Optical communication method and optical communication apparatus
The optical communication method and device address the challenge of authenticating and setting wavelengths and paths for newly connected terminals in All Photonics Networks, enabling secure and efficient communication.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-10-04
- Publication Date
- 2026-04-09
AI Technical Summary
SEBA, an activation sequence designed for Passive Optical Networks (PONs), cannot authenticate newly connected terminals or allocate wavelengths and activate optical paths in All Photonics Networks (APNs), which establish end-to-end optical paths.
An optical communication method and device that includes an authentication step, a method setting step, a wavelength setting step, and a route setting step to authenticate terminals and establish optical paths.
Enables authentication of newly connected terminals and wavelength allocation, as well as optical path activation, ensuring secure and efficient communication setup in All Photonics Networks.
Smart Images

Figure 0007843365000001 
Figure 0007843365000002 
Figure 0007843365000003
Abstract
Description
Technical Field
[0001] The present invention relates to optical communication methods and technologies for optical communication devices.
Background Art
[0002] In a communication system, in order to avoid attacks from malicious users, it is required to authenticate the connected devices at the time of activation. One communication system in which an activation sequence including authentication is defined is SEBA (SDN-Enabled Broadband Access).
Prior Art Documents
Non-Patent Documents
[0003]
Non-Patent Document 1
Non-Patent Document 2
Summary of the Invention
Problems to be Solved by the Invention
[0004] SEBA is an activation sequence designed for Passive Optical Networks (PONs), and therefore cannot be directly applied to All Photonics Networks (APNs: see Non-Patent Literature 2), which establish optical paths end-to-end. Specifically, SEBA only determines whether the main signal can be transmitted based on the authentication result, and cannot assign wavelengths to newly connected terminals or activate optical paths.
[0005] In view of the above circumstances, the present invention aims to provide a technology that enables authentication of newly connected terminals, as well as wavelength allocation and activation of optical paths for terminals. [Means for solving the problem]
[0006] One aspect of the present invention is an optical communication method for an optical communication device, comprising: an authentication step for authenticating a terminal; a method setting step for setting a communication method to be used between the terminal and a destination terminal to which the terminal is connected; a wavelength setting step for setting a wavelength to be used between the terminal and the destination terminal; and a route setting step for setting an optical path to be used between the terminal and the destination terminal.
[0007] One aspect of the present invention is an optical communication device comprising: an authentication unit for authenticating a terminal; a method setting unit for setting a communication method to be used between the terminal and a destination terminal to which the terminal is connected; a wavelength setting unit for setting a wavelength to be used between the terminal and the destination terminal; and a route setting unit for setting an optical path to be used between the terminal and the destination terminal. [Effects of the Invention]
[0008] The present invention provides a technology that enables authentication of newly connected terminals, as well as wavelength allocation and optical path activation for those terminals. [Brief explanation of the drawing]
[0009] [Figure 1] This is a block diagram showing the configuration of an optical communication system. [Figure 2] This figure shows a modified example of a network device. [Figure 3] This is a state transition diagram for each terminal managed by the network controller. [Figure 4] This is an activation sequence diagram showing the processing flow of an optical communication system. [Figure 5] This is a flowchart showing the processing flow of an optical communication device. [Figure 6] This diagram shows the timing of measurements during the activation sequence. [Modes for carrying out the invention]
[0010] Embodiments of the present invention will be described in detail with reference to the drawings. Figure 1 is a block diagram showing the configuration of the optical communication system 1 in an embodiment. The optical communication system 1 comprises an optical communication device 1000 and a plurality (two in the figure) of terminals 300. The terminals 300 are terminals used by the user, which are connected to the optical communication device 1000 and perform optical communication with the connected terminal (hereinafter also referred to as the "connected terminal"). In the example in Figure 1, for the sake of simplicity, an optical communication device capable of connecting up to two terminals 300 is used as an example, but it is not limited to this.
