WO2011127731A1 - 光网络单元的注册激活方法及系统 - Google Patents

光网络单元的注册激活方法及系统 Download PDF

Info

Publication number
WO2011127731A1
WO2011127731A1 PCT/CN2010/078840 CN2010078840W WO2011127731A1 WO 2011127731 A1 WO2011127731 A1 WO 2011127731A1 CN 2010078840 W CN2010078840 W CN 2010078840W WO 2011127731 A1 WO2011127731 A1 WO 2011127731A1
Authority
WO
WIPO (PCT)
Prior art keywords
onu
olt
information
registration
authentication code
Prior art date
Application number
PCT/CN2010/078840
Other languages
English (en)
French (fr)
Inventor
张伟良
张德智
袁立权
耿丹
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2011127731A1 publication Critical patent/WO2011127731A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04QSELECTING
    • H04Q11/00Selecting arrangements for multiplex systems
    • H04Q11/0001Selecting arrangements for multiplex systems using optical switching
    • H04Q11/0062Network aspects
    • H04Q11/0067Provisions for optical access or distribution networks, e.g. Gigabit Ethernet Passive Optical Network (GE-PON), ATM-based Passive Optical Network (A-PON), PON-Ring
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04QSELECTING
    • H04Q11/00Selecting arrangements for multiplex systems
    • H04Q11/0001Selecting arrangements for multiplex systems using optical switching
    • H04Q11/0062Network aspects
    • H04Q2011/0079Operation or maintenance aspects
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04QSELECTING
    • H04Q11/00Selecting arrangements for multiplex systems
    • H04Q11/0001Selecting arrangements for multiplex systems using optical switching
    • H04Q11/0062Network aspects
    • H04Q2011/0088Signalling aspects

