WO2018068671A1 - Pon承载小基站回传的网络安全防护的方法及系统 - Google Patents

Pon承载小基站回传的网络安全防护的方法及系统 Download PDF

Info

Publication number
WO2018068671A1
WO2018068671A1 PCT/CN2017/104833 CN2017104833W WO2018068671A1 WO 2018068671 A1 WO2018068671 A1 WO 2018068671A1 CN 2017104833 W CN2017104833 W CN 2017104833W WO 2018068671 A1 WO2018068671 A1 WO 2018068671A1
Authority
WO
WIPO (PCT)
Prior art keywords
vlan
base station
small base
backhaul
pon
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2017/104833
Other languages
English (en)
French (fr)
Inventor
钱凯
熊慧
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Fiberhome Telecommunication Technologies Co Ltd
Original Assignee
Fiberhome Telecommunication Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Fiberhome Telecommunication Technologies Co Ltd filed Critical Fiberhome Telecommunication Technologies Co Ltd
Priority to MYPI2019000206A priority Critical patent/MY200171A/en
Publication of WO2018068671A1 publication Critical patent/WO2018068671A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/02Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04BTRANSMISSION
    • H04B10/00Transmission systems employing electromagnetic waves other than radio-waves, e.g. infrared, visible or ultraviolet light, or employing corpuscular radiation, e.g. quantum communication
    • H04B10/80Optical aspects relating to the use of optical transmission for specific applications, not provided for in groups H04B10/03 - H04B10/70, e.g. optical power feeding or optical transmission through water
    • H04B10/85Protection from unauthorised access, e.g. eavesdrop protection
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/46Interconnection of networks
    • H04L12/4641Virtual LANs, VLANs, e.g. virtual private networks [VPN]

