Methods, apparatuses and device for dynamic negotiation of encryption algorithm, and readable storage medium

By constructing a target sequence number message from the device in the FTTR system, including its sequence number and supported encryption algorithms, and having the master device decide and negotiate the encryption algorithm, the problem of undefined encryption algorithm negotiation between master and slave devices in the FTTR system is solved, and the negotiation of multiple encryption algorithms and the security of the service transmission channel are realized.

WO2026065841A1PCT designated stage Publication Date: 2026-04-02FIBERHOME TELECOMMUNICATION TECHNOLOGIES CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-01-06
Publication Date
2026-04-02

AI Technical Summary

Technical Problem

The negotiation process between master and slave devices in the FTTR system for various encryption algorithms is not defined, which makes it impossible to uniformly select encryption algorithms and affects system security.

Method used

By constructing a target serial number message from the device, which includes its serial number and supported encryption algorithms, the master device decides on the target encryption algorithm based on the message and negotiates the encryption algorithm through the target identifier, thus realizing the encryption algorithm negotiation between the master and slave devices.

Benefits of technology

It effectively enables the negotiation of multiple encryption algorithms between master and slave devices, ensuring the security of business transmission channels without changing the existing interaction process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025070643_02042026_PF_FP_ABST
    Figure CN2025070643_02042026_PF_FP_ABST
Patent Text Reader

Abstract

Methods, apparatuses and a device for dynamic negotiation of an encryption algorithm, and a readable storage medium, which relate to the field of PON management for FTTR gateways. A method comprises: when a slave device in a serial number state receives a serial number request message broadcast by a master device, constructing a target serial number message comprising the serial number of the slave device and encryption algorithms supported by the slave device, and sending the target serial number message to the master device, such that on the basis of the target serial number message, the master device determines a target encryption algorithm from among the encryption algorithms supported by the slave device, and constructs a target identifier assignment message on the basis of the target encryption algorithm and a target identifier assigned to the slave device; and when the target identifier assignment message sent by the master device is received, parsing the target identifier assignment message to obtain the target encryption algorithm, so as to implement encryption and decryption processing of a service transmission channel by means of the target encryption algorithm. By means of the present application, the negotiation of multiple encryption algorithms between the master and slave devices can be effectively realized, without the need for changing the existing interaction process.
Need to check novelty before this filing date? Find Prior Art

Description

Encryption algorithm dynamic negotiation method, device and equipment and readable storage medium TECHNICAL FIELD

[0001] The present application relates to FTTR (Fiber to the Room) gateway PON (Passive Optical Network) management technical field, in particular to an encryption algorithm dynamic negotiation method, device, equipment and readable storage medium. BACKGROUND

[0002] At present, FTTR adopts 1 master gateway+N slave gateway mode to realize fiber access of corridors, rooms and the like. Compared with the traditional networking mode, it has the characteristics of strong transmission capacity, higher transmission rate, longer line life and the like, and is widely used in large residential buildings, hotels, small and medium-sized enterprises and the like. In the traditional GPON (Gigabit-Capable PON) / 10GPON system, only AES128 encryption algorithm is supported to encrypt the service transmission channel gemport (GPON Encapsulation Method port). With the rise of FTTR technology and the promotion of national encryption algorithm (such as SM4 block cipher algorithm), in the FTTR system specification, CCSA (China Communications Standards Association) requires FTTR equipment to support other encryption algorithms in addition to AES128 encryption algorithm. Therefore, considering the chip, standard and industry reuse, FTTR master-slave gateway and other master-slave devices need to support multiple encryption algorithms such as AES128 and national encryption algorithm.

[0003] In related technologies, if the master-slave devices in FTTR want to support multiple encryption algorithms, not only does the PON chip need to support multiple encryption algorithms, but also the FTTR master-slave device software needs to support encryption algorithm negotiation to unify the encryption algorithm of both parties. However, the related standards do not define how to perceive the other party's capability and complete encryption algorithm negotiation between the master-slave devices, and select and specify the encryption algorithm. Therefore, how to realize the negotiation of multiple encryption algorithms between the master-slave devices in the FTTR system is a problem that needs to be solved in the FTTR system at present. SUMMARY

[0004] The present application provides an encryption algorithm dynamic negotiation method, device, equipment and readable storage medium, which can effectively realize the negotiation of multiple encryption algorithms between master-slave devices.

[0005] In a first aspect, the present application provides an encryption algorithm dynamic negotiation method, which is applied to a slave device, and the method comprises the following steps:

[0006] When the slave device in the serial number state receives the serial number request message broadcast by the master device, a target serial number message is constructed, the target serial number message including the serial number of the slave device and the encryption algorithm supported by the slave device;

[0007] The target serial number message is sent to the master device, so that the master device decides a target encryption algorithm from the encryption algorithms supported by the slave device based on the target serial number message, and constructs a target identifier allocation message according to the target encryption algorithm and a target identifier allocated to the slave device;

[0008] When receiving the target identifier allocation message sent by the master device, the target identifier allocation message is parsed to obtain the target encryption algorithm, so that the encryption and decryption processing of the service transmission channel is realized through the target encryption algorithm.

[0009] In combination with the first aspect, in an implementation manner, the constructing the target serial number message comprises:

[0010] The write operation is performed on the serial number bytes in the serial number message according to the serial number of the slave device, and the write operation is performed on the reserved bytes in the serial number message based on the encryption algorithm supported by the slave device itself, so as to generate the target serial number message;

[0011] The master device determines the type of the encryption algorithm supported by the slave device through the value of the reserved bytes in the target serial number message.

[0012] In combination with the first aspect, in an implementation manner, when the slave device is in the running state, the method further comprises:

[0013] If the target key message sent by the master device is received, the target key message is parsed to obtain the updated encryption algorithm, the target key message being generated by the master device based on the encryption algorithm expected to be used by the user;

[0014] A new key is generated according to the updated encryption algorithm, and the new key is sent to the master device, so as to realize the key update between the slave device and the master device.

[0015] In combination with the first aspect, in an implementation manner, the target key message is generated by the master device based on the encryption algorithm expected to be used by the user, comprising:

[0016] The master device determines the updated encryption algorithm based on the encryption algorithm expected to be used by the user, and performs the write operation on the reserved bytes in the key message according to the updated encryption algorithm, so as to generate the target key message;

[0017] The slave device determines the updated encryption algorithm decided by the master device through the value of the reserved bytes in the target key message.

[0018] In a second aspect, the embodiments of the present application provide a device for dynamically negotiating an encryption algorithm, comprising a slave device, the slave device being configured to:

[0019] When the slave device in the sequence number state receives a sequence number request message broadcast by the master device, a target sequence number message is constructed, the target sequence number message comprising a sequence number of the slave device and an encryption algorithm supported by the slave device;

[0020] The target sequence number message is sent to the master device, so that the master device decides a target encryption algorithm from the encryption algorithm supported by the slave device based on the target sequence number message, and constructs a target identifier allocation message according to the target encryption algorithm and a target identifier allocated to the slave device;

[0021] When the target identifier allocation message sent by the master device is received, the target encryption algorithm is obtained by parsing the target identifier allocation message, so that encryption and decryption processing of a service transmission channel is realized through the target encryption algorithm.

[0022] In combination with the second aspect, in an implementation, the slave device is specifically configured to:

[0023] The sequence number bytes in the sequence number message are written according to the sequence number of the slave device, and the reserved bytes in the sequence number message are written based on the encryption algorithm supported by the slave device itself, so as to generate the target sequence number message;

[0024] The master device determines the type of the encryption algorithm supported by the slave device through the value of the reserved bytes in the target sequence number message.

[0025] In combination with the second aspect, in an implementation, when the slave device is in the running state, the slave device is further configured to:

[0026] If the target key message sent by the master device is received, the target key message is parsed to obtain an updated encryption algorithm, the target key message being generated by the master device based on an encryption algorithm expected to be used by a user;

[0027] A new key is generated according to the updated encryption algorithm, and the new key is sent to the master device, so as to realize key updating between the slave device and the master device.

[0028] In combination with the second aspect, in an implementation, the master device is specifically configured to:

[0029] An updated encryption algorithm is determined based on an encryption algorithm expected to be used by a user, and the reserved bytes in the key message are written according to the updated encryption algorithm, so as to generate the target key message;

[0030] Wherein, the slave device determines the encryption algorithm decided by the master device through the value of the reserved byte in the target key message.

[0031] In a third aspect, the embodiments of the present application provide a dynamic encryption algorithm negotiation method, which is applied to a master device, and the method comprises the following steps:

[0032] sending a sequence number request message to the slave device in a broadcast manner;

[0033] deciding a target encryption algorithm from the encryption algorithms supported by the slave device based on a target sequence number message sent by the slave device in the sequence number state based on the sequence number request message, the target sequence number message being generated by the slave device based on its sequence number and the encryption algorithms supported by the slave device;

[0034] constructing a target identifier allocation message according to the target encryption algorithm and a target identifier allocated to the slave device, so that the slave device parses the target encryption algorithm from the target identifier allocation message and implements encryption and decryption processing of a service transmission channel based on the target encryption algorithm.

