WO2016169260A1 - Procédé, dispositif et système d'authentification et d'enregistrement pour module d'accès optique - Google Patents

Procédé, dispositif et système d'authentification et d'enregistrement pour module d'accès optique Download PDF

Info

Publication number
WO2016169260A1
WO2016169260A1 PCT/CN2015/094729 CN2015094729W WO2016169260A1 WO 2016169260 A1 WO2016169260 A1 WO 2016169260A1 CN 2015094729 W CN2015094729 W CN 2015094729W WO 2016169260 A1 WO2016169260 A1 WO 2016169260A1
Authority
WO
WIPO (PCT)
Prior art keywords
volt
access module
optical access
management
optical
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2015/094729
Other languages
English (en)
Chinese (zh)
Inventor
刁渊炯
江晓林
李明生
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
ZTE Corp
Original Assignee
ZTE Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by ZTE Corp filed Critical ZTE Corp
Publication of WO2016169260A1 publication Critical patent/WO2016169260A1/fr
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04QSELECTING
    • H04Q11/00Selecting arrangements for multiplex systems

Definitions

  • the present invention relates to the field of communications, and in particular to a method, device, and system for authenticating an optical access module.
  • the passive optical network device can be divided into an Ethernet-based passive optical network device (Ethernet Passive Optical Network, EPON for short) and a Gigabit-capable Passive Optical Network (G).
  • XG-PON 10G Gigabit-capable passive optical networks
  • NGPON2 Next Next Passive Optical Networks
  • Passive optical network devices have a consistent system architecture, including Optical Line Terminals (OLTs) and Optical Network Units (ONUs).
  • OLTs Optical Line Terminals
  • ONUs Optical Network Units
  • a centralized OLT device discovers changes in the state of the PON port through power-up and loading of the integrated PON line card.
  • vOLT virtualized optical line terminal
  • the discovery and management mechanism of the PON port under the traditional centralized OLT architecture is no longer applicable.
  • vOLT is the management and control center of the entire system. How to solve the authentication and registration of optical access modules has become an urgent problem to be solved.
  • the vOLT cannot effectively authenticate the optical access module, and no effective solution has been proposed yet.
  • the vOLT cannot effectively register the optical access module
  • the present invention provides an authentication registration method, device, and system for the optical access module, to at least solve the above problem.
  • a method for authenticating an optical access module including: a virtualized optical line terminal vOLT receiving physical location information of an optical access module and a device identifier of the optical access module; The vOLT authenticates the optical access module according to the device identifier of the optical access module; if the vOLT authenticates the optical access module, the vOLT corresponds to the physical location information.
  • the optical access module sends management configuration information, and the vOLT establishes a management channel with the optical access module according to the management configuration information.
  • the vOLT in the case that the vOLT is authenticated by the optical access module, the vOLT sends the management configuration information to the optical access module, including at least one of: at the vOLT
  • the vOLT receives a management IP request of the optical access module, and the vOLT delivers the optical The management MAC and the management IP configured by the access module; in the case that the vOLT is authenticated by the optical access module, and the optical access module initiates 802.1x authentication, the vOLT passes the local area network The extended authentication protocol EAPoL replies to the optical access module, and the vOLT carries the management MAC and management IP of the vOLT by a type length value TLV.
  • the vOLT establishes a management channel with the optical access module according to the management configuration information, and includes at least one of the following: establishing, by using the management IP, the optical access module and the vOLT A channel is established between the optical access module and the vOLT through an Ethernet maintenance communication channel ETH-MCC.
  • the physical location information of the optical access module includes: a port number where the optical access module is located, and a slot number where the optical access module is located.
  • the device identifier of the optical access module includes: a MAC address of the optical access module, and a sequence number of the optical access module.
  • an authentication registration method for an optical access module including: an authentication request of a first vOLT of the plurality of virtualized optical line terminals vOLT to receive an optical access module; The vOLT forwards the authentication request to the centralized authentication and authorization charging AAA server; when the AAA server authenticates the optical access module, the first vOLT sends a corresponding response to the optical access module.
  • vOLT management configuration information including: an authentication request of a first vOLT of the plurality of virtualized optical line terminals vOLT to receive an optical access module; The vOLT forwards the authentication request to the centralized authentication and authorization charging AAA server; when the AAA server authenticates the optical access module, the first vOLT sends a corresponding response to the optical access module.
  • the sending, by the first vOLT, the corresponding vOLT management configuration information to the optical access module includes: sending, by the first vOLT, an 802.1x response message to the optical access module,
  • the response message includes: a management IP of the corresponding vOLT and a MAC of the corresponding vOLT; the first vOLT allocates a management IP of the vOLT corresponding to the optical access module by using a dynamic host configuration protocol subsequent protocol.
  • an authentication registration method of an optical access module including: when the access aggregation device finds that the optical access module is in place, accessing the convergence device to read Receiving the device identifier of the optical access module; the access aggregation device reporting the physical location information of the optical access module and the device identifier of the optical access module to the virtualized optical line terminal vOLT; receiving the vOLT An authentication message of the optical access module, where the vOLT authenticates the optical access module according to the device identifier of the optical access module.
  • the method further includes: The access aggregation device receives the notification of the management IP and the interface information of the vOLT; the access aggregation device notifies the vOLT of the management IP and interface information of the access aggregation device; the access aggregation device and the The vOLT establishes a management control channel.
  • the access aggregation device advertises the management IP of the access aggregation device to the vOLT, including: a static pre-configuration management IP, and a management IP obtained by using a dynamic host configuration protocol.
