Service encryption method for passive optical network system, and electronic device and storage medium
By dynamically switching encryption algorithms and key synchronization in passive optical network systems, the problem of compatibility of multiple encryption algorithms in FTTR scenarios is solved, and a variety of encryption algorithms are supported and dynamic switching in FTTR scenarios is realized to ensure seamless encryption and decryption of uplink service messages.
Patent Information
- Application Number
- PCT/CN2025/071772
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-17
- Filing Date
- 2025-01-10
- Publication Date
- 2025-07-24
AI Technical Summary
In the prior art, passive optical network systems lack compatible processing for multiple encryption algorithms, and cannot meet the requirements of multiple encryption algorithms and dynamic switching of GPON devices in FTTR scenarios by multiple countries, multiple regions and multiple network operators.
By sending encryption enable information between the optical circuit terminal OLT and the optical network unit ONU, dynamically switch the encryption algorithm, and perform key synchronization, dynamic switching and key synchronization of the encryption algorithm are achieved using the OMCI entity ONU2-G, and the target value of the superframe counter or the Key Index is used to determine the activation of the new key or new encryption algorithm.
It realizes supporting a variety of encryption algorithms and dynamic switching in the FTTR scenario, ensuring seamless switching of uplink service packets, avoiding data packet loss, and meeting the encryption needs of different countries and operators.
Smart Images

Figure CN2025071772_24072025_PF_FP_ABST
Abstract
Description
Service encryption method, electronic equipment and storage medium for passive optical network system
[0001] Cross-references
[0002] This application claims priority to a Chinese patent application filed with the Patent Office of China on January 17, 2024, with application number 202410063582.1 and invention name “Service encryption method, electronic device and storage medium for passive optical network system”. The entire contents of the application are incorporated by reference into this application. Technical Field
[0003] The present application relates to the field of communication technology, and in particular to a service encryption method, electronic equipment, and storage medium for a passive optical network system. Background Art
[0004] A Passive Optical Network (PON) is a broadband passive optical access technology, a point-to-multipoint fiber optic access technology. It consists of an optical line terminal (OLT) installed in a central control station, a number of optical network units (ONUs) installed at user locations, and an optical distribution network (ODN). The ODN is typically a point-to-multipoint structure, with one OLT connecting multiple ONUs. The ODN between the OLT and ONUs contains optical fibers and passive components such as passive splitters or couplers, and does not contain any active devices. PON has become the future direction of broadband access network development due to its relatively low cost and smooth upgrade convenience among fiber optic access methods.
[0005] PONs come in many forms, including APON (Asynchronous Transfer Mode Passive Optical Network), BPON (Broadband Passive Optical Network), EPON (Ethernet Passive Optical Network), GPON (Gigabit Passive Optical Network), XGPON (10-Gigabit-capable Passive Optical Networks), and XGSPON (10-Gigabit-capable Symmetric Passive Optical Networks). However, their basic structures differ significantly. Downlink data transmission uses a broadcast method. The OLT at the central office transmits the downlink optical signal through an optical splitter, splitting it into multiple channels for each ONU. The uplink signal from each ONU is then combined using an optical coupler onto a single fiber for multiplexed transmission to the OLT.
[0006] With the continuous development of optical networks, fiber to the home (FTTH) has been fully rolled out, and its optical line terminals (OLTs) and optical network units (ONUs) have also been widely used. However, the current international standards only define one advanced encryption algorithm for GPON. The development of GPON products for FTTR (Fiber to the Room) scenarios requires adapting to the application needs of different countries, regions, and network operators. Different countries and network operators may use different encryption algorithms.
[0007] The existing technical solutions only consider one data encryption algorithm mode, and do not provide a multi-algorithm mode negotiation process during the configuration phase when the ONU is connected to the OLT. They lack compatible processing for multiple encryption algorithms and cannot meet the requirements of multiple countries, regions, and network operators for GPON equipment in FTTR scenarios to support multiple encryption algorithms and dynamic switching of algorithms. Summary of the Invention
[0008] The main purpose of this application is to provide a service encryption method, electronic equipment and storage medium for a passive optical network system.
[0009] To achieve the above-mentioned objectives, the present application provides a service encryption method for a passive optical network system, which is applied to an optical line terminal (OLT), comprising: sending encryption enable information to an optical network unit (ONU), wherein the encryption enable information is used to indicate whether encryption is currently not enabled, only uplink encryption is enabled, only downlink encryption is enabled, or uplink and downlink encryption is enabled; after enabling uplink and downlink encryption or enabling uplink encryption, dynamically switching the encryption algorithm currently negotiated between the OLT and the ONU through an OMCI entity (ONU2-G); performing key synchronization with the ONU based on the encryption algorithm after the dynamic switching; after key synchronization, determining to use a new key or a new encryption algorithm starting from a specified frame based on a target value or a Key Index of a superframe counter, and sending the target value or the Key Index of the superframe counter to the ONU.
[0010] In addition, to achieve the above-mentioned purpose, the present application provides a service encryption method for a passive optical network system, which is applied to an optical network unit ONU, including: receiving encryption enable information sent by an optical line terminal OLT, wherein the encryption enable information is used to indicate whether encryption is currently not enabled, only uplink encryption is enabled, only downlink encryption is enabled, or uplink and downlink encryption is enabled; after enabling uplink and downlink encryption or enabling uplink encryption, dynamically switching the encryption algorithm currently negotiated between the OLT and the ONU through the OMCI entity ONU2-G; performing key synchronization with the OLT based on the encryption algorithm after the dynamic switching; after key synchronization, receiving the target value or Key Index of the superframe counter sent by the OLT, and determining to use a new key or a new encryption algorithm starting from a specified frame based on the target value or Key Index of the superframe counter.
[0011] In addition, to achieve the above-mentioned purpose, the present application also provides a service encryption method for a passive optical network system, which is applied to the FTTR master device MFU, including: sending encryption enable information to the FTTR slave device SFU, wherein the encryption enable information is used to indicate that encryption is currently not enabled, only uplink encryption is enabled, only downlink encryption is enabled, or uplink and downlink encryption is enabled; after enabling uplink and downlink encryption or enabling uplink encryption, dynamically switching the encryption algorithm currently negotiated and adopted by the MFU and the SFU through the OMCI entity ONU2-G; performing key synchronization with the SFU according to the encryption algorithm after the dynamic switching; after key synchronization, determining to use a new key or a new encryption algorithm starting from a specified frame according to the target value or Key Index of the superframe counter, and sending the target value or Key Index of the superframe counter to the SFU.
[0012] In addition, to achieve the above-mentioned purpose, the present application also provides a service encryption method for a passive optical network system, which is applied to the FTTR slave device SFU, including: receiving encryption enable information sent by the FTTR master device MFU, wherein the encryption enable information is used to indicate whether encryption is currently not enabled, only uplink encryption is enabled, only downlink encryption is enabled, or uplink and downlink encryption is enabled; after enabling uplink and downlink encryption or enabling uplink encryption, dynamically switching the encryption algorithm currently negotiated and adopted by the MFU and the SFU through the OMCI entity ONU2-G; performing key synchronization with the MFU according to the encryption algorithm after the dynamic switching; after key synchronization, receiving the target value or Key Index of the superframe counter sent by the MFU, and determining to use a new key or a new encryption algorithm starting from the specified frame according to the target value or Key Index of the superframe counter.
[0013] In addition, to achieve the above-mentioned purpose, the present application also provides an electronic device, which includes: a memory, a processor, and a service encryption program of a passive optical network system stored on the memory and runnable on the processor. When the service encryption program of the passive optical network system is executed by the processor, the service encryption method of the passive optical network system as described above is implemented.
[0014] In addition, to achieve the above-mentioned purpose, the present application also provides a storage medium, which is a computer-readable storage medium, and the computer-readable storage medium stores a service encryption program of a passive optical network system. When the service encryption program of the passive optical network system is executed by a processor, the service encryption method of the passive optical network system as described above is implemented. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on the structures shown in these drawings without paying any creative work.
[0016] FIG1 is a schematic flow chart of a service encryption method for a passive optical network system in a first embodiment of the present application;
[0017] FIG2 is a schematic flow chart of a service encryption method for a passive optical network system in a second embodiment of the present application;
[0018] FIG3 is a structural block diagram of an electronic device according to an exemplary embodiment of the present application. DETAILED DESCRIPTION
[0019] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.
[0020] With the continuous development of optical networks, fiber to the home (FTTH) has been fully rolled out, and its central office products (OLT) and terminal products (ONU) have also been widely used. In passive optical network systems, PON equipment can be divided into Gigabit-capable Passive Optical Network (GPON), 10G PON (10-Gigabit-capable Passive Optical Networks), 10G Symmetric PON (10-Gigabit-capable Symmetric PON), 50G High-speed PON (HSPON), and the currently researched 100G PON, based on the different protocols used in the transmission convergence layer (TC). These PON system architectures generally include the optical network terminal (OLT), optical network unit (ONU), and optical distribution network (ODN).
[0021] In the ITU-T standards, all PON access technologies use the AES-128 encryption algorithm, but the encryption direction varies. GPON asymmetric and GPON symmetric encrypt only the downstream direction, while XGPON asymmetric and XGPON symmetric encrypt both the downstream and upstream directions. In FTTR (Fiber to the Room) scenarios and the G.fin standards, different PON access technologies (including but not limited to GPON asymmetric, GPON symmetric, XGPON asymmetric, and XGPON symmetric PON modes) must support multiple encryption algorithms (including but not limited to AES-128, AES-256, Camellia-128, Camellia-256, and SM4) in both the downstream and upstream directions, as well as dynamic algorithm switching.