Definitions

  • the present invention relates to the field of passive optical networks, and in particular, to a method and system for network security protection of a PON bearer small base station backhaul.
  • PON Passive Optical Network
  • IPTV Internet Protocol Television
  • IP TV/interactive network TV IP TV/interactive network TV
  • the small base station is a small, low-power cellular technology. It is mainly used in indoor places such as homes and small and medium-sized enterprises offices through fixed-line broadband backhaul. It is used as a supplement to indoor coverage of cellular networks to provide users with voice and high-speed data services. For subsequent small-scale base stations such as scale deployment, PON backhaul is the only feasible scale deployment solution. Therefore, the PON technology can realize the integrated access of fixed broadband and small base stations for residential users in the future.
  • the mobile backhaul network where the small base station is located is a closed network. It is necessary to prevent someone from intercepting and eavesdropping data on the mobile backhaul network, so as to obtain some sensitive data on the base station device, and the PON can carry multiple services. On the PON network, there are a variety of services mixed. How to realize the isolation of services and the protection between different services, especially the isolation of mobile backhaul networks, is a problem that needs to be solved.
  • VLAN virtual local area network
  • the purpose of the present invention is to overcome the deficiencies of the foregoing background, and to provide a method and system for network security protection of a PON bearer small base station backhaul, which can implement isolation between different services within the PON system.
  • the invention provides a method for network security protection of a PON carrying a small base station backhaul, comprising the following steps:
  • VLAN virtual local area network
  • the port number of the ONU of the optical network unit that carries the backhaul service of the small base station, and the port of the designated ONU is dedicated to carry the small base station backhaul;
  • the PON system periodically dynamically assigns the VLAN number of the small cell backhaul service, and dynamically sends the VLAN configuration to the corresponding ONU port.
  • the ONU After receiving the VLAN configuration, the ONU dynamically generates a corresponding configuration to implement communication of the small base station backhaul service.
  • the range of the VLAN address pool is: 1 to 4095.
  • the VLAN for configuring the common data service is 100
  • the VLAN pool for the backhaul service of the user small base station is 200 to 4000.
  • step S3 in the PON system, the master disk of the OLT dynamically assigns the VLAN number of the small cell backhaul service every 60 seconds, and the VLAN number range is randomly selected from 200 to 4000.
  • the invention also provides a system for network security protection of a PON carrying small base station backhaul, the system comprising a virtual local area network VLAN pool division unit, an optical network unit ONU, a port number designation unit, and a VLAN dynamic allocation unit, wherein:
  • the VLAN pool dividing unit is configured to: plan a segment of a VLAN address pool in the PON system of the passive optical network, where the VLAN address pool is specifically used by the user small base station to return the network, and does not overlap with the VALN of other services;
  • the port number specifying unit is configured to: specify a port number of the ONU that carries the backhaul service of the small base station, and the port of the designated ONU is dedicated to carry the small base station backhaul;
  • the VLAN dynamic allocation unit is configured to periodically dynamically assign a VLAN number of the small base station backhaul service, and dynamically send the VLAN configuration to the corresponding ONU port;
  • the ONU After receiving the VLAN configuration delivered by the VLAN dynamic allocation unit, the ONU dynamically generates the corresponding configuration to implement the communication of the small base station backhaul service.
  • the range of the VLAN address pool is: 1 to 4095.
  • the VLAN for configuring the common data service is 100
  • the VLAN pool for the backhaul service of the user small base station is 200 to 4000.
  • the VLAN dynamic allocation unit dynamically assigns the VLAN number of the small base station backhaul service every 60 seconds, and the VLAN number range is randomly selected from 200 to 4000.
  • the present invention plans a segment of a VLAN address pool in a PON system, the VLAN The address pool is reserved for the user's small base station to return to the network, and does not overlap with the VALN of other services; the port number of the ONU that carries the small base station backhaul service is specified, and the port of the designated ONU is dedicated to carry the small base station backhaul; the PON system
  • the VLAN number of the small-base station backhaul service is dynamically assigned periodically, and the VLAN configuration is dynamically sent to the corresponding ONU port. After receiving the VLAN configuration, the ONU dynamically generates the corresponding configuration to implement the communication of the small base station backhaul service. .
  • the invention dynamically allocates VLANs by dividing a VLAN pool, and can implement isolation between different services within the PON system.
  • the present invention can ensure that a VLAN carrying a small base station backhaul service is not easily captured, and functions as a network isolation and a certain anti-interception and anti-eavesdrop function.
