WO2016169260A1 - Procédé, dispositif et système d'authentification et d'enregistrement pour module d'accès optique - Google Patents
Procédé, dispositif et système d'authentification et d'enregistrement pour module d'accès optique Download PDFInfo
- Publication number
- WO2016169260A1 WO2016169260A1 PCT/CN2015/094729 CN2015094729W WO2016169260A1 WO 2016169260 A1 WO2016169260 A1 WO 2016169260A1 CN 2015094729 W CN2015094729 W CN 2015094729W WO 2016169260 A1 WO2016169260 A1 WO 2016169260A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- volt
- access module
- optical access
- management
- optical
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04Q—SELECTING
- H04Q11/00—Selecting arrangements for multiplex systems
Definitions
- the present invention relates to the field of communications, and in particular to a method, device, and system for authenticating an optical access module.
- the passive optical network device can be divided into an Ethernet-based passive optical network device (Ethernet Passive Optical Network, EPON for short) and a Gigabit-capable Passive Optical Network (G).
- XG-PON 10G Gigabit-capable passive optical networks
- NGPON2 Next Next Passive Optical Networks
- Passive optical network devices have a consistent system architecture, including Optical Line Terminals (OLTs) and Optical Network Units (ONUs).
- OLTs Optical Line Terminals
- ONUs Optical Network Units
- a centralized OLT device discovers changes in the state of the PON port through power-up and loading of the integrated PON line card.
- vOLT virtualized optical line terminal
- the discovery and management mechanism of the PON port under the traditional centralized OLT architecture is no longer applicable.
- vOLT is the management and control center of the entire system. How to solve the authentication and registration of optical access modules has become an urgent problem to be solved.
- the vOLT cannot effectively authenticate the optical access module, and no effective solution has been proposed yet.
- the vOLT cannot effectively register the optical access module
- the present invention provides an authentication registration method, device, and system for the optical access module, to at least solve the above problem.
- a method for authenticating an optical access module including: a virtualized optical line terminal vOLT receiving physical location information of an optical access module and a device identifier of the optical access module; The vOLT authenticates the optical access module according to the device identifier of the optical access module; if the vOLT authenticates the optical access module, the vOLT corresponds to the physical location information.
- the optical access module sends management configuration information, and the vOLT establishes a management channel with the optical access module according to the management configuration information.
- the vOLT in the case that the vOLT is authenticated by the optical access module, the vOLT sends the management configuration information to the optical access module, including at least one of: at the vOLT
- the vOLT receives a management IP request of the optical access module, and the vOLT delivers the optical The management MAC and the management IP configured by the access module; in the case that the vOLT is authenticated by the optical access module, and the optical access module initiates 802.1x authentication, the vOLT passes the local area network The extended authentication protocol EAPoL replies to the optical access module, and the vOLT carries the management MAC and management IP of the vOLT by a type length value TLV.
- the vOLT establishes a management channel with the optical access module according to the management configuration information, and includes at least one of the following: establishing, by using the management IP, the optical access module and the vOLT A channel is established between the optical access module and the vOLT through an Ethernet maintenance communication channel ETH-MCC.
- the physical location information of the optical access module includes: a port number where the optical access module is located, and a slot number where the optical access module is located.
- the device identifier of the optical access module includes: a MAC address of the optical access module, and a sequence number of the optical access module.
- an authentication registration method for an optical access module including: an authentication request of a first vOLT of the plurality of virtualized optical line terminals vOLT to receive an optical access module; The vOLT forwards the authentication request to the centralized authentication and authorization charging AAA server; when the AAA server authenticates the optical access module, the first vOLT sends a corresponding response to the optical access module.
- vOLT management configuration information including: an authentication request of a first vOLT of the plurality of virtualized optical line terminals vOLT to receive an optical access module; The vOLT forwards the authentication request to the centralized authentication and authorization charging AAA server; when the AAA server authenticates the optical access module, the first vOLT sends a corresponding response to the optical access module.
- the sending, by the first vOLT, the corresponding vOLT management configuration information to the optical access module includes: sending, by the first vOLT, an 802.1x response message to the optical access module,
- the response message includes: a management IP of the corresponding vOLT and a MAC of the corresponding vOLT; the first vOLT allocates a management IP of the vOLT corresponding to the optical access module by using a dynamic host configuration protocol subsequent protocol.
- an authentication registration method of an optical access module including: when the access aggregation device finds that the optical access module is in place, accessing the convergence device to read Receiving the device identifier of the optical access module; the access aggregation device reporting the physical location information of the optical access module and the device identifier of the optical access module to the virtualized optical line terminal vOLT; receiving the vOLT An authentication message of the optical access module, where the vOLT authenticates the optical access module according to the device identifier of the optical access module.
- the method further includes: The access aggregation device receives the notification of the management IP and the interface information of the vOLT; the access aggregation device notifies the vOLT of the management IP and interface information of the access aggregation device; the access aggregation device and the The vOLT establishes a management control channel.
