Terminal authentication method and device, server and medium

By redirecting the terminal to the correct authentication server for authentication after the cloud management network is split, the problem of the terminal being unable to authenticate after the cloud management network is split, and the reliability of network equipment management is improved.

CN120455118APending Publication Date: 2025-08-08NEW H3C TECH CO LTD
View PDF 10 Cites 0 Cited by

Patent Information

Application Number
CN202510706202.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-28
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

After the cloud management network is split, the original authentication server cannot authenticate the terminal connected to the access device, resulting in users being unable to access, reducing the reliability of network device management.

Method used

The first authentication server receives the terminal's authentication request message and obtains the management identifier and authentication template identifier of the access device. If the access device does not belong to the first cloud management network, it will be redirected to the corresponding second cloud management network authentication server for authentication processing, which solves the problem that some terminals cannot be authenticated after the cloud management network is split.

Benefits of technology

It realizes effective authentication of terminals after the cloud management network split, improves the reliability of network equipment management, and ensures that users can access the network normally.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455118A_ABST
    Figure CN120455118A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a terminal authentication method and device, a server and a medium, relates to the technical field of communication, is applied to a first authentication server in a first cloud management network, and comprises the following steps: receiving a first authentication request message forwarded by a terminal according to an address of the first authentication server carried by the first authentication request message, the first authentication request message is sent by an access device connected with the terminal, and the first authentication request message further carries a management identifier and an authentication template identifier of the access device; and if the management identifier of the access device is not the management identifier in the first cloud management network and the authentication template identifier of the access device corresponds to authentication of a second authentication server in a second cloud management network, sending an address of the second authentication server to the terminal, so that the terminal performs authentication processing by using authentication information in the second authentication server. According to the method, the problem that part of terminals cannot be authenticated after the cloud management network is split can be solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a terminal authentication method, device, server and medium. Background Art

[0002] The cloud management network manages access devices connected to the network. Each access device managed by the cloud management network is configured with the address of its authentication server. After a terminal connects to the access device, it obtains the authentication server address from the access device and sends an authentication request message to the server, which then authenticates the terminal. Once the authentication server successfully authenticates the terminal, the terminal can access the network normally.

[0003] To facilitate the management of different types of access devices, the cloud management network is split into multiple cloud management sub-networks. Each cloud management network manages a specific type of access device. Each cloud management sub-network also deploys an authentication server responsible for authenticating terminals connected to the access devices managed by that cloud management network. In this scenario, the authentication server in one cloud management sub-network can use its original address, while the authentication servers in other cloud management networks must use different addresses.

[0004] After the cloud management network is split, the address configured on the configured access device remains the original address. The terminal connected to the access device is authenticated based on the original address on the authentication server in the cloud management sub-network using the original address. However, if the access device is managed by another cloud management sub-network formed by the split, the authentication server in the original cloud management network will not be able to authenticate the terminal connected to the access device, resulting in user access failure and reduced reliability of network device management. Summary of the Invention

[0005] The purpose of the embodiments of the present application is to provide a terminal authentication method, apparatus, server, and medium to improve the reliability of network device management after the cloud-management network is split. The specific technical solution is as follows:

[0006] In a first aspect, an embodiment of the present application provides a terminal authentication method, applied to a first authentication server in a first cloud management network, the method comprising:

[0007] receiving a first authentication request message forwarded by a terminal according to the address of the first authentication server carried in the first authentication request message, where the first authentication request message is sent by an access device to which the terminal is connected, and the first authentication request message further carries a management identifier and an authentication template identifier of the access device;

[0008] If the management identifier of the access device is not the management identifier in the first cloud management network, and the authentication template identifier of the access device corresponds to the second authentication server authentication in the second cloud management network, the address of the second authentication server is sent to the terminal so that the terminal uses the authentication information in the second authentication server for authentication processing.

[0009] In some embodiments, the method further comprises:

[0010] If the first preset condition is met, sending the address of the third-party authentication server to the terminal, so that the terminal performs authentication processing using the authentication information in the third-party authentication server;

[0011] The first preset condition includes:

[0012] The management identifier of the access device is not a management identifier in the first cloud management network, and the authentication template identifier of the access device corresponds to the third-party authentication server authentication; or,

[0013] The management identifier of the access device is not a management identifier in the first cloud management network, the authentication template identifier of the access device corresponds to the third-party authentication server authentication and the second authentication server authentication, and the terminal indicates that the authentication mode is the third-party authentication server authentication; or,

[0014] The management identifier of the access device is a management identifier in the first cloud management network, and the authentication template identifier of the access device corresponds to the third-party authentication server authentication; or,

[0015] The management identifier of the access device is the management identifier in the first cloud management network, the authentication template identifier of the access device corresponds to the third-party authentication server authentication and the first authentication server authentication, and the terminal indicates that the authentication method is the third-party authentication server authentication.

[0016] In some embodiments, the method further comprises:

[0017] If a second preset condition is met, authenticating the terminal using the authentication information in the first authentication server;

[0018] The second preset condition includes:

[0019] The management identifier of the access device is not a management identifier in the first cloud management network, the authentication template identifier of the access device corresponds to third-party authentication server authentication and second authentication server authentication, and the terminal indicates that the authentication mode is the second authentication server authentication; or

[0020] The management identifier of the access device is a management identifier in the first cloud management network, and the authentication template identifier of the access device corresponds to the first authentication server authentication; or,

[0021] The management identifier of the access device is the management identifier in the first cloud management network, the authentication template identifier of the access device corresponds to third-party authentication server authentication and first authentication server authentication, and the terminal indicates that the authentication method is the first authentication server authentication.

[0022] In some embodiments, before receiving the first authentication request message forwarded by the terminal, the method further includes:

[0023] receiving an authentication-free request message of the terminal sent by the access device, where the authentication-free request message carries a management identifier of the access device;

[0024] If the management identifier of the access device is not a management identifier in the first cloud management network, forwarding the authentication-free request message to the second authentication server, so that the second authentication server performs authentication-free processing on the terminal using the authentication-free information, and obtains an authentication-free processing result; if the management identifier of the access device is a management identifier in the first cloud management network, performing authentication-free processing on the terminal using the authentication-free information in the first authentication server, and obtains an authentication-free processing result;

[0025] The authentication-free processing result is sent to the access device, so that when the authentication-free processing result indicates that the authentication-free processing has failed, the access device sends a first authentication request message to the terminal, the terminal forwards the first authentication request message to the first authentication server, and the first authentication server executes the step of receiving the first authentication request message forwarded by the terminal according to the address of the first authentication server carried in the first authentication request message.

[0026] In some embodiments, after the terminal passes authentication using the authentication information in the third-party authentication server, or passes authentication using the authentication information in the first authentication server, or passes authentication-free processing on the terminal using the authentication-free information on the second authentication server, the method further includes:

[0027] Receive an online (online) confirmation response (ACK) message sent by the access device; according to the online confirmation response message, send an online notification message to the second authentication server, wherein the online notification message carries user management information of the terminal, so that the second authentication server stores the user management information.

[0028] In some embodiments, after sending the online notification message to the second authentication server, the method further includes:

[0029] Receive a offline notification message of the terminal sent by the access device; and forward the offline notification message to the second authentication server so that the second authentication server updates user management information of the terminal.

[0030] In a second aspect, an embodiment of the present application provides a terminal authentication device, which is applied to a first authentication server in a first cloud management network, and the device includes:

[0031] a receiving module, configured to receive a first authentication request message forwarded by a terminal according to the address of the first authentication server carried in the first authentication request message, wherein the first authentication request message is sent by an access device to which the terminal is connected, and the first authentication request message further carries a management identifier and an authentication template identifier of the access device;

[0032] An authentication module is used to send the address of the second authentication server to the terminal if the management identifier of the access device is not the management identifier in the first cloud management network, and the authentication template identifier of the access device corresponds to the second authentication server authentication in the second cloud management network, so that the terminal uses the authentication information in the second authentication server for authentication processing.

[0033] In some embodiments, the authentication module is further configured to:

[0034] If the first preset condition is met, sending the address of the third-party authentication server to the terminal, so that the terminal performs authentication processing using the authentication information in the third-party authentication server;

[0035] The first preset condition includes:

[0036] The management identifier of the access device is not a management identifier in the first cloud management network, and the authentication template identifier of the access device corresponds to the third-party authentication server authentication; or,

[0037] The management identifier of the access device is not a management identifier in the first cloud management network, the authentication template identifier of the access device corresponds to the third-party authentication server authentication and the second authentication server authentication, and the terminal indicates that the authentication mode is the third-party authentication server authentication; or,

[0038] The management identifier of the access device is a management identifier in the first cloud management network, and the authentication template identifier of the access device corresponds to the third-party authentication server authentication; or,

[0039] The management identifier of the access device is the management identifier in the first cloud management network, the authentication template identifier of the access device corresponds to the third-party authentication server authentication and the first authentication server authentication, and the terminal indicates that the authentication method is the third-party authentication server authentication.