[0011] The optical communication device 1000 consists of a network controller 100 and a network device 200. The network controller 100 controls the network device 200. The network controller 100 and the network device 200 may be housed in the same enclosure. The network device 200 connects to a terminal 300, and the network controller 100 controls the establishment of an optical path between the terminal 300 and the connected terminal. The establishment of the optical path is performed by a request from the terminal 300 or by an instruction from a higher-level device. The higher-level device is, for example, an operating system for which an operator manages and controls the network controller.
[0012] Specifically, the network device 200 consists of multiple (two in the diagram) multiplexers / demultiplexers 230 and an optical distribution unit 210. The multiplexers / demultiplexers 230 are optical devices that combine and separate optical signals, such as wavelength filters, but optical couplers may also be used. The multiplexers / demultiplexers 230 connect the terminal 300 to the optical distribution unit 210 or the control TRx120 described later.
[0013] The optical distribution unit 210 is equipped with ports 220 and 221, and distributes the main signal of terminal 300 input from port 220 to port 221 corresponding to the destination terminal. Conversely, the optical distribution unit 210 distributes the main signal of the destination terminal input from port 221 to port 220 corresponding to terminal 300. The optical distribution unit 210 is, for example, an optical switch, but it may also be a device that constitutes a ROADM (Reconfigurable optical add-drop multiplexer).
[0014] The network controller 100 consists of a control unit 110 and a number of control TRx120s (two in the diagram). The control TRx120s connect the terminal 300 to the control unit 110. The control TRx120s transmit and receive control signals. The control TRx120s are, for example, AMCC (Auxiliary Management and Control Channel) compatible transceivers. In this case, the control TRx120s transmit and receive control signals by superimposing them on the main signal using AMCC. Alternatively, the control TRx120s may be control optical transceivers that use a signal different from the main signal.
[0015] The control unit 110 is connected to the optical oscillator unit 210 and the control TRx 120. The control unit 110 includes an authentication unit 111, a registration unit 112, a method setting unit 113, a wavelength setting unit 114, and a path setting unit 115. The authentication unit 111 authenticates the terminal 300. The registration unit 112 registers the device information of the terminal 300. The device information is, for example, the communication method (capabilities such as baud rate, modulation method, error correction method, etc.) that the terminal 300 can use. Also, the device information is the port information of the optical oscillator unit 210 connected to the terminal 300. The method for obtaining the port information of the optical oscillator unit 210 includes, for example, having a relationship table of the port information of the control TRx 120 and the optical oscillator unit 210 in advance and based on the control TRx 120 to which the terminal 300 is connected, but is not limited to this.
[0016] The method setting unit 113 sets the communication method to be used between the terminal 300 and the destination terminal to which the terminal 300 is connected. The wavelength setting unit 114 sets the wavelength to be used between the terminal 300 and the destination terminal. The path setting unit 115 sets the optical path to be used between the terminal 300 and the destination terminal.
[0017] In addition to the above settings, the control unit 110 performs control on the terminal 300 (settings such as optical power, error correction method, transmission / reception rate, etc.) and control on the optical oscillator unit 200 (opening of the main signal, change of the connection destination).
[0018] Note that the setting order of the above communication method setting, wavelength setting, and optical path setting is arbitrary. Also, if the wavelength or communication method cannot be set for the terminal 300, the setting for the terminal 300 may be skipped. Examples of cases where the wavelength or communication method cannot be set include being single wavelength compatible or only corresponding to a single communication method.
[0019] When at least one of the wavelength and the communication method cannot be aligned between the terminal 300 and the destination terminal, or when there is no configurable optical path (for example, when there is no configurable wavelength or communication method), the network device 200 remains blocked and the opening of the optical path is aborted. Note that wavelength conversion may be performed in the optical path between the terminal 300 and the destination terminal. In this case, if there is a configurable wavelength considering wavelength conversion, it is assumed that the wavelengths can be aligned. The control unit 110 may notify the upper device that the opening of the optical path has been aborted due to a configuration mismatch.