[0035] In combination with the third aspect, in an implementation manner, the step of constructing the target identifier allocation message according to the target encryption algorithm and the target identifier allocated to the slave device comprises:

[0036] performing write operation on an identifier byte in the identifier allocation message according to the target identifier allocated to the slave device, and performing write operation on a reserved byte in the identifier allocation message according to the target encryption algorithm, so as to generate the target identifier allocation message;

[0037] Wherein, the slave device determines the target encryption algorithm decided by the master device through the value of the reserved byte in the target identifier allocation message.

[0038] In combination with the third aspect, in an implementation manner, the target sequence number message is generated by the slave device based on its sequence number and the encryption algorithms supported by the slave device, which comprises:

[0039] the slave device performs write operation on a sequence number byte in the sequence number message according to its sequence number, and performs write operation on a reserved byte in the sequence number message based on the encryption algorithms supported by the slave device, so as to generate the target sequence number message;

[0040] Wherein, the master device determines the encryption algorithm type supported by the slave device through the value of the reserved byte in the target sequence number message.

[0041] In combination with the third aspect, in an implementation manner, the method further comprises:

[0042] determining the updated encryption algorithm based on the encryption algorithm expected to be used by the user, and performing a write operation on the reserved bytes in the key message according to the updated encryption algorithm to generate a target key message;

[0043] sending the target key message to the slave device, so that the slave device in the running state determines the updated encryption algorithm decided by the master device based on the value of the reserved bytes in the target key message, and generates a new key according to the updated encryption algorithm;

[0044] performing a key update based on the new key when the new key sent by the slave device is received.

[0045] In a fourth aspect, an encryption algorithm dynamic negotiation apparatus is provided, comprising a master device, which is configured to:

[0046] sending a sequence number request message to the slave device in a broadcast manner;

[0047] determining a target encryption algorithm from the encryption algorithms supported by the slave device based on a target sequence number message sent by the slave device in the sequence number state based on the sequence number request message, the target sequence number message being generated by the slave device based on its sequence number and the encryption algorithm supported by the slave device;

[0048] constructing a target identifier allocation message according to the target encryption algorithm and a target identifier allocated to the slave device, so that the slave device can obtain the target encryption algorithm by parsing the target identifier allocation message and perform encryption and decryption processing of a service transmission channel based on the target encryption algorithm.

[0049] In combination with the fourth aspect, in an implementation manner, the master device is specifically configured to:

[0050] performing a write operation on the identifier bytes in the identifier allocation message according to the target identifier allocated to the slave device, and performing a write operation on the reserved bytes in the identifier allocation message according to the target encryption algorithm to generate the target identifier allocation message;

[0051] The slave device determines the target encryption algorithm decided by the master device based on the value of the reserved bytes in the target identifier allocation message.

[0052] In combination with the fourth aspect, in an implementation manner, the slave device is specifically configured to:

[0053] performing a write operation on the sequence number bytes in the sequence number message according to its sequence number, and performing a write operation on the reserved bytes in the sequence number message based on the encryption algorithm supported by the slave device to generate the target sequence number message;

[0054] The master device determines the encryption algorithm type supported by the slave device according to the value of the reserved byte in the target sequence number message.

[0055] In combination with the fourth aspect, in an implementation, the master device is further configured to:

[0056] determine the updated encryption algorithm based on the encryption algorithm expected to be used by the user, and perform a write operation on the reserved byte in the key message according to the updated encryption algorithm to generate a target key message;

[0057] send the target key message to the slave device, so that the slave device in the running state determines the updated encryption algorithm decided by the master device according to the value of the reserved byte in the target key message, and generates a new key according to the updated encryption algorithm;

[0058] perform a key update based on the new key when the new key sent by the slave device is received.

[0059] In a fifth aspect, an embodiment of the present application provides an encryption algorithm dynamic negotiation device, which comprises a processor, a memory, and an encryption algorithm dynamic negotiation program stored in the memory and executable by the processor, wherein the encryption algorithm dynamic negotiation program, when executed by the processor, implements the steps of the encryption algorithm dynamic negotiation method as described above.

[0060] In a sixth aspect, an embodiment of the present application provides a computer readable storage medium, which stores an encryption algorithm dynamic negotiation program, wherein the encryption algorithm dynamic negotiation program, when executed by a processor, implements the steps of the encryption algorithm dynamic negotiation method as described above.

[0061] The technical scheme provided by the embodiments of the present application has at least the following beneficial effects:

[0062] The slave device in the sequence number state informs the master device of the multiple encryption algorithms supported by the slave device by constructing a target sequence number message comprising the sequence number of the slave device and the encryption algorithms supported by the slave device, so that the master device can determine a target encryption algorithm from the multiple encryption algorithms supported by the master device based on the target sequence number message, and construct a target identifier allocation message according to the target encryption algorithm, to inform the slave device of the encryption algorithm decided by the master device through the identifier allocation message, so that the slave device can learn the target encryption algorithm decided by the master device after analyzing the identifier allocation message, and use the target encryption algorithm as the result of negotiation between the two devices to perform encryption and decryption processing on the service transmission channel. Through the present application, the negotiation of multiple encryption algorithms between the master device and the slave device can be effectively implemented, and the existing interaction process does not need to be changed. BRIEF DESCRIPTION OF DRAWINGS

[0063] Figure 1 is a flowchart of a first embodiment of the encryption algorithm dynamic negotiation method of the present application;

[0064] Figure 2 is a flowchart of a second embodiment of the encryption algorithm dynamic negotiation method of the present application;

[0065] Figure 3 is a flowchart of the encryption algorithm negotiation involved in the embodiment of the present application;

[0066] Figure 4 is a flowchart of the key update involved in the embodiment of the present application;

[0067] Figure 5 is a hardware structure diagram of the encryption algorithm dynamic negotiation device involved in the embodiment of the present application. DETAILED DESCRIPTION

[0068] In order to make the person in the art better understand the present application, the technical solutions in the embodiments of the present application will be described clearly and completely below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by the person in the art without creative labor fall within the scope of protection of the present application.

[0069] In order to make the purpose, technical solutions and advantages of the present application clearer, the embodiments of the present application will be described in further detail below in conjunction with the drawings.

[0070] In a first aspect, the embodiments of the present application provide an encryption algorithm dynamic negotiation method.

[0071] In an embodiment, referring to Figure 1, Figure 1 is a flowchart of a first embodiment of the encryption algorithm dynamic negotiation method of the present application. As shown in Figure 1, the encryption algorithm dynamic negotiation method is applied to a slave device, and the method comprises the following steps:

[0072] Step S10: When the slave device in the sequence number state receives the sequence number request message broadcast by the master device, a target sequence number message is constructed, and the target sequence number message comprises the sequence number of the slave device and the encryption algorithm supported by the slave device.

[0073] It should be noted that the encryption algorithm dynamic negotiation method provided in the embodiment is applicable to the encryption algorithm dynamic negotiation between the FTTR main gateway (Main FTTR Unit, MFU) and the FTTR slave gateway (Sub FTTR Unit, SFU) in the GPON / 10GPON system, and is also applicable to the encryption algorithm dynamic negotiation between the OLT (Optical Line Terminal) and the ONU (Optical Network Unit) in the GPON / 10GPON system based on the OLT and the ONU. Therefore, the slave device in the embodiment can be the slave gateway or the ONU, and the master device can be the master gateway or the OLT. It should be understood that if the master device is the master gateway, the slave device should be the slave gateway, and if the master device is the OLT, the slave device should be the ONU. In addition, the encryption algorithm dynamic negotiation processes and principles in the above two scenarios are similar, and therefore, for the sake of simplicity, the subsequent embodiments will take the master device as the master gateway MFU and the slave device as the slave gateway SFU as an example to explain the encryption algorithm dynamic negotiation process and principle between the master device and the slave device.

[0074] It should be understood that the FTTR GPON / 10GPON system protocol stack mainly includes a physical layer (PHY) and a data link layer (DLL), and the DLL layer includes two sub-layers of a framing sub-layer and a service adaptation sub-layer. The service adaptation sub-layer is responsible for the encapsulation, multiplexing and delimitation of upper layer user services and management messages, and the framing sub-layer is responsible for the processing of PLOAM (Physical Layer OAM) messages, performance monitoring, key management, energy saving management and framing of DLL frames or DLL bursts.

[0075] In the embodiment, for the FTTR main gateway and the FTTR slave gateway of the GPON / 10GPON system, the encryption algorithm negotiation between the master gateway and the slave gateway is implemented by extending the PLOAM messages between the master gateway and the slave gateway of the GPON / 10GPON system, and the gemport channel is encrypted and decrypted based on the negotiated encryption algorithm. In the embodiment, when the PLOAM messages of the framing sub-layer are extended, the extended messages include a serial number message Serial_Number_SFU corresponding to the uplink message (i.e., the message sent by the slave gateway SFU to the master gateway MFU) and an identifier assignment message Assign_SFU-ID corresponding to the downlink message (i.e., the message sent by the master gateway MFU to the slave gateway SFU).