[0022] The existing related technologies do not provide an effective solution to the above problems. How to solve the above problems in practical applications has become a problem that needs to be solved in the FTTR scenario.
[0023] From the above introduction to PON international standards, it can be seen that existing technical solutions only consider one data encryption algorithm mode, do not provide a multi-algorithm mode negotiation process during the configuration phase when the ONU is connected to the OLT, lack compatible processing for multiple encryption algorithms, and cannot meet the requirements of multiple countries, regions, and network operators for PON equipment to support multiple encryption algorithms and the needs of dynamic switching between algorithms.
[0024] Based on this, please refer to Figure 1, which is a flow chart of a service encryption method for a passive optical network system in a first embodiment of the present application. As shown in Figure 1, the service encryption method is applied to an optical line terminal (OLT), and the service encryption method for a passive optical network system mainly includes the following steps.
[0025] Step S100: Send encryption enabling information to the optical network unit ONU.
[0026] The encryption enabling information is used to indicate whether encryption is currently disabled, only uplink encryption is enabled, only downlink encryption is enabled, or both uplink and downlink encryption are enabled.
[0027] The service encryption method of the passive optical network system in the embodiment of the present application can be applied to PON system home or enterprise networking applications, as well as FTTR scenarios, etc., and this embodiment does not make specific limitations.
[0028] As those skilled in the art will appreciate, PLOAM (Physical Layer Operations, Administration, and Maintenance) messages refer to the physical layer operations, administration, and maintenance of the transport convergence layer system protocol stack in the GPON protocol layer. OMCI (ONU Management and Control Interface) messages are a protocol defined in the GPON standard for information exchange between the Optical Network Unit (OLT) and the Optical Network Unit (ONU). OMCI messages are used by the OLT to manage ONUs in a GPON network, including configuration management, fault management, performance management, and security management.
[0029] In this embodiment, the encryption enable information can be sent to the optical network unit (ONU) via a PLOAM message or an OMCI message. Specifically, the encryption enable information can carry an encryption enable flag, which is used to indicate whether encryption is currently disabled, only uplink encryption is enabled, only downlink encryption is enabled, or both uplink and downlink encryption are enabled.
[0030] Exemplarily, the encryption enablement information carries an encryption enablement flag in the following manner, including: step A10, carrying the encryption enablement flag through the designated bit of the PTI (Payload Type Indicator) field in the encryption enablement information, wherein the designated bit value is the first designated value indicating that encryption is not enabled, the designated bit value is the second designated value indicating that only uplink encryption is enabled, the designated bit value is the third designated value indicating that only downlink encryption is enabled, and the designated bit value is the fourth designated value indicating that uplink and downlink encryption are enabled.
[0031] In this embodiment, it is easy to understand that the first designated value, the second designated value, the third designated value, and the fourth designated value are all different. Different designated values indicate different encryption modes.
[0032] The embodiments of the present application can enable uplink and downlink encryption for various PON modes. For different application scenarios, various PON modes (including but not limited to GPON asymmetric, GPON symmetric, XGPON asymmetric, XGPON symmetric, etc.) support encryption enabling actions through standard PLOAM messages, OMCI messages, or customized PLOAM messages, OMCI messages, including four uplink and downlink encryption enabling strategies: no encryption, uplink encryption only, downlink encryption only, and uplink and downlink encryption.
[0033] Furthermore, the embodiments of the present application can implement hybrid encryption for different ONUs under the same PON port. Depending on the importance of the services, different ONUs under the same PON port can use different encryption algorithms. The OLT configures the encryption algorithm of each ONU through the OMCI entity ONU2-G. Specifically, all ONUs under the same PON port can be configured with the same encryption algorithm through broadcast, or a specific ONU or group of ONUs can be specified to be configured with a specific encryption algorithm through unicast and multicast configuration.
[0034] The embodiment of the present invention adds uplink encryption and frame interval configuration rules to GPON asymmetric and GPON symmetric PON modes, adds uplink and downlink encryption enabling strategies, SM4 encryption algorithms, and encryption algorithm dynamic switching strategies to various PON modes (including but not limited to GPON asymmetric, GPON symmetric, XGPON asymmetric, XGPON symmetric, etc. PON modes), and proposes a hybrid encryption strategy for different ONUs under the same PON port of the OLT, thereby realizing the FTTR encryption method.
[0035] After step S100, step S200 is executed. After enabling uplink and downlink encryption or enabling uplink encryption, the encryption algorithm currently negotiated and adopted by the OLT and the ONU is dynamically switched through the OMCI (ONU Management and Control Interface) entity ONU2-G.
[0036] Generally, a PON system consists of three components: the Optical Line Termination (OLT), the Optical Distribution Network (ODN), and the Optical Network Unit (ONU) / ONT (Optical Network Termination). The OLT provides the PON system with a Service Network Interface (SNI), connecting to one or more ODNs. Passive optical splitters distribute downstream data from the OLT to the individual ONUs and aggregate upstream data from multiple ONUs / ONTs to the OLT.
[0037] Those skilled in the art will know that the transmission from the OLT to the ONU is called downstream, and the reverse is called upstream.
[0038] In this embodiment, since the ONU and OLT have completed key synchronization, during the uplink encryption process, the keys currently used by the ONU and OLT are consistent. The OLT and ONU can use the same key for encryption / decryption, and uplink frame loss will not occur.
[0039] In this embodiment, the initiator of the key negotiation process for dynamic switching of the encryption algorithm is not necessarily the OLT, but may be the ONU, or may be jointly initiated by both parties, which is not specifically limited in this embodiment.
[0040] In one example, key negotiation can be performed by the OLT and ONU generating an encryption key based on a random number and system parameters. During the entire negotiation process, a transfer number generated from the random number and system parameters is transmitted. This prevents an eavesdropper from obtaining the transfer number or even the system parameters without knowing the random number and thus being unable to obtain the encryption key. This significantly improves the security of the key negotiation process compared to the related art of directly transmitting plaintext keys over the network. Furthermore, the transfer number or response message sent in this embodiment is fragmented and sent multiple times. Fragmenting data effectively improves data transmission security, while sending multiple times improves data transmission reliability. If the OLT or ONU fails to receive any fragment of the transfer number, it resends a request to update the encryption key message. If the number of consecutive requests to update the encryption key messages exceeds a predetermined number, the key negotiation is declared failed.
[0041] It should be noted that the encryption algorithms currently negotiated between the OLT and ONU include but are not limited to: AES-128, AES-256, Camellia-128, Camellia-256, and SM4 encryption algorithms.
[0042] Wherein, it is known to those skilled in the art that OMCI entity ONU2-G is a virtual device or entity unit for dynamically switching an encryption algorithm in the prior art, and will not be described in detail herein. It should be noted that, at present, OMCI entity ONU2-G is not temporarily used for dynamically switching an encryption algorithm for uplink transmission data.
[0043] In the present embodiment, in the process of dynamically switching the encryption algorithm according to the OMCI entity ONU2-G, various PON modes (including but not limited to GPON asymmetric, GPON symmetric, XGPON asymmetric, XGPON symmetric PON modes) all support multiple encryption algorithms (including but not limited to AES-128, AES-256, Camellia-128, Camellia-256 and SM4). Specifically, the ONU reports the encryption algorithm supported by the ONU to the OLT through the security capability (Security capability) attribute in the OMCI entity ONU2-G, and the security mode (Security mode) attribute in the entity ONU2-G is set to a specific value when the ONU is instantiated. For example, if it is set to 1, the AES-128 encryption algorithm is used.
[0044] Exemplarily, OLT sets the encryption algorithm of ONU by the Security mode attribute in OMCI entity ONU2-G, if Security mode value is 1 in OMCI entity ONU2-G, then encryption algorithm is switched to AES-128 encryption algorithm, if OMCI entity Security mode value is 5, then switches to SM4 encryption algorithm.Realize the switching of encryption algorithm after ONU responds.
[0045] After step S200, step S300 is executed to synchronize keys with the ONU according to the encryption algorithm after dynamic switching; step S400, after key synchronization, determines to use a new key or a new encryption algorithm starting from a specified frame according to the target value or Key Index of the superframe counter, and sends the target value or Key Index of the superframe counter to the ONU.
[0046] Exemplarily, based on the target value of the superframe counter or the Key Index, determining whether to use a new key or a new encryption algorithm starting from a specified frame includes: when the passive optical network system is a GPON asymmetric system or a GPON symmetric system, based on the target value of the superframe counter, using a new key or a new encryption algorithm starting from a specified frame; when the passive optical network system is an XGPON or XGSPON system, based on the change of the Key Index, using a new key or a new encryption algorithm starting from a specified frame.
[0047] In this embodiment, the target value of the superframe counter or the Key Index may be sent to the ONU via a PLOAM message or an OMCI message.
[0048] Exemplarily, the OLT and all the ONUs use the synchronized superframe counter, which includes an intra-frame counter and an inter-frame counter. The width of the superframe counter is 46 bits, of which the lower 16 bits are the intra-frame counter and the upper 30 bits are the inter-frame counter. For the uplink encryption, the intra-frame counter is set to 0 at the beginning of the uplink frame and increments every 4 bytes. The inter-frame counter is included in the GTC Header field of the downlink GTC (GPON Transmission Convergence) frame. The GTC Header field specifies the uplink GTC burst for transmitting the uplink GEM frame.