  • the access aggregation device reads the device identifier of the optical access module, and the access aggregation device reads the device identifier of the optical access module through the two-wire serial bus I2C control bus. .
  • the access aggregation device reports the optical access module to the virtualized optical line terminal vOLT.
  • the physical location information and the device identifier of the optical access module include: the access aggregation device reports the physical location information of the optical access module to the virtualized optical line terminal vOLT through the network configuration protocol NETCONF or the network management protocol SNMP. And device identification of the optical access module.
  • the physical location information of the optical access module includes: a port number where the optical access module is located, and a slot number where the optical access module is located.
  • the device identifier of the optical access module includes: a MAC address of the optical access module, and a sequence number of the optical access module.
  • an authentication registration device for an optical access module including: a first receiving module, configured to virtualize an optical line terminal vOLT, receive physical location information of the optical access module, and a device identifier of the optical access module; the first authentication module is configured to: the vOLT authenticates the optical access module according to the device identifier of the optical access module; and the first sending module is configured to be in the vOLT pair When the authentication of the optical access module is passed, the vOLT sends the management configuration information to the optical access module corresponding to the physical location information; and the establishing module is configured to be configured by the vOLT according to the management configuration information.
  • the optical access module establishes a management channel.
  • the first sending module includes: a sending unit, configured to: when the vOLT authenticates the optical access module, the vOLT receives the optical access module The management IP request, the vOLT sends a management MAC and a management IP configured to the optical access module; and the carrying unit is configured to be in the case that the vOLT authenticates the optical access module, and In the case that the optical access module initiates the 802.1x authentication, the vOLT responds to the optical access module by using the LAN-based extended authentication protocol EAPoL, and the vOLT carries the management MAC and management IP of the vOLT by using a type length value TLV. .
  • a sending unit configured to: when the vOLT authenticates the optical access module, the vOLT receives the optical access module The management IP request, the vOLT sends a management MAC and a management IP configured to the optical access module; and the carrying unit is configured to be in the case that the vOLT authenticates the optical access module,
  • the establishing module includes: a first management channel unit, configured to establish a management channel between the optical access module and the vOLT by using a management IP; and a second management channel unit, configured as a A management channel is established between the optical access module and the vOLT through the Ethernet maintenance communication channel ETH-MCC.
  • an authentication registration device for an optical access module comprising: a second receiving module, configured to receive the first vOLT in the plurality of virtualized optical line terminals vOLT An authentication request of the optical access module; the second authentication module is configured to forward the authentication request to the centralized authentication and authorization charging AAA server by the first vOLT; and the second sending module is configured to be in the AAA server When the optical access module is authenticated, the first vOLT sends the management configuration information corresponding to the vOLT to the optical access module.
  • the second sending module includes: a response unit, configured to send the 802.1x response message to the optical access module by the first vOLT, where the response message includes: a management IP of the corresponding vOLT And the corresponding vOLT MAC; the configuration unit is configured to allocate, by the first vOLT, the management IP of the vOLT corresponding to the optical access module by using a dynamic host configuration protocol subsequent protocol.
  • an authentication registration device for an optical access module comprising: a reading module, configured to find that the optical access module is in place at the access aggregation device
  • the access aggregation device reads the device identifier of the optical access module, and the reporting module sets the access aggregation device to the virtualized optical line terminal.
  • the vOLT reports the physical location information of the optical access module and the device identifier of the optical access module
  • the third authentication module is configured to receive the authentication message of the vOLT to the optical access module, where the vOLT And authenticating the optical access module according to the device identifier of the optical access module.
  • the device further includes: an advertisement receiving module, configured to receive, by the access aggregation device, a management IP of the vOLT An advertisement of the interface information, the notification sending module is configured to notify the vOLT of the management IP and interface information of the access aggregation device, and the management control module is configured to be the access aggregation device and the The vOLT establishes a management control channel.
  • an advertisement receiving module configured to receive, by the access aggregation device, a management IP of the vOLT An advertisement of the interface information
  • the notification sending module is configured to notify the vOLT of the management IP and interface information of the access aggregation device
  • the management control module is configured to be the access aggregation device and the The vOLT establishes a management control channel.
  • an authentication registration system for an optical access module including: an optical access module, an access aggregation device, and a virtualized optical line terminal vOLT; the vOLT includes the foregoing device,
  • the access aggregation device includes the above devices.
  • the physical location information of the optical access module and the device identifier of the optical access module are received by the virtualized optical line terminal vOLT; the vOLT authenticates the optical access module according to the device identifier of the optical access module; And the vOLT sends management configuration information to the optical access module corresponding to the physical location information, where the vOLT establishes management with the optical access module according to the management configuration information, where the vOLT is authenticated by the optical access module.
  • the channel solves the problem that the vOLT cannot effectively authenticate and register the optical access module under the virtualization architecture, and realizes the discovery, authentication, and registration of the optical access module by the vOLT.