Definitions

  • the present invention relates to a communication link or, in particular, to a registration activation method and system for an Optical Network Unit (ONU).
  • ONU Optical Network Unit
  • GPON Gigabit Passive Optical Network
  • the GPON system usually consists of an optical line terminal (OLT) on the network side, an ONU on the user side, and an optical distribution network (ODN).
  • ONT optical line terminal
  • ODN optical distribution network
  • the point-to-multipoint network structure is generally used.
  • the ODN consists of passive optical components such as single-mode fibers, optical splitters, and optical connectors that provide optical transmission media for the physical connection between the OLT and the ONU.
  • the broadcast mode is used for communication, and each ONU can receive all downlink frames, but according to the ONU identifier (ONU-ID) in the downlink frame, GPON Encapsulation Mode-Port ID (GEM-Port ID) and Allocation-ID (Llocation-ID) are used to obtain their own downstream frames.
  • ONU-ID ONU identifier
  • GEM-Port ID GPON Encapsulation Mode-Port ID
  • Llocation-ID Allocation-ID
  • the uplink frame uses Time Division Multiple Access (TDMA) technology. The technology divides the uplink channel into multiple time slots.
  • the OLT allocates uplink bandwidth to the ONU.
  • the ONU sends the uplink bandwidth to the OLT. data.
  • the OLT needs to authenticate the validity of the ONU before the ONU accesses the OLT.
  • the OLT uses the serial number (Serial Number, SN for short) based on the ONU to carry out the legality of the ONU. And refuse access to the illegal ONU.
  • Serial Number, SN Serial Number
  • the registration activation process of the ONU defined in the ITU-T G.984.3 standard is described below.
  • Figure 1 is the International Telecommunications Union-Telecommunications Standardization Sector (ITU-T) G.984.3 standard.
  • the flow chart of the ONU registration activation method is as shown in FIG. 1.
  • the ONU registration activation method includes the following steps: Step 1: When the ONU is powered on, it is in an initial state; the ONU listens to the downlink frame sent by the OLT and acquires frame synchronization, and enters a standby state. In this step, the OLT sends a downlink frame every 125 sec., when the ONU is just powered on, it cannot be synchronized with the downlink frame. Therefore, Loss of Signal/Loss of Frame (Loss of Signal/Loss of Frame) LOS/LOF) Two types of alarms; when the ONU receives the downstream frame and acquires the frame synchronization, the two alarms are cleared.
  • Step 1 When the ONU is powered on, it is in an initial state; the ONU listens to the downlink frame sent by the OLT and acquires frame synchronization, and enters a standby state. In this step, the OLT sends a downlink frame every 125 sec., when the ONU is just powered on, it cannot be synchronized
  • Step 2 The ONU in the standby state receives an Upstream_overhead parameters message sent by the OLT, or an Upstream_overhead parameters message and an Extended Burst Length message, and then uplinks according to parameters included in the message. Frame related configuration, and enter the serial number state.
  • the uplink overhead parameter message and the extended burst length message are broadcasted by the OLT in the downlink direction through the physical layer operation, management and maintenance (PLO AM) message in the downlink frame.
  • the uplink frame correlation configuration includes: the number of protection bits, the number of preamble bits, the number of delimiter bits, and the like.
  • Step 3 The ONU in the sequence number state receives the SN request (SN Request) sent by the OLT.
  • the ONU After receiving the SN request, the ONU sends its own SN to the OLT.
  • Step 4 After the SN of the ONU owed by the OLT, a unique ONU_ID is assigned and sent to the ONU, and the ONU enters the measurement state after receiving the ONU_ID.
  • Step 5 The ONU that measures the giant state receives the ranging request (Ranging Request) sent by the OLT, and the ONU sends its own serial number information to the OLT after receiving the ranging request.
  • the OLT needs to measure the equalization delay of the ONUs. After the OLT completes the measurement of the equalization delay of the ONUs, the OLT sends the equalization delay to the ONUs.
  • the ONUs successfully receive the equalization delay and enter the working state.
  • the equalization delay is calculated according to the corresponding sending time and receiving time and other parameters. Because the GPON system is a point-to-multipoint network structure, each ONU uses TDMA technology to access the OLT, and each ONU is different from the OLT. When each ONU sends data on the uplink, collision may occur, and the effect of equalization delay It is to make all ONUs logically appear to be far away from the OLT, so that the bandwidth allocation is to avoid collisions in the upstream direction. The "equalization delay" needs to be delayed when the ONU is ready to send upstream frames.
  • Step 6 The OLT compares the SN sent by the ONU with the legal SN stored in the SN library of the OLT. If the SN of the OLT includes the SN of the received ONU, the OLT determines that the ONU is a legal ONU, and the ONU registration activation succeeds. If the ONU is determined to be an illegal ONU, the OLT sends a Deactivate ONU-ID (Deactivate ONU-ID) message to the ONU, and the ONU releases the ONU-ID, and the ONU registration activation process fails.
  • Deactivate ONU-ID Deactivate ONU-ID
  • FIG. 2 is a schematic diagram of the composition of the bandwidth mapping allocation structure in the downlink physical control block of the downlink frame.
  • the downstream frame consists of two parts: PCBd and payload.
  • the PCBd consists of Physical Synchronization (Psync) or I, Ident I or Downstream PLOAM (PLOAM downstream).
  • the PLOAMd) domain the Bit Interleaved Parity (BIP) domain, the Payload Length downstream (Plend) domain, and the Upstream Bandwidth Map (US BWmap) domain, where US BWmap i or consists of N allocation structures (Allocation Structure), each allocation structure consists of Allocation ID (Alloc-ID) domain, bandwidth allocation option (Flags) domain, bandwidth start time (StartTime) domain, bandwidth end time ( StopTime) i or a Cyclic Redundancy Check (CRC) i or composition.
  • the inventor has found that in the above-mentioned ONU registration activation process, there are two cases in which the activation of the legal ONU registration fails:
  • the ONU only sends the SN to the OLT, so that it can determine whether the ONU is legal through the SN. If an ONU's SN is not pre-stored in the OLT's SN library, then this ONU cannot be registered.
  • the ONU is a user equipment, and the user can purchase and replace it.
  • the SN of the ONU is not pre-stored in the SN library of the OLT. In this case, it is not credible. Then, such an ONU cannot be successfully registered and activated.
  • the provision of services for such an ONU requires the support of the operator, which not only causes trouble for the user, but also increases the operating cost for the operator.
  • the malicious ONU can listen to the Assign_ONU-ID message sent by the OLT to the legal ONU, and the message includes the SN information of the legal ONU and the ONU-ID information allocated by the OLT to the ONU.
  • the malicious ONU may allocate the monitored SN information and the OLT to the
  • the ONU-ID information of the ONU is sent to the OLT, and the legal ONU also has its own SN information and The ONU-ID information that is allocated by the OLT to the ONU is sent to the OLT. If the information sent by the malicious ONU reaches the OLT first, the equalization delay value assigned by the OLT to the legal ONU is greater than the equalization that the legal ONU should obtain. The delay value, the uplink data sent by the legal ONU after entering the working state conflicts with the uplink data sent by other legal ONUs. If the information sent by the malicious ONU and the legal ONU arrives at the OLT at the same time, the OLT cannot correctly parse the uplink data, and the registration activation process of the legal ONU fails.
  • a primary object of the present invention is to provide a method and system for registering activation of an optical network unit to at least solve the above problems.
  • a registration activation method of an ONU including the following steps: The ONU receives a registration request from an optical line terminal OLT; the ONU sends registration information to the OLT according to a type of registration information stored by the ONU; and the OLT according to the OLT The registration information of the legal ONU stored by itself and the received registration information determine the validity of the ONU, and the processing result is activated by the ONU.
  • a registration activation method of an ONU including the following steps: The ONU receives a predetermined request from an OLT, where the predetermined request is a registration request or a ranging request; and the ONU sends a corresponding reservation to the OLT. The response information of the request and the message authentication code corresponding to the response information; and the OLT performs integrity check on the response information according to the message authentication code, and performs subsequent processing on the ONU after the check is passed.
  • a registration activation system for an optical network unit including an ONU and an OLT, where: the ONU includes: a receiving module, configured to receive a registration request from an optical line terminal OLT; For transmitting the registration information to the OLT according to the type of the registration information stored by the OLT; the OLT includes: a determination module, configured to determine the validity of the ONU according to the registration information of the legal ONU stored by the user and the received registration information; A process for registering activation of an ONU according to a judgment result.
  • a registration activation system of an ONU including an ONU and an OLT, where: the ONU includes: a receiving module, configured to receive a predetermined request from the OLT, where the predetermined request is a registration request or a ranging request a sending module, configured to send, to the OLT, response information corresponding to the predetermined request and a message authentication code corresponding to the response information; the OLT includes: an checking module, configured to perform integrity checking on the response information according to the message authentication code; and a processing module, configured to: Check the passage The corresponding subsequent processing is performed on the ONU.
  • the ONU sends the registration information to the OLT according to the type of the registration information stored by the ONU or the ONU sends the response information to the OLT and the message authentication code for performing the integrity verification, which solves the problem that the legal ONU registration activation fails in the related art.
  • the problem is that the legal ONU can successfully register and activate, which improves the user experience and reduces the operating cost of the operator.
  • FIG. 1 is a schematic flowchart of an ONU registration activation method in the ITU-T G.984.3 standard
  • FIG. 2 is a schematic diagram of a bandwidth mapping allocation structure in a downlink physical control block of a downlink frame
  • FIG. 4 is a structural block diagram of a registration activation system of an optical network unit according to an embodiment of the present invention
  • FIG. 5 is a block diagram of a registration activation system of an optical network unit according to an embodiment of the present invention
  • FIG. 6 is a flowchart of a registration activation method of another optical network unit ONU according to an embodiment of the present invention
  • FIG. 7 is a flowchart of a method for registering activation of another optical network unit ONU according to an embodiment of the present invention
  • FIG. 3 is a flowchart of a method for registering an ONU according to an embodiment of the present invention. As shown in FIG.
  • the method includes the following steps: Step S302: The ONU receives a registration request from the OLT; Step S304, The ONU sends the registration information to the OLT according to the type of the registration information stored by the ONU; and in step S306, the OLT determines the validity of the ONU according to the registration information of the legal ONU stored by the OLT and the received registration information, and registers the ONU with the judgment result. Activated processing.
  • the ONU only sends the SN to the OLT. Therefore, if the SN of the ONU is not stored in the OLT, the ONU cannot successfully register the activation.
  • the ONU uses the registration information stored by the ONU.
  • the type sends the registration information to the OLT, and is not limited to only transmitting the SN. Therefore, the registration information can be transmitted more flexibly, so that when the SN of the ONU is not stored in the OLT, the OLT can determine the legality of the ONU by comparing other registration information of the ONU. Sex, to achieve the smooth registration activation of the legal ONU, while reducing the operating costs of operators.
  • the step S304 may include: determining, by the ONU, whether the registration information stored by the ONU is only the serial number information of the ONU, and if yes, sending the serial number information to the OLT; otherwise, transmitting at least one of the types of the stored registration information to the OLT. Type of registration information.
  • the OLT can flexibly implement the OLT to perform registration authentication on the registration information other than the SN of the ONU, even if the SN of the legal ONU is not stored at the OLT.
  • the ONU can still be successfully registered, which facilitates the ONU users and at the same time reduces the operating costs of the operators.
