Message transmission method and device and related equipment

By encapsulating the IPv4 message header on the outer layer of the PPPOE message and expanding the protocol field, the problem that the PPPOE protocol can only be carried on the second layer network is solved, and the transmission of PPPOE messages in the third layer network is realized, reducing the operation and maintenance complexity and broadcast storm risks, and improving service management and control capabilities.

CN120547249APending Publication Date: 2025-08-26CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510977002.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-15
Publication Date
2025-08-26

AI Technical Summary

Technical Problem

The PPPOE protocol needs to be based on layer two network bearer, resulting in inefficient investment efficiency and complex operation and maintenance, and is unable to effectively cross the layer three network for authentication and session-level control.

Method used

By encapsulating network layer data packets, especially IPv4 message headers, and expanding the definition protocol field, the transmission of PPPOE messages in the third-layer network is realized, ensuring that the access server can identify and process the inner layer PPPOE messages.

Benefits of technology

It realizes the transmission of PPPOE packets in the third-layer network, avoids investment waste and operation and maintenance complexity of the second-layer network, reduces the risk of broadcast storms, and improves the operator's business management and control capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120547249A_ABST
    Figure CN120547249A_ABST
Patent Text Reader

Abstract

The invention provides a message transmission method and device and related equipment, and relates to the technical field of communication, and the method comprises the steps: transmitting an authentication request message after first packaging processing to receiving end equipment, so as to enable the receiving end equipment to execute a user authentication process based on the authentication request message after first packaging processing, the authentication request message comprises a point-to-point protocol message on the Ethernet and a network layer data packet, the network layer data packet comprises a protocol field, and the protocol field is filled with predefined data; after the user authentication succeeds, determining predefined data filled with a protocol field in a transmission request message based on the transmission request message which is transmitted by the receiving end equipment and is subjected to second encapsulation processing; and according to predefined data filled in the protocol field, identifying and de-encapsulating the point-to-point protocol message on the Ethernet in the transmission request message, and continuing to execute the point-to-point protocol flow on the Ethernet. According to the invention, point-to-point authentication and session-level management and control on the Ethernet can be carried out across a three-layer network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of communication technology, and in particular to a message transmission method, apparatus, and related equipment. Background Art

[0002] The Point-to-Point Protocol Over Ethernet (PPPOE) protocol is a mature technology for implementing authentication and authorization between dial-up terminals and access servers. Operators usually use PPPOE to provide broadband Internet service authentication. As a mature and secure technology, it has been widely used in operators' Internet services. Combined with the Remote Authentication Dial In User Service (Radius), it implements session-level authentication, authorization, billing, and management. However, PPPOE can only be implemented based on the link layer. A Layer 2 network is required between the dial-up terminal and the access server to carry the PPPOE authentication flow and data flow. As the performance of access servers continues to improve and their deployment locations move upward, both Layer 2 direct connection and large Layer 2 methods have disadvantages.

[0003] To meet the PPPoE link layer bearer requirements, operators may place access servers close to user locations, with users connecting directly via Ethernet or optical line terminals (OLTs) at Layer 2. However, this solution is inefficient. Alternatively, operators may place access servers at core nodes, requiring the creation of a large Layer 2 network within the Internet Protocol (IP) network. This poses risks such as Layer 2 flooding and insufficient operation and maintenance tools.

[0004] Specifically, the PPPOE bearer solution and encapsulation technology in the related art are as follows:

[0005] like Figure 1 As shown, PPPoE needs to be carried over a Layer 2 network to ensure that Layer 2 information such as Media Access Control (MAC) and Virtual Local Area Network (VLAN) is sent to the access server without being modified or lost. The access server performs authentication, establishes traffic, and ensures the normal flow of round-trip traffic based on this information.

[0006] Figure 2These are the main fields in the PPPoE packet encapsulation format (from the dial-up terminal to the access server). 0x8864 is preceded by the Ethernet header, the most important of which are the dMAC and sMAC fields, representing the MAC addresses of both ends. There may also be a VLAN field (not shown in the diagram). 0x8864 is a specific value, indicating that the following is the PPPoE packet, followed by the PPPoE header and PPP, and finally the packet payload, such as IP plus Internet Control Message Protocol (ICMP), IP plus User Datagram Protocol (UDP), etc. Because the Layer 2 Ethernet header is exposed at the outer layer, it cannot pass through the Layer 3 network. Otherwise, the dMAC and sMAC will change at each hop, making it impossible for the access server to effectively authenticate and establish flow tables.

[0007] It should be noted that the information disclosed in the above background technology section is only used to enhance the understanding of the background of the present disclosure, and therefore may include information that does not constitute prior art known to ordinary technicians in the field. Summary of the Invention

[0008] The present disclosure provides a message transmission method, apparatus and related equipment, which at least to a certain extent overcome the problem in the related art that PPPOE must be carried on a layer 2 network.

[0009] Other features and advantages of the present disclosure will become apparent from the following detailed description, or may be learned in part by practice of the present disclosure.

[0010] According to one aspect of the present disclosure, a message transmission method is provided, which is applied to a sending device, comprising: transmitting an authentication request message after a first encapsulation process to a receiving device, so that the receiving device performs a user authentication process based on the authentication request message after the first encapsulation process, wherein the authentication request message includes a point-to-point protocol message on Ethernet and a network layer data packet, and the network layer data packet includes a protocol field, and the protocol field is filled with predefined data; after user authentication is successful, based on a transmission request message after a second encapsulation process transmitted by the receiving device, determining the predefined data filled with the protocol field in the transmission request message, wherein the transmission request message includes a point-to-point protocol message on Ethernet and a network layer data packet; according to the predefined data filled in the protocol field, identifying and decapsulating the point-to-point protocol message on Ethernet in the transmission request message, and continuing to execute the point-to-point protocol process on Ethernet.

[0011] In some exemplary embodiments of the present disclosure, based on the aforementioned scheme, before transmitting the authentication request message after the first encapsulation processing to the receiving device, the method also includes: performing a first encapsulation processing on the outer layer of the point-to-point protocol message on the Ethernet, and filling predefined data in the protocol field in the network layer data packet, wherein the payload of the network layer data packet contains a complete Layer 2 Ethernet frame.

[0012] In some exemplary embodiments of the present disclosure, based on the aforementioned solution, a first encapsulation process is performed on the outer layer of the point-to-point protocol message on the Ethernet, including: encapsulating a layer of header information of the network layer data packet on the outer layer of the point-to-point protocol message on the Ethernet.

