An access management method, authentication point and authentication server

By working together with authentication points and authentication servers, changes to temporary IPv6 addresses are detected and updated in real time. By using an extended message format, the problem of service interruption caused by changes to temporary IPv6 addresses is solved, ensuring the continuity of network services.

CN114173340BActive Publication Date: 2025-11-07HUAWEI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202011027414.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-08-20
Filing Date
2020-09-25
Publication Date
2025-11-07
Estimated Expiration
2040-09-25

AI Technical Summary

Technical Problem

When a temporary IPv6 address changes, the network side cannot effectively control the access and configuration authorization policies of terminal devices, leading to service interruption.

Method used

By working together between authentication points and authentication servers, changes in temporary IPv6 addresses of terminal devices are detected and updated in real time. An extended message format is used to carry indication information to ensure that the authentication server configures authorization policies in a timely manner and avoids business interruption.

Benefits of technology

It ensures the continuity of terminal device services during temporary IPv6 address changes, reducing the risk of network interruption caused by address changes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114173340B_ABST
    Figure CN114173340B_ABST
Patent Text Reader

Abstract

The application discloses an access management method, an authentication point and an authentication server, and is applied to a terminal device access network (for example, a park network) scene. After the terminal device completes authentication, the terminal device sends a first message to the authentication point, and the first message carries a first IPv6 address of the terminal device and a MAC address of the terminal device. When it is determined that the first IPv6 address is a new IPv6 address, the authentication point sends a second message carrying the first IPv6 address and the MAC address to the authentication server, so as to instruct the authentication server to send a first authorization policy to a policy execution point according to the first IPv6 address. Since the authentication point can send the new IPv6 address to the authentication server, so that the authentication server formulates the first authorization policy for accessing the network based on the first IPv6 address. Therefore, service messages of the terminal device can be transmitted to an address or a network segment which allows the user to access through the policy execution point. Therefore, even if the IPv6 address of the terminal device changes, the service can be ensured to be as uninterrupted as possible.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims priority from the Chinese patent application No. 202010842714.2 filed on August 20, 2020, and entitled "A method for temporary IPv6 address tracing and policy linkage for park scene", the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD

[0002] Embodiments of the present application relate to the field of data communication, and in particular to an access management method, an authentication point and an authentication server. BACKGROUND

[0003] A global unicast address (GUA) is a unicast address defined in the Internet Protocol version 6 (IPv6) protocol to uniquely identify a user of an access network. When a terminal uses a stable IPv6 GUA to access an Internet application, there is a risk of targeted eavesdropping, which causes a network security risk. Therefore, a temporary IPv6 GUA (hereinafter referred to as a temporary IPv6 address) is defined. When a user uses a temporary IPv6 address to access a network, the temporary IPv6 address will change over time, realizing the unpredictability of the user address. Although the use of a temporary IPv6 address by a terminal device improves the privacy of communication, it also brings new problems for operation and management. For example, the change of the temporary IPv6 address will cause the network side to be unable to control the terminal device to access the network or configure an authorized policy for the terminal device based on the updated temporary IPv6 address, thus causing the terminal device to interrupt the access to a service application.

[0004] Therefore, it is an urgent problem to seek a solution that can ensure the service as much as possible without interruption in the case of a change in the temporary IPv6 address. SUMMARY

[0005] Embodiments of the present application provide an access management method, an authentication point (authenticator) and an authentication server, which are used to effectively reduce the possibility of service interruption of a terminal device in the case of a change in a temporary IPv6 address, and to ensure the normal operation of the service as much as possible.

[0006] In a first aspect, an access management method is provided, which is applied to a terminal device accessing a network (e.g., a campus network). In the method, the terminal device first performs an access authentication, which can be based on an 802. lx protocol or a Portal protocol. Then, an authentication point receives a first packet from the terminal device, which carries a first IPv6 address of the terminal device and a MAC address of the terminal device. The first IPv6 address is a new temporary IPv6 address of the terminal device, or can be understood as a newly generated temporary IPv6 address of the terminal device. Then, when the authentication point determines that the first IPv6 address is a new IPv6 address, the authentication point sends a second packet to an authentication server, which carries the first IPv6 address and the MAC address, so that the authentication server sends a first authorization policy to a policy enforcement point according to the first IPv6 address. The first authorization policy is an authorization policy related to the first IPv6 address.

[0007] It should be understood that the first packet can be sent by the terminal device directly to the authentication point, or can be sent by the authentication point to an access point, and then sent by the access point to the authentication point. In an optional embodiment, the access point is a Layer 2 switch. In an optional embodiment, the authentication point is a switch, a router or a firewall. In an optional embodiment, the policy enforcement point is a switch, a router or a firewall. In an optional embodiment, the policy enforcement point is the authentication point, or can be understood as that the authentication point and the policy enforcement point are the same device.

[0008] When the authentication point receives the first packet carrying the first IPv6 address and the MAC address from the terminal device, the authentication point sends the first IPv6 address and the MAC address to the authentication server when it is determined that the first IPv6 address is a new IPv6 address. Then, the authentication server determines the first authorization policy sent to the policy enforcement point (e.g., a gateway) based on the first IPv6 address. Since the first authorization policy sent by the authentication server is determined based on the first IPv6 address (i.e., a new IPv6 address), when the policy enforcement point receives the first authorization policy, the service packet from the first IPv6 address of the terminal device (or can be understood as that the source address of the first packet is the first IPv6 address) can be transmitted by the policy enforcement point to the address or network segment that is allowed to be accessed by the user using the terminal device. Therefore, even if the IPv6 address of the terminal device changes, the service will not be interrupted.

[0009] In an alternative embodiment, the authentication point does not store the correspondence between the MAC address and the first IPv6 address before receiving the first packet. It can also be understood that the authentication point determines the first IPv6 address as a new IPv6 address when the authentication point determines that the authentication point does not store the correspondence between the MAC address and the first IPv6 address after receiving the first packet.

[0010] In an alternative embodiment, the authentication point determines the first IPv6 address as a new IPv6 address when the authentication point has stored the MAC address carried by the first packet and the first IPv6 address does not correspond to the IPv6 address corresponding to the MAC address in the authentication point after receiving the first packet.

[0011] In an alternative embodiment, the authentication point determines the first IPv6 address as a new IPv6 address when the authentication point has stored the MAC address carried by the first packet and the first IPv6 address does not exist in the authentication point after receiving the first packet.

[0012] It should be understood that the authentication point will immediately trigger the operation of sending the second packet to the authentication server when the authentication point determines that the first IPv6 address is a new IPv6 address. Therefore, it can be understood that the aforementioned second packet is triggered in real time, rather than periodically. That is, each time the aforementioned authentication point receives an IPv6 address and determines that the IPv6 address is a new IPv6 address, the authentication point will trigger the aforementioned second packet to send the new IPv6 address and the MAC address corresponding to the new IPv6 address to the authentication server through the aforementioned second packet.

[0013] In an alternative embodiment, the authentication point will also store the correspondence between the MAC address and the first IPv6 address after receiving the first packet. It can also be understood that the authentication point stores the aforementioned MAC address and the first IPv6 address in the aforementioned authentication point. After storage, the authentication point can query one or more IPv6 addresses (for example, the aforementioned first IPv6 address) corresponding to the MAC address according to the MAC address. Of course, the authentication point can also query the MAC address according to the first IPv6 address.

[0014] In an optional implementation, before receiving the first packet, the authentication point stores a correspondence between the MAC address and at least one IPv6 address, each of the at least one IPv6 address corresponding to the MAC address. Thus, when the authentication point finds the at least one IPv6 address corresponding to the MAC address and the first IPv6 address is not included in the at least one IPv6 address, the authentication point can determine that the first IPv6 address is a new IPv6 address. In addition, the at least one IPv6 address is an IPv6 address that the terminal device is using or has used before sending the first packet. For example, the terminal device registers authentication in the authentication server by using IPv6 address A, and the terminal device can send service packets by using IPv6 address A. Then, the terminal device generates IPv6 address B and sends service packets by using IPv6 address B, and then the terminal device generates IPv6 address C and sends the first packet to the authentication point by carrying IPv6 address C. The at least one IPv6 address stored in the authentication point can be understood as IPv6 address A and IPv6 address B in the example, and the first IPv6 address can be understood as IPv6 address C in the example.

[0015] In an optional implementation, the authentication point stores a first correspondence table including the correspondence between the MAC address and the first IPv6 address, and the first correspondence table can be understood as being used to store the correspondence between the MAC address and the first IPv6 address.

[0016] In the embodiment, the authentication point is provided with a table capable of storing the correspondence between the MAC address and the first IPv6 address. The authentication point can also be understood as storing the correspondence between the MAC address and the first IPv6 address in the first correspondence table.

[0017] In an optional implementation, the authentication point stores a first correspondence table including the correspondence between the MAC address and the at least one IPv6 address, and the first correspondence table can be understood as being used to store the correspondence between the MAC address and the at least one IPv6 address.

[0018] In this embodiment, after receiving the first packet, the authentication point queries the first correspondence table. If the MAC address carried by the first packet is stored in the first correspondence table, and the first IPv6 address does not correspond to the MAC address in the first correspondence table, the authentication point determines that the first IPv6 address is a new IPv6 address. Alternatively, after receiving the first packet, the authentication point queries the first correspondence table. If the MAC address carried by the first packet is already stored in the first correspondence table, and the first IPv6 address does not exist in the first correspondence table, the authentication point determines that the first IPv6 address is a new IPv6 address.

[0019] In an optional embodiment, before receiving the first packet, the authentication point stores a correspondence between the MAC address and user information. The user information is information of a user corresponding to the MAC address.

[0020] It should be understood that the user is a user of the terminal device, the user has a user account, and the user account is logged in the terminal device, so that the user transmits or receives service packets through the terminal device. It can also be understood that the terminal device is a carrier for the user to transmit service packets, and the user can access the network and obtain the service function required by the user through the terminal device. The user information is information related to the user, such as user identification, user state information, or other information related to the user.

[0021] In this embodiment, the authentication point not only stores the correspondence between the MAC address and the first IPv6 address, but also stores the correspondence between the MAC address and the user information. Therefore, the user information can be queried through the MAC address based on the first IPv6 address.

[0022] In an optional embodiment, the authentication point stores a second correspondence table, and the second correspondence table includes the correspondence between the MAC address and the user information. It can also be understood that the second correspondence table is used to store the correspondence between the MAC address and the user information.

[0023] In the embodiment, the first correspondence table stores the correspondence between the MAC address and the first IPv6 address, and the second correspondence table also stores the correspondence between the MAC address and the user information. That is, the user information and the first IPv6 address are stored in different tables in the authentication point. However, since the first correspondence table and the second correspondence table both store the MAC address, the user information and the first IPv6 address are also associated. That is, the authentication point can query the first correspondence table and the second correspondence table based on the first IPv6 address to obtain the user information of the user corresponding to the first IPv6 address.

[0024] In an optional embodiment, the second correspondence table further includes the correspondence between the MAC address and the first IPv6 address. It can also be understood that the second correspondence table includes the content in the first correspondence table (for example, the MAC address and the first IPv6 address; for example, the MAC address and one or more IPv6 addresses corresponding to the MAC address). It can also be understood that the first correspondence table and the second correspondence table are the same table.

[0025] In an optional embodiment, the user information includes a user identifier. The user identifier is used to uniquely identify a user. For example, the user identifier can be a user identity number, a user name, or other information capable of uniquely identifying a user.

[0026] In an optional embodiment, the user information includes user state information. The user state information is used to indicate the state of the user, for example, the user is in an online state (or online state) or the user is in an offline state (or offline state). In an example, the user state can be an indication of successful identity authentication, at which time the user can also be implicitly online.

[0027] In an optional embodiment, before sending the second packet, the method further includes: the authentication point determining that the user corresponding to the first IPv6 address is in an online state. Specifically, the authentication point can query the table (for example, the second correspondence table) in which the user state information is stored, and determine whether the user is in an online state or an offline state according to the user state information.

[0028] In an optional embodiment, before the authentication point determines that the user is online, the authentication point further determines the user identifier of the user corresponding to the MAC address according to the MAC address, and then determines the user state information according to the user identifier. It can be understood that the authentication point first finds the user identifier in the table (for example, the second correspondence table) in which the user state information is stored by using the MAC address, and then determines the user state information of the user according to the user identifier.

[0029] In an alternative embodiment, before determining that the user is online, the authentication point further determines user status information corresponding to the MAC address according to the MAC address. It can be understood that the aforementioned user status information is directly associated with the MAC address, and the authentication point can find the user status information of the user in the table (for example, the aforementioned second correspondence table) storing the user status information through the MAC address.

[0030] In an alternative embodiment, the first correspondence table is a neighbor discovery table or a neighbor discovery probe table. The neighbor discovery table or the neighbor discovery probe table is a table related to a neighbor discovery protocol (NDP), and the authentication point can generate the aforementioned table related to the neighbor discovery protocol (NDP) (for example, the neighbor discovery table or the neighbor discovery probe table) after receiving a message based on the neighbor discovery protocol (NDP). The authentication point can use the neighbor discovery table or the neighbor discovery probe table to store the address information and the like that the first correspondence table in the aforementioned embodiment can store.

[0031] In an alternative embodiment, the second correspondence table is a neighbor discovery table or a neighbor discovery probe table.

[0032] In an alternative embodiment, the second message is used to indicate that the first IPv6 address is a new IPv6 address.

[0033] In the embodiment, the second message is a newly defined message, and the second message can not only carry an IPv6 address and a MAC address, but also indicate that the first IPv6 address is a new IPv6 address. That is, a message for transmitting a new IPv6 address between the authentication point and the authentication server is newly defined, and when the authentication server receives the aforementioned second message, it can be known that the IPv6 address carried in the second message is a new IPv6 address. In this implementation, the authentication server does not need to determine whether the first IPv6 address is a new IPv6 address according to the information stored in the authentication server.

[0034] In an alternative embodiment, the second message includes first indication information, and the first indication information is used to indicate that the first IPv6 address is a new IPv6 address.

[0035] In this embodiment, the second message extends a field, which is used to indicate that the IPv6 address carried in the second message is a new IPv6 address. The field is first indication information, which is used to indicate that the IPv6 address carried in the second message is a new IPv6 address. In this implementation, when the authentication server receives the second message, it can know that the IPv6 address carried in the second message is a new IPv6 address, without the need to determine whether the first IPv6 address is a new IPv6 address according to the information stored in the authentication server.

[0036] In an optional implementation, the first indication information is also used to indicate that the authentication server determines the first authorization policy according to the first IPv6 address.

[0037] In this embodiment, the second message extends a field (i.e. first indication information), which is used to indicate that the IPv6 address carried in the second message is a new IPv6 address, and is also used to indicate that the authentication server determines the authorization policy (e.g. the first authorization policy) according to the IPv6 address (e.g. the first IPv6 address) carried in the second message.

[0038] In an optional implementation, the first authorization policy includes the access right of the terminal device corresponding to the first IPv6 address. The access right of the terminal device is determined by the access right of a user, and the access right of the user is stored in the authentication server. When determining the first authorization policy, the authentication server can find the access right of the user according to the MAC address and / or the first IPv6 address, and configure the first authorization policy by taking the access right of the user as the access right of the terminal device.

[0039] In an optional implementation, the second message is not an authentication request message. Since the access management method is implemented after the terminal device completes authentication, the second message is not a message involved in the authentication process.

[0040] In an optional implementation, the second message is a charging message.

[0041] In the embodiment, if the authentication server is a server based on a remote authentication dial in user service (Radius) protocol (hereinafter referred to as a Radius server), the second message is a message based on the Radius protocol (hereinafter referred to as a Radius message), that is, the second message can reuse the format of the Radius message. Since the Radius message has a charging function, and if the network accessed by the terminal device needs to be charged, the second message can reuse the format of a Radius charging message (hereinafter referred to as a charging message). At this time, the second message is a charging message, and the second message has a charging function in addition to carrying the IPv6 address and the MAC address, and can trigger the authentication server to perform real-time charging. It should be noted that the charging message in the prior art is periodically sent. The charging message in the embodiment can be sent immediately after the first IPv6 address is determined at the authentication point, and it can also be understood that the charging message in the embodiment is sent in real time. Therefore, it is beneficial to synchronize the newly generated IPv6 address (for example, the first IPv6 address) of the terminal device between the authentication point and the authentication server, and further to enable the authentication server to configure the authorization policy (for example, the first authorization policy) based on the newly generated IPv6 address (for example, the first IPv6 address) of the terminal device in a short time, and further to avoid the service message transmitted by the terminal device using the first IPv6 address from being affected to cause service interruption.

[0042] It should also be understood that the MAC address and the first IPv6 address are carried in a content field (i.e., a payload field) in the second message.

[0043] In an optional embodiment, the first message is a neighbor solicitation (NS) message.