  • the ONU further sends a message authentication code corresponding to the registration information to the OLT.
  • the OLT Before the OLT determines the validity of the ONU according to the registration information of the legal ONU stored by the OLT and the received registration information, the OLT further includes: the OLT registers according to the message authentication code. The information is checked for integrity, and the check is passed for subsequent processing.
  • the method of providing the danger certificate by the method can also prevent the malicious ONU from spoofing the legitimate ONU for registration activation, thereby causing the problem that the legitimate ONU registration activation fails.
  • the ONU Before the ONU sends the message authentication code to the OLT, the ONU generates a message authentication code according to the registration information and the preset key; the OLT performs integrity check on the response information according to the message authentication code.
  • the check includes: the OLT generates a message authentication code for verification according to the received registration information and a preset key, and compares whether the message authentication code used for verification is consistent with the received message authentication code, and if yes, the check passes Otherwise, initiate a deactivation of the ONU ID Deactive_ONU-ID message to the ONU or disable the serial number Disable_Serial_Number (or simply Disable) message.
  • the legal ONU generates a message authentication code through a preset key, and the OLT generates a message authentication code for verification by using the same key, and compares the two to determine whether the ONU that sends the message is a legal ONU, and can prevent malicious ONUs.
  • the spoofing legal ONU performs registration activation, which causes the problem that the legal ONU registration activation fails.
  • the authentication process is simpler and the processing speed is faster.
  • the OLT further includes: the OLT sends a ranging request to the ONU; the ONU sends the ranging information and the ranging to the OLT.
  • the method of providing a risk-proofing process can prevent the malicious ONU from spoofing the legitimate ONU to perform a ranging response, thereby causing a problem of legitimate ONU data transmission conflict.
  • the ONU before the ONU sends the message authentication code to the OLT, the ONU generates a message authentication code according to the ranging information and the preset key; the integrity check of the ranging information by the OLT according to the message authentication code includes: the OLT according to the received measurement Generating a message authentication code for verification from the information and the preset key, and comparing whether the message authentication code used for verification is consistent with the received message authentication code, and if so, the check is passed, otherwise, the activation is initiated to the ONU. .
  • the legal ONU generates a message authentication code through a preset key, and the OLT generates a message authentication code for verification by using the same key, and compares the two to determine whether the ONU that sends the message is a legal ONU, so as to prevent malicious ONUs.
  • a counterfeit legal ONU performs a ranging response, which causes a problem of legitimate ONU data transmission conflicts.
  • the above preset key may include at least one of the following: a password of the ONU, data sent by the OLT to the ONU, data sent by the ONU to the OLT, data sent by the OLT to the ONU, and a combination of data sent by the ONU to the OLT.
  • the stored registration information includes serial number information of the ONU and/or password information of the ONU. That is, when the ONU itself stores the ONU serial number and password information, the registration information sent by the ONU is the serial number information of the ONU, the ONU password information, or the ONU serial number and password information; when the ONU itself only stores the ONU serial number information, The registration information sent by the ONU is the ONU serial number information.
  • the password information of the ONU may be a temporary password allocated by the operator for the ONU of the GPON service, and the ONU may send the temporary password.
  • the temporary password is stored in the crypto library of the OLT, and the ONU can be registered and activated by the password.
  • This method is simple and easy to implement.
  • the ONU sends the serial number information and the password information to the OLT, and the OLT stores the serial number information of the ONU after determining that the ONU is legal.
  • the OLT stores the SN of the ONU in its own SN library, so as to update the SN library.
  • the SN of the ONU is already stored in the SN of the OLT.
  • the registration activation of the ONUs in this class can be directly implemented by the SN, which facilitates subsequent processing, and as a preferred solution, the ONU can only send the two in the process of registering activation to the OLT for the first time.
  • the information can be sent only after the SN, so the overhead of this method is small.
  • the ONU can carry the serial number information and the password information in a physical layer operation, management and maintenance PLOAM message and send the information to the OLT; or the ONU can also carry the serial number information and the password information in the two PLOAM messages and send the information.
  • the carrying of the serial number information and the password information in one message can save the interaction process between the ONU and the OLT, and has high processing efficiency.
  • the process of determining, by the OLT, the validity of the ONU according to the registration information of the legal ONU stored by the OLT and the received registration information in the step S306 includes: according to the registration information of the received ONU, the OLT determines its own registration information base. Whether or not the registration information sent by the ONU is stored, and if so, it is determined that the ONU is legal, and if not, it is determined that the ONU is invalid.
  • the foregoing registration information base may be specifically a serial number library and/or a password library.
  • step S306 the OLT performs the registration activation of the ONU by the determination result: if the ONU is legal, the OLT allows the ONU to complete the registration activation process; if the ONU is invalid, the OLT rejects the ONU for registration activation, ONU registration activation failed.
  • 4 is a structural block diagram of a registration activation system of an optical network unit according to an embodiment of the present invention, including an ONU 42 and an OLT 44.
  • the ONU 42 includes: a receiving module 45, configured to receive a registration request from the OLT 44.
  • the sending module 46 is configured to send the registration information to the OLT 44 according to the type of the registration information stored by the OLT 44.
  • the OLT 44 includes: a determining module 47, configured to the ONU 42 according to the registration information of the legal ONU stored by itself and the received registration information. The legality judgment is performed; the registration activation module 48 is configured to perform registration activation on the ONU 42 in the result of the judgment.
  • the ONU 42 only sends the SN to the OLT 44. Therefore, if the SN of the ONU 42 is not stored in the OLT 44, the ONU 42 cannot successfully register the activation. In the system provided by the embodiment of the present invention, the ONU 42 is used.
  • the sending module 46 sends the registration information to the OLT 44 according to the type of the registration information stored by itself, so that the registration information can be transmitted more flexibly, so that when the SN of the ONU 42 is not stored in the OLT 44, the OLT 44 can compare the ONUs through the determining module 47.
  • the other registration information of the 42 determines the legality of the ONU 42 and implements the smooth registration activation of the legal ONU 42 through the registration activation module 48, and at the same time reduces the operating cost of the operator.
  • 5 is a block diagram of a preferred structure of the registration activation system of the optical network unit according to the embodiment of the present invention. Preferably, as shown in FIG.
  • the sending module 46 includes: a determining module 52, configured to determine whether the registration information stored by itself is It is only the serial number information of the ONU 42.
  • the scheduling module 54 is configured to schedule the first sending module 56 when the determining result of the determining module 52 is YES, and if the determining result of the determining module 52 is negative, the scheduling is performed.
  • the second sending module 58 is configured to send the serial number information to the OLT 44.
  • the second sending module 58 is configured to send, to the OLT 44, at least one type of registration information of the stored type of registration information.
  • the preferred structure can also flexibly implement the ONU 42 to send registration information other than the SN to the OLT 44 for registration verification by the OLT 44, even at the OLT 44. If the SN of the legal ONU 42 is not stored, the ONU 42 can still be successfully registered, which greatly facilitates the ONU user and reduces the operating cost of the operator.
  • the embodiment 1-3 described below combines the technical solutions of the above-described plurality of preferred embodiments.
  • Embodiment 1 when the SN and the password are stored in the ONU, the ONU sends a password to respond to the registration request of the OLT, and the ONU sends the SN+ password to respond to the ranging request sent by the OLT.
  • the ONU of the sequence number state receives the registration request sent by the OLT, and the ONU determines the registration information type stored by the ONU. If the ONU only stores the SN information of the ONU, the ONU sends a sequence number message to the OLT, and the OLT and the ONU follow the background art.
  • the registration activation step in the registration activation process if the serial number information and the password information are stored in the ONU, the ONU sends a password message to the OLT; Step 2, after receiving the password message of the ONU, the OLT allocates and sends a unique ONU_ID to the After the ONU receives the ONU_ID, the ONU enters a ranging state; Step 3: The ONU in the ranging state receives the ranging request sent by the OLT, and the ONU sends the SN and the password information to the OLT in a PLOAM message, or the ONU sends the SN and the password information to the OLT in the two PLOAM messages respectively. .
  • Step 4 The OLT compares the password sent by the ONU with the OLT.
  • the legal password stored in the password library. If the password of the OLT contains the password of the received ONU (that is, the password of the OLT contains the password corresponding to the password of the received ONU), then the ONU is determined to be legal.
  • the ONU stores the SN received in the third step in its own SN library, updates the SN library, and the ONU completes the registration activation process, and the ONU registration is activated successfully; otherwise, the ONU is determined to be an illegal ONU, and the OLT sends the deactivated ONU- An ID (Deactivate ONU-ID) message is sent to the ONU, the ONU releases the ONU-ID, and enters a standby state, and the ONU registration activation process fails.
  • the OLT may also perform the validity judgment of the ONU after receiving the password of the ONU in step 2.
  • the OLT If the password of the OLT contains the password of the received ONU (that is, the password pool of the OLT) If the password is the same as the password of the received ONU, the ONU is determined to be a valid ONU, and the ONU continues the registration activation process. After receiving the SN sent by the ONU in step 3, the OLT stores the SN in its own SN. In the library, the SN library is updated, and the OLT does not need to perform the operation of step 4; otherwise, the OLT rejects the ONU to perform the registration activation process, and the ONU registration activation process fails.
  • Embodiment 2 when the SN and the password are stored at the ONU, the ONU sends the SN and the password to respond to the registration request of the OLT, and the ONU sends the SN+ password to respond to the ranging request sent by the OLT.
  • the ONU of the sequence number state receives the registration request sent by the OLT, and the ONU determines the registration information type stored by the ONU. If the ONU only stores the SN information of the ONU, the ONU sends a sequence number message to the OLT, and the OLT and the ONU follow the background art.
  • the registration activation step in the registration activation process if the serial number information and the password information are stored in the ONU, the ONU sends the serial number and password information to the OLT in a PLOAM message, or the ONU sends the SN and the two in the PLOAM message respectively.
  • the password information is sent to the OLT.
  • Step 2 After receiving the PLOAM message sent by the ONU and including the serial number and the password information, the OLT allocates and sends a unique ONU ID to the ONU.
  • Step 3 The ONU in the ranging state receives the ranging request sent by the OLT, and after receiving the ranging request, the ONU sends the SN and the password information to the OLT in a PLOAM message, or the ONU The SN and password information are respectively sent to the OLT in the two PLOAM messages.
  • the equalization delay is sent to the ONU, and the ONU enters the working state after receiving the equalization delay;
  • Step 4 The OLT compares the SN and the OLT sent by the ONU. The legal SN stored in the SN library.