  • FIG. 1 is a flowchart 1 of an authentication registration method of an optical access module according to an embodiment of the present invention
  • FIG. 2 is a second flowchart of a method for authenticating an optical access module according to an embodiment of the present invention
  • FIG. 3 is a third flowchart of an authentication registration method of an optical access module according to an embodiment of the present invention.
  • FIG. 4 is a structural block diagram 1 of an authentication registration apparatus of an optical access module according to an embodiment of the present invention.
  • FIG. 5 is a structural block diagram 2 of an authentication and registration device of an optical access module according to an embodiment of the present invention.
  • FIG. 6 is a structural block diagram 3 of an authentication registration apparatus of an optical access module according to an embodiment of the present invention.
  • FIG. 7 is a schematic diagram of a network architecture of a virtual access network in accordance with a preferred implementation of the present invention.
  • FIG. 8 is a flow chart showing the authentication and registration of an optical access module on a general-purpose Ethernet switch (access aggregation device B) according to a preferred implementation of the present invention
  • FIG. 9 is a flow chart showing the authentication and registration on a network card port of a general-purpose server (access aggregation device A) according to a preferred embodiment of the present invention.
  • FIG. 1 is a flowchart 1 of an authentication registration method of an optical access module according to an embodiment of the present invention. As shown in FIG. 1 , the process includes the following steps. step:
  • Step S102 The virtualized optical line terminal vOLT receives the physical location information of the optical access module and the device identifier of the optical access module.
  • Step S104 The vOLT authenticates the optical access module according to the device identifier of the optical access module.
  • Step S106 in the case that the vOLT is authenticated by the optical access module, the vOLT sends management configuration information to the optical access module corresponding to the physical location information, and the vOLT is configured according to the management configuration information and the optical access module. Establish a management channel.
  • the virtualized optical line terminal vOLT receives the physical location information of the optical access module and the device identifier of the optical access module, and the vOLT authenticates the optical access module according to the device identifier, and accesses the optical access at the vOLT.
  • the vOLT establishes a management channel with the optical access module according to the management configuration information, and solves the problem that the vOLT cannot effectively register the optical access module by using the above authentication registration mode, and implements the vOLT pair. Discovery, authentication and registration of optical access modules.
  • the vOLT may send the management configuration information to the optical access module in multiple manners, where the vOLT receives the optical interface in the case that the vOLT passes the authentication of the optical access module.
  • the management IP address of the incoming module the vOLT sends a management MAC and a management IP configured for the optical access module; if the vOLT authenticates the optical access module, and the optical access module initiates 802.1x
  • the vOLT answers the optical access module through the LAN-based extended authentication protocol EAPoL, and the vOLT carries the management MAC and the management IP of the vOLT through the type length value TLV.
  • the vOLT establishes a management channel with the optical access module according to the management configuration information, and the method includes: establishing, by the management module, the management channel between the optical access module and the vOLT; A management channel is established between the optical access module and the vOLT through the Ethernet maintenance communication channel ETH-MCC.
  • the physical location information of the optical access module includes: a port number where the optical access module is located, and a slot number where the optical access module is located.
  • the device identifier of the optical access module includes: a MAC address of the optical access module, and a serial number of the optical access module.
  • FIG. 2 is a flowchart 2 of an authentication registration method of an optical access module according to an embodiment of the present invention. As shown in FIG. 2, the process includes the following steps:
  • Step S202 the first vOLT of the plurality of virtualized optical line terminals vOLT receives the authentication request of the optical access module
  • Step S204 the first vOLT forwards the authentication request to the centralized authentication and authorization charging AAA server;
  • Step S206 When the AAA server authenticates the optical access module, the first vOLT sends the management configuration information corresponding to the vOLT to the optical access module.
  • the first vOLT of the plurality of virtualized optical line terminals vOLT receives the authentication request of the optical access module, and the first vOLT forwards the authentication request to the centralized authentication and authorization accounting server (Authentication, Authorization and Accounting, for short AAA), in the case that the AAA server authenticates the optical access module, the first vOLT sends the management configuration information corresponding to the vOLT to the optical access module.
  • the centralized authentication and authorization accounting server Authentication, Authorization and Accounting, for short AAA
  • the optical access module In the case of accessing multiple vOLTs, the vOLT becomes a proxy server, which completes the cross-vOLT authentication of the optical access module, and solves the problem that the vOLT cannot effectively authenticate the optical access module, and implements the vOLT optical access module. Discovery, certification and registration.
  • the first vOLT sends the corresponding vOLT management configuration information to the optical access module in multiple manners, where the method includes: the first vOLT sends an 802.1x response message to the optical access module, The response message includes: a management IP of the corresponding vOLT and a MAC of the corresponding vOLT; the first vOLT allocates a management IP of the vOLT corresponding to the optical access module by using a dynamic host configuration protocol subsequent protocol.
  • FIG. 3 is a flowchart 3 of an authentication registration method of an optical access module according to an embodiment of the present invention. As shown in FIG. 3, the process includes the following steps:
  • Step S302 the access aggregation device reads the device identifier of the optical access module when the access aggregation device finds that the optical access module is in place;
  • Step S304 the access aggregation device reports the physical location information of the optical access module and the device identifier of the optical access module to the virtualized optical line terminal vOLT.
  • Step S306 Receive an authentication message of the vOLT to the optical access module, where the vOLT authenticates the optical access module according to the device identifier of the optical access module.