  • test can ensure that the service will not generate an interruption, and at the same time, it will not increase the data delay, and can ensure that the corresponding operation does not affect the normal data service.
  • FIG. 1 is a structural block diagram of a PON system
  • FIG. 2 is a flowchart of a method for network security protection of a PON bearer small base station backhaul according to an embodiment of the present invention.
  • FIG. 3 is a schematic diagram of an application example of dynamically allocating VLANs based on dividing a VLAN pool according to an embodiment of the present invention.
  • an embodiment of the present invention provides a method for network security protection of a PON carrying a small base station backhaul, including the following steps:
  • a VLAN address pool is planned in the PON system.
  • the range of the VLAN address pool is 1 to 4095.
  • the VLAN address pool is reserved for the user to return the network to the small base station. Does not overlap with VALN of other services;
  • the VLAN for configuring the common data service is 100
  • the VLAN pool for the small cell backhaul service is 200 to 4000.
  • the port number of the ONU (Optical Network Unit) that carries the backhaul service of the small base station, and the port of the designated ONU is dedicated to carry the small base station backhaul, and cannot be used for other purposes;
  • the port user of the ONU1 carries the normal data service, and the ONU2 is used to carry the small base station backhaul. All the ports are small cell backhaul service ports.
  • the PON system periodically dynamically assigns the VLAN number of the small cell backhaul service, and dynamically sends the VLAN configuration to the corresponding ONU port.
  • the OLT's main control disk dynamically assigns the VLAN number of the small cell backhaul service every 60 seconds.
  • the VLAN number range is randomly selected from 200 to 4000 and sent to the ONU2.
  • the ONU After receiving the VLAN configuration, the ONU dynamically generates a corresponding configuration to implement communication of the small base station backhaul service.
  • the ONU2 dynamically modifies the service VLAN on the ONU port.
  • a 1:1 VLAN translation is implemented on the port of the ONU, and the data VLAN sent by the small base station is implemented.
  • Translated into the VLAN number transmitted internally by the PON system that is, the VLAN number sent by the main control panel to ensure that the configuration of the small base station can be dynamically changed.
  • the VLAN configuration inside the PON system is changed, and the corresponding uplink port on the OLT is implemented.
  • There will also be a 1:1 VLAN translation service that translates the VLAN number passed inside the PON system to the VLAN supported by the uplink device.
  • the method can ensure that the VLAN carrying the backhaul service of the small base station is not easy to be captured, and the network isolation and certain anti-interception and anti-eavesdrop functions are performed.
  • the instrument test data service is directly used in FIG. 3, and the test can ensure the service is not guaranteed. Will generate an interruption, the same It will not increase the data delay, and it can guarantee that the corresponding operation will not affect the normal data service.
  • the embodiment of the invention further provides a network security protection system for a PON bearer small cell backhaul, comprising a VLAN pool dividing unit, an ONU, a port number specifying unit, and a VLAN dynamic allocating unit, wherein:
  • the VLAN pool division unit is used to: plan a segment of a VLAN address pool in the PON system.
  • the range of the VLAN address pool is from 1 to 4095.
  • the VLAN address pool is reserved for the user to return the network to the small base station, and does not overlap with the VALN of other services. ;
  • the VLAN for configuring the common data service is 100
  • the VLAN pool for the small cell backhaul service is 200 to 4000.
  • the port number specifying unit is configured to: specify a port number of an ONU (Optical Network Unit) that carries the backhaul service of the small base station, and the port of the designated ONU is dedicated to carry the small base station backhaul, and cannot be used for other use;
  • ONU Optical Network Unit
  • the port user of the ONU1 carries the normal data service, and the ONU2 is used to carry the small base station backhaul. All the ports are small cell backhaul service ports.
  • the VLAN dynamic allocation unit is configured to: periodically dynamically assign the VLAN number of the small base station backhaul service, and dynamically send the VLAN configuration to the corresponding ONU port;
  • the VLAN dynamic allocation unit dynamically assigns the VLAN number of the backhaul service of the small base station every 60 seconds.
  • the VLAN number range is randomly selected from 200 to 4000 and sent to the four ports of the ONU2.
  • the ONU After receiving the VLAN configuration delivered by the VLAN dynamic allocation unit, the ONU dynamically generates the corresponding configuration to implement the communication of the small base station backhaul service.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • Electromagnetism (AREA)
  • Small-Scale Networks (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本发明公开了一种PON承载小基站回传的网络安全防护的方法及系统,涉及无源光网络领域。该方法包括以下步骤:在PON系统中规划一段VLAN地址池,所述VLAN地址池专门供用户小基站回传网络使用,与其他业务的VALN不重叠;指定承载小基站回传业务的ONU的端口号,被指定的ONU的端口被专用来承载小基站回传;PON系统定期动态指派小基站回传业务的VLAN号,并动态的将这个VLAN配置下发到相应的ONU的端口上;ONU接收到VLAN配置后,动态生成相应的配置,实现小基站回传业务的通信。本发明能够在PON系统内部实现不同业务之间的隔离。