[0049] Furthermore, when the passive optical network system is a GPON asymmetric system or a GPON symmetric system, in the uplink direction, the burst of the GTC framing sublayer is divided into multiple data blocks of 4 bytes, and each of the data blocks is sequentially numbered from S to (S+X).
[0050] Wherein, S = |_Target StartTime / m_|, where Target StartTime is the StartTime of the first allocation (i.e., allocation) of the DLL (Dynamic Link Library) framing sublayer burst, StartTime is used to indicate the start time of the bandwidth allocation timeslot, X is the number of data blocks minus one (i.e., X is the number of data blocks in a GTC uplink burst minus one), and m is a preset value for the uplink data transmission rate, where, for 1.25G uplink, m = 4, and for 2.5G uplink, m = 2; the superframe counter includes an intra-frame counter and an inter-frame counter, where the value of the intra-frame counter includes all FEC (forward error correction) check bytes.
[0051] In this embodiment, it should be noted that in CTR (counter mode), the OLT and all ONUs use a synchronized superframe counter (SFC). The superframe counter is 46 bits wide, of which the lower 16 bits are the intra-frame counter and the upper 30 bits are the inter-frame counter. The intra-frame counter is reset to 0 at the beginning of the uplink and downlink frames and increments every 4 bytes. The value of the intra-frame counter in uplink and downlink encryption can include all FEC (forward error correction) check bytes. Of course, the value of the intra-frame counter in uplink and downlink encryption can also not include all FEC check bytes, which is not specifically limited in this embodiment.
[0052] Specifically, the intra-frame counter starts at 0 (the first byte of the GTC Header) at the beginning of the downlink frame and increments every 4 bytes. In a downlink rate 2.488 Gbit / s system, the intra-frame counter ranges from 0 to 9719.
[0053] In the uplink direction, the GTC framing sublayer burst is divided into 4-byte blocks, which are numbered sequentially from S to (S+X). Here, S = |_StartTime / m_|, where m = 4 for 1.25G uplink and m = 2 for 2.5G uplink. |_xxx_| represents xxx rounded down, where StartTime is the StartTime of the first allocation of the DLL framing sublayer burst, and X is the number of complete and incomplete 4-byte blocks in the GTC uplink burst minus 1. It is important to note that encryption occurs before FEC. However, the intra-frame counter values are derived from the transmitted frame, so in general, the downlink and uplink intra-frame counter values include all FEC check bytes before scrambling.
[0054] In the upstream direction, the interframe counter is contained in the PCBd (Physical Control Block downstream) field of the downstream GTC frame. This field specifies the upstream burst in which the upstream GTC frame is transmitted. The ONU implements a synchronized local counter and can therefore correct errors in this field. The random cipher block is aligned with the start of the GEM payload.
[0055] In this embodiment, only the payload of the GEM frame / slice is encrypted; the GEM frame header is not encrypted. Because a GEM slice is not necessarily a complete coded block, the MSB of the tail data block (1 to 16 bytes in length) is XORed with the MSB of the tail cipher block (16 bytes in length). The remainder of the tail cipher block is discarded.
[0056] In one embodiment, the designated frame is an information frame corresponding to when the value of the superframe counter reaches the target value. According to the target value of the superframe counter, the step of determining to use a new decryption key for decryption starting from the designated frame may specifically include: according to the target value of the superframe counter, when the value of the superframe counter configured on the ONU side reaches the target value, starting to use the new decryption key, wherein the superframe counter configured on the ONU side is synchronized with the superframe counter configured on the ONT side.
[0057] After key synchronization, this embodiment can determine the use of a new key or a new encryption algorithm starting from a specified frame based on the target value of the superframe counter or the Key Index. The target value of the superframe counter or the Key Index is sent to the ONU through a PLOAM message or an OMCI message to notify the ONU to use the new key or the new encryption algorithm starting from the specified frame. This can avoid the problem of inconsistent activation time of the new key or the new encryption algorithm caused by message exchange between the OLT and the ONU, achieve seamless switching of Port-ID encryption and decryption, and ensure that upstream data flows are not lost.
[0058] It is worth mentioning that the embodiment of the present application provides a method for implementing FTTR (Fiber to the Rome) encryption. For GPON asymmetric and GPON symmetric in FTTR scenarios, it is possible to add configuration rules for uplink encryption and inter-packet gap (IPG). For various PON modes in FTTR scenarios (including but not limited to GPON asymmetric, GPON symmetric, XGPON asymmetric, XGPON symmetric and other PON modes), uplink and downlink encryption enabling strategies, SM4 encryption algorithms and encryption algorithm dynamic switching strategies are added; a hybrid encryption strategy is proposed for different ONUs under the same PON port of the OLT.
[0059] It should be noted that all embodiments of the present application can operate in FTTR scenarios and the G.fin series standards, and can also operate in other scenarios, and the present application does not impose any restrictions on this.
[0060] The present application proposes a service encryption method, electronic device and storage medium of a passive optical network system. In the service encryption method of the passive optical network system, the technical solution of the embodiment of the present application is to send encryption enabling information to the optical network unit ONU, wherein the encryption enabling information is used to indicate whether encryption is currently not enabled, only uplink encryption is enabled, only downlink encryption is enabled or uplink and downlink encryption is enabled. Then, after enabling uplink and downlink encryption or enabling uplink encryption, the encryption algorithm currently negotiated and adopted by the OLT and the ONU is dynamically switched through the OMCI entity ONU2-G of the OMCI device. According to the encryption algorithm after the dynamic switching, key synchronization is performed between the ONU and the ONU. After key synchronization, according to the target value or Key Index of the superframe counter, it is determined to use a new key or a new encryption algorithm from the specified frame, and the target value or Key Index of the superframe counter is sent to the ONU to notify the ONU to use the new key or the new encryption algorithm from the specified frame to implement encryption and decryption of the uplink service message, thereby enabling FTTR (Fiber To The The GPON asymmetric and GPON symmetric in the FTTR (Fiber to the Room) scenario increase uplink encryption, thereby enabling various PON modes in the FTTR scenario (including but not limited to GPON asymmetric, GPON symmetric, XGPON asymmetric, XGPON symmetric and other PON modes) to support uplink and downlink encryption enabling strategies, SM4 encryption algorithms and dynamic switching strategies for encryption algorithms, effectively realizing the PON system's support for multiple encryption algorithms and the demand for dynamic switching of algorithms.
[0061] To help understand the embodiments of the present application, the technical principles of key interaction and update between the OLT and the ONU in a specific embodiment are listed, including: in this embodiment, after the encryption algorithm is switched according to the OMCI entity ONU2-G, the OLT and the ONU perform key interaction and update through a series of PLOAM messages.
[0062] For both asymmetric and symmetric GPON PON modes, the OLT requests a new key from the ONU by sending a downstream PLOAM message, Request_Key. The ONU responds by generating and storing a key and sending it to the OLT via an upstream PLOAM message, Encryption_Key. Due to PLOAM message length limitations, the key is sent in two parts, with the Frag_Index field indicating which part of the key is being sent. Both parts of the key are sent three times. The Key_Index field indicates which ONU the key belongs to. If the OLT fails to successfully receive either part of the key three times, it requests the ONU to generate another key by sending a new Request_Key message. If key transmission fails three times, the OLT declares key synchronization lost and deactivates the ONU. If the OLT successfully receives the key, it stores the verified key in the Shadow_Key_Register.
[0063] After the OLT successfully receives the key, it updates it. The OLT sends the value of the superframe counter (SFC) to the ONU via the PLOAM message Key_Switching_Time. This message is sent three times, and the ONU only needs to receive one of these messages to obtain the key update time, which indicates the frame in which the key or new encryption algorithm should be updated. At the beginning of a specific frame, the OLT copies the contents of the Shadow_Key_Register to the Active_Key_Register, and the ONU assigns the value of its Shadow_Key_Register to the Active_Key_Register. From the specified frame onward, both the OLT and the ONU begin using the new key or encryption algorithm, completing the key update.
[0064] For the two PON modes of GPON asymmetric and GPON symmetric, after the encryption algorithm is switched, the SFC value (ie, the target value of the superframe counter mentioned above) sent by the OLT received by the key update ONU is used as the benchmark for effectiveness.
[0065] It should be noted that the many details described in this specific embodiment are only helpful for understanding the technical principles or technical concepts of this application, and do not constitute a limitation of this application. More simple transformations based on the technical concepts of this application should all be within the scope of protection of this application.
[0066] In a possible implementation, the step S300 of synchronizing keys with the ONU according to the encryption algorithm after the dynamic switch includes the following steps.
[0067] Step S310: instruct the ONU to generate a new key according to the encryption algorithm after the dynamic switch.
[0068] In this embodiment, the OLT may instruct the ONU to generate a new key by sending a key request message Request_Key message.
[0069] Specifically, the ONU is instructed to generate a new key based on the algorithm type corresponding to the dynamically switched encryption algorithm. For example, if the algorithm type corresponding to the dynamically switched encryption algorithm is SM4, the new key generated by the ONU is a new key generated based on the SM4 algorithm.
[0070] Step S320: After receiving the new key reported by the ONU, specify a key switching time at which the new key becomes effective, and notify the ONU of the key switching time.