- the access aggregation device advertises the management IP of the access aggregation device to the vOLT, including: a static pre-configuration management IP, and a management IP obtained by using a dynamic host configuration protocol.
- the access aggregation device reads the device identifier of the optical access module, and the access aggregation device reads the device identifier of the optical access module through the two-wire serial bus I2C control bus. .
- the access aggregation device reports the optical access module to the virtualized optical line terminal vOLT.
- the physical location information and the device identifier of the optical access module include: the access aggregation device reports the physical location information of the optical access module to the virtualized optical line terminal vOLT through the network configuration protocol NETCONF or the network management protocol SNMP. And device identification of the optical access module.
- the physical location information of the optical access module includes: a port number where the optical access module is located, and a slot number where the optical access module is located.
- the device identifier of the optical access module includes: a MAC address of the optical access module, and a sequence number of the optical access module.
- an authentication registration device for an optical access module including: a first receiving module, configured to virtualize an optical line terminal vOLT, receive physical location information of the optical access module, and a device identifier of the optical access module; the first authentication module is configured to: the vOLT authenticates the optical access module according to the device identifier of the optical access module; and the first sending module is configured to be in the vOLT pair When the authentication of the optical access module is passed, the vOLT sends the management configuration information to the optical access module corresponding to the physical location information; and the establishing module is configured to be configured by the vOLT according to the management configuration information.
- the optical access module establishes a management channel.
- the first sending module includes: a sending unit, configured to: when the vOLT authenticates the optical access module, the vOLT receives the optical access module The management IP request, the vOLT sends a management MAC and a management IP configured to the optical access module; and the carrying unit is configured to be in the case that the vOLT authenticates the optical access module, and In the case that the optical access module initiates the 802.1x authentication, the vOLT responds to the optical access module by using the LAN-based extended authentication protocol EAPoL, and the vOLT carries the management MAC and management IP of the vOLT by using a type length value TLV. .
- a sending unit configured to: when the vOLT authenticates the optical access module, the vOLT receives the optical access module The management IP request, the vOLT sends a management MAC and a management IP configured to the optical access module; and the carrying unit is configured to be in the case that the vOLT authenticates the optical access module,
- the establishing module includes: a first management channel unit, configured to establish a management channel between the optical access module and the vOLT by using a management IP; and a second management channel unit, configured as a A management channel is established between the optical access module and the vOLT through the Ethernet maintenance communication channel ETH-MCC.
- an authentication registration device for an optical access module comprising: a second receiving module, configured to receive the first vOLT in the plurality of virtualized optical line terminals vOLT An authentication request of the optical access module; the second authentication module is configured to forward the authentication request to the centralized authentication and authorization charging AAA server by the first vOLT; and the second sending module is configured to be in the AAA server When the optical access module is authenticated, the first vOLT sends the management configuration information corresponding to the vOLT to the optical access module.
- the second sending module includes: a response unit, configured to send the 802.1x response message to the optical access module by the first vOLT, where the response message includes: a management IP of the corresponding vOLT And the corresponding vOLT MAC; the configuration unit is configured to allocate, by the first vOLT, the management IP of the vOLT corresponding to the optical access module by using a dynamic host configuration protocol subsequent protocol.
- an authentication registration device for an optical access module comprising: a reading module, configured to find that the optical access module is in place at the access aggregation device
- the access aggregation device reads the device identifier of the optical access module, and the reporting module sets the access aggregation device to the virtualized optical line terminal.
- the vOLT reports the physical location information of the optical access module and the device identifier of the optical access module
- the third authentication module is configured to receive the authentication message of the vOLT to the optical access module, where the vOLT And authenticating the optical access module according to the device identifier of the optical access module.
- the device further includes: an advertisement receiving module, configured to receive, by the access aggregation device, a management IP of the vOLT An advertisement of the interface information, the notification sending module is configured to notify the vOLT of the management IP and interface information of the access aggregation device, and the management control module is configured to be the access aggregation device and the The vOLT establishes a management control channel.
- an advertisement receiving module configured to receive, by the access aggregation device, a management IP of the vOLT An advertisement of the interface information
- the notification sending module is configured to notify the vOLT of the management IP and interface information of the access aggregation device
- the management control module is configured to be the access aggregation device and the The vOLT establishes a management control channel.
- an authentication registration system for an optical access module including: an optical access module, an access aggregation device, and a virtualized optical line terminal vOLT; the vOLT includes the foregoing device,
- the access aggregation device includes the above devices.
- the physical location information of the optical access module and the device identifier of the optical access module are received by the virtualized optical line terminal vOLT; the vOLT authenticates the optical access module according to the device identifier of the optical access module; And the vOLT sends management configuration information to the optical access module corresponding to the physical location information, where the vOLT establishes management with the optical access module according to the management configuration information, where the vOLT is authenticated by the optical access module.