[0013] In some exemplary embodiments of the present disclosure, based on the aforementioned scheme, based on the transmission request message after the second encapsulation processing transmitted by the receiving device, the predefined data filled in the protocol field in the transmission request message is determined, including: receiving the transmission request message after the second encapsulation processing transmitted by the receiving device; parsing the transmission request message after the second encapsulation processing, and determining the predefined data filled in the protocol field in the transmission request message.

[0014] In some exemplary embodiments of the present disclosure, based on the aforementioned solution, the network layer data packet is an Internet Protocol version 4 IPv4 data packet.

[0015] According to another aspect of the present disclosure, a message transmission method is also provided, which is applied to a receiving device, including: determining the predefined data to be filled in the protocol field in the authentication request message based on the first encapsulation processing of the authentication request message transmitted by the sending device, so as to execute the user authentication process, wherein the authentication request message includes a point-to-point protocol message on the Ethernet and a network layer data packet, the network layer data packet includes a protocol field, and the protocol field is filled with predefined data; after the user authentication is successful, transmitting the point-to-point protocol message on the Ethernet to the network side device; performing a second encapsulation processing on the point-to-point protocol message on the Ethernet returned by the network side device, and transmitting the point-to-point protocol message on the Ethernet after the second encapsulation processing to the sending device, so that the sending device continues to execute the point-to-point protocol process on the Ethernet.

[0016] According to another aspect of the present disclosure, a message transmission device is also provided, which is applied to a sending end device, including: an authentication request message transmission module, which is used to transmit an authentication request message after a first encapsulation process to a receiving end device, so that the receiving end device performs a user authentication process based on the authentication request message after the first encapsulation process, wherein the authentication request message includes a point-to-point protocol message on Ethernet and a network layer data packet, and the network layer data packet includes a protocol field, and the protocol field is filled with predefined data; a transmission request message parsing module, which is used to determine the predefined data filled with the protocol field in the transmission request message based on the transmission request message after the second encapsulation process transmitted by the receiving end device after the user authentication is successful, wherein the transmission request message includes a point-to-point protocol message on Ethernet and a network layer data packet; a transmission request message processing module, which is used to identify and decapsulate the point-to-point protocol message on Ethernet in the transmission request message according to the predefined data filled in the protocol field, and continue to execute the point-to-point protocol process on Ethernet.

[0017] According to another aspect of the present disclosure, a message transmission device is also provided, which is applied to a receiving device and includes: an authentication request message parsing module, which is used to determine the predefined data filled in the protocol field in the authentication request message based on the authentication request message after the first encapsulation processing transmitted by the sending device, so as to execute the user authentication process, wherein the authentication request message includes a point-to-point protocol message on the Ethernet and a network layer data packet, the network layer data packet includes a protocol field, and the protocol field is filled with predefined data; a message data transmission module, which is used to transmit the point-to-point protocol message on the Ethernet to the network side device after the user authentication is successful; a message data processing module, which is used to perform a second encapsulation processing on the point-to-point protocol message on the Ethernet returned by the network side device, and transmit the point-to-point protocol message on the Ethernet after the second encapsulation processing to the sending device, so that the sending device continues to execute the point-to-point protocol process on the Ethernet.

[0018] According to another aspect of the present disclosure, an electronic device is provided, comprising: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute any one of the above-mentioned message transmission methods by executing the executable instructions.

[0019] According to another aspect of the present disclosure, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, any one of the above-mentioned message transmission methods is implemented.

[0020] According to another aspect of the present disclosure, a computer program product is provided, including: a computer program or instructions, wherein when the computer program or instructions are executed by a processor, any one of the above-mentioned message transmission methods is implemented.

[0021] A message transmission method, apparatus, and related equipment provided in the embodiments of the present disclosure encapsulate Ethernet point-to-point protocol messages in network layer packets by extending the definition of protocol fields in network layer packets. This is a new method proposed based on new requirements for network and application deployment. Based on a simple extension of the network layer packet, Ethernet point-to-point protocol authentication and session-level control can be performed across three layers of the network. This solves the defect that traditional Ethernet point-to-point protocols must be carried on the second layer of the network, and also avoids the high overhead and complex operation and maintenance of the Layer 2 Tunneling Protocol (L2TP) and IPv6 tunneling methods.

[0022] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] The accompanying drawings are incorporated into and constitute a part of the specification, illustrate embodiments consistent with the present disclosure, and together with the specification, are used to explain the principles of the present disclosure. Obviously, the drawings described below are only some embodiments of the present disclosure, and those skilled in the art can derive other drawings based on these drawings without inventive effort.

[0024] Figure 1 A schematic diagram of PPPOE protocol bearer in related technology is shown;

[0025] Figure 2 Shown is a schematic diagram of the PPPOE message format in the related art;

[0026] Figure 3 A schematic diagram showing an exemplary application system architecture of a message transmission method according to an embodiment of the present disclosure;

[0027] Figure 4 A schematic diagram of a message transmission method applied to a sending end device in an embodiment of the present disclosure is shown;

[0028] Figure 5 A schematic diagram showing the location of an IPv4 header and protocol fields according to an embodiment of the present disclosure is shown;

[0029] Figure 6 A schematic diagram showing a message encapsulation format between a sending end device and a receiving end device in an embodiment of the present disclosure is shown;

[0030] Figure 7A schematic diagram of a message transmission method applied to a receiving device in an embodiment of the present disclosure is shown;

[0031] Figure 8 A schematic diagram showing a PPPOE protocol carried over an IPv4 network in an embodiment of the present disclosure is shown;

[0032] Figure 9 A schematic diagram of a message transmission device applied to a sending end device in an embodiment of the present disclosure is shown;

[0033] Figure 10 A schematic diagram of a message transmission device applied to a receiving end device in an embodiment of the present disclosure is shown;

[0034] Figure 11 A schematic diagram of an electronic device using a message transmission method according to an embodiment of the present disclosure is shown. DETAILED DESCRIPTION

[0035] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be embodied in many forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this disclosure will be thorough and complete and will fully convey the concepts of the example embodiments to those skilled in the art. The described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.

[0036] In addition, the described features, structures or characteristics may be combined in any suitable manner in one or more embodiments. In the following description, many specific details are provided to provide a full understanding of the embodiments of the present disclosure. However, those skilled in the art will appreciate that the technical solutions of the present disclosure can be practiced without one or more of the specific details, or other methods, components, devices, steps, etc. can be adopted. In other cases, well-known methods, devices, implementations or operations are not shown or described in detail to avoid blurring various aspects of the present disclosure.