[0071] In this embodiment, the OLT may notify the ONU of the key switching time by sending a key switching time message Key_Switching_Time message.
[0072] Step S330: After receiving the response of the key switching time fed back by the ONU, the new key is set in the register of the currently used key at the key switching time.
[0073] After receiving the key switching time sent by the OLT, the ONU feeds back a response of receiving the key switching time to the ONU.
[0074] In this embodiment, the OLT and ONU can specifically interact using messages specified in the ITU-T G.984.3 standard. The OLT instructs the ONU to generate a new key by sending a Request_Key message and notifies the ONU of the key switching time by sending a Key_Switching_Time message. After key synchronization, the ONU can be notified to enable the GEM-PORT decryption function by sending an Encrypted_Port_ID message. The ONU reports the new key to the OLT by sending an Encryption_Key message and notifies the OLT of receipt of the key switching time by sending an Acknowledgement message.
[0075] This embodiment instructs the ONU to generate a new key based on the encryption algorithm after dynamic switching. After receiving the new key reported by the ONU, the embodiment specifies a key switching time at which the new key takes effect, notifies the ONU of the key switching time, and then sets the new key to the register of the currently used key at the key switching time after receiving a response of the key switching time from the ONU. This ensures that the key switching times on the ONU and OLT sides are consistent. If they are inconsistent, the OLT will not receive data sent by the ONU.
[0076] In a possible implementation, when the passive optical network system is a GPON asymmetric system or a GPON symmetric system, the target value of the superframe counter is sent to the ONU through a PLOAM message, wherein the step of sending the target value of the superframe counter to the ONU includes: step B10, sending an Encrypted_Port_ID message to the ONU, wherein the Encrypted_Port_ID message carries the target value of the superframe counter.
[0077] In this embodiment, after key synchronization, the OLT may enable the encryption function of the GPON encapsulation method channel (GEM-PORT) and notify the ONU to enable the decryption function of the GEM-PORT by sending a GEM-PORT encryption message Encrypted_Port_ID message.
[0078] This embodiment sends an Encrypted_Port_ID message to the ONU, where the Encrypted_Port_ID message carries the target value of the superframe counter. This embodiment of the present application avoids the problem of information frame asynchrony caused by the use of new keys or new encryption algorithms due to message exchange between the OLT and the ONU, realizes seamless switching of Port-ID encryption and decryption, ensures that upstream data flows are not lost, and fully guarantees the reliability of data exchange between the OLT and the ONU.
[0079] Furthermore, to achieve the above-mentioned objectives, please refer to FIG. 2 , which is a flow chart illustrating a service encryption method for a passive optical network system in a second embodiment of the present application. As shown in FIG. 2 , the present embodiment further provides a service encryption method for a passive optical network system, which is applied to an optical network unit (ONU) and includes the following steps: Step S500 , receiving encryption enable information sent by an optical line terminal (OLT).
[0080] In this embodiment, encryption enabling information sent by the optical line terminal OLT may be received.
[0081] The encryption enabling information is used to indicate whether encryption is currently disabled, only uplink encryption is enabled, only downlink encryption is enabled, or both uplink and downlink encryption are enabled.
[0082] The service encryption method of the passive optical network system in the embodiment of the present application can be applied to PON system home or enterprise networking applications, as well as FTTR scenarios, etc., and this embodiment does not make specific limitations.
[0083] As those skilled in the art will appreciate, PLOAM (Physical Layer Operations, Administration, and Maintenance) messages refer to the physical layer operations, management, and maintenance of the transport convergence layer system protocol stack in the GPON protocol layer. OMCI (ONU Management and Control Interface) messages are a protocol defined in the GPON standard for information exchange between an optical network unit (OLT) and an optical network unit (ONT). OMCI messages are used by the OLT to manage the ONTs in a GPON network, including configuration management, fault management, performance management, and security management.
[0084] Specifically, the encryption enable information may carry an encryption enable flag, and the encryption enable flag is used to indicate whether encryption is currently disabled, only uplink encryption is enabled, only downlink encryption is enabled, or both uplink and downlink encryption are enabled.
[0085] Exemplarily, the encryption enable information carries an encryption enable identifier in the following manner, including: step C10, carrying the encryption enable identifier through the designated bit of the PTI (Payload Type Indicator) field in the encryption enable information, wherein the designated bit value is the first designated value indicating that encryption is not enabled, the designated bit value is the second designated value indicating that only uplink encryption is enabled, the designated bit value is the third designated value indicating that only downlink encryption is enabled, and the designated bit value is the fourth designated value indicating that uplink and downlink encryption are enabled.
[0086] In this embodiment, it is easy to understand that the first designated value, the second designated value, the third designated value, and the fourth designated value are all different. Different designated values indicate different encryption modes.
[0087] The embodiments of the present application can enable uplink and downlink encryption for various PON modes. For different application scenarios, various PON modes (including but not limited to GPON asymmetric, GPON symmetric, XGPON asymmetric, XGPON symmetric, etc.) support encryption enabling actions through standard PLOAM messages, OMCI messages, or customized PLOAM messages and OMCI messages, including four uplink and downlink encryption enabling strategies: no encryption, uplink encryption only, downlink encryption only, and uplink and downlink encryption.
[0088] Furthermore, the embodiments of the present application can implement hybrid encryption for different ONUs under the same PON port. Depending on the importance of the services, different ONUs under the same PON port can use different encryption algorithms. The OLT configures the encryption algorithm of each ONU through the OMCI entity ONU2-G. Specifically, all ONUs under the same PON port can be configured with the same encryption algorithm through broadcast, or a specific ONU or group of ONUs can be specified to be configured with a specific encryption algorithm through unicast and multicast configuration.
[0089] The embodiment of the present invention adds uplink encryption and frame interval configuration rules to GPON asymmetric and GPON symmetric PON modes, adds uplink and downlink encryption enabling strategies, SM4 encryption algorithms, and encryption algorithm dynamic switching strategies to various PON modes (including but not limited to GPON asymmetric, GPON symmetric, XGPON asymmetric, XGPON symmetric, etc. PON modes), and proposes a hybrid encryption strategy for different ONUs under the same PON port of the OLT, thereby realizing the FTTR encryption method.
[0090] After step S500, step S600 is executed. After enabling uplink and downlink encryption or enabling uplink encryption, the encryption algorithm currently negotiated and adopted by the OLT and the ONU is dynamically switched through the OMCI entity ONU2-G.
[0091] Generally, a PON system consists of three components: the Optical Line Termination (OLT), the Optical Distribution Network (ODN), and the Optical Network Unit (ONU) / ONT (Optical Network Termination). The OLT provides the PON system with a Service Network Interface (SNI), connecting to one or more ODNs. Passive optical splitters distribute downstream data from the OLT to the individual ONUs and aggregate upstream data from multiple ONUs / ONTs to the OLT.
[0092] Those skilled in the art will know that the transmission from the OLT to the ONU is called downstream, and the reverse is called upstream.
[0093] In this embodiment, since the ONU and OLT have completed key synchronization, during the uplink encryption process, the keys currently used by the ONU and OLT are consistent. The OLT and ONU can use the same key for encryption / decryption, and uplink frame loss will not occur.
[0094] In this embodiment, the initiator of the key negotiation process for dynamic switching of the encryption algorithm is not necessarily the OLT, but may be the ONU, or may be jointly initiated by both parties, which is not specifically limited in this embodiment.
[0095] In one example, key negotiation can be performed by the OLT and ONU generating an encryption key based on a random number and system parameters. During the entire negotiation process, a transfer number generated from the random number and system parameters is transmitted. This prevents an eavesdropper from obtaining the transfer number or even the system parameters without knowing the random number and thus being unable to obtain the encryption key. This significantly improves the security of the key negotiation process compared to the related art of directly transmitting plaintext keys over the network. Furthermore, the transfer number or response message sent in this embodiment is fragmented and sent multiple times. Fragmenting data effectively improves data transmission security, while sending multiple times improves data transmission reliability. If the OLT or ONU fails to receive any fragment of the transfer number, it resends a request to update the encryption key message. If the number of consecutive requests to update the encryption key messages exceeds a predetermined number, the key negotiation is declared failed.
[0096] It should be noted that the encryption algorithms currently negotiated between the OLT and ONU include but are not limited to: AES-128, AES-256, Camellia-128, Camellia-256, and SM4 encryption algorithms.
[0097] Wherein, it is known to those skilled in the art that OMCI entity ONU2-G is a virtual device or entity unit for dynamically switching an encryption algorithm in the prior art, and will not be described in detail herein. It should be noted that, at present, OMCI entity ONU2-G is not temporarily used for dynamically switching an encryption algorithm for uplink transmission data.
[0098] In the present embodiment, in the process of carrying out dynamic switching of encryption algorithm according to OMCI entity ONU2-G, various PON modes (including but not limited to PON modes such as GPON asymmetric, GPON symmetric, XGPON asymmetric, XGPON symmetric) all support multiple encryption algorithms (including but not limited to AES-128, AES-256, Camellia-128, Camellia-256 and SM4). Specifically, ONU reports the encryption algorithm supported by ONU to OLT through the Security capability attribute in OMCI entity ONU2-G, and when instantiating ONU, the Security mode attribute in entity ONU2-G can be set to a certain specific value, such as being set to 1, i.e., using AES-128 encryption algorithm.