  • the access aggregation device uploads the authentication information of the optical access module to the vOLT.
  • the vOLT receives the authentication message from the vOLT to the optical access module, thereby solving the problem that the vOLT cannot effectively provide light.
  • the access module performs authentication and registration, and realizes the discovery, authentication, and registration of the optical access module by the vOLT.
  • the access aggregation device receives the management IP address of the vOLT before the access aggregation device reads the device identifier of the optical access module.
  • the interface information is advertised to the vOLT to advertise the management IP and interface information of the access aggregation device; the access aggregation device establishes a management control channel with the vOLT.
  • the IP address of the access aggregation device that the access aggregation device advertises to the vOLT may include: a static pre-configuration management IP, and a management IP obtained by using a dynamic host configuration protocol.
  • the access aggregation device reads the device identification of the optical access module through the two-wire serial bus I2C control bus.
  • the access aggregation device virtualizes the light through the network configuration protocol NETCONF or the network management protocol SNMP
  • the line terminal vOLT reports the physical location information of the optical access module and the device identifier of the optical access module.
  • the method according to the above embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, by hardware, but in many cases, the former is A better implementation.
  • the technical solution of the present invention which is essential or contributes to the prior art, may be embodied in the form of a software product stored in a storage medium (such as ROM/RAM, disk,
  • the optical disc includes a number of instructions for causing a terminal device (which may be a mobile phone, a computer, a server, or a network device, etc.) to perform the method of various embodiments of the present invention.
  • an authentication registration device for an optical access module is further provided, and the device is located in the terminal.
  • the device is used to implement the above embodiments and preferred embodiments, and the description thereof has been omitted.
  • the term "module” may implement a combination of software and/or hardware of a predetermined function.
  • FIG. 4 is a structural block diagram 1 of an authentication registration apparatus of an optical access module according to an embodiment of the present invention. As shown in FIG. 4, the apparatus includes:
  • the first receiving module 42 is configured to receive the physical location information of the optical access module and the device identifier of the optical access module by the virtualized optical line terminal vOLT;
  • the first authentication module 44 is configured to: the vOLT authenticates the optical access module according to the device identifier of the optical access module;
  • the first sending module 46 is configured to send, by the vOLT, the management configuration information to the optical access module corresponding to the physical location information, in the case that the vOLT is authenticated by the optical access module;
  • the establishing module 48 is configured to establish, by the vOLT, a management channel with the optical access module according to the management configuration information.
  • the first sending module 46 may include:
  • a sending unit configured to receive a management IP request of the optical access module, where the vOLT receives a management IP request of the optical access module, where the vOLT sends a management MAC and a configuration of the optical access module Management IP;
  • the portable unit is configured to answer the optical access by using the extended authentication protocol EAPoL based on the local area network, in the case that the vOLT passes the authentication of the optical access module, and the optical access module initiates the 802.1x authentication.
  • the module, the vOLT carries the management MAC and the management IP of the vOLT by the type length value TLV.
  • the establishing module 48 includes: a first management channel unit, configured to establish a management channel between the optical access module and the vOLT through management IP; and a second management channel unit, configured as the optical access module A management channel is established between the vOLT and the vOLT through the Ethernet maintenance communication channel ETH-MCC.
  • FIG. 5 is a structural block diagram 2 of an authentication and registration device of an optical access module according to an embodiment of the present invention. As shown in FIG. 5, the device includes:
  • the second receiving module 52 is configured to receive the optical access module by the first vOLT in the plurality of virtualized optical line terminals vOLT Authentication request;
  • the second authentication module 54 is configured to forward the authentication request to the centralized authentication and authorization charging AAA server by the first vOLT;
  • the second sending module 56 is configured to send, when the AAA server authenticates the optical access module, the first vOLT sends the management configuration information corresponding to the vOLT to the optical access module.
  • the second sending module 56 may include:
  • the response unit is configured to send the 802.1x response message to the optical access module, where the response message includes: a management IP of the corresponding vOLT and a MAC of the corresponding vOLT;
  • the configuration unit is configured to allocate, by the first vOLT, the management IP of the vOLT corresponding to the optical access module by using a dynamic host configuration protocol subsequent protocol.
  • FIG. 6 is a structural block diagram 3 of an authentication and registration device of an optical access module according to an embodiment of the present invention. As shown in FIG. 6, the device includes:
  • the reading module 62 is configured to: when the access aggregation device finds that the optical access module is in place, the access aggregation device reads the device identifier of the optical access module;
  • the reporting module 64 is configured to report, by the access aggregation device, the physical location information of the optical access module and the device identifier of the optical access module to the virtualized optical line terminal vOLT;
  • the third authentication module 66 is configured to receive the authentication message of the vOLT to the optical access module, where the vOLT authenticates the optical access module according to the device identifier of the optical access module.
  • the device further includes: an advertisement receiving module, configured to receive, by the access aggregation device, a management IP and interface information of the vOLT;
  • the sending module is configured to notify the vOLT of the management IP and interface information of the access aggregation device, and the management control module is configured to establish a management control channel between the access aggregation device and the vOLT.
