Mutual Authentication Logic Registration IDs Passive Optical Network

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods in Passive Optical Networks (PON) are insecure, as they only verify the legality of Optical Network Units (ONUs)/Optical Network Terminals (ONTs) without ensuring the authenticity of the Optical Line Terminal (OLT), making user data vulnerable to leakage.

Innovation Solution

A method where ONU/ONT and OLT authenticate each other using logic registration IDs, with the ONU/ONT receiving a logic registration ID from the OLT and sending its own, ensuring mutual authentication and preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If only ONU/ONT legality is authenticated by OLT according to reported password, then authentication process is simple, but user data is vulnerable to leakage and security is compromised

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies inversion by making the ONU/ONT the active authenticator of the OLT, rather than the OLT being the sole authenticator. The ONU/ONT sends authentication requests to the OLT and verifies the OLT's responses using pre-stored authentication information, thereby inverting the traditional authentication direction and achieving mutual authentication

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent introduces authentication information (such as authentication IDs and passwords) as an intermediary element that enables mutual verification between OLT and ONU/ONT. This intermediary mechanism allows both parties to independently verify each other's identity without requiring direct trust relationships

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If mutual authentication using logic registration IDs is implemented, then user data security is improved, but authentication process complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-configuring authentication information (logic registration IDs and corresponding passwords) in both the OLT and ONU/ONT before actual authentication occurs. This pre-preparation enables rapid mutual verification during operation without requiring complex real-time computation or external verification processes

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2426866B1Method and apparatus for authentication in passive optical network and passive optical network thereof
Publication Date: 2013.09.04 HUAWEI TECH CO LTD
  • EP2426866B1 patent drawingFigure 1
  • EP2426866B1 patent drawingFigure 2
  • EP2426866B1 patent drawingFigure 3~4

AI summary

The embodiments of the present invention provide a method and an apparatus for authentication in a Passive Optical Network (PON), and a PON. The method includes: receiving, by an Optical Network Unit /Optical Network Terminal (ONU/ONT), a first negotiation message sent by an Optical Line Terminal (OLT), and authenticating the OLT according to a logic registration ID of the OLT; sending, by the ONU/ONT, a second negotiation message to the OLT, the logic registration ID of the ONU/ONT is used to enable the OLT to authenticate the ONU/ONT according to a logic registration ID of the ONU/ONT, and allocates a terminal identifier for the ONU/ONT after the authentication succeeds. In the embodiments of the present invention, the OLT and the ONU/ONT are authenticated through the logic registration IDs, thus eliminating security threats in the authentication process.