Authentication method, authentication device, and storage medium

By comparing the first data of the device to be authenticated with its historical data in the optical network, the activation of devices with duplicate data is terminated, thus solving the problem of non-unique authentication caused by duplicate serial numbers in the optical network and realizing the uniqueness and legitimacy of the device authentication.

WO2025241574A1PCT designated stage Publication Date: 2025-11-27ZTE CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/073196
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-05-21
Filing Date
2025-01-20
Publication Date
2025-11-27

AI Technical Summary

Technical Problem

In existing technologies, when the serial numbers of devices to be authenticated in an optical network are duplicated, there is a lack of an effective authentication mechanism, resulting in non-unique device authentication and an inability to distinguish between legitimate and illegitimate devices.

Method used

By obtaining the first data report message from the device to be authenticated and comparing it with the second data from historical devices, if a duplicate is found, the activation process of the current device is terminated to ensure the uniqueness of the device data.

Benefits of technology

It achieves accurate authentication of devices to be authenticated, prevents activation of devices with duplicate serial numbers, and ensures the uniqueness and legitimacy of devices in the optical network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025073196_27112025_PF_FP_ABST
    Figure CN2025073196_27112025_PF_FP_ABST
Patent Text Reader

Abstract

The present application provides an authentication method, an authentication device, and a storage medium. The authentication method comprises: acquiring a first data reporting message, wherein the first data reporting message comprises first data, the first data is data required for authentication of a corresponding current device to be authenticated before a working stage, and the current device to be authenticated comprises a current device to be authenticated in an optical network (S110); and in response to determining that the detected first data is the same as previously obtained second data, terminating the activation of the current device to be authenticated, wherein the second data is data required for authentication of a historical device to be authenticated (S120).
Need to check novelty before this filing date? Find Prior Art

Description

Authentication method, authentication device and storage medium TECHNICAL FIELD

[0001] The present application relates to the technical field of communication, for example, to an authentication method, an authentication device and a storage medium. BACKGROUND

[0002] An optical network refers to a communication network with optical fibers as the main transmission medium. In the optical network, the characteristics of light transmission in the optical fiber are utilized to realize high-speed and large-capacity data transmission. Through a series of optical devices and equipment, such as an optical line terminal (OLT), an optical network unit (ONU), etc., a complete network architecture is constructed, which can provide high-quality communication services for users.

[0003] The first data required for the authentication of the to-be-authenticated device in the optical network, such as a serial number, needs to have uniqueness. However, there is currently no authentication method for the to-be-authenticated device using the same first data. SUMMARY

[0004] The present application provides an authentication method, an authentication device and a storage medium.

[0005] In a first aspect, an embodiment of the present application provides an authentication method, comprising:

[0006] obtaining a first data reporting message, wherein the first data reporting message comprises first data, the first data is data required for authentication of a current to-be-authenticated device before a working phase, and the current to-be-authenticated device comprises a device to be authenticated in an optical network at present;

[0007] in response to determining that the detected first data is the same as previously obtained second data, terminating activation of the current to-be-authenticated device, wherein the second data is data required for authentication of a historical to-be-authenticated device.

[0008] In a second aspect, an embodiment of the present application provides an authentication device, comprising:

[0009] one or more processors;

[0010] a storage device configured to store one or more programs;

[0011] When the one or more programs are executed by the one or more processors, the one or more processors implement the method provided by the embodiments of the present application.

[0012] In a third aspect, an embodiment of the present application provides a storage medium, which stores a computer program. When the computer program is executed by a processor, the method provided by the embodiments of the present application is implemented.

[0013] Further description is provided in the description of the drawings, the detailed description and the claims regarding the above embodiments and other aspects of the present application and implementation thereof. BRIEF DESCRIPTION OF DRAWINGS

[0014] FIG. 1 is a flow diagram of an authentication method according to an embodiment of the present application;

[0015] FIG. 2 is a structural diagram of an authentication system according to an embodiment of the present application;

[0016] FIG. 3 is a flow diagram of another authentication method according to an embodiment of the present application;

[0017] FIG. 4 is a flow diagram of still another authentication method according to an embodiment of the present application;

[0018] FIG. 5 is a structural diagram of an authentication device according to an embodiment of the present application;

[0019] FIG. 6 is a structural diagram of an authentication apparatus according to an embodiment of the present application. DETAILED DESCRIPTION

[0020] The steps shown in the flowcharts of the drawings can be executed in a computer system such as a set of computer-executable instructions. Also, although a logical order is shown in the flowcharts, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0021] The terms "first", "second", and the like in the present application are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence.

[0022] Passive optical network (PON) uses a serial number (SN) method for authentication, and the standard specifies that the SN of an optical network user equipment, also referred to as an authentication device, needs to be unique under an optical distribution network (ODN). The optical network user equipment can be an optical network unit (ONU) of a PON system, or a sub fiber unit (SFU) of a fiber to the room (FTTR) system using G.fin technology. Currently, there is no provision for the optical line terminal (OLT) on how to handle the case when the SN of the connected ONU is the same, and there is also no provision for the main fiber unit (MFU) of the FTTR on how to handle the case when the connected SFU is the same.