  • an authentication registration system for an optical access module including: an optical access module, an access aggregation device, and a virtualized optical line terminal vOLT; the vOLT includes the device in the foregoing embodiment;
  • the incoming convergence device includes the apparatus of the above embodiment.
  • FIG. 7 is a schematic diagram of a network architecture of a virtual access network according to a preferred implementation of the present invention.
  • the network is composed of a network cloud platform, access aggregation devices A and B, and user-side network terminals.
  • the network cloud platform can use a common data infrastructure such as an Internet Data Center (IDC) or a data center.
  • IDC Internet Data Center
  • the access aggregation devices A and B remotely connect to the network cloud platform through the metropolitan area network.
  • Access aggregation device A includes the capabilities of the general server's IT infrastructure, so the network function virtualization module can be distributed on the access aggregation device A and the network cloud platform as needed, such as vOLT, virtual broadband network gateway control device (virtualization Broadband) Network Gateway, referred to as vBNG), virtual communication Functional modules such as the Control Communications Control Application (vCCAP) and the Virtualization Custom Premise Equipment (vCPE) can be flexibly deployed to the virtual machines in the access aggregation device A and the network cloud platform. Run on.
  • the access aggregation device B uses a universal Ethernet switch and does not have the capability of loading a virtual machine. It needs to rely on the network function virtualization function provided by the access aggregation device A to assist the work.
  • the access aggregation device B supports the OpenFlow protocol and is controlled by a Software Defined Network (SDN) controller in the aggregation device A.
  • SDN Software Defined Network
  • Access aggregation devices A and B provide standard Ethernet interfaces, such as the 10G network port of the Institute of Electrical and Electronics Engineers (IEEE), or multi-source agreement (Multi-Source Agreement). Standard Small Form-Factor Pluggable (SFP+) slots for MSA). These interfaces connect optical access modules to the user side.
  • the optical access module performs the medium conversion function of the PON to Ethernet data message.
  • the preferred embodiment provides automatic discovery of the optical access module through the vOLT under the virtualized optical line terminal (vOLT) architecture, and authenticates and registers them to realize plug and play.
  • the optical access module may be an SFP physical package optical module that resides on a universal Ethernet switch (access aggregation device B) or a general-purpose server (access aggregation device A) network card port where the vOLT is located.
  • the method for the vOLT to automatically discover, authenticate, and register the optical access module includes the following steps:
  • the access aggregation device finds that the optical access module is in place.
  • the access aggregation device A or B reads the management MAC address and serial number (as the device identifier) of the optical access module through the I2C control bus.
  • the access aggregation device A or B reports the optical access module by using a Network Configuration Protocol (NETCONF) or a Simple Network Management Protocol (SNMP) trap.
  • NETCONF Network Configuration Protocol
  • SNMP Simple Network Management Protocol
  • the physical location information of the port and the slot and the physical address (Media Access Control, MAC) and serial number of the optical access module are reported to the vOLT.
  • the vOLT checks the serial number of the optical access module to check whether it is a resource managed by itself. If it is authenticated (or the optical access module is required to further initiate 802.1x authentication).
  • the vOLT tells the access aggregation device A or B (Authenticator) to pass the authentication.
  • the subsequent optical access module requests the management IP through the Dynamic Host Configuration Protocol (DHCP), the configuration is delivered.
  • the parameter includes the MAC and IP of the vOLT.
  • the vOLT can be in the Extensible Authentication Protocol OVER LAN (EAPOL) response to the optical access module.
  • the vMAC management MAC and IP can also be carried by the type-length-value (TLV).
  • the optical access module and the vOLT can establish a management channel by using the management IP, or can also use a layer 2 connection, such as the Ethernet maintenance communication channel of the Y.1731 (Ethernet maintenance).
  • the communication channel (referred to as ETH-MCC) establishes a management channel, and the optical access module directly accepts the management and control of the vOLT.
  • the authentication and registration of the optical access module is completed.
  • the optical access module is automatically discovered, authenticated, and registered to implement the optical access module. Plug and play, in line with the need for network operators to automate and simplify network configuration and operation and maintenance under the access network virtualization architecture.
  • the optical access module on the universal Ethernet switch (accessing the aggregation device B) is summarized in the preferred embodiment, and one vOLT instance represents a certain management domain, in order to let the vOLT know its own management boundary.
  • the operator should first assign all the resource identifiers that the vOLT needs to manage to the vOLT through the human-computer interaction interface. This can be defined by the data model such as the SNMP Management Information Base (MIB) or the YANG language.
  • MIB SNMP Management Information Base
  • YANG language the binding relationship between the optical access module and the vOLT is software definable.
  • FIG. 8 is a flow chart showing the authentication and registration of an optical access module on a general-purpose Ethernet switch (access aggregation device B) according to a preferred embodiment of the present invention, as shown in FIG.
  • step S802 the vOLT control virtual switch (vSwitch) in the access aggregation device A advertises its management IP address to the access aggregation device B through the Link Layer Discovery Protocol (LLDP) protocol.
  • LLDP Link Layer Discovery Protocol
  • Step S804 after the access aggregation device B is powered on, the LLDP advertises its own management IP to the vOLT.
  • the management IP address can be statically pre-configured or obtained through a DHCP client.
  • the topology discovery is performed between the aggregation device B and the vOLT.
  • the aggregation device B registers with the vOLT authentication and accepts the vOLT control with the vOLT as the virtual network controller.
  • the Chassis ID (such as the bridge MAC address) of the LLDP of the two parties is used as one of the authentication factors, and the vOLT and the access aggregation device B are uniquely identified.
  • the vOLT and the access aggregation device B complete the mutual discovery.
  • the vOLT can establish a management control channel to the access aggregation device B, and then perform management control on the access aggregation device B through the NetConf protocol/OpenFlow protocol.
  • Step S806 after the optical access module is inserted into the access aggregation device B, the access aggregation device B finds that the optical access module is in place.