[0040] In some embodiments, the authentication module is further configured to:

[0041] The authentication module is further configured to:

[0042] If a second preset condition is met, authenticating the terminal using the authentication information in the first authentication server;

[0043] The second preset condition includes:

[0044] The management identifier of the access device is not a management identifier in the first cloud management network, the authentication template identifier of the access device corresponds to third-party authentication server authentication and second authentication server authentication, and the terminal indicates that the authentication mode is the second authentication server authentication; or

[0045] The management identifier of the access device is a management identifier in the first cloud management network, and the authentication template identifier of the access device corresponds to the first authentication server authentication; or,

[0046] The management identifier of the access device is the management identifier in the first cloud management network, the authentication template identifier of the access device corresponds to third-party authentication server authentication and first authentication server authentication, and the terminal indicates that the authentication method is the first authentication server authentication.

[0047] In some embodiments, the apparatus further includes: an authentication-free module, configured to receive an authentication-free request message of the terminal sent by the access device before receiving the first authentication request message forwarded by the terminal, wherein the authentication-free request message carries a management identifier of the access device;

[0048] If the management identifier of the access device is not a management identifier in the first cloud management network, forwarding the authentication-free request message to the second authentication server, so that the second authentication server performs authentication-free processing on the terminal using the authentication-free information, and obtains an authentication-free processing result; if the management identifier of the access device is a management identifier in the first cloud management network, performing authentication-free processing on the terminal using the authentication-free information in the first authentication server, and obtains an authentication-free processing result;

[0049] The authentication-free processing result is sent to the access device, so that when the authentication-free processing result indicates that the authentication-free processing has failed, the access device sends a first authentication request message to the terminal, the terminal forwards the first authentication request message to the first authentication server, and the first authentication server executes the step of receiving the first authentication request message forwarded by the terminal according to the address of the first authentication server carried in the first authentication request message.

[0050] In some embodiments, the authentication module is further configured to:

[0051] After the terminal passes authentication using the authentication information in the third-party authentication server, or passes authentication using the authentication information in the first authentication server, or passes authentication-free processing for the terminal using the authentication-free information on the second authentication server, an online confirmation response message is received from the access device; and based on the online confirmation response message, an online notification message is sent to the second authentication server, where the online notification message carries user management information of the terminal, so that the second authentication server stores the user management information.

[0052] In some embodiments, the authentication module is further configured to:

[0053] After sending the online notification message to the second authentication server, receiving the offline notification message of the terminal sent by the access device; forwarding the offline notification message to the second authentication server, so that the second authentication server updates the user management information of the terminal.

[0054] In a third aspect, an embodiment of the present application provides a server comprising a processor and a machine-readable storage medium, wherein the machine-readable storage medium stores machine-executable instructions that can be executed by the processor, and the processor is prompted by the machine-executable instructions to implement any of the methods provided in the first aspect above.

[0055] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, any one of the methods provided in the first aspect is implemented.

[0056] In a fifth aspect, an embodiment of the present application further provides a computer program product comprising instructions, which, when executed on a computer, enables the computer to execute any one of the methods provided in the first aspect.

[0057] Beneficial effects of the embodiments of the present application:

[0058] In the technical solution provided by the embodiment of the present application, the first authentication server receives the first authentication request message forwarded by the terminal, and obtains the management identifier and authentication template identifier of the access device. When the management identifier of the access device is not the management identifier in the first cloud management network, indicating that the first cloud management network is not the cloud management network that manages the access device, then the authentication template identifier of the access device corresponds to the second authentication server in the second cloud management network, and the terminal uses the authentication information in the second authentication server to authenticate the terminal. By applying the technical solution provided by the embodiment of the present application, the terminal is authenticated by redirecting to the second authentication server that manages the access device, which solves the problem that some terminals cannot be authenticated after the cloud management network is split, resulting in users being unable to access, and improves the reliability of network device management after the cloud management network is split.

[0059] Of course, it is not necessary to achieve all the advantages described above at the same time when implementing any product or method of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0060] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other embodiments can also be obtained based on these drawings.

[0061] Figure 1 A schematic diagram of a first flow chart of a terminal authentication method provided in an embodiment of the present application;

[0062] Figure 2 A second flow chart of the terminal authentication method provided in an embodiment of the present application;

[0063] Figure 3 This is a first interaction diagram for terminal authentication provided in an embodiment of the present application;

[0064] Figure 4 This is a second interaction diagram for terminal authentication provided in an embodiment of the present application;

[0065] Figure 5 This is a third interaction diagram for terminal authentication provided in an embodiment of the present application;

[0066] Figure 6 An interactive diagram of terminal authentication exemption provided in an embodiment of the present application;

[0067] Figure 7 A schematic diagram of the structure of a terminal authentication device provided in an embodiment of the present application;

[0068] Figure 8A schematic diagram of the structure of a server provided in an embodiment of the present application. DETAILED DESCRIPTION

[0069] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field based on this application are within the scope of protection of this application.

[0070] The cloud management network manages access devices connected to the network. Each access device managed by the cloud management network is configured with the address of its authentication server. After a terminal connects to the access device, it obtains the authentication server address from the access device and sends an authentication request message to the server, which then authenticates the terminal. Once the authentication server successfully authenticates the terminal, the terminal can access the network normally.

[0071] To facilitate the management of different types of access devices, the cloud management network is divided into multiple cloud management sub-networks. Each cloud management network manages a specific type of access device. Each cloud management sub-network has an authentication server deployed in it, responsible for authenticating terminals connecting to the access devices managed by that cloud management network. In this scenario, the authentication server in one cloud management sub-network can use its original address, while the authentication servers in other cloud management networks must use different addresses. Each authentication server is independent of the others, and their databases, file systems, and other systems are not interconnected.

[0072] For example, the cloud management network is Oasis, which manages both commercial devices (i.e., commercial access devices) and industry devices (i.e., industry access devices). The authentication server address is aaa.xxx.com. To facilitate management, the Oasis network is split into an industry-specific cloud management sub-network and a business-specific cloud management sub-network, namely the Oasis network and the uCloud network. The Oasis network manages industry devices, and the authentication server is responsible for authenticating terminals connected to industry devices, using the original address: aaa.xxx.com. The uCloud network manages business devices, and the authentication server is responsible for authenticating terminals connected to industry devices, using the address: bbb.xxx.com.

[0073] After the cloud management network is split, the address configured on the configured access device remains the original address. The terminal connected to the access device is authenticated based on the original address on the authentication server in the cloud management sub-network using the original address. However, if the access device is managed by another cloud management sub-network formed by the split, the authentication server in the original cloud management network will not be able to authenticate the terminal connected to the access device, resulting in user access failure and reduced reliability of network device management.

[0074] For example, the authentication server in the Jianyou Cloud network uses the address bbb.xxx.com, while the address configured on the commercial device is still aaa.xxx.com; the terminal connected to the commercial device still sends authentication request messages to the authentication server in the Jianyou Cloud network based on the address configured on the commercial device, but the authentication server in the Jianyou Cloud network cannot authenticate the terminal connected to the commercial device, which results in the user being unable to access.

[0075] In order to solve the above problems, the embodiment of the present application provides a terminal authentication method, which is applied to the first authentication server in the first cloud management network. Figure 1 , Figure 1 This is a first flow chart of a terminal authentication method provided in an embodiment of the present application, which includes the following steps:

[0076] Step S11: receiving a first authentication request message forwarded by a terminal according to the address of a first authentication server carried in the first authentication request message. The first authentication request message is sent by an access device connected to the terminal and also carries a management identifier and an authentication template identifier of the access device.

[0077] In step S12, if the management identifier of the access device is not the management identifier in the first cloud management network, and the authentication template identifier of the access device corresponds to the second authentication server authentication in the second cloud management network, the address of the second authentication server is sent to the terminal so that the terminal uses the authentication information in the second authentication server for authentication processing.