[0023] In the PON technology, the ONU is initially authenticated by the SN, and a unique identifier ONU-ID (Optical Network Unit Identifier) is assigned to the device by the SN, and the ONU-ID is used for subsequent management control messages such as test messages. The ONU-ID can be a code or a mark for uniquely identifying the ONU.

[0024] In the G.FIN technology, the SFU is also initially authenticated by the SN, and a unique identifier SFU-ID (Sub Fiber Unit Identifier) is assigned to the device by the SN, and the SFU-ID is used for subsequent management control messages such as test messages. The SFU-ID can be a code or a mark for uniquely identifying the SFU.

[0025] To solve the technical problem of how to authenticate the to-be-authenticated device when the data for authentication of the to-be-authenticated device is repeated, such as the SN, the application provides an authentication method. The repeated data for authentication can be considered as the same data for authentication corresponding to multiple to-be-authenticated devices.

[0026] In an example embodiment, FIG. 1 is a flowchart of an authentication method provided by an embodiment of the application. The authentication method can be applied to the case of authenticating a to-be-authenticated device, such as the case of authenticating a to-be-authenticated device using the same first data. The authentication method can be executed by an authentication device, which can be integrated in an authentication device. The authentication device can be considered as a device for authenticating a to-be-authenticated device. The to-be-authenticated device can be considered as a device to be authenticated, such as a device to be identified and / or verified.

[0027] FIG. 2 is a structural diagram of an authentication system provided by an embodiment of the application, which includes an authentication device 1 and multiple to-be-authenticated devices 2. The authentication device 1 and the to-be-authenticated devices 2 have a corresponding relationship. In an embodiment, the to-be-authenticated devices 2 are ONUs, and the authentication device 1 is an OLT. In an embodiment, the to-be-authenticated devices 2 are SFUs, and the authentication device 1 is an MFU. The authentication device 1 can authenticate the to-be-authenticated devices 2. In the case that the data required for authentication of at least two to-be-authenticated devices 2, such as the SN, is repeated, the authentication device 1 can authenticate the to-be-authenticated devices 2 by executing the authentication method provided by the application.

[0028] The authentication device 1 can allow the to-be-authenticated devices 2 with the same first data to be activated, or can not allow the to-be-authenticated devices 2 with the same first data to be activated.

[0029] The application provides an authentication method of a to-be-authenticated device, which realizes the authentication of the to-be-authenticated device under the condition of repeated first data. The embodiment takes the case that the authentication device does not allow the to-be-authenticated device with the same first data to be activated as an example. As shown in FIG. 1, the authentication method provided by the application includes the following operations:

[0030] S110, obtaining a first data reporting message.

[0031] The first data reporting message can be regarded as a message for reporting the first data. For example, a message for reporting the first data by the to-be-authenticated device to the authentication device. The first data reporting message includes the first data, and the first data is the data required for the current to-be-authenticated device to be authenticated before the working stage. The current to-be-authenticated device includes a device to be authenticated in an optical network. The current to-be-authenticated device can be an SFU or an ONU. The current to-be-authenticated device corresponding to the first data can be the to-be-authenticated device that sends the first data reporting message containing the first data, and the to-be-authenticated device is currently authenticated by the authentication device.

[0032] During the operation of the to-be-authenticated device, the to-be-authenticated device can work in multiple stages, such as an initial stage (O1), a serial number stage (O2, O3), a ranging stage (O4), and a working stage (O5). Among them, the initial stage (O1) is a preparation stage when the device starts to start; in the serial number stage (O2, O3), the confirmation and processing of the device serial number and other related information are mainly performed to ensure the uniqueness and legality of the device; in the ranging stage (O4), the distance and other parameters are measured to prepare for the subsequent accurate operation; in the working stage (O5), the device enters the formal working state and performs various data transmission and functional operations. This series of stages jointly constitute the complete process and different states of the device from starting to normal operation in the optical network.

[0033] The data required for the to-be-authenticated device to be authenticated before the working stage can be understood as the data required for the to-be-authenticated device to be authenticated before the working stage. The data required for the to-be-authenticated device to be authenticated before the working stage can include the data required for the to-be-authenticated device to be authenticated in the serial number stage and / or the ranging stage. The first data corresponding to different stages can be different, which is not limited here.

[0034] When the current to-be-authenticated device is authenticated, the first data reporting message is transmitted to the authentication device. The authentication device obtains the first data reporting message.

[0035] In one embodiment, the first data comprises one or more of: a serial number, device identification information. The device identification information can be information unique to the device. In the case of the device to be authenticated being an ONU, the device identification information can be an ONU-ID. In the case of the device to be authenticated being an SFU, the device identification information can be an SFU-ID.

