Method and apparatus for obtaining digital certificate
By configuring a virtual LAN in the router device and associating it with the server URL, the download of digital certificates is automatically redirected, solving the problem of the complexity of obtaining digital certificates and improving the user experience.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-07-06
- Publication Date
- 2026-03-24
AI Technical Summary
The acquisition of digital certificates requires a high level of expertise from users and involves complex operations, resulting in low usage rates of certificate-based internet access in real life and impacting network security.
By pre-configuring a first virtual LAN in the routing device and associating it with the server URL used to provide digital certificates, when a user initiates a network access request through this virtual LAN, the user is automatically redirected to the server to download and install the digital certificate, simplifying the user's operation.
The process of obtaining digital certificates is simplified, eliminating the need for users to remember or enter server domain names or addresses, thus improving the user experience.
Smart Images

Figure CN113972988B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to methods and apparatus for obtaining digital certificates. Background Technology
[0002] A digital certificate is a digital authentication document used in internet communication to identify the identities of parties involved. It is also known as a digital identifier. Digital certificates ensure the integrity and security of information and data exchanged between internet users on computer networks.
[0003] Currently, based on Wireless LAN Authentication and Privacy Infrastructure (WAPI) and WiFi network access, digital certificates are used to ensure network access (commonly known as "internet access") security. This method of internet access is called certificate mode. Certificate mode is currently the highest level of security that smart devices can choose when accessing the internet wirelessly.
[0004] However, accessing the network using digital certificates, especially the methods for obtaining digital certificates, requires a high level of expertise from users and is not easy to operate. This limits the adoption of certificate-based internet access in real-world production and daily life, and is detrimental to network security as a whole. Therefore, simplifying the process of obtaining digital certificates to facilitate user access to the network is a technical problem that needs to be solved. Summary of the Invention
[0005] This application provides a digital certificate acquisition method and apparatus to simplify the digital certificate acquisition process and improve user experience.
[0006] In a first aspect, embodiments of this application provide a method for obtaining a digital certificate, including:
[0007] The routing device receives a network access request sent by a terminal based on a first virtual local area network (VLAN); wherein the first VLAN is associated with a Uniform Resource Locator (URL) of a server, enabling the terminal to obtain a digital certificate for accessing a second VLAN through the server;
[0008] In response to a network access request sent by a terminal based on a first virtual LAN, the routing device sends the server's URL to the terminal, enabling the terminal to obtain a digital certificate from the server based on the URL.
[0009] In embodiments of this application, it further includes:
[0010] The routing device receives network access requests sent by the terminal based on the second virtual LAN;
[0011] The routing device performs digital certificate authentication with the terminal based on the network access request sent by the terminal based on the second virtual LAN, and establishes a network connection with the terminal after successful authentication.
[0012] In embodiments of this application, the routing device, in response to a network access request sent by a terminal based on a first virtual local area network, sends the URL of a server to the terminal, including:
[0013] After receiving a DNS resolution request sent by the terminal based on the first virtual LAN, the proxy Domain Name System (DNS) service in the routing device sends a DNS resolution response to the terminal, which carries the IP address of the proxy web service.
[0014] The proxy web service receiving terminal in the routing device sends a redirect message carrying the server's URL to the terminal based on the proxy web service's IP address and the network access request sent based on the first virtual LAN. The server enables the terminal to obtain a digital certificate for accessing the second virtual LAN.
[0015] In embodiments of this application, the routing device, in response to a network access request sent by a terminal based on a first virtual local area network, sends the URL of a server to the terminal, including:
[0016] After receiving a DNS resolution request sent by the terminal based on the first virtual LAN, the proxy DNS service in the routing device sends a redirection message carrying the server's URL to the terminal. The server then enables the terminal to obtain a digital certificate for accessing the second virtual LAN.
[0017] In the embodiments of this application, the routing device is configured with a first service set identifier and a second service set identifier. The first service set identifier is used to identify a first virtual local area network (VLAN), and the second service set identifier is used to identify a second VLAN.