[0099] Exemplarily, OLT sets the encryption algorithm of ONU by the Security mode attribute in OMCI entity ONU2-G, and if Security mode value is 1 in OMCI entity ONU2-G, encryption algorithm is switched to AES-128 encryption algorithm, and if Security mode value is 5 in OMCI entity, encryption algorithm is switched to SM4 encryption algorithm. After ONU responds, the switching of encryption algorithm is realized.
[0100] After step S600, step S700 is executed to synchronize keys with the OLT based on the encryption algorithm after the dynamic switching. In step S800, after key synchronization, a target value or Key Index of a superframe counter sent by the OLT is received, and a new key or a new encryption algorithm is determined to be used starting from a specified frame based on the target value or Key Index of the superframe counter.
[0101] Exemplarily, based on the target value of the superframe counter or the Key Index, determining whether to use a new key or a new encryption algorithm starting from a specified frame includes: when the passive optical network system is a GPON asymmetric system or a GPON symmetric system, based on the target value of the superframe counter, using a new key or a new encryption algorithm starting from a specified frame; when the passive optical network system is an XGPON or XGSPON system, based on the change of the Key Index, using a new key or a new encryption algorithm starting from a specified frame.
[0102] In this embodiment, the target value of the superframe counter or the Key Index sent by the OLT may be received through a PLOAM message or an OMCI message.
[0103] Exemplarily, the OLT and all the ONUs use the synchronized superframe counter, which includes an intra-frame counter and an inter-frame counter. The width of the superframe counter is 46 bits, of which the lower 16 bits are the intra-frame counter and the upper 30 bits are the inter-frame counter. For the uplink encryption, the intra-frame counter is set to 0 at the beginning of the uplink frame and increments every 4 bytes. The inter-frame counter is included in the GTC Header field of the downlink GTC frame, and the GTC Header field specifies the uplink GTC burst for transmitting the uplink GEM frame.
[0104] Specifically, when the passive optical network system is a GPON asymmetric system or a GPON symmetric system, in the uplink direction, the burst of the GTC framing sublayer is divided into multiple data blocks of 4 bytes, and each of the data blocks is sequentially numbered from S to (S+X).
[0105] Wherein, S = |_target StartTime / m_|, where Target StartTime is the StartTime of the first allocation of the DLL framing sublayer burst, StartTime is used to indicate the start time of the bandwidth allocation time slot, X is the number of data blocks minus one (i.e., X is the number of data blocks in the GTC uplink burst minus one), and m is a preset value for the uplink data transmission rate, where for 1.25G uplink, m = 4, and for 2.5G uplink, m = 2; the superframe counter includes an intra-frame counter and an inter-frame counter, where the value of the intra-frame counter includes all FEC check bytes.
[0106] It should be noted that in CTR (counter mode), the OLT and all ONUs use a synchronized superframe counter (SFC). The superframe counter is 46 bits wide, of which the lower 16 bits are the intra-frame counter and the upper 30 bits are the inter-frame counter. The intra-frame counter is reset to 0 at the beginning of a downlink frame and increments every 4 bytes. The value of the superframe counter in uplink and downlink encryption can include all FEC (forward error correction) check bytes. Of course, the value of the superframe counter in uplink and downlink encryption can also not include all FEC check bytes, which is not specifically limited in this embodiment.
[0107] Specifically, the intra-frame counter starts at 0 at the beginning of the downlink frame (the first byte of the PHY Header) and increments every 4 bytes. In a downlink rate 2.488 Gbit / s system, the intra-frame counter ranges from 0 to 9719.
[0108] In the uplink direction, the DLL (Dynamic Link Library) framing sublayer bursts are divided into 4-byte blocks, which are numbered sequentially from S to (S+X). Here, S = |_StartTime / m_|, where m = 4 for 1.25G uplink and m = 2 for 2.5G uplink. |_xxx_| represents xxx rounded down, where StartTime is the StartTime of the first allocation of the DLL framing sublayer burst, and X is the number of complete and incomplete 4-byte blocks in the DLL burst minus 1. It is important to note that encryption occurs before FEC. However, the intra-frame counter values are derived from the transmitted frame, so in general, all FEC check bytes are included in the downlink and uplink intra-frame counter values before scrambling.
[0109] In the upstream direction, the interframe counter is contained in the PCBd (Physical Control Block downstream) field of the downstream GTC frame. This field specifies the upstream burst in which the upstream GTC frame is transmitted. The ONU implements a synchronized local counter and can therefore correct errors in this field. The random cipher block is aligned with the start of the GEM payload.
[0110] In this embodiment, only the payload of the GEM frame / slice is encrypted; the GEM frame header is not encrypted. Because a GEM slice is not necessarily a complete coded block, the MSB of the tail data block (1 to 16 bytes in length) is XORed with the MSB of the tail cipher block (16 bytes in length). The remainder of the tail cipher block is discarded.
[0111] In one embodiment, the designated frame is an information frame corresponding to when the value of the superframe counter reaches the target value. According to the target value of the superframe counter, the step of determining to use a new decryption key for decryption starting from the designated frame may specifically include: according to the target value of the superframe counter, when the value of the superframe counter configured on the ONU side reaches the target value, starting to use the new decryption key, wherein the superframe counter configured on the ONU side is synchronized with the superframe counter configured on the ONT side.
[0112] After key synchronization, this embodiment can receive the target value of the superframe counter or the Key Index sent by the OLT through a PLOAM message or an OMCI message. Based on the target value of the superframe counter or the Key Index, a new key or a new encryption algorithm is determined to be used starting from a specified frame. This can avoid the problem of inconsistent activation time of the new key caused by message exchange between the OLT and the ONU, achieve seamless switching of Port-ID encryption and decryption, and ensure that upstream data flows are not lost.
[0113] It is worth mentioning that the embodiment of the present application provides a method for implementing FTTR (Fiber to the Rome) encryption. For GPON asymmetric and GPON symmetric in FTTR scenarios, it is possible to add configuration rules for uplink encryption and inter-packet gap (IPG). For various PON modes in FTTR scenarios (including but not limited to GPON asymmetric, GPON symmetric, XGPON asymmetric, XGPON symmetric and other PON modes), uplink and downlink encryption enabling strategies, SM4 encryption algorithms and encryption algorithm dynamic switching strategies are added; a hybrid encryption strategy is proposed for different ONUs under the same PON port of the OLT.
[0114] The present application proposes a service encryption method, electronic device and storage medium of a passive optical network system. In the service encryption method of the passive optical network system, the technical solution of the embodiment of the present application is to receive encryption enabling information sent by an optical line terminal (OLT), wherein the encryption enabling information is used to indicate whether encryption is currently not enabled, only uplink encryption is enabled, only downlink encryption is enabled or uplink and downlink encryption is enabled. After enabling uplink and downlink encryption or enabling uplink encryption, the encryption algorithm currently negotiated and adopted by the OLT and the ONU is dynamically switched through the OMCI entity ONU2-G, and according to the encryption algorithm after dynamic switching, key synchronization is performed with the OLT. Then, after key synchronization, the target value or Key Index of the superframe counter sent by the OLT is received, and according to the target value or Key Index of the superframe counter, it is determined to use a new key or a new encryption algorithm starting from a specified frame to complete encryption and decryption of the uplink service message, thereby enabling FTTR (Fiber To The The GPON asymmetric and GPON symmetric in the FTTR (Fiber to the Room) scenario increase uplink encryption, thereby enabling various PON modes in the FTTR scenario (including but not limited to GPON asymmetric, GPON symmetric, XGPON asymmetric, XGPON symmetric and other PON modes) to support uplink and downlink encryption enabling strategies, SM4 encryption algorithms and dynamic switching strategies for encryption algorithms, effectively realizing the PON system's support for multiple encryption algorithms and the demand for dynamic switching of algorithms.
[0115] In a possible implementation, the step S700 of performing key synchronization with the OLT according to the dynamically switched encryption algorithm includes the following steps.
[0116] Step S710: According to the encryption algorithm after the dynamic switch, the OLT instructs the ONU to generate a new key.
[0117] In this embodiment, the ONU may receive a key request message Request_Key sent by the OLT, and trigger the ONU to generate a new key according to the Request_Key message.
[0118] Specifically, the OLT instructs the ONU to generate a new key based on the algorithm type corresponding to the dynamically switched encryption algorithm. For example, if the algorithm type corresponding to the dynamically switched encryption algorithm is SM4, the new key generated by the ONU is a new key generated based on the SM4 algorithm.
[0119] Step S720: reporting the new key to the ONU to trigger the OLT to specify a key switching time at which the new key takes effect.
[0120] In this embodiment, the ONU may receive a key switching time message Key_Switching_Time sent by the OLT, and obtain the key switching time according to the Key_Switching_Time message.
[0121] Step S730: Receive the key switching time returned by the OLT in response to the new key, and feed back a response of receiving the key switching time to the OLT, so as to trigger the OLT to set the new key to the register of the currently used key at the key switching time.
[0122] In this embodiment, the OLT and ONU can specifically interact using messages specified in the ITU-T G.984.3 standard. The OLT instructs the ONU to generate a new key by sending a Request_Key message and notifies the ONU of the key switching time by sending a Key_Switching_Time message. After key synchronization, the ONU can be notified to enable the GEM-PORT decryption function by sending an Encrypted_Port_ID message. The ONU reports the new key to the OLT by sending an Encryption_Key message and notifies the OLT of receipt of the key switching time by sending an Acknowledgement message.
