limited to, random access memory (RAM) 1022 and other volatile memories that do not persist during power-off periods.
[0218] Computer program 1030 includes computer-executable instructions that are executed by associated processing unit 1010. Computer program 1030 may be stored in ROM 1024. Processing unit 1010 may perform any appropriate actions and processes by loading computer program 1030 into RAM 1022.
[0219] The exemplary embodiments of this disclosure can be implemented by means of computer program 1030, enabling device 1000 to perform as described in the reference. Figures 2 to 9 Any process discussed in this disclosure. Exemplary embodiments of this disclosure may also be implemented by hardware or by a combination of software and hardware.
[0220] In some example embodiments, the computer program 1030 may be tangibly contained in a computer-readable medium, which may include in device 1000 (such as in memory 1020) or other storage devices accessible by device 1000. The computer program 1030 may be loaded from the computer-readable medium into RAM 1022 for execution. The computer-readable medium may include any type of tangible non-volatile memory, such as ROM, EPROM, flash memory, hard disk, CD, DVD, etc. Figure 11 An example of a computer-readable medium 1100 in the form of a CD or DVD according to some exemplary embodiments of the present disclosure is shown. A computer program 1030 is stored on the computer-readable medium 1100.
[0221] Generally, the various embodiments of this disclosure can be implemented in hardware or dedicated circuitry, software, logic, or any combination thereof. Some aspects can be implemented in hardware, while others can be implemented in firmware or software, which can be executed by a controller, microprocessor, or other computing device. While various aspects of exemplary embodiments of this disclosure are shown and described as block diagrams, flowcharts, or represented using some other illustration, it should be understood that the blocks, apparatuses, systems, techniques, or methods described herein can be implemented as, as in the non-limiting examples, hardware, software, firmware, dedicated circuitry or logic, general-purpose hardware or controllers or other computing devices, or some combination thereof.
[0222] This disclosure also provides at least one computer program product tangibly stored on a computer-readable storage medium. In some example embodiments, the computer-readable storage medium may be non-transitory. The computer program product includes computer-executable instructions, such as instructions included in program modules, which execute in a device on a real or virtual processor of a target to perform the above-referenced... Figure 6 The method described in 600, reference Figure 10 The method described in 1000, reference Figure 11 The method described in 1100 or reference Figure 9 The method described in 900. Typically, a program module includes routines, programs, libraries, objects, classes, components, data structures, etc., that perform specific tasks or implement specific abstract data types. In various embodiments, the functionality of program modules can be combined or divided among program modules as needed. The machine-executable instructions for a program module can be executed locally or in a distributed device. In a distributed device, the program module can reside in both local and remote storage media.
[0223] Computer program code used to implement the methods of this disclosure may be written in one or more programming languages. This computer program code may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus, such that when executed by the computer or other programmable data processing apparatus, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be performed. The program code may be executed entirely on a computer, partially on a computer, as a stand-alone software package, partially on a computer and partially on a remote computer, or entirely on a remote computer or server.
[0224] In the context of this disclosure, computer program code or related data may be carried on any suitable carrier to enable a device, apparatus, or processor to perform the various processes and operations described above. Examples of carriers include signals, computer-readable media, and so on. Examples of signals may include electrical, optical, radio, sound, or other forms of propagation signals, such as carrier waves, infrared signals, etc.
[0225] A computer-readable medium can be any tangible medium that contains or stores a program for or relating to an instruction execution system, apparatus, or device. A computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. A computer-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. More detailed examples of computer-readable storage media include electrical connections with one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0226] Furthermore, although the operation of the methods of this disclosure is described in a specific order in the accompanying drawings, this does not require or imply that these operations must be performed in that specific order, or that all of the operations shown must be performed to achieve the desired result. Rather, the steps depicted in the flowcharts may be performed in a different order. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps. It should also be noted that the features and functions of two or more devices according to this disclosure may be embodied in one device. Conversely, the features and functions of one device described above may be further divided and embodied by multiple devices.
[0227] While this disclosure has been described with reference to several specific embodiments, it should be understood that this disclosure is not limited to the specific embodiments disclosed. This disclosure is intended to cover various modifications and equivalent arrangements included within the spirit and scope of the appended claims.
Claims
1. A first device for a passive optical network (PON), comprising: At least one processor; as well as At least one memory, the at least one memory storing instructions, the instructions, when executed by the at least one processor, cause the first device to at least: During the key exchange process, a key control message is received from the second device, the key control message instructing the first device to: Generate a key using the encryption algorithm to be used and send the key; or Confirm the key corresponding to the currently used encryption algorithm; Generate a key report based on the key control message; as well as The key report is sent to the second device.