[0020] FIG. 2 is a diagram showing a modified example of the network device 200. The differences from the configuration shown in FIG. 1 are that a multiplexer / demultiplexer 230 is provided at the subsequent stage of the optical oscillator unit 210 and an initial connection port 222 is provided. When the multiplexer / demultiplexer 230 is provided at the subsequent stage of the optical oscillator unit 210, when the terminal 300 starts connection, it is first connected to the initial connection port 222 so that the main signal of the terminal 300 before authentication does not reach the upper network. After connecting the terminal 300 to the initial connection port 222 and performing authentication and the like, it is connected to the port 221. The method for acquiring the port information of the optical oscillator unit 210 in the case of the modified example shown in FIG. 2 includes, for example, a method based on the variation of the received optical power measured at the port 220 of the optical oscillator unit 210, but is not limited thereto. In the present embodiment, it is also applicable to the configuration shown in FIG. 2.
[0021] FIG. 3 is a state transition diagram of each terminal 300 managed by the network controller 100. The states of the terminal 300 include an initial state, a standby (unauthenticated) state, a standby (authenticated) state, and an open state. The initial state is a state in which the network controller 100 has not detected the connection of the terminal 300. The state in which the connection of the terminal 300 has not been detected means that the terminal 300 is not connected or the terminal 300 is connected but not detected.
[0022] Standby (unauthenticated) means that authentication for terminal 300 has not been completed. In this standby (unauthenticated) state, the control unit 110 cannot set a path. Standby (authenticated) means that authentication has been completed by the authentication unit 111 and registration of terminal 300 has been completed by the registration unit 112, but communication is not taking place. In other words, it is a state of waiting for instructions / requests to open a path, or a state where the path has been set but communication is not possible due to terminal sleep, etc. Opened state means that communication is possible between terminal 300 and the connected terminal.
[0023] Each state transitions according to an event. There are four types of events: A, B, C, D, E, F, and G. Event A is the event that transitions from the initial state to standby (unauthenticated). Event A includes the completion of connection detection for terminal 300. Event B is the event that transitions from standby (unauthenticated) to standby (authenticated). Event B includes the completion of authentication and registration of terminal 300. Event C is the event that transitions from standby (authenticated) to the activated state. Event C includes the completion of optical path activation, terminal 300 returning from sleep state to normal state, instructions from a higher-level device, reconnection by the connected terminal, or re-authentication. Instructions from a higher-level device are given, for example, when an APN failure is resolved.
[0024] Event D is an event that transitions the system from the activated state, standby (unauthenticated), and standby (authenticated) to the initial state. Event D includes failure or replacement of terminal 300, or deletion of the information of terminal 300 registered by the registration unit 112.
[0025] Event E is an event that transitions from Standby (Authenticated) to Standby (Unauthenticated). Event E includes the deletion of authentication information. For example, if the authentication information for terminal 300 expires (authentication expires) and becomes invalid, the authentication information is deleted.
[0026] Event F is an event that transitions from the active state to the standby (authenticated) state. Event F can occur when terminal 300 transitions from the normal state to the sleep state, when there is an instruction from a higher-level device, when the connected terminal loses connection or authentication expires, or when the optical path is released. Instructions from a higher-level device are given, for example, when there is a break in the optical fiber constituting the APN or when the APN fails.
[0027] Event G is an event that transitions the connection from active to standby (unauthenticated). Event F includes the deletion of authentication information or a period of no communication between terminal 300 and the connected terminal.
[0028] Figure 4 is an activation sequence diagram showing the processing flow of the optical communication system 1. Terminal 300 connects to the network controller 100 via the network device 200 (step S101). Authentication processing for terminal 300 is performed between terminal 300 and the authentication unit 111 of the network controller 100 (step S102). Here, it is assumed that authentication is successful.
[0029] Next, the terminal 300 and the registration unit 112 of the network controller 100 exchange information to obtain device information for the terminal 300 (step S103) and port information for the optical distribution unit 210 (step S104). The network controller 100 sets the communication method, wavelength, and path (step S105). As a result, the wavelength and communication method are set for the terminal 300 (step S106), and an optical path is set for the optical distribution unit 210 of the network device 200 (step S107).