[0078] In the technical solution provided by the embodiment of the present application, the first authentication server receives the first authentication request message forwarded by the terminal, and obtains the management identifier and authentication template identifier of the access device. When the management identifier of the access device is not the management identifier in the first cloud management network, indicating that the first cloud management network is not the cloud management network that manages the access device, then the authentication template identifier of the access device corresponds to the second authentication server in the second cloud management network, and the terminal uses the authentication information in the second authentication server to authenticate the terminal. By applying the technical solution provided by the embodiment of the present application, the terminal is authenticated by redirecting to the second authentication server that manages the access device, which solves the problem that some terminals cannot be authenticated after the cloud management network is split, resulting in users being unable to access, and improves the reliability of network device management after the cloud management network is split.

[0079] In the above step S11, the terminal is any user device to be authenticated, which can be a mobile phone, a personal computer (PC), etc. The terminal can be authenticated through a client such as a browser, and there is no limitation on this. The terminal is connected to an access device, and the access device can be a network device that provides authentication functions, such as an access controller (AC), an access point (AP), a router, etc., and there is no limitation on this. The access device is pre-configured with the address of an authentication server, which is the first authentication server, and the cloud management network where the first authentication server is located is the first cloud management network.

[0080] In this embodiment of the present application, the system within which the first cloud management network resides may also include other cloud management networks (such as a second cloud management network). Each cloud management network in the system is a cloud management sub-network split from the original cloud management network and belongs to the same cloud server provider. The address of the authentication server in the original cloud management network is retained by the first authentication server. For ease of understanding, the cloud management sub-network is referred to herein as the cloud management network.

[0081] In the embodiment of the present application, the cloud management network that manages the access device is referred to as the target cloud management network. The access device stores the management identifier and the authentication template identifier of the access device. The management identifier is the identifier of the management group to which the access device belongs in the target cloud management network that manages the access device. The authentication template identifier is the identifier of the configuration information of the access device. The configuration information may include information required for authentication, such as the authentication method and the authentication login page. The authentication method includes the authentication method that the terminal can adopt during the authentication process. The authentication login page is the authentication page displayed on the terminal. The content of the configuration information is not limited here. For the sake of ease of description, the management identifier of the access device will be referred to as the target management identifier, and the authentication template identifier of the access device will be referred to as the target authentication template identifier.

[0082] In an embodiment of the present application, after connecting to an access device, a terminal may send an access request message to the access device requesting access to any web page. The access request message may carry an access address, the terminal's Media Access Control (MAC) address, and Internet Protocol (IP) address. The access address may be the IP address or Uniform Resource Locator (URL) address of a web page.

[0083] The access device receives the access request message. If the access address is a URL, the access device can perform Domain Name System (DNS) resolution on the domain name included in the URL to convert it into an IP address. If the access address is an IP address, the access device can directly obtain the IP address.

[0084] The access device determines whether the obtained IP address is on a pre-stored blocking whitelist. If it is, the terminal can access the webpage directly without authentication. If it is not, the terminal cannot access the webpage directly and must first be authenticated.

[0085] In the embodiment of the present application, the first authentication request message is a message for the terminal to perform authentication. The access device can generate the first authentication request message, which carries the address of the authentication server configured on the access device (i.e., the address of the first authentication server), the target management identifier, and the target authentication template identifier. The first authentication request message can also carry the MAC address and IP address of the terminal, which are not limited to this.

[0086] The access device sends a first authentication request message to the terminal. The terminal receives the first authentication request message and forwards the first authentication request message to the first authentication server according to the address of the first authentication server carried in the first authentication request message, thereby redirecting the first authentication request message to the first authentication server.

[0087] In an embodiment of the present application, the IP address corresponding to the address of the first authentication server is configured in an interception whitelist of the access device. When the terminal sends a first authentication request message to the first authentication server based on the address of the first authentication server, the access device can extract the domain name of the first authentication server from the address of the first authentication server, resolve the domain name into an IP address, and determine that the resolved IP address is in the interception whitelist. Therefore, the access device will not intercept the first authentication request message, and the terminal can send the first authentication request message to the first authentication server.

[0088] In step S12, the first authentication server stores a management identifier in the first cloud management network, that is, an identifier of the management group to which the access device managed by the first cloud management network belongs.

[0089] The first authentication server also stores authentication template identifiers for the first cloud management network and authentication template identifiers for the second cloud management network. Specifically, the first authentication server stores authentication template identifiers for access devices managed by the first cloud management network and authentication template identifiers for access devices managed by the second cloud management network. The first authentication server may also store configuration information such as authentication methods and authentication login pages corresponding to all authentication template identifiers.

[0090] The first authentication server receives a first authentication request message from a terminal and retrieves the target management identifier and target authentication template identifier carried in the first authentication request message. The first authentication server may first search for the target management identifier among the stored management identifiers. The search result for the target management identifier can be divided into the following two specific cases.

[0091] In case 1, the first authentication server fails to find the target management identifier, and the target management identifier is not a management identifier in the first cloud management network. In other words, the access device is not managed by the first cloud management network, and the target cloud management network that manages the access device is the second cloud management network.

[0092] In case 1, the first authentication server can search for the target authentication template identifier in the stored authentication template identifiers, and determine the authentication method corresponding to the target authentication template identifier. In an embodiment of the present application, the authentication methods can be divided into two types, namely, a third-party authentication method and an ordinary authentication method. The third-party authentication method is an authentication method that needs to be authenticated on the authentication server of a third-party platform (referred to as a third-party authentication server), which may include public account authentication, mini-program visitor authentication, third-party software authentication, etc., and is not limited to this. The ordinary authentication method is an authentication method that does not require authentication on a third-party authentication server, which may include one-click authentication, account authentication, SMS authentication, etc., and is not limited to this. According to the authentication method corresponding to the target authentication template identifier, it can be specifically divided into the following three situations.

[0093] In case 1a, the authentication method corresponding to the target authentication template identifier only includes the normal authentication method. In case 1a, the terminal can use the authentication server in the second cloud management network (referred to as the second authentication server) for authentication. That is, the target authentication template identifier corresponds to the second authentication server authentication, and the terminal indicates the authentication method (i.e., the authentication method used by the terminal for authentication) as the second authentication server authentication.

[0094] The first authentication server may also store the address of the second authentication server. After determining that the target authentication template identifier corresponds to the second authentication server, the first authentication server may send the address of the second authentication server to the terminal. The terminal may perform authentication on the second authentication server based on the address of the second authentication server.

[0095] In an embodiment of the present application, the first authentication server may generate a second authentication request message carrying the address of the second authentication server and the target authentication template identifier, and send the second authentication request message to the terminal. After receiving the second authentication request message, the terminal may forward the second authentication request message to the second authentication server based on the address of the second authentication server carried in the second authentication request message, and perform authentication using the second authentication request message. The second authentication request message may also carry the target management identifier, the terminal's MAC address, the IP address, and other information, without limitation.

[0096] In an embodiment of the present application, the domain name of the first authentication server and the IP address corresponding to the domain name of the second authentication server are the same and are configured in an interception whitelist on the access device. When the terminal sends a second authentication request message to the second authentication server based on the address of the second authentication server, the access device can extract the domain name of the second authentication server from the address of the second authentication server, resolve the domain name into an IP address, and determine that the resolved IP address is in the interception whitelist. Therefore, the access device will not intercept the second authentication request message, and the terminal can send the second authentication request message to the second authentication server.

[0097] In this embodiment of the present application, the second authentication server stores an authentication template identifier belonging to the second cloud management network. That is, the second authentication server stores an authentication template identifier of an access device managed by the second cloud management network, and configuration information such as an authentication method corresponding to the stored authentication template identifier.

[0098] The second authentication server may receive the second authentication request message and obtain the target authentication template identifier carried in the second authentication request message. The second authentication server may search for the target authentication template identifier in the stored authentication template identifiers, determine the configuration information corresponding to the target authentication template identifier, and perform authentication processing on the terminal.

[0099] In an embodiment of the present application, the second authentication server may further store a management identifier in the second cloud management network, that is, an identifier of the management group to which the access device managed by the second cloud management network belongs. To ensure the accuracy of authentication, after receiving the second authentication request message, the second authentication server may further obtain the target management identifier carried in the second authentication request message, search for the target management identifier among the stored management identifiers, and after finding the target management identifier, search for the target authentication template identifier. This is not limited to this.

[0100] The following describes in detail the process of the second authentication server authenticating the terminal.