[0036] S120, in the case of detecting that the first data is the same as the second data obtained previously, terminating the activation of the current device to be authenticated.

[0037] The second data is data required for authentication of a historical device to be authenticated. The historical device to be authenticated can be a device to be authenticated authenticated prior to the current device to be authenticated. The second data can be data used to authenticate the historical device to be authenticated. In the present application, the first data and the second data can be data transmitted by different devices to be authenticated of the same type. For example, the second data can be a SN transmitted by a historical device to be authenticated. The first data can be a SN transmitted by the current device to be authenticated. For another example, the second data can be device identification information transmitted by a historical device to be authenticated. The first data can be device identification information transmitted by the current device to be authenticated. The first and the second can be used to distinguish data corresponding to different devices to be authenticated.

[0038] In one embodiment, the authentication device obtains a first data reporting message transmitted by the current device to be authenticated, and detects whether the authentication device has obtained second data identical to the first data in the first data reporting message prior to obtaining the first data.

[0039] In the case of detecting that the first data is identical to the second data obtained prior to obtaining the first data, the activation of the current device to be authenticated is terminated, so as to ensure the uniqueness of the first data. The termination of the activation of the current device to be authenticated can be considered as stopping or ending the activation process of the current device to be authenticated.

[0040] In the case of not detecting data identical to the first data from the second data obtained prior to obtaining the first data, a subsequent operation can be performed on the current device to be authenticated. The subsequent operation is not limited herein and can be an operation required to be performed after the stage corresponding to the first data. For example, in the case of the first data being data transmitted in a serial number stage, the current device to be authenticated can be allocated device identification information in the case of determining that there is no duplicate first data.

[0041] In one embodiment, in the case of the authentication device not allowing activation of an ONU with the same SN, the same SN is detected in the activation process (i.e. detecting that the SN is identical to the SN obtained previously), and the activation of the ONU for this SN is terminated, i.e. the activation of the current device to be authenticated is terminated.

[0042] In one embodiment, when the authentication device does not allow the activation of the SFU with the same SN, the same SN is detected during the activation process, and the activation of the SFU for this SN will be terminated.

[0043] The application provides an authentication method. When an authentication device authenticates a current to-be-authenticated device, the authentication device determines whether there is repeated data based on first data of the current to-be-authenticated device, i.e., whether the first data is the same as second data obtained previously. Based on the determination result, it is determined whether to terminate the activation of the current to-be-authenticated device. In the case of terminating the activation process of the current to-be-authenticated device, it is considered that the authentication of the current to-be-authenticated device fails. The authentication of the to-be-authenticated device using the same first data is implemented.

[0044] Based on the above embodiment, a variant embodiment of the above embodiment is provided. It should be noted that, in order to make the description brief, only the differences from the above embodiment are described in the variant embodiment.

[0045] In one embodiment, the first data includes a serial number.

[0046] The first data can be a SN transmitted by the current to-be-authenticated device in a serial number phase, or a SN obtained by a historical to-be-authenticated device in a working phase.

[0047] In one embodiment, the first data reporting message is data transmitted by the current to-be-authenticated device in a serial number phase.

[0048] In this embodiment, the authentication device obtains a first data reporting message transmitted by the current to-be-authenticated device in a serial number phase, and obtains first data included in the first data reporting message, to implement the authentication of the current to-be-authenticated device in the serial number phase.

[0049] In this embodiment, the first data obtained in the serial number phase can be compared with second data obtained previously, to determine whether it is repeated, so as to determine whether to terminate the activation of the current to-be-authenticated device based on the determination result. In the case of repetition, the activation of the current to-be-authenticated device is terminated.

[0050] The second data obtained previously can be multiple. As long as there is one second data that is the same as the first data, it is considered that the first data is the same as the second data obtained previously.

[0051] When the authentication device does not allow multiple SN same to-be-authenticated devices to be activated, the authentication device terminates the activation process for the current to-be-authenticated device if the same SN report message (i.e. the first data report message) is found in the serial number stage (O2, O3) of the current to-be-authenticated device. The current to-be-authenticated device can generate an alarm and send it to the management system connected to the to-be-authenticated device. The management system can be a system for managing to-be-authenticated devices.

[0052] In an embodiment, when the authentication device is an OLT and the current to-be-authenticated device is an ONU, and the OLT does not allow multiple SN same ONUs to be activated, the OLT terminates the activation process for the ONU if the same SN report message (i.e. the first data report message) is found in the serial number stage (O2, O3) of the ONU. The ONU can generate an alarm and send it to the management system connected to the ONU. The management system can be a system for managing to-be-authenticated devices.

[0053] In an embodiment, when the authentication device is an MFU and the current to-be-authenticated device is an SFU, and the MFU does not allow multiple SN same SFUs to be activated, the MFU terminates the activation process for the SFU if the same SN report message (i.e. the first data report message) is found in the serial number stage (O2, O3) of the SFU. The SFU can generate an alarm and send it to the management system connected to the SFU. The management system can be a system for managing to-be-authenticated devices.