[0018] Secondly, embodiments of this application provide a routing device, including:
[0019] The receiving module is configured to receive network access requests sent by the terminal based on a first virtual local area network (VLAN); wherein the first VLAN is associated with a Uniform Resource Locator (URL) of a server, enabling the terminal to obtain a digital certificate for accessing a second VLAN through the server.
[0020] The processing module is configured to send the server's URL to the terminal in response to a network access request initiated based on the first virtual LAN, so that the terminal can obtain a digital certificate from the server based on the URL.
[0021] In embodiments of this application, the receiving module is further configured to receive network access requests sent by the terminal based on a second virtual local area network;
[0022] The processing module is also configured to perform digital certificate authentication with the terminal based on the network access request sent by the terminal based on the second virtual LAN, and establish a network connection with the terminal after successful authentication.
[0023] In embodiments of this application, the processing module includes a proxy Domain Name System (DNS) service module and a proxy Web service module;
[0024] The proxy DNS service module is configured to receive a DNS resolution request sent by the terminal based on the first virtual LAN, and then send a DNS resolution response to the terminal, the DNS resolution response carrying the IP address of the proxy WEB service;
[0025] The proxy web service module is configured to receive network access requests sent by the terminal based on the IP address of the proxy web service and the first virtual LAN, and send a redirect message carrying the server's URL to the terminal. The server enables the terminal to obtain a digital certificate for accessing the second virtual LAN.
[0026] In embodiments of this application, the processing module includes a proxy DNS service module;
[0027] The proxy DNS service module is configured to receive a DNS resolution request sent by the terminal based on the first virtual LAN, and then send a redirect message carrying the server's URL to the terminal. The server enables the terminal to obtain a digital certificate for accessing the second virtual LAN.
[0028] In the embodiments of this application, the routing device is configured with a first service set identifier and a second service set identifier. The first service set identifier is used to identify a first virtual local area network (VLAN), and the second service set identifier is used to identify a second VLAN.
[0029] Thirdly, embodiments of this application provide a routing device, including a processor, a memory, and a communication interface;
[0030] The communication interface, under the control of the processor, receives and sends data;
[0031] Memory stores computer instructions;
[0032] A processor is used to read computer instructions and execute methods such as those described in the first aspect.
[0033] Fourthly, this application provides a computer-readable storage medium storing computer-executable instructions for causing a computer to perform the method as described in any one of the first aspects.
[0034] In the embodiments of this application, the routing device receives and responds to a network access request sent by a terminal based on a first virtual local area network (VLAN), sending the server's URL to the terminal. This allows the terminal to obtain a digital certificate for accessing a second VLAN from the server based on the URL. The terminal can then use this digital certificate to access the network via the second VLAN. The first VLAN is associated with the URL of the server providing the digital certificate, eliminating the need for the user to remember the server's domain name or address, simplifying the digital certificate acquisition process and improving the user experience. Attached Figure Description
[0035] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0036] Figure 1 An exemplary diagram illustrating an application scenario provided in an embodiment of this application is shown;
[0037] Figure 2 An exemplary schematic diagram of the routing device structure provided in an embodiment of this application is shown;
[0038] Figure 3 An exemplary flowchart of a network access method provided in an embodiment of this application is shown;
[0039] Figure 4 An exemplary flowchart illustrating the process of obtaining a digital certificate provided in an embodiment of this application is shown;
[0040] Figure 5 An exemplary flowchart illustrating the process of obtaining a digital certificate provided in an embodiment of this application is shown;
[0041] Figure 6 An exemplary schematic diagram of the terminal structure provided in an embodiment of this application is shown;
[0042] Figure 7 An exemplary schematic diagram of the base station structure provided in an embodiment of this application is shown. Detailed Implementation
[0043] To make the objectives, technical solutions, and advantages of this application clearer, the present invention will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are merely some embodiments of the present invention, and not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0044] Hereinafter, the terms "first" and "second" are used only for distinguishing descriptions and should not be construed as implying or suggesting relative importance or implicitly indicating the number of indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of the embodiments of this application, unless otherwise stated, "at least one" means one or more.