[0101] In an embodiment of the present application, the configuration information may include an authentication login page. The second authentication server may return the authentication login page to the terminal, which then receives and displays the authentication login page. The authentication login page may include one or more common authentication methods. When the authentication login page includes one common authentication method, the authentication method indicated by the terminal is that method. When the authentication login page includes multiple common authentication methods, the user may select one on the authentication login page, in which case the authentication method selected by the user is the authentication method indicated by the terminal.

[0102] The terminal can send the information entered by the user on the authentication login page to the second authentication server. If the terminal indicates that the authentication method is account authentication, the information entered by the user can be a username and password; if the terminal indicates that the authentication method is SMS authentication, the information entered by the user can be a mobile phone number and verification code, without limitation.

[0103] In the embodiment of the present application, the second authentication server stores authentication information. The authentication information in the second authentication server is user information pre-configured in the second cloud management network for authentication. The authentication information may include the user's username, password, mobile phone number, etc., which is not limited to this.

[0104] The second authentication server can authenticate the information input by the user based on the authentication method indicated by the terminal and the stored authentication information. If the second authentication server successfully authenticates the terminal, it generates an authentication random number (code).

[0105] After generating the authentication random number, the second authentication server can also cache user access information such as the terminal's MAC address, IP address, target management identifier, and target authentication template identifier, as well as authentication information corresponding to the authentication method indicated by the terminal. For example, for SMS authentication, the authentication information is the mobile phone number; for account authentication, the authentication information is the username.

[0106] The second authentication server generates a message carrying the authentication random number and the address of the access device and returns the message to the terminal. The terminal receives the message sent by the second authentication server and forwards it to the access device, thereby redirecting the user to the access device.

[0107] The access device receives the message and forwards it to the second authentication server. The second authentication server performs verification based on the authentication random number carried in the message, and after the verification is successful, returns an access token to the access device. The access device sends a message carrying the access token to the second authentication server, and the second authentication server performs verification based on the access token carried in the message, and after the verification is successful, returns the cached information (such as user access information and authentication information) to the access device. In an embodiment of the present application, the access device can obtain the MAC address and IP address of the terminal based on the access request message sent by the terminal. In this case, the second authentication server can only return the authentication information.

[0108] In scenario 1a, after receiving the authentication information, the access device returns a login success page to the terminal, allowing the terminal to log in. The access device may also send an online confirmation response message to the second authentication server. This message carries online status information indicating that the terminal has logged in. The message may also carry the terminal's MAC address and IP address.

[0109] The second authentication service can determine that the terminal is online based on the online status information carried in the online confirmation response message, and store user management information. User management information may include user access information, authentication information, online list, authentication-free information, etc. For example, the second authentication service can save the terminal's MAC address, IP address, target management identifier of the access device, target authentication template identifier, user's online time, cumulative Internet access time and other user access information, record the authentication method indicated by the terminal for this authentication and the authentication information corresponding to the authentication method, and add the terminal to the online list. If the user selects the authentication-free option, the second authentication server also generates an authentication-free table entry including authentication-free information, or updates the aging time of the authentication-free table entry. The authentication-free information may include the target management identifier and target authentication template identifier of the access device, and may also include device information such as the service set identifier (SSID) of the access device and the device serial number.

[0110] After a terminal goes offline, the access device sends a terminal offline notification message to the secondary authentication server. This message carries the terminal's MAC address. The secondary authentication server can then update user management information based on the MAC address. For example, the secondary authentication server can update user access information such as cumulative online time and remove the terminal from the online list.

[0111] In case 1b, the authentication method corresponding to the target authentication template identifier only includes third-party authentication. In case 1b, the terminal can use the third-party authentication server for authentication. That is, the target authentication template identifier corresponds to third-party authentication server authentication, and the terminal indicates that the authentication method is third-party authentication server authentication.

[0112] In the embodiment of the present application, in order to ensure that the authentication function is available when the third-party authentication server is used for authentication, the terminal can use the first authentication server to assist in the authentication process.

[0113] The following describes in detail the process of authenticating the terminal using the authentication information in the third-party authentication server.

[0114] In an embodiment of the present application, after determining that the target authentication template identifier corresponds to authentication with a third-party authentication server, the first authentication server may return an authentication login page to the terminal. In this case, the authentication login page may include one or more third-party authentication methods. For example, if the authentication login page includes multiple third-party authentication methods, the third-party authentication method selected by the user is the authentication method indicated by the terminal.

[0115] The first authentication server may store the addresses of various third-party authentication servers. In response to a user's selection, the first authentication server may send the address of the third-party authentication server corresponding to the third-party authentication method selected by the user to the terminal. The terminal may then perform authentication based on the address of the third-party authentication server and the authentication information stored in the third-party authentication server.

[0116] In an embodiment of the present application, the first authentication server may generate a message in response to a user's selection operation. The message may carry the address and third-party identifier of the third-party authentication server corresponding to the third-party authentication method selected by the user, as well as user access information such as the MAC address of the terminal. The first authentication server may send the generated message to the terminal, and the terminal may forward the message to the third-party authentication server to redirect the user to the third-party authentication server. Depending on the third-party authentication server, the third-party identifier may be an enterprise identifier, an application identifier, or an application programming interface (API), etc., and this is not limited to this.

[0117] In an embodiment of the present application, the third-party authentication server may use a third-party identifier to obtain a third-party random number of the third-party authentication server and generate a message carrying the third-party random number.

[0118] A domain name whitelist may be pre-stored in the third-party authentication server, and the authentication servers indicated by the domain names in the domain name whitelist are authorized authentication servers. In the embodiment of the present application, since the domain name whitelist is configured before the original cloud management network is split, the domain name whitelist only includes the domain names of the authentication servers in the original cloud management network, which is also the domain name of the first authentication server. In other words, the domain name whitelist includes the domain name of the first authentication server and does not include the domain name of the second authentication server.

[0119] Before obtaining the third-party random number, the third-party authentication server can verify the domain name of the first authentication server to determine whether the first authentication server is an authorized authentication server. The third-party authentication server can also verify the domain name of the first authentication server after obtaining the third-party random number, without limitation. Because the terminal is authenticated by the first authentication server, which has been authorized by the third-party authentication server, the availability of the authentication function is guaranteed, and no authorization of other authentication servers is required on the third-party authentication server, thereby improving security.

[0120] The third-party authentication server sends a message carrying the third-party random number to the terminal, which then forwards the message to the first authentication server. Upon receiving the message, the first authentication server verifies the third-party random number on the third-party authentication server to obtain authentication information corresponding to the authentication method indicated by the terminal (e.g., user nickname, user's unique identifier (OpenID) on the third-party authentication server, email address, etc.).

[0121] After receiving the authentication information, the first authentication server indicates that the terminal has been successfully authenticated. It generates an authentication random number and caches the authentication information corresponding to the user access information and the authentication method indicated by the terminal. The following process is similar to the process in scenario 1a above, with the following differences:

[0122] 1) The first authentication server receives an online confirmation response message sent by the access device; based on the online status information carried in the online confirmation response message, it determines that the terminal is online, and generates an online notification message carrying the user management information of the terminal. The user management information may include user access information and authentication information cached in the first authentication server. The first authentication server sends an online notification message to the second authentication server, and the second authentication server receives the online notification message and stores the carried user management information. For example, the second authentication service can save user access information such as the terminal's MAC address, IP address, target management identifier of the access device, target authentication template identifier, user's online time, accumulated Internet access time, etc., record the authentication method indicated by the terminal for this authentication and the authentication information corresponding to the authentication method, and add the terminal to the online list. If the user selects the authentication-free option, the second authentication server can also generate an authentication-free table entry including the authentication-free information, or update the aging time of the authentication-free table entry.

[0123] 2) After sending the online notification message to the second authentication server, the first authentication server can also receive a terminal offline notification message sent by the access device after the access device goes offline, and forward the offline notification message to the second authentication server. Based on the offline notification message, the second authentication server can update the terminal's user management information, update user access information such as accumulated online time, and delete the terminal from the online list. For details, see the description of scenario 1a above.

[0124] In case 1c, the authentication mode corresponding to the target authentication template identifier includes a common authentication mode and a third-party authentication mode. In case 1c, the target authentication template identifier corresponds to the second authentication server authentication and the third-party authentication server authentication. In this embodiment of the present application, the terminal can use the first authentication server to assist in the authentication process.

[0125] After determining that the target authentication template identifier corresponds to authentication with the second authentication server and authentication with the third-party authentication server, the first authentication server may return an authentication login page to the terminal. The authentication login page may include both standard authentication and third-party authentication methods. The user may select a method on the authentication login page, and the selected authentication method will be the authentication method indicated by the terminal.