[0076] It should be understood that the slave gateway SFU will experience the following 7 states from power-on: O1 initial state, O2 standby state, O3 sequence number state, O4 ranging state, O5 running state, O6 POPUP state and O7 emergency stop state; the activation of the slave gateway SFU includes three stages: downlink synchronization stage, sequence number acquisition stage (i.e. SFU discovery stage) and ranging stage (optional), so the activation of the slave gateway SFU involves the O1 initial state, O2 standby state, O3 sequence number state and O4 ranging state. Among them, the encryption algorithm negotiation will be implemented in the sequence number acquisition stage (i.e. the slave gateway SFU is in the O3 sequence number state).

[0077] Specifically, the master gateway MFU will periodically broadcast a sequence number request message to the slave gateway SFU; and the sequence number message Serial_Number_SFU is used by the slave gateway SFU to respond to the sequence number request periodically broadcast by the master gateway MFU in the sequence number state, which contains the sequence number of the slave gateway SFU, so that the master gateway MFU can obtain the sequence number of the slave gateway SFU and allocate an unused identifier SFU-ID to the slave gateway SFU after receiving the Serial_Number_SFU message. Therefore, when the slave gateway SFU receives the sequence number request message broadcast by the master gateway MFU in the sequence number acquisition stage, it will respond to the sequence number request periodically broadcast by the master gateway MFU by sending the sequence number message Serial_Number_SFU, that is, by responding to the sequence number authorization to announce its own existence in the FTTR system to inform the master gateway MFU that it expects to join the FTTR network. It should be noted that the sequence number authorization is a distribution structure with the purpose of broadcasting Alloc-ID and marking the PLOAMu identification set; where Alloc-ID (Allocation Identifier) represents the allocation identifier, which is used to identify the service bearer entity as the receiver of the uplink bandwidth allocation within the slave gateway SFU; and PLOAMu represents the uplink PLOAM message.

[0078] It should be understood that when the slave gateway SFU writes its sequence number into the sequence number message Serial_Number_SFU to respond to the sequence number request broadcast by the master gateway MFU, it also needs to write the encryption algorithm supported by itself into the sequence number message Serial_Number_SFU to realize the construction of the target sequence number message; and send the target sequence number message to the master gateway MFU, so that the master gateway MFU can learn the encryption algorithm supported by the slave gateway SFU through the target sequence number message. It should be noted that the encryption algorithm supported by the slave gateway SFU includes but is not limited to AES128 encryption algorithm, national encryption SM1, SM2, SM3, SM4 and homomorphic encryption.

[0079] Further, in an embodiment, the constructing the target serial number message comprises:

[0080] writing the serial number bytes in the serial number message according to the serial number of the slave device, and writing the reserved bytes in the serial number message according to the encryption algorithm supported by the slave device itself, to generate the target serial number message;

[0081] wherein the master device determines the type of the encryption algorithm supported by the slave device according to the value of the reserved bytes in the target serial number message.

[0082] For example, in the embodiment, the slave gateway SFU reports the encryption algorithm supported by the slave gateway SFU to the master gateway MFU through the target serial number message. Specifically, after receiving the serial number authorization broadcast message sent by the master gateway MFU in the O2-O3 state, the slave gateway SFU writes its own serial number into the serial number message Serial_Number_SFU, and sends the serial number message Serial_Number_SFU to the master gateway MFU to declare its existence; meanwhile, the slave gateway SFU writes the encryption algorithm supported by the slave gateway SFU into the reserved bytes in the serial number message Serial_Number_SFU, to generate the target serial number message, i.e., the embodiment extends the use of the reserved bytes in the serial number message Serial_Number_SFU, to report the encryption algorithm currently supported by the slave gateway SFU to the master gateway MFU.

[0083] It should be noted that if the FTTR is a GPON system, the last two bit positions of the 12th byte in the serial number message Serial_Number_SFU can be preferably extended, i.e., the two extended bit positions are used to report the encryption algorithm currently supported by the slave gateway SFU, and each bit position represents one encryption algorithm, so that two encryption algorithms E1 and E2 can be extended; for example, "01" represents supporting the encryption algorithm E1, "10" represents supporting the encryption algorithm E2, "11" represents supporting the encryption algorithms E1 and E2 and the default AES128 encryption algorithm, and "00" represents supporting only the default AES128 encryption algorithm.

[0084] Table 1: Extension of Serial_Number_SFU message in GPON system

[0085] Therefore, referring to Table 1, the slave gateway SFU can set the value of the last two bit positions of the 12th byte of the serial number message Serial_Number_SFU according to the encryption algorithm supported by the slave gateway SFU, for example, if the slave gateway SFU only extends one encryption algorithm E1, the last two bit positions of the 12th byte take the value "01", if the slave gateway SFU needs to extend two encryption algorithms E1 and E2, the last two bit positions of the 12th byte take the value "11", and if no encryption algorithm extension is needed, i.e., the master gateway MFU and the slave gateway SFU use the default AES128 algorithm for encryption and decryption, the last two bit positions of the 12th byte take the value "00", and then the target serial number message is generated, so that the master gateway MFU can determine the encryption algorithm type supported by the slave gateway SFU through the value of the two bit positions of the reserved byte in the target serial number message.

[0086] If the FTTR is a 10GPON system, referring to Table 2, the 8 bit positions of any one of the 17th to 36th and 38th to 40th reserved bytes in the serial number message Serial_Number_SFU can be preferably extended, and each bit position represents one encryption algorithm, so that 8 encryption algorithms E1 to E8 can be extended, and the bit position 1 indicates that the slave gateway SFU supports the encryption algorithm, so if all the extended bit positions are set to 1, it indicates that the slave gateway SFU supports the default AES128 encryption algorithm and can also extend to support 8 encryption algorithms; for example, "0000001" indicates that the encryption algorithm E1 is supported, "00000011" indicates that the encryption algorithms E1 and E2 are supported, and so on, "11111111" indicates that the encryption algorithms E1 to E8 and the default AES128 encryption algorithm are supported, and "00000000" indicates that only the default AES128 encryption algorithm is supported.

[0087] Table 2 Serial_Number_SFU message extension in 10GPON system

[0088] Therefore, referring to Table 2, the slave gateway SFU can set the value of the 8-bit bit of the reserved byte in the serial number message Serial_Number_SFU according to the encryption algorithm supported by the slave gateway SFU; for example, if the slave gateway SFU only extends one encryption algorithm E1, the 40th byte takes the value "00000001", if the slave gateway SFU needs to extend two encryption algorithms E1 and E2, the 40th byte takes the value "00000011", and so on, if the slave gateway SFU needs to extend E1-E8, the 40th byte takes the value "11111111", and if the slave gateway SFU does not need to extend the encryption algorithm, i.e., the master gateway MFU and the slave gateway SFU use the default AES128 algorithm for encryption and decryption, the 40th byte takes the value "00000000", and then the target serial number message is generated, so that the master gateway MFU can determine the type of encryption algorithm supported by the slave gateway SFU through the value of the 8-bit bit of the reserved byte in the target serial number message.

[0089] Step S20: sending the target serial number message to the master device, so that the master device decides a target encryption algorithm from the encryption algorithms supported by the slave device based on the target serial number message, and constructs a target identifier allocation message according to the target encryption algorithm and a target identifier allocated to the slave device.

[0090] For example, in this embodiment, after the slave gateway SFU completes the construction of the target serial number message, the slave gateway SFU sends the target serial number message to the master gateway MFU, so that the master gateway MFU can learn the encryption algorithm supported by the slave gateway SFU after analyzing the target serial number message; then the master gateway MFU randomly selects one of the encryption algorithms supported by the slave gateway SFU or selects a corresponding encryption algorithm from the encryption algorithms supported by the slave gateway SFU according to a pre-specified requirement as the target encryption algorithm of the two parties; then sets the value of the reserved byte in the identifier allocation message Assign_SFU-ID according to the type of the decided target encryption algorithm, and writes the unique target identifier allocated to the slave gateway SFU into the identifier allocation message Assign_SFU-ID to generate a target identifier allocation message, and sends the target identifier allocation message to the slave gateway SFU.

[0091] Step S30: when receiving the target identifier allocation message sent by the master device, analyzing the target identifier allocation message to obtain the target encryption algorithm, so as to realize the encryption and decryption processing of the service transmission channel through the target encryption algorithm.

[0092] Exemplarily, in the embodiment, after receiving the target identifier allocation message sent by the master gateway MFU from the slave gateway SFU, the corresponding reserved byte in the target identifier allocation message is parsed to obtain the negotiated encryption algorithm (i.e., the target encryption algorithm) returned by the master gateway MFU, so that the encryption algorithm can be used for subsequent encryption and decryption of the gemport channel between the slave gateway SFU and the master gateway MFU. It can be seen that the embodiment can effectively realize negotiation of multiple encryption algorithms between the master and slave gateways, and does not need to change the existing interaction process.

[0093] Further, in an embodiment, when the slave device is in a running state, the method further comprises:

[0094] If the target key message sent by the master device is received, the target key message is parsed to obtain the updated encryption algorithm, and the target key message is generated by the master device based on the encryption algorithm expected to be used by the user;

[0095] A new key is generated according to the updated encryption algorithm, and the new key is sent to the master device to realize key update between the slave device and the master device.