[0045] When using a security mechanism based on digital certificates, the terminal needs to install a digital certificate.
[0046] In the civilian sector, the typical process for obtaining and installing a digital certificate is as follows: The user connects to the internet via their terminal (e.g., through a wired LAN (local area network) or dial-up connection), logs into the server, enters the required information on the server's digital certificate application interface, downloads the digital certificate file, and manually installs it locally. This method requires the user to know the server's domain name or IP address beforehand and to be familiar with the digital certificate application process, making it relatively cumbersome.
[0047] In the industry / enterprise user field, industry / enterprises typically have network administrators configure digital certificates for industry / enterprise users or employees through a certificate server, and then distribute the digital certificates to industry / enterprise users or employees for certificate installation via email, SMS, or mobile storage (such as USB flash drive). The whole process is cumbersome, error-prone, and inefficient.
[0048] To address the aforementioned issues, this application provides a method for obtaining digital certificates. In this method, a first virtual local area network (VLAN) is pre-configured in a routing device and associated with a Uniform Resource Locator (URL) pointing to a server providing digital certificates. When a user initiates a network access request through the first VLAN, the request is redirected to the server corresponding to the URL. This allows the terminal to download and install a digital certificate for accessing a second VLAN through the server, enabling normal network access via the second VLAN. This process eliminates the need for users to remember or obtain server domain names or addresses, saving network administrators and simplifying the acquisition and use of digital certificates, thus improving the user experience.
[0049] The embodiments of this application are described in detail below with reference to the accompanying drawings.
[0050] Figure 1An exemplary illustration of an application scenario provided by an embodiment of this application is shown. As shown in the figure, the scenario includes terminal 100a and terminal 100b. The terminals (100a, 100b) are connected to the routing device 200 wirelessly or via a wired connection. The routing device 200 is connected to the server 300 via a network 400.
[0051] The terminals (100a, 100b) can be various forms of user equipment, such as mobile stations (MS) and terminal equipment. Examples of terminals include: mobile phones, tablets, laptops, PDAs, mobile internet devices (MIDs), wearable devices, wireless terminals in self-driving vehicles, wireless terminals in smart grids, and wireless terminals in smart homes.
[0052] The routing device 200 is mainly used to provide network access, and can be an access router, enterprise router, home router or other network device with routing function.
[0053] Server 300 can be used as an enterprise-level server, public network server, etc., to provide digital certificate services so that users can obtain digital certificates.
[0054] Network 400 can be the Internet, and correspondingly, Server 300 is a server of a digital certificate authority, which can provide digital certificate application services to public users. Network 400 can also be a local area network, such as an enterprise LAN, and correspondingly, Server 300 is an enterprise-level server (for example, the IP address of this enterprise-level server is http: / / 192.168.1.1), which can provide digital certificate application services to users within the enterprise LAN. The applied digital certificates are internal enterprise digital certificates that can identify the identity of users within the enterprise's internal network.
[0055] In some embodiments, server 300 may also be directly connected to routing device 200 or directly integrated into routing device 200.
[0056] In this embodiment of the application, a first virtual local area network is pre-configured in the routing device 200. This virtual local area network is associated with a URL pointing to the server 300. When the terminal (100a, 100b) accesses the network based on the first virtual local area network, the access request is redirected to the server to guide the user to complete the digital certificate acquisition operation.
[0057] Figure 2An exemplary diagram illustrates the configuration of a virtual local area network (VLAN) in a routing device 200 provided in this application embodiment. As shown in the figure, VLAN1 (first VLAN), VLAN2 (second VLAN), service set identifier SSID1, and service set identifier SSID2 are configured on the routing device 200. SSID1 identifies VLAN1, and the network to which SSID1 belongs is VLAN1. SSID2 identifies VLAN2, and the network to which SSID2 belongs is VLAN2.