[0044] The neighbor solicitation (NS) message is a message defined by a neighbor discovery protocol (NDP) to implement address resolution, track neighbor status, duplicate address detection, router discovery, and redirection functions using an internet control management protocol version 6 (ICMPv6) message.

[0045] It should also be understood that the MAC address and the first IPv6 address are carried in a content field (i.e., a payload field) in the first message.

[0046] In an alternative implementation, the method further comprises: when a second IPv6 address of the plurality of IPv6 addresses of the terminal device is invalid, the authentication point sends a third message to the authentication server, wherein the third message comprises the second IPv6 address and second indication information, and the second indication information is used to indicate that the second IPv6 address is an invalid IPv6 address.

[0047] Compared with the prior art, the present implementation extends a field used to indicate an invalid IPv6 address. When the authentication server receives the first message, it can know that the first message carries an invalid IPv6 address, and thus can prompt the authentication server to revoke the authorization policy corresponding to the invalid IPv6 address.

[0048] In an alternative implementation, the second indication information is further used to indicate that the authentication server revokes the authorization policy corresponding to the second IPv6 address.

[0049] In an alternative implementation, before the third message is sent to the authentication server, the method further comprises: the authentication point sends a first probe message, and a destination address of the first probe message is the second IPv6 address; and in response to not receiving a first response message from the second IPv6 address in response to the first probe message, the authentication point determines that the second IPv6 address is invalid. The first response message from the second IPv6 address can also be understood as that a source address of the first response message is the second IPv6 address.

[0050] In an alternative implementation, the method further comprises: the authentication point determines that a third IPv6 address of the plurality of IPv6 addresses of the terminal device is invalid, and the third IPv6 address is the last used IPv6 address of the terminal device; and the authentication point sends a fourth message to the authentication server, and the fourth message comprises third indication information, and the third indication information is used to indicate that the third IPv6 address corresponds to a user of the terminal device being offline.

[0051] The last used IPv6 address of the terminal device can also be understood as the currently used IPv6 address of the terminal device. For example, the authentication point stores information such as generation time, preferred period, and valid period of each IPv6 address, and the authentication point can determine which IPv6 address of the plurality of IPv6 addresses corresponding to the terminal device is the last used IPv6 address of the terminal device according to the information.

[0052] In the present implementation, since a terminal device has a plurality of IPv6 addresses, a user logged in the terminal device also has a plurality of IPv6 addresses. The authentication point determines whether the user is offline by probing the last used IPv6 address of the terminal device. In such an implementation, the number of probe messages sent by the authentication point can be saved.

[0053] In an optional implementation, the third indication information is further used to instruct the authentication server to revoke the authorization policy corresponding to all IPv6 addresses of the user.

[0054] In the embodiment, since one user can correspond to multiple IPv6 addresses and each IPv6 address corresponds to one authorization policy, one user has multiple authorization policies. Therefore, when the user is offline, the authorization policies corresponding to all IPv6 addresses of the user need to be revoked. In the prior art, one user has only one authorization policy corresponding to one IPv6 address, and only the authorization policy corresponding to the IPv6 address needs to be revoked.

[0055] In an optional implementation, the fourth message includes at least one of the following: a user identifier corresponding to the third IPv6 address; or a MAC address corresponding to the third IPv6 address; or all IPv6 addresses of the user corresponding to the third IPv6 address.

[0056] In an optional implementation, before the fourth message is sent to the authentication server, the authentication point determines that the third IPv6 address of the multiple IPv6 addresses of the terminal device is invalid, which can be implemented in the following manner: the authentication point sends a second probe message, wherein the destination address of the second probe message is the third IPv6 address; in response to the fact that no second response message from the third IPv6 address is received in response to the second probe message, it is determined that the third IPv6 address is invalid. The second response message from the third IPv6 address can also be understood as that the source address of the second response message is the third IPv6 address.

[0057] It should be understood that since the third IPv6 address is the last IPv6 address used by the terminal device, when the third IPv6 address is invalid, it can be inferred that other IPv6 addresses corresponding to the terminal device are also invalid, and therefore the authentication point can determine that the user corresponding to the third IPv6 address is offline.

[0058] In the embodiment, the last IPv6 address used by the terminal device is probed to determine whether the user is offline, and the number of probe messages sent by the authentication point can be saved.

[0059] In an optional implementation, the policy enforcement point is the authentication point, which can also be understood as that the aforementioned authentication point and the aforementioned policy enforcement point are the same device.

[0060] In an alternative implementation, before the receiving the first message sent by the terminal device, the method further comprises: receiving, by the authentication point, a fifth message carrying a fourth IPv6 address of the terminal device and the MAC address; and sending, by the authentication point, a sixth message carrying the fourth IPv6 address and the MAC address to the authentication server, the sixth message being used to instruct the authentication server to send a second authorization policy to the policy enforcement point according to the fourth IPv6 address.

[0061] In an alternative implementation, the sixth message is an authentication request message.

[0062] In an alternative implementation, the second authorization policy comprises access rights of the terminal device corresponding to the fourth IPv6 address.

[0063] In an alternative implementation, the first authorization policy comprises access rights of the terminal device corresponding to the first IPv6 address.

[0064] In an alternative implementation, the first authorization policy comprises access rights of the terminal device corresponding to the first IPv6 address, wherein the access rights of the terminal device corresponding to the fourth IPv6 address are the same as the access rights of the terminal device corresponding to the first IPv6 address.

[0065] In the implementation, the user corresponding to the terminal device is still logged in on the terminal device and has not been logged out, and only a new temporary IPv6 address is generated by the terminal device for the user. That is, the user on the terminal device has not changed, and only the user has a new temporary IPv6 address. Therefore, the behavior of the terminal device still reflects the behavior of the user logged in on the terminal device, and the access rights of the terminal device corresponding to the fourth IPv6 address are the same as the access rights of the terminal device corresponding to the first IPv6 address.

[0066] In a second aspect, an access management method is provided, which is performed by an authentication server and comprises: receiving, by the authentication server, a first message from an authentication point after a terminal device completes access authentication, the first message comprising a first IPv6 address of the terminal device and a MAC address of the terminal device, the first IPv6 address being a new temporary IPv6 address of the terminal device; determining, by the authentication server, that the first IPv6 address is a new IPv6 address according to the MAC address; and sending, by the authentication server, a first authorization policy corresponding to the first IPv6 address to a policy enforcement point, the first authorization policy comprising access rights of the terminal device corresponding to the first IPv6 address.

[0067] In an alternative embodiment, the authentication point is a switch, a router or a firewall. In an alternative embodiment, the policy enforcement point is a switch, a router or a firewall. In an alternative embodiment, the policy enforcement point is the authentication point. It is also understood that the authentication point and the policy enforcement point are the same device.

[0068] Since the authentication point sends the newly generated IPv6 address (i.e. the first IPv6 address) and the MAC address of the terminal device to the authentication server. The authentication server determines the first authorization policy sent to the policy enforcement point (i.e. the gateway) based on the first IPv6 address. Since the first authorization policy sent by the authentication server is determined based on the first IPv6 address (i.e. the new IPv6 address). Therefore, when the policy enforcement point receives the first authorization policy, the traffic message from the first IPv6 address of the terminal device (i.e. the source address of the first message is the first IPv6 address) can be transmitted through the policy enforcement point to the address or network segment accessible to the user using the terminal device. Therefore, even if the IPv6 address of the terminal device changes, the service will not be interrupted.

[0069] In an alternative embodiment, the authentication server does not store the correspondence between the MAC address and the first IPv6 address before receiving the first message. It is also understood that the authentication server determines that the first IPv6 address is a new IPv6 address when the authentication server determines that the authentication point does not store the correspondence between the MAC address and the first IPv6 address after receiving the first message.

[0070] In an alternative embodiment, the authentication server determines that the first IPv6 address is a new IPv6 address when the authentication server has stored the MAC address carried by the first message and the first IPv6 address does not correspond to the MAC address in the authentication server after receiving the first message.

[0071] In an alternative embodiment, the authentication server determines that the first IPv6 address is a new IPv6 address when the authentication server has stored the MAC address carried by the first message and the first IPv6 address does not exist in the authentication server after receiving the first message.

[0072] In an alternative embodiment, after receiving the first packet, the method further comprises storing the correspondence between the MAC address and the first IPv6 address. It can also be understood that the authentication server stores the correspondence between the MAC address and the first IPv6 address in the authentication server. After storing, the authentication server can query one or more IPv6 addresses (e.g., the first IPv6 address) corresponding to the MAC address according to the MAC address. Of course, the authentication server can also query the MAC address according to the first IPv6 address.

[0073] In an alternative embodiment, before receiving the first packet, the authentication server stores the correspondence between the MAC address and at least one IPv6 address, wherein each of the at least one IPv6 address corresponds to the MAC address. Thus, when the authentication server finds at least one IPv6 address corresponding to the MAC address and the first IPv6 address is not included in the at least one IPv6 address, the authentication server can determine that the first IPv6 address is a new IPv6 address. In addition, the at least one IPv6 address is an IPv6 address that the terminal device is using or has used before sending the first packet.

[0074] In an alternative embodiment, the authentication server stores a first correspondence table for storing the correspondence between the MAC address and the first IPv6 address. It can also be understood that the first correspondence table includes the correspondence between the MAC address and the first IPv6 address.

[0075] In an alternative embodiment, the authentication server stores a first correspondence table for storing the correspondence between the MAC address and at least one IPv6 address. It can also be understood that the first correspondence table includes the correspondence between the MAC address and at least one IPv6 address.

[0076] In this embodiment, after receiving the first packet, the authentication server queries the first correspondence table. When the first correspondence table stores the MAC address carried by the first packet, and the first IPv6 address does not correspond to the MAC address in the first correspondence table, the authentication server determines that the first IPv6 address is a new IPv6 address. Alternatively, after receiving the first packet, the authentication server queries the first correspondence table. When the first correspondence table has stored the MAC address carried by the first packet, and the first correspondence table does not store the first IPv6 address, the authentication server determines that the first IPv6 address is a new IPv6 address.

[0077] In an optional implementation, the authentication server stores the correspondence between the MAC address and the user information before receiving the first packet. The user information is information of a user corresponding to the MAC address.

[0078] It should be understood that the user is a user of the terminal device, the user has a user account, and the user account is logged in the terminal device, so that the user sends or receives service packets through the terminal device. It can also be understood that the terminal device is a carrier for the user to transmit service packets, and the user can access the network and obtain the service function required by the user through the terminal device. The user information is information related to the user, such as user identification, user state information, and other information related to the user.

[0079] In an optional implementation, the authentication server stores a second correspondence table for storing the correspondence between the MAC address and the user information. It can also be understood that the second correspondence table includes the correspondence between the MAC address and the user information.

[0080] In the embodiment, if the first correspondence table stores the correspondence between the MAC address and the first IPv6 address, and the second correspondence table also stores the correspondence between the MAC address and the user information. That is, the user information and the first IPv6 address are stored in different tables in the authentication point. However, since the first correspondence table and the second correspondence table both store the MAC address, the user information and the first IPv6 address are also associated. That is, the authentication server can query the first correspondence table and the second correspondence table based on the first IPv6 address to obtain the user information of the user corresponding to the first IPv6 address.

[0081] In an optional implementation, the second correspondence table further includes the correspondence between the MAC address and the first IPv6 address. It can also be understood that the second correspondence table includes the contents in the first correspondence table (for example, the MAC address and the first IPv6 address; for example, the MAC address and one or more IPv6 addresses corresponding to the MAC address). It can also be understood that the first correspondence table and the second correspondence table are the same table.

[0082] In an optional implementation, the user information includes user identification.

[0083] In an optional implementation, the user information includes the access right of the user.

[0084] In an alternative embodiment, the authentication server stores a second correspondence table for storing the correspondence between the user identifier and the access right.

[0085] In an alternative embodiment, the authentication server stores a second correspondence table for storing the correspondence between the user identifier and the access right.

[0086] In an alternative embodiment, the user information comprises user state information.

[0087] In an alternative embodiment, before the authentication server sends the first authorization policy corresponding to the first IPv6 address to the policy enforcement point after determining that the first IPv6 address is a new IPv6 address according to the MAC address, the authentication server further determines that the user corresponding to the first IPv6 address is in an online state. Specifically, the authentication server can query the aforementioned table storing user state information (e.g., the aforementioned second correspondence table) to determine whether the user is in an online state or an offline state according to the user state information.

[0088] In an alternative embodiment, before the authentication server determines that the user is online, the authentication server further determines the user identifier of the user corresponding to the MAC address according to the MAC address, and then determines the user state information according to the user identifier. It can be understood that the authentication server first finds the user identifier in the table storing user state information (e.g., the aforementioned second correspondence table) according to the MAC address, and then determines the user state information of the user according to the user identifier.

[0089] In an alternative embodiment, before the authentication server determines that the user is online, the authentication server further determines the user state information corresponding to the MAC address according to the MAC address. It can be understood that the aforementioned user state information is directly associated with the MAC address, and the authentication server can find the user state information of the user in the table storing user state information (e.g., the aforementioned second correspondence table) according to the MAC address.

[0090] In an alternative embodiment, the first correspondence table is a neighbor discovery table or a neighbor discovery probe table. Both the neighbor discovery table and the neighbor discovery probe table are tables related to a neighbor discovery protocol (NDP), and the authentication server can generate the aforementioned table related to the neighbor discovery protocol (e.g., the neighbor discovery table or the neighbor discovery probe table) after receiving a message based on the neighbor discovery protocol (NDP). The authentication server can use the neighbor discovery table or the neighbor discovery probe table to store the address information and other information that the first correspondence table in the aforementioned embodiments can store.

[0091] In an optional implementation, the second correspondence table is a neighbor discovery table or a neighbor discovery probe table.

[0092] In an optional implementation, the determining the first authorization policy corresponding to the first IPv6 address comprises: determining access right of a user corresponding to the first IPv6 address according to the MAC address; and determining the first authorization policy according to the first IPv6 address and the access right.

[0093] In an optional implementation, the determining the first authorization policy corresponding to the first IPv6 address comprises: determining a user identity of a user corresponding to the first IPv6 address according to the MAC address by an authentication server; determining access right of the user according to the user identity by the authentication server; and determining the first authorization policy according to the first IPv6 address and the access right by the authentication server.

[0094] In an optional implementation, the first message is used to indicate that the first IPv6 address is a new IPv6 address.

[0095] In the embodiment, the first message is a newly defined message, the first message can carry not only an IPv6 address and a MAC address, but also indicate that the first IPv6 address is a new IPv6 address. That is, a message for transmitting a new IPv6 address between an authentication point and an authentication server is newly defined, and when the authentication server receives the first message, it can know that the IPv6 address carried in the first message is a new IPv6 address. In this implementation, the authentication server does not need to determine whether the first IPv6 address is a new IPv6 address according to information stored in the authentication server.

[0096] In an optional implementation, the first message comprises first indication information, and the first indication information is used to indicate that the first IPv6 address is a new IPv6 address.

[0097] In the embodiment, the first message is extended with a field for indicating that the IPv6 address carried in the first message is a new IPv6 address. The field is first indication information, and the first indication information is used to indicate that the IPv6 address carried in the first message is a new IPv6 address. In this implementation, when the authentication server receives the first message, it can know that the IPv6 address carried in the first message is a new IPv6 address, without the need to determine whether the first IPv6 address is a new IPv6 address according to information stored in the authentication server.

[0098] In an alternative implementation, the first indication information is further used to instruct the authentication server to determine the first authorization policy according to the first IPv6 address.

[0099] In the embodiment, the first message is extended with a field (i.e. the first indication information). The first indication information is used to instruct the authentication server to determine the authorization policy (e.g. the first authorization policy) according to the IPv6 address (e.g. the first IPv6 address) carried in the first message, in addition to indicating that the IPv6 address carried in the first message is a new IPv6 address.

[0100] In an alternative implementation, the first message is not an authentication request message.

[0101] In an alternative implementation, the first message is a charging message. It should be appreciated that the aforementioned MAC address and the first IPv6 address are carried in a content field (i.e. a payload field) of the first message.

[0102] In an alternative implementation, the method further comprises: receiving, by the authentication server, a second message from the authentication point, the second message comprising a second IPv6 address and a second indication information, the second indication information being used to indicate that the second IPv6 address is a stale IPv6 address, the second IPv6 address being one of the plurality of IPv6 addresses of the terminal device; and sending, by the authentication server, a first revocation instruction to the policy enforcement point, the first revocation instruction being used to instruct the policy enforcement point to revoke an authorization policy corresponding to the second IPv6 address, the first revocation instruction comprising the second IPv6 address.

[0103] In the embodiment, the message sent by the authentication point to the authentication server is extended with a field (i.e. the second indication information). The second indication information is used to indicate that the IPv6 address (e.g. the aforementioned second IPv6 address) carried in the second message is a stale IPv6 address. Therefore, when the authentication server receives the aforementioned second message, the authentication server can decide to revoke the authorization policy corresponding to the second IPv6 address. Then, the authentication server will send a first revocation instruction to the policy enforcement point, so that the policy enforcement point deletes the authorization policy related to the second IPv6 address.