- the channel solves the problem that the vOLT cannot effectively authenticate and register the optical access module under the virtualization architecture, and realizes the discovery, authentication, and registration of the optical access module by the vOLT.
- FIG. 1 is a flowchart 1 of an authentication registration method of an optical access module according to an embodiment of the present invention
- FIG. 2 is a second flowchart of a method for authenticating an optical access module according to an embodiment of the present invention
- FIG. 3 is a third flowchart of an authentication registration method of an optical access module according to an embodiment of the present invention.
- FIG. 4 is a structural block diagram 1 of an authentication registration apparatus of an optical access module according to an embodiment of the present invention.
- FIG. 5 is a structural block diagram 2 of an authentication and registration device of an optical access module according to an embodiment of the present invention.
- FIG. 6 is a structural block diagram 3 of an authentication registration apparatus of an optical access module according to an embodiment of the present invention.
- FIG. 7 is a schematic diagram of a network architecture of a virtual access network in accordance with a preferred implementation of the present invention.
- FIG. 8 is a flow chart showing the authentication and registration of an optical access module on a general-purpose Ethernet switch (access aggregation device B) according to a preferred implementation of the present invention
- FIG. 9 is a flow chart showing the authentication and registration on a network card port of a general-purpose server (access aggregation device A) according to a preferred embodiment of the present invention.
- FIG. 1 is a flowchart 1 of an authentication registration method of an optical access module according to an embodiment of the present invention. As shown in FIG. 1 , the process includes the following steps. step:
- Step S102 The virtualized optical line terminal vOLT receives the physical location information of the optical access module and the device identifier of the optical access module.
- Step S104 The vOLT authenticates the optical access module according to the device identifier of the optical access module.
- Step S106 in the case that the vOLT is authenticated by the optical access module, the vOLT sends management configuration information to the optical access module corresponding to the physical location information, and the vOLT is configured according to the management configuration information and the optical access module. Establish a management channel.
- the virtualized optical line terminal vOLT receives the physical location information of the optical access module and the device identifier of the optical access module, and the vOLT authenticates the optical access module according to the device identifier, and accesses the optical access at the vOLT.
- the vOLT establishes a management channel with the optical access module according to the management configuration information, and solves the problem that the vOLT cannot effectively register the optical access module by using the above authentication registration mode, and implements the vOLT pair. Discovery, authentication and registration of optical access modules.
- the vOLT may send the management configuration information to the optical access module in multiple manners, where the vOLT receives the optical interface in the case that the vOLT passes the authentication of the optical access module.
- the management IP address of the incoming module the vOLT sends a management MAC and a management IP configured for the optical access module; if the vOLT authenticates the optical access module, and the optical access module initiates 802.1x
- the vOLT answers the optical access module through the LAN-based extended authentication protocol EAPoL, and the vOLT carries the management MAC and the management IP of the vOLT through the type length value TLV.
- the vOLT establishes a management channel with the optical access module according to the management configuration information, and the method includes: establishing, by the management module, the management channel between the optical access module and the vOLT; A management channel is established between the optical access module and the vOLT through the Ethernet maintenance communication channel ETH-MCC.
- the physical location information of the optical access module includes: a port number where the optical access module is located, and a slot number where the optical access module is located.
- the device identifier of the optical access module includes: a MAC address of the optical access module, and a serial number of the optical access module.
- FIG. 2 is a flowchart 2 of an authentication registration method of an optical access module according to an embodiment of the present invention. As shown in FIG. 2, the process includes the following steps:
- Step S202 the first vOLT of the plurality of virtualized optical line terminals vOLT receives the authentication request of the optical access module
- Step S204 the first vOLT forwards the authentication request to the centralized authentication and authorization charging AAA server;
- Step S206 When the AAA server authenticates the optical access module, the first vOLT sends the management configuration information corresponding to the vOLT to the optical access module.
- the first vOLT of the plurality of virtualized optical line terminals vOLT receives the authentication request of the optical access module, and the first vOLT forwards the authentication request to the centralized authentication and authorization accounting server (Authentication, Authorization and Accounting, for short AAA), in the case that the AAA server authenticates the optical access module, the first vOLT sends the management configuration information corresponding to the vOLT to the optical access module.
- the centralized authentication and authorization accounting server Authentication, Authorization and Accounting, for short AAA
- the optical access module In the case of accessing multiple vOLTs, the vOLT becomes a proxy server, which completes the cross-vOLT authentication of the optical access module, and solves the problem that the vOLT cannot effectively authenticate the optical access module, and implements the vOLT optical access module. Discovery, certification and registration.
- the first vOLT sends the corresponding vOLT management configuration information to the optical access module in multiple manners, where the method includes: the first vOLT sends an 802.1x response message to the optical access module, The response message includes: a management IP of the corresponding vOLT and a MAC of the corresponding vOLT; the first vOLT allocates a management IP of the vOLT corresponding to the optical access module by using a dynamic host configuration protocol subsequent protocol.
