An authentication method for link protection between an OLT and an ONU
newly connected thereto in an EPON, which is implemented in a data link
layer to which cryptography is applied. First, an authentication key is
distributed to both the OLT and an ONU. The OLT (or ONU) generates first
and second random values, generates an authentication request frame
containing the random values, and transmits it to the ONU (or OLT). The
ONU generates a first hash value according to a hash function using the
random values contained in the request frame, and transmits an
authentication response frame containing the first hash value to the OLT.
The OLT compares the first hash value with a second hash value calculated
by it according to the has function using the two random values and an
authentication key distributed to it, and transmits an authentication
result frame to the ONU.