[0104] In an alternative implementation, the second indication information is further used to instruct the authentication server to revoke the authorization policy corresponding to the second IPv6 address.

[0105] In an alternative implementation, the method further comprises: receiving, by the authentication server, a third message from the authentication point, the third message comprising third indication information, the third indication information being used to indicate that a user corresponding to a third IPv6 address is offline, the third IPv6 address being a last used IPv6 address of the terminal device; and sending, by the authentication server, a second revocation indication to the policy enforcement point, the second revocation indication being used to instruct the policy enforcement point to revoke authorization policies corresponding to all IPv6 addresses of the user corresponding to the third IPv6 address.

[0106] In the present implementation, a field (i.e. the third indication information) is added in the message sent by the authentication point to the authentication server, and the third indication information is used to indicate that the IPv6 address (e.g. the third IPv6 address) carried in the third message is an invalid IPv6 address. Since the third IPv6 address is the last used IPv6 address of the terminal device, when the authentication server receives the third message, the authentication server can determine that the user corresponding to the third IPv6 address is offline. Therefore, the authentication server can decide to revoke the authorization policies corresponding to the user, i.e. the authorization policies corresponding to all IPv6 addresses of the user. Then, the authentication server sends a second revocation indication to the policy enforcement point, so that the policy enforcement point deletes the authorization policies related to all IPv6 addresses of the user.

[0107] In an alternative implementation, the third indication information is further used to instruct the authentication server to revoke the authorization policies corresponding to all IPv6 addresses of the user corresponding to the third IPv6 address.

[0108] In an alternative implementation, the third message comprises at least one of the following: a user identifier corresponding to the third IPv6 address; or a MAC address corresponding to the third IPv6 address; or all IPv6 addresses of the user corresponding to the third IPv6 address.

[0109] In an alternative implementation, the second revocation indication comprises all IPv6 addresses of the user corresponding to the third IPv6 address.

[0110] In an alternative implementation, the policy enforcement point is the authentication point.

[0111] In an optional implementation, before the authentication server receives the first message from the authentication point, the method further comprises: the authentication server receiving a fourth message from the authentication point, the fourth message comprising a fourth IPv6 address of the terminal device and the MAC address; determining, according to the MAC address, that the fourth IPv6 address is a new IPv6 address; and the authentication server sending, to the policy enforcement point, a second authorization policy corresponding to the fourth IPv6 address, the second authorization policy comprising access rights of the terminal device corresponding to the fourth IPv6 address.

[0112] In an optional implementation, the determining the second authorization policy corresponding to the fourth IPv6 address comprises: determining, according to the correspondence between the MAC address and the access rights of the user, the access rights of the user; and determining, according to the access rights of the user, the second authorization policy corresponding to the fourth IPv6 address.

[0113] In an optional implementation, the fourth message is an authentication request message.

[0114] It should be noted that the embodiments of the present application have a variety of other specific implementations, and specific implementations and advantages thereof can be referred to the specific implementations of the first aspect, which will not be described here.

[0115] In a third aspect, an access management method is provided, which is performed by an authentication point and comprises: determining, by the authentication point, that a first IPv6 address among a plurality of IPv6 addresses of a terminal device is invalid; and sending, by the authentication point, a first message to an authentication server, the first message comprising the first IPv6 address and first indication information, the first indication information being used to indicate that the first IPv6 address is an invalid IPv6 address.

[0116] In an optional implementation, the first indication information is further used to indicate that the authentication server revokes an authorization policy corresponding to the first IPv6 address.

[0117] In an optional implementation, the determining that the first IPv6 address among the plurality of IPv6 addresses of the terminal device is invalid comprises: sending, by the authentication point, a probe message, a destination address of the probe message being the first IPv6 address; and determining that the first IPv6 address is invalid in response to not receiving a response message from the first IPv6 address in response to the probe message.

[0118] In an optional implementation, the method further comprises: when a second IPv6 address among the plurality of IPv6 addresses is invalid, sending, by the authentication point, a second message to the authentication server, the first message comprising the second IPv6 address and second indication information, the second indication information being used to indicate that the second IPv6 address is an invalid IPv6 address.

[0119] It should be noted that the embodiments of the present application have a plurality of other specific implementation manners, and specific implementation manners and beneficial effects thereof can be referred to the specific implementation manners of the first aspect, which will not be described here.

[0120] In a fourth aspect, an access management method is provided, which is performed by an authentication server storing a correspondence between a plurality of IPv6 addresses of a terminal device, a MAC address of the terminal device, and access permissions of a user using the terminal device. The method comprises: receiving a first message from an authentication point, the first message comprising a first IPv6 address and first indication information, the first indication information being used to indicate that the first IPv6 address is an invalid IPv6 address; and sending a first revocation indication to a policy enforcement point, the first revocation indication carrying the first IPv6 address, the first revocation indication being used to instruct the policy enforcement point to revoke an authorization policy corresponding to the first IPv6 address.

[0121] In an optional implementation manner, the first indication information is further used to instruct the authentication server to revoke an authorization policy corresponding to the first IPv6 address.

[0122] In an optional implementation manner, the method further comprises: receiving a second message from the authentication point, the second message comprising a second IPv6 address and second indication information, the second indication information being used to indicate that the second IPv6 address is an invalid IPv6 address; and sending a second revocation indication to the policy enforcement point, the second revocation indication carrying the second IPv6 address, the second revocation indication being used to instruct the policy enforcement point to revoke an authorization policy corresponding to the second IPv6 address.

[0123] It should be noted that the embodiments of the present application have a plurality of other specific implementation manners, and specific implementation manners and beneficial effects thereof can be referred to the specific implementation manners of the second aspect, which will not be described here.

[0124] In a fifth aspect, an access management method is provided, which is performed by an authentication point. The method comprises: determining, by the authentication point, that a first IPv6 address of a plurality of IPv6 addresses of a terminal device is invalid, the first IPv6 address being a last used IPv6 address of the terminal device; and sending a first message to an authentication server, the first message comprising first indication information, the first indication information being used to indicate that a user using the terminal device corresponding to the first IPv6 address is offline.

[0125] In an optional implementation manner, the first indication information is further used to instruct the authentication server to revoke authorization policies corresponding to all IPv6 addresses corresponding to the user.

[0126] In an optional implementation, the first message comprises at least one of the following: a user identifier corresponding to the first IPv6 address; or a MAC address corresponding to the first IPv6 address; or all IPv6 addresses of the user corresponding to the first IPv6 address.

[0127] In an optional implementation, the determining that the first IPv6 address in the plurality of IPv6 addresses of the terminal device is invalid comprises: sending a probe message, the destination address of the probe message being the first IPv6 address; and in response to not receiving a response message from the first IPv6 address for the probe message, determining that the first IPv6 address is invalid.

[0128] It should be noted that the embodiments of the present application have a plurality of other specific implementations, and specific implementations and beneficial effects can be referred to the specific implementations of the first aspect and the beneficial effects, which will not be described here.

[0129] In a sixth aspect, an access management method is provided, executed by an authentication server, the authentication server storing a correspondence between a plurality of IPv6 addresses of a terminal device, a MAC address of the terminal device, and access permissions of a user using the terminal device, the method comprising: receiving a first message from an authentication point, the first message comprising first indication information, the first indication information being used to indicate that a user using a first IPv6 address logs off, the first IPv6 address being a last used IPv6 address of the terminal device; and sending a revocation indication to a policy execution point, the revocation indication being used to instruct the policy execution point to revoke an authorization policy corresponding to all IPv6 addresses of the user corresponding to the first IPv6 address.

[0130] In an optional implementation, the first indication information is further used to instruct the authentication server to revoke the authorization policy corresponding to all IPv6 addresses of the user corresponding to the first IPv6 address.

[0131] In an optional implementation, the first message comprises at least one of the following: a user identifier of the user corresponding to the first IPv6 address; or a MAC address corresponding to the first IPv6 address; or all IPv6 addresses of the user corresponding to the third IPv6 address.

[0132] In an optional implementation, the revocation indication comprises all IPv6 addresses of the user corresponding to the third IPv6 address.

[0133] It should be noted that the embodiments of the present application have a plurality of other specific implementations, and specific implementations and beneficial effects can be referred to the specific implementations of the second aspect and the beneficial effects, which will not be described here.

[0134] In a seventh aspect, an embodiment of the present application provides a communication apparatus, which can be the authentication point in the foregoing embodiments, or a chip in the authentication point. The communication apparatus can include a processing module and a transceiver module. When the communication apparatus is the authentication point, the processing module can be a processor, and the transceiver module can be a transceiver. The authentication point can further include a storage module, which can be a memory. The storage module is configured to store instructions, and the processing module executes the instructions stored in the storage module, so that the authentication point performs the method in the first aspect or any of the implementations of the first aspect, or the third aspect or any of the implementations of the third aspect, or the fifth aspect or any of the implementations of the fifth aspect. When the communication apparatus is a chip in the authentication point, the processing module can be a processor, and the transceiver module can be an input / output interface, a pin, a circuit, or the like. The processing module executes the instructions stored in the storage module, so that the authentication point performs the method in the first aspect or any of the implementations of the first aspect, or the third aspect or any of the implementations of the third aspect, or the fifth aspect or any of the implementations of the fifth aspect. The storage module can be a storage module (for example, a register, a cache, or the like) in the chip, or a storage module (for example, a read-only memory, a random access memory, or the like) in the authentication point and located outside the chip.

[0135] In an eighth aspect, an embodiment of the present application provides a communication apparatus, which can be the authentication server in the foregoing embodiments, or a chip in the authentication server. The communication apparatus can include a processing module and a transceiver module. When the communication apparatus is the authentication server, the processing module can be a processor, and the transceiver module can be a transceiver. The authentication server can further include a storage module, which can be a memory. The storage module is configured to store instructions, and the processing module executes the instructions stored in the storage module, so that the authentication server performs the method in the second aspect or any of the implementations of the second aspect, or performs the fourth aspect or any of the implementations of the fourth aspect, or performs the sixth aspect or any of the implementations of the sixth aspect. When the communication apparatus is a chip in the authentication server, the processing module can be a processor, and the transceiver module can be an input / output interface, a pin, a circuit, or the like. The processing module executes the instructions stored in the storage module, so that the authentication server performs the method in the second aspect or any of the implementations of the second aspect, or performs the fourth aspect or any of the implementations of the fourth aspect, or performs the sixth aspect or any of the implementations of the sixth aspect. The storage module can be a storage module (for example, a register, a cache, or the like) in the chip, or a storage module (for example, a read-only memory, a random access memory, or the like) in the authentication server and located outside the chip.

[0136] In a ninth aspect, the present application provides a communication apparatus, which can be an integrated circuit chip. The integrated circuit chip includes a processor. The processor is coupled to a memory for storing a program or instructions, which when executed by the processor, cause the communication apparatus to perform the method in the first aspect or any of the implementation forms of the first aspect, or the third aspect or any of the implementation forms of the third aspect, or the fifth aspect or any of the implementation forms of the fifth aspect.

[0137] In a tenth aspect, the present application provides a communication apparatus, which can be an integrated circuit chip. The integrated circuit chip includes a processor. The processor is coupled to a memory for storing a program or instructions, which when executed by the processor, cause the communication apparatus to perform the method in the second aspect or any of the implementation forms of the second aspect, or the fourth aspect or any of the implementation forms of the fourth aspect, or the sixth aspect or any of the implementation forms of the sixth aspect.

[0138] In an eleventh aspect, the embodiments of the present application provide a computer program product including instructions, which when executed on a computer, cause the computer to perform the method as introduced above in the first aspect to the sixth aspect, and any of the implementation forms of the respective aspects.

[0139] In a twelfth aspect, the embodiments of the present application provide a computer readable storage medium including instructions, which when executed on a computer, cause the computer to perform the method as introduced above in the first aspect to the sixth aspect, and any of the implementation forms of the respective aspects.

[0140] In a thirteenth aspect, the embodiments of the present application provide a communication system, which includes the communication apparatus in the seventh aspect and any of the implementation forms of the seventh aspect, and the communication device in the eighth aspect and any of the implementation forms of the eighth aspect.

[0141] From the above technical solutions, it can be seen that the embodiments of the present application have the following advantages:

[0142] In the embodiments of the present application, when the authentication point receives the first message carrying the first IPv6 address and the MAC address from the terminal device, the authentication point will send the first IPv6 address and the MAC address to the authentication server when it is determined that the first IPv6 address is a new IPv6 address. Then, the authentication server determines the first authorization policy sent to the policy execution point (i.e. the gateway) based on the first IPv6 address. Since the first authorization policy sent by the authentication server is determined based on the first IPv6 address (i.e. the new IPv6 address), when the policy execution point receives the first authorization policy, the service message of the terminal device can be transmitted to the address or network segment allowed to be accessed by the user through the policy execution point. Therefore, even if the IPv6 address of the terminal device changes, the service will not be interrupted. BRIEF DESCRIPTION OF DRAWINGS

[0143] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application.

[0144] Figure 1A A system architecture diagram suitable for the access management method in the embodiments of the present application;

[0145] Figure 1B Another system architecture diagram suitable for the access management method in the embodiments of the present application;

[0146] Figure 1C Another system architecture diagram suitable for the access management method in the embodiments of the present application;

[0147] Figure 2 An example diagram of the authentication process based on the 802.1x protocol;

[0148] Figure 3 A flowchart of the access management method in the embodiments of the present application;

[0149] Figure 4 Another flowchart of the access management method in the embodiments of the present application;

[0150] Figure 5 Another flowchart of the access management method in the embodiments of the present application;

[0151] Figure 6 Another flowchart of the access management method in the embodiments of the present application;

[0152] Figure 7 Another flowchart of the access management method in the embodiments of the present application;

[0153] Figure 8Another flow chart of the access management method in the embodiments of the present application;

[0154] Figure 9 Another flow chart of the access management method in the embodiments of the present application;

[0155] Figure 10 Another flow chart of the access management method in the embodiments of the present application;

[0156] Figure 11 Another flow chart of the access management method in the embodiments of the present application;

[0157] Figure 12 Another flow chart of the access management method in the embodiments of the present application;

[0158] Figure 13 Another flow chart of the access management method in the embodiments of the present application;

[0159] Figure 14 Another flow chart of the access management method in the embodiments of the present application; DETAILED DESCRIPTION

[0160] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, not all the embodiments of the present application.

[0161] The terms "first", "second", "third", "fourth" and the like (if any) in the specification and claims of the present application and the above drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or a chronological sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to include only those steps or units clearly listed, but can include other steps or units that are not clearly listed or inherent to the process, method, product or device.

[0162] For the convenience of understanding, some technical terms related to the embodiments of the present application will be explained first as follows:

[0163] Global Unicast Address (GUA): A unicast address defined in the IPv6 protocol to uniquely identify a user of an access network. Therefore, it is also referred to as IPv6 GUA. A terminal device can obtain an IPv6 address through a dynamic host configuration protocol version 6 (DHCPv6) or a stateless address autoconfiguration (SLAAC). When accessing the same network, the same terminal device will obtain the same IPv6 GUA in a stable network access environment. In addition, a temporary IPv6 GUA refers to an IPv6 GUA generated by a terminal device based on a temporary prefix, which changes over time to achieve unpredictable user addresses. It should be noted that in subsequent embodiments, the IPv6 GUA is referred to as IPv6 address, and the temporary IPv6 GUA is referred to as temporary IPv6 address.

[0164] Stateless Address Autoconfiguration (SLAAC): An address configuration method that can obtain an IPv6 GUA address without the service of a DHCPv6 server. The core of SLAAC is the internet control management protocol version 6 (ICMPv6). SLAAC provides prefix information and other configuration information for addressing to a terminal device through router solicitation (RS) messages and router advertisement (RA) messages in the ICMPv6 protocol, so that the terminal device can generate a temporary IPv6 address based on the aforementioned prefix information.

[0165] Campus Network: Refers to a university campus network or an enterprise local area network (intranet), etc. The characteristic of the campus network is that the routing structure is managed by an organization. Generally, the campus network mainly includes terminal devices, routers, and three-layer switches.

[0166] Neighbor Discovery Protocol (NDP): is an important basic protocol in the IPv6 protocol system. The neighbor discovery protocol replaces the address resolution protocol (ARP) and ICMPv4 router discovery (router discovery) protocol of IPv4. The neighbor discovery protocol defines the use of ICMPv6 packets to implement address resolution, track neighbor status, duplicate address detection, router discovery, and redirection functions. Among them, the address resolution process mainly uses the neighbor solicitation (NS) message and the neighbor advertisement (NA) message.

[0167] Duplicate Address Detection (DAD): is a process for a node to determine whether an address to be used is unique on the link.

[0168] Remote Authentication Dial In User Service (Radius) protocol: a protocol that includes authentication, authorization and accounting functions.