- FIG. 3 is a flowchart 3 of an authentication registration method of an optical access module according to an embodiment of the present invention. As shown in FIG. 3, the process includes the following steps:
- Step S302 the access aggregation device reads the device identifier of the optical access module when the access aggregation device finds that the optical access module is in place;
- Step S304 the access aggregation device reports the physical location information of the optical access module and the device identifier of the optical access module to the virtualized optical line terminal vOLT.
- Step S306 Receive an authentication message of the vOLT to the optical access module, where the vOLT authenticates the optical access module according to the device identifier of the optical access module.
- the access aggregation device uploads the authentication information of the optical access module to the vOLT.
- the vOLT receives the authentication message from the vOLT to the optical access module, thereby solving the problem that the vOLT cannot effectively provide light.
- the access module performs authentication and registration, and realizes the discovery, authentication, and registration of the optical access module by the vOLT.
- the access aggregation device receives the management IP address of the vOLT before the access aggregation device reads the device identifier of the optical access module.
- the interface information is advertised to the vOLT to advertise the management IP and interface information of the access aggregation device; the access aggregation device establishes a management control channel with the vOLT.
- the IP address of the access aggregation device that the access aggregation device advertises to the vOLT may include: a static pre-configuration management IP, and a management IP obtained by using a dynamic host configuration protocol.
- the access aggregation device reads the device identification of the optical access module through the two-wire serial bus I2C control bus.
- the access aggregation device virtualizes the light through the network configuration protocol NETCONF or the network management protocol SNMP
- the line terminal vOLT reports the physical location information of the optical access module and the device identifier of the optical access module.
- the method according to the above embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, by hardware, but in many cases, the former is A better implementation.
- the technical solution of the present invention which is essential or contributes to the prior art, may be embodied in the form of a software product stored in a storage medium (such as ROM/RAM, disk,
- the optical disc includes a number of instructions for causing a terminal device (which may be a mobile phone, a computer, a server, or a network device, etc.) to perform the method of various embodiments of the present invention.
- an authentication registration device for an optical access module is further provided, and the device is located in the terminal.
- the device is used to implement the above embodiments and preferred embodiments, and the description thereof has been omitted.
- the term "module” may implement a combination of software and/or hardware of a predetermined function.
- FIG. 4 is a structural block diagram 1 of an authentication registration apparatus of an optical access module according to an embodiment of the present invention. As shown in FIG. 4, the apparatus includes:
- the first receiving module 42 is configured to receive the physical location information of the optical access module and the device identifier of the optical access module by the virtualized optical line terminal vOLT;
- the first authentication module 44 is configured to: the vOLT authenticates the optical access module according to the device identifier of the optical access module;
- the first sending module 46 is configured to send, by the vOLT, the management configuration information to the optical access module corresponding to the physical location information, in the case that the vOLT is authenticated by the optical access module;
- the establishing module 48 is configured to establish, by the vOLT, a management channel with the optical access module according to the management configuration information.
- the first sending module 46 may include:
- a sending unit configured to receive a management IP request of the optical access module, where the vOLT receives a management IP request of the optical access module, where the vOLT sends a management MAC and a configuration of the optical access module Management IP;
- the portable unit is configured to answer the optical access by using the extended authentication protocol EAPoL based on the local area network, in the case that the vOLT passes the authentication of the optical access module, and the optical access module initiates the 802.1x authentication.
- the module, the vOLT carries the management MAC and the management IP of the vOLT by the type length value TLV.
- the establishing module 48 includes: a first management channel unit, configured to establish a management channel between the optical access module and the vOLT through management IP; and a second management channel unit, configured as the optical access module A management channel is established between the vOLT and the vOLT through the Ethernet maintenance communication channel ETH-MCC.
- FIG. 5 is a structural block diagram 2 of an authentication and registration device of an optical access module according to an embodiment of the present invention. As shown in FIG. 5, the device includes:
- the second receiving module 52 is configured to receive the optical access module by the first vOLT in the plurality of virtualized optical line terminals vOLT Authentication request;
- the second authentication module 54 is configured to forward the authentication request to the centralized authentication and authorization charging AAA server by the first vOLT;
- the second sending module 56 is configured to send, when the AAA server authenticates the optical access module, the first vOLT sends the management configuration information corresponding to the vOLT to the optical access module.
- the second sending module 56 may include:
- the response unit is configured to send the 802.1x response message to the optical access module, where the response message includes: a management IP of the corresponding vOLT and a MAC of the corresponding vOLT;
- the configuration unit is configured to allocate, by the first vOLT, the management IP of the vOLT corresponding to the optical access module by using a dynamic host configuration protocol subsequent protocol.