[0096] Exemplarily, during the connection lifetime of the slave gateway SFU, i.e., when the slave gateway SFU is in a running state, if the user modifies the encryption mode through configuration, the embodiment changes the encryption algorithm between the master gateway MFU and the slave gateway SFU by extending the key message periodically sent by the master gateway MFU, so as to trigger the slave gateway SFU to generate a new key and send the new key to the master gateway MFU.

[0097] Specifically, when the user presets the encryption algorithm used by the gemport channel in the FTTR GPON / 10GPON system through configuration on the master gateway MFU (the encryption algorithm is the encryption algorithm expected to be used by the user), the master gateway MFU writes the encryption algorithm expected to be used by the user as the updated encryption algorithm into the key message (such as the Request_Key in the GPON system or the Key_Control message in the 10GPON system) to generate a target key message; and then sends the target key message to the slave gateway SFU, so that the slave gateway SFU can learn the updated encryption algorithm newly decided by the master gateway MFU after parsing the target key message, and generate a new key according to the updated encryption algorithm, and at the same time, reply the new key to the master gateway MFU through the message, thereby realizing key update between the slave gateway and the master gateway, so that the new encryption algorithm and the new key are used for subsequent encryption and decryption between the master and slave gateways.

[0098] It should be noted that, for the 10G PON system, the slave gateway SFU can reply the master gateway MFU with a new key through a Key_Report message; and for the GPON system, the slave gateway SFU can reply the master gateway MFU with a new key through an Encryption_Key message.

[0099] Further, in an embodiment, the target key message is generated by the master device based on the encryption algorithm expected to be used by the user, and includes:

[0100] The master device determines the updated encryption algorithm based on the encryption algorithm expected to be used by the user, and performs a write operation on the reserved byte in the key message according to the updated encryption algorithm, to generate the target key message.

[0101] The slave device determines the updated encryption algorithm decided by the master device through the value of the reserved byte in the target key message.

[0102] For example, in the embodiment, since the encryption algorithm expected to be used by the user can be the same as the encryption algorithm currently used by the system, or can be different from the encryption algorithm currently used by the system, when the master gateway MFU receives the encryption algorithm expected to be used by the user configured by the user, it needs to match the encryption algorithm expected to be used by the user with the encryption algorithm currently used by the system; if they are the same, the key update process is not triggered; if they are different, the encryption algorithm expected to be used by the user is written into the reserved byte of the key message as the updated encryption algorithm, to generate the target key message, that is, the reserved byte in the key message is extended in the embodiment, to inform the slave gateway SFU of the updated encryption algorithm of the master gateway MFU.

[0103] It should be noted that, in the GPON system, as shown in Table 3, the lower 2 bits of the 3rd byte of the key message Request_Key can be preferably extended, that is, the extended lower 2 bits are used to inform the slave gateway SFU of the updated encryption algorithm currently selected by the master gateway MFU; for example, "01" indicates that the master gateway MFU selects the encryption algorithm E1, "10" indicates that the master gateway MFU selects the encryption algorithm E2, and "00" indicates that the master gateway MFU selects the default AES128 encryption algorithm.

[0104] Table 3: Extension of Request_Key message in GPON system

[0105] Therefore, the master gateway MFU can set the value of the lower 2 bits of the 3rd byte in the key message Request_Key according to the decided updated encryption algorithm, to generate the target key message, so that the slave gateway SFU can determine the updated encryption algorithm required to be used by both sides through the value of the lower 2 bits of the reserved byte in the target key message, that is, after receiving the Request_Key message, the slave gateway SFU parses the new encryption method from the message, if the encryption algorithm is changed, a new encryption algorithm is used to generate a new key, and the master gateway MFU is replied through the Encryption Key message.

[0106] In the 10G PON system, as shown in Table 4, the lower 4 bits of the 5th byte of the key message Key_Control can be preferably extended, that is, the extended lower 4 bits are used to inform the slave gateway SFU of the currently selected updated encryption algorithm; wherein the lower 4 bits can be differentially valued according to binary to represent different encryption algorithms selected, but the actual value of the lower 4 bits and the specific correspondence between different encryption algorithms can be determined according to actual needs, which is not limited here, for example, "0001" represents that the master gateway MFU selects the encryption algorithm E1, "0010" represents that the master gateway MFU selects the encryption algorithm E2, "0011" represents that the master gateway MFU selects the encryption algorithm E3, "0100" represents that the master gateway MFU selects the encryption algorithm E4, "0101" represents that the master gateway MFU selects the encryption algorithm E5, "0110" represents that the master gateway MFU selects the encryption algorithm E6, "0111" represents that the master gateway MFU selects the encryption algorithm E7, "1000" represents that the master gateway MFU selects the encryption algorithm E8, and "0000" represents that the master gateway MFU selects the default AES128 encryption algorithm.

[0107] It should be noted that the expanded low 4 bits need to be used together with the value of byte 6 in the key message Key_Control, wherein the value of the 6th byte has the following two cases: (1) generating and sending a new key, (2) confirming an existing key; if the master gateway MFU needs to modify the existing encryption algorithm, the 6th byte value "generating and sending a new key", i.e. C=0, to require the slave gateway SFU to generate a new key according to the encryption algorithm of the expanded 5th byte, and to inform the slave gateway SFU of the new encryption algorithm through the expanded byte; and if the master gateway MFU does not need to modify the existing encryption algorithm, the 6th byte value "confirming the existing key", i.e. C=1, so that the slave gateway SFU does not need to generate a new key according to the encryption algorithm of the expanded 5th byte, but only informs the slave gateway SFU of the new encryption algorithm through the expanded byte. Therefore, after receiving the Key_Control message, the slave gateway SFU can parse the new encryption method from the message, and if the encryption algorithm changes, a new key is generated using the new encryption algorithm, and the master gateway MFU is replied through the Encryption Key message.

[0108] Table 4 Expansion of Key_Control message in 10GPON system

[0109] In a second aspect, the embodiments of the present application further provide an encryption algorithm dynamic negotiation device.

[0110] In an embodiment, the encryption algorithm dynamic negotiation device comprises a slave device, and the slave device is configured to:

[0111] When the slave device in the sequence number state receives the sequence number request message broadcast by the master device, a target sequence number message is constructed, wherein the target sequence number message comprises the sequence number of the slave device and the encryption algorithm supported by the slave device;

[0112] The target sequence number message is sent to the master device, so that the master device decides a target encryption algorithm from the encryption algorithm supported by the slave device based on the target sequence number message, and constructs a target identifier allocation message according to the target encryption algorithm and a target identifier allocated to the slave device;

[0113] When receiving the target identifier allocation message sent by the master device, the target identifier allocation message is parsed to obtain the target encryption algorithm, so as to realize encryption and decryption processing of the service transmission channel through the target encryption algorithm.

[0114] Further, in an embodiment, the slave device is specifically configured to:

[0115] write operation is performed on the sequence number bytes in the sequence number message according to the sequence number of the slave device, and a write operation is performed on the reserved bytes in the sequence number message based on the encryption algorithm supported by the slave device itself, to generate a target sequence number message;

[0116] The master device determines the type of encryption algorithm supported by the slave device through the value of the reserved bytes in the target sequence number message.

[0117] Further, in an embodiment, when the slave device is in a running state, the slave device is further configured to:

[0118] If the target key message sent by the master device is received, the target key message is parsed to obtain an updated encryption algorithm, and the target key message is generated by the master device based on an encryption algorithm expected to be used by a user;

[0119] A new key is generated according to the updated encryption algorithm, and the new key is sent to the master device to implement key updating between the slave device and the master device.

[0120] Further, in an embodiment, the master device is specifically configured to:

[0121] The updated encryption algorithm is determined based on an encryption algorithm expected to be used by a user, and a write operation is performed on the reserved bytes in the key message according to the updated encryption algorithm, to generate a target key message;

[0122] The slave device determines the updated encryption algorithm decided by the master device through the value of the reserved bytes in the target key message.

[0123] The functions of each module in the encryption algorithm dynamic negotiation device correspond to each step in the encryption algorithm dynamic negotiation method, and the functions and implementation processes will not be repeated here.

[0124] In a third aspect, the embodiments of the present application further provide another encryption algorithm dynamic negotiation method.

[0125] In an embodiment, referring to FIG. 2, FIG. 2 is a flowchart of a second embodiment of the encryption algorithm dynamic negotiation method of the present application. As shown in FIG. 2, the encryption algorithm dynamic negotiation method is applied to a master device, and the method includes the following steps:

[0126] Step N10: sending a sequence number request message to the slave device in a broadcast manner.

[0127] It should be noted that the encryption algorithm dynamic negotiation method provided by the embodiment is applicable to the encryption algorithm dynamic negotiation between the FTTR master gateway and the FTTR slave gateway of the GPON / 10GPON system, and is also applicable to the encryption algorithm dynamic negotiation between the OLT and the ONU in the GPON / 10GPON system based on the OLT and the ONU. Therefore, the slave device in the embodiment can be a slave gateway or an ONU, and the master device can be a master gateway or an OLT. However, it should be understood that if the master device is a master gateway, the slave device should be a slave gateway, and if the master device is an OLT, the slave device should be an ONU. In addition, the encryption algorithm dynamic negotiation processes and principles in the above two scenarios are similar, and therefore, for the sake of simplicity of description, the subsequent embodiments will take the master device as a master gateway MFU and the slave device as a slave gateway SFU as an example to explain the encryption algorithm dynamic negotiation process and principle between the master device and the slave device.