[0169] Before introducing the access management method proposed by the embodiments of the present application, the system architecture to which the access management method is applicable will be exemplarily introduced as follows:

[0170] The access management method proposed by the embodiments of the present application can be applied to the scenario of terminal device access to a campus network. Therefore, the system architecture to which the access management method is applicable includes but is not limited to: a terminal device, a node for controlling the access of the terminal device, and an authentication server. Specifically, when the terminal device needs to access a network (for example, a campus network), the terminal device needs to send information about the terminal device (for example, identity information of the terminal device, address information of the terminal device, etc.) to the node, and initiate an authentication process through the node. The node sends the information of the terminal device to the authentication server, and the authentication server authenticates the terminal device. After the authentication is passed, the authentication server sends an authorization policy for controlling the access of the terminal device to the aforementioned node. Subsequently, the node can control the access of the terminal device according to the authorization policy.

[0171] The terminal device is a device supporting a temporary IPv6 address function. Specifically, the terminal device can generate a temporary IPv6 address by using a stateless address auto-configuration (SLAAC) scheme. That is, the terminal device can automatically generate a temporary IPv6 address according to the obtained prefix information, and initiate communication by default using the temporary IPv6 address as the preferred address. The terminal device can be, for example, an office personal computer (PC), a mobile tablet, a mobile terminal, an Internet of Things (IoT) terminal, or the like. If the network to which the terminal device needs to access is a campus network, the terminal device can be a terminal using a Windows operating system (e.g., Windows 10, Windows 8, Windows 7, or the like), a Linux operating system, an Android operating system, or other operating systems, without limitation. It should be noted that the user of the terminal device is referred to as a user, and the user has a user account and logs in to the terminal device, so that the user can send or receive service packets through the terminal device. It can also be understood that the terminal device is a carrier for the user to transmit service packets, and the user can access the network and obtain the service function required by the user through the terminal device. In addition, when the terminal device initiates the authentication process, the user logged in to the terminal device is determined. After the terminal device is authenticated successfully, the terminal device will be bound to the user until the user logs out.

[0172] The authentication server is a server or controller with authentication and authorization functions. For example, the authentication server described in the present application can be an authentication, authorization, and accounting (AAA) server or other server or controller supporting a remote authentication dial in user service (Radius) protocol.

[0173] In the present application, the node for controlling the access of the terminal device can have the function of a gateway. If the node for controlling the access of the terminal device can provide an interface for authentication to the terminal device, the node has the function of a gateway, and the node can be referred to as an authenticator. If the node for controlling the access of the terminal device can execute an authorization policy for controlling the access of the terminal device, the node can be referred to as a policy enforcement point (PEP). The authenticator and the PEP can be integrated, for example, in the same gateway, or can be configured as two different devices, for example, arranged in two nodes. For example, the authenticator and / or the PEP can be a switch, a router, a firewall, or a functional entity in a device for executing a specific function, such as a single board or a chip for executing the function of the authenticator or the PEP. The specific implementation is not limited here.

[0174] In a specific implementation, the authenticator and the PEP are two independent devices. As shown in FIG. 1, the system includes a terminal device, an authentication server, an authenticator, and a PEP. Before accessing the network, the terminal device initiates authentication through the authenticator, and the authenticator sends the information of the terminal device to the authentication server for authentication. After the authentication is passed, the authentication server sends an authorization policy to the PEP, which permits the terminal device to access the network. Subsequently, if the terminal device sends a packet to the PEP, the PEP can control the transmission of the packet according to the authorization policy. Figure 1A

[0175] In another specific implementation, the authenticator and the PEP can be integrated. As shown in FIG. 2, the system includes a terminal device, an authentication server, and an authenticator (i.e., a PEP). Figure 1B

[0176] In another specific implementation, if the terminal device is not directly connected to the authenticator (or the PEP), the terminal device and the authenticator (or the PEP) further include an access point. The access point can be a layer 2 forwarding device (for example, a layer 2 switch or the like), which can select an appropriate port to forward the received packet to the authenticator (or the PEP). As shown in FIG. 3, the system includes a terminal device, an authentication server, an authenticator (i.e., a PEP), and an access point. Figure 1C ​​As shown, the system comprises a terminal device, an authentication server, an authentication point, a policy enforcement point and an access point. In the authentication process, the terminal device sends a message carrying information of the terminal device to the access point, which forwards the message to the authentication point, which in turn sends the message to the authentication server. After the authentication is passed, the authentication server sends an authorization policy about the terminal device to the policy enforcement point. Thereafter, the terminal device sends a service message to the access point, which forwards the message to the policy enforcement point, which controls the transmission of the service message based on the authorization policy.

[0177] It should be understood that the terminal device in the foregoing Figure 1B may also have an access point between the terminal device and the authentication point (i.e. the policy enforcement point). Therefore, in practical applications, the system architecture to which the access management method is applicable can have other embodiments in addition to the embodiments listed in the foregoing Figure 1A , Figure 1B and Figure 1C . The system architecture shown in the foregoing Figure 1A , Figure 1B and Figure 1C is only an example for the reader to understand. In practical applications, the foregoing system architecture can be adjusted according to the needs of enterprise campus networks or campus networks, and specific adjustments will not be listed here. In the subsequent embodiments, only the system architecture shown in Figure 1A will be introduced.

[0178] For example, the authentication process between the authentication server and the authentication point in the present application can adopt an authentication process based on the 802.1x protocol or an authentication process based on the Portal protocol.

[0179] The 802.1x protocol is a client / server-based access control and authentication protocol. The 802.1x protocol can restrict unauthorized users / devices from accessing a local area network (LAN) or a wireless local area network (WLAN) through an access port (AP). Based on the 802.1x protocol, an authentication point first authenticates a terminal device connected to the authentication point. Before authentication is passed, the authentication point only allows extensible authentication protocol over LAN (EAPOL) messages (or data) to pass through the authentication point port; after authentication is passed, normal service messages (or data) can pass through the Ethernet port smoothly. In a specific implementation, the terminal device can first send a temporary IPv6 address newly generated by the terminal device to the authentication point, and then initiate an authentication process to the authentication server through the authentication point. After authentication is passed, the authentication server sends an authorization policy to a policy execution point based on the temporary IPv6 address. In another specific implementation, the terminal device first initiates an authentication process to the authentication server through the authentication point, and then sends a temporary IPv6 address newly generated by the terminal device to the authentication point. After authentication is passed, the authentication point sends the temporary IPv6 address to the authentication server, so that the authentication server sends an authorization policy to the policy execution point based on the temporary IPv6 address.

[0180] In addition, the authentication based on the Portal protocol (also referred to as the Web authentication) can provide the identity authentication and personalized information service to the user in the form of a webpage. Generally, the authentication procedure based on the Portal protocol is that the terminal device initiates the access based on the hyper text transfer protocol (HTTP), the authentication point redirects the message from the terminal device to the Portal server, so that the Portal server provides the Portal authentication page to the user through the terminal device. The Portal server receives the user identification (e.g., the user account, the password, and the like) input by the user for authentication, and sends the user identification for authentication to the authentication point, so that the authentication point transmits the user identification for authentication to the authentication server to initiate the authentication procedure. Therefore, if the authentication procedure based on the Portal protocol is adopted in the present application, the authentication point also has a connection with the Portal server. In a specific implementation manner, the terminal device sends the temporary IPv6 address newly generated by the terminal device to the authentication point, and then the authentication point sends the user identification and the temporary IPv6 address to the authentication server for authentication. After the authentication is passed, the authentication server sends the authorization policy to the policy execution point based on the temporary IPv6 address.

[0181] For the convenience of understanding, the following will be described in combination with Figure 2 An implementation manner of the authentication procedure based on the 802.1x protocol is exemplarily introduced. As shown in FIG. 2, a method 200 for authentication based on the 802.1x protocol includes the following steps. Figure 2

[0182] Step 201: The terminal device sends a route solicitation (RS) message to the authentication point.

[0183] The route solicitation (RS) message is a message based on the stateless address auto-configuration (SLAAC) protocol, and is used to request the prefix information from the authentication point. The prefix information includes the prefix, the prefix length, and other related information. The prefix can be an IPV6 prefix, an IPV6-PD prefix (DHCP-PD (prefix-delegation) prefix in the IPV6 environment), and the like.

[0184] Step 202: The authentication point sends a route advertisement (RA) message to the terminal device.

[0185] When the authentication point receives the route solicitation (RS) message, the authentication point sends a route advertisement (RA) message to the terminal device. The route advertisement (RA) message is also a message based on the stateless address auto-configuration (SLAAC) protocol, and is used to carry the prefix information.

[0186] ​Step 203, the terminal device generates a temporary IPv6 address 0 according to the prefix information.

[0187] Specifically, the terminal device can generate one temporary IPv6 address of the terminal device based on the aforementioned prefix and interface identifier (IID). For example, the terminal device can generate a temporary IPv6 address based on a 64-bit prefix and a 64-bit interface identifier IID. At this time, the terminal device can generate the aforementioned interface identifier IID in the following two ways: way one, using a 64-bit Extended Unique Identifier (EUI-64) process to create an interface identifier IID through a 48-bit MAC address. Way two, using a random number generator to randomly generate a 64-bit random number as an interface identifier IID. For the convenience of subsequent introduction, the temporary IPv6 address generated by the terminal device in step 203 is referred to as temporary IPv6 address 0. The temporary IPv6 address 0 can be understood as the temporary IPv6 address generated by the terminal device for the first time. If the terminal device can successfully authenticate in the subsequent authentication process, the terminal device will use the temporary IPv6 address 0 to transmit service packets.

[0188] In addition, the terminal device will also perform duplicate address detection (i.e. DAD detection) on the temporary IPv6 address 0. If the temporary IPv6 address 0 does not conflict with the existing IPv6 address, the terminal device will execute step 204.

[0189] Step 204, the terminal device sends the temporary IPv6 address 0 and the MAC address 1 to the authentication point.

[0190] Wherein, the MAC address 1 is the MAC address of the terminal device, and the temporary IPv6 address 0 is the temporary IPv6 address generated in the aforementioned step 203 (i.e. the temporary IPv6 address newly generated by the terminal device).

[0191] At this time, the terminal device encapsulates the aforementioned temporary IPv6 address 0 and the MAC address 1 of the terminal device into a packet, and sends the aforementioned temporary IPv6 address 0 and the MAC address 1 to the authentication point through the packet, so that the authentication point stores the aforementioned temporary IPv6 address 0 and the MAC address 1, and prepares for the subsequent authentication process.

[0192] Step 205, the authentication point stores the temporary IPv6 address 0 and the MAC address 1.

[0193] Since the temporary IPv6 address 0 and the MAC address 1 received by the authentication point are in one packet, the authentication point can determine that the temporary IPv6 address 0 and the MAC address 1 correspond to the same terminal device, and can also be understood as the temporary IPv6 address 0 and the MAC address 1 correspond to the same user. Therefore, the authentication point stores the correspondence between the temporary IPv6 address 0 and the MAC address 1 in the authentication point, that is, the authentication point stores the correspondence between the temporary IPv6 address 0 and the MAC address 1. That is, the authentication point can query the MAC address 1 according to the temporary IPv6 address 0, and can also query the temporary IPv6 address 0 according to the MAC address 1. In order to identify the packet sent by the terminal device subsequently, or to prepare for the subsequent authentication process of the terminal device.

[0194] It should be noted that since the terminal device has not been authenticated at this time, the authentication point cannot send the temporary IPv6 address 0 and the MAC address 1 to the authentication server. And the terminal device can only communicate with the authentication point using the EAPOL packet in the 802.1x protocol.

[0195] It should be understood that before step 205, since the terminal device has not been authenticated, the authentication point does not store the related information of the terminal device (such as the IPv6 address of the terminal device, the MAC address of the terminal device, etc.). It can also be understood that the related information of the user corresponding to the terminal device is not stored.

[0196] From step 201 to step 205, the terminal device generates a temporary IPv6 address 0 and sends the temporary IPv6 address 0 to the authentication point.

[0197] Step 206, the terminal device sends an EAPOL packet to the authentication point.

[0198] In step 206, the terminal device initiates an 802.1x authentication process through an extended authentication protocol EAPOL packet based on a local area network. The EAPOL packet carries a user identifier for authentication. For example, the user identifier for authentication can be a user account and password, or a username and password. The specific implementation is not limited here.

[0199] Step 207, the authentication point sends an authentication request packet to the authentication server.

[0200] The authentication request packet is a packet that can carry a user identifier and a MAC address. For example, the authentication request packet is a Radius protocol based packet.

[0201] In this step, the authentication point encapsulates the user identity for authentication carried in the EAPOL packet into an authentication request packet recognizable by the authentication server, which carries not only the user identity for authentication but also the MAC address 1 of the terminal device, so that the authentication server can authenticate the terminal device based on the user identity for authentication. If the authentication is successful, the MAC address 1 is stored to identify the subsequent packets or information related to the terminal device.

[0202] In step 208, the authentication server stores the user identity for authentication and the MAC address 1 and performs authentication.

[0203] In step 208, the authentication server can first store the user identity for authentication and the MAC address 1 carried in the foregoing authentication packet, and then authenticate the terminal device using the user identity for authentication; or the authentication server can authenticate the terminal device using the user identity for authentication, and then store the user identity for authentication and the MAC address 1 correspondingly after the authentication is successful.

[0204] Specifically, the authentication server stores the user identity for authentication and the MAC address 1 correspondingly in the authentication server. In addition, the authentication server also stores other information about the terminal device generated in the authentication process.

[0205] If the authentication server successfully authenticates the terminal device using the user identity for authentication, the authentication server and the authentication point will perform steps 209 and 210 in turn.

[0206] In step 209, the authentication server informs the authentication point that the authentication is successful.

[0207] In step 210, the authentication point informs the terminal device that the authentication is successful.

[0208] Steps 206 to 210 are the authentication process of the terminal device.

[0209] It should be understood that when the authentication process based on the 802.1x protocol is used, the process in which the terminal device sends the newly generated temporary IPv6 address to the authentication point (i.e., steps 201 to 205) and the authentication process of the terminal device (i.e., steps 206 to 210) can be exchanged in execution order. That is, in another specific implementation, the terminal device can first be authenticated based on the 802.1x protocol, and then the terminal device generates a temporary IPv6 address and sends the temporary IPv6 address to the authentication point.

[0210] In step 211, the authentication point sends the temporary IPv6 address 0 and the MAC address 1 to the authentication server.

[0211] It should be noted that in the foregoing steps of the present scenario, although the terminal device sends the temporary IPv6 address 0 and the MAC address 1 to the authentication point, the authentication point has not sent the temporary IPv6 address 0 and the MAC address 1 to the authentication server, because the terminal device has not been authenticated.

[0212] However, after step 209, the authentication point has received the notification that the terminal device has been authenticated successfully, the authentication point sends the temporary IPv6 address 0 and the MAC address 1 stored internally to the authentication server through a packet, so that the authentication server configures an authorization policy for the terminal device based on the foregoing temporary IPv6 address.

[0213] Step 212, the authentication server stores the temporary IPv6 address 0 and the MAC address 1 correspondingly.

[0214] At this time, the authentication server stores the temporary IPv6 address 0, the MAC address 1, the user identifier (i.e. the user identifier used by the terminal device for authentication), and other information about the user or the terminal device generated in the authentication process (e.g. the access right of the user, etc.). The foregoing information is stored correspondingly in the authentication server. The authentication server can query other information through the foregoing information.

[0215] Step 213, the authentication server generates an authorization policy 0 based on the temporary IPv6 address 0.

[0216] Specifically, the authentication server determines the authorization policy of the terminal device (hereinafter referred to as authorization policy 0) according to the temporary IPv6 address 0 and the access right of the user corresponding to the temporary IPv6 address 0.

[0217] It should be understood that after the terminal device is authenticated successfully, the terminal device is bound to the user corresponding to the foregoing user identifier until the user logs off. Therefore, in the present scenario and subsequent embodiments, the access right of the user can also be understood as the access right of the terminal device. It can also be understood that the access right of the terminal device is determined by the access right of the user.

[0218] Step 214, the authentication server sends the authorization policy 0 to the policy enforcement point.

[0219] Thereafter, the packet transmitted by the terminal device to the policy enforcement point can be transmitted to the address or network segment allowed to be accessed by the terminal device through the port of the foregoing policy enforcement point.

[0220] From step 211 to step 214 is the process of sending the authorization policy by the authentication server based on the temporary IPv6 address 0 of the terminal device.

[0221] It should be understood that the method 200 is only an exemplary introduction of the access scenario based on the 802.1x protocol, and in actual applications, other steps can be included in addition to the steps listed in the foregoing examples, which are not limited herein.