[0054] In an embodiment, the first data report message is data transmitted by the historical to-be-authenticated device in the working stage, and the second data corresponds to the same stage as the first data.

[0055] In this embodiment, the authentication device obtains the first data report message of the current to-be-authenticated device in the working stage of the historical to-be-authenticated device. The authentication device can detect whether the first data is the same as the previously obtained second data.

[0056] The second data corresponds to the stage of the historical to-be-authenticated device when the second data is obtained. The first data corresponds to the stage of the current to-be-authenticated device when the first data is obtained.

[0057] In an embodiment, the first data can be data (e.g. SN) transmitted by the current to-be-authenticated device in the serial number stage for authentication. The previously obtained second data can be data (e.g. SN) transmitted by the historical to-be-authenticated device in the serial number stage for authentication.

[0058] In one embodiment, the first data can be data transmitted by the current to-be-authenticated device in the ranging phase for authentication, such as device identification information. The second data acquired previously can be data transmitted by the historical to-be-authenticated device in the ranging phase for authentication, such as device identification information.

[0059] In this embodiment, the first data transmitted by the current to-be-authenticated device in the sequence number phase acquired by the working phase of the historical to-be-authenticated device can be reported. Then, the first data is compared with the second data acquired previously and required for authentication of the sequence number phase of the historical to-be-authenticated device.

[0060] In this embodiment, the first data transmitted by the current to-be-authenticated device in the ranging phase acquired by the working phase of the historical to-be-authenticated device can be reported. Then, the first data is compared with the second data acquired previously and required for authentication of the ranging phase of the historical to-be-authenticated device.

[0061] When the authentication device does not allow multiple to-be-authenticated devices with the same SN to be activated, if the authentication device finds that a new current to-be-authenticated device with the same SN is activated in the working phase (O5) of the historical to-be-authenticated device, the authentication device terminates the activation process of the new current to-be-authenticated device. The current to-be-authenticated device can generate an alarm and send the alarm to a management system.

[0062] In one embodiment, when the authentication device is an OLT, the historical to-be-authenticated device is an ONU, and the current to-be-authenticated device is an ONU, if the OLT finds that a new ONU with the same SN is activated in the working phase (O5) of the ONU, the OLT terminates the activation process of the new ONU. The OLT can generate an alarm and send the alarm to a management system.

[0063] In one embodiment, when the authentication device is an MFU, the historical to-be-authenticated device is an SFU, and the current to-be-authenticated device is an SFU, if the MFU finds that a new SFU with the same SN is activated in the working phase (O5) of the SFU, the MFU terminates the activation process of the new SFU. The MFU can generate an alarm and send the alarm to a management system.

[0064] In one embodiment, the first data includes device identification information of the current to-be-authenticated device.

[0065] The first data can be device identification information transmitted by the current to-be-authenticated device in the ranging phase.

[0066] In one embodiment, the first data reporting message is data transmitted by the current to-be-authenticated device in the ranging phase.

[0067] In the embodiment, the authentication device obtains the first data report message transmitted by the current to-be-authenticated device in the ranging stage of the current to-be-authenticated device, and obtains the first data included in the first data report message, so as to implement authentication of the current to-be-authenticated device in the ranging stage.

[0068] The embodiment can compare the first data transmitted by the current to-be-authenticated device in the ranging stage and the second data transmitted by the historical to-be-authenticated device in the ranging stage, determine whether the to-be-authenticated devices are repeated, and determine whether to terminate the activation of the current to-be-authenticated device based on the determined result.

[0069] When the authentication device does not allow multiple to-be-authenticated devices with the same SN to be activated, if the authentication device finds the same device identifier information in the ranging stage (O4) of the to-be-authenticated device, the authentication device terminates the activation process for the to-be-authenticated device, and the to-be-authenticated device can generate an alarm and send the alarm to the management system.

[0070] In an embodiment, when the authentication device is an OLT and the current to-be-authenticated device is an ONU, if the OLT finds the same ONU-ID in the ranging stage (O4) of the ONU, the OLT terminates the activation process for the ONU, and the OLT can generate an alarm and send the alarm to the management system.

[0071] In an embodiment, when the authentication device is an MFU and the current to-be-authenticated device is an SFU, if the MFU finds the same SFU-ID in the ranging stage (O4) of the SFU, the MFU terminates the activation process for the SFU, and the MFU can generate an alarm and send the alarm to the management system.

[0072] In an example, when there are at least three to-be-authenticated devices, if two to-be-authenticated devices send the first data indication message conflict, so that the authentication device does not receive the first data indication message, but the authentication device receives the first data indication message of the remaining to-be-authenticated devices. The authentication device will authenticate the to-be-authenticated devices based on the first data indication information, and broadcast the device identifier information after the authentication is passed. The device identifier information will be associated with the first data during the broadcast. Then, the to-be-authenticated devices that send the first data (including the conflicting to-be-authenticated devices) obtain the device identifier information to enter the next stage based on the device identifier information, such as the O4 stage. Therefore, multiple to-be-authenticated devices with the same device identifier information will transmit data to the authentication device. Therefore, the embodiment solves the above problems by authenticating the first data in the ranging stage, and implements the accuracy of authentication.