[0128] It should be understood that when the slave gateway SFU is in the serial number state, if the user does not configure the encryption algorithm on the master gateway MFU, the encryption algorithm negotiation process does not need to be triggered. If the user presets the encryption algorithm used by the gemport channel in the FTTR GPON / 10GPON system through configuration on the master gateway MFU, the master gateway MFU periodically sends a serial number request message to the slave gateway SFU through a broadcast message, so that the slave gateway SFU in the serial number state receives the message.

[0129] Step N20: When receiving the target serial number message sent by the slave device in the serial number state based on the serial number request message, a target encryption algorithm is decided from the encryption algorithms supported by the slave device based on the serial number message, and the target serial number message is generated by the slave device based on its serial number and the encryption algorithms supported by the slave device.

[0130] It should be understood that the serial number message Serial_Number_SFU is used by the slave gateway SFU in the serial number state to respond to the periodic broadcast of the serial number request by the master gateway MFU, and the message contains the serial number of the slave gateway SFU, so that the master gateway MFU can obtain the serial number of the slave gateway SFU and allocate an unused identifier SFU-ID to the slave gateway SFU after receiving the Serial_Number_SFU message. Therefore, when the slave gateway SFU receives the serial number request message broadcast by the master gateway MFU in the serial number acquisition stage, it responds to the periodic broadcast of the serial number request by the master gateway MFU by sending the serial number message Serial_Number_SFU, that is, by responding to the serial number authorization to announce its existence in the FTTR system, to notify the master gateway MFU that it expects to join the FTTR network.

[0131] It should be noted that when the slave gateway SFU writes its serial number into the serial number message Serial_Number_SFU in response to the serial number request broadcasted by the master gateway MFU, it also writes the encryption algorithm supported by itself into the serial number message Serial_Number_SFU to realize the construction of the target serial number message and send the target serial number message to the master gateway MFU; when the master gateway receives the target serial number message, it learns the encryption algorithm supported by the slave gateway SFU by analyzing the target serial number message; then the master gateway MFU randomly selects one of the encryption algorithms supported by the slave gateway SFU or selects a corresponding encryption algorithm from the encryption algorithms supported by the slave gateway SFU according to a pre-specified requirement as the target encryption algorithm of both parties. It should be understood that the encryption algorithms supported by the slave gateway SFU include but are not limited to the AES128 encryption algorithm, the national encryption SM1, SM2, SM3, SM4, and homomorphic encryption.

[0132] Further, in an embodiment, the target serial number message is generated by the slave device based on its serial number and the encryption algorithm supported by itself, and includes:

[0133] The slave device writes the serial number byte in the serial number message according to its serial number and writes the reserved byte in the serial number message based on the encryption algorithm supported by itself to generate the target serial number message.

[0134] The master device determines the type of the encryption algorithm supported by the slave device through the value of the reserved byte in the target serial number message.

[0135] Illustratively, in the present embodiment, the slave gateway SFU reports the encryption algorithm supported by itself to the master gateway MFU through the target serial number message. Specifically, after the slave gateway SFU receives the serial number authorization broadcast message sent by the master gateway MFU in the O2-O3 state, it writes its serial number into the serial number message Serial_Number_SFU to announce its existence to the master gateway MFU by replying the serial number message Serial_Number_SFU; at the same time, it writes the encryption algorithm supported by itself into the reserved byte in the serial number message Serial_Number_SFU to generate the target serial number message, that is, the reserved byte in the serial number message Serial_Number_SFU is extended in the present embodiment to report the encryption algorithm currently supported by the slave gateway SFU to the master gateway MFU.

[0136] It should be noted that if the FTTR is a GPON system, the last two bits of the 12th byte reserved in the serial number message Serial_Number_SFU can be preferably extended, i.e. the two extended bits are used to report the encryption algorithms currently supported by the slave gateway SFU, and each bit represents an encryption algorithm, so that two encryption algorithms E1 and E2 can be extended; for example, "01" indicates that the encryption algorithm E1 is supported, "10" indicates that the encryption algorithm E2 is supported, "11" indicates that the encryption algorithms E1, E2 and the default AES128 encryption algorithm are supported, and "00" indicates that only the default AES128 encryption algorithm is supported.

[0137] Therefore, the slave gateway SFU can set the value of the last two bits of the 12th byte in the serial number message Serial_Number_SFU according to the encryption algorithms supported by itself, for example, if the slave gateway SFU only extends one encryption algorithm E1, the last two bits of the 12th byte take the value "01", if two encryption algorithms E1 and E2 are extended, the last two bits of the 12th byte take the value "11", and if no encryption algorithm extension is required, i.e. the default AES128 algorithm is used for encryption and decryption between the master gateway MFU and the slave gateway SFU, the last two bits of the 12th byte take the value "00", and then the target serial number message is generated, so that the master gateway MFU can determine the type of encryption algorithm supported by the slave gateway SFU through the value of the two bits of the reserved byte in the target serial number message.

[0138] If the FTTR is a 10GPON system, the 8 bits of any one of the 17th to 36th and 38th to 40th bytes in the serial number message Serial_Number_SFU can be preferably extended, and each bit represents an encryption algorithm, so that 8 encryption algorithms E1 to E8 can be extended, and the bit position 1 indicates that the slave gateway SFU supports the encryption algorithm, so if all the extended bits are set to 1, it indicates that the slave gateway SFU supports the default AES128 encryption algorithm and can also support 8 encryption algorithms; for example, "0000001" indicates that the encryption algorithm E1 is supported, "00000011" indicates that the encryption algorithms E1 and E2 are supported, and so on, "11111111" indicates that the encryption algorithms E1 to E8 and the default AES128 encryption algorithm are supported, and "00000000" indicates that only the default AES128 encryption algorithm is supported.

[0139] Therefore, the slave gateway SFU can set the value of the 8 bit positions of the reserved byte in the serial number message Serial Number SFU according to the encryption algorithm supported by the slave gateway SFU; for example, if the slave gateway SFU only extends one encryption algorithm E1, the 40th byte takes the value "00000001", if two encryption algorithms E1 and E2 need to be extended, the 40th byte takes the value "00000011", and so on, if E1-E8 need to be extended, the 40th byte takes the value "11111111", and if no encryption algorithm extension is needed, i.e., the default AES128 algorithm is used for encryption and decryption between the master gateway MFU and the slave gateway SFU, the 40th byte takes the value "00000000", and then the target serial number message is generated, so that the master gateway MFU can determine the encryption algorithm type supported by the slave gateway SFU through the value of the 8 bit positions of the reserved byte in the target serial number message.

[0140] Step N30: constructing a target identifier allocation message according to the target encryption algorithm and the target identifier allocated for the slave device, so that the slave device can parse the target encryption algorithm from the target identifier allocation message and implement encryption and decryption processing of the service transmission channel based on the target encryption algorithm.

[0141] Exemplarily, in the present embodiment, the master gateway MFU sets the value of the reserved byte in the identifier allocation message Assign SFU-ID according to the target encryption algorithm type decided by the master gateway MFU, and writes the unique target identifier allocated for the slave gateway SFU into the identifier allocation message Assign SFU-ID, to generate a target identifier allocation message, and sends the target identifier allocation message to the slave gateway SFU. After receiving the target identifier allocation message sent by the master gateway MFU, the slave gateway SFU parses the corresponding reserved byte in the target identifier allocation message to obtain the negotiation encryption algorithm (i.e., the target encryption algorithm) returned by the master gateway MFU, and the target encryption algorithm will be used for encryption and decryption of the gemport channel in the future. It can be seen that the present embodiment can effectively realize negotiation of multiple encryption algorithms between the master and slave gateways, and does not need to change the existing interaction process.

[0142] In summary, in the PLOAM message interaction process of the existing master gateway MFU and slave gateway SFU of the FTTR, the encryption algorithm negotiation in the FTTR system is realized by extending the existing message, without the need to change the existing interaction process, and the support for multiple encryption algorithms of the gemport channel and dynamic negotiation of the encryption algorithm is increased, the demand for multiple key coexistence is realized, and the compatibility and flexibility of the encryption mode selection of the product are improved. In addition, the encryption algorithm negotiation and the start of the encryption function before the slave gateway is activated are used to improve the device security. At the same time, the chip of the embodiment can meet the different encryption needs of the traditional PON gateway and the FTTR gateway, can maximize the protection of investment, and reduce the chip cost.

[0143] Further, in an embodiment, the constructing a target identifier allocation message according to the target encryption algorithm and a target identifier allocated for the slave device comprises:

[0144] performing a write operation on an identifier byte in the identifier allocation message according to the target identifier allocated for the slave device, and performing a write operation on a reserved byte in the identifier allocation message according to the target encryption algorithm, to generate the target identifier allocation message;

[0145] Wherein, the slave device determines the target encryption algorithm decided by the master device through the value of the reserved byte in the target identifier allocation message.