[0058] VLAN1 is configured for access without digital certificate authentication. For example, when a smartphone accesses a wireless LAN, it often uses the access method of clicking the SSID and then entering the password or the access method of clicking the SSID without entering a password; VLAN2 is configured for access with digital certificate authentication.
[0059] VLAN 1 is associated with a URL on server 300, which provides digital certificates, to redirect network access initiated based on VLAN 1 to server 300, allowing terminals to download digital certificates through server 300. This digital certificate serves as credentials for terminals (100a, 100b) to access VLAN 2.
[0060] After the digital certificate is installed, the terminals (100a, 100b) can access VLAN2 through the digital certificate for normal network access.
[0061] according to Figure 2 The diagram shown is a structural schematic of the routing device 200. Figure 3 An exemplary flowchart of a network access method provided in an embodiment of this application is shown. As illustrated, the process mainly includes the following steps:
[0062] S301: Router device 200 receives network access requests initiated by the terminal based on VLAN 1.
[0063] In this configuration, VLAN1 is associated with the server's URL, enabling the terminal to obtain a digital certificate for accessing VLAN2 through the server.
[0064] In this step, on the terminal side, the terminal obtains the SSID list of the routing device. This SSID list contains SSID1 and SSID2, where SSID1 is the identifier for VLAN 1 and SSID2 is the identifier for VLAN 2. SSID1 in this SSID list is triggered to select the corresponding VLAN 1 (for example, the user clicks SSID1 in the SSID list via the terminal's touchscreen, or the application (APP) on the terminal automatically selects SSID1), so that the terminal can access VLAN 1 corresponding to SSID1.
[0065] The browser on the terminal is opened actively (automatically by the terminal program) or passively (by the user), and the browser actively or passively sends a network access request to the router device 200. Currently, most smartphones automatically submit network access requests to the router device via their browser, which is called actively submitting a network access request. Other terminal devices may still require manual input of a string conforming to the domain name format (e.g., xxx.com, yyy.org, etc.) into the browser to trigger the terminal to send a network access request to the router device 200 via the browser, which is called passively submitting a network access request.
[0066] S302: In response to a network access request sent by a terminal based on VLAN 1, the routing device 200 sends the URL of the server 300 to the terminal, enabling the terminal to obtain a digital certificate from the server 300 based on the URL.
[0067] In this step, routing device 200 can confirm that the network access request was sent based on VLAN 1 based on the SSID1 identifier. Routing device 200 responds to the network access request by sending the URL of the server 300 associated with VLAN 1 back to the terminal, enabling the terminal to access the server 300 corresponding to that URL through a browser.
[0068] In this embodiment, for any network access request sent by the terminal with a domain name (a string that conforms to the domain name format), the routing device will send the URL of the server 300 associated with VLAN1 back to the terminal as a response, so that the terminal can access the server 300 corresponding to the URL.
[0069] S303: The terminal applies for a digital certificate through server 300.
[0070] In this step, on the terminal side, the user can click the "Download" option according to the prompts on the digital certificate application interface provided by server 300, and select the local storage path for the digital certificate as prompted. After the download is complete, click the "Install" option, and select the local installation path for the digital certificate as prompted, thereby installing the digital certificate on the terminal.
[0071] In other embodiments, for example, the digital certificate download page can provide methods for downloading and installing digital certificates. For instance, the download page may provide a document containing the download address and installation process of the digital certificate. On the terminal side, the user can download and install the digital certificate according to the document.
[0072] After obtaining a digital certificate, the terminal can use this digital certificate to initiate a network access process based on VLAN 2 when network access is required. The specific steps may include the following:
[0073] S304: Router device 200 receives a network access request initiated by the terminal based on VLAN 2.