[0123] In this embodiment, the OLT instructs the ONU to generate a new key based on the encryption algorithm after dynamic switching, reports the new key to the ONU, triggers the OLT to specify a key switching time at which the new key takes effect, receives the key switching time returned by the OLT in response to the new key, and feeds back a response to the key switching time to the OLT, triggering the OLT to set the new key to the register of the currently used key at the key switching time, thereby ensuring that the key switching times on the ONU and OLT sides are synchronized. If they are not synchronized, the OLT will not receive data sent by the ONU.
[0124] In a possible implementation, when the passive optical network system is a GPON asymmetric system or a GPON symmetric system, a target value of a superframe counter sent by the OLT is received through a PLOAM message, wherein the step of receiving the target value of the superframe counter sent by the OLT includes: step D10, receiving an Encrypted_Port_ID message sent by the OLT; and step D20, determining the target value of the superframe counter based on the Encrypted_Port_ID message.
[0125] In this embodiment, after key synchronization, the OLT may enable the encryption function of the GPON encapsulation method channel (GEM-PORT) and notify the ONU to enable the decryption function of the GEM-PORT by sending a GEM-PORT encryption message Encrypted_Port_ID message.
[0126] This embodiment receives an Encrypted_Port_ID message sent by the OLT and determines the target value of the superframe counter based on the Encrypted_Port_ID message. This embodiment of the present application avoids the problem of information frame asynchrony caused by the use of new keys or new encryption algorithms due to message exchange between the OLT and the ONU, thereby achieving seamless switching of Port-ID encryption and decryption, ensuring that upstream data flows are not lost, and fully ensuring the reliability of data exchange between the OLT and the ONU.
[0127] In order to help understand the technical principles or technical concepts of the embodiments of the present application, a specific embodiment 2 is listed, including the following (1)-(3).
[0128] (1) Encrypt the plaintext at the sending end to obtain the ciphertext
[0129] At the sender, the 128-bit input to the encryption algorithm is derived for each data block based on the 46-bit synchronization counter value as follows: 46 bits are replicated three times to form a 138-bit sequence, with the upper 10 bits discarded. The remaining 128 bits are encrypted using an encryption algorithm (including but not limited to AES-128, AES-256, Camellia-128, Camellia-256, and SM4) to generate a 128-bit random key, which is then XORed with the payload data.
[0130] For downstream transmission, the OLT is the transmitter and the ONU is the receiver. The OLT encrypts the plaintext to generate ciphertext and sends it to the ONU. For upstream transmission, the ONU is the transmitter and the OLT is the receiver. The ONU encrypts the plaintext to generate ciphertext and sends it to the OLT.
[0131] (2) Decrypt the ciphertext at the receiving end to obtain the plaintext
[0132] Since the counter values and keys of the OLT and ONU are synchronized, the plain text can be decrypted by performing an XOR operation on the received ciphertext and the same 128-bit random password at the receiving end.
[0133] (3) Two other encryption enabling solutions for GPON asymmetric and GPON symmetric
[0134] GPON asymmetric and GPON symmetric encryption is enabled by modifying the PTI field in the Encrypted_Port-ID message or GEM frame.
[0135] The Encrypted_Port-ID message in the GPON asymmetric and GPON symmetric downstream PLOAM messages is used to indicate the time when downstream encryption is enabled or when uplink and downlink encryption is enabled. The unused four bytes from bytes 6 to 12 in the Encrypted_Port-ID message are used to indicate the SFC value of the first frame in which the new key takes effect after key exchange. As shown in the table below, bytes 6 to 9 are used to indicate the SFC value of the first frame in which the new key takes effect after key exchange. The six least significant bits of the sixth byte represent the six most significant bits of the SFC value of the first frame in which the key exchange takes effect. The ninth byte represents the eight least significant bits of the SFC value of the first frame in which the key exchange takes effect. Bytes 7 and 8 are middle bits.
[0136] As shown in the following table.
[0137] In this embodiment, the second bit value of the PTI field in the GEM frame is used to indicate whether encryption is enabled. A value of 1 in the second bit of the PTI field indicates that encryption is enabled, and a value of 0 in the second bit of the PTI field indicates that encryption is not enabled, as shown in the following table.
[0138] In this embodiment, whether encryption is enabled in the current transmission direction can be determined according to the value of the PTI field in the uplink and downlink GEM frames.
[0139] It should be noted that the many details described in this specific embodiment 2 are only helpful for understanding the technical principles or technical concepts of this application, and do not constitute a limitation of this application. More simple transformations based on the technical concepts of this application should all be within the scope of protection of this application.
[0140] In order to further help understand the technical principles or technical concepts of the embodiments of the present application, a specific embodiment three is listed, including: This embodiment provides a method for implementing FTTR (Fiber To The Room) encryption, which includes the following 1-8.
[0141] 1. GPON asymmetric and GPON symmetric configuration rules for upstream encryption and interframe spacing are added. The IFC value for the GEM frame in the upstream GTC burst is obtained based on the value of the intra-frame counter (IFC) of the synchronization counter. When the synchronization counter IFC = N, the position of the first byte of the GEM frame header is marked. The synchronization counter value at this byte position is used as the cipher block counter value for the GTC upstream burst. For each subsequent cipher block in the GTC upstream burst, the counter is incremented by 1. This method ensures that the same counter value is not reused.
[0142] 2. Enable uplink and downlink encryption.
[0143] 3. Switch the encryption algorithm based on the OMCI entity ONU2-G.
[0144] 4. Hybrid encryption of different ONUs under the same PON port.
[0145] 5. After the encryption algorithm is switched, the OLT and ONU exchange and update keys based on the new encryption algorithm. The encryption algorithm switch takes effect based on the key update SFC. The encryption algorithm switch can also take effect based on the change in the Key Index.
[0146] 6. Encrypt the plaintext at the sending end to obtain the ciphertext.
[0147] 7. Decrypt the ciphertext at the receiving end to obtain the plaintext.
[0148] 8. Modify the PTI field in the Encrypted_Port-ID message and GEM frame of GPON asymmetric and GPON symmetric.
[0149] It should be noted that the many details described in this specific embodiment 3 are only helpful for understanding the technical principles or technical concepts of this application, and do not constitute a limitation of this application. More simple transformations based on the technical concepts of this application should all be within the scope of protection of this application.
[0150] In addition, an embodiment of the present application also provides a service encryption method for a passive optical network system, which is applied to an FTTR main device MFU (Main FTTR Unit), including: sending encryption enable information to an FTTR slave device SFU (Sub FTTR Unit), wherein the encryption enable information is used to indicate whether encryption is currently not enabled, only uplink encryption is enabled, only downlink encryption is enabled, or uplink and downlink encryption is enabled; after enabling uplink and downlink encryption or enabling uplink encryption, dynamically switching the encryption algorithm currently negotiated and adopted by the MFU and the SFU through the OMCI entity ONU2-G; performing key synchronization with the SFU based on the encryption algorithm after the dynamic switching; after key synchronization, determining to use a new key or a new encryption algorithm starting from a specified frame based on the target value or Key Index of the superframe counter, and sending the target value or Key Index of the superframe counter to the SFU.
[0151] The present application proposes a service encryption method, electronic device and storage medium of a passive optical network system. In the service encryption method of the passive optical network system, the technical solution of the embodiment of the present application is to send encryption enabling information to the FTTR slave device SFU, wherein the encryption enabling information is used to indicate whether encryption is currently not enabled, only uplink encryption is enabled, only downlink encryption is enabled or uplink and downlink encryption is enabled. Then, after enabling uplink and downlink encryption or enabling uplink encryption, the encryption algorithm currently negotiated and adopted by the MFU and the SFU is dynamically switched through the OMCI entity ONU2-G of the OMCI device. According to the encryption algorithm after the dynamic switching, key synchronization is performed with the SFU. After key synchronization, according to the target value or Key Index of the superframe counter, it is determined to use a new key or a new encryption algorithm from the specified frame, and the target value or Key Index of the superframe counter is sent to the SFU to notify the SFU to use the new key or the new encryption algorithm from the specified frame to encrypt and decrypt the uplink service message, so that in the FTTR (Fiber To The The GPON asymmetric and GPON symmetric in the FTTR (Fiber to the Room) scenario increase uplink encryption, thereby enabling various PON modes in the FTTR scenario (including but not limited to GPON asymmetric, GPON symmetric, XGPON asymmetric, XGPON symmetric and other PON modes) to support uplink and downlink encryption enabling strategies, SM4 encryption algorithms and dynamic switching strategies for encryption algorithms, effectively realizing the PON system's support for multiple encryption algorithms and the demand for dynamic switching of algorithms.
[0152] In some embodiments, when the passive optical network system is a GPON asymmetric system or a GPON symmetric system, a new key or a new encryption algorithm is used starting from a specified frame according to the target value of the superframe counter; when the passive optical network system is an XGPON or XGSPON system, a new key or a new encryption algorithm is used starting from a specified frame according to the change of the Key Index.
[0153] In some embodiments, when the passive optical network system is a GPON asymmetric system or a GPON symmetric system, in the upstream direction, the burst of the GTC framing sublayer is divided into multiple data blocks of 4 bytes, and each of the data blocks is sequentially numbered from S to (S+X); wherein S=|_target StartTime / m_|, the target StartTime is the StartTime of the first allocation of the DLL framing sublayer burst, StartTime is used to indicate the start time of the bandwidth allocation time slot, X is the number of the data blocks minus one (that is, X is the number of data blocks in the GTC upstream burst minus one), and m is a preset value for the upstream data transmission rate, wherein for 1.25G upstream, m=4, and for 2.5G upstream, m=2; the superframe counter includes an intra-frame counter and an inter-frame counter, wherein the value of the intra-frame counter includes all FEC check bytes.