  • the ONU is determined to be Legal ONU, ONU registration activation process is completed, the ONU registration activation is successful, otherwise the OLT compares the password sent by the ONU with the legal password stored in the OLT password database, if the OLT password library contains the password of the received ONU (that is, The OLT password library contains a password corresponding to the received ONU password.
  • the OLT is determined to be a valid ONU.
  • the OLT stores the SN received in step 4 in its own SN library and updates the SN library.
  • the ONU completes the registration activation process, and the ONU registration is successfully activated.
  • the OLT can also determine the validity of the ONU after receiving the SN and the password of the ONU in the second step. If the OLT determines that the ONU is a legal ONU through the password information of the ONU, the OLT will use the SN of the ONU.
  • the SN library is stored in its own SN library, and the SN library is updated. The ONU continues to perform the registration activation process.
  • the OLT does not need to perform the operation of step 4. Otherwise, the OLT rejects the ONU to perform the registration activation process, and the ONU registration activation process fails.
  • Embodiment 3 when the SN and the password are stored in the ONU, the ONU sends the SN/password/(SN+password) and the information authentication code to respond to the registration request of the OLT, and the ONU sends the SN/(SN+password) and the information authentication code to respond to the OLT. Ranging request sent. The ONU of the sequence number state receives the registration request sent by the OLT, and the ONU determines the registration information type stored by the ONU.
  • the ONU If the ONU only stores the SN information of the ONU, the ONU sends a sequence number message to the OLT, and the OLT and the ONU follow the background art.
  • the registration activation step in the registration activation process if the serial number information and password information are stored in the ONU, the ONU will make the password information For the key, the integrity check of the SN information is calculated, and a message authentication code is generated. The ONU sends the SN along with the message authentication code to the OLT.
  • Step 2 After receiving the content sent by the ONU, the OLT compares the SN sent by the ONU with the legal SN stored in the SN library of the OLT, and if the SN of the OLT includes the SN of the received ONU ( That is, the SN of the OLT includes the SN of the received ONU, and the OLT obtains the locally stored cipher information corresponding to the SN through the SN sent by the ONU, and the OLT uses the cipher information as a key, The SN information performs the integrity check calculation, and generates a message authentication code. If the message authentication code generated at the OLT is different from the message authentication code sent by the ONU, the ONU registration activation process fails.
  • the OLT allocates and sends a unique ONU_ID to the OLT.
  • the ONU After receiving the ONU_ID, the ONU enters the ranging state; Step 3: The ONU in the ranging state receives the ranging request sent by the OLT, and after receiving the ranging request, the ONU uses the password information as a key. And performing an integrity check on the SN information to generate a message authentication code. The ONU sends the SN along with the message authentication code to the OLT.
  • the OLT After receiving the content sent by the ONU, the OLT obtains the locally stored password information corresponding to the SN through the SN sent by the ONU, and the OLT uses the password information as a key to perform integrity check calculation on the SN information, and generates The message authentication code, if the message authentication code generated by the OLT is different from the message authentication code sent by the ONU, the ONU registration activation process fails. Otherwise, after the OLT completes the measurement of the equalization delay of the ONU, the equalization delay is sent. To the ONU, the ONU enters the working state after receiving the equalization delay.
  • the ONU sends the SN and the message authentication code to respond to the registration request of the OLT, and may also use the ONU to send the password and the message authentication code to respond to the registration request of the OLT, and the ONU uses the password as the key to complete the password information.
  • the calculation of the sex check generates a message authentication code.
  • the ONU sends the password along with the message authentication code to the OLT.
  • the OLT compares the password sent by the ONU with the legal password stored in the OLT's password database. If the OLT's password database contains the password of the received ONU, the OLT uses the same calculation method as the ONU to authenticate the password information.
  • the ONU sends the SN and the message authentication code to respond to the registration and ranging request of the OLT, and may also use the ONU to send the SN, the password, and the message authentication code to respond to the OLT registration request and the ranging request.
  • the ONU uses the password as a key to perform an integrity check on the SN and the password information to generate a message authentication code.
  • the ONU sends the SN, the password, and the message authentication code to the OLT.
  • the OLT compares the SN sent by the ONU with the legal SN stored in the SN library of the OLT, or the OLT compares the password sent by the ONU with the legal secret stored in the OLT's crypto library.
  • the OLT also authenticates the password information by the same calculation method as that of the ONU.
  • the ONU and the OLT use the password of the ONU as the key for calculating the message authentication code, and may also use the data sent by the OLT to the ONU as a key, or the data sent by the ONU to the OLT as a key, or an OLT and The data sent by the ONU to the other party constitutes a key, or the OLT and the ONU may store an identical key in advance locally.
  • FIG. 6 is a flowchart of a registration activation method of another optical network unit ONU according to an embodiment of the present invention.
  • Step S602 The ONU receives a predetermined request from the OLT, where the predetermined request is The SMB sends the response information corresponding to the predetermined request and the message authentication code corresponding to the response information to the OLT; and in step S606, the OLT performs an integrity check on the response information according to the message authentication code, and after the check is passed Performing corresponding processing on the ONU (for example, if the predetermined request is a registration request, subsequent steps such as issuing an ONU-ID and initiating a ranging request may be performed. If the predetermined request is a ranging request, subsequent ranging may be performed. Corresponding steps such as equalization delay issuance).
  • the malicious ONU can obtain the SN information of the legal ONU and the ONU-ID information that the OLT allocates to the ONU, thereby maliciously returning the ranging response, so that the uplink data sent by the legal ONU after entering the working state is sent by other legal ONUs.
  • the upstream data conflicts, or the registration activation process of the legitimate ONU fails.
  • the ONU sends a response message and a message authentication code to ensure that the OLT correctly determines whether the content of the received ONU response is from the legal ONU through the message authentication code, so that the OLT does not send the ONU-ID to the malicious ONU.
  • the OLT ensure that the OLT correctly calculates the equalization delay of the legal ONU so that the legal ONU performs normal uplink data transmission.
  • the ONU generates a message authentication code according to the response information and the preset key; the OLT performs integrity check on the response information according to the message authentication code, including: The received response information and the preset key generate a message authentication code for verification, and compare whether the message authentication code used for verification is consistent with the received message authentication code, and if so, the check passes, otherwise, to the ONU Initiate deactivation of the ONU identifier Deactive_ONU-ID message or disable the serial number Disable Serial Number (Disable) message.
  • the legal ONU generates a message authentication code by using a preset key
  • the OLT generates a message authentication code for verification by using the same key, and compares the two to determine whether the ONU that sends the message is a legal ONU.
  • the preset key may include at least one of the following: a password of the ONU, data sent by the OLT to the ONU, data sent by the ONU to the OLT, data sent by the OLT to the ONU, and a combination of data sent by the ONU to the OLT. , the keys stored in the OLT and the ONU in advance.
  • the system includes an ONU 42 and an OLT 44, wherein the ONU 42 includes:
  • the module 72 is configured to receive a predetermined request from the OLT 44, where the predetermined request is a registration request or a ranging request, and the sending module 74 is configured to send, to the OLT 44, response information corresponding to the predetermined request and a message authentication code corresponding to the response information;
  • the method includes: an checking module 76, configured to perform an integrity check on the response information according to the message authentication code; and a processing module 78, configured to perform corresponding subsequent processing on the ONU 42 if the check passes.
  • the malicious ONU can obtain the SN information of the legal ONU and the ONU-ID information that the OLT 44 assigns to the ONU 42 to maliciously return the measurement response, so that the uplink data sent by the legal ONU after being in the working state is sent by other legal ONUs.
  • the upstream data conflicts, or the registration activation process of the legitimate ONU fails.
  • the sending module 74 in the ONU 42 sends a response message and a message authentication code, so that the checking module 76 of the OLT 44 correctly determines whether the content of the received ONU response is from the legal ONU through the message authentication code.
  • Embodiment 4 combines the technical solutions of the above-described plurality of preferred embodiments.
  • the ONU sends the SN and the information authentication code in response to the registration request and the measurement request sent by the OLT.
  • Step 1 The ONU in the sequence number state receives the registration request sent by the OLT, and the ONU uses the password information as a key to perform an integrity check on the SN information to generate a message authentication code, and the ONU compares the SN with the calculated message authentication code. Sent to the OLT.
  • Step 2 After receiving the foregoing content sent by the ONU, the OLT obtains the locally stored password information corresponding to the SN by using the SN sent by the ONU, and the OLT uses the password information as a key to perform integrity check calculation on the SN information, and generates a message.
  • the authentication code if the message authentication code generated by the OLT is different from the message authentication code sent by the ONU, the ONU registration activation process fails. Otherwise, the OLT allocates and sends a unique ONU_ID to the ONU. After receiving the ONU_ID, the The ONU enters the ranging state.
  • Step 3 The ONU in the ranging state receives the ranging request sent by the OLT, and after receiving the ranging request,
  • the ONU uses the data sent by the OLT to the ONU as a key to perform integrity check on the SN information to generate a message authentication code.
  • the ONU sends the SN to the OLT along with the calculated message authentication code.
  • the OLT determines the content of the data that is sent to the ONU by using the SN sent by the ONU, and the OLT uses the content as a key to perform integrity check on the SN information to generate a message.
  • the authentication code if the message authentication code generated by the OLT is different from the message authentication code sent by the ONU, the ONU registration activation process fails.
  • the solution provided by the embodiment of the present invention solves the problem that the legal ONU registration activation fails in the related art, so that the legal ONU can successfully register and activate, which improves the user experience and reduces the operation cost of the operator. It should be noted that the steps shown in the flowchart of the accompanying drawings may be performed in a computer system such as a set of computer executable instructions, and, although the logical order is shown in the flowchart, in some cases, The steps shown or described may be performed in an order different than that herein.
  • modules or steps of the present invention can be implemented by a general-purpose computing device, which can be concentrated on a single computing device or distributed over a network composed of multiple computing devices. Alternatively, they may be implemented by program code executable by the computing device, such that they may be stored in the storage device by the computing device, or they may be separately fabricated into individual integrated circuit modules, or they may be Multiple modules or steps are made into a single integrated circuit module.
  • the invention is not limited to any specific combination of hardware and software.
  • the above is only the preferred embodiment of the present invention, and is not intended to limit the present invention, and various modifications and changes can be made to the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the scope of the present invention are intended to be included within the scope of the present invention.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Small-Scale Networks (AREA)