[0074] In this step, SSID2 in the terminal's SSID list is triggered (e.g., the user clicks SSID2, or the app on the terminal automatically selects SSID2), enabling the terminal to access VLAN 2. The terminal is able to access VLAN 2 because the digital certificate installed on the terminal serves as the credential for accessing VLAN 2.
[0075] The routing device 200 performs digital certificate authentication with the terminal, and establishes a network connection with the terminal after successful authentication, thereby enabling normal network access.
[0076] Digital certificates generally have an expiration date. Within this period, the terminal can skip the download and installation processes S301-S303 and directly execute the network access process S304. Within a preset number of days before the digital certificate expires, when a user accesses the network through the terminal, the APP user interface on the terminal can display a prompt to update the digital certificate, allowing the user to update it accordingly. If the digital certificate is not updated by the expiration date, the terminal will be unable to access the network and will need to re-execute the digital certificate acquisition process of S301-S303.
[0077] In steps S301 to S303 above, which is the process of obtaining a digital certificate, the routing device 200 redirects the access request sent by the terminal to the server 300 based on VLAN 1, so that the user can download and install the digital certificate without having to remember the server's IP address, thereby simplifying the user's operation of obtaining a digital certificate.
[0078] In some embodiments, the routing device 200 and the server 300 may be integrated into a single device, the function of which is the same as that achieved by the routing device 200 and the server 300 when deployed independently.
[0079] In some embodiments, the routing device may include a proxy DNS service and a proxy WEB service. These services can be used to redirect network access requests from terminals to servers. The process can be as follows: Figure 4 As shown.
[0080] Figure 4 An exemplary flowchart of a network access request redirection provided in an embodiment of this application is illustrated. As shown in the figure, the process includes the following steps:
[0081] S401: The terminal selects SSID1 from the SSID list provided by the routing device 200 to access VLAN1, and receives the domain name address entered by the user or automatically generated by the terminal program.
[0082] S402: The terminal sends a DNS resolution request based on VLAN 1 to the routing device 200, which is then submitted to the proxy DNS service for processing.
[0083] S403: After receiving the DNS resolution request, the proxy DNS service in the routing device 200 sends a DNS resolution response to the terminal. The DNS resolution response carries the IP address of the proxy WEB service.
[0084] S404: The terminal sends an HTTP access request to the routing device 200 based on the IP address of the proxy web service. The HTTP access request is then submitted to the proxy web service for processing.
[0085] S405: The proxy WEB service in the routing device 200 responds to the HTTP access request and sends a redirect message to the terminal carrying the URL of server 300. Server 300 is used to enable the terminal to obtain a digital certificate for accessing VLAN 2.
[0086] S406: The terminal sends an HTTP access request to the corresponding server 300 based on the URL, and completes the digital certificate acquisition operation by accessing the server 300.
[0087] In some embodiments, when server 300 is a server that provides public network digital certificates, the source IP address of the terminal can be converted to a public network IP address through Source Network Address Translation (SNAT) to access server 300; when server 300 is a server that provides internal network digital certificates, source address translation is not required.
[0088] In the above embodiments of this application, in S402, the DNS resolution request sent by the terminal may include the domain name entered by the user and some other parameters; in S403, the DNS resolution response returned to the terminal by the proxy DNS access will contain these parameters; in S404, the proxy WEB service can normalize the domain name address entered by the user and delete unnecessary parameters so that the server can ensure that it responds correctly to the received request (in most cases, servers on the market can process unnecessary parameters in the domain name and thus respond correctly to the received access request; however, in a few cases, some servers cannot process unnecessary parameters in the domain name, causing them to consider the received access request as an erroneous request and thus report an error to the terminal, such as a 404 error).
[0089] In other embodiments of this application, the routing device may include a proxy DNS service, which can redirect network access requests from terminals to server 300. The process can be as follows: Figure 5As shown.