[0126] When the user selects any third-party authentication method, the terminal indicates that the authentication method is third-party authentication server authentication. In response to the user's selection, the first authentication server may send the terminal the address of the third-party authentication server corresponding to the third-party authentication method selected by the user. The terminal may then perform authentication based on the third-party authentication server address and the authentication information stored in the third-party authentication server. For details, see the relevant description in the above scenario 1b.

[0127] In the embodiment of the present application, the first authentication server stores authentication information, which is user information pre-configured in the first cloud management network and used for authentication, and user information pre-configured in the second cloud management network and used for authentication.

[0128] When the user selects any standard authentication method, the terminal indicates that the authentication method is second-authentication server authentication. The terminal then sends the information entered by the user on the authentication login page to the first authentication server. The first authentication server then authenticates the terminal using the authentication information stored in the first authentication server. In other words, the first authentication server authenticates the user's input information based on the authentication method indicated by the terminal and the stored authentication information. If the first authentication server successfully authenticates the terminal, it generates an authentication random number. The subsequent process after the second authentication server successfully authenticates the terminal in scenario 1a above can be seen.

[0129] Similar to scenario 1b above, after receiving the online confirmation response message from the access device, the first authentication server can generate an online notification message and forward it to the second authentication server. Furthermore, after receiving the offline notification message from the access device, the first authentication server can forward the offline notification message to the second authentication server. For details, see the description of scenario 1b above.

[0130] In case 2, the first authentication server finds the target management identifier, which is a management identifier in the first cloud management network. That is, the target cloud management network for managing the access device is the first cloud management network.

[0131] In case 2, the first authentication server can search for the target authentication template identifier in the stored authentication template identifiers and determine the authentication method and authentication login page configuration information corresponding to the target authentication template identifier. According to the authentication method corresponding to the target authentication template identifier, there are three specific cases.

[0132] In case 2a, the authentication mode corresponding to the target authentication template identifier only includes the common authentication mode. In case 2a, the target authentication template identifier corresponds to the first authentication server authentication, and the terminal indicates that the authentication mode is the first authentication server authentication.

[0133] The first authentication server can return an authentication login page to the terminal, receive the information entered by the user on the authentication login page, and authenticate the terminal using the authentication information on the first authentication server. This process is similar to the process of authenticating the terminal using the authentication information on the second authentication server in scenario 1a above. For details, please refer to the relevant description of scenario 1a above.

[0134] In case 2b, the authentication method corresponding to the target authentication template identifier only includes third-party authentication. In case 2b, the target authentication template identifier corresponds to third-party authentication server authentication, and the terminal indicates that the authentication method is third-party authentication server authentication.

[0135] The first authentication server can return an authentication login page to the terminal. For example, if the authentication login page includes multiple third-party authentication methods, when the user selects any third-party authentication method, the first authentication server can, in response to the user's selection, send the terminal the address of the third-party authentication server corresponding to the selected third-party authentication method. The terminal can then use the authentication information stored on the third-party authentication server based on the address of the third-party authentication server to perform authentication. For details, see the description of scenario 1b above.

[0136] In case 2c, the authentication mode corresponding to the target authentication template identifier includes a common authentication mode and a third-party authentication mode. In case 2c, the target authentication template identifier corresponds to the first authentication server authentication and the third-party authentication server authentication.

[0137] The first authentication server may return an authentication login page to the terminal. The authentication login page may include a standard authentication method and a third-party authentication method. The user may select a method on the authentication login page. The selected authentication method is the authentication method indicated by the terminal.

[0138] When the user selects any third-party authentication method, the terminal indicates that the authentication method is third-party authentication server authentication. In response to the user's selection, the first authentication server may send the terminal the address of the third-party authentication server corresponding to the third-party authentication method selected by the user. The terminal may then perform authentication based on the third-party authentication server address and the authentication information stored in the third-party authentication server. For details, see the relevant description in the above scenario 1b.

[0139] If the user selects any common authentication method, the terminal indicates that the authentication method is authentication with the first authentication server. The first authentication server can receive the information entered by the user on the authentication login page and authenticate the terminal using the authentication information on the first authentication server. This process is similar to the process of authenticating the terminal using the authentication information on the second authentication server in scenario 1a above. For details, please refer to the relevant description of scenario 1a above.

[0140] Based on the above description, see Figure 2 , Figure 2 A second flow chart of a terminal authentication method provided in an embodiment of the present application may include the following steps:

[0141] Step S21: The receiving terminal forwards the first authentication request message according to the address of the first authentication server carried in the first authentication request message. This is the same as the above step S11.

[0142] Step S22: Determine whether a preset condition is satisfied based on the management identifier and authentication template identifier of the access device. If the first preset condition is satisfied, execute step S23; if the second preset condition is satisfied, execute step S24; if the third preset condition is satisfied, execute step S25.

[0143] Step S23: Send the address of the third-party authentication server to the terminal, so that the terminal performs authentication processing using the authentication information in the third-party authentication server.

[0144] Step S24: Authenticate the terminal using the authentication information in the first authentication server.

[0145] Step S25: Send the address of the second authentication server to the terminal, so that the terminal performs authentication processing using the authentication information in the second authentication server.

[0146] In the above step S22, the first authentication server can search for the target management identifier of the access device in the stored management identifiers, and search for the target authentication template identifier of the access device in the stored authentication template identifiers, and determine whether the first preset condition, the second preset condition or the third preset condition is met based on the search result of the target management identifier and the authentication method corresponding to the target authentication template identifier.

[0147] The first preset condition may include: the management identifier of the access device is not the management identifier in the first cloud management network, and the authentication template identifier of the access device corresponds to the third-party authentication server authentication (corresponding to case 1b); or, the management identifier of the access device is not the management identifier in the first cloud management network, the authentication template identifier of the access device corresponds to the third-party authentication server authentication and the second authentication server authentication, and the terminal indicates that the authentication method is the third-party authentication server authentication (corresponding to case 1c); or, the management identifier of the access device is the management identifier in the first cloud management network, and the authentication template identifier of the access device corresponds to the third-party authentication server authentication (corresponding to case 2b); or, the management identifier of the access device is the management identifier in the first cloud management network, the authentication template identifier of the access device corresponds to the third-party authentication server authentication and the first authentication server authentication, and the terminal indicates that the authentication method is the third-party authentication server authentication (corresponding to case 2c). Meeting any one of these items means that the first preset condition is met, and the first authentication server can execute step S23. For details, please refer to the description of the corresponding situation.

[0148] The first preset condition may include: the management identifier of the access device is not the management identifier in the first cloud management network, the authentication template identifier of the access device corresponds to the third-party authentication server authentication and the second authentication server authentication, and the terminal indicates that the authentication method is the second authentication server authentication (corresponding to situation 1c); or, the management identifier of the access device is the management identifier in the first cloud management network, and the authentication template identifier of the access device corresponds to the first authentication server authentication (corresponding to situation 2a); or, the management identifier of the access device is the management identifier in the first cloud management network, and the authentication template identifier of the access device corresponds to the third-party authentication server authentication and the first authentication server authentication, and the terminal indicates that the authentication method is the first authentication server authentication (corresponding to situation 2c). Meeting any one of these items means meeting the second preset condition, and the first authentication server can execute step S24. For details, please refer to the description of the corresponding situation.

[0149] The third preset condition may be: the management identifier of the access device is not a management identifier in the first cloud management network, and the authentication template identifier of the access device corresponds to the authentication of the second authentication server (corresponding to case 1a). After the third preset condition is met, the first authentication server may execute step S25. For details, please refer to the description of the corresponding case.

[0150] In the technical solution provided by the embodiments of this application, the first authentication server authenticates the terminal under different circumstances, resolving the issue of being unable to authenticate some terminals after a cloud-management network split, resulting in user access failures. This improves the reliability of network device management after the split. Furthermore, the first authentication server can also send online and offline notification messages of the terminal to the second authentication server, enabling the second authentication server to update user management information.

[0151] In some embodiments, before the terminal performs authentication, it can be determined whether the terminal is in an authentication-free state to improve the authentication efficiency. Before executing the above step S11, the above terminal authentication method can also include the following steps: receiving an authentication-free request message of the terminal sent by the access device, the authentication-free request message carries the management identifier of the access device; if the management identifier of the access device is not the management identifier in the first cloud management network, forwarding the authentication-free request message to the second authentication server, so that the second authentication server uses the authentication-free information to perform authentication-free processing on the terminal and obtains an authentication-free processing result; if the management identifier of the access device is the management identifier in the first cloud management network, using the authentication-free information in the first authentication server to perform authentication-free processing on the terminal and obtain an authentication-free processing result; sending the authentication-free processing result to the access device, so that when the authentication-free processing result indicates that the authentication-free processing has not passed, the access device sends a first authentication request message to the terminal, the terminal forwards the first authentication request message to the first authentication server, and the first authentication server executes the above step S11.