- FIG. 6 is a structural block diagram 3 of an authentication and registration device of an optical access module according to an embodiment of the present invention. As shown in FIG. 6, the device includes:
- the reading module 62 is configured to: when the access aggregation device finds that the optical access module is in place, the access aggregation device reads the device identifier of the optical access module;
- the reporting module 64 is configured to report, by the access aggregation device, the physical location information of the optical access module and the device identifier of the optical access module to the virtualized optical line terminal vOLT;
- the third authentication module 66 is configured to receive the authentication message of the vOLT to the optical access module, where the vOLT authenticates the optical access module according to the device identifier of the optical access module.
- the device further includes: an advertisement receiving module, configured to receive, by the access aggregation device, a management IP and interface information of the vOLT;
- the sending module is configured to notify the vOLT of the management IP and interface information of the access aggregation device, and the management control module is configured to establish a management control channel between the access aggregation device and the vOLT.
- an authentication registration system for an optical access module including: an optical access module, an access aggregation device, and a virtualized optical line terminal vOLT; the vOLT includes the device in the foregoing embodiment;
- the incoming convergence device includes the apparatus of the above embodiment.
- FIG. 7 is a schematic diagram of a network architecture of a virtual access network according to a preferred implementation of the present invention.
- the network is composed of a network cloud platform, access aggregation devices A and B, and user-side network terminals.
- the network cloud platform can use a common data infrastructure such as an Internet Data Center (IDC) or a data center.
- IDC Internet Data Center
- the access aggregation devices A and B remotely connect to the network cloud platform through the metropolitan area network.
- Access aggregation device A includes the capabilities of the general server's IT infrastructure, so the network function virtualization module can be distributed on the access aggregation device A and the network cloud platform as needed, such as vOLT, virtual broadband network gateway control device (virtualization Broadband) Network Gateway, referred to as vBNG), virtual communication Functional modules such as the Control Communications Control Application (vCCAP) and the Virtualization Custom Premise Equipment (vCPE) can be flexibly deployed to the virtual machines in the access aggregation device A and the network cloud platform. Run on.
- the access aggregation device B uses a universal Ethernet switch and does not have the capability of loading a virtual machine. It needs to rely on the network function virtualization function provided by the access aggregation device A to assist the work.
- the access aggregation device B supports the OpenFlow protocol and is controlled by a Software Defined Network (SDN) controller in the aggregation device A.
- SDN Software Defined Network
- Access aggregation devices A and B provide standard Ethernet interfaces, such as the 10G network port of the Institute of Electrical and Electronics Engineers (IEEE), or multi-source agreement (Multi-Source Agreement). Standard Small Form-Factor Pluggable (SFP+) slots for MSA). These interfaces connect optical access modules to the user side.
- the optical access module performs the medium conversion function of the PON to Ethernet data message.
- the preferred embodiment provides automatic discovery of the optical access module through the vOLT under the virtualized optical line terminal (vOLT) architecture, and authenticates and registers them to realize plug and play.
- the optical access module may be an SFP physical package optical module that resides on a universal Ethernet switch (access aggregation device B) or a general-purpose server (access aggregation device A) network card port where the vOLT is located.
- the method for the vOLT to automatically discover, authenticate, and register the optical access module includes the following steps:
- the access aggregation device finds that the optical access module is in place.
- the access aggregation device A or B reads the management MAC address and serial number (as the device identifier) of the optical access module through the I2C control bus.
- the access aggregation device A or B reports the optical access module by using a Network Configuration Protocol (NETCONF) or a Simple Network Management Protocol (SNMP) trap.
- NETCONF Network Configuration Protocol
- SNMP Simple Network Management Protocol
- the physical location information of the port and the slot and the physical address (Media Access Control, MAC) and serial number of the optical access module are reported to the vOLT.
- the vOLT checks the serial number of the optical access module to check whether it is a resource managed by itself. If it is authenticated (or the optical access module is required to further initiate 802.1x authentication).
- the vOLT tells the access aggregation device A or B (Authenticator) to pass the authentication.
- the subsequent optical access module requests the management IP through the Dynamic Host Configuration Protocol (DHCP), the configuration is delivered.
- the parameter includes the MAC and IP of the vOLT.
- the vOLT can be in the Extensible Authentication Protocol OVER LAN (EAPOL) response to the optical access module.
- the vMAC management MAC and IP can also be carried by the type-length-value (TLV).
- the optical access module and the vOLT can establish a management channel by using the management IP, or can also use a layer 2 connection, such as the Ethernet maintenance communication channel of the Y.1731 (Ethernet maintenance).
- the communication channel (referred to as ETH-MCC) establishes a management channel, and the optical access module directly accepts the management and control of the vOLT.
- the authentication and registration of the optical access module is completed.
- the optical access module is automatically discovered, authenticated, and registered to implement the optical access module. Plug and play, in line with the need for network operators to automate and simplify network configuration and operation and maintenance under the access network virtualization architecture.
- the optical access module on the universal Ethernet switch (accessing the aggregation device B) is summarized in the preferred embodiment, and one vOLT instance represents a certain management domain, in order to let the vOLT know its own management boundary.