[0146] It can be understood that the master gateway MFU discovers a newly added slave gateway SFU through the serial number of the slave gateway SFU, and allocates a unique identifier SFU-ID to the slave gateway SFU; wherein, the SFU-ID is an 8-bit or 10-bit identifier allocated to the slave gateway SFU by the master gateway MFU during activation of the slave gateway SFU using the identifier allocation message Assign_SFU-ID, which is unique in a specific optical distribution network; when the slave gateway SFU enters the initial state of the activation state machine, it will discard the previously allocated SFU-ID and all related data link layer configuration allocation. It can be seen that the identifier allocation message Assign_SFU-ID is a message triggered when the master gateway MFU discovers the serial number of a slave gateway SFU, i.e. after receiving the Serial_Number_SFU message sent by the slave gateway SFU, which will cause the master gateway MFU to allocate an unused target identifier SFU-ID to the slave gateway SFU and bind it with the serial number of the slave gateway SFU. Therefore, in the embodiment, the encryption algorithm used between the master gateway MFU and the slave gateway SFU will be confirmed by extending the identifier allocation message Assign_SFU-ID, i.e. the master gateway MFU will reply to the slave gateway SFU through the target identifier allocation message the target encryption algorithm decided by the master gateway MFU which needs to be used by both parties.

[0147] Specifically, after receiving the target sequence number message sent by the slave gateway SFU, the master gateway MFU will allocate a unique target identifier for the slave gateway SFU and write the target identifier into the identifier allocation message Assign_SFU-ID; at the same time, the target encryption algorithm decided by the master gateway MFU needs to be written into the reserved bytes in the identifier allocation message Assign_SFU-ID to generate the target identifier allocation message, that is, the reserved bytes in the identifier allocation message Assign_SFU-ID are extended to be used to inform the slave gateway SFU of the target encryption algorithm decided by the master gateway MFU for common use.

[0148] It should be noted that when the extended identifier allocation message Assign_SFU-ID is used to confirm the encryption algorithm used between the master gateway MFU and the slave gateway SFU, if the FTTR is a GPON system, the low 2 bits of the 12th byte in the extended identifier allocation message Assign_SFU-ID can be preferably used to reply to the slave gateway SFU, that is, the extended low 2 bits are used to inform the slave gateway SFU of the target encryption algorithm currently selected by the master gateway MFU; for example, "01" indicates that the master gateway MFU selects the encryption algorithm E1, "10" indicates that the master gateway MFU selects the encryption algorithm E2, and "00" indicates that the master gateway MFU selects the default AES128 encryption algorithm. Therefore, the master gateway MFU can set the value of the low 2 bits of the 12th byte in the identifier allocation message Assign_SFU-ID according to the target encryption algorithm decided by the master gateway MFU to generate the target identifier allocation message, so that the slave gateway SFU can determine the target encryption algorithm required to be commonly used by both parties through the value of the low 2 bits of the reserved byte in the target identifier allocation message.

[0149] Table 5: Extension of Assign_SFU-ID message in GPON system

[0150] If the FTTR is a 10G PON system, the low 4 bits of the 16th byte reserved in the extended identifier assignment message Assign_SFU-ID can be preferably used to reply to the slave gateway SFU, i.e., the extended low 4 bits are used to inform the slave gateway SFU of the currently selected target encryption algorithm; wherein the low 4 bits can be differently valued in binary to represent different selected encryption algorithms, but the actual values of the low 4 bits and the specific correspondence between different encryption algorithms can be determined according to actual needs, which are not limited herein. For example, "0001" represents that the master gateway MFU selects encryption algorithm E1, "0010" represents that the master gateway MFU selects encryption algorithm E2, "0011" represents that the master gateway MFU selects encryption algorithm E3, "0100" represents that the master gateway MFU selects encryption algorithm E4, "0101" represents that the master gateway MFU selects encryption algorithm E5, "0110" represents that the master gateway MFU selects encryption algorithm E6, "0111" represents that the master gateway MFU selects encryption algorithm E7, "1000" represents that the master gateway MFU supports encryption algorithm E8, and "0000" represents that the master gateway MFU selects the default AES128 encryption algorithm. Therefore, the master gateway MFU can set the value of the low 4 bits of the 16th byte in the identifier assignment message Assign_SFU-ID according to the target encryption algorithm decided, to generate a target identifier assignment message, so that the slave gateway SFU can determine the target encryption algorithm required to be used by both parties through the value of the low 4 bits of the reserved byte in the target identifier assignment message.

[0151] Table 6: Extension of Assign_SFU-ID message in 10G PON system

[0152] Further, in an embodiment, the method further comprises:

[0153] determining the updated encryption algorithm based on the encryption algorithm expected to be used by the user, and performing a write operation on the reserved byte in the key message according to the updated encryption algorithm to generate a target key message;

[0154] sending the target key message to the slave device, so that the slave device in the running state determines the updated encryption algorithm decided by the master device through the value of the reserved byte in the target key message, and generates a new key according to the updated encryption algorithm;

[0155] performing key update based on the new key when the new key sent by the slave device is received.

[0156] Exemplarily, during the slave gateway SFU connection lifetime, i.e. when the slave gateway SFU is in operation, if the user modifies the encryption mode through configuration, the embodiment will change the encryption algorithm between the master gateway MFU and the slave gateway SFU through the extended key message periodically sent by the master gateway MFU, so as to trigger the slave gateway SFU to generate a new key and send the new key to the master gateway MFU.

[0157] It should be understood that, since the encryption algorithm expected to be used by the user can be the same as or different from the encryption algorithm currently used by the system, when the master gateway MFU receives the encryption algorithm expected to be used by the user configured by the user, it needs to match the encryption algorithm currently used by the system; if the same, the key update process is not triggered; and if different, the encryption algorithm expected to be used by the user is written into the reserved byte of the key message as the updated encryption algorithm, so as to generate a target key message and send it to the slave gateway SFU, i.e. the embodiment will extend the use of the reserved byte in the key message, so as to inform the slave gateway SFU of the updated encryption algorithm decided by the master gateway MFU. After receiving the target key message, the slave gateway SFU will parse it, so as to learn the updated encryption algorithm newly decided by the master gateway MFU, and generate a new key according to the updated encryption algorithm, and at the same time, reply the new key to the master gateway MFU through a message, so as to realize the key update between the slave gateway and the master gateway, so that the new encryption algorithm and key are used for encryption and decryption between the master gateway and the slave gateway in the future.

[0158] It should be understood that, in the GPON system, referring to Table 3, the low 2 bits of the 3rd byte of the key message Request_Key can be preferably extended, i.e. the extended low 2 bits are used to inform the slave gateway SFU of the updated encryption algorithm currently selected by the slave gateway SFU; for example, “01” represents that the master gateway MFU selects the encryption algorithm E1, “10” represents that the master gateway MFU selects the encryption algorithm E2, and “00” represents that the master gateway MFU selects the default AES128 encryption algorithm.

[0159] Therefore, in the use scenario where the master gateway MFU specifies the encryption mode through configuration, if the master gateway MFU modifies the configuration to switch the encryption mode, the master gateway MFU will send a target key message to the slave gateway SFU to inform the modified encryption mode, that is, the master gateway MFU can set the value of the lower 2 bits of the 3rd byte of the key message Request_Key according to the updated encryption algorithm decided, that is, set the lower 2 bits of the 3rd byte of the key message Request_Key to the updated encryption algorithm; for example, if the master gateway MFU selects the encryption algorithm E1 as the updated encryption algorithm, the value of the lower 2 bits of the 3rd byte is "01", and the value "10" indicates that the encryption algorithm E2 is selected as the updated encryption algorithm, and the value "00" indicates that the default encryption algorithm AES128 is used, and then a target key message is generated, so that the slave gateway SFU in the running state can determine the updated encryption algorithm required to be used by both parties through the value of the lower 2 bits of the reserved byte in the target key message. Therefore, when the slave gateway SFU receives the Request_Key message, the new encryption mode will be parsed from the message, and if the encryption algorithm is changed, a new key is generated using the new encryption algorithm, and the master gateway MFU is replied through the Encryption Key message.

[0160] In the 10GPON system, the key message Key_Control is used for the master gateway MFU to instruct the slave gateway SFU to generate a new data encryption key of a specified length or to confirm the existing data encryption key; as shown in Table 4, the lower 4 bits of the 5th byte of the key message Key_Control can be preferably extended, that is, the extended lower 4 bits are used to inform the slave gateway SFU of the selected updated encryption algorithm; wherein the lower 4 bits can be differentially valued according to binary to represent different encryption algorithms selected, but the actual value of the lower 4 bits and the specific correspondence between different encryption algorithms can be determined according to actual needs, which is not limited here, for example, "0001" indicates that the master gateway MFU selects the encryption algorithm E1, "0010" indicates that the master gateway MFU selects the encryption algorithm E2, "0011" indicates that the master gateway MFU selects the encryption algorithm E3, "0100" indicates that the master gateway MFU selects the encryption algorithm E4, "0101" indicates that the master gateway MFU selects the encryption algorithm E5, "0110" indicates that the master gateway MFU selects the encryption algorithm E6, "0111" indicates that the master gateway MFU selects the encryption algorithm E7, "1000" indicates that the master gateway MFU selects the encryption algorithm E8, and "0000" indicates that the master gateway MFU selects the default AES128 encryption algorithm.