Description

PON承载小基站回传的网络安全防护的方法及系统 技术领域
本发明涉及无源光网络领域,具体是涉及一种PON承载小基站回传的网络安全防护的方法及系统。
背景技术
PON(Passive Optical Network,无源光网络)技术是最新一代宽带无源光综合接入标准,具有高带宽、高效率、大覆盖范围、用户接口丰富等众多优点,被大多数运营商视为实现接入网业务宽带化、综合化改造的理想技术。参见图1所示,PON系统可以为用户提供数据、语音、IPTV(Internet Protocol Television,IP电视/交互式网络电视)等多种业务,真正实现三网融合。
小基站是一种小型、低功率蜂窝技术,通过固网宽带回程,主要用于家庭及中小企业办公室等室内场所,作为蜂窝网在室内覆盖的补充,为用户提供话音及高速数据业务。后续小基站如规模部署,采用PON回传是唯一可行的规模部署方案。由此,通过PON技术可实现未来住宅用户固定宽带、小基站一体化接入。
使用PON承载小基站回传,网络安全防护是一个亟待解决的重要问题。小基站所在的移动回传网络本身是一个封闭的网络,需要防止有人对移动回传网络上的数据进行截获和窃听,从而获取基站设备上的一些敏感数据,而PON由于可以承载多种业务,PON网络上是存在多种业务混合的情况的,如何实现业务的隔离和不同业务之间的保护,特别是对移动回传网络的隔离,是需要重点解决的问题。
目前PON系统上实现业务隔离主要是通过划分VLAN(Virtual Local Area Network,虚拟局域网)的方法来实现,但是静态的划分VLAN容易被检测到,使用相应的设备也可以发送相同VLAN的数据侵入到对应VLAN的网络中,存在一定的安全隐患。
发明内容
本发明的目的是为了克服上述背景技术的不足,提供一种PON承载小基站回传的网络安全防护的方法及系统,能够在PON系统内部实现不同业务之间的隔离。
本发明提供一种PON承载小基站回传的网络安全防护的方法,包括以下步骤:
S1、在无源光网络PON系统中规划一段虚拟局域网VLAN地址池,所述VLAN地址池专门供用户小基站回传网络使用,与其他业务的VALN不重叠;
S2、指定承载小基站回传业务的光网络单元ONU的端口号,被指定的ONU的端口被专用来承载小基站回传;
S3、PON系统定期动态指派小基站回传业务的VLAN号,并动态的将这个VLAN配置下发到相应的ONU的端口上;
S4、ONU接收到VLAN配置后,动态生成相应的配置,实现小基站回传业务的通信。
在上述技术方案的基础上,所述VLAN地址池的范围为:1~4095。
在上述技术方案的基础上,所述VLAN地址池中,配置普通数据业务的VLAN为100,用户小基站回传业务的VLAN池为200~4000。
在上述技术方案的基础上,步骤S3中,所述PON系统中, OLT的主控盘每隔60秒,动态指派小基站回传业务的VLAN号,VLAN号范围从200~4000中随机选取。
本发明还提供一种PON承载小基站回传的网络安全防护的系统,该系统包括虚拟局域网VLAN池划分单元、光网络单元ONU、端口号指定单元、VLAN动态分配单元,其中:
所述VLAN池划分单元用于:在无源光网络PON系统中规划一段VLAN地址池,所述VLAN地址池专门供用户小基站回传网络使用,与其他业务的VALN不重叠;
所述端口号指定单元用于:指定承载小基站回传业务的ONU的端口号,被指定的ONU的端口被专用来承载小基站回传;
所述VLAN动态分配单元用于:定期动态指派小基站回传业务的VLAN号,并动态的将这个VLAN配置下发到相应的ONU的端口上;
ONU接收到VLAN动态分配单元下发的VLAN配置后,动态生成相应的配置,实现小基站回传业务的通信。
在上述技术方案的基础上,所述VLAN地址池的范围为:1~4095。
在上述技术方案的基础上,所述VLAN地址池中,配置普通数据业务的VLAN为100,用户小基站回传业务的VLAN池为200~4000。
在上述技术方案的基础上,所述VLAN动态分配单元每隔60秒,动态指派小基站回传业务的VLAN号,VLAN号范围从200~4000中随机选取。
与现有技术相比,本发明的优点如下:
(1)本发明在PON系统中规划一段VLAN地址池,所述VLAN 地址池专门供用户小基站回传网络使用,与其他业务的VALN不重叠;指定承载小基站回传业务的ONU的端口号,被指定的ONU的端口被专用来承载小基站回传;PON系统定期动态指派小基站回传业务的VLAN号,并动态的将这个VLAN配置下发到相应的ONU的端口上;ONU接收到VLAN配置后,动态生成相应的配置,实现小基站回传业务的通信。本发明通过划分VLAN池,动态分配VLAN,能够在PON系统内部实现不同业务之间的隔离。
(2)经过实际测试,本发明能够保证承载小基站回传业务的VLAN不易被捕获,起到网络隔离和一定的防截获和防窃听功能。
(3)如果直接使用仪表测试数据业务,测试可以保证业务不会产生中断,同时还不会增加数据延迟,能够保证相应的操作不会影响到正常的数据业务。
附图说明
图1是PON系统的结构框图;
图2是本发明实施例中PON承载小基站回传的网络安全防护的方法的流程图。
图3是本发明实施例中基于划分VLAN池动态分配VLAN的应用实例示意图。
具体实施方式
下面结合附图及具体实施例对本发明作进一步的详细描述。
参见图2所示,本发明实施例提供一种PON承载小基站回传的网络安全防护的方法,包括以下步骤:
S1、在PON系统中规划一段VLAN地址池,VLAN地址池的范围为:1~4095,这段VLAN地址池专门供用户小基站回传网络使用, 与其他业务的VALN不重叠;
参见图3所示,VLAN地址池中,配置普通数据业务的VLAN为100,用户小基站回传业务的VLAN池为200~4000;
S2、指定承载小基站回传业务的ONU(Optical Network Unit,光网络单元)的端口号,被指定的ONU的端口被专用来承载小基站回传,不能用来做其它的用途;
参见图3所示,ONU1的端口用户承载普通数据业务,ONU2专门用于承载小基站回传,所有端口都是小基站回传业务端口;
S3、PON系统定期动态指派小基站回传业务的VLAN号,并动态的将这个VLAN配置下发到相应的ONU的端口上;
参见图3所示,PON系统中,OLT的主控盘每隔60秒,动态指派小基站回传业务的VLAN号,VLAN号范围从200~4000中随机选取,并下发到ONU2的4个端口上;
S4、ONU接收到VLAN配置后,动态生成相应的配置,实现小基站回传业务的通信。
参见图3所示,ONU2接收到OLT主控盘的配置后,动态修改ONU端口上的业务VLAN,这时在ONU的端口上会实现一个1:1的VLAN翻译,将小基站发出的数据VLAN翻译为PON系统内部传送的VLAN号,也就是主控盘下发的VLAN号,以保证小基站的配置可以不同动态改变,改变的是PON系统内部的VLAN配置,相应的在OLT的上联口也会有一个1:1的VLAN翻译业务,将PON系统内部传递的VLAN号转换为上联设备支持的VLAN。
经过实际测试,该方法可以保证承载小基站回传业务的VLAN不易被捕获,起到网络隔离和一定的防截获和防窃听功能,同时如图3直接使用仪表测试数据业务,测试可以保证业务不会产生中断,同 时还不会增加数据延迟,能够保证相应的操作不会影响到正常的数据业务。
本发明实施例还提供一种PON承载小基站回传的网络安全防护的系统,包括VLAN池划分单元、ONU、端口号指定单元、VLAN动态分配单元,其中:
VLAN池划分单元用于:在PON系统中规划一段VLAN地址池,VLAN地址池的范围为:1~4095,这段VLAN地址池专门供用户小基站回传网络使用,与其他业务的VALN不重叠;
参见图3所示,VLAN地址池中,配置普通数据业务的VLAN为100,用户小基站回传业务的VLAN池为200~4000;
端口号指定单元用于:指定承载小基站回传业务的ONU(Optical Network Unit,光网络单元)的端口号,被指定的ONU的端口被专用来承载小基站回传,不能用来做其它的用途;
参见图3所示,ONU1的端口用户承载普通数据业务,ONU2专门用于承载小基站回传,所有端口都是小基站回传业务端口;
VLAN动态分配单元用于:定期动态指派小基站回传业务的VLAN号,并动态的将这个VLAN配置下发到相应的ONU的端口上;
参见图3所示,VLAN动态分配单元每隔60秒,动态指派小基站回传业务的VLAN号,VLAN号范围从200~4000中随机选取,并下发到ONU2的4个端口上;
ONU接收到VLAN动态分配单元下发的VLAN配置后,动态生成相应的配置,实现小基站回传业务的通信。
本领域的技术人员可以对本发明实施例进行各种修改和变型,倘若这些修改和变型在本发明权利要求及其等同技术的范围之内,则这些修改和变型也在本发明的保护范围之内。
说明书中未详细描述的内容为本领域技术人员公知的现有技术。