2. The first apparatus according to claim 1, wherein generating the key report comprises: If it is determined that the key control message instructs the first device to generate the key by employing the encryption algorithm to be used and to send the key, then the key is generated by the encryption algorithm to be used; as well as Generate the key report, which indicates the key and the encryption algorithm used to generate the key.
3. The first apparatus of claim 2, wherein the instructions, when executed by the at least one processor, further cause the first apparatus to: If it is determined that another key control message has been received from the second device instructing the first device to confirm the key corresponding to the currently used encryption algorithm, the first device shall report the key and the encryption algorithm to the second device; and The key is then used for communication between the first device and the second device.
4. The first apparatus according to claim 1, wherein generating the key report comprises: If it is determined that the key control message instructs the first device to confirm the key corresponding to the currently used encryption algorithm, the key report is generated, and the key report indicates the key and the currently used encryption algorithm.
5. The first apparatus of claim 4, wherein the instructions, when executed by the at least one processor, further cause the first apparatus to: The key is maintained for communication between the first device and the second device.
6. The first apparatus of claim 1, wherein the first apparatus uses a first key corresponding to a first encryption algorithm, and wherein generating the key report further comprises: If a Management Information Base (MIB) reset message is received, remove the configuration associated with the Optical Network Unit Management and Control Interface (OMCI) while continuing to use the first key; If it is determined that the key control message is received instructing the first device to generate and send a second key corresponding to the second encryption algorithm, the second key is generated based on the key control message, and the second encryption algorithm may be the same as or different from the first encryption algorithm; as well as The key report is sent to the second device, the key report indicating the second key and the second encryption algorithm.
7. The first apparatus according to claim 6, wherein the second encryption algorithm is a default encryption algorithm.
8. The first apparatus of claim 1, wherein the first apparatus uses a first key corresponding to a first encryption algorithm, and wherein the instructions, when executed by the at least one processor, further cause the first apparatus to: If a Management Information Base (MIB) reset message is received, remove the configuration associated with the Optical Network Unit Management and Control Interface (OMCI) while continuing to use the first key; If it is determined that the key control message is received instructing the first device to confirm the first key corresponding to the currently used first encryption algorithm, the first key shall continue to be used for communication between the first device and the second device. as well as The key report is sent to the second device, the key report indicating the first key and the first encryption algorithm.
9. The first apparatus according to any one of claims 1 to 8, wherein the key control message is received in a physical layer operation, management and maintenance PLOAM message.
10. The first apparatus according to any one of claims 6 to 8, wherein the MIB reset message is received via the OMCI.
11. The first device according to claim 1, wherein the first device comprises an optical network unit (ONU) and the second device comprises an optical line terminal (OLT).
12. A second device for a passive optical network (PON), comprising: At least one processor; as well as At least one memory, the at least one memory storing instructions, the instructions, when executed by the at least one processor, cause the second device to at least: During the key exchange process, a key control message is sent to the first device, the key control message instructing the first device to: Generate and send the key by employing the encryption algorithm to be used; or Confirm the key corresponding to the currently used encryption algorithm; as well as A key report is received from the first device, the key report being generated by the first device based on the key control message.
13. The second apparatus of claim 12, wherein the key control message is sent in a physical layer operation, management and maintenance PLOAM message.
14. The second apparatus of claim 12, wherein the instructions, when executed by the at least one processor, further cause the second apparatus to: Receive the key report, which indicates the key generated by employing the encryption algorithm and the encryption algorithm to be used.
15. The second apparatus of claim 12, wherein the instructions, when executed by the at least one processor, further cause the second apparatus to: Receive the key report, which indicates the key corresponding to the currently used encryption algorithm and the currently used encryption algorithm.
16. The second apparatus of claim 12, wherein the first apparatus comprises an optical network unit (ONU) and the second apparatus comprises an optical line terminal (OLT).
17. A communication method, comprising: During the key exchange process, a key control message is received from the second device, the key control message instructing the first device: Generate a key using the encryption algorithm to be used and send the key; or Confirm the key corresponding to the currently used encryption algorithm; Generate a key report based on the key control message; as well as The key report is sent to the second device.
18. A communication method, comprising: During the key exchange process, a key control message is sent to the first device, the key control message instructing the first device to: Generate and send the key by employing the encryption algorithm to be used; or Confirm the key corresponding to the currently used encryption algorithm; as well as A key report is received from the first device, the key report being generated by the first device based on the key control message.