[0152] In an embodiment of the present application, after a terminal sends any request (such as a request to access a webpage) to an access device, the access device may, based on the configured address of the first authentication server, send a MAC request message carrying the target management identifier of the access device to the first authentication server. The MAC request message may also carry the terminal's MAC address and the target authentication template identifier.

[0153] The first authentication server may obtain the target management identifier carried in the authentication-free message, and search for the target management identifier in the stored management identifiers.

[0154] If the first authentication server fails to find the target management identifier, and the target management identifier is not a management identifier in the first cloud management network, indicating that the target cloud management network for managing the access device is the second cloud management network, the first authentication server may forward the authentication-free request message to the second authentication server. The second authentication server may search for the terminal's authentication-free entry in a pre-stored authentication-free table based on the target management identifier, MAC address, and target authentication template identifier to determine whether the terminal's authentication-free information is stored in the second authentication server.

[0155] If an authentication-free entry is found, it indicates that the terminal's authentication-free information has been stored and the terminal is in an authentication-free state. The second authentication server performs authentication-free processing on the terminal. In this embodiment of the present application, in this case, the terminal has been authenticated at least once and passed. The second authentication server obtains the authentication-free processing result (such as the access token and authentication information) indicating that the authentication-free processing has passed, and sends it to the first authentication server. The first authentication server forwards the authentication-free processing result to the access device.

[0156] After receiving the authentication information, the access device sends an online confirmation response message to the first authentication server, confirming that the terminal has come online. Similarly, the first authentication server can also forward online notification messages / offline notification messages to the second authentication server. For details, see the relevant description in the above scenario 1b.

[0157] If no authentication-free entry is found, the second authentication server rejects the authentication-free process for the terminal. The second authentication server receives a result indicating the authentication-free process failed and forwards it to the access device via the first authentication server. If the authentication-free process fails, the access device may generate a first authentication request message and send it to the terminal. Subsequently, the first authentication server may receive the first authentication request message forwarded by the terminal and continue authenticating the terminal.

[0158] If the first authentication server finds the target management identifier, which is a management identifier in the first cloud management network, indicating that the target cloud management network for managing the access device is the first cloud management network, the first authentication server can search for the terminal's authentication-free entry in the pre-stored authentication-free entry based on the target management identifier, MAC address, and target authentication template identifier to determine whether the terminal's authentication-free information is stored in the first authentication server. The process by which the first authentication server performs authentication-free processing on the terminal is similar to the process by which the second authentication server performs authentication-free processing on the terminal, and will not be repeated here.

[0159] The following combination Figures 3 to 6 The terminal authentication method provided in the embodiment of the present application is described in detail. Taking the first cloud management network as Yunjian Network, the second cloud management network as Jianyou Cloud Network, Yunjian Network management industry equipment, Jianyou Cloud Network management business equipment, and the access device as AC as an example, it involves a terminal, an AC connected to the terminal, a Yunjian Network authentication server, a Jianyou Cloud Network authentication server, and a third-party authentication server. For Yunjian Network, the management group to which the access device belongs is called a place, and the management identifier is a place identifier; for Jianyou Cloud Network, the management group to which the access device belongs is called a project, and the management identifier is a project identifier.

[0160] like Figure 3As shown in the figure, after connecting to the AC, the terminal requests any address (or webpage) from the AC, generating arbitrary network traffic. The AC redirects the request to the corresponding authentication server based on the configured authentication address (i.e., the address of the authentication server). Currently, if the authentication address configured in the AC is the address of the Yunjian Network authentication server, the request is redirected to the Yunjian Network authentication server.

[0161] The terminal receives the authentication request message from the AC and forwards it to the Yunjian Network Authentication Server. The authentication request message can carry information such as the AC's site ID (i.e., target management identifier), authentication template ID (i.e., target authentication template identifier), SSID, terminal's MAC address, and IP address. A World Wide Web (web) server (such as nginx) can forward the authentication request message to the Yunjian Network Authentication Server or Jianyou Cloud Network Authentication Server based on the address.

[0162] After receiving the authentication request, the Yunjian Network Authentication Server determines whether the AC is a commercial or industrial device based on the location ID. Specifically, the server searches for the AC's location ID among the location IDs stored on the Yunjian Network Authentication Server. If the location ID is found, the AC is considered an industrial device; otherwise, it is a commercial device.

[0163] If the AC is a commercial device, the Yunjian Network Authentication Server determines the terminal's authentication method based on the authentication template ID. That is, it searches for the AC's authentication template ID in the authentication template IDs stored by the Yunjian Network Authentication Server, and determines the configuration information corresponding to the authentication template ID, as well as the authentication method included in the configuration information.

[0164] 1) If the authentication method does not include a third-party authentication method, such as a common authentication method such as one-click authentication, account authentication and / or SMS authentication, it will be redirected to the Jianyou Cloud Network Authentication Server, which will perform subsequent authentication processes, such as returning the authentication login page to the terminal, authenticating according to the authentication method selected by the user, etc. For details, please refer to the relevant description in the above situation 1a.

[0165] 2) If the authentication method includes a third-party authentication method, such as official account authentication, DingTalk authentication, mini-program visitor authentication, etc., the Yunjian network authentication server obtains the authentication login page included in the configuration information and directly returns the authentication login page to the terminal, and the user selects the authentication method.

[0166] If the user chooses third-party authentication, a message 1 (carrying a third-party identifier and the address of a third-party authentication server) is generated and sent to the terminal. The terminal forwards the message 1 to the third-party authentication server to redirect the user to the third-party authentication server and obtain a third-party random number, such as Figure 4 shown.

[0167] After successfully verifying the Yunjian Network Authentication Server, the third-party authentication server uses the third-party identifier to obtain a third-party random number and generates Message 2. Message 2 carries the third-party random number, the Yunjian Network Authentication Server address, and other information (such as the terminal's MAC address, IP address, AC SSID, location ID, authentication template ID, etc.). The third-party authentication server sends Message 2 to the terminal and returns the third-party random number.

[0168] The terminal forwards message 2 to the Yunjian Network Authentication Server, forwarding the third-party random number and other information. After receiving message 2, the Yunjian Network Authentication Server sends message 3 to obtain the access token and message 4 to obtain user information (i.e., the authentication information corresponding to the authentication method indicated by the terminal) to the third-party authentication server, and receives the access token and user information returned by the third-party authentication server.

[0169] After obtaining the user information, the Yunjian Network Authentication Server generates an authentication random number and message 5 (carrying the authentication random number and the AC's address) and sends them to the terminal. The terminal forwards message 5 to the AC based on the AC's address, thereby redirecting the user to the AC. The AC forwards message 5 to the Yunjian Network Authentication Server and obtains an access token. The Yunjian Network Authentication Server returns the access token to the AC and sends message 6 carrying the access token to the Yunjian Network Authentication Server to obtain the user information. The Yunjian Network Authentication Server returns the user authentication information to the AC, and the AC returns a login success page to the terminal, redirecting the user to the login success page.

[0170] The Yunjian Network Authentication Server receives the online confirmation response message from the AC and generates an online notification message, which it sends to the Jianyou Cloud Network Authentication Server. The Jianyou Cloud Network Authentication Server saves visitor information (i.e., user access information) such as the terminal's MAC address, IP address, user online time, and accumulated online time. It also records the authentication method and user information and adds the terminal to the online list. If the user selects the authentication-free option, the Jianyou Cloud Network Authentication Server generates an authentication-free entry or updates the aging time of the authentication-free entry.

[0171] After the terminal goes offline, the Yunjian Network Authentication Server receives the offline notification message sent by the AC and sends it to the Jianyou Cloud Network Authentication Server. The Jianyou Cloud Network Authentication Server updates the accumulated online time and deletes the terminal from the online list.

[0172] If the user chooses the normal authentication method, the Yunjian network authentication server can authenticate the terminal, directly generate an authentication random number and send message 5 to the terminal, such as Figure 5 The subsequent process is similar to that of third-party authentication. Figure 4 Part of the description.