[0090] Figure 5 An exemplary flowchart of obtaining a digital certificate provided in an embodiment of this application is illustrated. As shown in the figure, the process includes the following steps:
[0091] S501: The terminal selects SSID1 from the SSID list provided by the routing device 200 to access VLAN1, and receives the domain name address entered by the user or automatically generated by the terminal program.
[0092] S502: The terminal sends a DNS resolution request based on VLAN 1 to the routing device 200, and the request is submitted to the proxy DNS service for processing.
[0093] S503: After receiving the DNS resolution request, the proxy DNS service in the routing device 200 sends a redirection message carrying the URL of server 300 to the terminal. Server 300 is used to enable the terminal to obtain a digital certificate for accessing VLAN 2.
[0094] S504: The terminal sends an HTTP access request to the corresponding server 300 based on the URL, and completes the digital certificate acquisition operation by accessing the server 300.
[0095] In the embodiments of this application, the routing device is internally configured with VLAN 1 and VLAN 2. VLAN 1 is associated with the URL of a server that provides a digital certificate enabling the terminal to access VLAN 2. When a terminal accesses VLAN 1, the terminal's browser submits a network access request to the routing device 200. The routing device 200 redirects this network access request to the server associated with VLAN 1, thereby allowing the terminal to obtain a digital certificate from that server. When a user needs to access the network, they can initiate a network access request based on VLAN 2 for normal network access. This eliminates the need for the user to remember or obtain the server's domain name or address, reducing the difficulty of obtaining a digital certificate, simplifying the digital certificate acquisition process, and improving the user experience.
[0096] Based on the same technical concept, this application also provides a routing device that can realize the functions of the routing device in the foregoing embodiments.
[0097] Figure 6 The structure of a node device in an embodiment of this application is illustrated. As shown in the figure, the node device may include a receiving module 601 and a processing module 602.
[0098] The receiving module 601 is configured to receive network access requests sent by the terminal based on the first virtual local area network; wherein the first virtual local area network is associated with the Uniform Resource Locator (URL) of the server, enabling the terminal to obtain a digital certificate for accessing the second virtual local area network through the server.
[0099] The processing module 602 is configured to send the server's URL to the terminal in response to a network access request initiated by the terminal based on the first virtual local area network, so that the terminal can obtain a digital certificate from the server based on the URL.
[0100] In some embodiments of this application, the receiving module 601 is further configured to receive network access requests initiated by the terminal based on a second virtual local area network;
[0101] The processing module 602 is also configured to perform digital certificate authentication with the terminal based on the network access request sent by the terminal based on the second virtual local area network, and establish a network connection with the terminal after successful authentication.
[0102] In some embodiments of this application, the processing module includes a proxy Domain Name System (DNS) service module 6021 and a proxy Web service module 6022;
[0103] The proxy DNS service module 6021 is configured to send a DNS resolution response to the terminal after receiving a DNS resolution request sent by the terminal based on the first virtual local area network. The DNS resolution response carries the IP address of the proxy WEB service.
[0104] The proxy web service module 6022 is configured to receive network access requests sent by the terminal based on the IP address of the proxy web service and the first virtual LAN, and send a redirect message carrying the URL of the server to the terminal. The server enables the terminal to obtain a digital certificate for accessing the second virtual LAN.
[0105] In some embodiments of this application, the processing module includes a proxy DNS service module 6021;
[0106] The proxy DNS service module 6021 is also configured to send a redirect message carrying the server's URL to the terminal after receiving a DNS resolution request sent by the terminal based on the first virtual LAN, so that the server enables the terminal to obtain a digital certificate for accessing the second virtual LAN.
[0107] In some embodiments of this application, the routing device is configured with a first service set identifier and a second service set identifier, wherein the first service set identifier is used to identify a first virtual local area network (VLAN), and the second service set identifier is used to identify a second VLAN.