Description

光网各单元的注册激活方法及系统 技术领域 本发明涉及通信领 i或,具体而言, 涉及一种光网络单元( Optical Network Unit, 简称为 ONU ) 的注册激活方法及系统。 背景技术 随着网络技术的发展, 语音、 数据和视频等业务的传输对网络带宽的要 求不断提高, 千兆无源光网络 ( Gigabit Passive Optical Network , 简称为 GPON ) 就是在这种需求下应运而生的。 GPON 系统通常由网络侧的光线路 终端 (Optical Line Terminal, 简称为 OLT ) 以及用户侧的 ONU和光分配网 络(Optical Distribution Network, 简称为 ODN )组成, 一般釆用点到多点的 网络结构,其中, ODN由单模光纤、光分路器和光连接器等无源光器件组成, 其为 OLT和 ONU之间的物理连接提供光传输媒质。
GPON系统中, 在下行方向 (即, 由 OLT到 ONU的方向) 釆用广播方 式进行通信, 各个 ONU都能够收到所有的下行帧, 但是要根据下行帧中的 ONU 标识 (ONU-ID )、 GPON 封装模式端口标识 ( GPON Encapsulation Mode-Port ID, 简称为 GEM-Port ID )和分配标识 (Allocation-ID ) 来获得属 于自己的下行帧。 而在上行方向 (即, 从 ONU到 OLT方向) 上, 由于各个 ONU需要共享传输媒质,因此各个 ONU需要在 OLT安排给自己的时隙内传 输上行数据。 上行帧釆用时分复用接入 (Time Division Multiple Access, 简 称为 TDMA )技术, 该技术将上行信道分成多个时隙, OLT为 ONU分配上 行带宽, ONU在 OLT分配给自己的上行带宽内发送数据。 为了安全考虑, 在 ONU接入 OLT前, OLT需要对 ONU的合法性进行 认证, 相关技术中, OLT釆用基于 ONU的序列号 ( Serial Number, 简称为 SN )来对 ONU进行合法性-险证, 并拒绝非法 ONU的接入。 下面阐述 ITU-T G.984.3标准中所定义的 ONU的注册激活流程, 图 1是国际电信联盟一电信 标 准 部 ( International Telecommunications Union-Telecommunications standardization sector, 简称为 ITU-T ) G.984.3标准中的 ONU注册激活方法 的流程示意图, 如图 1所示, ONU注册激活方法包括以下几个步骤: 步骤 1 , ONU刚上电时, 处于初始状态; ONU侦听 OLT发送的下行帧 并获取帧同步, 进入待机状态。 在该步骤中, OLT每隔 125 ^啟秒发送一个下行帧, 当 ONU刚上电时暂 时不能与下行帧保持同步, 因此会产生信号丢失 /帧丢失(Loss of Signal/Loss of Frame, 简称为 LOS/LOF ) 两种告警; 当 ONU接收到下行帧并获取帧同 步后, 则会清除这两种告警。 步骤 2 , 待机状态的 ONU 接收 OLT 发来的上行开销参数 ( Upstream—overhead parameters ) 消息, 或者 Upstream—overhead parameters 消息和扩展突发长度 ( Extended Burst Length ) 消息, 之后根据消息中包含 的参数进行上行帧相关配置, 并进入序列号状态。 在该步骤中,上行开销参数消息和扩展突发长度消息由 OLT以广播方式 通过下行帧中的物理层操作、 管理与维护 ( Physical Layer Operation , Administration & Maintenance, 简称为 PLO AM )消息在下行方向上发送; 上 行帧相关配置包括: 保护比特数、 前导码比特数和定界符比特数等。 步骤 3 , 序列号状态的 ONU接收 OLT发来的 SN请求 ( SN Request ), 收到上述 SN请求后, ONU发送自身的 SN给 OLT。 步骤 4, OLT 欠到的 ONU的 SN后, 将分配并发送一个唯一的 ONU_ID 给该 ONU, 该 ONU收到 ONU_ID后进入测 巨状态。 步骤 5 ,测 巨状态的 ONU接收 OLT发来的测距请求( Ranging Request ), 该 ONU收到该测距请求后发送自身的序列号信息给 OLT。 为了使所有 ONU 的上行传输同步, OLT需要测量 ONU的均衡时延, OLT完成 ONU的均衡 时延的测量后, 将均衡时延发送给 ONU, ONU成功接收到均衡时延后进入 工作状态。 本步骤中, OLT发送测距请求并从 ONU获得响应后, 根据相应的发送 时间和接收时间以及其他参数计算均衡时延。 因为 GPON系统是点到多点网 络结构, 各个 ONU釆用 TDMA技术接入 OLT, 而各个 ONU距 OLT的 巨离 不一样, 当各个 ONU在上行发送数据时, 可能产生冲突, 均衡时延的作用 就是让所有 ONU从逻辑上显得与 OLT—样远, 从而安 4 带宽分配以避免上 行方向的冲突。 当 ONU准备发送上行帧时需延迟 "均衡时延"。 步骤 6, OLT比较 ONU发来的 SN与 OLT的 SN库中存储的合法 SN, 如果 OLT的 SN库中包含接收到的 ONU的 SN,则判定此 ONU为合法 ONU, 该 ONU 注册激活成功, 否则判定 匕 ONU 为非法 ONU, OLT发送去激活 ONU-ID ( Deactivate ONU-ID ) 消息给该 ONU, 该 ONU释放该 ONU-ID , ONU注册激活过程失败。 在 ITU-T的 G984.3标准中规定, OLT发送给处于序列号^ I 态的 ONU 的 SN请求是以带宽映射分配结构 ( BWmap Allocation Structures ) 方式通过 下行帧中的下行物理控制块 ( Physical Control Block downstream, PCBd ) 传 递的, 图 2是下行帧的下行物理控制块中带宽映射分配结构的组成示意图。 如图 2 所示, 下行帧由 PCBd和净荷两部分组成, 其中 PCBd 由物理同步 ( Physical Synchronization,简称为 Psync )i或、标 i只符( Ident )i或、下行 PLOAM ( PLOAM downstream , 简称为 PLOAMd ) 域、 比特间插奇偶校-险 ( Bit Interleaved Parity,简称为 BIP )域、信息净荷长度( Payload Length downstream, 简称为 Plend ) 域和上行带宽映射 (US BWmap ) 域组成, 其中 US BWmap i或由 N个分配结构 ( Allocation Structure )组成,每个分配结构由 Allocation ID ( Alloc-ID ) 域、 带宽分配的选项 (Flags ) 域、 带宽起始时间 ( StartTime ) 域、带宽结束时间( StopTime ) i或和循环冗余校-险( Cyclic Redundancy Check, 简称为 CRC ) i或组成。 发明人发现, 在上述的 ONU注册激活过程中, 存在以下两种会导致合 法 ONU注册激活失败的情况:
1、 ONU仅仅发送 SN到 OLT, 以便其通过 SN判断该 ONU是否合法。 如果一个 ONU的 SN没有预先存储在 OLT的 SN库中,则此 ONU不能注册。 当考虑光纤到户 ( Fiber To The Home , 简称为 FTTH )应用场景时, ONU是 用户设备, 用户可以自行购买、 更换, 这样的 ONU的 SN由于没有预先存储 在 OLT的 SN库中, 对运营商来说是不可信的, 那么, 这样的 ONU就不能 顺利注册激活, 为这样的 ONU开通业务需要运营商的支持, 不仅为用户带 来麻烦, 也会让运营商提高运营成本。
2、 如果 GPON系统中存在恶意 ONU , 恶意 ONU可以监听 OLT发送给 合法 ONU的 Assign_ONU-ID消息, 该消息中包含所述合法 ONU的 SN信 息和 OLT分配给所述 ONU的 ONU-ID信息。 在 OLT给所述合法 ONU发送 测距请求时, 所述恶意 ONU可以将上述监听的 SN信息和 OLT分配给所述
ONU的 ONU-ID信息发送给 OLT, 所述合法 ONU也将自身的 SN信息和 OLT分配给所述 ONU的 ONU-ID信息发送给 OLT, 如果所述恶意 ONU发 送的上述信息先到达 OLT, 则 OLT分配给所述合法 ONU的均衡时延值大于 所述合法 ONU应该得到的均衡时延值,则所述合法 ONU进入工作状态后发 送的上行数据会与其他合法 ONU发送的上行数据产生冲突。 如果所述恶意 ONU和所述合法 ONU发送的上述信息同时到达 OLT, 则 OLT不能正确解 析上行数据, 所述合法 ONU的注册激活过程失败。 发明内容 本发明的主要目的在于提供一种光网络单元的注册激活方法及系统, 以 至少解决上述问题。 居本发明的一个方面, 提供了一种 ONU的注册激活方法, 包括以下 步骤: ONU从光线路终端 OLT接收到注册请求; ONU根据自身存储的注册 信息的类型向 OLT发送注册信息;以及 OLT根据自身存储的合法 ONU的注 册信息和接收到的注册信息对 ONU 进行合法性判断, 并 居判断结果对 ONU进行注册激活的处理。 才艮据本发明的另一个方面, 提供了一种 ONU的注册激活方法, 包括以 下步骤: ONU从 OLT接收到预定请求, 其中, 预定请求为注册请求或测距 请求; ONU向 OLT发送对应预定请求的响应信息和对应响应信息的消息认 证码; 以及 OLT根据消息认证码对响应信息进行完整性检查, 检查通过后对 ONU进行相应的后续处理。 才艮据本发明的又一个方面, 提供了一种光网络单元的注册激活系统, 包 括 ONU和 OLT, 其中: ONU包括: 接收模块, 用于从光线路终端 OLT接 收到注册请求; 发送模块, 用于根据自身存储的注册信息的类型向 OLT发送 注册信息; OLT包括: 判断模块, 用于根据自身存储的合法 ONU的注册信 息和接收到的注册信息对 ONU进行合法性判断; 注册激活模块, 用于根据 判断结果对 ONU进行注册激活的处理。 根据本发明的再一个方面,提供了一种 ONU的注册激活系统,包括 ONU 和 OLT, 其中: ONU包括: 接收模块, 用于从 OLT接收预定请求, 其中, 预定请求为注册请求或测距请求; 发送模块, 用于向 OLT发送对应预定请求 的响应信息和对应响应信息的消息认证码; OLT包括: 检查模块, 用于根据 消息认证码对响应信息进行完整性检查; 处理模块, 用于在检查通过的情况 下对 ONU进行相应的后续处理。 通过本发明, 釆用 ONU根据自身存储的注册信息的类型向 OLT发送注 册信息或者 ONU 向 OLT 发送响应信息和用于进行完整性验证的消息认证 码, 解决了相关技术中合法 ONU注册激活失败的问题, 使得合法 ONU能够 成功注册激活, 提高了用户体验, 同时降低了运营商的运营成本。 附图说明 此处所说明的附图用来提供对本发明的进一步理解, 构成本申请的一部 分, 本发明的示意性实施例及其说明用于解释本发明, 并不构成对本发明的 不当限定。 在附图中: 图 1是 ITU-T G.984.3标准中的 ONU注册激活方法的流程示意图; 图 2是下行帧的下行物理控制块中带宽映射分配结构的组成示意图; 图 3是才艮据本发明实施例的一种 ONU的注册激活方法的流程图; 图 4 是才艮据本发明实施例的一种光网络单元的注册激活系统的结构框 图; 图 5 是才艮据本发明实施例的光网络单元的注册激活系统的优选结构框 图; 图 6是才艮据本发明实施例的另一种光网络单元 ONU的注册激活方法的 流程图; 图 7是才艮据本发明实施例的另一种光网络单元 ONU的注册激活系统的 结构框图。 具体实施方式 下文中将参考附图并结合实施例来详细说明本发明。 需要说明的是, 在 不冲突的情况下, 本申请中的实施例及实施例中的特征可以相互组合。