[0073] In an embodiment, the authentication method further comprises:

[0074] In the case that the current to-be-authenticated device is in the working stage, the current to-be-authenticated device is authenticated.

[0075] In the case that the current to-be-authenticated device fails to pass the authentication, the current to-be-authenticated device is deactivated.

[0076] In the case that the current to-be-authenticated device is in the working stage, the authentication device can further authenticate the current to-be-authenticated device, such as further authenticating the current to-be-authenticated device based on the password and / or the certificate of the current to-be-authenticated device, to ensure the legitimacy of the current to-be-authenticated device.

[0077] In the case that the current to-be-authenticated device fails to pass the authentication, the current to-be-authenticated device can be deactivated, i.e., the current to-be-authenticated device is deactivated, so that the current to-be-authenticated device in the activated state loses the activated state.

[0078] In an embodiment, the OLT can continue to further authenticate the ONU working in the working stage, and if the authentication fails, the ONU is deactivated, and the OLT can generate an alarm and send it to the management system.

[0079] In an embodiment, the MFU can continue to further authenticate the SFU working in the working stage, and if the authentication fails, the SFU is deactivated, and the MFU can generate an alarm and send it to the management system.

[0080] In the case that the authentication device allows multiple ONUs with the same SN to be activated, the third data and target identification information are included in the third data report information transmitted by the to-be-authenticated device to the authentication device. The authentication device authenticates the to-be-authenticated device according to the third data and the target identification information, and generates the device identification information of the to-be-authenticated device.

[0081] The third data can be data required for the corresponding to-be-authenticated device to pass the authentication before the working stage, such as the SN and / or the device identification information. The target identification information can be considered as data for assisting the third data to authenticate the to-be-authenticated device.

[0082] In an embodiment, when multiple ONUs with the same SN are allowed to be activated, the ONU needs to carry other identification information (i.e., target identification information) of the ONU when reporting the SN. The OLT authenticates according to the SN and the other identification information, and assigns different ONU-IDs to complete the activation process of the ONU.

[0083] In an embodiment, when multiple SFUs with the same SN are allowed to be activated, the SFU needs to carry other identification information of the SFU when reporting the SN. The MFU authenticates according to the SN and the other identification information, and assigns different SFU-IDs to complete the activation process of the SFU.

[0084] In the case that the authentication device allows the activation of the to-be-authenticated device with the same SN, the authentication device can continue to authenticate the to-be-authenticated device in the working stage after the working stage of the to-be-authenticated device, and if the authentication fails, the to-be-authenticated device in the working stage is deactivated.

[0085] When the OLT allows the activation of the ONUs with the same SN, the OLT can continue to further authenticate the ONUs in the working stage (O5) after the working stage of the ONUs, and if the authentication fails, the ONU is deactivated, and the OLT can generate an alarm and send it to the management system.

[0086] When the MFU allows the activation of the SFUs with the same SN, the MFU can continue to further authenticate the SFUs in the working stage (O5) after the working stage of the SFUs, and if the authentication fails, the SFU is deactivated, and the MFU can generate an alarm and send it to the management system.

[0087] The authentication method provided by the present application can also be regarded as an activation method of the to-be-authenticated device. The present application solves the problem of how to ensure the activation of the legal to-be-authenticated device when the SN of the to-be-authenticated device is repeated. In the case that the first data of the current to-be-authenticated device is the same as the previously obtained second data, the current to-be-authenticated device is terminated.

[0088] FIG. 3 is a flowchart of another authentication method provided by the present application. As shown in FIG. 3, when the authentication device does not support the activation of multiple ONUs with the same SN, the working process of the OLT is as follows:

[0089] 1) When the OLT sends a bandwidth allocation with a serial number request, the ONU in the serial number stage will respond to the SN reporting message (Serial_Number_ONU), i.e., the first data reporting message.

[0090] 2) If the OLT receives multiple SN reporting messages with the same SN in the time range corresponding to the bandwidth allocation with the serial number request, the OLT terminates the activation process of the ONU with the SN, and further generates an alarm and sends it to the management system.

[0091] In the present embodiment, the OLT can obtain the first data reporting message responded by the ONU in the serial number stage after the bandwidth allocation with the serial number request. In the case that the first data included in the received first data reporting message is the same as the previously obtained second data (which can be regarded as receiving multiple SN reporting messages with the same SN), the activation of the ONU sending the first data reporting message is terminated, such as the activation of the non-first ONU sending the SN.

[0092] 3) OLT if not receive multiple SN same report message in the time range of this serial number request bandwidth allocation, and receive a SN report message, OLT will continue to send the message of allocating ONU-ID, ONU will enter the ranging stage (O4).