- the operator should first assign all the resource identifiers that the vOLT needs to manage to the vOLT through the human-computer interaction interface. This can be defined by the data model such as the SNMP Management Information Base (MIB) or the YANG language.
- MIB SNMP Management Information Base
- YANG language the binding relationship between the optical access module and the vOLT is software definable.
- FIG. 8 is a flow chart showing the authentication and registration of an optical access module on a general-purpose Ethernet switch (access aggregation device B) according to a preferred embodiment of the present invention, as shown in FIG.
- step S802 the vOLT control virtual switch (vSwitch) in the access aggregation device A advertises its management IP address to the access aggregation device B through the Link Layer Discovery Protocol (LLDP) protocol.
- LLDP Link Layer Discovery Protocol
- Step S804 after the access aggregation device B is powered on, the LLDP advertises its own management IP to the vOLT.
- the management IP address can be statically pre-configured or obtained through a DHCP client.
- the topology discovery is performed between the aggregation device B and the vOLT.
- the aggregation device B registers with the vOLT authentication and accepts the vOLT control with the vOLT as the virtual network controller.
- the Chassis ID (such as the bridge MAC address) of the LLDP of the two parties is used as one of the authentication factors, and the vOLT and the access aggregation device B are uniquely identified.
- the vOLT and the access aggregation device B complete the mutual discovery.
- the vOLT can establish a management control channel to the access aggregation device B, and then perform management control on the access aggregation device B through the NetConf protocol/OpenFlow protocol.
- Step S806 after the optical access module is inserted into the access aggregation device B, the access aggregation device B finds that the optical access module is in place.
- Step S808 the access aggregation device B reads the management MAC address and the serial number (as the device identifier) of the optical access module through the I2C control bus.
- step S810 the access aggregation device B reports the physical location information such as the port and the slot where the optical access module is located, and the MAC address and serial number of the optical access module, and reports the vOLT to the vOLT.
- the vOLT checks the serial number of the optical access module to check whether it is a resource managed by itself. If yes, the optical access module is required to initiate 802.1x authentication.
- Step S812 the optical access module (suppliant) initiates the authentication of the 802.1x EAPoL to the vOLT authentication server (Authentication Server).
- Step S814 the vOLT tells the access aggregation device B (Authenticator) that the optical access module passes the authentication, and the vOLT can carry the management MAC and IP of the vOLT through the extended TLV in the EAPoL response to the optical access module, or in the subsequent light.
- the access module manages the IP address through DHCP
- the configuration parameters are delivered including the MAC and IP of the vOLT.
- the topology discovery is completed between the optical access module and the vOLT, and the vOLT is controlled by the vOLT as a virtual network controller.
- the management module can be used to establish a management channel between the access module and the vOLT, or a Layer 2 connection, such as the ETH-MCC of the Y.1731.
- the topology discovery is performed between the optical access module and the vOLT.
- the optical access module and the vOLT can establish a management channel by using the management IP, or can be connected by using a layer 2, such as the ETH-MCC of the Y.1731. Management channel, the optical access module directly accepts the management and control of the vOLT.
- the optical access module obtains the authorization of the vOLT, accepts the authentication registration of the ONT to the vOLT, completes the topology discovery between the ONT and the vOLT, and the management channel between the access module and the ONT follows the existing methods such as OMCC.
- one aggregation access network is one management domain and only one vOLT.
- the authentication of the optical access module can be centralized authentication across the vOLT.
- the first vOLT acts as a proxy server (Radius Proxy), and the optical access module is authenticated.
- the request is forwarded to the centralized AAA (Authentication, Authorization, Accounting) server.
- AAA Authentication, Authorization, Accounting
- the content of the response message is extended by the 802.1x, or when the DHCP assigns the optical access module to manage the IP.
- the configuration is delivered, the management IP and MAC of the corresponding vOLT are rewritten, and the optical access module is reset to register with the correct vOLT.
- FIG. 9 is a flow chart showing the process of authentication and registration on a network card port of a general-purpose server (access aggregation device A) according to a preferred embodiment of the present invention, as shown in FIG. Including the following steps:
- Step S902 After the optical access module is inserted into the NIC port of the general-purpose server (accessing the aggregation device A), the access aggregation device A finds that the optical access module is in place.
- Step S904 the access aggregation device A reads the management MAC address and serial number (as the device identifier) of the optical access module through the I2C control bus.
- step S906 the access aggregation device A reports the physical location information such as the port where the optical access module is located, and the MAC address and serial number of the optical access module, and reports the vOLT to the vOLT.
- the vOLT checks the serial number of the optical access module to check whether it is a resource managed by itself. If yes, the optical access module is required to initiate 802.1x authentication.
- Step S908 the optical access module (suppliant) initiates authentication of the 802.1x EAPoL to the vOLT (Authentication Server)
- the vOLT tells the access aggregation device A (Authenticator) that the optical access module passes the authentication, and the vOLT can carry the management MAC address and IP of the vOLT through the extended TLV in the EAPoL response to the optical access module, or in the subsequent light.