  • Step S808 the access aggregation device B reads the management MAC address and the serial number (as the device identifier) of the optical access module through the I2C control bus.
  • step S810 the access aggregation device B reports the physical location information such as the port and the slot where the optical access module is located, and the MAC address and serial number of the optical access module, and reports the vOLT to the vOLT.
  • the vOLT checks the serial number of the optical access module to check whether it is a resource managed by itself. If yes, the optical access module is required to initiate 802.1x authentication.
  • Step S812 the optical access module (suppliant) initiates the authentication of the 802.1x EAPoL to the vOLT authentication server (Authentication Server).
  • Step S814 the vOLT tells the access aggregation device B (Authenticator) that the optical access module passes the authentication, and the vOLT can carry the management MAC and IP of the vOLT through the extended TLV in the EAPoL response to the optical access module, or in the subsequent light.
  • the access module manages the IP address through DHCP
  • the configuration parameters are delivered including the MAC and IP of the vOLT.
  • the topology discovery is completed between the optical access module and the vOLT, and the vOLT is controlled by the vOLT as a virtual network controller.
  • the management module can be used to establish a management channel between the access module and the vOLT, or a Layer 2 connection, such as the ETH-MCC of the Y.1731.
  • the topology discovery is performed between the optical access module and the vOLT.
  • the optical access module and the vOLT can establish a management channel by using the management IP, or can be connected by using a layer 2, such as the ETH-MCC of the Y.1731. Management channel, the optical access module directly accepts the management and control of the vOLT.
  • the optical access module obtains the authorization of the vOLT, accepts the authentication registration of the ONT to the vOLT, completes the topology discovery between the ONT and the vOLT, and the management channel between the access module and the ONT follows the existing methods such as OMCC.
  • one aggregation access network is one management domain and only one vOLT.
  • the authentication of the optical access module can be centralized authentication across the vOLT.
  • the first vOLT acts as a proxy server (Radius Proxy), and the optical access module is authenticated.
  • the request is forwarded to the centralized AAA (Authentication, Authorization, Accounting) server.
  • AAA Authentication, Authorization, Accounting
  • the content of the response message is extended by the 802.1x, or when the DHCP assigns the optical access module to manage the IP.
  • the configuration is delivered, the management IP and MAC of the corresponding vOLT are rewritten, and the optical access module is reset to register with the correct vOLT.
  • FIG. 9 is a flow chart showing the process of authentication and registration on a network card port of a general-purpose server (access aggregation device A) according to a preferred embodiment of the present invention, as shown in FIG. Including the following steps:
  • Step S902 After the optical access module is inserted into the NIC port of the general-purpose server (accessing the aggregation device A), the access aggregation device A finds that the optical access module is in place.
  • Step S904 the access aggregation device A reads the management MAC address and serial number (as the device identifier) of the optical access module through the I2C control bus.
  • step S906 the access aggregation device A reports the physical location information such as the port where the optical access module is located, and the MAC address and serial number of the optical access module, and reports the vOLT to the vOLT.
  • the vOLT checks the serial number of the optical access module to check whether it is a resource managed by itself. If yes, the optical access module is required to initiate 802.1x authentication.
  • Step S908 the optical access module (suppliant) initiates authentication of the 802.1x EAPoL to the vOLT (Authentication Server)
  • the vOLT tells the access aggregation device A (Authenticator) that the optical access module passes the authentication, and the vOLT can carry the management MAC address and IP of the vOLT through the extended TLV in the EAPoL response to the optical access module, or in the subsequent light.
  • the access module manages the IP address through DHCP
  • the configuration parameters are delivered including the MAC and IP of the vOLT.
  • the topology discovery is performed between the optical access module and the vOLT, and a Layer 3 or Layer 2 management channel is established between the optical access module and the vOLT, and the optical access module directly accepts management and control of the vOLT.
  • the topology discovery is completed between the optical access module and the vOLT, and the vOLT is controlled by the vOLT as a virtual network controller.
  • the management module can be used to establish a management channel between the access module and the vOLT, or a Layer 2 connection, such as the ETH-MCC of the Y.1731.
  • step S912 the optical access module obtains the authorization of the vOLT, accepts the authentication registration of the ONT to the vOLT, completes the topology discovery between the ONT and the vOLT, and the management channel between the access module and the ONT follows the existing methods such as OMCC.
  • the various modules or steps of the present invention described above can be used with general calculations.
  • the devices are implemented, they may be centralized on a single computing device, or distributed over a network of multiple computing devices, optionally they may be implemented in program code executable by the computing device, such that they may be stored Executed by the computing device in a storage device, and in some cases, the steps shown or described may be performed in an order different than that herein, or separately fabricated into individual integrated circuit modules, or Multiple modules or steps are made into a single integrated circuit module.
  • the invention is not limited to any specific combination of hardware and software.
  • the virtualized optical line terminal vOLT receives the physical location information of the optical access module and the device identifier of the optical access module; the vOLT uses the device according to the device identifier of the optical access module.
  • the access module performs authentication.
  • the vOLT passes the authentication of the optical access module, the vOLT sends management configuration information to the optical access module corresponding to the physical location information, where the vOLT is configured according to the management configuration information.
  • the optical access module establishes a management channel, which solves the problem that the vOLT cannot effectively register and register the optical access module under the virtualization architecture, and realizes the discovery, authentication, and registration of the optical access module by the vOLT.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Small-Scale Networks (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