[0037] The flowcharts shown in the accompanying drawings are for illustrative purposes only and do not necessarily include all contents and operations / steps, nor must they be executed in the order described. For example, some operations / steps may be decomposed, while others may be combined or partially combined. Therefore, the actual execution order may vary depending on the actual situation.

[0038] Figure 3 FIG. 1 shows an exemplary application system architecture diagram to which the message transmission method in the embodiment of the present disclosure can be applied. Figure 3 As shown, the system architecture may include a terminal device 301 , a network 302 and a server 303 .

[0039] The network 302 is a medium for providing a communication link between the terminal device 301 and the server 303 , and can be a wired network or a wireless network.

[0040] Optionally, the above-mentioned wireless network or wired network uses standard communication technologies and / or protocols. The network is typically the Internet, but can also be any network, including but not limited to a local area network (LAN), a metropolitan area network (MAN), a wide area network (WAN), a mobile, wired or wireless network, a private network or any combination of a virtual private network). In some embodiments, technologies and / or formats including Hypertext Markup Language (HTML), Extensible Markup Language (XML), etc. are used to represent data exchanged over the network. In addition, conventional encryption technologies such as Secure Socket Layer (SSL), Transport Layer Security (TLS), Virtual Private Network (VPN), Internet Protocol Security (IPsec), etc. can be used to encrypt all or some links. In other embodiments, customized and / or dedicated data communication technologies can also be used to replace or supplement the above-mentioned data communication technologies.

[0041] The terminal device 301 can be various electronic devices, including but not limited to smart phones, tablet computers, laptop computers, desktop computers, wearable devices, augmented reality devices, virtual reality devices, etc.

[0042] Optionally, the client of the application installed in different terminal devices 301 is the same, or the client of the same type of application based on different operating systems. Based on the different terminal platforms, the specific form of the client of the application can also be different, for example, the application client can be a mobile phone client, a PC client, etc.

[0043] The server 303 may be a server that provides various services, such as a background management server that provides support for the device operated by the user using the terminal device 301. The background management server may analyze and process the received request and other data, and feed back the processing results to the terminal device.

[0044] Optionally, the server can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. The terminal can be a smart phone, tablet computer, laptop computer, desktop computer, smart speaker, smart watch, etc., but is not limited to these. The terminal and the server can be directly or indirectly connected via wired or wireless communication, which is not limited in this application.

[0045] Those skilled in the art will know that Figure 3 The number of terminal devices, networks, and servers in the embodiment is merely illustrative, and any number of terminal devices, networks, and servers may be provided based on actual needs. This embodiment of the present disclosure does not limit this.

[0046] Under the above system architecture, an embodiment of the present disclosure provides a message transmission method, which can be executed by any electronic device with computing and processing capabilities.

[0047] In some embodiments, the message transmission method provided in the embodiments of the present disclosure can be executed by the terminal device of the above-mentioned system architecture; in other embodiments, the message transmission method provided in the embodiments of the present disclosure can be executed by the server in the above-mentioned system architecture; in other embodiments, the message transmission method provided in the embodiments of the present disclosure can be implemented by the terminal device and the server in the above-mentioned system architecture through interaction.

[0048] In order to explain the embodiments of the present disclosure more clearly, some professional terms are now explained:

[0049] Point-to-Point Protocol Over Ethernet (PPPOE): It is a network tunneling protocol that encapsulates the Point-to-Point Protocol (PPP) in an Ethernet framework.

[0050] Media Access Control Address (MAC): Media Access Control Address, also known as physical address, is an address used to identify the location of a network device.

[0051] Virtual Local Area Network (VLAN): is a technology that logically divides a physical local area network into multiple broadcast domains.

[0052] First, the embodiment of the present disclosure provides a method for extending and defining a new Internet Protocol version 4 (IPv4) message header predefined data (also known as a protocol number), and encapsulating a PPPoE message as an inner data packet in an IPv4 message. In the middle, only the IPv4 network route is required. After the access terminal and the access gateway identify the protocol number defined in the embodiment of the present disclosure, they encapsulate / decapsulate the round-trip messages and extract the inner PPPoE message for normal authentication and authorization. That is, there is no need for operators to build a large Layer 2 network. Considering that all devices along the way from the user side to the network side support the IPv4 protocol, the embodiment of the present disclosure is based on the more widely used IPv4 implementation.

[0053] Figure 4 A schematic diagram of a message transmission method according to an embodiment of the present disclosure is shown, which is applied to a sending end device. The method includes the following steps:

[0054] S402, transmitting the authentication request message after the first encapsulation processing to the receiving device, so that the receiving device performs the user authentication process based on the authentication request message after the first encapsulation processing, wherein the authentication request message includes a point-to-point protocol message and a network layer data packet on the Ethernet, the network layer data packet includes a protocol field, and the protocol field is filled with predefined data.

[0055] It should be noted that the authentication request message in the embodiment of the present disclosure is a data packet sent by a user device (such as a home router or a dial-up terminal) for requesting identity authentication. During the broadband access process, the user needs to prove his or her identity to the operator in some way (for example, a user name and password). The authentication request message in the embodiment of the present disclosure is the carrier of this information; PPPoE in the embodiment of the present disclosure is a network protocol that allows point-to-point connections to be established on Ethernet. A PPPoE message is a structured data unit in the PPPoE protocol used to exchange control information or data, and usually includes a PPPoE header + a PPP data frame; the network layer data packet in the embodiment of the present disclosure refers to a data unit used in the network layer, the most common of which is an IPv4 or IPv6 data packet, which is responsible for transmitting data from a source host to a target host and relies on an IP address for addressing. Taking an IPv4 data packet as an example, each data packet going online will have an IPv4 header, which contains fields such as the source IP address, the destination IP address, and the protocol number. In addition, the protocol field in the embodiment of the present disclosure refers to the data unit in the IPv 4 In the packet header, there is a field called "Protocol", which is used to identify the upper layer protocol type carried by the IP data packet. Predefined data refers to a fixed value or a group of values ​​agreed in advance, and here specifically refers to the value of the Protocol field in the IPv4 packet header (for example, the predefined data can be 6, 17, 240, etc.). For example, the Protocol field of an IPv4 packet is "6", which means that its payload is TCP data; the Protocol field of an IPv4 packet is "17", which means that its payload is UDP data; the Protocol field of an IPv4 packet is "240", which means that the packet is a special packet encapsulated with PPPoE; the first encapsulation process in the embodiment of the present disclosure refers to adding another layer of encapsulation outside the PPPoE packet, usually adding an IPv4 packet header and a new Ethernet header, so that the packet can be transmitted through the three-layer network (IP network); the receiving device in the embodiment of the present disclosure is the party receiving the data, for example, a broadband access server (Broadband Remote Access Server (BRAS) is used to receive and parse the encapsulated PPPOE message, extract the original authentication information, and complete the user authentication process; the execution of the user authentication process in the embodiment of the present disclosure is to verify the received authentication request and determine whether the user has the right to access the network.