- the access module manages the IP address through DHCP
- the configuration parameters are delivered including the MAC and IP of the vOLT.
- the topology discovery is performed between the optical access module and the vOLT, and a Layer 3 or Layer 2 management channel is established between the optical access module and the vOLT, and the optical access module directly accepts management and control of the vOLT.
- the topology discovery is completed between the optical access module and the vOLT, and the vOLT is controlled by the vOLT as a virtual network controller.
- the management module can be used to establish a management channel between the access module and the vOLT, or a Layer 2 connection, such as the ETH-MCC of the Y.1731.
- step S912 the optical access module obtains the authorization of the vOLT, accepts the authentication registration of the ONT to the vOLT, completes the topology discovery between the ONT and the vOLT, and the management channel between the access module and the ONT follows the existing methods such as OMCC.
- the various modules or steps of the present invention described above can be used with general calculations.
- the devices are implemented, they may be centralized on a single computing device, or distributed over a network of multiple computing devices, optionally they may be implemented in program code executable by the computing device, such that they may be stored Executed by the computing device in a storage device, and in some cases, the steps shown or described may be performed in an order different than that herein, or separately fabricated into individual integrated circuit modules, or Multiple modules or steps are made into a single integrated circuit module.
- the invention is not limited to any specific combination of hardware and software.
- the virtualized optical line terminal vOLT receives the physical location information of the optical access module and the device identifier of the optical access module; the vOLT uses the device according to the device identifier of the optical access module.
- the access module performs authentication.
- the vOLT passes the authentication of the optical access module, the vOLT sends management configuration information to the optical access module corresponding to the physical location information, where the vOLT is configured according to the management configuration information.
- the optical access module establishes a management channel, which solves the problem that the vOLT cannot effectively register and register the optical access module under the virtualization architecture, and realizes the discovery, authentication, and registration of the optical access module by the vOLT.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Small-Scale Networks (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
La présente invention concerne un procédé, un dispositif et un système d'authentification et d'enregistrement pour un module d'accès optique. Le procédé comprend les étapes suivantes : un terminal de ligne optique de virtualisation (vOLT) reçoit des informations de position physique relatives à un module d'accès optique et à l'identification de dispositif du module d'accès optique ; le vOLT met en oeuvre une authentification sur le module d'accès optique selon l'identification de dispositif du module d'accès optique ; et, en cas d'authentification réussie dudit vOLT sur le module d'accès optique, le vOLT envoie des informations de gestion et de configuration au module d'accès optique qui correspondent aux informations de position physique, et le vOLT établit un canal de gestion avec le module d'accès optique selon les informations de gestion et de configuration. L'invention, qui résout le problème de l'impossibilité de mettre en oeuvre efficacement une authentification et un enregistrement sur un module d'accès optique sous une structure de virtualisation, permet ainsi de mettre en oeuvre la découverte, l'authentification et l'enregistrement d'un vOLT sur le module d'accès optique.
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201510202164.7A CN106162387B (zh) | 2015-04-24 | 2015-04-24 | 光接入模块的认证注册方法、装置及系统 |
| CN201510202164.7 | 2015-04-24 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2016169260A1 true WO2016169260A1 (fr) | 2016-10-27 |
Family
ID=57143714
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2015/094729 Ceased WO2016169260A1 (fr) | 2015-04-24 | 2015-11-16 | Procédé, dispositif et système d'authentification et d'enregistrement pour module d'accès optique |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN106162387B (fr) |
| WO (1) | WO2016169260A1 (fr) |
Cited By (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN107342820A (zh) * | 2017-01-09 | 2017-11-10 | 烽火通信科技股份有限公司 | 基于模板管理实现volt的方法及系统 |