[0093] 4) OLT sends the bandwidth allocation of ranging request when ONU is in the ranging stage, ONU will respond to the ranging request; Gigabit capable passive optical networks (GPON) ONU responds to the SN report message (Serial Number ONU), 10 Gigabit capable passive optical networks (XG PON) responds to the registration message (Registration).

[0094] 5) OLT if receive multiple ONU-ID same report message in the time range of this ranging request bandwidth allocation or receive conflict message (such as the received message can be considered as error, such as format error, also can be considered as message sent at the same time), OLT terminates the activation process of ONU for this ONU-ID, further can generate an alarm, send to the management system.

[0095] 6) OLT if only receive 1 ONU-ID same report message in this bandwidth, OLT will continue to send the message of configuring ranging time (Ranging_Time), ONU will enter the working stage (O5)

[0096] 7) can choose to continue to further authenticate the ONU entering O5, such as password or certificate authentication, if authentication fails, deactivate this ONU, further can generate an alarm, send to the management system.

[0097] As shown in Figure 3, when multiple SN same SFU activation is not supported, the working flow of MFU is as follows:

[0098] 1) when MFU sends a serial number request bandwidth allocation, SFU in the serial number stage will respond to the SN report message (Serial Number SFU), that is, the first data report message.

[0099] 2) MFU if receive multiple SN same report message in this bandwidth, MFU terminates the activation process of SFU for this SN, further can generate an alarm, send to the management system.

[0100] 3) If the MFU does not receive multiple report messages with the same SN in the time range corresponding to the bandwidth allocation with serial number request, and receives a report message with SN, the MFU continues to send the message of allocating SFU-ID, and the ONU enters the ranging stage (O4).

[0101] 4) The MFU sends the bandwidth allocation with ranging request when the SFU is in the ranging stage, and the SFU responds to the ranging request; the SFU responds to the report message with SN (Serial_Number_SFU).

[0102] 5) If the MFU receives multiple report messages with the same SFU-ID or receives a conflict message in the time range corresponding to the bandwidth allocation with ranging request, the MFU terminates the activation process of the MFU for the SFU-ID, and further generates an alarm sent to the management system.

[0103] 6) If the MFU receives only one report message with the same SFU-ID in the bandwidth, the MFU continues to send the message of configuring ranging time (Ranging_Time), and the SFU enters the working stage (O5).

[0104] 7) Further authentication, such as password or certificate authentication, can be selected for the SFU entering O5, and if the authentication fails, the SFU is deactivated, and further an alarm is generated and sent to the management system.

[0105] FIG. 4 is a flowchart of another authentication method provided by the embodiments of the application; as shown in FIG. 4, when multiple ONUs with the same SN are supported to be activated, the working process of the OLT and the ONU is as follows:

[0106] 1) When the OLT sends a bandwidth allocation with serial number request, the ONU in the stage O2-O3 responds to the report message (i.e., the third data report information) with SN (i.e., the third data) and other identification information (i.e., target identification information) (Serial_Number_ONU message needs to be redefined, for example, as shown in Table 1), the SN can be the same, but the other identification information is not the same, and the SN plus the other identification information forms the information for uniquely identifying the ONU.

[0107] 2) After the OLT authentication is successful, a corresponding ONU-ID is allocated according to the SN and other identification information. At this time, if the SN is the same and the other identification information is different, the ONU-ID will also be different. In order to prevent the same SN from being activated at the same time, the SN encrypted by using other identification information can be carried in the ONU-ID message, so as to ensure that ONUs with the same SN do not interfere with each other. The ONU receives the message and enters the ranging stage, and completes the subsequent activation process. If the authentication fails, the OLT will terminate the activation of the ONU, and the ONU cannot receive the ONU-ID allocation message, and will return to the initial stage (O1) after a period of time.

[0108] 3) It can be selected to continue to further authenticate the ONU entering O5, such as password or certificate authentication. If the authentication fails, the ONU is deactivated, and further an alarm can be generated and sent to the management system.

[0109] When multiple SFUs with the same SN are supported to be activated, the working process of the SFU is as follows:

[0110] 1) When the MFU sends a bandwidth allocation request with a serial number, the SFU in the O2-O3 stage will respond to the SN (i.e., the third data) and the reporting message of other identification information (i.e., the target identification information) (for example, using a format similar to Table 1, redefining the Serial_Number_SFU message), the SN can be the same, but the other identification information is different, which ensures that the SN and the other identification information form unique identification information of the SFU.

[0111] 2) After the MFU authentication is successful, a corresponding SFU-ID is allocated according to the SN and other identification information. At this time, if the SN is the same and the other identification information is different, the SFU-ID will also be different. In order to prevent the same SN from being activated at the same time, the SN encrypted by using other identification information can be carried in the SFU-ID message, so as to ensure that SFUs with the same SN do not interfere with each other. The SFU receives the message and enters the ranging stage, and completes the subsequent activation process. If the authentication fails, the MFU will terminate the activation of the SFU, and the SFU cannot receive the SFU-ID allocation message, and will return to the initial stage (O1) after a period of time.