[0056] S404, after the user authentication is successful, based on the transmission request message after the second encapsulation processing transmitted by the receiving device, determine the predefined data filled in the protocol field in the transmission request message, wherein the transmission request message includes a point-to-point protocol message and a network layer data packet on the Ethernet.

[0057] It should be noted that the second encapsulation processing in the embodiment of the present disclosure is relative to the "first encapsulation", which refers to the re-encapsulation processing of the received data so that it can be correctly transmitted in a specific network environment. It is equivalent to the first encapsulation usually being the sending device encapsulating the PPPOE message into an IPv4 data packet for transmission across the three-layer network; and the second encapsulation is the encapsulation operation on the reverse path; the transmission request message in the embodiment of the present disclosure represents a request or response message for data transmission, which may refer to a data message sent by the receiving device to the sending device.

[0058] S406 , identifying and decapsulating the Point-to-Point Protocol over Ethernet message in the transmission request message according to the predefined data filled in the protocol field, and continuing to execute the Point-to-Point Protocol over Ethernet process.

[0059] It should be noted that the decapsulation in the embodiment of the present disclosure refers to the process of peeling off the outer encapsulated data structure layer by layer to restore the original data. Here, it can be understood that the receiving device needs to peel off the IPv4 message header and Ethernet header in sequence, and finally extract the internal PPPOE message; in addition, the embodiment of the present disclosure executes the point-to-point protocol process on Ethernet, which can be to extract the PPPOE message, continue to execute the control protocol of the PPP layer, finally complete the network parameter negotiation, and start normal Internet access.

[0060] The message transmission method provided in the embodiments of the present disclosure first transmits a first encapsulated authentication request message to a receiving device, so that the receiving device executes a user authentication process based on the first encapsulated authentication request message; then, after the user authentication is successful, based on the second encapsulated transmission request message transmitted by the receiving device, determines the predefined data filled in the protocol field of the transmission request message; finally, based on the predefined data filled in the protocol field, identifies and decapsulates the Ethernet point-to-point protocol message in the transmission request message, and continues to execute the Ethernet point-to-point protocol process. Compared with the related art, since the second-layer Ethernet header is exposed in the outer layer, it cannot pass through the third-layer network in the middle. Otherwise, the dMAC and sMAC will be changed at each hop, resulting in the access server being unable to effectively authenticate and establish a flow table. The embodiment of the present disclosure expands the definition of the protocol field in the network layer data packet to encapsulate the point-to-point protocol message on the Ethernet in the network layer data packet. This is a new method proposed based on the new requirements of network and application deployment. Based on the simple extension of the network layer data packet, the point-to-point protocol authentication and session-level control on the Ethernet can be performed across the three-layer network. This solves the defect that the point-to-point protocol on the traditional Ethernet must be carried on the second-layer network, and also avoids the problems of high overhead and complex operation and maintenance of L2TP and IPv6 tunnel methods.

[0061] In some embodiments, before transmitting the authentication request message after the first encapsulation processing to the receiving device, the message transmission method in the embodiment of the present disclosure also includes: performing a first encapsulation processing on the outer layer of the point-to-point protocol message on the Ethernet, and filling predefined data in the protocol field in the network layer data packet, wherein the payload of the network layer data packet contains a complete layer 2 Ethernet frame. Specifically, in the related art, PPPOE messages can only run in the layer 2 Ethernet and cannot be directly forwarded through the layer 3 router. However, the embodiment of the present disclosure adds network layer data packet encapsulation in the outer layer, so that the PPPOE message can be transmitted in the layer 3 network like an ordinary IP data packet. There is no need to build a complex layer 2 network, and the encapsulated traffic can be managed and controlled through conventional IP tools (such as ping, traceroute, ACL policy). In addition, the complete layer 2 Ethernet frame and PPPOE message content are retained in the encapsulated network layer data packet. The receiving device can directly restore the original structure after decapsulation, avoiding any modification to the original PPPOE protocol, and has strong compatibility.

[0062] In some embodiments, the embodiment of the present disclosure takes IPv4 data packets as an example in the network layer data packet, and defines a new protocol number (Protocol) in the IPv4 data packet extension, that is, fills predefined data in the protocol field, which is used to encapsulate the PPPOE message in the inner layer of the IPv4 message, ensuring that the second-layer information required by the PPPOE message client device and the receiving device will not change. After the message is encapsulated and decapsulated based on the new protocol number between the sending device and the receiving device, the inner layer PPPOE message is extracted and processed according to the normal process. It should be noted that the protocol field in the embodiment of the present disclosure represents the upper layer message type. The predefined data in the embodiment of the present disclosure, such as 240, represents that the upper layer (inner layer) is an Ethernet-encapsulated PPPOE message; of course, the Ethernet message protocol number (143, currently not defined and applied in the IPv4 message header) can also be used for definition. The embodiment of the present disclosure does not limit the above-mentioned predefined data.

[0063] In some embodiments, the disclosed embodiments perform a first encapsulation process on the outer layer of a point-to-point protocol message on the Ethernet, including: encapsulating a layer of network layer data packet header information on the outer layer of the point-to-point protocol message on the Ethernet. Specifically, taking IPv4 as an example, the location of the IPv4 header and protocol field is as follows: Figure 5As shown, by adding IPv4 header information in the outer layer, these messages can be encapsulated into data packets that can be transmitted on a three-layer network, so that PPPoE messages can pass through multiple routers and autonomous systems, rather than being limited to devices within the same LAN. Moreover, IPv4 protocol numbers generally carry upper-layer applications such as UDP, TCP, and ICMP, and applications such as L2TP can only be encapsulated in the UDP inner layer, which increases overhead and reduces forwarding performance. Moreover, during the encapsulation process, the original PPPoE message (including its Ethernet header and PPPoE header) is completely retained in the payload part of the new network layer data packet. After receiving the encapsulated data packet, the receiving device (such as an access server) can easily decapsulate and restore the original PPPoE message and continue to execute subsequent processing procedures (such as user authentication, allocation of IP addresses, etc.).