[0222] As can be seen from the foregoing examples, the authorization policy sent by the authentication server to the policy enforcement point is generated based on the temporary IPv6 address of the terminal device. The temporary IPv6 address of the terminal device is time-limited, that is, the terminal device updates the temporary IPv6 address at intervals. For example, it is suggested in the request for comments No. 4941 (RFC4941) that the preferred time of the temporary IPv6 address is 1 day and the valid time is 7 days. That is, it is suggested that the temporary IPv6 address changes once a day, and the terminal device will no longer use the foregoing temporary IPv6 address after 7 days. It should be understood that in actual applications, the preferred time and the valid time of the foregoing temporary IPv6 address can be modified according to actual needs, which are not limited herein.

[0223] When the terminal device updates the temporary IPv6 address, and the updated temporary IPv6 address is also successfully authenticated, the terminal device will send a service packet to the policy enforcement point using the updated temporary IPv6 address (i.e., a new temporary IPv6 address, for example, temporary IPv6 address 1 to be introduced hereinafter) as a source address. However, at this time, the authorization policy related to the temporary IPv6 address before the update (i.e., an old temporary IPv6 address, for example, temporary IPv6 address 0) is stored in the policy enforcement point. That is, there is no authorization policy related to the updated temporary IPv6 address in the policy enforcement point. Therefore, the transmission of the service packet of the terminal device will be limited, and further, the service of the terminal device will be interrupted.

[0224] To this end, the present application provides an access management method, which can be applied to the foregoing access scenario based on the 802.1x protocol (for example, the network scenario shown in Figure 2 The method can ensure that the service of the terminal device is not interrupted as much as possible when the temporary IPv6 address of the terminal device is changed.

[0225] As shown in Figure 3 , the present application provides an implementation of the access management method 300. When the temporary IPv6 address of the terminal device is changed, the terminal device, the authentication point, and the authentication server will perform the following steps:

[0226] For example, the temporary IPv6 address of the terminal device is changed from temporary IPv6 address 0 to temporary IPv6 address 1.

[0227] Step 301, the terminal device sends a message 1 to the authentication point.

[0228] The message 1 carries a temporary IPv6 address (hereinafter referred to as temporary IPv6 address 1) newly generated by the terminal device and a MAC address (hereinafter referred to as MAC address 1) of the terminal device. The IPv6 address 1 is generated by the terminal device based on a prefix and an interface identifier (IID). The prefix is obtained from the authentication point through a route solicitation (RS) message and a route advertisement (RA) message. For details, refer to the foregoing description of steps 201 to 203, which will not be repeated here.

[0229] In addition, the foregoing message 1 is a message that can carry an IPv6 address and a MAC address, and the message 1 can trigger the authentication point to find a corresponding relationship related to the MAC address based on the MAC address. For example, the message 1 is a neighbor solicitation (NS) message.

[0230] It should be understood that, before step 301, the terminal device sends a service message to the policy enforcement point using a temporary IPv6 address (for example, temporary IPv6 address 0) before updating, and only the authorization policy 0 corresponding to the temporary IPv6 address 0 is stored in the authentication server and the policy enforcement point.

[0231] When the authentication point receives the foregoing message 1, the authentication point will perform step 302.

[0232] Step 302, the authentication point determines that the temporary IPv6 address 1 is a new temporary IPv6 address.

[0233] Since the foregoing temporary IPv6 address 1 is an address generated by the terminal device based on a prefix, rather than an address configured by the authentication point, the authentication point cannot directly determine whether the temporary IPv6 address 1 is a new temporary IPv6 address. Therefore, after receiving the temporary IPv6 address 1 and the MAC address 1 in the message 1, the authentication point needs to determine whether the temporary IPv6 address 1 is a new temporary IPv6 address according to the information stored in the authentication point. If the temporary IPv6 address 1 is a new temporary IPv6 address, the authentication point will perform step 303. If the temporary IPv6 address 1 is not a new temporary IPv6 address, the authentication point will not perform the subsequent steps.

[0234] It should also be understood that before step 301, the terminal device has generated one or more temporary IPv6 addresses, and the terminal device sends each generated temporary IPv6 address and the MAC address (i.e., MAC address 1) of the terminal device to the authentication point storage. As described in the foregoing steps 204 and 205, the authentication point can receive the temporary IPv6 address 0 and the MAC address 1 from the terminal device, and store the foregoing temporary IPv6 address 0 and the MAC address 1. Therefore, the authentication point stores at least one temporary IPv6 address (e.g., temporary IPv6 address 0) and the MAC address (e.g., MAC address 1) corresponding to the temporary IPv6 address, and one or more temporary IPv6 addresses corresponding to the MAC address 1 can be found by looking up the MAC address 1. For example, the authentication point stores the MAC address 1, the temporary IPv6 address 0, and the temporary IPv6 address 2, wherein the temporary IPv6 address 0 and the temporary IPv6 address 2 are both temporary IPv6 addresses generated by the terminal device, and the MAC address 1 is the MAC address of the terminal device, and the foregoing temporary IPv6 address 0 and the temporary IPv6 address 2 are stored in the authentication point corresponding to the MAC address 1. Then, the authentication point can find the temporary IPv6 address 0 and the temporary IPv6 address 2 corresponding to the MAC address 1 by the MAC address 1.

[0235] Specifically, the authentication point will find whether the foregoing MAC address 1 is stored in the authentication point, and if the foregoing MAC address 1 is stored in the authentication point and the foregoing temporary IPv6 address 1 (i.e., the temporary IPv6 address carried in the message 1 received by the authentication point) does not exist in one or more temporary IPv6 addresses corresponding to the MAC address 1, the authentication point can determine that the temporary IPv6 address 1 is a new temporary IPv6 address. It can also be understood that the authentication point determines that the correspondence between the MAC address 1 and the temporary IPv6 address 1 is not stored, and then determines that the IPv6 address 1 is the new IPv6 address.

[0236] It should be understood that the authentication point can receive messages from different terminal devices, and therefore the authentication point can store different MAC addresses and temporary IPv6 addresses corresponding to each MAC address. In order to facilitate the maintenance of the MAC addresses and temporary IPv6 addresses received by the authentication point, the authentication point can store the foregoing one or more MAC addresses and one or more temporary IPv6 addresses in a table (hereinafter referred to as a correspondence table 1). The correspondence table 1 is a table in the authentication point, and the correspondence table 1 is used to store MAC addresses, temporary IPv6 addresses, and the correspondence between the foregoing stored MAC addresses and temporary IPv6 addresses. It can also be understood that the MAC addresses and the temporary IPv6 addresses are stored in the foregoing correspondence table 1.

[0237] In one specific implementation, the correspondence between the MAC address and the temporary IPv6 address in the correspondence table 1 can be implicit. For example, the correspondence table 1 can be shown in Table 1-1 as follows. In this case, the MAC address and the temporary IPv6 address in the same row can be understood as corresponding, which can be referred to as one correspondence. For example, the temporary IPv6 address 0 corresponds to the MAC address 1, which can be referred to as one correspondence. The temporary IPv6 address 2 also corresponds to the MAC address 1, which can be referred to as one correspondence.

[0238] Table 1-1

[0239]

[0240] In another specific implementation, the correspondence between the MAC address and the temporary IPv6 address in the correspondence table 1 can also be explicit. For example, the correspondence table 1 can be shown in Table 1-2 as follows. In this case, the correspondence table 1 has a column recording the correspondence, and explicitly records that a certain temporary IPv6 address corresponds to a certain MAC address. For example, in the row where the MAC address 1 and the temporary IPv6 address 0 are located, it is recorded that the temporary IPv6 address 0 corresponds to the MAC address 1.

[0241] Table 1-2

[0242] MAC address IPv6 address Correspondence MAC address 1 Temporary IPv6 address 0 Temporary IPv6 address 0 corresponds to MAC address 1 MAC address 1 Temporary IPv6 address 2 Temporary IPv6 address 2 corresponds to MAC address 1 MAC address 1 Temporary IPv6 address 3 Temporary IPv6 address 3 corresponds to MAC address 1 MAC address 2 Temporary IPv6 address 4 Temporary IPv6 address 4 corresponds to MAC address 2 MAC address 2 Temporary IPv6 address 5 Temporary IPv6 address 5 corresponds to MAC address 2 MAC address 2 Temporary IPv6 address 6 Temporary IPv6 address 6 corresponds to MAC address 2

[0243] It should be understood that the foregoing Table 1-1 and Table 1-2 are only two common examples of the correspondence table 1. In actual applications, the correspondence table 1 can also store other information, such as port number, etc., which is not limited here.

[0244] Specifically, when the authentication point stores the correspondence table 1, after the authentication point obtains the MAC address 1 and the temporary IPv6 address 1 from the foregoing message 1, the authentication point will look up the MAC address 1 in the foregoing correspondence table 1. If the foregoing MAC address 1 exists in the correspondence table 1, and the temporary IPv6 address 1 does not exist in one or more temporary IPv6 addresses corresponding to the MAC address 1, the authentication point determines that the temporary IPv6 address 1 is the new IPv6 address.

[0245] It should be noted that the aforementioned correspondence table 1 can be a table in the prior art capable of storing the temporary IPv6 address and the MAC address, or can be a newly defined table for storing the temporary IPv6 address and the MAC address, and the specific implementation is not limited herein. For example, the aforementioned correspondence table 1 can be a table generated based on a neighbor discovery protocol (NDP) message. For example, a neighbor discovery (ND) table (also referred to as an ND neighbor table), a neighbor discovery snooping table (also referred to as an ND snooping table), etc.

[0246] Step 303, the authentication point stores the temporary IPv6 address 1 and the MAC address 1 in correspondence.

[0247] Specifically, when the authentication point determines that the temporary IPv6 address 1 is a new temporary IPv6 address, the authentication point stores the temporary IPv6 address 1 and the MAC address 1 in correspondence.

[0248] In a specific implementation, when the authentication point stores the aforementioned correspondence table 1, the authentication point stores the aforementioned temporary IPv6 address 1 and the MAC address 1 in the correspondence table 1. It can also be understood that the correspondence between the temporary IPv6 address 1 and the MAC address 1 is stored.

[0249] For example, if the correspondence table 1 is as shown in the aforementioned table 1-1, after storage, the correspondence table 1 is as shown in the following table 1-3.

[0250] Table 1-3

[0251]

[0252] For another example, if the correspondence table 1 is as shown in the aforementioned table 1-2, after storage, the correspondence table 1 is as shown in the following table 1-4.

[0253] Table 1-4

[0254] MAC address IPv6 address Correspondence MAC address 1 Temporary IPv6 address 0 Temporary IPv6 address 0 corresponds to MAC address 1 MAC address 1 Temporary IPv6 address 2 Temporary IPv6 address 2 corresponds to MAC address 1 MAC address 1 Temporary IPv6 address 3 Temporary IPv6 address 3 corresponds to MAC address 1 MAC address 2 Temporary IPv6 address 4 Temporary IPv6 address 4 corresponds to MAC address 2 MAC address 2 Temporary IPv6 address 5 Temporary IPv6 address 5 corresponds to MAC address 2 MAC address 2 Temporary IPv6 address 6 Temporary IPv6 address 6 corresponds to MAC address 2 MAC address 1 Temporary IPv6 address 1 Temporary IPv6 address 1 corresponds to MAC address 1

[0255] Step 304, the authentication point determines that the user corresponding to the temporary IPv6 address 1 is online.

[0256] In this embodiment, step 304 is optional. When step 304 is performed, the authentication point also stores user state information of the user corresponding to MAC address 1, i.e., user state information of the user corresponding to the terminal device (hereinafter referred to as user A). The user state information is used to indicate the state of user A. For example, user A is in an online state, or user A is in an offline state (or an offline state). If the user state information indicates that user A is in an online state, the authentication point will perform step 305. If the user state information indicates that user A is in an offline state (or an offline state), the authentication point will not perform subsequent steps 305 to 307, but delete the information corresponding to the user in the authentication point. Specifically, the authentication point can determine the user state information corresponding to MAC address 1 based on the MAC address (i.e., MAC address 1) corresponding to the temporary IPv6 address 1, and then determine whether the user corresponding to the temporary IPv6 address 1 is online. In this process, the authentication point can not need to query which user the MAC address 1 corresponds to, but only determine whether the user is online.

[0257] In a specific implementation, the authentication point stores a correspondence table 2, which is used to store user state information of one or more users, and the MAC address corresponding to the user state information of the user. For example, the user state information of user A can be stored in the correspondence table 2, and the user state information of user A is stored in the correspondence table 2 corresponding to the MAC address 1.

[0258] For example, the correspondence table 2 can be as shown in Table 2-1. At this time, the MAC address and user state information in the same row indicate the state of the user corresponding to the MAC address. For example, based on MAC address 1, it can be determined that the user corresponding to the MAC address 1 is in an online state. For another example, based on MAC address 2, it can be determined that the user corresponding to the MAC address 2 is in an offline state.

[0259] Table 2-1

[0260] MAC address User status information MAC address 1 Online MAC address 2 Offline MAC address 3 Online

[0261] In another specific implementation, the correspondence table 2 stores, in addition to the user state information and the MAC address, a user identifier, which is used to identify the user corresponding to the MAC address. In addition, the user identifier is also stored in correspondence with the MAC address, and thus, the user identifier also corresponds to the user state information. It can also be understood that the MAC address of the user, the user identifier of the user, and the user state information of the user are stored in correspondence in the correspondence table 2. The user identifier can be a user identity document (user ID), a username, or other information that can uniquely identify a user. Thus, when determining the user state information of the user based on the MAC address, the authentication point can also determine the user identifier of the user corresponding to the MAC address.

[0262] For example, the correspondence table 2 can be as shown in Table 2-2. At this time, the MAC address and the user state information in the same row represent the state of the user corresponding to the MAC address. For example, based on the MAC address 1, it can be determined that the user corresponding to the MAC address 1 is the user with the username a, and the user corresponding to the MAC address 1 is in an online state. For another example, based on the MAC address 2, it can be determined that the user corresponding to the MAC address 2 is the user with the username b, and the user corresponding to the MAC address 2 is in an offline state.

[0263] Table 2-2

[0264] MAC address User identification User status information MAC address 1 User name a Online MAC address 2 User name b Offline MAC address 3 User name c Online

[0265] In another specific implementation, the correspondence table 2 can include the correspondence table 1. That is, the contents in the correspondence table 1 and the correspondence table 2 are integrated in one table.

[0266] For example, the table stored in the authentication point can be as shown in Table 2-3.

[0267] Table 2-3

[0268]

[0269] It should be understood that the tables listed in the present embodiment and subsequent embodiments are all examples for facilitating the understanding of the reader, and are not limitations of the foregoing tables. In actual applications, the foregoing tables can be modified according to actual needs, and the present embodiment is not limited.

[0270] It should also be noted that in a specific embodiment, the authentication point can also not perform step 304, but directly perform step 305. That is, after storing the temporary IPv6 address 1 and the MAC address 1, the authentication point directly sends the temporary IPv6 address 1 and the MAC address 1 to the authentication server, so that the authentication server generates an authorization policy based on the temporary IPv6 address 1. In such an embodiment, it can be understood that the terminal device has just generated a new temporary IPv6 address, and the user will not be offline in a short time. Alternatively, it is judged by the authentication server whether the user is offline. For details, please refer to Figure 4 The related description in the corresponding embodiment.

[0271] Step 305, the authentication point sends message 2 to the authentication server.

[0272] Among them, message 2 carries temporary IPv6 address 1 (i.e. the new temporary IPv6 address generated by the terminal device) and MAC address 1 (i.e. the MAC address of the terminal device). The message 2 is a message that can carry a temporary IPv6 address and a MAC address, and the message 2 is used to trigger the authentication server to find the corresponding relationship related to the MAC address based on the MAC address. In addition, the aforementioned message 2 can adopt a newly defined message format, or can adopt a message format multiplexed in a traditional technology. If the message 2 adopts a newly defined message format, the message 2 at least needs to be able to carry an IPv6 address and a MAC address. If the message 2 multiplexes the message format in the traditional technology, the message 2 can have other functions in addition to carrying the aforementioned IPv6 address and MAC address.

[0273] In a specific implementation, the message 2 is a message already existing in the traditional technology, but the message 2 extends a field (hereinafter referred to as indication information 1). The indication information 1 is used to instruct the authentication server to determine the authorization policy according to the IPv6 address (i.e. the temporary IPv6 address 1) carried by the message 2. In this implementation, after receiving the message 2, the authentication server needs to determine whether the temporary IPv6 address 1 is a new temporary IPv6 address according to the information stored in the authentication server.

[0274] In another specific implementation, the message 2 is a newly defined message, which can not only carry a temporary IPv6 address and a MAC address, but also indicate that the temporary IPv6 address 1 is a new IPv6 address. That is, a message for transmitting a new IPv6 address between the authentication point and the authentication server is newly defined, and when the authentication server receives the aforementioned message 2, it can be known that the IPv6 address carried in the message 2 is a new IPv6 address. For example, the content field of the message 2 can be as shown in Table 3-1.