[0161] It should be noted that the expanded low 4 bits need to be used together with the value of byte 6 in the key message Key_Control, wherein the value of the 6th byte has the following two cases: (1) generating and sending a new key, (2) confirming the existing key; if the master gateway MFU needs to modify the existing encryption algorithm, the 6th byte value "generate and send a new key" is taken to require the slave gateway SFU to generate a new key according to the encryption algorithm of the expanded 5th byte, and to inform the slave gateway SFU of the new encryption algorithm through the expanded byte; and if the master gateway MFU does not need to modify the existing encryption algorithm, the 6th byte value "confirm the existing key" is taken so that the slave gateway SFU does not need to generate a new key according to the encryption algorithm of the expanded 5th byte, but only needs to inform the slave gateway SFU of the new encryption algorithm through the expanded byte.

[0162] Therefore, in the use scenario where the master gateway MFU specifies the encryption mode through configuration, if the master gateway MFU modifies the configuration and switches the encryption mode, it will send a target key message to the slave gateway SFU to inform the modified encryption mode, that is, the master gateway MFU can set the value of the low 4 bits of the 5th byte in the key message Key_Control according to the updated encryption algorithm decided, that is, set the low 4 bits of the 5th byte in the key message Key_Control to the updated encryption algorithm, and at the same time, take the 6th byte value as "generate and send a new key", and then generate a target key message; when the slave gateway SFU receives the target key message, it can parse the new encryption mode from the message, and if the encryption algorithm has changed, it uses the new encryption algorithm to generate a new key and replies to the master gateway MFU through the Encryption Key message.

[0163] The following takes the master device as the master gateway MFU and the slave device as the slave gateway SFU as an example and explains the overall flow of encryption algorithm negotiation in the FTTR GPON / 10GPON system in combination with FIG. 3.

[0164] (1) The control encryption algorithm negotiation process is carried out in the slave gateway SFU in the serial number state (i.e. O3 state); first, the user pre-sets the encryption algorithm used in the gemport channel in the FTTR GPON / 10GPON system on the master gateway MFU through configuration; it should be noted that if the user does not configure the encryption algorithm, the key negotiation process is not triggered.

[0165] (2) The master gateway MFU periodically sends a serial number request message to the slave gateway SFU through a broadcast message, so that the slave gateway SFU in the serial number state receives the message.

[0166] (3) When the Serial_Number_SFU message is received from the slave gateway SFU, the Serial_Number_SFU message is sent back to the master gateway MFU in reply; it should be noted that the Serial_Number_SFU message not only needs to carry the serial number of the slave gateway SFU, but also needs to inform the master gateway MFU of the encryption algorithm supported by the slave gateway SFU through message extension; for the specific extension method and principle of the Serial_Number_SFU message, refer to the foregoing embodiments, which will not be described here.

[0167] (4) After the master gateway MFU receives the Serial_Number_SFU sent by the slave gateway SFU, if the user has preset an encryption algorithm, the preset encryption algorithm is directly used as the target encryption algorithm, and if the user has not preset an encryption algorithm, a random encryption algorithm is selected from the encryption algorithms recorded in the Serial_Number_SFU as the target encryption algorithm; it should be noted that the encryption algorithm preset by the user is derived from the encryption algorithm supported by the slave gateway SFU, that is, the encryption algorithm supported by the slave gateway SFU necessarily covers the encryption algorithm preset by the user.

[0168] (5) After the master gateway MFU confirms the target encryption algorithm currently used, the Assign_SFU-ID message sent to the slave gateway SFU is extended to specify the target encryption algorithm as the encryption algorithm between the master gateway MFU and the slave gateway SFU, so that the slave gateway SFU can encrypt and decrypt the Gemport channel through the target encryption algorithm specified in the Assign_SFU-ID message; it should be noted that for the specific extension method and principle of the Assign_SFU-ID message, refer to the foregoing embodiments, which will not be described here.

[0169] The following takes the master device as the master gateway MFU and the slave device as the slave gateway SFU as an example and combines FIG. 4 to explain the overall flow of the key update in the FTTR GPON / 10GPON system.

[0170] (1) The control key update flow is performed when the slave gateway SFU is in a running state (i.e., O5 state); first, when the slave gateway SFU is in a connection lifetime, the user modifies the encryption algorithm on the master gateway MFU to generate an encryption algorithm expected to be used by the user.

[0171] (2) The master gateway MFU compares the encryption algorithm expected to be used by the user with the encryption algorithm currently used by the system. If they are the same, no processing is performed. If they are not the same, the master gateway MFU informs the slave gateway SFU of the encryption algorithm update. In the GPON system, the master gateway MFU informs the slave gateway SFU of the encryption algorithm update by extending the Request_Key message, i.e., the updated encryption algorithm is carried in the message. In the 10GPON system, the master gateway MFU informs the slave gateway SFU of the encryption algorithm update by extending the Key_Control message, i.e., the updated encryption algorithm is carried in the message, and the slave gateway SFU is required to generate and send a new key. It should be noted that the specific extension method and principle of the Request_Key message and the Key_Control message are described in the foregoing embodiments, and will not be described here again.

[0172] (3) After the slave gateway SFU receives the Request_Key / Key_Control message, the updated encryption algorithm is obtained therefrom, and a new key is generated based on the updated encryption algorithm, and a reply message is sent to the master gateway MFU to inform the master gateway MFU of the new key. In the GPON system, the slave gateway SFU can send the new key to the master gateway MFU through the Encryption_Key message. In the 10GPON system, the slave gateway SFU can send the new key to the master gateway MFU through the Key_Report message.

[0173] In a fourth aspect, the embodiments of the present application further provide another encryption algorithm dynamic negotiation device.

[0174] In an embodiment, the another encryption algorithm dynamic negotiation device comprises a master device, which is configured to:

[0175] send a sequence number request message to a slave device through a broadcast mode;

[0176] when receiving a target sequence number message sent by the slave device based on the sequence number request message, decide a target encryption algorithm from encryption algorithms supported by the slave device based on the sequence number message, the target sequence number message being generated by the slave device based on its sequence number and the encryption algorithm supported by the slave device;

[0177] construct a target identifier allocation message according to the target encryption algorithm and a target identifier allocated to the slave device, so that the slave device can parse the target encryption algorithm from the target identifier allocation message and implement encryption and decryption processing of a service transmission channel based on the target encryption algorithm.

[0178] Further, in an embodiment, the master device is specifically configured to:

[0179] write the identifier byte in the identifier allocation message according to the target identifier allocated to the slave device, and write the reserved byte in the identifier allocation message according to the target encryption algorithm, to generate a target identifier allocation message;

[0180] The slave device determines the target encryption algorithm decided by the master device through the value of the reserved byte in the target identifier allocation message.

[0181] Further, in an embodiment, the slave device is specifically configured to:

[0182] write the sequence number byte in the sequence number message according to the sequence number, and write the reserved byte in the sequence number message based on the encryption algorithm supported by the slave device, to generate a target sequence number message;

[0183] The master device determines the type of the encryption algorithm supported by the slave device through the value of the reserved byte in the target sequence number message.

[0184] Further, in an embodiment, the master device is further configured to:

[0185] determine the updated encryption algorithm based on the encryption algorithm expected to be used by the user, and write the reserved byte in the key message according to the updated encryption algorithm, to generate a target key message;

[0186] send the target key message to the slave device, so that the slave device in the running state determines the updated encryption algorithm decided by the master device through the value of the reserved byte in the target key message, and generates a new key according to the updated encryption algorithm;

[0187] When the new key sent by the slave device is received, the key is updated based on the new key.

[0188] Corresponding to each step in the encryption algorithm dynamic negotiation method, the functions of each module in the encryption algorithm dynamic negotiation device are not repeated here.

[0189] In a fifth aspect, an encryption algorithm dynamic negotiation device is provided in the embodiments of the present application. The encryption algorithm dynamic negotiation device can be a personal computer (PC), a notebook computer, a server, or other devices with data processing functions.

[0190] Referring to FIG. 5, FIG. 5 is a schematic diagram of the hardware structure of the encryption algorithm dynamic negotiation device involved in the embodiments of the present application. In the embodiments of the present application, the encryption algorithm dynamic negotiation device can include a processor, a memory, a communication interface, and a communication bus.

[0191] The communication bus can be any type of bus, for example, a bus for interconnecting the processor, the memory and the communication interface.

[0192] The communication interface includes an input / output (I / O) interface, a physical interface and a logical interface, etc. for realizing the interconnection of devices inside the encryption algorithm dynamic negotiation device, and an interface for realizing the interconnection of the encryption algorithm dynamic negotiation device and other devices (for example, other computing devices or user devices). The physical interface can be an Ethernet interface, a fiber interface, an ATM interface, etc.; the user device can be a display (Display), a keyboard (Keyboard), etc.

[0193] The memory can be various types of storage media, for example, random access memory (RAM), read-only memory (ROM), non-volatile RAM (NVRAM), flash memory, optical storage, hard disk, programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), etc.