GPON系统通常由网络侧的 OLT以及用户侧的 ONU和 ODN组成。 ONU 为了实现注册激活, 需要与 OLT进行交互, 提供自身的注册信息, 以便 OLT 对注册信息进行-险证, 从而完成对 ONU的注册激活的处理。 图 3是才艮据本发明实施例的一种 ONU的注册激活方法的流程图,如图 3 所示, 该方法包括以下步 4聚: 步骤 S302 , ONU从 OLT接收到注册请求; 步骤 S304 , ONU根据自身存储的注册信息的类型向 OLT发送注册信息; 以及 步骤 S306, OLT根据自身存储的合法 ONU的注册信息和接收到的注册 信息对 ONU进行合法性判断,并 居判断结果对 ONU进行注册激活的处理。 相关技术中, 由于 ONU仅仅向 OLT发送 SN, 因此, 若 OLT中未存储 ONU的 SN, 此 ONU则无法成功注册激活, 在本发明实施例提供的方法中, 通过 ONU根据自身存储的注册信息的类型向 OLT发送注册信息, 而不限定 于只传送 SN, 所以能够更加灵活地发送注册信息, 从而在 ONU的 SN未存 储于 OLT中时, OLT可通过比较 ONU的其他注册信息, 判断 ONU的合法 性, 实现合法 ONU的顺利注册激活, 同时降低了运营商的运营成本。 优选地, 步骤 S304可以包括: ONU判断自身存储的注册信息是否仅为 ONU的序列号信息, 若是, 则向 OLT发送序列号信息, 否则, 向 OLT发送 存储的注册信息的类型中的至少一种类型的注册信息。 一般来说, 如果用户 在运营商处购买 ONU, 则该 ONU的 SN已存储于 OLT的 SN库中, 所以该 ONU可以直接通过自身的 SN进行注册激活; 而如果用户在设备供应商处购 买 ONU, 则该 ONU的 SN未存储于 OLT的 SN库中, 所以该 ONU不能直 接通过 SN进行注册激活。 通过该方法, 除了能够支持 OLT对 ONU进行 SN 注册认证之外, 还能灵活地实现 OLT对 ONU除 SN之外的注册信息进行注 册认证, 即使在 OLT处没有存储合法 ONU的 SN的情况下, 依然能够使该 ONU顺利注册, 方便了 ONU用户, 同时降氏了运营商的运营成本。 优选地, ONU还向 OLT发送注册信息对应的消息认证码; OLT根据自 身存储的合法 ONU的注册信息和接收到的注册信息对 ONU进行合法性判断 之前, 还包括: OLT根据消息认证码对注册信息进行完整性检查, 检查通过 后进行后续处理。 通过该方法提供 -险证过程, 还能够防止恶意 ONU仿冒合 法 ONU进行注册激活, 从而导致合法 ONU注册激活失败的问题。 优选地, ONU向 OLT发送消息认证码之前, ONU根据注册信息和预先 设定的密钥生成消息认证码; OLT根据消息认证码对响应信息进行完整性检 查包括: OLT根据接收到的注册信息和预先设定的密钥生成用于检验的消息 认证码, 并比较用于检验的消息认证码与接收到的消息认证码是否一致, 若 是, 则检查通过, 否则, 向 ONU发起去激活 ONU标识 Deactive_ONU-ID 消息或者去使能序列号 Disable_Serial_Number (或简称 Disable)消息。 合法 ONU 通过预先设定的密钥生成消息认证码, OLT 通过同样的密钥生成用于 检验的消息认证码, 将两者比较即可确定发送该消息的 ONU 是否是合法 ONU,能够防止恶意 ONU仿冒合法 ONU进行注册激活,从而导致合法 ONU 注册激活失败的问题, 且认证过程较简单, 处理速度较快。 优选地, OLT根据自身存储的合法 ONU的注册信息和接收到的注册信 息对 ONU进行合法性判断之前或之后,还包括: OLT向 ONU发起测距请求; ONU向 OLT发送测距信息和测距信息对应的消息认证码; 以及 OLT才艮据消 息认证码对测距信息进行完整性检查, 检查通过后测量 ONU 的均衡时延并 将其发送至 ONU。 通过该方法提供 -险证过程, 还能够防止恶意 ONU仿冒合 法 ONU进行测距响应, 从而导致合法 ONU数据发送冲突的问题。 优选地, ONU向 OLT发送消息认证码之前, ONU根据测距信息和预先 设定的密钥生成消息认证码; OLT根据消息认证码对测距信息进行完整性检 查包括: OLT根据接收到的测距信息和预先设定的密钥生成用于检验的消息 认证码, 并比较用于检验的消息认证码与接收到的消息认证码是否一致, 若 是, 则检查通过, 否则, 向 ONU发起去激活。 合法 ONU通过预先设定的密 钥生成消息认证码, OLT通过同样的密钥生成用于检验的消息认证码, 将两 者比较即可确定发送该消息的 ONU是否是合法 ONU, 以便防止恶意 ONU 仿冒合法 ONU进行测距响应, 从而导致合法 ONU数据发送冲突的问题。 优选地, 以上预先设定的密钥可以包括以下至少之一: ONU 的密码、 OLT发送至 ONU的数据、 ONU发送至 OLT的数据、 OLT发送至 ONU的数 据以及 ONU发送至 OLT的数据的组合、 预先存储在 OLT和 ONU的密钥, 通过设置多种密钥, 可以提高认证的安全性。 优选地, 以上过程中, 存储的注册信息包括 ONU 的序列号信息和 /或 ONU的密码信息。 也就是说, 当 ONU 自身存储 ONU序列号和密码信息时, ONU发送的注册信息为 ONU的序列号信息、 ONU密码信息或者 ONU序列 号和密码信息; 当 ONU 自身仅存储 ONU序列号信息时, ONU发送的注册 信息为 ONU序列号信息。 具体地, 该 ONU的密码信息可以为运营商为办理 GPON业务的该类 ONU分配的临时密码,该类 ONU可以将该临时密码发送 至 OLT, 该临时密码存储于 OLT的密码库中, 该类 ONU可通过该密码进行 注册激活, 这种方法实现简单, 且易于实现。 优选地, ONU向 OLT发送序列号信息和密码信息, OLT判断 ONU合 法后, 存储 ONU 的序列号信息。 通过这种方法, 在注册激活过程中, OLT 将该类 ONU的 SN存储于自身的 SN库中, 以便更新该 SN库, ONU注册激 活成功后, 由于该类 ONU的 SN已存储于 OLT的 SN库中, 故该类 ONU以 后的注册激活可直接通过 SN实现, 方便了后续的处理, 并且, 作为一种优 选的方案, ONU可以仅在第一次向 OLT注册激活的过程中发送这两种信息, 其后均可以只发送 SN, 因此, 这种方法的开销较小。 优选地, ONU可以在一个物理层操作、管理与维护 PLOAM消息中携带 序列号信息和密码信息并发送至 OLT;或者, ONU也可以在两个 PLOAM消 息中分别携带序列号信息和密码信息并发送至 OLT。 其中, 在一个消息中同 时携带序列号信息和密码信息能够节省 ONU与 OLT之间的交互流程, 具有 较高的处理效率。 在两个消息中分别携带序列号信息和密码信息能够釆用现 有的消息格式进行发送, 无需修改消息格式, 实现较简单。 具体地, 步骤 S306中 OLT根据自身存储的合法 ONU的注册信息和接 收到的注册信息对 ONU 进行合法性判断的过程具体包括: 根据接收到的 ONU的注册信息, OLT判断自身的注册信息库中是否存储有该 ONU发来的 注册信息, 若有, 则判定该 ONU合法, 若没有, 则判定该 ONU不合法。 具 体地, 上述注册信息库可以具体为序列号库和 /或密码库。 具体地, 步骤 S306中, OLT 居判断结果对 ONU进行注册激活的处理 包括: 如果该 ONU合法, 则 OLT允许该 ONU完成注册激活过程; 如果该 ONU不合法, 则 OLT拒绝该 ONU进行注册激活, ONU注册激活失败。 图 4 是才艮据本发明实施例的一种光网络单元的注册激活系统的结构框 图, 包括 ONU 42和 OLT 44 , 其中, ONU 42包括: 接收模块 45 , 用于从 OLT 44接收到注册请求; 发送模块 46 , 用于根据自身存储的注册信息的类 型向 OLT 44发送注册信息; OLT 44包括: 判断模块 47 , 用于根据自身存储 的合法 ONU的注册信息和接收到的注册信息对 ONU 42进行合法性判断; 注册激活模块 48 , 用于 居判断结果对 ONU 42进行注册激活的处理。 相关技术中, 由于 ONU 42仅仅向 OLT 44发送 SN, 因此, 若 OLT 44 中未存储 ONU 42的 SN, 此 ONU 42则无法成功注册激活, 在本发明实施例 提供的系统中,通过 ONU 42中的发送模块 46根据自身存储的注册信息的类 型向 OLT 44发送注册信息, 能够更加灵活地发送注册信息, 从而在 ONU 42 的 SN未存储于 OLT 44中时, OLT 44可通过判断模块 47比较 ONU 42的其 他注册信息,判断 ONU 42的合法性,并通过注册激活模块 48实现合法 ONU 42的顺利注册激活, 同时降氏了运营商的运营成本。 图 5 是才艮据本发明实施例的光网络单元的注册激活系统的优选结构框 图, 优选地, 如图 5所示, 发送模块 46包括: 判断模块 52 , 用于判断自身 存储的注册信息是否仅为 ONU 42的序列号信息; 调度模块 54, 用于在判断 模块 52的判断结果为是的情况下, 调度第一发送模块 56, 在判断模块 52的 判断结果为否的情况下, 调度第二发送模块 58; 第一发送模块 56, 用于向 OLT 44发送序列号信息; 第二发送模块 58 , 用于向 OLT 44发送存储的注册 信息的类型中的至少一种类型的注册信息。 该优选结构除了能够支持 ONU 42向 OLT 44发送 SN信息以便注册认证 之外, 还能灵活地实现 ONU 42向 OLT 44发送除 SN之外的注册信息以便 OLT 44进行注册认证, 即使在 OLT 44处没有存储合法 ONU 42的 SN的情 况下, 依然能够使该 ONU 42顺利注册, 极大地方便了 ONU用户, 同时降 低了运营商的运营成本。 下面描述的实施例 1-3 , 综合了上述多个优选实施例的技术方案。 实施例 1 该实施例中, ONU处存储 SN和密码时, ONU发送密码来响应 OLT的 注册请求, ONU发送 SN+密码来响应 OLT发送的测距请求。 步骤 1、 序列号状态的 ONU接收 OLT发来的注册请求, ONU判断自身 存储的注册信息类型, 如果 ONU处仅存储了 ONU的 SN信息, ONU发送 序列号消息给 OLT, OLT和 ONU按照背景技术中的注册激活步骤进行注册 激活过程; 如果 ONU处存储了序列号信息和密码信息, ONU发送密码消息 给 OLT; 步骤 2、 OLT收到 ONU的密码消息后,分配并发送一个唯一的 ONU_ID 给该 ONU, 该 ONU收到所述 ONU_ID后, 进入测距状态; 步骤 3、 测距状态的 ONU接收到 OLT发来的测距请求, 该 ONU在一个 PLOAM消息中发送 SN和密码信息给 OLT,或者该 ONU在两个 PLOAM消 息中分别发送 SN和密码信息给 OLT。 OLT完成该 ONU的均衡时延的测量 后, 将所述均衡时延发送给该 ONU, 该 ONU收到所述均衡时延后进入工作 状态; 步骤 4、 OLT比较 ONU发来的密码与 OLT的密码库中存储的合法密码, 如果 OLT的密码库中包含接收到的 ONU的密码(也就是说, OLT的密码库 中包含与接收到的 ONU的密码一致的密码), 则判定此 ONU为合法 ONU, OLT将第 3步中收到的 SN存储在自身的 SN库中, 更新 SN库, ONU完成 注册激活过程, 该 ONU注册激活成功; 否则判定此 ONU为非法 ONU, OLT 发送去激活 ONU-ID ( Deactivate ONU-ID )消息给所述 ONU, 所述 ONU释 放该 ONU-ID, 并进入待机状态, ONU注册激活过程失败。 在上述注册激活过程中, OLT也可以在第 2步收到 ONU的密码后进行 ONU的合法性判断,如果 OLT的密码库中包含接收到的 ONU的密码(也就 是说, OLT的密码库中包含与接收到的 ONU的密码一致的密码), 则判定此 ONU为合法 ONU, ONU继续进行注册激活过程, OLT在第 3步收到 ONU 发送的 SN后, 将所述 SN存储在自身的 SN库中, 更新 SN库, OLT不需要 进行步骤 4的操作; 否则 OLT拒绝 ONU进行注册激活过程, 所述 ONU注 册激活过程失败。 实施例 2 该实施例中, ONU处存储 SN和密码时, ONU发送 SN和密码来响应 OLT的注册请求, ONU发送 SN+密码来响应 OLT发送的测距请求。 步骤 1、 序列号状态的 ONU接收 OLT发来的注册请求, ONU判断自身 存储的注册信息类型, 如果 ONU处仅存储了 ONU的 SN信息, ONU发送 序列号消息给 OLT, OLT和 ONU按照背景技术中的注册激活步骤进行注册 激活过程;如果 ONU处存储了序列号信息和密码信息, ONU在一个 PLOAM 消息中发送序列号和密码信息给 OLT, 或者该 ONU在两个 PLOAM消息中 分别发送 SN和密码信息给 OLT; 步骤 2、 OLT收到 ONU发送的包含序列号和密码信息的 PLOAM消息 后, 分配并发送一个唯一的 ONU ID给该 ONU, 收到所述 ONU ID后, 该 ONU进入测距状态; 步骤 3、 测距状态的 ONU接收 OLT发来的测距请求, 收到所述测距请 求后, 该 ONU在一个 PLOAM消息中发送 SN和密码信息给 OLT, 或者该 ONU在两个 PLOAM消息中分别发送 SN和密码信息给 OLT。 