La présente invention concerne un procédé, un dispositif et un système d'authentification et d'enregistrement pour un module d'accès optique. Le procédé comprend les étapes suivantes : un terminal de ligne optique de virtualisation (vOLT) reçoit des informations de position physique relatives à un module d'accès optique et à l'identification de dispositif du module d'accès optique ; le vOLT met en oeuvre une authentification sur le module d'accès optique selon l'identification de dispositif du module d'accès optique ; et, en cas d'authentification réussie dudit vOLT sur le module d'accès optique, le vOLT envoie des informations de gestion et de configuration au module d'accès optique qui correspondent aux informations de position physique, et le vOLT établit un canal de gestion avec le module d'accès optique selon les informations de gestion et de configuration. L'invention, qui résout le problème de l'impossibilité de mettre en oeuvre efficacement une authentification et un enregistrement sur un module d'accès optique sous une structure de virtualisation, permet ainsi de mettre en oeuvre la découverte, l'authentification et l'enregistrement d'un vOLT sur le module d'accès optique.
PCT/CN2015/094729 2015-04-24 2015-11-16 Procédé, dispositif et système d'authentification et d'enregistrement pour module d'accès optique Ceased WO2016169260A1 (fr)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201510202164.7A CN106162387B (zh) 2015-04-24 2015-04-24 光接入模块的认证注册方法、装置及系统
CN201510202164.7 2015-04-24