[0173] After the AC passes the first authentication, it can also perform authentication-free processing, such as Figure 6 As shown. After receiving the message requesting any address sent by the terminal, the AC can send a message 7 querying for authentication-free to the Yunjian Network Authentication Server to inquire whether the terminal is in an authentication-free state. The Yunjian Network Authentication Server can look up the place ID and make a judgment based on the place ID. If the AC is a commercial device, it calls the interface of the Jianyou Cloud Network Authentication Server and forwards the message 7 querying for authentication-free to the Jianyou Cloud Network Authentication Server for query. The Jianyou Cloud Network Authentication Server inquires whether the terminal is in an authentication-free state and returns the query result (such as the access token and user information) to the Yunjian Network Authentication Server and the AC. Subsequently, after receiving the online confirmation response message (or offline notification message) sent by the AC, the Yunjian Network Authentication Server will also send an online notification message (or offline notification message) to the Jianyou Cloud Network Authentication Server.

[0174] By applying the technical solution provided in the embodiment of the present application, since the domain names of the two authentication servers before and after the migration correspond to the same IP address, the access device will not intercept the authentication request sent to the Jianyou Cloud Network authentication server. In addition, the terminal follows different authentication processes based on the cloud management network that manages the access device and the configured authentication method, thus solving the problem that some terminals cannot be authenticated. In the case of a third-party authentication method configured by a third-party platform, the terminal can also use the authentication server authorized on the third-party platform for authentication.

[0175] In addition, compared with modifying the address configured on the access device, the technical solution provided by the embodiment of the present application avoids the problem of failure to modify the address configured on the access device due to reasons such as the access device version not being supported or the access device being offline, which in turn leads to the inability to authenticate the terminal.

[0176] Corresponding to the above-mentioned terminal authentication method, the embodiment of the present application also provides a terminal authentication device, such as Figure 7 As shown, the first authentication server applied to the first cloud management network includes:

[0177] a receiving module 71 configured to receive a first authentication request message forwarded by the terminal according to the address of the first authentication server carried in the first authentication request message, wherein the first authentication request message is sent by the access device to which the terminal is connected, and the first authentication request message further carries a management identifier and an authentication template identifier of the access device;

[0178] The authentication module 72 is used to send the address of the second authentication server to the terminal if the management identifier of the access device is not the management identifier in the first cloud management network, and the authentication template identifier of the access device corresponds to the second authentication server authentication in the second cloud management network, so that the terminal uses the authentication information in the second authentication server for authentication processing.

[0179] In the technical solution provided by the embodiment of the present application, the first authentication server receives the first authentication request message forwarded by the terminal, and obtains the management identifier and authentication template identifier of the access device. When the management identifier of the access device is not the management identifier in the first cloud management network, indicating that the first cloud management network is not the cloud management network that manages the access device, then the authentication template identifier of the access device corresponds to the second authentication server in the second cloud management network, and the terminal uses the authentication information in the second authentication server to authenticate the terminal. By applying the technical solution provided by the embodiment of the present application, the terminal is authenticated by redirecting to the second authentication server that manages the access device, which solves the problem that some terminals cannot be authenticated after the cloud management network is split, resulting in users being unable to access, and improves the reliability of network device management after the cloud management network is split.

[0180] In some embodiments, the authentication module 72 is further configured to:

[0181] If the first preset condition is met, the address of the third-party authentication server is sent to the terminal, so that the terminal performs authentication processing using the authentication information in the third-party authentication server;

[0182] The first precondition includes:

[0183] The management identifier of the access device is not a management identifier in the first cloud management network, and the authentication template identifier of the access device corresponds to the authentication of the third-party authentication server; or

[0184] The management identifier of the access device is not the management identifier in the first cloud management network, the authentication template identifier of the access device corresponds to third-party authentication server authentication and second authentication server authentication, and the terminal indicates that the authentication mode is third-party authentication server authentication; or,

[0185] The management identifier of the access device is a management identifier in the first cloud management network, and the authentication template identifier of the access device corresponds to the third-party authentication server authentication; or,

[0186] The management identifier of the access device is the management identifier in the first cloud management network, the authentication template identifier of the access device corresponds to third-party authentication server authentication and first authentication server authentication, and the terminal indicates that the authentication mode is third-party authentication server authentication.

[0187] In some embodiments, the authentication module 72 is further configured to:

[0188] If the second preset condition is met, the terminal is authenticated using the authentication information in the first authentication server;

[0189] The second precondition includes:

[0190] The management identifier of the access device is not the management identifier in the first cloud management network, the authentication template identifier of the access device corresponds to third-party authentication server authentication and second authentication server authentication, and the terminal indicates that the authentication mode is second authentication server authentication; or,

[0191] The management identifier of the access device is a management identifier in the first cloud management network, and the authentication template identifier of the access device corresponds to the first authentication server authentication; or,

[0192] The management identifier of the access device is the management identifier in the first cloud management network, the authentication template identifier of the access device corresponds to third-party authentication server authentication and first authentication server authentication, and the terminal indicates that the authentication mode is first authentication server authentication.

[0193] In some embodiments, the apparatus further includes: an authentication-free module, configured to receive an authentication-free request message from the terminal sent by the access device before receiving the first authentication request message forwarded by the terminal, wherein the authentication-free request message carries a management identifier of the access device;

[0194] If the management identifier of the access device is not the management identifier in the first cloud management network, the authentication-free request message is forwarded to the second authentication server, so that the second authentication server performs authentication-free processing on the terminal using the authentication-free information, and obtains an authentication-free processing result; if the management identifier of the access device is the management identifier in the first cloud management network, the authentication-free information in the first authentication server is used to perform authentication-free processing on the terminal, and obtains an authentication-free processing result;

[0195] The result of the authentication-free processing is sent to the access device, so that when the result of the authentication-free processing indicates that the authentication-free processing has failed, the access device sends a first authentication request message to the terminal, the terminal forwards the first authentication request message to the first authentication server, and the first authentication server executes the step of receiving the first authentication request message forwarded by the terminal according to the address of the first authentication server carried in the first authentication request message.

[0196] In some embodiments, the authentication module 72 is further configured to:

[0197] After the terminal passes the authentication process using the authentication information in the third-party authentication server, or passes the authentication process for the terminal using the authentication information in the first authentication server, or passes the authentication-free process for the terminal using the authentication-free information on the second authentication server, an online confirmation response message sent by the access device is received; based on the online confirmation response message, an online notification message is sent to the second authentication server, where the online notification message carries the user management information of the terminal, so that the second authentication server stores the user management information.

[0198] In some embodiments, the authentication module 72 is further configured to:

[0199] After sending the online notification message to the second authentication server, the terminal receives the offline notification message sent by the access device; and forwards the offline notification message to the second authentication server so that the second authentication server updates the user management information of the terminal.

[0200] The embodiment of the present application also provides a server, such as Figure 8 As shown, it includes a processor 81 and a machine-readable storage medium 82, and the machine-readable storage medium 82 stores machine-executable instructions that can be executed by the processor 81. The processor 81 is prompted by the machine-executable instructions to: implement any of the above-mentioned terminal authentication methods applied to the first authentication server in the first cloud management network.

[0201] The machine-readable storage medium may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage. Alternatively, the machine-readable storage medium may be at least one storage device located remote from the processor.

[0202] The processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, and discrete hardware components.

[0203] In another embodiment provided in the present application, a computer-readable storage medium is also provided, which stores a computer program. When the computer program is executed by a processor, it implements any of the above-mentioned terminal authentication methods applied to the first authentication server in the first cloud management network.

[0204] In another embodiment provided in the present application, a computer program product comprising instructions is also provided, which, when executed on a computer, enables the computer to execute any of the terminal authentication methods of the above embodiments applied to the first authentication server in the first cloud management network.

[0205] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When software is used for implementation, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website, computer, server or data center to another website, computer, server or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrations. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive (SSD)).

[0206] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply the existence of any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device comprising the element.

[0207] Each embodiment in this specification is described in a related manner. Similar portions between embodiments can be referenced to each other. Each embodiment focuses on the differences between the other embodiments. In particular, the device, server, storage medium, and program product embodiments are generally similar to the method embodiments, so their descriptions are relatively simple. For relevant portions, reference can be made to the descriptions of the method embodiments.

[0208] The above description is only a preferred embodiment of the present application and is not intended to limit the scope of protection of the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application are included in the scope of protection of the present application.