| CN107493524A (zh) * | 2017-09-21 | 2017-12-19 | 烽火通信科技股份有限公司 | 一种实现虚拟olt的方法 |
| WO2018157299A1 (fr) * | 2017-02-28 | 2018-09-07 | 华为技术有限公司 | Procédé de virtualisation pour dispositif olt (terminaison de ligne optique), et dispositif associé |
Families Citing this family (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN111385026B (zh) * | 2018-12-29 | 2022-08-26 | 中兴通讯股份有限公司 | 一种olt设备虚拟化的方法及olt设备 |
| CN110121123A (zh) * | 2019-05-10 | 2019-08-13 | 江西山水光电科技股份有限公司 | 一种pon聚合拉远设备管理方法 |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20050053376A1 (en) * | 2003-09-08 | 2005-03-10 | Young-Hun Joo | FTTH system for convergence of broadcasting and communication through switched broadcasting |
| CN101621331A (zh) * | 2008-06-30 | 2010-01-06 | 中兴通讯股份有限公司 | 光网络单元配置方法和装置 |
| CN102882717A (zh) * | 2012-09-26 | 2013-01-16 | 烽火通信科技股份有限公司 | 无源光网络系统中光网络单元的管理方法 |
Family Cites Families (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101562480A (zh) * | 2008-04-15 | 2009-10-21 | 华为技术有限公司 | 一种光接入网络、光线路终端的备份方法、系统及设备 |
-
2015
- 2015-04-24 CN CN201510202164.7A patent/CN106162387B/zh active Active
- 2015-11-16 WO PCT/CN2015/094729 patent/WO2016169260A1/fr not_active Ceased
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20050053376A1 (en) * | 2003-09-08 | 2005-03-10 | Young-Hun Joo | FTTH system for convergence of broadcasting and communication through switched broadcasting |
| CN101621331A (zh) * | 2008-06-30 | 2010-01-06 | 中兴通讯股份有限公司 | 光网络单元配置方法和装置 |
| CN102882717A (zh) * | 2012-09-26 | 2013-01-16 | 烽火通信科技股份有限公司 | 无源光网络系统中光网络单元的管理方法 |
Cited By (8)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN107342820A (zh) * | 2017-01-09 | 2017-11-10 | 烽火通信科技股份有限公司 | 基于模板管理实现volt的方法及系统 |
| CN107342820B (zh) * | 2017-01-09 | 2019-06-25 | 烽火通信科技股份有限公司 | 基于模板管理实现volt的方法及系统 |
| WO2018157299A1 (fr) * | 2017-02-28 | 2018-09-07 | 华为技术有限公司 | Procédé de virtualisation pour dispositif olt (terminaison de ligne optique), et dispositif associé |
| CN110301104A (zh) * | 2017-02-28 | 2019-10-01 | 华为技术有限公司 | 一种光线路终端olt设备虚拟方法及相关设备 |
| CN110301104B (zh) * | 2017-02-28 | 2021-01-05 | 华为技术有限公司 | 一种光线路终端olt设备虚拟方法及相关设备 |
| US11336973B2 (en) | 2017-02-28 | 2022-05-17 | Huawei Technologies Co., Ltd. | Optical line terminal OLT device virtualization method and related device |
| CN107493524A (zh) * | 2017-09-21 | 2017-12-19 | 烽火通信科技股份有限公司 | 一种实现虚拟olt的方法 |
| CN107493524B (zh) * | 2017-09-21 | 2020-02-11 | 烽火通信科技股份有限公司 | 一种实现虚拟olt的方法 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN106162387B (zh) | 2020-08-18 |
| CN106162387A (zh) | 2016-11-23 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11038751B2 (en) | Information processing method, network node, authentication method, and server | |
| CN106161077B (zh) | 接入汇聚装置和认证注册方法 | |
| US11336973B2 (en) | Optical line terminal OLT device virtualization method and related device | |
| US9832136B1 (en) | Streaming software to multiple virtual machines in different subnets | |
| US10367693B2 (en) | Service configuration data processing method and apparatus | |
| CN108881308B (zh) | 一种用户终端及其认证方法、系统、介质 | |
| US20150049631A1 (en) | Topology aware provisioning in a software-defined networking environment | |
| CA3063688A1 (fr) | Procede et systeme d'etablissement d'un chemin de service dans un reseau de communication | |
| CN103701628A (zh) | 家庭网关的配置管理方法、虚拟家庭网关和光网络终端 | |
| CN106533883A (zh) | 一种网络专线的建立方法、装置及系统 | |
| US9118588B2 (en) | Virtual console-port management | |
| CN106162387B (zh) | 光接入模块的认证注册方法、装置及系统 | |
| CN107769939B (zh) | 数据通信网中网元管理方法、网管、网关网元及系统 | |
| KR20130101663A (ko) | 클라우드 네트워킹 장치 및 방법 | |
| CN103200030B (zh) | 网络管理的装置和方法 | |
| US11956574B2 (en) | Optical communication network system, optical network unit, and optical communication method | |
| WO2018171124A1 (fr) | Procédé d'attribution de ressource, serveur, terminal de ligne optique, et système | |
| CN112929387B (zh) | 应用于智慧社区的宽带网络多重认证、加密方法 | |
| CN104253980A (zh) | 一种前端设备与后台媒体设备的连接方法及装置 | |
| WO2017076146A1 (fr) | Procédé et système d'authentification d'accès au réseau | |
| US12081924B2 (en) | Optical network unit, communication network system and communication method | |
| CN103227822B (zh) | 一种p2p通信连接建立方法和设备 | |
| WO2017219856A1 (fr) | Procédé et système de traitement de validation de circuits, contrôleur, et support de stockage informatique | |
| WO2017077760A1 (fr) | Dispositif côté station, dispositif de gestion d'informations, procédé d'authentification de terminal et procédé de gestion d'informations | |
| US20130275967A1 (en) | Dynamic provisioning of virtual systems |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 15889743 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 15889743 Country of ref document: EP Kind code of ref document: A1 |