[0064] In more detail, when the sending end device in the embodiment of the present disclosure (for example, the sending end device can be a dial-up terminal) initiates PPPOE authentication, it encapsulates an IPv4 message header in the outer layer of the PPPOE message, wherein the protocol field is filled with "240", and the encapsulated message is as follows: Figure 6 As shown in the figure, the Layer 2 Ethernet header and PPPoE message are completely encapsulated in the IPv4 payload. The outer layer encapsulates a new Layer 2 Ethernet header and IPv4 message header, where dIP is the access server IP and sIP is the dial-up terminal IP. This ensures that the authentication information is sent from the dial-up terminal to the access server. The source and destination MAC addresses of the outer Ethernet header change with the Layer 3 devices along the way, but this does not affect the inner MAC and VLAN.

[0065] In some embodiments, the embodiments of the present disclosure determine the predefined data filled in the protocol field in the transmission request message based on the transmission request message after the second encapsulation processing transmitted by the receiving device, including: receiving the transmission request message after the second encapsulation processing transmitted by the receiving device; parsing the transmission request message after the second encapsulation processing, and determining the predefined data filled in the protocol field in the transmission request message. Specifically, by checking the predefined data filled in the protocol field, it is possible to identify which data packets have been specially encapsulated (such as PPPOE messages), so that the receiving end can correctly distinguish between ordinary IP traffic and traffic that requires special processing, thereby ensuring that only specific types of data packets are further decapsulated and processed. If the predefined data filled in the protocol field is 240 (this is a custom value), it means that the data packet contains a PPPOE message, and the receiving end can perform the corresponding decapsulation operation based on this identifier; and, by adding additional encapsulation in the outer layer (ie, "second encapsulation processing"), data packets that were originally only transmitted on the second-layer network (such as PPPOE messages) can be transmitted in the third-layer IP network, allowing data to pass from one LAN to another, or even across the Internet, without relying on complex second-layer network configuration.

[0066] In some embodiments, the network layer data packets in the embodiments of the present disclosure are Internet Protocol version 4 (IPv4) data packets. Specifically, IPv4 assigns a 32-bit IP address to each device connected to the Internet, allowing these devices to be uniquely identified globally, ensuring that data packets can be accurately sent from the source to the destination, no matter where they are located in the world. More specifically, the fields in the IPv4 packet header (such as the source IP address, destination IP address, TTL, etc.) provide sufficient information to enable routers to determine how to forward data packets based on routing tables, thereby achieving global data transmission, even if the source and destination span multiple different networks or autonomous systems.

[0067] Figure 7 A schematic diagram of a message transmission method according to an embodiment of the present disclosure is shown, which is applied to a receiving device. The method includes the following steps:

[0068] S702: Determine, based on the first encapsulated authentication request message transmitted by the sending device, predefined data to be filled in a protocol field in the authentication request message, to perform a user authentication process, wherein the authentication request message includes a point-to-point protocol message and a network layer data packet on an Ethernet network, the network layer data packet includes a protocol field, and the protocol field is filled with the predefined data;

[0069] S704, after the user authentication is successful, the point-to-point protocol message on the Ethernet is transmitted to the network side device;

[0070] S706: Perform a second encapsulation process on the Point-to-Point Protocol on Ethernet message returned by the network side device, and transmit the Point-to-Point Protocol on Ethernet message after the second encapsulation process to the sending end device, so that the sending end device continues to execute the Point-to-Point Protocol on Ethernet process.

[0071] In some embodiments, the message transmission method of the embodiment of the present disclosure first determines the predefined data filled in the protocol field in the authentication request message based on the authentication request message after the first encapsulation processing transmitted by the sending end device to execute the user authentication process; then, after the user authentication is successful, the point-to-point protocol message on the Ethernet is transmitted to the network side device; finally, the point-to-point protocol message on the Ethernet returned by the network side device is subjected to a second encapsulation processing, and the point-to-point protocol message on the Ethernet after the second encapsulation processing is transmitted to the sending end device, so that the sending end device continues to execute the point-to-point protocol process on the Ethernet. Compared with the related art, since the second-layer Ethernet header is exposed in the outer layer, it cannot pass through the third-layer network in the middle. Otherwise, the dMAC and sMAC will be changed at each hop, resulting in the access server being unable to effectively authenticate and establish a flow table. The embodiment of the present disclosure expands the definition of the protocol field in the network layer data packet to encapsulate the point-to-point protocol message on the Ethernet in the network layer data packet. This is a new method proposed based on the new requirements of network and application deployment. Based on the simple extension of the network layer data packet, the point-to-point protocol authentication and session-level control on the Ethernet can be performed across the three-layer network. This solves the defect that the point-to-point protocol on the traditional Ethernet must be carried on the second-layer network, and also avoids the problems of high overhead and complex operation and maintenance of L2TP and IPv6 tunnel methods.

[0072] In some embodiments, a new encapsulation method is supported between the sending device and the receiving device in both the PPPOE authentication stage and the data transmission stage in the embodiments of the present disclosure. That is, the sending device encapsulates a layer of IPv4 message header in the outer layer of the PPPOE message, in which the protocol field is filled with "240", so that the receiving end can correctly decapsulate and process it. Based on the message transmission method in the embodiments of the present disclosure, only the sending and receiving ends need to support the extended defined IPv4 protocol number, and the devices along the way only need normal IPv4 forwarding. There is no need to deploy an end-to-end Layer 2 channel in the network, which facilitates implementation and reduces risks and maintenance. Since the PPPOE message is encapsulated in the inner layer of the IPv4 message, although it passes through the IP network along the way, the MAC address, VLAN and other information of the sending device (dial-up terminal) and the receiving device (access gateway / authentication server) remain unchanged, thereby retaining the information and capabilities required for PPPOE authentication. In this way, the embodiments of the present disclosure do not need to place the access gateway / authentication server at the edge of the network to waste investment, and also avoid the risk of broadcast storms caused by deploying a large Layer 2 network.

[0073] In more detail, the embodiment of the present disclosure takes the dial-up terminal (sending device) initiating a PPPOE authentication request to the access server (receiving device) as an example. It should be noted that the embodiment of the present disclosure is not limited to implementation in this scenario:

[0074] When a dial-up terminal initiates PPPoE authentication, an IPv4 header is encapsulated around the PPPoE message, with the protocol number field filled with "240." The Layer 2 Ethernet header and PPPoE are completely encapsulated within the IPv4 payload. A new Layer 2 Ethernet header and IPv4 header are then encapsulated around the message, with the dIP representing the access server's IP address and the sIP representing the dial-up terminal's IP address. This ensures that the authentication information is transmitted from the dial-up terminal to the access server. The source and destination MAC addresses in the outer Ethernet header vary with Layer 3 devices along the way, but this does not affect the inner MAC and VLAN IDs.