[0275] In another specific implementation, the message 2 is a conventional message, but the message 2 extends a field (hereinafter referred to as indication information 1) for indicating that the IPv6 address (i.e. the temporary IPv6 address 1) carried by the message 2 is a new IPv6 address. For example, the indication information 1 can be represented by an attribute type in the attribute field in Table 3-1 below. In this implementation, the authentication server can directly determine that the IPv6 address (i.e. the temporary IPv6 address 1) carried by the message 2 is a new IPv6 address after receiving the message 2, without determining whether the temporary IPv6 address 1 is a new temporary IPv6 address according to the information stored in the authentication server. For example, if the authentication server is a Radius protocol-based server (hereinafter referred to as Radius server), the message 2 is a Radius protocol-based message (hereinafter referred to as Radius message), i.e. the message 2 can reuse the format of the Radius message. Since the Radius message has a charging function, and if the network to which the terminal device accesses needs charging, the message 2 can reuse the format of the Radius charging message (hereinafter referred to as charging message). At this time, in addition to carrying the IPv6 address and the MAC address, the message 2 also has a charging function, and can trigger the authentication server to perform real-time charging. Generally, the message that can carry the IPv6 address and the MAC address generally encapsulates the IPv6 address and the MAC address in the content field.

[0276] For example, the format of the content field of the Radius message is shown in Table 3-1 below:

[0277] Table 3-1

[0278]

[0279] Code: used to indicate the type of Radius message. Different Radius messages have different code values. For example, code 1 indicates an Access-Request message; code 2 indicates an Access-Accept message (also referred to as an Access-Response message). Identifier: used to match a request message and a response message. For example, after the Radius client (i.e., the aforementioned authentication point) sends a request message, the value of the identifier in the response message returned by the Radius server (i.e., the aforementioned authentication server) should be the same as the value of the identifier in the request message. Length: used to indicate the length of the Radius message. Authenticator: used to verify the response message of the Radius server (i.e., the authentication server). Attribute: i.e., the attribute field, is the content body of the message, used to carry authentication information, authorization information and charging information, and to provide configuration details of the request message and the response message. In this example, the aforementioned temporary IPv6 address and the MAC address are carried in the attribute field; the aforementioned indication information 1 can be represented by the attribute type in the attribute field.

[0280] It should be noted that the message 2 is a message triggered by the authentication point in real time. Each time the aforementioned authentication point receives a new temporary IPv6 address, i.e., the authentication point determines that the received temporary IPv6 address is a newly generated temporary IPv6 address of the terminal device, the authentication point will trigger the sending of the aforementioned message 2 to the authentication server, and transmit the newly generated temporary IPv6 address of the terminal device to the authentication server through the aforementioned message 2, so as to enable the authentication server to have an opportunity to configure a control policy for the terminal device to access the network using the newly generated temporary IPv6 address of the terminal device.

[0281] When the authentication server receives the aforementioned message 2, the authentication server will perform step 306.

[0282] Step 306, the authentication server determines that the temporary IPv6 address 1 is a new temporary IPv6 address.

[0283] It should be understood that before step 301, the authentication server has authenticated the terminal device as introduced in the aforementioned steps 211 and 212, and has stored the first generated temporary IPv6 address of the terminal device and the MAC address of the terminal device. Therefore, the authentication server stores at least one temporary IPv6 address (including the first generated temporary IPv6 address of the terminal device) and the MAC address of the terminal device.

[0284] In a specific implementation, the message 2 does not indicate that the temporary IPv6 address 1 is a new temporary IPv6 address. At this time, after the authentication server obtains the temporary IPv6 address 1 and the MAC address 1 in the message 2, the authentication server will check whether the MAC address 1 is stored in the authentication server. If the MAC address 1 is stored in the authentication server and the temporary IPv6 address 1 (i.e. the temporary IPv6 address carried in the message 2 received by the authentication server) does not exist in one or more temporary IPv6 addresses corresponding to the MAC address 1, the authentication server can determine that the temporary IPv6 address 1 is a new temporary IPv6 address. It can also be understood that the authentication server determines that the correspondence between the MAC address 1 and the temporary IPv6 address 1 is not stored, and then determines that the IPv6 address 1 is the new IPv6 address. At this time, the authentication server will trigger steps 307 and 308.

[0285] In another specific implementation, the message 2 or the indication information 1 carried in the message 2 indicates that the temporary IPv6 address 1 is a new temporary IPv6 address. At this time, after receiving the message 2, the authentication server can directly determine that the IPv6 address (i.e. the temporary IPv6 address 1) carried in the message 2 is a new IPv6 address, without the need to determine whether the temporary IPv6 address 1 is a new temporary IPv6 address according to the information stored in the authentication server. At this time, the authentication server will trigger steps 307 and 308.

[0286] It should be understood that the authentication server can simultaneously authenticate and manage multiple terminal devices, and therefore the authentication server can store different MAC addresses and temporary IPv6 addresses corresponding to each MAC address. In order to facilitate the maintenance of the MAC addresses and temporary IPv6 addresses received by the authentication server, the authentication server stores the one or more MAC addresses and the one or more temporary IPv6 addresses in a table (hereinafter referred to as a correspondence table 3). The correspondence table 3 is a table in the authentication server, which is used to store MAC addresses, temporary IPv6 addresses, and the correspondence between the stored MAC addresses and temporary IPv6 addresses. It can also be understood that the MAC addresses and the temporary IPv6 addresses are stored in the correspondence table 3.

[0287] When the authentication server stores the correspondence table 3, after the authentication server obtains the MAC address 1 and the temporary IPv6 address 1 from the message 2, the authentication server will search for the MAC address 1 in the correspondence table 3. If the MAC address 1 exists in the correspondence table 3, and the temporary IPv6 address 1 does not exist in one or more temporary IPv6 addresses corresponding to the MAC address 1, the authentication server determines that the temporary IPv6 address 1 is the new IPv6 address.

[0288] It should be understood that the correspondence between the MAC address and the temporary IPv6 address in the correspondence table 3 can be implicit or explicit. The correspondence table 3 is similar to the correspondence table 1, and details can be referred to the description of the correspondence table 1 in the step 302. The correspondence table 3 can be a table capable of storing temporary IPv6 addresses and MAC addresses in the prior art, or a newly defined table for storing temporary IPv6 addresses and MAC addresses, which is not limited here.

[0289] In step 307, the authentication server stores the temporary IPv6 address 1 and the MAC address 1.

[0290] In this embodiment, the step of storing the temporary IPv6 address 1 and the MAC address 1 by the authentication server is similar to the step of storing the temporary IPv6 address 1 and the MAC address 1 by the authentication point, and details can be referred to the description in the step 303.

[0291] In this embodiment, since the authentication server can store the temporary IPv6 address before updating (e.g., the temporary IPv6 address 0) and the temporary IPv6 address after updating (e.g., the temporary IPv6 address 1), and the temporary IPv6 address before updating and the temporary IPv6 address after updating can be associated by the MAC address (e.g., the MAC address 1) of the terminal device, and the MAC address of the terminal device is also associated with the information of the user (e.g., the user identifier, the user state information, the user access permission, etc.). Therefore, although the terminal device changes the temporary IPv6 address, the authentication server side can still query the information of the user based on the temporary IPv6 address after updating, so that the authentication server side can realize the tracing based on the temporary IPv6 address. In addition, after the temporary IPv6 address of the terminal device is changed, the terminal device no longer uses the temporary IPv6 address before updating to transmit the service message, so that the risk of eavesdropping on the IPv6 address by illegal devices can be reduced.

[0292] In step 308, the authentication server determines the authorization policy 1 corresponding to the temporary IPv6 address 1.

[0293] The authorization policy is used to restrict the access behavior of the terminal device, and different authorization policies are configured for different terminal devices by the authentication server. The authorization policy can be understood as a rule configured by the authentication server to the policy enforcement point for controlling the message from the terminal device, and the policy enforcement point can determine the destination address to which the message from the terminal device can be transmitted according to the authorization policy.

[0294] For example, the authorization policy can include a source address and a destination address. The source address is the temporary IPv6 address currently used by the terminal device, and can also be understood as the temporary IPv6 address (for example, the temporary IPv6 address 1) currently used by the user. The destination address can be understood as an address allowed to be accessed by the terminal device, which is determined by the access right of the user. Since the user is bound to the terminal device in this process, the authorization policy is used to control the access behavior of the terminal device, and the destination address can also be understood as an address allowed to be accessed by the user.

[0295] It should also be understood that different users can correspond to different access rights, but the user corresponding to the terminal device is always logged in on the terminal device and has not logged out, and only a new temporary IPv6 address is generated for the user to use. That is, the user on the terminal device does not change, but the user has a new temporary IPv6 address. Therefore, the behavior of the terminal device still reflects the behavior of the user logged in on the terminal device. Therefore, it can also be understood that the authorization policy is determined based on the access right of the user, that is, the access right of the user determines the access right of the terminal device, and the authorization policy records the access right of the terminal device.

[0296] In this embodiment, the authentication server stores the access right of the user, and the access right of the user can determine the access right of the terminal device. For example, the access right of a user records an IPv6 address C, which indicates that the user is allowed to access the IPv6 address C, and can also be understood as that the user has the right to access the IPv6 address C. If the user logs in on the terminal device A, the terminal device A also has the right to access the IPv6 address C. In addition, the access right of the user can also be used to indicate the network segment allowed to be accessed by the user.

[0297] In addition, the access right of the user is stored corresponding to the MAC address of the user, or the access right of the user is stored corresponding to the user identifier of the user. For example, the authentication server stores a MAC address 1, and the access right of the user corresponding to the MAC address 1 is stored in the authentication server corresponding to the MAC address 1. For another example, the authentication server stores a user identifier, and the access right of the user corresponding to the user identifier is stored in the authentication server corresponding to the user identifier.

[0298] In this embodiment, the access right of the user can be stored in the aforementioned correspondence table 3, or can be stored in another table (hereinafter referred to as correspondence table 4) independently of the aforementioned correspondence table 3.

[0299] For example, when the access right of the user is stored in the aforementioned correspondence table 3, if a MAC address and the access right of the user corresponding to the MAC address are stored in the same row, it indicates that the MAC address and the access right of the user correspond to each other. For example, the correspondence table 3 can be as shown in Table 4-1 below:

[0300] Table 4-1

[0301]

[0302] For example, the aforementioned correspondence table 3 can also store a user identifier. In this case, the correspondence table 3 can be as shown in Table 4-2 below:

[0303] Table 4-2

[0304]

[0305] When the access right of the user is stored independently of the aforementioned correspondence table 3, the access right of the user needs to be stored in correspondence with an association identifier, which is used to associate the access right of the user with the user indicated in the aforementioned correspondence table 3. Since the MAC address and the user identifier in the aforementioned correspondence table 3 can be used to indicate a user, the aforementioned association identifier can be a MAC address or a user identifier. For the convenience of introduction, the table storing the access right of the user is referred to as correspondence table 4.

[0306] When the MAC address and the temporary IPv6 address are stored in the aforementioned correspondence table 3, the correspondence table 4 needs to store the access right of the user and the MAC address. For example, the correspondence table 4 can be as shown in Table 5-1 below:

[0307] Table 5-1

[0308]

[0309] When the user identifier, the MAC address and the temporary IPv6 address are stored in the aforementioned correspondence table 3, the correspondence table 4 can store the access right of the user and the user identifier. For example, the correspondence table 4 can be as shown in Table 5-2 below:

[0310] Table 5-2

[0311]

[0312] It should be understood that the storage manner of the MAC address, the temporary IPv6 address, the user identity, and the access permission in the authentication server can be adjusted according to actual needs, and the correspondence table 1, the correspondence table 2, the correspondence table 3, and the correspondence table 4 listed in the foregoing are only examples for the reader to understand. In actual application, there is a correspondence between the MAC address, the temporary IPv6 address, the user identity, and the access permission, and when the authentication server receives a temporary IPv6 address, the access permission of the user corresponding to the temporary IPv6 address can be determined according to the foregoing correspondence.

[0313] In a specific implementation, the authorization policy includes the IPv6 address currently used by the terminal device and the access permission of the terminal device, wherein the access permission of the terminal device is determined by the access permission of the user. It can also be understood that the foregoing authorization policy is determined by the IPv6 address (for example, the temporary IPv6 address 1) currently used by the terminal device and the access permission of the user. Generally, the addresses allowed to be accessed by the same user are the same. That is, although the temporary IPv6 address of the same terminal device changes, the access permission of the user corresponding to the terminal device does not change. For example, the temporary IPv6 address of the terminal device before updating is the temporary IPv6 address 0, and the temporary IPv6 address 0 corresponds to the access permission A; if the temporary IPv6 address of the terminal device after updating is the temporary IPv6 address 1, the temporary IPv6 address 1 also corresponds to the access permission A.

[0314] Therefore, when the authentication server determines that the temporary IPv6 address 1 is a new temporary IPv6 address, the authentication server needs to determine the access permission of the user corresponding to the temporary IPv6 address 1, and determine the authorization policy (hereinafter referred to as authorization policy 1) corresponding to the temporary IPv6 address 1 based on the temporary IPv6 address 1 and the access permission of the user. For example, the access permission of the user corresponding to the temporary IPv6 address 1 is the IPv6 address C, the IPv6 address D, the IPv6 address E, and the IPv6 address F, and the authorization policy based on the temporary IPv6 address 1 is: the temporary IPv6 address 1 is allowed to access the IPv6 address C; the temporary IPv6 address 1 is allowed to access the IPv6 address D; the temporary IPv6 address 1 is allowed to access the IPv6 address E; and the temporary IPv6 address 1 is allowed to access the IPv6 address F.

[0315] It should be understood that there is no time sequence limitation between the step 307 and the step 308. That is, the authentication server can execute the step 307 first and then execute the step 308, the authentication server can execute the step 308 first and then execute the step 307, or the authentication server can execute the step 307 and the step 308 at the same time. The specific implementation is not limited here.

[0316] Step 309, the authentication server sends the authorization policy 1 to the policy enforcement point.

[0317] Thereafter, the message transmitted by the terminal device to the policy enforcement point can be transmitted to the address or network segment allowed to be accessed by the terminal device through the port of the policy enforcement point.

[0318] In the embodiment, when the authentication point receives the message 1 with the temporary IPv6 address 1 and the MAC address 1 from the terminal device, the authentication point sends the temporary IPv6 address 1 and the MAC address 1 to the authentication server if it is determined that the temporary IPv6 address 1 is a new IPv6 address. Then, the authentication server determines the authorization policy 1 sent to the policy enforcement point based on the temporary IPv6 address 1. Since the authorization policy 1 sent by the authentication server is determined based on the temporary IPv6 address 1 (i.e., the new temporary IPv6 address), when the policy enforcement point receives the authorization policy 1, the service message of the terminal device can be transmitted to the address or network segment allowed to be accessed by the user through the policy enforcement point. Therefore, even if the IPv6 address of the terminal device is changed, the service will not be interrupted, and the fine-grained terminal permission policy control can be achieved.

[0319] In addition, in the embodiment, when it is determined that the temporary IPv6 address 1 is a new IPv6 address, the authentication point further determines whether the user corresponding to the temporary IPv6 address 1 is online. If the user corresponding to the temporary IPv6 address 1 is online, the authentication point sends the temporary IPv6 address 1 and the MAC address 1 to the authentication server. This is advantageous to filter out the temporary IPv6 address of the offline user, and avoid the authentication server from configuring the authorization policy for the temporary IPv6 address of the offline user.

[0320] The above Figure 3 In the corresponding embodiment, the authentication point determines whether the user corresponding to the temporary IPv6 address 1 is online, and this step can also be performed by the authentication server. As shown in FIG. 4, an implementation manner of the access management method 400 provided by the present application is shown. When the temporary IPv6 address of the terminal device is changed, the terminal device, the authentication point, and the authentication server perform the following steps: Figure 4

[0321] Step 401, the terminal device sends a message 1 to the authentication point.

[0322] In the embodiment, step 401 is similar to step 301, and details are referred to the related description of step 301.

[0323] Step 402, the authentication point determines that the temporary IPv6 address 1 is a new temporary IPv6 address.

[0324] ​When the authentication point determines that the temporary IPv6 address 1 is a new temporary IPv6 address, the authentication point will perform step 403 and step 404. In addition, the specific manner in which the authentication point determines that the temporary IPv6 address 1 is a new temporary IPv6 address can refer to the aforementioned step 302.

[0325] In this embodiment, the authentication point does not judge the state of the user corresponding to the temporary IPv6 address 1, but directly sends the temporary IPv6 address 1 and the MAC address 1 to the authentication server, and the authentication server determines the state of the user corresponding to the temporary IPv6 address 1. For details, please refer to step 406.

[0326] Step 403, the authentication point stores the temporary IPv6 address 1 and the MAC address 1 corresponding to the temporary IPv6 address 1.

[0327] In this embodiment, step 403 is similar to the aforementioned step 303. For details, please refer to the relevant introduction of the aforementioned step 303.