[0108] It should be noted that the routing device provided in this application embodiment can implement all the method steps implemented in the above method embodiment and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0109] Based on the same technical concept, this application also provides a routing device that can realize the functions of the routing device in the foregoing embodiments.
[0110] Figure 7 A schematic diagram of the structure of a node device in an embodiment of this application is shown as an example. As shown, the node device may include: a processor 701, a memory 702, a communication interface 703, and a bus interface 704.
[0111] Processor 701 is responsible for managing the bus architecture and general processing, while memory 702 stores data used by processor 701 during operation. Communication interface 703 is used to receive and send data under the control of processor 701.
[0112] The bus architecture can include any number of interconnected buses and bridges, specifically linking various circuits together, represented by one or more processors (processor 701) and memory (memory 702). The bus architecture can also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides the interface. Processor 701 is responsible for managing the bus architecture and general processing, and memory 702 can store data used by processor 701 during operation.
[0113] The process disclosed in this application embodiment can be applied to or implemented by processor 701. During implementation, each step of the signal processing flow can be completed by integrated logic circuits in the hardware or by instructions in software form within processor 701. Processor 701 can be a general-purpose processor, digital signal processor, application-specific integrated circuit, field-programmable gate array (FPGA), or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, and can implement or execute the methods, steps, and logic block diagrams disclosed in this application embodiment. A general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in this application embodiment can be directly implemented by the hardware processor, or implemented by a combination of hardware and software modules within the processor. The software modules can reside in random access memory (RAM), flash memory, read-only memory (ROM), programmable read-only memory (PROM), electrically erasable programmable memory (EEPROM), registers, or other mature storage media in the art. This storage medium is located in memory 702, and processor 701 reads information from memory 702 and, in conjunction with its hardware, completes the steps of the signal processing flow. Specifically, processor 701 is used to read and execute computer instructions from memory 702. Figure 2 The functions implemented on the terminal side in the process shown are as follows.
[0114] Specifically, processor 701 can read computer instructions from memory 702 and perform the following operations:
[0115] The routing device receives network access requests sent by the terminal based on the first virtual local area network (VLAN); wherein the first VLAN is associated with the server's Uniform Resource Locator (URL), enabling the terminal to obtain a digital certificate for accessing the second VLAN through the server;
[0116] In response to a network access request sent by a terminal based on a first virtual LAN, the routing device sends the server's URL to the terminal, enabling the terminal to obtain a digital certificate from the server based on the URL.
[0117] In embodiments of this application, the operations performed by the processor further include:
[0118] The receiving terminal sends a network access request based on the second virtual local area network;
[0119] Based on the network access request initiated by the terminal based on the second virtual LAN, digital certificate authentication is performed with the terminal, and a network connection is established with the terminal after successful authentication.
[0120] It should be noted that the routing device provided in this application embodiment can implement all the method steps implemented in the above method embodiment and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0121] This application also provides a computer-readable storage medium storing computer-executable instructions for causing a computer to perform the method executed by the routing device in the above embodiments.
[0122] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0123] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0124] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0125] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0126] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. A method for obtaining a digital certificate, characterized in that, include: The routing device receives a network access request sent by a terminal based on a first virtual local area network (VLAN). The routing device is pre-configured with a first VLAN and a second VLAN. The first VLAN is associated with a Uniform Resource Locator (URL) of a server, enabling the terminal to obtain a digital certificate for accessing the second VLAN through the server. In response to a network access request sent by the terminal based on a first virtual local area network (VLAN), the routing device sends the URL of the server to the terminal, enabling the terminal to obtain a digital certificate from the server based on the URL. For any domain name network access request sent by the terminal, the URL of the server associated with the first VLAN is returned to the terminal as a response.
2. The method as described in claim 1, characterized in that, Also includes: The routing device receives the network access request sent by the terminal based on the second virtual local area network; The routing device performs digital certificate authentication with the terminal based on the network access request sent by the terminal based on the second virtual local area network, and establishes a network connection with the terminal after successful authentication.