[0075] 2. After receiving the above message, the access server processes and parses the IPv4 message header. If the protocol number is "240", it will decapsulate and perform PPPOE processing, that is, user authentication and flow table establishment, and then send the user traffic to the network side to access the Internet.

[0076] 3. After the traffic coming back from the Internet enters the server, the access server performs PPPoE encapsulation according to the flow table, adds an IPv4 message and a new Ethernet header, fills the protocol number field of the IPv4 message header with "240", and sends it to the dial-up terminal.

[0077] 4. The dial-up terminal analyzes and parses the IPv4 packet header and finds that the protocol number is "240", then decapsulates it and performs PPPOE processing.

[0078] 5. The round-trip traffic repeatedly passes through the above four steps to achieve the normal transmission of authentication flow and business flow. PPPOE can directly cross the three-layer IP network (within the domain or across AS domains) for authentication control, such as Figure 8 As shown, only IPv4 reachability is required, and there is no need to deploy a large Layer 2 network.

[0079] In the future, as the performance of PPPOE servers continues to increase, their deployment location and coverage can be further improved from the perspective of investment benefits. However, the underlying layer currently uses a large Layer 2 solution for carrying. Although with the introduction of SRv6 EVPN, large Layer 2 broadcast storms and active-active have been improved to a certain extent, it has not completely avoided security risks and reduced the difficulty of operation and maintenance demarcation. The message transmission method in the embodiment of the present disclosure can untie the access server from the large Layer 2 network, and the access server can flexibly implement master-slave and sharing. Users can anchor different access servers based on different business types, which further provides the possibility of customized, intelligent, and differentiated business management on the basis of reducing operation and maintenance difficulty and improving investment benefits.

[0080] Based on the same inventive concept, the present disclosure also provides a message transmission device, such as the following embodiment. Since the principle of solving the problem in the device embodiment is similar to that in the above method embodiment, the implementation of the device embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be repeated.

[0081] Figure 9 A schematic diagram of a message transmission device according to an embodiment of the present disclosure is shown, which is applied to a sending end device. The device includes:

[0082] An authentication request message transmission module 901 is configured to transmit the authentication request message after the first encapsulation process to a receiving device, so that the receiving device performs a user authentication process based on the authentication request message after the first encapsulation process, wherein the authentication request message includes a point-to-point protocol message on an Ethernet network and a network layer data packet, the network layer data packet includes a protocol field, and the protocol field is filled with predefined data;

[0083] a transmission request message parsing module 902 configured to determine, after successful user authentication, based on the transmission request message transmitted by the receiving device after the second encapsulation process, predefined data to be filled in the protocol field of the transmission request message, wherein the transmission request message includes a point-to-point protocol message and a network layer data packet on an Ethernet network;

[0084] The transmission request message processing module 903 is configured to identify and decapsulate the Ethernet Point-to-Point Protocol message in the transmission request message according to the predefined data filled in the protocol field, and continue to execute the Ethernet Point-to-Point Protocol process.

[0085] A message transmission device provided in an embodiment of the present disclosure is applied to a sending-end device, and transmits an authentication request message after a first encapsulation process to a receiving-end device through an authentication request message transmission module, so that the receiving-end device performs a user authentication process based on the authentication request message after the first encapsulation process; after the user authentication is successful, the predefined data filled in the protocol field of the transmission request message in the transmission request message is determined based on the transmission request message after a second encapsulation process transmitted by the receiving-end device through a transmission request message parsing module; and according to the predefined data filled in the protocol field, the Ethernet point-to-point protocol message in the transmission request message is identified and decapsulated through the transmission request message processing module, and the Ethernet point-to-point protocol process is continued to be executed. Compared with the related art, since the second-layer Ethernet header is exposed in the outer layer, it cannot pass through the third-layer network in the middle. Otherwise, the dMAC and sMAC will be changed at each hop, resulting in the access server being unable to effectively authenticate and establish a flow table. The embodiment of the present disclosure expands the definition of the protocol field in the network layer data packet to encapsulate the point-to-point protocol message on the Ethernet in the network layer data packet. This is a new method proposed based on the new requirements of network and application deployment. Based on the simple extension of the network layer data packet, the point-to-point protocol authentication and session-level control on the Ethernet can be performed across the three-layer network. This solves the defect that the point-to-point protocol on the traditional Ethernet must be carried on the second-layer network, and also avoids the problems of high overhead and complex operation and maintenance of L2TP and IPv6 tunnel methods.

[0086] In some embodiments, the message transmission device in the embodiments of the present disclosure further includes: a first encapsulation processing module, which is used to perform a first encapsulation processing on the outer layer of the point-to-point protocol message on the Ethernet before transmitting the authentication request message after the first encapsulation processing to the receiving device, and fill predefined data in the protocol field in the network layer data packet, wherein the payload of the network layer data packet contains a complete Layer 2 Ethernet frame.

[0087] In some embodiments, the first encapsulation processing module in the embodiments of the present disclosure is further configured to encapsulate a layer of header information of a network layer data packet in an outer layer of a point-to-point protocol message on an Ethernet network.

[0088] In some embodiments, the transmission request message parsing module in the embodiments of the present disclosure is also used to receive the second encapsulated transmission request message transmitted by the receiving device; parse the second encapsulated transmission request message to determine the predefined data filled in the protocol field in the transmission request message.

[0089] In some embodiments, the network layer data packet in the embodiments of the present disclosure is an Internet Protocol version 4 IPv4 data packet.

[0090] Based on the same inventive concept, the present disclosure also provides a message transmission device, such as the following embodiment. Since the principle of solving the problem in the device embodiment is similar to that in the above method embodiment, the implementation of the device embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be repeated.

[0091] Figure 10 A schematic diagram of a message transmission device according to an embodiment of the present disclosure is shown, which is applied to a receiving device. The device includes:

[0092] An authentication request message parsing module 1001 is configured to determine, based on the first encapsulated authentication request message transmitted by the sending end device, predefined data to be filled in a protocol field in the authentication request message, so as to execute a user authentication process, wherein the authentication request message includes a point-to-point protocol message and a network layer data packet on an Ethernet network, the network layer data packet includes a protocol field, and the protocol field is filled with the predefined data;

[0093] The message data transmission module 1002 is used to transmit the point-to-point protocol message on the Ethernet to the network side device after the user authentication is successful;

[0094] The message data processing module 1003 is used to perform a second encapsulation process on the point-to-point protocol message on the Ethernet returned by the network side device, and transmit the point-to-point protocol message on the Ethernet after the second encapsulation process to the sending end device, so that the sending end device continues to execute the point-to-point protocol process on the Ethernet.