Claims (8)

  1. 一种PON承载小基站回传的网络安全防护的方法,其特征在于,包括以下步骤:
    S1、在无源光网络PON系统中规划一段虚拟局域网VLAN地址池,所述VLAN地址池专门供用户小基站回传网络使用,与其他业务的VALN不重叠;
    S2、指定承载小基站回传业务的光网络单元ONU的端口号,被指定的ONU的端口被专用来承载小基站回传;
    S3、PON系统定期动态指派小基站回传业务的VLAN号,并动态的将这个VLAN配置下发到相应的ONU的端口上;
    S4、ONU接收到VLAN配置后,动态生成相应的配置,实现小基站回传业务的通信。
  2. 如权利要求1所述的PON承载小基站回传的网络安全防护的方法,其特征在于:所述VLAN地址池的范围为:1~4095。
  3. 如权利要求2所述的PON承载小基站回传的网络安全防护的方法,其特征在于:所述VLAN地址池中,配置普通数据业务的VLAN为100,用户小基站回传业务的VLAN池为200~4000。
  4. 如权利要求3所述的PON承载小基站回传的网络安全防护的方法,其特征在于:步骤S3中,所述PON系统中,OLT的主控盘每隔60秒,动态指派小基站回传业务的VLAN号,VLAN号范围从200~4000中随机选取。
  5. 一种PON承载小基站回传的网络安全防护的系统,其特征在于:该系统包括虚拟局域网VLAN池划分单元、光网络单元ONU、端口号指定单元、VLAN动态分配单元,其中:
    所述VLAN池划分单元用于:在无源光网络PON系统中规划一 段VLAN地址池,所述VLAN地址池专门供用户小基站回传网络使用,与其他业务的VALN不重叠;
    所述端口号指定单元用于:指定承载小基站回传业务的ONU的端口号,被指定的ONU的端口被专用来承载小基站回传;
    所述VLAN动态分配单元用于:定期动态指派小基站回传业务的VLAN号,并动态的将这个VLAN配置下发到相应的ONU的端口上;
    ONU接收到VLAN动态分配单元下发的VLAN配置后,动态生成相应的配置,实现小基站回传业务的通信。
  6. 如权利要求5所述的PON承载小基站回传的网络安全防护的系统,其特征在于:所述VLAN地址池的范围为:1~4095。
  7. 如权利要求6所述的PON承载小基站回传的网络安全防护的系统,其特征在于:所述VLAN地址池中,配置普通数据业务的VLAN为100,用户小基站回传业务的VLAN池为200~4000。
  8. 如权利要求7所述的PON承载小基站回传的网络安全防护的系统,其特征在于:所述VLAN动态分配单元每隔60秒,动态指派小基站回传业务的VLAN号,VLAN号范围从200~4000中随机选取。
PCT/CN2017/104833 2016-10-10 2017-09-30 Pon承载小基站回传的网络安全防护的方法及系统 Ceased WO2018068671A1 (zh)

Priority Applications (1)

Application Number Priority Date Filing Date Title
MYPI2019000206A MY200171A (en) 2016-10-10 2017-09-30 Network security protection method and system using pon to bear small base station backhaul

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201610883427.XA CN106453307B (zh) 2016-10-10 2016-10-10 Pon承载小基站回传的网络安全防护的方法及系统
CN201610883427.X 2016-10-10

Publications (1)

Publication Number Publication Date
WO2018068671A1 true WO2018068671A1 (zh) 2018-04-19

Family

ID=58172283

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2017/104833 Ceased WO2018068671A1 (zh) 2016-10-10 2017-09-30 Pon承载小基站回传的网络安全防护的方法及系统

Country Status (3)

Country Link
CN (1) CN106453307B (zh)
MY (1) MY200171A (zh)
WO (1) WO2018068671A1 (zh)

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106453307B (zh) * 2016-10-10 2019-03-15 烽火通信科技股份有限公司 Pon承载小基站回传的网络安全防护的方法及系统
CN109905884B (zh) * 2017-12-07 2022-03-08 中国电信股份有限公司 室内覆盖系统
CN112584393B (zh) * 2019-09-27 2022-07-22 上海华为技术有限公司 一种基站配置方法、装置、设备及介质
CN111147345B (zh) * 2019-12-20 2022-01-07 航天信息股份有限公司 云环境网络隔离装置、方法及云系统

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20100220731A1 (en) * 2009-02-27 2010-09-02 Wael William Diab Method and system for supporting a plurality of providers via a single femtocell
CN102394776A (zh) * 2011-11-02 2012-03-28 深圳市共进电子股份有限公司 无源光网络中olt对onu进行动态网络配置的方法
CN104717030A (zh) * 2013-12-17 2015-06-17 中国移动通信集团公司 时间同步方法及相应设备、系统
CN105991738A (zh) * 2015-02-27 2016-10-05 中国移动通信集团四川有限公司 一种云资源池中跨安全域资源共享的方法及系统
CN106453307A (zh) * 2016-10-10 2017-02-22 烽火通信科技股份有限公司 Pon承载小基站回传的网络安全防护的方法及系统