[0154] In some embodiments, the step of synchronizing the key with the SFU according to the encryption algorithm after the dynamic switching includes: instructing the SFU to generate a new key according to the encryption algorithm after the dynamic switching; after receiving the new key reported by the SFU, specifying the key switching time when the new key takes effect, and notifying the SFU of the key switching time; after receiving the response of the key switching time fed back by the SFU, setting the new key to the register of the currently used key at the key switching time.
[0155] In some embodiments, the method further includes: instructing the SFU to generate a new key by sending a key request message Request_Key message; and notifying the SFU of the key switching time by sending a key switching time message Key_Switching_Time message.
[0156] In some embodiments, when the passive optical network system is a GPON asymmetric system or a GPON symmetric system, the target value of the superframe counter is sent to the SFU via a PLOAM message, wherein the step of sending the target value of the superframe counter to the SFU includes: sending an Encrypted_Port_ID message to the SFU, wherein the Encrypted_Port_ID message carries the target value of the superframe counter.
[0157] In some embodiments, the encryption enable information carries an encryption enable flag in the following manner, including: carrying the encryption enable flag through a designated bit of the PTI field in the encryption enable information, wherein the designated bit value is a first designated value indicating that encryption is not enabled, the designated bit value is a second designated value indicating that only uplink encryption is enabled, the designated bit value is a third designated value indicating that only downlink encryption is enabled, and the designated bit value is a fourth designated value indicating that uplink and downlink encryption are enabled.
[0158] In some embodiments, the MFU and all the SFUs use the synchronized superframe counter, the superframe counter includes an intra-frame counter and an inter-frame counter, the superframe counter has a width of 46 bits, wherein the lower 16 bits are the intra-frame counter and the upper 30 bits are the inter-frame counter, for the uplink encryption, the intra-frame counter is set to 0 at the beginning of the uplink frame and increments every 4 bytes, the inter-frame counter is included in the GTC Header field of the downlink GTC frame, and the GTC Header field specifies the uplink GTC burst for transmitting the uplink GEM frame.
[0159] The service encryption method for a passive optical network system provided in an embodiment of the present invention utilizes the same or similar technical features as those in the aforementioned embodiment, enabling PON systems to support multiple encryption algorithms and dynamically switch between them. Compared to the prior art, the service encryption method for a passive optical network system provided in an embodiment of the present invention achieves the same beneficial effects as those of the service encryption method for a passive optical network system provided in the aforementioned embodiment. Other technical features of the service encryption method for a passive optical network system are the same as those disclosed in the first embodiment above and are not further detailed here.
[0160] In addition, an embodiment of the present application also provides a service encryption method for a passive optical network system, which is applied to an FTTR slave device SFU, including: receiving encryption enable information sent by an FTTR master device MFU, wherein the encryption enable information is used to indicate whether encryption is currently not enabled, only uplink encryption is enabled, only downlink encryption is enabled, or uplink and downlink encryption is enabled; after enabling uplink and downlink encryption or enabling uplink encryption, dynamically switching the encryption algorithm currently negotiated and adopted by the MFU and the SFU through the OMCI entity ONU2-G; performing key synchronization with the MFU according to the encryption algorithm after the dynamic switching; after key synchronization, receiving the target value or Key Index of the superframe counter sent by the MFU, and determining to use a new key or a new encryption algorithm starting from a specified frame according to the target value or Key Index of the superframe counter.
[0161] The present application proposes a service encryption method, electronic device and storage medium of a passive optical network system. In the service encryption method of the passive optical network system, the technical solution of the embodiment of the present application is to receive encryption enabling information sent by the FTTR main device MFU, wherein the encryption enabling information is used to indicate whether encryption is currently not enabled, only uplink encryption is enabled, only downlink encryption is enabled or uplink and downlink encryption is enabled. After enabling uplink and downlink encryption or enabling uplink encryption, the encryption algorithm currently negotiated and adopted by the MFU and the SFU is dynamically switched through the OMCI entity ONU2-G, and according to the encryption algorithm after dynamic switching, key synchronization is performed with the MFU. Then, after key synchronization, the target value or Key Index of the superframe counter sent by the MFU is received. According to the target value or Key Index of the superframe counter, it is determined to use a new key or a new encryption algorithm starting from the specified frame to encrypt and decrypt the uplink service message, so that in FTTR (Fiber To The The GPON asymmetric and GPON symmetric in the FTTR (Fiber to the Room) scenario increase uplink encryption, thereby enabling various PON modes in the FTTR scenario (including but not limited to GPON asymmetric, GPON symmetric, XGPON asymmetric, XGPON symmetric and other PON modes) to support uplink and downlink encryption enabling strategies, SM4 encryption algorithms and dynamic switching strategies for encryption algorithms, effectively realizing the PON system's support for multiple encryption algorithms and the demand for dynamic switching of algorithms.
[0162] In some embodiments, when the passive optical network system is a GPON asymmetric system or a GPON symmetric system, a new key or a new encryption algorithm is used starting from a specified frame according to the target value of the superframe counter; when the passive optical network system is an XGPON or XGSPON system, a new key or a new encryption algorithm is used starting from a specified frame according to the change of the Key Index.
[0163] In some embodiments, when the passive optical network system is a GPON asymmetric system or a GPON symmetric system, in the upstream direction, the burst of the GTC framing sublayer is divided into multiple data blocks of 4 bytes, and each of the data blocks is sequentially numbered from S to (S+X); wherein S=|_target StartTime / m_|, the target StartTime is the StartTime of the first allocation of the DLL framing sublayer burst, StartTime is used to indicate the start time of the bandwidth allocation time slot, X is the number of the data blocks minus one (that is, X is the number of data blocks in the GTC upstream burst minus one), and m is a preset value for the upstream data transmission rate, wherein for 1.25G upstream, m=4, and for 2.5G upstream, m=2; the superframe counter includes an intra-frame counter and an inter-frame counter, wherein the value of the intra-frame counter includes all FEC check bytes.
[0164] In some embodiments, the method further includes: receiving a key request message Request_Key message sent by the MFU, and triggering the SFU to generate a new key according to the Request_Key message; receiving a key switching time message Key_Switching_Time message sent by the MFU, and obtaining the key switching time according to the Key_Switching_Time message.
[0165] In some embodiments, when the passive optical network system is a GPON asymmetric system or a GPON symmetric system, the target value of the superframe counter sent by the MFU is received through a PLOAM message, wherein the step of receiving the target value of the superframe counter sent by the MFU includes: receiving an Encrypted_Port_ID message sent by the MFU; and determining the target value of the superframe counter according to the Encrypted_Port_ID message.
[0166] In some embodiments, the encryption enable information carries an encryption enable flag in the following manner, including: carrying the encryption enable flag through a designated bit of the PTI field in the encryption enable information, wherein the designated bit value is a first designated value indicating that encryption is not enabled, the designated bit value is a second designated value indicating that only uplink encryption is enabled, the designated bit value is a third designated value indicating that only downlink encryption is enabled, and the designated bit value is a fourth designated value indicating that uplink and downlink encryption are enabled.
[0167] In some embodiments, the MFU and all the SFUs use the synchronized superframe counter, the superframe counter includes an intra-frame counter and an inter-frame counter, the superframe counter has a width of 46 bits, wherein the lower 16 bits are the intra-frame counter and the upper 30 bits are the inter-frame counter, for the uplink encryption, the intra-frame counter is set to 0 at the beginning of the uplink frame and increments every 4 bytes, the inter-frame counter is included in the GTC Header field of the downlink GTC frame, and the GTC Header field specifies the uplink GTC burst for transmitting the uplink GEM frame.
[0168] The service encryption method for a passive optical network system provided in an embodiment of the present invention utilizes the same or similar technical features as those in the aforementioned embodiment, enabling PON systems to support multiple encryption algorithms and dynamically switch between them. Compared to the prior art, the service encryption method for a passive optical network system provided in an embodiment of the present invention achieves the same beneficial effects as those of the service encryption method for a passive optical network system provided in the aforementioned embodiment. Other technical features of the service encryption method for a passive optical network system are the same as those disclosed in the first embodiment above and are not further detailed here.
[0169] FIG3 shows a block diagram of an electronic device 1800 according to an exemplary embodiment of the present application. The electronic device 1800 includes a central processing unit (CPU) 1801, a system memory 1804 including a random access memory (RAM) 1802 and a read-only memory (ROM) 1803, and a system bus 1805 connecting the system memory 1804 and the CPU 1801. The electronic device 1800 also includes a storage device 1806 for storing an operating system 1809, a client 1810, and other program modules 1811.
[0170] Without loss of generality, the computer-readable medium may include computer storage media and communication media. Computer storage media include volatile and non-volatile, removable and non-removable media implemented by any method or technology for storing information such as computer-readable instructions, data structures, program modules or other data. Computer storage media include RAM, ROM, Erasable Programmable Read Only Memory (EPROM), Electronically Erasable Programmable Read-Only Memory (EEPROM), flash memory or other solid-state storage technologies, CD-ROM, Digital Versatile Disc (DVD) or other optical storage, tape cassettes, magnetic tape, disk storage or other magnetic storage devices. Of course, those skilled in the art will appreciate that the computer storage media are not limited to the above-mentioned ones. The above-mentioned system memory 1804 and storage device 1806 can be collectively referred to as memory.