3. The method as described in claim 1, characterized in that, In response to a network access request sent by the terminal based on a first virtual local area network, the routing device sends the URL of the server to the terminal, including: After receiving a DNS resolution request sent by the terminal based on the first virtual local area network, the proxy domain name system (DNS) service in the routing device sends a DNS resolution response to the terminal, and the DNS resolution response carries the IP address of the proxy web service. The proxy web service in the routing device receives a network access request sent by the terminal based on the IP address of the proxy web service and the first virtual LAN, and sends a redirect message carrying the URL of the server to the terminal. The server enables the terminal to obtain a digital certificate for accessing the second virtual LAN.
4. The method as described in claim 1, characterized in that, In response to a network access request sent by the terminal based on a first virtual local area network, the routing device sends the URL of the server to the terminal, including: After receiving the DNS resolution request sent by the terminal based on the first virtual LAN, the proxy DNS service in the routing device sends a redirection message carrying the URL of the server to the terminal, and the server enables the terminal to obtain a digital certificate for accessing the second virtual LAN.
5. The method according to any one of claims 1-4, characterized in that, The routing device is configured with a first service set identifier and a second service set identifier. The first service set identifier is used to identify the first virtual local area network (VLAN), and the second service set identifier is used to identify the second VLAN.
6. A routing device, characterized in that, include: The receiving module is configured to receive network access requests sent by a terminal based on a first virtual local area network (VLAN). The routing device has a first VLAN and a second VLAN pre-configured. The first VLAN is associated with a Uniform Resource Locator (URL) of a server, enabling the terminal to obtain a digital certificate for accessing the second VLAN through the server. The processing module is configured to respond to a network access request initiated by the terminal based on a first virtual local area network by sending the URL of the server to the terminal, so that the terminal obtains a digital certificate from the server based on the URL. For any domain name network access request sent by the terminal, the URL of the server associated with the first virtual local area network will be fed back to the terminal as a response.
7. The routing device as described in claim 6, characterized in that: The receiving module is also configured to receive network access requests sent by the terminal based on the second virtual local area network; The processing module is further configured to perform digital certificate authentication with the terminal based on the network access request sent by the terminal based on the second virtual local area network, and establish a network connection with the terminal after successful authentication.
8. The routing device as described in claim 6, characterized in that, The processing module includes a proxy domain name system DNS service module and a proxy web service module; The proxy DNS service module is configured to send a DNS resolution response to the terminal after receiving a DNS resolution request sent by the terminal based on the first virtual local area network. The DNS resolution response carries the IP address of the proxy WEB service. The proxy web service module is configured to receive a network access request sent by the terminal based on the IP address of the proxy web service and the first virtual LAN, and send a redirect message carrying the URL of the server to the terminal, wherein the server enables the terminal to obtain a digital certificate for accessing the second virtual LAN.
9. The routing device as described in claim 6, characterized in that, The processing module includes a proxy DNS service module; The proxy DNS service module is configured to, upon receiving a DNS resolution request sent by the terminal based on the first virtual LAN, send a redirection message carrying the URL of the server to the terminal, thereby enabling the terminal to obtain a digital certificate for accessing the second virtual LAN.
10. The routing device as described in any one of claims 6-9, characterized in that, The routing device is configured with a first service set identifier and a second service set identifier. The first service set identifier is used to identify the first virtual local area network (VLAN), and the second service set identifier is used to identify the second VLAN.
11. A routing device, characterized in that, Includes processor, memory, and communication interface; The communication interface receives and sends data under the control of the processor; The memory stores computer instructions; The processor is configured to read the computer instructions and execute the method as described in any one of claims 1-5.
12. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions for causing the computer to perform the method as described in any one of claims 1-5.
Citation Information
Patent Citations
Network access control method and equipment
CN104767715A
Method, apparatus, and system for redirection
CN105991589A