OLT完成该 ONU的均衡时延的测量后, 将所述均衡时延发送给该 ONU, 该 ONU收到 所述均衡时延后进入工作状态; 步骤 4、 OLT比较 ONU发来的 SN与 OLT的 SN库中存储的合法 SN, 如果 OLT的 SN库中包含接收到的 ONU的 SN (也就是说, OLT的 SN库中 包含与接收到的 ONU的 SN—致的密码),则判定此 ONU为合法 ONU, ONU 注册激活过程完成, 该 ONU注册激活成功, 否则 OLT比较 ONU发来的密 码与 OLT的密码库中存储的合法密码, 如果 OLT的密码库中包含接收到的 ONU的密码(也就是说, OLT的密码库中包含与接收到的 ONU的密码一致 的密码), 则判定此 ONU为合法 ONU, OLT将第 4步中收到的 SN存储在 自身的 SN库中, 更新 SN库, ONU完成注册激活过程, 该 ONU注册激活 成功, 否则判定此 ONU 为非法 ONU , OLT 发送去激活 ONU-ID ( Deactivate ONU-ID )消息给所述 ONU, 所述 ONU释放该 ONU-ID, 并进 入待机状态, ONU注册激活过程失败。 在上述注册激活过程中, OLT也可以在第 2步收到 ONU的 SN和密码 后进行 ONU的合法性判断,如果 OLT通过 ONU的密码信息判定此 ONU为 合法 ONU, OLT将所述 ONU的 SN存储在自身的 SN库中, 更新 SN库, ONU继续进行注册激活过程, OLT不需要进行步骤 4的操作; 否则 OLT拒 绝 ONU进行注册激活过程, 所述 ONU注册激活过程失败。 实施例 3 该实施例中, ONU处存储 SN和密码时, ONU发送 SN/密码 /(SN+密码) 和信息认证码响应 OLT的注册请求, ONU发送 SN/(SN+密码)和信息认证码 响应 OLT发送的测距请求。 步骤 1、 序列号状态的 ONU接收 OLT发来的注册请求, ONU判断自身 存储的注册信息类型, 如果 ONU处仅存储了 ONU的 SN信息, ONU发送 序列号消息给 OLT, OLT和 ONU按照背景技术中的注册激活步骤进行注册 激活过程; 如果 ONU处存储了序列号信息和密码信息, ONU将密码信息作 为密钥, 对 SN信息进行完整性检查的计算, 生成消息认证码。 ONU将所述 SN和所述消息认证码一起发送给所述 OLT。 步骤 2、 所述 OLT在收到所述 ONU发送的上述内容后, OLT比较 ONU发来的 SN与 OLT的 SN库中存储 的合法 SN,如果 OLT的 SN库中包含接收到的 ONU的 SN (也就是说, OLT 的 SN库中包含与接收到的 ONU的 SN—致的 SN ),则 OLT通过 ONU发送 的 SN得到本地存储的对应该 SN的密码信息, OLT将密码信息作为密钥, 对 SN信息进行完整性检查的计算, 生成消息认证码, 如果 OLT处生成的消 息认证码与 ONU发送的消息认证码不同, 所述 ONU注册激活过程失败, 否 则, OLT分配并发送一个唯一的 ONU_ID给该 ONU, 收到所述 ONU_ID后, 该 ONU进入测距状态; 步骤 3、 测距状态的 ONU接收 OLT发来的测距请求, 收到所述测距请 求后, ONU将密码信息作为密钥, 对 SN信息进行完整性检查的计算, 生成 消息认证码。 ONU将所述 SN和所述消息认证码一起发送给所述 OLT。 所述 OLT在收到所述 ONU发送的上述内容后,通过 ONU发送的 SN得到本地存 储的对应该 SN的密码信息, OLT将密码信息作为密钥, 对 SN信息进行完 整性检查的计算, 生成消息认证码, 如果 OLT处生成的消息认证码与 ONU 发送的消息认证码不同, 所述 ONU注册激活过程失败, 否则, OLT完成该 ONU的均衡时延的测量后, 将所述均衡时延发送给该 ONU, 该 ONU收到 所述均衡时延后进入工作状态。 在本实施例的步骤 1 中, ONU发送 SN和消息认证码响应 OLT的注册 请求, 也可以釆用 ONU发送密码和消息认证码响应 OLT的注册请求, ONU 利用密码作为密钥对密码信息进行完整性检查的计算, 生成消息认证码。 ONU将所述密码和所述消息认证码一起发送给所述 OLT。 OLT比较 ONU发 来的密码与 OLT的密码库中存储的合法密码, 如果 OLT的密码库中包含接 收到的 ONU的密码, OLT处也釆用与 ONU处相同的计算方法认证所述密码 信息。 在本实施例的步骤 1和步骤 3中, ONU发送 SN和消息认证码响应 OLT 的注册和测距请求, 也可以釆用 ONU发送 SN、 密码和消息认证码响应 OLT 的注册请求和测距请求, ONU利用密码作为密钥对 SN和密码信息进行完整 性检查的计算, 生成消息认证码。 ONU将所述 SN、 密码和所述消息认证码 一起发送给所述 OLT。 OLT比较 ONU发来的 SN与 OLT的 SN库中存储的 合法 SN, 或者 OLT比较 ONU发来的密码与 OLT的密码库中存储的合法密 码, 如果 OLT的 SN库中包含接收到的 ONU的 SN, 或者如果 OLT的密码 库中包含接收到的 ONU的密码, 则 OLT处也釆用与 ONU处相同的计算方 法认证所述密码信息。 在本实施例中, ONU和 OLT利用 ONU的密码作为计算消息认证码的密 钥, 也可以釆用 OLT发送给 ONU的数据作为密钥, 或者 ONU发送给 OLT 的数据作为密钥, 或者 OLT和 ONU发送给对方的数据组成一个密钥, 也可 以是 OLT和 ONU预先将一个相同的密钥存储在本地。 上述实施例是基于目前 GPON支持的 SN和密码的认证方法, 但是并不 排除 GPON可以支持的基于其他消息,如数字证书、用户名等等的认证方法。 图 6是才艮据本发明实施例的另一种光网络单元 ONU的注册激活方法的 流程图, 该方法包括以下步 4聚: 步骤 S602, ONU从 OLT接收到预定请求, 其中, 预定请求为注册请求 或测 3巨请求; 步骤 S604, ONU向 OLT发送对应预定请求的响应信息和对应响应信息 的消息认证码; 以及 步骤 S606, OLT根据消息认证码对响应信息进行完整性检查,检查通过 后对 ONU进行相应的后续处理 (例如, 若预定请求为注册请求, 则后续可 能进行 ONU-ID的发放、发起测距请求等相应步骤,若预定请求为测距请求, 则后续可能进行测距, 均衡时延发放等相应步骤)。 相关技术中, 恶意 ONU可以获取合法 ONU的 SN信息和 OLT分配给 所述 ONU的 ONU-ID信息,从而恶意返回测距响应,使得合法 ONU进入工 作状态后发送的上行数据与其他合法 ONU发送的上行数据产生冲突, 或使 得合法 ONU的注册激活过程失败。 本发明实施例提供的方法中, ONU发送 响应消息和消息认证码, 保证 OLT正确通过消息认证码判断收到的 ONU响 应的内容是否来自合法 ONU, 从而保证 OLT不向恶意 ONU发送 ONU-ID, 或者, 保证 OLT正确计算合法 ONU的均衡时延以便合法 ONU进行正常的 上行数据传输。 优选地, 步骤 S604之前, ONU根据响应信息和预先设定的密钥生成消 息认证码; OLT根据消息认证码对响应信息进行完整性检查包括: OLT根据 接收到的响应信息和预先设定的密钥生成用于检验的消息认证码, 并比较用 于检验的消息认证码与接收到的消息认证码是否一致, 若是, 则检查通过, 否则, 向 ONU发起去激活 ONU标识 Deactive_ONU-ID消息或者去使能序 列号 Disable Serial Number (简称 Disable)消息。 该方法中, 合法 ONU通过预先设定的密钥生成消息认证码, OLT通过 同样的密钥生成用于检验的消息认证码, 将两者比较即可确定发送该消息的 ONU是否是合法 ONU, 能够防止恶意 ONU仿冒合法 ONU进行测距响应或 注册激活, 且认证过程较简单, 处理速度较快。 优选地, 上述预先设定的密钥可以包括以下至少之一: ONU 的密码、 OLT发送至 ONU的数据、 ONU发送至 OLT的数据、 OLT发送至 ONU的数 据以及 ONU发送至 OLT的数据的组合、 预先存储在 OLT和 ONU的密钥。 图 7是才艮据本发明实施例的另一种光网络单元 ONU的注册激活系统的 结构^ I图, 如图 7所示, 该系统包括 ONU 42和 OLT 44, 其中, ONU 42包 括: 接收模块 72, 用于从 OLT 44接收预定请求, 其中, 预定请求为注册请 求或测距请求; 发送模块 74, 用于向 OLT 44发送对应预定请求的响应信息 和对应响应信息的消息认证码; OLT 44包括: 检查模块 76, 用于才艮据消息 认证码对响应信息进行完整性检查; 处理模块 78, 用于在检查通过的情况下 对 ONU 42进行相应的后续处理。 相关技术中, 恶意 ONU可以获取合法 ONU的 SN信息和 OLT 44分配 给 ONU 42的 ONU-ID信息, 从而恶意返回测 巨响应, 使得合法 ONU进入 工作状态后发送的上行数据与其他合法 ONU发送的上行数据产生冲突, 或 使得合法 ONU的注册激活过程失败。 本发明实施例提供的系统中, ONU 42 中的发送模块 74发送响应消息和消息认证码, 保证 OLT 44的检查模块 76 正确通过消息认证码判断收到的 ONU响应的内容是否来自合法 ONU, 从而 保证 OLT 44正确计算合法 ONU的均衡时延以便合法 ONU进行正常的上行 数据传输。 下面描述的实施例 4, 综合了上述多个优选实施例的技术方案。 实施例 4 该实施例中, ONU发送 SN和信息认证码响应 OLT发送的注册请求和 测 巨请求。 步骤 1、 序列号状态的 ONU接收 OLT发来的注册请求, ONU将密码信 息作为密钥, 对 SN信息进行完整性检查的计算, 生成消息认证码, ONU将 该 SN和计算的消息认证码一起发送给 OLT。 步骤 2、 OLT在收到 ONU发送的上述内容后, 通过 ONU发送的 SN得 到本地存储的对应该 SN的密码信息, OLT将密码信息作为密钥, 对 SN信 息进行完整性检查的计算, 生成消息认证码, 如果 OLT处生成的消息认证码 与 ONU发送的消息认证码不同, 则该 ONU注册激活过程失败, 否则, OLT 分配并发送一个唯一的 ONU_ID给该 ONU, 收到所述 ONU_ID后, 该 ONU 进入测距状态。 步骤 3、 测距状态的 ONU接收 OLT发来的测距请求, 收到测距请求后,
ONU将 OLT发送至 ONU的数据作为密钥,对 SN信息进行完整性检查的计 算, 生成消息认证码。 ONU将该 SN和计算得到的消息认证码一起发送给所 述 OLT。 所述 OLT在收到所述 ONU发送的上述内容后, 通过 ONU发送的 SN确定其发送至 ONU的数据的内容, OLT将该内容作为密钥, 对 SN信息 进行完整性检查的计算, 生成消息认证码, 如果 OLT处生成的消息认证码与 ONU发送的消息认证码不同, 所述 ONU注册激活过程失败, 否则, OLT完 成该 ONU的均衡时延的测量后, 将所述均衡时延发送给该 ONU, 该 ONU 收到所述均衡时延后进入工作状态。 综上所述, 本发明实施例提供的方案解决了相关技术中合法 ONU注册 激活失败的问题, 使得合法 ONU 能够成功注册激活, 提高了用户体验, 同 时降低了运营商的运营成本。 需要说明的是, 在附图的流程图示出的步骤可以在诸如一组计算机可执 行指令的计算机系统中执行, 并且, 虽然在流程图中示出了逻辑顺序, 但是 在某些情况下, 可以以不同于此处的顺序执行所示出或描述的步骤。 显然, 本领域的技术人员应该明白, 上述的本发明的各模块或各步骤可 以用通用的计算装置来实现, 它们可以集中在单个的计算装置上, 或者分布 在多个计算装置所组成的网络上, 可选地, 它们可以用计算装置可执行的程 序代码来实现, 从而, 可以将它们存储在存储装置中由计算装置来执行, 或 者将它们分别制作成各个集成电路模块, 或者将它们中的多个模块或步骤制 作成单个集成电路模块来实现。 这样, 本发明不限制于任何特定的硬件和软 件结合。 以上所述仅为本发明的优选实施例而已, 并不用于限制本发明, 对于本 领域的技术人员来说, 本发明可以有各种更改和变化。 凡在本发明的 ^"神和 原则之内, 所作的任何修改、 等同替换、 改进等, 均应包含在本发明的保护 范围之内。