[0112] 3) It can be selected to continue to further authenticate the SFU entering O5, such as password or certificate authentication. If the authentication fails, the SFU is deactivated, and further an alarm can be generated and sent to the management system.

[0113] Table 1 is a schematic table of a reporting message in a scenario supporting activation of multiple to-be-authenticated devices with the same SN provided by the embodiment of the application. Table 1 is a schematic table of a reporting message in a scenario supporting activation of multiple to-be-authenticated devices with the same SN provided by the embodiment of the application.

[0114] The present application can be applied to a distributed multi-link network device and a multi-link terminal device.

[0115] In an example embodiment, the present application also provides an authentication device which can be integrated in the authentication apparatus. FIG. 5 is a structural schematic diagram of an authentication device provided by an embodiment of the present application. As shown in FIG. 5, the authentication device comprises:

[0116] The acquisition module 510 is configured to acquire a first data reporting message, wherein the first data reporting message comprises first data, and the first data is data required for a current to-be-authenticated device in an optical network to be authenticated before a working phase; and the current to-be-authenticated device comprises a device to be authenticated in the optical network.

[0117] The termination module 520 is configured to terminate activation of the current to-be-authenticated device in a case where the first data is detected to be the same as second data obtained previously, and the second data is data required for a historical to-be-authenticated device to be authenticated.

[0118] The authentication device provided by the present embodiment is used to implement the authentication method of the present embodiment, and the implementation principle and technical effects of the authentication device provided by the present embodiment are similar to those of the authentication method of the present embodiment, which will not be described herein again.

[0119] On the basis of the above-mentioned embodiments, variant embodiments of the above-mentioned embodiments are provided, and it should be noted that, in order to make the description brief, only the differences between the variant embodiments and the above-mentioned embodiments are described.

[0120] In an example embodiment, the first data comprises a serial number.

[0121] In an example embodiment, the first data reporting message is data transmitted in a serial number phase of the current to-be-authenticated device.

[0122] In an example embodiment, the first data reporting message is data transmitted in a working phase of a historical to-be-authenticated device, and a working phase corresponding to the second data is the same as a working phase corresponding to the first data.

[0123] In an example embodiment, the first data comprises device identification information of the current to-be-authenticated device.

[0124] In an example embodiment, the first data reporting message is data transmitted in a ranging phase of the current to-be-authenticated device.

[0125] In an example embodiment, the authentication device further comprises:

[0126] The deactivation module is configured to authenticate the current to-be-authenticated device in a case where the current to-be-authenticated device is in a working phase.

[0127] deactivating the current device to be authenticated in a case where the authentication of the current device to be authenticated fails.

[0128] In an example embodiment, the present application also provides an authentication device, and FIG. 6 is a structural schematic diagram of an authentication device provided by an embodiment of the present application. As shown in FIG. 6, the authentication device provided by the present application includes one or more processors 61 and a storage device 62; the processor 61 in the authentication device can be one or more, and FIG. 6 takes one processor 61 as an example; the storage device 62 is configured to store one or more programs; the one or more programs are executed by the one or more processors 61, so that the one or more processors 61 implement the authentication method as described in the embodiments of the present application.

[0129] The authentication device further includes a communication device 63, an input device 64, and an output device 65.

[0130] The processor 61, the storage device 62, the communication device 63, the input device 64, and the output device 65 in the authentication device can be connected through a bus or other means, and FIG. 6 takes the connection through the bus as an example.

[0131] The input device 64 can be used to receive input digital or character information, and generate key signal input related to user settings and function control of the authentication device. The output device 65 can include a display device such as a display screen.

[0132] The communication device 63 can include a receiver and a transmitter. The communication device 63 is configured to perform information receiving and transmitting communication according to the control of the processor 61. The information includes but is not limited to the first data reporting message.

[0133] The storage device 62 as a kind of computer readable storage medium can be configured to store software programs, computer executable programs, and modules, such as program instructions / modules (for example, the acquisition module 510 and the termination module 520 in the authentication device) corresponding to the authentication method described in the embodiments of the present application. The storage device 62 can include a program storage area and a data storage area, wherein the program storage area can store an operating system, application programs required by at least one function; the data storage area can store data created according to the use of the authentication device, etc. In addition, the storage device 62 can include a high-speed random access memory, and can also include a non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, or other non-volatile solid-state storage device. In some examples, the storage device 62 can further include a storage device remotely arranged with respect to the processor 61, and these remote storage devices can be connected to the authentication device through a network. Examples of the above-mentioned network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.

[0134] In an example embodiment, the application further provides a storage medium storing a computer program, wherein the computer program is executed by a processor to implement any of the methods provided by the application, and the storage medium stores a computer program, wherein the computer program is executed by a processor to implement the authentication method provided by the application, and the authentication method comprises:

[0135] The data required by the to-be-authenticated device before a working phase, and the current to-be-authenticated device comprises a device to be authenticated in an optical network;

[0136] In a case where the first data is detected to be the same as the second data obtained before, the activation of the current to-be-authenticated device is terminated, and the second data is data required by a historical to-be-authenticated device for authentication.