[0030] Figure 5 is a flowchart showing the processing flow of the optical communication device 1000. This flowchart shows the processing flow until the optical path of terminal 300 is established. The trigger for this processing is the connection of terminal 300 to the optical communication device 1000, but this connection may also be triggered by the detection of this connection by the network device 200 or network controller 100. Alternatively, the network device 200 or network controller 100 may actively search for a newly connectable terminal and the trigger may be the discovery of such a terminal. As an active search method, for example, a method such as PON (Passive Optical Network) Discovery may be used.
[0031] First, in the activation sequence, authentication is performed on the connected terminal. The network controller 100 obtains authentication information from the terminal 300 (step S201). Authentication information includes, for example, the ID (Identification) / PW (Password) and MAC (Media Access Control) address information assigned to the terminal 300, or encrypted information based on this information.
[0032] Next, the network controller 100 determines whether authentication is possible based on the acquired authentication information (step S203). Specifically, it checks whether the acquired ID / PW or MAC address information is registered in the network database as an authorized authentication target. As an authentication method, for example, RADIUS authentication using a RADIUS (Remote Authentication Dial In User Service) server may be used, but is not limited to this. In addition to the authentication of the terminal 300 described above, user authentication may also be used. In this case, user authentication uses authentication information independent of the terminal (for example, the user's ID / PW).
[0033] The network controller 100 determines whether authentication was successful or not based on the result of the authentication determination (step S203). If authentication fails (step S203), the network controller 100 terminates the process. In other words, the network controller 100 keeps the network blocked without opening it.
[0034] If authentication is successful (step S203: YES), the authentication process for terminal 300 is terminated, and the process proceeds to the registration of device information. The network controller 100 obtains and saves the device information from terminal 300 (step S204). The network controller 100 obtains and saves the port information of the optical distribution unit 210 connected to terminal 300 (step S205). This completes the process for registering device information. Note that steps S204 and S205 can be performed in any order.
[0035] Once the device information registration is complete, the process for activating the optical path will be performed. However, it is not necessary to activate the optical path immediately after the device information registration is complete; this does not need to be done unless instructed by the higher-level device or requested by terminal 300.
[0036] The network controller 100 acquires terminal information for connection based on instructions from a higher-level device or requests from terminal 300 (step S206). The network controller 100 searches for the optical path and wavelength to be used between terminal 300 and the destination terminal and allocates them for the connection (step S207). The network controller 100 searches for the communication method to be used for connection between terminal 300 and the destination terminal (step S208). Subsequently, it sets the wavelength and communication method for terminal 300 (step S209) and sets the optical path for the main signal for the optical distribution unit 210 (step S210).
[0037] The search order for communication method, wavelength, and optical path shown in the flowchart above is not in any particular order. Similarly, the order in which the communication method, wavelength, and optical path are set after the search is also not in any particular order.
[0038] Next, we will explain communication delay. During the activation process between terminal 300 and the connected terminal, it is conceivable to measure the delay time (propagation distance) in communication between terminal 300 and the network controller 100. Below, the method for measuring the delay between terminal 300 and the network controller 100 will be explained using Figure 6. Figure 6 is a diagram showing the timing of measurement in the activation sequence.
[0039] There are two timings for measurement (T1 and T2), so we will explain each of them. Note that in Figure 6, T1 and T2 are shown separately from steps S103 and S101, respectively, but this is for clarity only; T1 and T2 occur at the same timing as S103 and S101, respectively.
[0040] First, regarding T1, the network controller 100 sends and receives probe signals to and from the terminal 300 as part of acquiring device information. The network controller 100 then measures the RTT (Round Trip Time) required from the transmission to the reception of the probe signal, and uses the measured time as the delay time.
[0041] Next, regarding T2, the network controller 100 may measure the delay time when the terminal 300 is connected. For example, if the network controller 100 detects the connection of terminal 300 using PON's Discovery, the time measured by the accompanying Ranging process may be used as the delay time. If the network device 200 detects the connection of terminal 300, the network device 200 may measure the delay time.