Claims

权 利 要 求 书
1. 一种光网络单元 ONU的注册激活方法, 其特征在于包括以下步 4聚:
ONU从光线路终端 OLT接收到注册请求;
所述 ONU根据自身存储的注册信息的类型向所述 OLT发送注册信 息; 以及
所述 OLT根据自身存储的合法 ONU的注册信息和接收到的注册信 息对所述 ONU进行合法性判断, 并 居判断结果对所述 ONU进行注册 激活的处理。
2. 根据权利要求 1 所述的方法, 其特征在于, 所述 ONU根据存储的注册 信息的类型向所述 OLT发送注册信息包括:
所述 ONU判断自身存储的注册信息是否仅为所述 ONU的序列号信 息, 若是, 则向所述 OLT发送所述序列号信息, 否则, 向所述 OLT发 送所述存储的注册信息的类型中的至少一种类型的注册信息。
3. 根据权利要求 1所述的方法, 其特征在于, 所述 ONU还向所述 OLT发 送所述注册信息对应的消息认证码;所述 OLT根据自身存储的合法 ONU 的注册信息和接收到的注册信息对所述 ONU 进行合法性判断之前, 还 包括:
所述 OLT根据所述消息认证码对所述注册信息进行完整性检查,检 查通过后进行后续处理。
4. 根据权利要求 3所述的方法, 其特征在于,
所述 ONU向所述 OLT发送所述消息认证码之前, 所述 ONU才艮据 所述注册信息和预先设定的密钥生成所述消息认证码;
所述 OLT 根据所述消息认证码对所述响应信息进行完整性检查包 括: 所述 OLT才艮据接收到的注册信息和所述预先设定的密钥生成用于检 验的消息认证码, 并比较所述用于检验的消息认证码与接收到的消息认 证码是否一致, 若是, 则检查通过, 否则, 向所述 ONU发起去激活 ONU 标识消息或者去使能序列号消息。
5. 根据权利要求 1所述的方法, 其特征在于, 所述 OLT根据自身存储的合 法 ONU的注册信息和接收到的注册信息对所述 ONU进行合法性判断之 前或之后, 还包括:
向所述 ONU发起测距请求;
所述 ONU向所述 OLT发送测距信息和所述测距信息对应的消息认 证码; 以及 所述 OLT根据所述消息认证码对所述测距信息进行完整性检查,检 查通过后测量所述 ONU的均衡时延并将其发送至所述 ONU。
6. 根据权利要求 5所述的方法, 其特征在于,
所述 ONU向所述 OLT发送所述消息认证码之前, 所述 ONU才艮据 所述测距信息和预先设定的密钥生成所述消息认证码;
所述 OLT 根据所述消息认证码对所述测距信息进行完整性检查包 括: 所述 OLT 居接收到的测 巨信息和所述预先设定的密钥生成用于检 验的消息认证码, 并比较所述用于检验的消息认证码与接收到的消息认 证码是否一致, 若是, 则检查通过, 否则, 向所述 ONU发起去激活 ONU 标识消息或者去使能序列号消息。
7. 根据权利要求 4或 6所述的方法, 其特征在于, 所述预先设定的密钥包 括以下至少之一: 所述 ONU的密码、 所述 OLT发送至所述 ONU的数 据、 所述 ONU发送至所述 OLT的数据、 所述 OLT发送至所述 ONU的 数据以及所述 ONU发送至所述 OLT的数据的组合、预先存储在所述 OLT 和所述 ONU的密钥。
8. 根据权利要求 1至 6中任一项所述的方法, 其特征在于, 所述存储的注 册信息包括所述 ONU的序列号信息和 /或所述 ONU的密码信息。
9. 根据权利要求 8所述的方法, 其特征在于, 所述 ONU向所述 OLT发送 所述序列号信息和所述密码信息, 所述 OLT判断所述 ONU合法后, 存 储所述 ONU的所述序列号信息。
10. 根据权利要求 8所述的方法, 其特征在于, 所述 ONU在一个物理层操 作、 管理与维护 PLOAM消息中携带所述序列号信息和所述密码信息并 发送至所述 OLT; 或者, 所述 ONU在两个 PLOAM消息中分别携带所 述序列号信息和所述密码信息并发送至所述 OLT。
11. 一种光网络单元 ONU的注册激活方法, 其特征在于包括以下步 4聚:
ONU从 OLT接收到预定请求, 其中, 所述预定请求为注册请求或 测距请求;
所述 ONU向所述 OLT发送对应所述预定请求的响应信息和对应所 述响应信息的消息认证码; 以及
所述 OLT根据所述消息认证码对所述响应信息进行完整性检查,检 查通过后对所述 ONU进行相应的后续处理。
12. 居权利要求 11所述的方法, 其特征在于, 所述 ONU向所述 OLT发送 所述预定请求对应的响应信息和所述响应信息对应的消息认证码之前, 所述 ONU根据所述响应信息和预先设定的密钥生成所述消息认证码; 所述 OLT 根据所述消息认证码对所述响应信息进行完整性检查包 括: 所述 OLT 居接收到的响应信息和所述预先设定的密钥生成用于检 验的消息认证码, 并比较所述用于检验的消息认证码与接收到的消息认 证码是否一致, 若是, 则检查通过, 否则, 向所述 ONU发起去激活 ONU 标识消息或者去使能序列号消息。
13. 根据权利要求 12所述的方法, 其特征在于, 所述预先设定的密钥包括以 下至少之一: 所述 ONU的密码、 所述 OLT发送至所述 ONU的数据、 所述 ONU发送至所述 OLT的数据、 所述 OLT发送至所述 ONU的数据 以及所述 ONU发送至所述 OLT的数据的组合、预先存储在所述 OLT和 所述 ONU的密钥。
14. 一种光网络单元的注册激活系统, 包括 ONU和 OLT, 其特征在于: 所述 ONU包括:
接收模块, 用于从光线路终端 OLT接收到注册请求;
发送模块, 用于根据自身存储的注册信息的类型向所述 OLT发送注 册信息;
所述 OLT包括:
判断模块, 用于根据自身存储的合法 ONU 的注册信息和接收到的 注册信息对所述 ONU进行合法性判断; 注册激活模块, 用于 居判断结果对所述 ONU进行注册激活的处 理。
15. 根据权利要求 14所述的系统, 其特征在于, 所述发送模块包括:
判断模块, 用于判断自身存储的注册信息是否仅为所述 ONU 的序 列号信息;
调度模块, 用于在所述判断模块的判断结果为是的情况下, 调度第 一发送模块, 在所述判断模块的判断结果为否的情况下, 调度第二发送 模块;
所述第一发送模块, 用于向所述 OLT发送所述序列号信息; 所述第二发送模块,用于向所述 OLT发送所述存储的注册信息的类 型中的至少一种类型的注册信息。
16. —种光网络单元 ONU的注册激活系统,包括 ONU和 OLT,其特征在于: 所述 ONU包括:
接收模块, 用于从 OLT接收预定请求, 其中, 所述预定请求为注册 请求或测距请求; 发送模块, 用于向所述 OLT发送对应所述预定请求的响应信息和对 应所述响应信息的消息认证码;
所述 OLT包括:
检查模块, 用于根据所述消息认证码对所述响应信息进行完整性检 查;
处理模块, 用于在检查通过的情况下对所述 ONU进行相应的后续 处理。
PCT/CN2010/078840 2010-04-13 2010-11-17 光网络单元的注册激活方法及系统 WO2011127731A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201010164964.1A CN102223586B (zh) 2010-04-13 2010-04-13 光网络单元的注册激活方法及系统
CN201010164964.1 2010-04-13

Publications (1)

Publication Number Publication Date
WO2011127731A1 true WO2011127731A1 (zh) 2011-10-20

Family

ID=44779989

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2010/078840 WO2011127731A1 (zh) 2010-04-13 2010-11-17 光网络单元的注册激活方法及系统

Country Status (2)

Country Link
CN (1) CN102223586B (zh)
WO (1) WO2011127731A1 (zh)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103873962A (zh) * 2014-04-09 2014-06-18 上海斐讯数据通信技术有限公司 基于单任务管理的onu认证方法及系统
CN113490081A (zh) * 2021-06-29 2021-10-08 青岛海信宽带多媒体技术有限公司 一种onu网关及pon状态灯的点亮方法

Families Citing this family (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103095725B (zh) * 2013-02-05 2016-04-13 烽火通信科技股份有限公司 基于能力集模板管理onu的方法
CN105359441B (zh) * 2013-05-15 2018-03-02 中兴通讯股份有限公司 使用噪声窗用于未校准的光网络单元激活
WO2014183504A1 (en) * 2013-05-15 2014-11-20 Zte Corporation Using noisy window for uncalibrated optical network unit activation
CN104469561B (zh) * 2015-01-06 2018-01-02 烽火通信科技股份有限公司 Gpon系统中控制非法厂商onu接入能力的方法及装置
CN106162386A (zh) * 2015-04-20 2016-11-23 中兴通讯股份有限公司 一种实现注册的方法和装置
CN104902354A (zh) * 2015-06-18 2015-09-09 深圳市新格林耐特通信技术有限公司 一种gpon系统中灵活安全的ont认证方法
CN110944247B (zh) * 2018-09-25 2022-06-17 中兴通讯股份有限公司 无源光网络系统的数据处理方法、装置及无源光网络系统
CN113395611B (zh) * 2020-03-11 2022-10-21 中国电信股份有限公司 光网络单元和双模光模块注册方法
CN113839707A (zh) * 2020-06-23 2021-12-24 中兴通讯股份有限公司 一种认证方法、装置、设备及存储介质
CN113973032A (zh) * 2020-07-23 2022-01-25 上海诺基亚贝尔股份有限公司 用于光通信的设备、方法、装置及计算机可读介质
CN117768810A (zh) * 2022-09-16 2024-03-26 中兴通讯股份有限公司 光网络单元的注册方法、光线路终端、光网络单元、介质

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101159620A (zh) * 2007-11-26 2008-04-09 中国电信股份有限公司 光网络单元的注册方法
CN101577620A (zh) * 2009-04-10 2009-11-11 北京邮电大学 一种以太网无源光网络(epon)系统认证方法
CN101677414A (zh) * 2008-09-18 2010-03-24 华为技术有限公司 一种实现用户侧终端获取密码的方法、系统和设备
CN101692672A (zh) * 2009-10-19 2010-04-07 中兴通讯股份有限公司 无源光网络中光网络单元的注册方法与装置

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101159620A (zh) * 2007-11-26 2008-04-09 中国电信股份有限公司 光网络单元的注册方法
CN101677414A (zh) * 2008-09-18 2010-03-24 华为技术有限公司 一种实现用户侧终端获取密码的方法、系统和设备
CN101577620A (zh) * 2009-04-10 2009-11-11 北京邮电大学 一种以太网无源光网络(epon)系统认证方法
CN101692672A (zh) * 2009-10-19 2010-04-07 中兴通讯股份有限公司 无源光网络中光网络单元的注册方法与装置

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103873962A (zh) * 2014-04-09 2014-06-18 上海斐讯数据通信技术有限公司 基于单任务管理的onu认证方法及系统
CN103873962B (zh) * 2014-04-09 2018-01-16 上海斐讯数据通信技术有限公司 基于单任务管理的onu认证方法及系统
CN113490081A (zh) * 2021-06-29 2021-10-08 青岛海信宽带多媒体技术有限公司 一种onu网关及pon状态灯的点亮方法
CN113490081B (zh) * 2021-06-29 2024-05-07 青岛海信宽带多媒体技术有限公司 一种onu网关及pon状态灯的点亮方法

Also Published As

Publication number Publication date
CN102223586A (zh) 2011-10-19
CN102223586B (zh) 2015-06-03

Similar Documents

Publication Publication Date Title
WO2011127731A1 (zh) 光网络单元的注册激活方法及系统
US8850197B2 (en) Optical network terminal management control interface-based passive optical network security enhancement
US20120072973A1 (en) Method and apparatus for authentication in passive optical network and passive optical network
CN101902662B (zh) 光网络单元注册激活方法及系统
CN108270749B (zh) 一种虚拟光网络单元的注册方法及系统
WO2009009999A1 (en) Terminal detection authentication method, device and operational management system in passive optical network
CN103210606A (zh) 用于验证光网络单元的无线备份系统的方法
WO2013104987A1 (en) Method for authenticating identity of onu in gpon network
WO2010031269A1 (zh) 一种实现用户侧终端获取密码的方法、系统和设备
WO2011153791A1 (zh) 一种识别恶意光网络单元的方法及系统
US8942378B2 (en) Method and device for encrypting multicast service in passive optical network system
CN109039600B (zh) 一种无源光网络系统中协商加密算法的方法及系统
WO2014101084A1 (zh) 一种认证方法、设备和系统
CN101998180B (zh) 一种支持光线路终端和光网络单元版本兼容的方法及系统
KR100606095B1 (ko) 수동 광가입자망 시스템에서 가입자 인증 후 암호화 키의전달 방법 및 장치
WO2011095022A1 (zh) 一种对发光异常光网络单元正确定位的方法及系统
US20230231728A1 (en) Secure communication method and apparatus in passive optical network
WO2012163022A1 (zh) 光网络系统的认证方法、光网络终端及光网络系统
JP2013175835A (ja) 光通信ネットワークシステム、子局通信装置、親局通信装置、及び制御方法
WO2015077943A1 (zh) 无源光网络上行带宽分配的方法、装置及系统
WO2013155712A1 (zh) 密钥交换方法及装置、网元
JP2008236674A (ja) 加入者側光回線終端装置
WO2017028807A1 (zh) 光传送网的身份验证方法、装置及系统

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 10849740

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 10849740

Country of ref document: EP

Kind code of ref document: A1