[0328] Step 404, the authentication point sends message 2 to the authentication server.

[0329] In this embodiment, step 404 is similar to the aforementioned step 305. For details, please refer to the relevant introduction of the aforementioned step 305.

[0330] It should be understood that there is no specific time sequence between step 403 and step 404. That is, the authentication point can first perform step 403 and then perform step 404; or first perform step 404 and then perform step 403; or simultaneously perform the aforementioned step 403 and step 404, which is not limited here.

[0331] Step 405, the authentication server determines that the temporary IPv6 address 1 is a new temporary IPv6 address.

[0332] In this embodiment, step 405 is similar to the aforementioned step 306. For details, please refer to the relevant introduction of the aforementioned step 306.

[0333] Step 406, the authentication server determines that the user corresponding to the temporary IPv6 address 1 is online.

[0334] In this embodiment, in addition to storing the aforementioned correspondence table 3 and correspondence table 4, the authentication server also stores a correspondence table 2 in the internal of the authentication server, which is used to store the user state information of the user. Specifically, the correspondence table 2 is similar to the correspondence table 2 introduced in the aforementioned step 304, and the manner in which the authentication server judges whether the user corresponding to the temporary IPv6 address 1 is online is similar to the manner in which the authentication point judges whether the user corresponding to the temporary IPv6 address 1 is online. For details, please refer to the relevant introduction of the aforementioned step 304.

[0335] Step 407: The authentication server stores the temporary IPv6 address 1 and the corresponding MAC address 1.

[0336] Step 408: The authentication server determines the authorization policy 1 corresponding to IPv6 address 1.

[0337] Step 409: The authentication server sends authorization policy 1 to the policy enforcement point.

[0338] In this embodiment, steps 407 to 409 are similar to steps 307 to 309 described above. For details, please refer to the relevant descriptions of steps 307 to 309 described above, which will not be repeated here.

[0339] In this embodiment, the step of determining whether the user corresponding to temporary IPv6 address 1 is online is performed by the authentication server, reducing the complexity of the authentication point. This helps to filter out the temporary IPv6 addresses of offline users and avoids the authentication server configuring authorization policies for the temporary IPv6 addresses of offline users.

[0340] It should be noted that whenever a terminal device generates a new temporary IPv6 address, the terminal device, authentication point, and authentication server will again execute steps 301 to 309, or steps 401 to 409. Therefore, MAC address 1 stored in the aforementioned mapping table 1 will correspond to multiple temporary IPv6 addresses, and each temporary IPv6 address will be generated at a different time and have a different validity period. The most recently generated temporary IPv6 address will be the preferred temporary IPv6 address. Temporary IPv6 addresses generated before this most recently generated address will no longer be preferred addresses but will be valid addresses, or expired temporary IPv6 addresses. When an IPv6 address expires, the authentication server needs to revoke the authorization policy corresponding to the expired IPv6 address.

[0341] like Figure 5 The diagram shows the access management method 500 proposed in this application. In this method 500, the terminal device, authentication point, and authentication server will perform the following steps:

[0342] Step 501: The authentication point sends probe message 1 to temporary IPv6 address 2.

[0343] In this context, temporary IPv6 address 2 is any temporary IPv6 address stored within the authentication point. This temporary IPv6 address 2 could be a preferred temporary IPv6 address, a valid temporary IPv6 address, or an invalid temporary IPv6 address. The authentication point needs to determine this based on the probe results.

[0344] In this embodiment, the probe packet 1 can be periodically sent by the authentication point or randomly triggered by the authentication point. Generally, the authentication point periodically sends the probe packet to one or more temporary IPv6 addresses stored in the authentication point. If the temporary IPv6 address is valid, the authentication point receives a response packet based on the probe packet. If the authentication point does not receive the response packet based on the probe packet after a period of time, the authentication point sends the probe packet to the temporary IPv6 address again. If the authentication point sends multiple probe packets but does not receive the response packet based on the probe packet, the authentication point determines that the temporary IPv6 address is invalid.

[0345] Specifically, the authentication point sends the probe packet 1 with the temporary IPv6 address 2 as the destination address and waits for a response packet (hereinafter referred to as the response packet 1) to the probe packet 1. The source address of the response packet 1 should be the temporary IPv6 address 2. If the authentication point does not receive the response packet 1 to the probe packet 1, it determines that the IPv6 address 2 is invalid.

[0346] In a specific implementation, the probe packet 1 and the response packet to the probe packet 1 are based on the neighbor discovery protocol (NDP) packet. For example, the probe packet 1 is a neighbor solicitation packet (i.e., NS packet) and the response packet to the probe packet 1 is a neighbor advertisement packet (i.e., NA packet).

[0347] Step 502: When there is no response packet based on the probe packet 1, the authentication point determines that the temporary IPv6 address 2 is invalid.

[0348] In this embodiment, when the authentication point determines that the temporary IPv6 address 2 is invalid, the authentication point performs step 503.

[0349] Step 503: The authentication point sends a packet 3 to the authentication server.

[0350] The packet 3 is a packet that can carry an IPv6 address, or the packet 3 is a packet that can carry an IPv6 address and a MAC address. The packet 3 includes an indication information 2 indicating that the authentication server triggers the revocation of the authorization policy (e.g., the authorization policy associated with the temporary IPv6 address 2) corresponding to one or more IPv6 addresses of a user.

[0351] In addition, the packet 3 can adopt a newly defined packet format or can adopt a packet format in the prior art. For example, if the authentication server is a Radius server, the packet 3 is a billing packet. The authentication point can trigger the sending of the packet 3 each time the authentication point determines that the temporary IPv6 address 2 is invalid.

[0352] In a specific implementation, the message 3 carries the temporary IPv6 address 2 (i.e. the invalid temporary IPv6 address). In this implementation, the authentication server determines the temporary IPv6 address 2 in the message 3 received by default as the temporary IPv6 address corresponding to the authorization policy to be revoked, and then directly executes the step 505 without executing the step 504, the step 506 and the step 507.

[0353] In another specific implementation, the message 3 carries the temporary IPv6 address 2 (i.e. the invalid temporary IPv6 address) and the MAC address 1 (i.e. the MAC address corresponding to the invalid temporary IPv6 address). The MAC address 1 is used to enable the authentication server to determine the user corresponding to the invalid temporary IPv6 address. In this implementation, the authentication server executes the step 504, and determines whether to execute the step 505 or execute the step 504, the step 506 and the step 507 based on the determination result of the step 504.

[0354] The step 504 is to determine whether the temporary IPv6 address 2 is the last used temporary IPv6 address.

[0355] In this embodiment, the step 504 is an optional step.

[0356] In this step, the authentication server searches the correspondence table 3 to determine whether the temporary IPv6 address 2 is the last used temporary IPv6 address. The last used IPv6 address of the terminal device can also be understood as the currently used IPv6 address of the terminal device. For example, the authentication point stores the generation time, the preferred period and the valid period of each IPv6 address, and determines which IPv6 address among the multiple IPv6 addresses corresponding to the terminal device is the last used IPv6 address of the terminal device according to the above information.

[0357] If the correspondence table 3 stores the temporary IPv6 address 2, and the temporary IPv6 address 2 is the latest temporary IPv6 address stored in the correspondence table 3 among the multiple temporary IPv6 addresses corresponding to the MAC address 1, the authentication server can determine that the IPv6 address 2 is the last used temporary IPv6 address, which can also be understood as the latest temporary IPv6 address.

[0358] When the authentication server determines that the temporary IPv6 address 2 is the last used temporary IPv6 address, the authentication server executes the step 506; when the authentication server determines that the temporary IPv6 address 2 is not the last used temporary IPv6 address, the authentication server executes the step 505.

[0359] Step 505, the authentication server sends a revocation indication 1 to the policy enforcement point.

[0360] In this embodiment, when the authentication server determines that the temporary IPv6 address 2 is not the last used temporary IPv6 address, it indicates that even if the temporary IPv6 address 2 is invalid, other temporary IPv6 addresses of the user corresponding to the temporary IPv6 address 2 are valid, and the user can still transmit service packets using other temporary IPv6 addresses. At this time, the authentication server only needs to revoke the authorization policy corresponding to the temporary IPv6 address 2. Therefore, the revocation indication 1 sent by the authentication server to the policy enforcement point only carries the temporary IPv6 address 2, and does not carry other temporary IPv6 addresses. When the policy enforcement point receives the aforementioned temporary IPv6 address 2, the policy enforcement point deletes all authorization policies corresponding to the temporary IPv6 address 2.

[0361] For example, the policy enforcement point stores authorization policies corresponding to the temporary IPv6 address 2 and the temporary IPv6 address 3, which are: the temporary IPv6 address 2 is allowed to access the IPv6 address C; the temporary IPv6 address 2 is allowed to access the IPv6 address D; and the temporary IPv6 address 3 is allowed to access the IPv6 address E. When the policy enforcement point obtains the temporary IPv6 address 2 in the aforementioned revocation indication 1, the policy enforcement point will delete the two authorization policies of “the temporary IPv6 address 2 is allowed to access the IPv6 address C” and “the temporary IPv6 address 2 is allowed to access the IPv6 address D”, and retain the authorization policy of “the temporary IPv6 address 3 is allowed to access the IPv6 address E”.

[0362] Step 506, the authentication server determines all temporary IPv6 addresses of the user corresponding to the temporary IPv6 address 2.

[0363] In this embodiment, when the authentication server determines that the temporary IPv6 address 2 is the last used temporary IPv6 address, it indicates that other temporary IPv6 addresses of the user corresponding to the temporary IPv6 address 2 have also been invalid, and can also be understood as that the user corresponding to the temporary IPv6 address 2 has been offline. At this time, the authentication server needs to revoke the authorization policies corresponding to all temporary IPv6 addresses of the user. Therefore, the authentication server can determine all temporary IPv6 addresses corresponding to the user according to the MAC address 1 in the indication information 1. For example, all temporary IPv6 addresses corresponding to the MAC address 1 are found from the aforementioned correspondence table 3. Then, the revocation indication 2 in step 507 is sent to the policy enforcement point.

[0364] Step 507, the authentication server sends a revocation indication 2 to the policy enforcement point.

[0365] The revocation instruction 2 carries the user's entire temporary IPv6 address.

[0366] When a policy enforcement point receives all of a user's temporary IPv6 addresses, it will delete the authorization policies corresponding to all of those temporary IPv6 addresses.

[0367] This embodiment proposes that when a temporary IPv6 address expires, the authentication server can revoke the authorization policy corresponding to that expired temporary IPv6 address. Compared to traditional technologies where a user has only one authorization policy corresponding to one IPv6 address and can only revoke that single IPv6 address, this application's solution allows a user to have multiple temporary IPv6 addresses, each with its own authorization policy. Therefore, this application can revoke one of a user's multiple authorization policies. This allows for flexible control over the authorization policies stored at the policy execution point, reducing the complexity of finding authorization policies at the policy execution point.

[0368] like Figure 6 The diagram shows the access management method 600 proposed in this application. In this method 600, the terminal device, authentication point, and authentication server will perform the following steps:

[0369] Step 601: The authentication point determines that temporary IPv6 address 1 is the last temporary IPv6 address used by user A.

[0370] Since the authentication point stores a mapping table 1, it will look up the mapping table 1 to determine whether the temporary IPv6 address 1 is the last used temporary IPv6 address. If the mapping table 1 stores the temporary IPv6 address 1, and among the multiple temporary IPv6 addresses corresponding to the MAC address 1, the temporary IPv6 address 1 is the most recently stored in the mapping table 1, then the authentication server can determine that IPv6 address 1 is the last used temporary IPv6 address, or in other words, that IPv6 address 1 is the latest temporary IPv6 address.

[0371] It should be understood that the status of the last used temporary IPv6 address can reflect the user's status. If the status of the last used temporary IPv6 address is invalid, then the user A corresponding to the last used temporary IPv6 address is offline; if the status of the last used temporary IPv6 address is valid, then the user A corresponding to the last used temporary IPv6 address is online.

[0372] Step 602: The authentication point sends a probe message 2 to temporary IPv6 address 1 (or MAC address 1).

[0373] In one specific implementation, the authentication point sends a probe packet 2 with the temporary IPv6 address 1 as the destination address, and waits for a response packet (hereinafter referred to as response packet 2) to the probe packet 2, the source address of the response packet 2 should be the aforementioned temporary IPv6 address 1. If the authentication point does not receive the response packet 2 to the probe packet 2, it is determined that the user corresponding to the IPv6 address 1 is offline (i.e., user A is offline).

[0374] In another specific implementation, the authentication point sends a probe packet 2 with the MAC address 1 as the destination address, and waits for a response packet (hereinafter referred to as response packet 2) to the probe packet 2, the source address of the response packet 2 should be the aforementioned MAC address 1. If the authentication point does not receive the response packet 2 to the probe packet 2, it is determined that the user corresponding to the MAC address 1 is offline (i.e., user A is offline).

[0375] In addition, the aforementioned probe packet 2 and the response packet to the probe packet 2 are based on the Neighbor Discovery Protocol (NDP) packet. For example, the aforementioned probe packet 2 is a neighbor solicitation packet (i.e., NS packet), and the response packet to the probe packet 2 is a neighbor advertisement packet (i.e., NA packet).

[0376] Step 603: When there is no response packet based on the probe packet 2, the authentication point determines that user A is offline.

[0377] In one specific implementation, after determining that the status of user A is offline, the authentication point will perform step 604. At the same time, the authentication point will refresh the correspondence table 2 stored in the authentication point, i.e., modify the user status information corresponding to user A in the correspondence table 2 to offline. For more information about the correspondence table 2, please refer to the aforementioned step 303.

[0378] Step 604: The authentication point sends a packet 4 to the authentication server.

[0379] The packet 4 is a packet that can carry an IPv6 address, or the packet 4 is a packet that can carry a MAC address, or the packet 4 is a packet that can carry a user identifier. The packet 4 contains indication information 2, which is used to indicate that the authentication server triggers to revoke the authorization policy corresponding to one or more IPv6 addresses of a user.

[0380] In addition, the aforementioned packet 4 can adopt a newly defined packet format, or can adopt a packet format in the conventional technology. For example, if the authentication server is a Radius server, the aforementioned packet 4 is a charging packet. The authentication point can trigger to send the aforementioned packet 4 every time the authentication point determines that a user is offline.

[0381] In one embodiment, the message 4 carries information indicating all IPv6 addresses of user A. For example, the MAC address 1 (i.e. the MAC address of user A), the user identification of user A.

[0382] Specifically, the authentication point stores the correspondence table 1 and / or the correspondence table 2, and can find the MAC address (i.e. the MAC address 1) corresponding to the temporary IPv6 address 1 from the correspondence table 1 and / or the correspondence table 2. Similarly, the authentication point can find the user identification (i.e. the user identification of user A) of the user corresponding to the MAC address 1 from the correspondence table 1 and / or the correspondence table 2 based on the MAC address 1. When this embodiment is adopted, the authentication server will perform step 605 first and then perform step 606 after receiving the message 4.

[0383] In another embodiment, the message 4 carries all IPv6 addresses of user A.

[0384] Specifically, the authentication point finds the MAC address (i.e. the MAC address 1) corresponding to the temporary IPv6 address 1 from the correspondence table 1 and / or the correspondence table 2, and further finds all temporary IPv6 addresses (i.e. all IPv6 addresses of user A) corresponding to the MAC address 1. When this embodiment is adopted, the authentication server will directly perform step 606 after receiving the message 4.

[0385] It should be noted that in the conventional art, a user has only one IPv6 address corresponding to an authorization policy, and thus only the authorization policy corresponding to the one IPv6 address can be revoked. In the present application, a user can have multiple different temporary IPv6 addresses corresponding to authorization policies, and thus multiple different temporary IPv6 addresses of the user can be revoked.

[0386] Step 605: The authentication server determines all temporary IPv6 addresses of user A.

[0387] When step 605 is performed, the authentication server queries the MAC address 1 (i.e. the MAC address of user A) or the user identification of user A from the correspondence table 3 and / or the correspondence table 4 to find all temporary IPv6 addresses of user A.

[0388] Step 606: The authentication server sends a revocation indication 2 to the policy enforcement point.

[0389] The revocation indication 2 carries all temporary IPv6 addresses of user A.

[0390] When the policy enforcement point receives all temporary IPv6 addresses of user A, the policy enforcement point deletes the authorization policies corresponding to the all temporary IPv6 addresses.

[0391] In this embodiment, the authentication point has the ability to determine whether the temporary IPv6 address is the latest temporary IPv6 address. Therefore, the authentication point can find the latest temporary IPv6 address and determine whether the user has logged off by probing this latest temporary IPv6 address. In this embodiment, the number of probe packets sent by the authentication point can be reduced, which is beneficial to improving the efficiency of maintaining the mapping table 2. In addition, the authentication server can determine all corresponding temporary IPv6 addresses based on the authentication point's revocation instruction 2 and the internally stored mapping table 3 and / or mapping table 4, without having to carry all temporary IPv6 addresses in the revocation instruction 2. This helps to reduce the complexity of the revocation instruction 2 and reduce the transmission load of the revocation instruction 2.