[0137] The computer storage medium of the application can adopt any combination of one or more computer readable media. The computer readable medium can be a computer readable signal medium or a computer readable storage medium. The computer readable storage medium may, for example, be, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or component, or any combination thereof. More specific examples (non-exhaustive list) of the computer readable storage medium include: an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read only memory (ROM), an erasable programmable read only memory (EPROM), a flash memory, an optical fiber, a portable CD-ROM, an optical storage device, a magnetic storage device, or any suitable combination of the above. The computer readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device or component.

[0138] The computer readable signal medium can include a data signal carried in a baseband or as a part of a carrier wave, in which a computer readable program code is carried. Such a propagated data signal can take on many forms, including but not limited to electro-magnetic, optical, or any suitable combination thereof. The computer readable signal medium can also be any computer readable medium that is not a computer readable storage medium and that can communicate, propagate or transport a program for use by or in connection with an instruction execution system, apparatus, or device.

[0139] The program code embodied on the computer readable media can be transmitted using any appropriate medium, including but not limited to wireless, wire line, optical fiber cable, Radio Frequency (RF), and the like, or any suitable combination of the foregoing.

[0140] Computer program code for carrying out operations of the present application can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like, and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).

[0141] The specific embodiments described hereinabove are illustrative of specific embodiments of the present application and are not meant to be limiting of the scope of the application.

[0142] Those skilled in the art will appreciate that the term terminal device encompasses any suitable type of wireless user device, such as a mobile phone, a portable data processing apparatus, a portable web browser, or a vehicle-mounted mobile station.

[0143] In general, the various embodiments of the application can be implemented in hardware or special purpose circuits, software, logic or any combination thereof. For example, some aspects can be implemented in hardware, while other aspects can be implemented in

[0144] Embodiments of the application can be implemented by computer program instructions embodied on a tangible computer readable medium, such as a hard disk diskette, a compact diskette, a compact disk, a digital versatile disk, a memory stick, a flash drive, a punch card, a paper tape, an optical disk, a magnetic tape, or any other computer readable medium that can be used to carry or store desired program code in any appropriate format. The program code can be executed by one or more computer processors to implement the steps of the methods described herein.

[0145] The block diagrams of any logical flow of the present application can represent program steps or can represent interconnected logic circuits, modules, and functions, or can represent a combination of program steps and logic circuits, modules, and functions. The computer program can be stored on a memory. The memory can be of any type suitable to the local technical environment and can be implemented using any suitable data storage technology, such as, but not limited to, read only memory (ROM), random access memory (RAM), optical storage devices, and systems, digital video disc (DVD) or compact disc (CD) and the like. The computer readable media can include non-transitory storage media. The data processor can be of any type suitable to the local technical environment, and can include one or more of general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs), application specific integrated circuits (ASIC), field- programmable gate arrays (FPGAs) and processors based on multi-core processor architectures, as examples.

Claims

1. A method for authentication, comprising: obtaining a first data reporting message, the first data reporting message comprising first data, the first data being data required for authentication of a current device to be authenticated before a working phase, the current device to be authenticated comprising a device to be authenticated in an optical network; terminating activation of the current device to be authenticated in response to determining that the detected first data is the same as second data obtained previously, the second data being data required for authentication of a historical device to be authenticated.

2. The method of claim 1, wherein, The first data comprises a serial number.

3. The method of claim 2, wherein, The first data reporting message is data transmitted in a serial number phase of the current device to be authenticated.

4. The method of claim 2, wherein, The first data reporting message is data transmitted in a working phase of the historical device to be authenticated, a phase corresponding to the second data being the same as a phase corresponding to the first data.

5. The method of claim 1, wherein, The first data comprises device identification information of the current device to be authenticated.

6. The method of claim 5, wherein, The first data reporting message is data transmitted in a ranging phase of the current device to be authenticated.

7. The method of claim 1, further comprising: authenticating the current device to be authenticated in response to determining that the current device to be authenticated is in the working phase; deactivating the current device to be authenticated in response to determining that the current device to be authenticated fails in authentication.

8. An authentication device, comprising: one or more processors; a storage device configured to store one or more programs; when the one or more programs are executed by the one or more processors, the one or more processors are caused to implement the method of any one of claims 1-7.

9. The authentication device of claim 8, wherein, The authentication device is an optical network terminal or a master device in a fiber to the room scenario.

10. A storage medium, the storage medium storing a computer program, the computer program being executed by a processor to implement the method of any one of claims 1-7.

Citation Information

Patent Citations

  • Method and system of dynamically managing serial number, optical line terminal and optical network unit

    CN101990134A

  • Method and apparatus of modifying integrity protection configuration in a mobile user equipment of a wireless communications system

    US20070153793A1