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR100480366B1 (ko) * 2002-12-24 2005-03-31 한국전자통신연구원 E-pon의 가상 랜 구성 시스템 및 방법, 그 프로그램이 저장된 기록매체
CN103369616B (zh) * 2013-07-09 2016-08-10 京信通信系统(中国)有限公司 一种双模组网下的数据传输方法及装置
CN103840996B (zh) * 2014-03-03 2017-08-01 烽火通信科技股份有限公司 光网络单元中实现用户端口vlan业务管理的方法及系统

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20100220731A1 (en) * 2009-02-27 2010-09-02 Wael William Diab Method and system for supporting a plurality of providers via a single femtocell
CN102394776A (zh) * 2011-11-02 2012-03-28 深圳市共进电子股份有限公司 无源光网络中olt对onu进行动态网络配置的方法
CN104717030A (zh) * 2013-12-17 2015-06-17 中国移动通信集团公司 时间同步方法及相应设备、系统
CN105991738A (zh) * 2015-02-27 2016-10-05 中国移动通信集团四川有限公司 一种云资源池中跨安全域资源共享的方法及系统
CN106453307A (zh) * 2016-10-10 2017-02-22 烽火通信科技股份有限公司 Pon承载小基站回传的网络安全防护的方法及系统

Also Published As

Publication number Publication date
MY200171A (en) 2023-12-11
CN106453307A (zh) 2017-02-22
CN106453307B (zh) 2019-03-15

Similar Documents

Publication Publication Date Title
US12058514B2 (en) Virtual tenant for multiple dwelling unit
WO2018068671A1 (zh) Pon承载小基站回传的网络安全防护的方法及系统
CN104243206B (zh) 实现对onu无线功能集中配置和管理的系统及方法
CN105515772A (zh) 信息处理方法、网络节点、验证方法和服务器
WO2012100716A1 (zh) 在无源光网络中实现家庭网关功能的方法及装置
CN102394776B (zh) 无源光网络中olt对onu进行动态网络配置的方法
CN105611648A (zh) 一种无线中继设备的中继方法及无线中继设备
EP2153587A1 (en) Legal intercept of communication traffic particularly useful in a mobile environment
CN106488525B (zh) 一种ip动态绑定的无线网络构建方法及相应网络架构
CN104539743A (zh) 一种云计算系统及其控制方法
CN104113602B (zh) 一种基于物名的物联网设备访问管理系统及方法
CN110166270A (zh) 热备切换处理方法、设备及存储介质
CN105530200B (zh) 不同终端业务的vlan分配方法
WO2021089169A1 (en) Private sub-networks for virtual private networks (vpn) clients
KR101786620B1 (ko) 소프트웨어 정의 네트워크에서 서브넷을 지원하는 방법, 장치 및 컴퓨터 프로그램
CN105635335B (zh) 社会资源接入方法、装置及系统
WO2016202023A1 (zh) 路由信息生成方法及装置
WO2016078375A1 (zh) 数据传送方法及装置
CN113364661B (zh) 综合组网方法、装置、电子设备及计算机可读介质
WO2021002036A1 (ja) 光加入者線終端装置、通信ネットワークシステム及び通信方法
WO2016078325A1 (zh) 数据传送方法及装置
BR112019001085B1 (pt) Método e sistema de proteção de segurança de rede para backhaul de célula pequena baseado em pon
CN207588865U (zh) 网络接入系统
CN101217458A (zh) 一种虚拟私有网上资源分配的方法及路由器和系统
CN105812499B (zh) 通信方法和通信系统及虚拟客户终端设备

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 17860256

Country of ref document: EP

Kind code of ref document: A1

REG Reference to national code

Ref country code: BR

Ref legal event code: B01A

Ref document number: 112019001085

Country of ref document: BR

NENP Non-entry into the national phase

Ref country code: DE

REG Reference to national code

Ref country code: BR

Ref legal event code: B01E

Ref document number: 112019001085

Country of ref document: BR

Free format text: REAPRESENTE A DECLARACAO REFERENTE AO DOCUMENTO DE PRIORIDADE DEVIDAMENTE ASSINADA, CONFORME ART. 408 C/C ART. 410, II, DO CODIGO DE PROCESSO CIVIL.

ENP Entry into the national phase

Ref document number: 112019001085

Country of ref document: BR

Kind code of ref document: A2

Effective date: 20190118

122 Ep: pct application non-entry in european phase

Ref document number: 17860256

Country of ref document: EP

Kind code of ref document: A1