19. An apparatus for communication, comprising: A component for receiving a key control message from a second device during a key exchange, the key control message instructing the first device: Generate a key using the encryption algorithm to be used and send the key; or Confirm the key corresponding to the currently used encryption algorithm; A component for generating a key report based on the key control message; as well as Components for sending the key report to the second device.
20. An apparatus for communication, comprising: A component for sending a key control message to a first device during a key exchange, the key control message instructing the first device: Generate and send the key by employing the encryption algorithm to be used; or Confirm the key corresponding to the currently used encryption algorithm; as well as A component for receiving a key report from the first device, the key report being generated by the first device based on the key control message.
21. A first device for a passive optical network (PON), comprising: At least one processor; as well as At least one memory, the at least one memory storing instructions, the instructions, when executed by the at least one processor, cause the first device to at least: If it is determined that an encryption algorithm change has occurred in the first device and the second device communicating with the first device in the PON, at least one first integrity key (IK) is regenerated based on the new encryption algorithm to be used; Immediately begin using at least one of the first IKs; or The at least one first IK shall be used upon meeting at least one of the following conditions: Use the target IK to complete a specific message exchange between the first device and the second device; or The first device receives a specific downlink frame.
22. The first apparatus of claim 21, wherein the instructions, when executed by the at least one processor, further cause the first apparatus to: Message Integrity Check (MIC) information is generated based on at least one first IK; Transmit a message including the MIC information to the second device; If it is determined that another message including another MIC information is received from the second device, determine whether the other MIC information can be verified using the at least one first IK; as well as If it is determined that the other MIC information can be verified using the at least one first IK, discard at least one original IK previously used by the first device.
23. The first apparatus of claim 21, wherein the instructions, when executed by the at least one processor, further cause the first apparatus to: If it is determined that a message containing MIC information is received from the second device, determine whether the MIC information can be verified using the at least one first IK; If it is determined that the MIC information can be verified using the at least one first IK, another message including another MIC information is generated using the at least one first IK; as well as The other message is transmitted to the second device.
24. The first apparatus of claim 23, wherein the instructions, when executed by the at least one processor, further cause the first apparatus to: If it is determined that the MIC information cannot be verified using the at least one first IK, then at least one original IK previously used by the first device is used for verification.
25. The first apparatus according to claims 22-24, wherein the message includes a specific message for querying a security mode OMCI message, or a PLOAM message for querying a registration identifier.
26. The first apparatus of claim 21, wherein the instructions, when executed by the at least one processor, further cause the first apparatus to: If it is determined that a specific message generated by the second device using target IK has been received, a response is generated for the specific message using said target IK; and After the response to the specific message is transmitted to the second device, the use of the at least one first IK begins.
27. The first apparatus according to claim 26, wherein The specific message includes a request to register a PLOAM message and the target IK includes a default IK, a previously used original PLOAM IK, or a first PLOAM IK; or The specific message includes a security mode OMCI message and the target IK includes the default IK, the previously used original OMCIIK, or the first OMCIIK.
28. The first apparatus of claim 21, wherein the instructions, when executed by the at least one processor, further cause the first apparatus to: The configuration, indicating the IK switching, is received from the second device via the PLOAM message setting function; and If it is determined that a downlink frame corresponding to the frame counter value has been received from the second device, the use of the at least one first IK is initiated.
29. The first device according to claim 21, wherein the at least one first IK comprises at least one of the following: First OMCIIK, or First PLOAMIK.
30. The first apparatus of claim 29, wherein the instructions, when executed by the at least one processor, further cause the first apparatus to: Simultaneously begin using the first OMCIIK and the first PLOAMIK, or Start using the first OMCIIK and the first PLOAMIK respectively.
31. The first device according to claim 21, wherein the first device includes an optical network unit (ONU) and the second device includes an optical line terminal (OLT).
32. A second device for a passive optical network (PON), comprising: At least one processor; as well as At least one memory, the at least one memory storing instructions, the instructions, when executed by the at least one processor, cause the second device to at least: If it is determined that an encryption algorithm change has occurred in the second device and the first device communicating with the second device in the PON, at least one second integrity key (IK) is regenerated based on the new encryption algorithm to be used; Immediately begin using at least one of the second IKs; or The at least one second IK shall be used after certain conditions are met, said conditions including at least one of the following: Use the target IK to complete a specific message exchange between the first device and the second device; or The second device sends a specific downlink frame.