[0095] In some embodiments, the message transmission device in the embodiments of the present disclosure, through the authentication request message parsing module, determines the predefined data to be filled in the protocol field in the authentication request message based on the authentication request message after the first encapsulation processing transmitted by the sending end device, so as to execute the user authentication process; through the message data transmission module, after the user authentication is successful, the point-to-point protocol message on the Ethernet is transmitted to the network side device; through the message data processing module, the point-to-point protocol message on the Ethernet returned by the network side device is subjected to a second encapsulation processing, and the point-to-point protocol message on the Ethernet after the second encapsulation processing is transmitted to the sending end device, so that the sending end device continues to execute the point-to-point protocol process on the Ethernet. Compared with the related art, since the second-layer Ethernet header is exposed in the outer layer, it cannot pass through the third-layer network in the middle. Otherwise, the dMAC and sMAC will be changed at each hop, resulting in the access server being unable to effectively authenticate and establish a flow table. The embodiment of the present disclosure expands the definition of the protocol field in the network layer data packet to encapsulate the point-to-point protocol message on the Ethernet in the network layer data packet. This is a new method proposed based on the new requirements of network and application deployment. Based on the simple extension of the network layer data packet, the point-to-point protocol authentication and session-level control on the Ethernet can be performed across the three-layer network. This solves the defect that the point-to-point protocol on the traditional Ethernet must be carried on the second-layer network, and also avoids the problems of high overhead and complex operation and maintenance of L2TP and IPv6 tunnel methods.

[0096] Those skilled in the art will appreciate that various aspects of the present disclosure may be implemented as systems, methods, or program products. Therefore, various aspects of the present disclosure may be implemented in the following forms: a complete hardware implementation, a complete software implementation (including firmware, microcode, etc.), or a combination of hardware and software implementations, which may be collectively referred to herein as "circuits," "modules," or "systems."

[0097] Based on the same inventive concept, an embodiment of the present disclosure further provides an electronic device, comprising: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute any of the above-mentioned message transmission methods by executing the executable instructions. Since the principles for solving the problem in this electronic device embodiment are similar to those in the above-mentioned method embodiment, the implementation of this electronic device embodiment can refer to the implementation of the above-mentioned method embodiment, and the repeated parts will not be repeated here.

[0098] Refer to the following Figure 11 1100 according to this embodiment of the present disclosure will be described. Figure 11 The electronic device 1100 shown is merely an example and should not limit the functions and scope of use of the embodiments of the present disclosure.

[0099] like Figure 11As shown, electronic device 1100 is implemented as a general-purpose computing device. Components of electronic device 1100 may include, but are not limited to, the aforementioned at least one processing unit 1101, the aforementioned at least one storage unit 1102, and a bus 1103 connecting various system components (including storage unit 1102 and processing unit 1101).

[0100] The storage unit stores program codes, which can be executed by the processing unit 1101, so that the processing unit 1101 executes the steps according to various exemplary embodiments of the present disclosure described in the above “Exemplary Method” section of this specification.

[0101] In some embodiments, when an electronic device is used to control, for example, the message transmission method disclosed above, the processing unit 1101 may perform the following steps of the above method embodiment:

[0102] An authentication request message after a first encapsulation process is transmitted to a receiving device, so that the receiving device performs a user authentication process based on the authentication request message after the first encapsulation process, wherein the authentication request message includes a point-to-point protocol message and a network layer data packet on Ethernet, the network layer data packet includes a protocol field, and the protocol field is filled with predefined data; after the user authentication is successful, based on the transmission request message after a second encapsulation process transmitted by the receiving device, the predefined data filled with the protocol field in the transmission request message is determined, wherein the transmission request message includes a point-to-point protocol message and a network layer data packet on Ethernet; according to the predefined data filled in the protocol field, the point-to-point protocol message on Ethernet in the transmission request message is identified and decapsulated, and the point-to-point protocol process on Ethernet is continued to be executed.

[0103] The storage unit 1102 may include a readable medium in the form of a volatile storage unit, such as a random access memory unit (RAM) 11021 and / or a cache memory unit 11022 , and may further include a read-only memory unit (ROM) 11023 .

[0104] The storage unit 1102 may also include a program / utility 11024 having a set (at least one) of program modules 11025, such program modules 11025 including but not limited to: an operating system, one or more application programs, other program modules, and program data, each of which or some combination may include an implementation of a network environment.

[0105] The bus 1103 may represent one or more of several types of bus structures, including a memory unit bus or memory unit controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus architectures.

[0106] The electronic device 1100 can also communicate with one or more external devices 1104 (e.g., a keyboard, a pointing device, a Bluetooth device, etc.), one or more devices that enable a user to interact with the electronic device 1100, and / or any device that enables the electronic device 1100 to communicate with one or more other computing devices (e.g., a router, a modem, etc.). Such communication can occur via an input / output (I / O) interface 1105. Furthermore, the electronic device 1100 can also communicate with one or more networks (e.g., a local area network (LAN), a wide area network (WAN), and / or a public network such as the Internet) via a network adapter 1106. As shown, the network adapter 1106 communicates with other modules of the electronic device 1100 via a bus 1103. It should be understood that, although not shown in the figure, other hardware and / or software modules can be used in conjunction with the electronic device 1100, including but not limited to microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0107] Through the description of the above embodiments, it is easy for those skilled in the art to understand that the example embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solution according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes several instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the embodiments of the present disclosure.

[0108] Based on the same inventive concept, embodiments of the present disclosure further provide a computer-readable storage medium having a computer program stored thereon. When executed by a processor, the computer program implements any of the aforementioned message transmission methods. Because the principles underlying the problems solved by this computer-readable storage medium embodiment are similar to those of the aforementioned method embodiment, the implementation of this computer-readable storage medium embodiment can be referenced to the implementation of the aforementioned method embodiment, and any repetitions will not be repeated.

[0109] More specific examples of computer-readable storage media in the present disclosure may include, but are not limited to, an electrical connection having one or more conductors, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), optical fibers, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0110] In the present disclosure, a computer-readable storage medium may include a data signal propagated in baseband or as part of a carrier wave, which carries readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium that can transmit, propagate, or transfer a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0111] Alternatively, the program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination thereof.