Claims

1. A terminal authentication method, characterized in that: Applied to a first authentication server in a first cloud management network, the method includes: receiving a first authentication request message forwarded by a terminal according to the address of the first authentication server carried in the first authentication request message, where the first authentication request message is sent by an access device to which the terminal is connected, and the first authentication request message further carries a management identifier and an authentication template identifier of the access device; If the management identifier of the access device is not the management identifier in the first cloud management network, and the authentication template identifier of the access device corresponds to the second authentication server authentication in the second cloud management network, the address of the second authentication server is sent to the terminal so that the terminal uses the authentication information in the second authentication server for authentication processing.

2. The method according to claim 1, characterized in that The method further comprises: If the first preset condition is met, sending the address of the third-party authentication server to the terminal, so that the terminal performs authentication processing using the authentication information in the third-party authentication server; The first preset condition includes: The management identifier of the access device is not a management identifier in the first cloud management network, and the authentication template identifier of the access device corresponds to the third-party authentication server authentication; or, The management identifier of the access device is not a management identifier in the first cloud management network, the authentication template identifier of the access device corresponds to the third-party authentication server authentication and the second authentication server authentication, and the terminal indicates that the authentication mode is the third-party authentication server authentication; or, The management identifier of the access device is a management identifier in the first cloud management network, and the authentication template identifier of the access device corresponds to the third-party authentication server authentication; or, The management identifier of the access device is the management identifier in the first cloud management network, the authentication template identifier of the access device corresponds to the third-party authentication server authentication and the first authentication server authentication, and the terminal indicates that the authentication method is the third-party authentication server authentication.

3. The method according to claim 1, characterized in that The method further comprises: If a second preset condition is met, authenticating the terminal using the authentication information in the first authentication server; The second preset condition includes: The management identifier of the access device is not a management identifier in the first cloud management network, the authentication template identifier of the access device corresponds to third-party authentication server authentication and second authentication server authentication, and the terminal indicates that the authentication mode is the second authentication server authentication; or The management identifier of the access device is a management identifier in the first cloud management network, and the authentication template identifier of the access device corresponds to the first authentication server authentication; or The management identifier of the access device is the management identifier in the first cloud management network, and the authentication template identifier of the access device corresponds to third-party authentication server authentication and first authentication server authentication, and the terminal indicates that the authentication method is the first authentication server authentication.

4. The method according to claim 1, wherein Before receiving the first authentication request message forwarded by the terminal, the method further includes: receiving an authentication-free request message of the terminal sent by the access device, where the authentication-free request message carries a management identifier of the access device; If the management identifier of the access device is not a management identifier in the first cloud management network, forwarding the authentication-free request message to the second authentication server, so that the second authentication server performs authentication-free processing on the terminal using the authentication-free information, and obtains an authentication-free processing result; if the management identifier of the access device is a management identifier in the first cloud management network, performing authentication-free processing on the terminal using the authentication-free information in the first authentication server, and obtains an authentication-free processing result; The authentication-free processing result is sent to the access device, so that when the authentication-free processing result indicates that the authentication-free processing has failed, the access device sends a first authentication request message to the terminal, the terminal forwards the first authentication request message to the first authentication server, and the first authentication server executes the step of receiving the first authentication request message forwarded by the terminal according to the address of the first authentication server carried in the first authentication request message.

5. The method according to any one of claims 2 to 4, characterized in that: After the terminal passes authentication using the authentication information in the third-party authentication server, or passes authentication using the authentication information in the first authentication server, or passes authentication-free processing on the terminal using the authentication-free information on the second authentication server, the method further includes: Receive an online confirmation response message sent by the access device; and according to the online confirmation response message, send an online notification message to the second authentication server, wherein the online notification message carries user management information of the terminal, so that the second authentication server stores the user management information.

6. The method according to claim 5, characterized in that After sending the online notification message to the second authentication server, the method further includes: Receive a offline notification message of the terminal sent by the access device; and forward the offline notification message to the second authentication server so that the second authentication server updates user management information of the terminal.

7. A terminal authentication device, characterized in that: Applied to a first authentication server in a first cloud management network, the device includes: a receiving module, configured to receive a first authentication request message forwarded by a terminal according to the address of the first authentication server carried in the first authentication request message, wherein the first authentication request message is sent by an access device to which the terminal is connected, and the first authentication request message further carries a management identifier and an authentication template identifier of the access device; An authentication module is used to send the address of the second authentication server to the terminal if the management identifier of the access device is not the management identifier in the first cloud management network, and the authentication template identifier of the access device corresponds to the second authentication server authentication in the second cloud management network, so that the terminal uses the authentication information in the second authentication server for authentication processing.

8. The device according to claim 7, characterized in that The authentication module is further configured to: If the first preset condition is met, sending the address of the third-party authentication server to the terminal, so that the terminal performs authentication processing using the authentication information in the third-party authentication server; The first preset condition includes: The management identifier of the access device is not a management identifier in the first cloud management network, and the authentication template identifier of the access device corresponds to the third-party authentication server authentication; or, The management identifier of the access device is not a management identifier in the first cloud management network, the authentication template identifier of the access device corresponds to the third-party authentication server authentication and the second authentication server authentication, and the terminal indicates that the authentication mode is the third-party authentication server authentication; or, The management identifier of the access device is a management identifier in the first cloud management network, and the authentication template identifier of the access device corresponds to the third-party authentication server authentication; or, The management identifier of the access device is the management identifier in the first cloud management network, the authentication template identifier of the access device corresponds to the third-party authentication server authentication and the first authentication server authentication, and the terminal indicates that the authentication method is the third-party authentication server authentication.

9. The device according to claim 7, characterized in that The authentication module is further configured to: If a second preset condition is met, authenticating the terminal using the authentication information in the first authentication server; The second preset condition includes: The management identifier of the access device is not a management identifier in the first cloud management network, the authentication template identifier of the access device corresponds to third-party authentication server authentication and second authentication server authentication, and the terminal indicates that the authentication mode is the second authentication server authentication; or The management identifier of the access device is a management identifier in the first cloud management network, and the authentication template identifier of the access device corresponds to the first authentication server authentication; or, The management identifier of the access device is the management identifier in the first cloud management network, the authentication template identifier of the access device corresponds to third-party authentication server authentication and first authentication server authentication, and the terminal indicates that the authentication method is the first authentication server authentication.

10. The device according to claim 7, characterized in that The apparatus further includes: an authentication-free module, configured to receive an authentication-free request message of the terminal sent by the access device before receiving the first authentication request message forwarded by the terminal, wherein the authentication-free request message carries a management identifier of the access device; If the management identifier of the access device is not a management identifier in the first cloud management network, forwarding the authentication-free request message to the second authentication server, so that the second authentication server performs authentication-free processing on the terminal using the authentication-free information, and obtains an authentication-free processing result; if the management identifier of the access device is a management identifier in the first cloud management network, performing authentication-free processing on the terminal using the authentication-free information in the first authentication server, and obtains an authentication-free processing result; The authentication-free processing result is sent to the access device, so that when the authentication-free processing result indicates that the authentication-free processing has failed, the access device sends a first authentication request message to the terminal, the terminal forwards the first authentication request message to the first authentication server, and the first authentication server executes the step of receiving the first authentication request message forwarded by the terminal according to the address of the first authentication server carried in the first authentication request message.

11. The device according to any one of claims 8 to 10, characterized in that: The authentication module is further configured to: After the terminal passes authentication using the authentication information in the third-party authentication server, or passes authentication using the authentication information in the first authentication server, or passes authentication-free processing for the terminal using the authentication-free information on the second authentication server, an online confirmation response message is received from the access device; and based on the online confirmation response message, an online notification message is sent to the second authentication server, where the online notification message carries user management information of the terminal, so that the second authentication server stores the user management information.

12. The device according to claim 11, characterized in that The authentication module is further configured to: After sending the online notification message to the second authentication server, receiving the offline notification message of the terminal sent by the access device; forwarding the offline notification message to the second authentication server, so that the second authentication server updates the user management information of the terminal.

13. A server, characterized in that: The method comprises a processor and a machine-readable storage medium, wherein the machine-readable storage medium stores machine-executable instructions that can be executed by the processor, and the processor is prompted by the machine-executable instructions to implement the method according to any one of claims 1 to 6.

14. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.

Citation Information

Patent Citations

  • Internet authentication method and device

    CN106911681A

  • Authentication method and apparatus

    CN107995212A

  • Terminal authentication method, related equipment and authentication system

    CN110505188A

  • Equipment authentication method, device and system, terminal equipment and storage medium

    CN112417425A

  • Terminal authentication method, related equipment and authentication system

    CN114124452A