[0171] According to various embodiments of the present disclosure, the electronic device 1800 may also be connected to a remote computer on a network via a network such as the Internet. That is, the electronic device 1800 may be connected to a network 1808 via a network interface unit 1807 connected to the system bus 1805, or the network interface unit 1807 may be used to connect to other types of networks or remote computer systems (not shown).
[0172] The memory also includes at least one instruction, at least one program, code set or instruction set, and the at least one instruction, at least one program, code set or instruction set is stored in the memory. The central processing unit 1801 implements all or part of the steps in the service encryption method of the passive optical network system shown in the above-mentioned embodiments by executing the at least one instruction, at least one program, code set or instruction set.
[0173] In an exemplary embodiment, a computer-readable storage medium is further provided, wherein the computer-readable storage medium stores at least one computer program, which is loaded and executed by a processor to implement all or part of the steps in the above-mentioned service encryption method for a passive optical network system, or to implement all or part of the steps in the above-mentioned service encryption method for a passive optical network system. For example, the computer-readable storage medium can be a read-only memory (ROM), a random access memory (RAM), a compact disc read-only memory (CD-ROM), a magnetic tape, a floppy disk, an optical data storage device, or the like.
[0174] In an exemplary embodiment, a computer program product is also provided, which includes at least one computer program, which is loaded by a processor and executes all or part of the steps in the service encryption method of the above-mentioned passive optical network system shown in any of the above-mentioned embodiments, or all or part of the steps in the service encryption method of the above-mentioned passive optical network system.
[0175] Those skilled in the art will readily appreciate other embodiments of the present application after considering the specification and practicing the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present application that follow the general principles of the present application and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered merely as exemplary, and the true scope and spirit of the present application are indicated by the claims.
[0176] It should be understood that the present application is not limited to the exact structure described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present application is limited only by the appended claims.
Claims
1. A service encryption method for a passive optical network system, which is applied to an optical line terminal OLT and includes: Sending encryption enable information to an optical network unit ONU, where the encryption enable information is used to indicate that encryption is not enabled currently, only upstream encryption is enabled, only downstream encryption is enabled, or both upstream and downstream encryption are enabled; After enabling both upstream and downstream encryption or upstream encryption, dynamically switching the encryption algorithm negotiated between the OLT and the ONU through an OMCI entity ONU2-G; Performing key synchronization with the ONU according to the dynamically switched encryption algorithm; After key synchronization, determining to start using a new key or a new encryption algorithm from a specified frame according to the target value of the superframe counter or the Key Index, and sending the target value of the superframe counter or the Key Index to the ONU.
2. The service encryption method according to claim 1, wherein, In the case where the passive optical network system is a GPON asymmetric system or a GPON symmetric system, in the upstream direction, the bursts of the GTC framing sublayer are divided into multiple 4-byte data blocks, and each of the data blocks is sequentially numbered from S to (S + X); where S = |_target StartTime / m_|, the target StartTime is the first allocated StartTime of the burst of the DLL framing sublayer, StartTime is used to indicate the start time of the bandwidth allocation time slot, X is the number of the data blocks minus one, and m is a preset value for the upstream data transmission rate. Specifically, for 1.25G upstream, m = 4, and for 2.5G upstream, m = 2; The superframe counter includes an intra-frame counter and an inter-frame counter, where the value of the intra-frame counter includes all FEC check bytes.
3. The service encryption method according to claim 1, wherein, Determining to start using a new key or a new encryption algorithm from a specified frame according to the target value of the superframe counter or the Key Index includes: In the case where the passive optical network system is a GPON asymmetric system or a GPON symmetric system, starting to use a new key or a new encryption algorithm from a specified frame according to the target value of the superframe counter; In the case where the passive optical network system is an XGPON or XGSPON system, starting to use a new key or a new encryption algorithm from a specified frame according to the change of the Key Index.
4. The service encryption method according to claim 1, wherein, The step of performing key synchronization with the ONU according to the dynamically switched encryption algorithm includes: Instructing the ONU to generate a new key according to the dynamically switched encryption algorithm; After receiving the new key reported by the ONU, specifying the key switching time when the new key starts to take effect, and notifying the ONU of the key switching time; After receiving the response from the ONU indicating that it has received the key switching time, setting the new key into the register of the currently used key at the key switching time.
5. The service encryption method according to claim 4, wherein, The method further includes: Instructing the ONU to generate a new key by sending a key request message Request_Key message; Notifying the ONU of the key switching time by sending a key switching time message Key_Switching_Time message.
6. The service encryption method according to claim 5, wherein, In the case where the passive optical network system is a GPON asymmetric system or a GPON symmetric system, the target value of the superframe counter is sent to the ONU through PLOAM messages, where the step of sending the target value of the superframe counter to the ONU includes: Sending an Encrypted_Port_ID message to the ONU, where the Encrypted_Port_ID message carries the target value of the superframe counter.
7. The service encryption method according to any one of claims 1 to 6, wherein, The encryption enable information carries an encryption enable identifier in the following manner, including: Carrying the encryption enable identifier through a specified bit in the PTI field in the encryption enable information, where the specified bit taking the value of the first specified value indicates that encryption is not enabled, the specified bit taking the value of the second specified value indicates that only upstream encryption is enabled, the specified bit taking the value of the third specified value indicates that only downstream encryption is enabled, and the specified bit taking the value of the fourth specified value indicates that both upstream and downstream encryption are enabled.
8. The service encryption method according to claim 1, wherein, Both the OLT and all the ONUs use the synchronized superframe counter, the superframe counter includes an intra-frame counter and an inter-frame counter, the width of the superframe counter is 46 bits, where the lower 16 bits are the intra-frame counter and the higher 30 bits are the inter-frame counter. For the upstream encryption, the intra-frame counter is set to 0 at the start of the upstream frame and increments by every 4 bytes, and the inter-frame counter is included in the GTC Header field of the downstream GTC frame, and the GTC Header field specifies the upstream GTC burst for transmitting the upstream GEM frame.
9. A service encryption method for a passive optical network system, the service encryption method is applied to an optical network unit ONU, including: Receiving encryption enable information sent by an optical line terminal OLT, where the encryption enable information is used to indicate that currently encryption is not enabled, only upstream encryption is enabled, only downstream encryption is enabled, or both upstream and downstream encryption are enabled; After enabling both upstream and downstream encryption or upstream encryption, dynamically switching the encryption algorithm negotiated by the OLT and the ONU through the OMCI entity ONU2-G; Performing key synchronization with the OLT according to the dynamically switched encryption algorithm; After key synchronization, receiving the target value of the superframe counter or the Key Index sent by the OLT, and determining to use a new key or a new encryption algorithm starting from a specified frame according to the target value of the superframe counter or the Key Index.
10. A service encryption method for a passive optical network system, the service encryption method is applied to an FTTR master device MFU, including: Sending encryption enable information to an FTTR slave device SFU, where the encryption enable information is used to indicate that currently encryption is not enabled, only upstream encryption is enabled, only downstream encryption is enabled, or both upstream and downstream encryption are enabled; After enabling both upstream and downstream encryption or upstream encryption, dynamically switching the encryption algorithm negotiated by the MFU and the SFU through the OMCI entity ONU2-G; Perform key synchronization with the SFU according to the dynamically switched encryption algorithm; After key synchronization, determine to use a new key or a new encryption algorithm starting from a specified frame according to the target value of the superframe counter or the Key Index, and send the target value of the superframe counter or the Key Index to the SFU.
11. A service encryption method for a passive optical network system, the service encryption method is applied to an FTTR slave device SFU, and includes: Receive encryption enable information sent by an FTTR master device MFU, where the encryption enable information is used to indicate that encryption is not enabled currently, only uplink encryption is enabled, only downlink encryption is enabled, or both uplink and downlink encryption are enabled; After enabling both uplink and downlink encryption or uplink encryption, dynamically switch the encryption algorithm negotiated by the MFU and the SFU through the OMCI entity ONU2-G; Perform key synchronization with the MFU according to the dynamically switched encryption algorithm; After key synchronization, receive the target value of the superframe counter or the Key Index sent by the MFU, and determine to use a new key or a new encryption algorithm starting from a specified frame according to the target value of the superframe counter or the Key Index.
12. An electronic device, comprising: A memory, a processor, and a service encryption program for a passive optical network system stored on the memory and executable on the processor, where when the service encryption program for the passive optical network system is executed by the processor, it implements the service encryption method for the passive optical network system according to any one of claims 1 to 11.
13. A storage medium, the storage medium is a computer-readable storage medium, and a service encryption program for a passive optical network system is stored on the computer-readable storage medium, where when the service encryption program for the passive optical network system is executed by a processor, it implements the service encryption method for the passive optical network system according to any one of claims 1 to 11.
Citation Information
Patent Citations
Protection method for Gigabit passive optical network encryption service
CN101197663A
Method and device for improving safety of EPON system
CN102104478A
Method, device and system of avoiding gigabit passive optical network (GPON) system encryption enabling instant packet loss
CN103138918A
Encryption / decryption seamless switch achieving method, OLT and ONU in GPON system
CN103516515A
Service encryption method of passive optical network system, electronic equipment and storage medium
CN117579182A