Publications (1)

Publication Number Publication Date
WO2016169260A1 true WO2016169260A1 (fr) 2016-10-27

Family

ID=57143714

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2015/094729 Ceased WO2016169260A1 (fr) 2015-04-24 2015-11-16 Procédé, dispositif et système d'authentification et d'enregistrement pour module d'accès optique

Country Status (2)

Country Link
CN (1) CN106162387B (fr)
WO (1) WO2016169260A1 (fr)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107342820A (zh) * 2017-01-09 2017-11-10 烽火通信科技股份有限公司 基于模板管理实现volt的方法及系统
CN107493524A (zh) * 2017-09-21 2017-12-19 烽火通信科技股份有限公司 一种实现虚拟olt的方法
WO2018157299A1 (fr) * 2017-02-28 2018-09-07 华为技术有限公司 Procédé de virtualisation pour dispositif olt (terminaison de ligne optique), et dispositif associé

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111385026B (zh) * 2018-12-29 2022-08-26 中兴通讯股份有限公司 一种olt设备虚拟化的方法及olt设备
CN110121123A (zh) * 2019-05-10 2019-08-13 江西山水光电科技股份有限公司 一种pon聚合拉远设备管理方法

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20050053376A1 (en) * 2003-09-08 2005-03-10 Young-Hun Joo FTTH system for convergence of broadcasting and communication through switched broadcasting
CN101621331A (zh) * 2008-06-30 2010-01-06 中兴通讯股份有限公司 光网络单元配置方法和装置
CN102882717A (zh) * 2012-09-26 2013-01-16 烽火通信科技股份有限公司 无源光网络系统中光网络单元的管理方法

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101562480A (zh) * 2008-04-15 2009-10-21 华为技术有限公司 一种光接入网络、光线路终端的备份方法、系统及设备

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20050053376A1 (en) * 2003-09-08 2005-03-10 Young-Hun Joo FTTH system for convergence of broadcasting and communication through switched broadcasting
CN101621331A (zh) * 2008-06-30 2010-01-06 中兴通讯股份有限公司 光网络单元配置方法和装置
CN102882717A (zh) * 2012-09-26 2013-01-16 烽火通信科技股份有限公司 无源光网络系统中光网络单元的管理方法

Cited By (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107342820A (zh) * 2017-01-09 2017-11-10 烽火通信科技股份有限公司 基于模板管理实现volt的方法及系统
CN107342820B (zh) * 2017-01-09 2019-06-25 烽火通信科技股份有限公司 基于模板管理实现volt的方法及系统
WO2018157299A1 (fr) * 2017-02-28 2018-09-07 华为技术有限公司 Procédé de virtualisation pour dispositif olt (terminaison de ligne optique), et dispositif associé
CN110301104A (zh) * 2017-02-28 2019-10-01 华为技术有限公司 一种光线路终端olt设备虚拟方法及相关设备
CN110301104B (zh) * 2017-02-28 2021-01-05 华为技术有限公司 一种光线路终端olt设备虚拟方法及相关设备
US11336973B2 (en) 2017-02-28 2022-05-17 Huawei Technologies Co., Ltd. Optical line terminal OLT device virtualization method and related device
CN107493524A (zh) * 2017-09-21 2017-12-19 烽火通信科技股份有限公司 一种实现虚拟olt的方法
CN107493524B (zh) * 2017-09-21 2020-02-11 烽火通信科技股份有限公司 一种实现虚拟olt的方法

Also Published As

Publication number Publication date
CN106162387B (zh) 2020-08-18
CN106162387A (zh) 2016-11-23

Similar Documents

Publication Publication Date Title
US11038751B2 (en) Information processing method, network node, authentication method, and server
CN106161077B (zh) 接入汇聚装置和认证注册方法
US11336973B2 (en) Optical line terminal OLT device virtualization method and related device
US9832136B1 (en) Streaming software to multiple virtual machines in different subnets
US10367693B2 (en) Service configuration data processing method and apparatus
CN108881308B (zh) 一种用户终端及其认证方法、系统、介质
US20150049631A1 (en) Topology aware provisioning in a software-defined networking environment
CA3063688A1 (fr) Procede et systeme d'etablissement d'un chemin de service dans un reseau de communication
CN103701628A (zh) 家庭网关的配置管理方法、虚拟家庭网关和光网络终端
CN106533883A (zh) 一种网络专线的建立方法、装置及系统
US9118588B2 (en) Virtual console-port management
CN106162387B (zh) 光接入模块的认证注册方法、装置及系统
CN107769939B (zh) 数据通信网中网元管理方法、网管、网关网元及系统
KR20130101663A (ko) 클라우드 네트워킹 장치 및 방법
CN103200030B (zh) 网络管理的装置和方法
US11956574B2 (en) Optical communication network system, optical network unit, and optical communication method
WO2018171124A1 (fr) Procédé d'attribution de ressource, serveur, terminal de ligne optique, et système
CN112929387B (zh) 应用于智慧社区的宽带网络多重认证、加密方法
CN104253980A (zh) 一种前端设备与后台媒体设备的连接方法及装置
WO2017076146A1 (fr) Procédé et système d'authentification d'accès au réseau
US12081924B2 (en) Optical network unit, communication network system and communication method
CN103227822B (zh) 一种p2p通信连接建立方法和设备
WO2017219856A1 (fr) Procédé et système de traitement de validation de circuits, contrôleur, et support de stockage informatique
WO2017077760A1 (fr) Dispositif côté station, dispositif de gestion d'informations, procédé d'authentification de terminal et procédé de gestion d'informations
US20130275967A1 (en) Dynamic provisioning of virtual systems

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15889743

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 15889743

Country of ref document: EP

Kind code of ref document: A1