33. The second apparatus of claim 32, wherein the instructions, when executed by the at least one processor, further cause the second apparatus to: If it is determined that a message containing MIC information is received from the first device, determine whether the MIC information can be verified using the at least one second IK; If it is determined that the MIC information can be verified using the at least one second IK, another message including another MIC information is generated using the at least one second IK; as well as Send the other message to the first device.
34. The second apparatus of claim 33, wherein the instructions, when executed by the at least one processor, further cause the second apparatus to: If it is determined that the MIC information cannot be verified using the at least one second IK, verification is performed using at least one original IK previously used by the second device.
35. The second apparatus of claim 32, wherein the instructions, when executed by the at least one processor, further cause the second apparatus to: Message Integrity Check (MIC) information is generated based on at least one second IK; Transmit a message including the MIC information to the first device; If it is determined that another message including another MIC information is received from the first device, determine whether the other MIC information can be verified using the at least one second IK; as well as If it is determined that the other MIC information can be verified using the at least one second IK, discard at least one original IK previously used by the second device.
36. The second apparatus of claim 35, wherein the instructions, when executed by the at least one processor, further cause the second apparatus to: If it is determined that no response has been received for the message, the message is retransmitted to the first device.
37. The second apparatus according to claims 34-36, wherein the message includes a specific message for querying a security mode OMCI message, or a PLOAM message for querying a registration identifier.
38. The second apparatus of claim 32, wherein the instructions, when executed by the at least one processor, further cause the second apparatus to: Use the target IK to generate a specific message; Transmit the specific message to the first device; as well as If it is determined that a response to the specific message has been received from the first device, the use of the at least one second IK is initiated.
39. The second apparatus of claim 38, wherein the specific message includes a request to register a PLOAM message and the target IK includes a default IK, a previously used original PLOAMIK, or a second PLOAMIK; or The specific message includes a security mode OMCI message and the target IK includes a default IK, a previously used original OMCIIK, or a second OMCIIK.
40. The second apparatus of claim 32, wherein the instructions, when executed by the at least one processor, further cause the second apparatus to: The configuration, indicating the IK switching, is transmitted to the first device via the PLOAM message setting function; and The use of at least one second IK is initiated based on the frame counter value.
41. The second device according to claim 40, wherein the at least one second IK comprises at least one of the following: Second OMCIIK, or Second PLOAMIK.
42. The second apparatus of claim 41, wherein the instructions, when executed by the at least one processor, further cause the first apparatus to: Simultaneously begin using the second OMCI IK and the second PLOAM IK, or Start using the second OMCIIK and the second PLOAMIK respectively.
43. The second apparatus according to claim 32, wherein the first apparatus includes an optical network unit (ONU) and the second apparatus includes an optical line terminal (OLT).
44. A communication method, comprising: If it is determined that an encryption algorithm change has occurred in the first device and the second device communicating with the first device in the PON, at least one first integrity key (IK) is regenerated based on the new encryption algorithm to be used; Immediately begin using at least one of the first IKs; or The at least one first IK shall be used upon meeting at least one of the following conditions: Use the target IK to complete a specific message exchange between the first device and the second device; or The first device receives a specific downlink frame.
45. A communication method, comprising: If it is determined that the encryption algorithm of the first device communicating with the second device in the PON has changed, at least one second integrity key (IK) is regenerated based on the new encryption algorithm to be used; Immediately begin using at least one of the second IKs; or The at least one second IK shall be used after certain conditions are met, said conditions including at least one of the following: Use the target IK to complete a specific message exchange between the first device and the second device; or The second device sends a specific downlink frame.
46. An apparatus for communication, comprising: A component for regenerating at least one first integrity key (IK) based on the new encryption algorithm to be used if a second device that is communicating with the first device in a PON changes its encryption algorithm. Components for immediately commencing use of at least one of the first IK; or A component for initiating use of the at least one first IK after certain conditions are met, said conditions including at least one of the following: Use the target IK to complete a specific message exchange between the first device and the second device; or The first device receives a specific downlink frame.
47. An apparatus for communication, comprising: A component for regenerating at least one second integrity key (IK) based on the new encryption algorithm to be used if it is determined that an encryption algorithm change has occurred in the second device and the first device communicating with the second device in the PON. Components for immediately commencing use of at least one of the second IKs; or The component for initiating use of the at least one second IK after a condition is met, the condition including at least one of the following: Use the target IK to complete a specific message exchange between the first device and the second device; or The second device sends a specific downlink frame.
48. A computer-readable storage medium having a computer program stored thereon, the computer program including instructions that, when executed by a processor on a device, cause the device to perform the method according to claim 17, claim 18, claim 44, or claim 45.