[0112] In a specific implementation, the program code for performing the operations of the present disclosure may be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java, C++, and the like, as well as conventional procedural programming languages ​​such as "C" or similar programming languages. The program code may be executed entirely on the user's computing device, partially on the user's device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0113] Based on the same inventive concept, embodiments of the present disclosure further provide a computer program product, including a computer program or instructions, which, when executed by a processor, implements the message transmission method of any one of the above-described method embodiments. Because the principles for solving the problems of this computer program product embodiment are similar to those of the above-described method embodiments, the implementation of this computer program product embodiment can refer to the implementation of the above-described method embodiments, and any repetitions will not be repeated.

[0114] It should be noted that although several modules or units of the device for action execution are mentioned in the detailed description above, this division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more modules or units described above can be concretized in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided into multiple modules or units to be concretized.

[0115] Furthermore, although the steps of the method of the present disclosure are described in a particular order in the accompanying drawings, this does not require or imply that the steps must be performed in this particular order, or that all steps shown must be performed to achieve the desired results. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step, and / or one step may be decomposed into multiple steps.

[0116] Through the description of the above embodiments, it is easy for those skilled in the art to understand that the example embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solution according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes several instructions to enable a computing device (which can be a personal computer, a server, a mobile terminal, or a network device, etc.) to execute the method according to the embodiments of the present disclosure.

[0117] Other embodiments of the present disclosure will readily occur to those skilled in the art after considering the specification and practicing the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, with the true scope and spirit of the present disclosure being indicated by the appended claims.

Claims

1. A message transmission method, characterized in that: Applicable to the sending end device, including: Transmitting the first encapsulated authentication request message to a receiving device, so that the receiving device performs a user authentication process based on the first encapsulated authentication request message, wherein the authentication request message includes a point-to-point protocol message and a network layer data packet on an Ethernet network, the network layer data packet includes a protocol field, and the protocol field is filled with predefined data; After successful user authentication, determining, based on the transmission request message transmitted by the receiving device and subjected to the second encapsulation process, predefined data to be filled in the protocol field of the transmission request message, wherein the transmission request message includes a point-to-point protocol message and a network layer data packet on the Ethernet; According to the predefined data filled in the protocol field, the Point-to-Point Protocol over Ethernet message in the transmission request message is identified and decapsulated, and the Point-to-Point Protocol over Ethernet process is continued to be executed.

2. The message transmission method according to claim 1, wherein: Before transmitting the authentication request message after the first encapsulation process to the receiving device, the method further includes: A first encapsulation process is performed on the outer layer of the point-to-point protocol message on the Ethernet, and predefined data is filled in the protocol field in the network layer data packet, wherein the payload of the network layer data packet includes a complete layer 2 Ethernet frame.

3. The message transmission method according to claim 2, wherein: Performing a first encapsulation process on an outer layer of a point-to-point protocol message on the Ethernet includes: A layer of header information of the network layer data packet is encapsulated in the outer layer of the point-to-point protocol message on the Ethernet.

4. The message transmission method according to claim 1, wherein: Determining, based on the transmission request message after the second encapsulation processing and transmitted by the receiving device, predefined data to be filled in the protocol field in the transmission request message includes: receiving the second encapsulated transmission request message transmitted by the receiving end device; The transmission request message after the second encapsulation process is parsed to determine predefined data filled in the protocol field in the transmission request message.

5. The message transmission method according to claim 1, wherein: The network layer data packet is an Internet Protocol version 4 IPv4 data packet.

6. A message transmission method, characterized in that: Applied to receiving devices, including: Determining, based on the authentication request message after the first encapsulation process transmitted by the sending end device, predefined data to be filled in a protocol field in the authentication request message, so as to perform a user authentication process, wherein the authentication request message includes a point-to-point protocol message and a network layer data packet on an Ethernet network, the network layer data packet includes a protocol field, and the protocol field is filled with the predefined data; After the user authentication is successful, the point-to-point protocol message on the Ethernet is transmitted to the network side device; Perform a second encapsulation process on the point-to-point protocol message on Ethernet returned by the network side device, and transmit the point-to-point protocol message on Ethernet after the second encapsulation process to the sending end device, so that the sending end device continues to execute the point-to-point protocol process on Ethernet.

7. A message transmission device, characterized in that: Applicable to the sending end device, including: an authentication request message transmission module, configured to transmit the authentication request message after the first encapsulation process to a receiving device, so that the receiving device performs a user authentication process based on the authentication request message after the first encapsulation process, wherein the authentication request message includes a point-to-point protocol message on an Ethernet network and a network layer data packet, the network layer data packet includes a protocol field, and the protocol field is filled with predefined data; a transmission request message parsing module, configured to determine, after successful user authentication, based on the transmission request message after the second encapsulation process and transmitted by the receiving device, predefined data to be filled in the protocol field of the transmission request message, wherein the transmission request message includes a point-to-point protocol message and a network layer data packet on the Ethernet; The transmission request message processing module is used to identify and decapsulate the Ethernet point-to-point protocol message in the transmission request message according to the predefined data filled in the protocol field, and continue to execute the Ethernet point-to-point protocol process.

8. A message transmission device, characterized in that: Applied to receiving devices, including: an authentication request message parsing module, configured to determine, based on the authentication request message after the first encapsulation process transmitted by the sending end device, predefined data to be filled in the protocol field in the authentication request message, so as to execute the user authentication process, wherein the authentication request message includes a point-to-point protocol message and a network layer data packet on the Ethernet, the network layer data packet includes a protocol field, and the protocol field is filled with the predefined data; A message data transmission module, used for transmitting the point-to-point protocol message on the Ethernet to the network side device after the user authentication is successful; The message data processing module is used to perform a second encapsulation process on the point-to-point protocol message on the Ethernet returned by the network side device, and transmit the point-to-point protocol message on the Ethernet after the second encapsulation process to the sending end device, so that the sending end device continues to execute the point-to-point protocol process on the Ethernet.

9. An electronic device, characterized in that: include: processor; as well as a memory for storing executable instructions of the processor; The processor is configured to execute the message transmission method according to any one of claims 1 to 7 by executing the executable instructions.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the message transmission method according to any one of claims 1 to 7 is implemented.

11. A computer program product comprising: A computer program or instruction, characterized in that when the computer program or instruction is executed by a processor, it implements the message transmission method according to any one of claims 1 to 7.