[0194] The processor can be a general-purpose processor, which can invoke the encryption algorithm dynamic negotiation program stored in the memory and execute the encryption algorithm dynamic negotiation method provided by the embodiments of the present application. For example, the general-purpose processor can be a central processing unit (CPU). The method executed by the encryption algorithm dynamic negotiation program when invoked can refer to the various embodiments of the encryption algorithm dynamic negotiation method of the present application, which will not be repeated here.

[0195] Those skilled in the art can understand that the hardware structure shown in FIG. 5 does not constitute a limitation on the present application, and can include more or fewer components than those shown, or combine certain components, or different component arrangements.

[0196] In a sixth aspect, the embodiments of the present application also provide a computer readable storage medium.

[0197] The encryption algorithm dynamic negotiation program is stored on the computer readable storage medium of the present application, and when the encryption algorithm dynamic negotiation program is executed by the processor, the steps of the encryption algorithm dynamic negotiation method as described above are realized.

[0198] The method realized by the encryption algorithm dynamic negotiation program when executed can refer to the various embodiments of the encryption algorithm dynamic negotiation method of the present application, which will not be repeated here.

[0199] It should be noted that the terms "comprise", "comprising", "have", "having", "include", "including", "contain", "containing", "provide", "providing", "offer", "offering", "specify", "specifying", "carry", "carrying", "contain", "containing", "characterized by" and any variations thereof in the specification and in the claims of the application and in the above description of the drawings are intended to cover both "include" and "consist of".

[0200] In the description of the embodiments of the present application, "exemplary", "for example", "e.g." or "for instance" are used on the basis that a person of ordinary skill in the art will be able to draw more general principles from the embodiments described. Any embodiment or design described as "exemplary", "for example", "e.g." or "for instance" in the present application should not be interpreted as being more preferred or advantageous than other embodiments or designs. In fact, a person of ordinary skill in the art will be able to draw different conclusions from the embodiments described, and such conclusions do not affect the scope of the present application.

[0201] In some of the processes described in the embodiments of the present application, the order of operations or steps can be changed relative to the order described. Unless otherwise specified, elements of the processes can occur in any order. The sequence of operations or steps should not be construed as limiting the claims. Furthermore, an object or items of the processes can occur sequentially or in parallel.

[0202] The above are only the preferred embodiments of the present application, and do not limit the patent scope of the present application. Any equivalent structure or equivalent process transformation based on the content of the specification and drawings of the present application, or direct or indirect application in other related technical fields, are also included in the patent protection scope of the present application.

Claims

1. A method for dynamic negotiation of cryptographic algorithms, characterized in that, The encryption algorithm dynamic negotiation method is applied to a slave device, and the method comprises the following steps: When the slave device in the sequence number state receives a sequence number request message broadcast by a master device, a target sequence number message is constructed, the target sequence number message comprising a sequence number of the slave device and an encryption algorithm supported by the slave device; The target sequence number message is sent to the master device, so that the master device decides a target encryption algorithm from the encryption algorithm supported by the slave device based on the target sequence number message, and constructs a target identifier allocation message according to the target encryption algorithm and a target identifier allocated for the slave device; When the target identifier allocation message sent by the master device is received, the target identifier allocation message is parsed to obtain the target encryption algorithm, so that encryption and decryption processing of a service transmission channel is realized through the target encryption algorithm.

2. The cryptographic algorithm dynamic negotiation method of claim 1, wherein, The target sequence number message is constructed, comprising: sequence number bytes in the sequence number message are written according to the sequence number of the slave device, and reserved bytes in the sequence number message are written based on the encryption algorithm supported by the slave device itself, so as to generate the target sequence number message; wherein the master device determines the type of the encryption algorithm supported by the slave device through the value of the reserved bytes in the target sequence number message.

3. The cryptographic algorithm dynamic negotiation method of claim 1, wherein, When the slave device is in a running state, the method further comprises: If the target key message sent by the master device is received, the target key message is parsed to obtain an updated encryption algorithm, the target key message being generated by the master device based on an encryption algorithm expected to be used by a user; a new key is generated according to the updated encryption algorithm, and the new key is sent to the master device, so as to realize key updating between the slave device and the master device.

4. The cryptographic algorithm dynamic negotiation method of claim 3, wherein, The target key message is generated by the master device based on the encryption algorithm expected to be used by the user, comprising: The master device determines the updated encryption algorithm based on the encryption algorithm expected to be used by the user, and writes reserved bytes in the key message according to the updated encryption algorithm, so as to generate the target key message; wherein the slave device determines the updated encryption algorithm decided by the master device through the value of the reserved bytes in the target key message.

5. A cryptographic algorithm dynamic negotiation apparatus, characterized by, The slave device is used for: When the slave device in the sequence number state receives a sequence number request message broadcast by a master device, a target sequence number message is constructed, the target sequence number message comprising a sequence number of the slave device and an encryption algorithm supported by the slave device; The target sequence number message is sent to the master device, so that the master device decides a target encryption algorithm from the encryption algorithm supported by the slave device based on the target sequence number message, and constructs a target identifier allocation message according to the target encryption algorithm and a target identifier allocated for the slave device; When the target identifier allocation message sent by the master device is received, the target identifier allocation message is parsed to obtain the target encryption algorithm, so that encryption and decryption processing of a service transmission channel is realized through the target encryption algorithm.

6. A method for dynamic negotiation of encryption algorithms, characterized in that, The encryption algorithm dynamic negotiation method is applied to a master device, and the method comprises the following steps: A sequence number request message is sent to a slave device in a broadcast mode; When receiving a target sequence number message sent by the slave device based on the sequence number request message in the sequence number state, a target encryption algorithm is decided from the encryption algorithms supported by the slave device based on the sequence number message, and the target sequence number message is generated by the slave device based on its sequence number and the encryption algorithm supported by the slave device; A target identifier allocation message is constructed according to the target encryption algorithm and a target identifier allocated for the slave device, so that the slave device parses the target encryption algorithm from the target identifier allocation message and implements encryption and decryption processing of a service transmission channel based on the target encryption algorithm.

7. The cryptographic algorithm dynamic negotiation method of claim 6, wherein, The target identifier allocation message is constructed according to the target encryption algorithm and a target identifier allocated for the slave device, and includes: The identifier bytes in the identifier allocation message are written according to the target identifier allocated for the slave device, and the reserved bytes in the identifier allocation message are written according to the target encryption algorithm, so as to generate the target identifier allocation message; The target encryption algorithm decided by the master device is determined by the value of the reserved bytes in the target identifier allocation message.

8. The cryptographic algorithm dynamic negotiation method of claim 6, wherein, The target sequence number message is generated by the slave device based on its sequence number and the encryption algorithm supported by the slave device, and includes: The sequence number bytes in the sequence number message are written according to the sequence number of the slave device, and the reserved bytes in the sequence number message are written according to the encryption algorithm supported by the slave device, so as to generate the target sequence number message; The encryption algorithm type supported by the slave device is determined by the value of the reserved bytes in the target sequence number message.

9. The method of claim 6, wherein the encryption algorithm is dynamically negotiated by the first and second devices based on the encryption algorithm information. The method further includes: An updated encryption algorithm is determined based on the encryption algorithm expected to be used by the user, and the reserved bytes in the key message are written according to the updated encryption algorithm, so as to generate a target key message; The target key message is sent to the slave device, so that the updated encryption algorithm decided by the master device is determined by the value of the reserved bytes in the target key message, and a new key is generated according to the updated encryption algorithm by the slave device in the running state; When receiving the new key sent by the slave device, the key is updated based on the new key.

10. A cryptographic algorithm dynamic negotiation apparatus, characterized by, The master device includes: The sequence number request message is sent to the slave device in a broadcast manner; When receiving a target sequence number message sent by the slave device based on the sequence number request message in the sequence number state, a target encryption algorithm is decided from the encryption algorithms supported by the slave device based on the sequence number message, and the target sequence number message is generated by the slave device based on its sequence number and the encryption algorithm supported by the slave device; A target identifier allocation message is constructed according to the target encryption algorithm and a target identifier allocated for the slave device, so that the slave device parses the target encryption algorithm from the target identifier allocation message and implements encryption and decryption processing of a service transmission channel based on the target encryption algorithm.

11. An encryption algorithm dynamic negotiation device, characterized by, The encryption algorithm dynamic negotiation device comprises a processor, a memory, and an encryption algorithm dynamic negotiation program stored in the memory and executable by the processor, wherein the encryption algorithm dynamic negotiation program, when executed by the processor, implements the steps of the encryption algorithm dynamic negotiation method according to any one of claims 1 to 4 and 6 to 9.

12. A computer-readable storage medium, characterized in that, The computer readable storage medium stores an encryption algorithm dynamic negotiation program, wherein the encryption algorithm dynamic negotiation program, when executed by the processor, implements the steps of the encryption algorithm dynamic negotiation method according to any one of claims 1 to 4 and 6 to 9.

Citation Information

Patent Citations

  • Cryptographic algorithm negotiating method in PON system

    CN101064719A

  • Encryption algorithm dynamic negotiation method, apparatus and device, and readable storage medium

    CN119094127A

  • Systems and methods for remote access of network devices having private addresses

    US20070180081A1