[0042] In the embodiment described above, when terminal 300 connects, authentication is performed, the wavelength is set, the communication method is set, and the optical path is opened. This makes it possible to authenticate new connected users, assign wavelengths to new connected users, and open the optical path.
[0043] The authentication unit 111, registration unit 112, method setting unit 113, wavelength setting unit 114, and route setting unit 115 may be configured using a processor such as a CPU (Central Processing Unit) and memory. In this case, the authentication unit 111, registration unit 112, method setting unit 113, wavelength setting unit 114, and route setting unit 115 function as the authentication unit 111, registration unit 112, method setting unit 113, wavelength setting unit 114, and route setting unit 115 by the processor executing a program. Note that all or part of the functions of the authentication unit 111, registration unit 112, method setting unit 113, wavelength setting unit 114, and route setting unit 115 may be implemented using hardware such as an ASIC (Application Specific Integrated Circuit), PLD (Programmable Logic Device), or FPGA (Field Programmable Gate Array). The above program may be recorded on a computer-readable recording medium. Computer-readable recording media include, for example, portable media such as flexible disks, magneto-optical disks, ROMs, CD-ROMs, and semiconductor storage devices (e.g., SSDs: Solid State Drives), as well as storage devices such as hard disks and semiconductor storage devices built into computer systems. The above program may be transmitted via a telecommunications line.
[0044] While embodiments of this invention have been described in detail above with reference to the drawings, the specific configuration is not limited to these embodiments and includes designs and the like that do not depart from the spirit of this invention. [Industrial applicability]
[0045] The present invention is applicable to a system for assigning wavelengths to terminals and opening optical paths. [Explanation of Symbols]
[0046] 1 Optical communication system, 100 Network controller, 110 Control unit, 111 Authentication unit, 112 Registration unit, 113 Method setting unit, 114 Wavelength setting unit, 115 Route setting unit, 200 Network device, 210 Optical distribution unit, 220, 221 Ports, 222 Initial connection port, 230 Splitter / multiplexer, 300 Terminal, 1000 Optical communication device
Claims
1. An optical communication method for an optical communication device, When a terminal is connected to the network device to which the optical communication device is connected, an authentication step is performed to authenticate the terminal. If the authentication of the terminal is successful in the authentication step, a method setting step is performed to set the communication method to be used between the terminal and the destination terminal to which the terminal is connected. If the authentication of the terminal is successful in the authentication step, a wavelength setting step is performed to set the wavelength to be used between the terminal and the destination terminal. If the authentication of the terminal is successful in the authentication step, a route setting step is performed to set the optical path to be used between the terminal and the destination terminal. Equipped with an optical communication method.
2. The terminal includes a communication method acquisition step to acquire a communication method that can be used, The optical communication method according to claim 1, wherein the method setting step sets a communication method based on the communication method acquired in the communication method acquisition step.
3. The optical communication method according to claim 2, wherein the delay time in communication between the optical communication device and the terminal is measured in the step of acquiring the communication method.
4. The optical communication method according to claim 1, further comprising the step of measuring the delay time in communication between the optical communication device and the terminal in the step of detecting the connection of the terminal.
5. The optical communication method according to any one of claims 1 to 4, further authenticating the user of the terminal in the authentication step.
6. An optical communication device, When a terminal is connected to the network device to which the optical communication device is connected, an authentication unit authenticates the terminal, When the authentication unit successfully authenticates the terminal, the method setting unit sets the communication method to be used between the terminal and the destination terminal to which the terminal is connected. When the authentication unit successfully authenticates the terminal, the wavelength setting unit sets the wavelength to be used between the terminal and the destination terminal. When the authentication unit successfully authenticates the terminal, the routing unit sets the optical path to be used between the terminal and the destination terminal. An optical communication device equipped with this device.
Citation Information
Patent Citations
Optical multi-branching communication system and method for restoring its high speed line
JP2002198983A
Optical transmission system and communication condition selection method
JP2019161512A