[0392] like Figure 7 The diagram shows the access management method 700 proposed in this application, which is executed by an authentication point. This access management method 700 can be applied to the aforementioned... Figure 3 The method 300 described in the corresponding embodiment, and the aforementioned Figure 4 The steps performed by the authentication point in method 400 described in the corresponding embodiment. Specifically, after the terminal device completes access authentication, the access management method 700 includes:

[0393] Step 701: Receive the first message.

[0394] The first message carries the first IPv6 address and the MAC address of the terminal device. The first IPv6 address is a newly generated temporary IPv6 address of the terminal device.

[0395] In this method, the first message in method 700 can correspond to message 1 in method 300; the first IPv6 address in method 700 can correspond to IPv6 address 1 in method 300; and the MAC address in method 700 can correspond to MAC address 1 in method 300.

[0396] Alternatively, the first message in method 700 can correspond to message 1 in method 400; the first IPv6 address in method 700 can correspond to IPv6 address 1 in method 400; and the MAC address in method 700 can correspond to MAC address 1 in method 400.

[0397] Step 702: Determine that the first IPv6 address is the new IPv6 address.

[0398] In one implementation, the authentication point does not store the mapping between the MAC address and the first IPv6 address before receiving the first message.

[0399] Step 703: Send the second message to the authentication server.

[0400] The second message carries the first IPv6 address and the MAC address, and is used to instruct the authentication server to send a first authorization policy to a policy enforcement point according to the first IPv6 address.

[0401] The second message in the method 700 can correspond to the message 2 in the method 300, or the second message in the method 700 can correspond to the message 2 in the method 400.

[0402] In an implementation manner, after receiving the first message, the authentication point stores the correspondence between the MAC address and the first IPv6 address.

[0403] In an implementation manner, before receiving the first message, the authentication point stores a correspondence between the MAC address and at least one IPv6 address, the MAC address corresponding to each of the at least one IPv6 address one by one, and the at least one IPv6 address being an IPv6 address used by the terminal device before or after sending the first message.

[0404] In an implementation manner, the authentication point stores a first correspondence table used to store the correspondence between the MAC address and the first IPv6 address.

[0405] The first correspondence table in the method 700 can correspond to the correspondence table 1 in the method 300 or the method 400.

[0406] For example, the first correspondence table can be shown in the foregoing table 1-1, table 1-2, table 1-3, and table 1-4.

[0407] In an implementation manner, the authentication point stores a first correspondence table used to store the correspondence between the MAC address and the at least one IPv6 address.

[0408] In an implementation manner, before receiving the first message, the authentication point stores a correspondence between the MAC address and user information.

[0409] In an implementation manner, the authentication point stores a second correspondence table used to store the correspondence between the MAC address and the user information.

[0410] The first correspondence table in the method 700 can correspond to the correspondence table 2 in the method 300 or the method 400.

[0411] For example, the first correspondence table can be shown in the foregoing table 2-1 or table 2-2.

[0412] In an implementation, the second correspondence table further comprises a correspondence between the MAC address and the first IPv6 address. It can also be understood that the second correspondence table comprises the first correspondence table described above. At this time, the content in the first correspondence table in the foregoing embodiment and the content in the second correspondence table are stored in one table. For example, the table 2-3 described above.

[0413] In an implementation, the user information comprises a user identity. The user identity can be a user identity document (user ID), a user name, or any information that can uniquely identify a user.

[0414] In an implementation, the user information comprises user state information.

[0415] In an implementation, before sending the second packet, the method further comprises: determining that the user is online according to the user state information.

[0416] In an implementation, before determining that the user is online according to the user state information, the method further comprises: determining the user identity according to the MAC address; and determining the user state information according to the user identity.

[0417] In an implementation, the first correspondence table stored in the authentication point is a neighbor discovery table or a neighbor discovery probe table.

[0418] In an implementation, the second correspondence table stored in the authentication point is a neighbor discovery table or a neighbor discovery probe table.

[0419] In an implementation, the second packet is used to indicate that the first IPv6 address is a new IPv6 address.

[0420] In an implementation, the second packet comprises first indication information, and the first indication information is used to indicate that the first IPv6 address is a new IPv6 address.

[0421] In the method 700, the first indication information can correspond to the indication information 1 in the method 300 or the method 400.

[0422] For example, the first indication information can be represented by the type in the attribute field in the table 3-1 described above.

[0423] In an implementation, the first indication information is further used to indicate that the authentication server determines the first authorization policy according to the first IPv6 address.

[0424] The first indication information in the method 700 can correspond to the authorization policy 1 in the method 300 or the method 400.

[0425] In an implementation manner, the second packet is not an authentication request packet.

[0426] In an implementation manner, the second packet is a charging packet.

[0427] In an implementation manner, the first packet is a neighbor solicitation (NS) packet.

[0428] In an implementation manner, the method further includes: when a second IPv6 address in the plurality of IPv6 addresses of the terminal device is invalid, sending a third packet to the authentication server, the third packet including the second IPv6 address and second indication information, the second indication information being used to indicate that the second IPv6 address is an invalid IPv6 address.

[0429] The second IPv6 address in the method 700 can correspond to the IPv6 address 2 in the method 500, the third packet in the method 700 can correspond to the packet 3 in the method 500, and the second indication information in the method 700 can correspond to the indication information 2 in the method 500.

[0430] In an implementation manner, the second indication information is further used to indicate that the authentication server revokes an authorization policy corresponding to the second IPv6 address.

[0431] In an implementation manner, before the third packet is sent to the authentication server, the method further includes: sending a first probe packet, a destination address of the first probe packet being the second IPv6 address; and in response to a first response packet from the second IPv6 address not being received in response to the first probe packet, determining that the second IPv6 address is invalid.

[0432] The first probe packet in the method 700 can correspond to the probe packet 1 in the method 500, and the first response packet in the method 700 can correspond to the response packet 1 in the method 500.

[0433] In an implementation manner, the method further includes: determining that a third IPv6 address in the plurality of IPv6 addresses of the terminal device is invalid, the third IPv6 address being a last used IPv6 address of the terminal device; and sending a fourth packet to the authentication server, the fourth packet including third indication information, the third indication information being used to indicate that a user using the terminal device corresponding to the third IPv6 address is offline.

[0434] The third IPv6 address in the method 700 can correspond to the temporary IPv6 address 1 in the method 600.

[0435] In an implementation manner, the third indication information is further used for instructing the authentication server to revoke the authorization policy corresponding to all IPv6 addresses of the user.

[0436] In an implementation manner, the fourth message comprises at least one of the following: a user identifier corresponding to the third IPv6 address; or a MAC address corresponding to the third IPv6 address; or all IPv6 addresses of the user corresponding to the third IPv6 address.

[0437] The MAC address in the method 700 can correspond to the MAC address 1 in the method 600.

[0438] In an implementation manner, the authentication point determines that a third IPv6 address in the plurality of IPv6 addresses of the terminal device is invalid, and specifically, the authentication point sends a second probe message, a destination address of the second probe message being the third IPv6 address; and in response to not receiving a second response message from the third IPv6 address and for the second probe message, it is determined that the third IPv6 address is invalid.

[0439] The second probe message in the method 700 can correspond to the probe message 2 in the method 600.

[0440] In an implementation manner, the policy enforcement point is the authentication point.

[0441] In an implementation manner, before the first message is received, the method further comprises: receiving a fifth message sent by the terminal device, the fifth message comprising a fourth IPv6 address and the MAC address of the terminal device; and sending a sixth message to the authentication server, the sixth message comprising the fourth IPv6 address and the MAC address, the sixth message being used for instructing the authentication server to send a second authorization policy to the policy enforcement point according to the fourth IPv6 address.

[0442] The fifth message in the method 700 can correspond to the message in which the temporary IPv6 address 0 and the MAC address 1 are encapsulated in step 204 in the method 200, wherein the fourth IPv6 address corresponds to the temporary IPv6 address 0, and the MAC address corresponds to the MAC address 1. The sixth message in the method 700 can correspond to the message in which the temporary IPv6 address 0 and the MAC address 1 are encapsulated in step 211 in the method 200.

[0443] In one implementation, the sixth message is an authentication request message.

[0444] In one implementation, the second authorization policy includes access permissions for the terminal device corresponding to the fourth IPv6 address.

[0445] In this method, the second authorization strategy can correspond to authorization strategy 0 in method 200.

[0446] In one implementation, the first authorization policy includes access permissions for the terminal device corresponding to the first IPv6 address.

[0447] The second authorization strategy in method 700 can correspond to authorization strategy 1 in method 300 or method 400.

[0448] In one implementation, the first authorization policy includes access permissions for the terminal device corresponding to the first IPv6 address, wherein the access permissions for the terminal device corresponding to the fourth IPv6 address are the same as the access permissions for the terminal device corresponding to the first IPv6 address.

[0449] In this embodiment, because the authentication point can send the new IPv6 address to the authentication server, the authentication server can formulate a first authorization policy for network access based on the first IPv6 address. Therefore, the service packets of the terminal device can be transmitted through the policy enforcement point to the address or network segment that allows the user to access. Thus, even if the IPv6 address of the terminal device changes, the service will not be interrupted.

[0450] like Figure 8 The diagram shows the access management method 800 proposed in this application, which is executed by an authentication server. This access management method 800 can be applied to the aforementioned... Figure 3 The method 300 described in the corresponding embodiment, and the aforementioned Figure 4 The steps performed by the authentication server in method 400 described in the corresponding embodiment. Specifically, after the terminal device completes access authentication, the access management method 800 includes:

[0451] Step 801: Receive the first message from the authentication point.

[0452] The first message includes the terminal device's first IPv6 address and the terminal device's MAC address, where the first IPv6 address is the terminal device's new temporary IPv6 address.

[0453] The first message in the method 800 can correspond to the message 2 in the method 300; the first IPv6 address in the method 800 can correspond to the IPv6 address 1 in the method 300; and the first MAC address in the method 800 can correspond to the MAC address 1 in the method 300.

[0454] Alternatively, the first message in the method 800 can correspond to the message 2 in the method 400; the first IPv6 address in the method 800 can correspond to the IPv6 address 1 in the method 400; and the first MAC address in the method 800 can correspond to the MAC address 1 in the method 400.

[0455] In step 802, the first IPv6 address is determined as a new IPv6 address according to the MAC address.

[0456] In an implementation, before receiving the first message, the authentication server does not store the correspondence between the MAC address and the first IPv6 address.

[0457] In another implementation, the first message is used to indicate that the first IPv6 address is a new IPv6 address.

[0458] In another implementation, the first message includes first indication information, which is used to indicate that the first IPv6 address is a new IPv6 address.

[0459] In an implementation, the first indication information is further used to indicate that the authentication server determines the first authorization policy according to the first IPv6 address.

[0460] The first indication information in the method 800 can correspond to the indication information 2 in the method 300; and the first authorization policy in the method 800 can correspond to the authorization policy 1 in the method 300.

[0461] In step 803, a first authorization policy corresponding to the first IPv6 address is determined.

[0462] In step 804, the first authorization policy is sent to a policy enforcement point.

[0463] In an implementation, after receiving the first message, the method further includes:

[0464] The correspondence between the MAC address and the first IPv6 address is stored.

[0465] In an implementation, the authentication server stores a correspondence between the MAC address and at least one IPv6 address before receiving the first packet, the MAC address corresponding to each of the at least one IPv6 address one by one, the at least one IPv6 address being an IPv6 address used by the terminal device before using the first IPv6 address.

[0466] In an implementation, the authentication server stores a first correspondence table for storing a correspondence between the MAC address and the first IPv6 address.

[0467] In an implementation, the first correspondence table in the method 800 can correspond to the correspondence table 3 in the method 300 or the method 400.

[0468] In an implementation, the authentication server stores a first correspondence table for storing a correspondence between the MAC address and at least one IPv6 address.

[0469] In an implementation, the authentication server stores a correspondence between the MAC address and user information before receiving the first packet.

[0470] In an implementation, the authentication server stores a second correspondence table for storing a correspondence between the MAC address and the user information.

[0471] In an implementation, the first correspondence table in the method 800 can correspond to the correspondence table 4 in the method 300 or the method 400.

[0472] In an implementation, the authentication server stores a second correspondence table for storing a correspondence between the MAC address and user information.

[0473] In an implementation, the second correspondence table further includes a correspondence between the MAC address and the first IPv6 address. It can also be understood that the second correspondence table includes the first correspondence table.

[0474] In an implementation, the user information includes a user identifier. The user identifier can be a user identity number, a user name, or any information capable of uniquely identifying a user.

[0475] In an implementation, the user information includes a user's access right.

[0476] In an implementation, the authentication server stores a correspondence between the user identifier and the access right before receiving the first packet.

[0477] In an implementation, the authentication server stores a second correspondence table, which is used to store the correspondence between the user identifier and the access right.

[0478] In an implementation, the user information comprises user state information.

[0479] In an implementation, after determining that the first IPv6 address is a new IPv6 address according to the MAC address, before sending the first authorization policy corresponding to the first IPv6 address to the policy enforcement point, the method further comprises:

[0480] determining that the user is online according to the first IPv6 address.

[0481] In an implementation, according to the user state information, determining that the user is online comprises: determining the user identifier according to the MAC address; and determining the user state information according to the user identifier.

[0482] In an implementation, the determining the first authorization policy corresponding to the first IPv6 address comprises: determining the access right of the user corresponding to the first IPv6 address according to the MAC address; and determining the first authorization policy according to the first IPv6 address and the access right.

[0483] In an implementation, the determining the first authorization policy corresponding to the first IPv6 address comprises: determining the user identifier of the user corresponding to the first IPv6 address according to the MAC address; determining the access right of the user according to the user identifier; and determining the first authorization policy according to the first IPv6 address and the access right.

[0484] In an implementation, the first message is not an authentication request message.

[0485] In an implementation, the first message is a charging message.

[0486] In an implementation, the method further comprises: receiving a second message from the self-authentication point, the second message comprising a second IPv6 address and second indication information, the second indication information being used to indicate that the second IPv6 address is an invalid IPv6 address, the second IPv6 address being one of the multiple IPv6 addresses of the terminal device; and sending a first revocation indication to the policy enforcement point, the first revocation indication being used to instruct the policy enforcement point to revoke an authorization policy corresponding to the second IPv6 address, the first revocation indication carrying the second IPv6 address.

[0487] The second IPv6 address in the method 800 can correspond to the IPv6 address 2 in the method 500, the second message in the method 800 can correspond to the message 3 in the method 500, the second indication information in the method 800 can correspond to the indication information 2 in the method 500, and the revocation indication in the method 800 can correspond to the revocation indication 1 in the method 500.

[0488] In an implementation manner, the second indication information is further used to instruct the authentication server to revoke the authorization policy corresponding to the second IPv6 address.

[0489] In an implementation manner, the method further includes: receiving a third message from the authentication point, the third message including third indication information, the third indication information being used to indicate that a user of a terminal device corresponding to a third IPv6 address is offline, the third IPv6 address being the last used IPv6 address of the terminal device; and sending a second revocation indication to a policy execution point, the second revocation indication being used to instruct the policy execution point to revoke the authorization policy corresponding to all IPv6 addresses of the user corresponding to the third IPv6 address.

[0490] The third IPv6 address in the method 800 can correspond to the IPv6 address 1 in the method 600, the third message in the method 800 can correspond to the message 4 in the method 600, the third indication information in the method 800 can correspond to the indication information 2 in the method 600, the revocation indication in the method 800 can correspond to the revocation indication 2 in the method 600, and the user in the method 800 can correspond to the user A in the method 600.

[0491] In an implementation manner, the third indication information is further used to instruct the authentication server to revoke the authorization policy corresponding to all IPv6 addresses of the user corresponding to the third IPv6 address.

[0492] In an implementation manner, the third message includes at least one of the following: a user identifier corresponding to the third IPv6 address; or a MAC address corresponding to the third IPv6 address; or all IPv6 addresses corresponding to the user corresponding to the third IPv6 address.

[0493] In an implementation manner, the revocation indication carries all IPv6 addresses corresponding to the user corresponding to the third IPv6 address.

[0494] In an implementation manner, the policy execution point is the authentication point.

[0495] In one implementation, before the authentication server receives the first message from the authentication point, the method further includes: receiving a fourth message from the authentication point, the fourth message including the fourth IPv6 address of the terminal device and the MAC address; determining the fourth IPv6 address as a new IPv6 address based on the MAC address; determining a second authorization policy corresponding to the fourth IPv6 address; and sending the second authorization policy to the policy enforcement point.

[0496] In this method, the fourth message can correspond to the message encapsulated with temporary IPv6 address 0 and MAC address 1 in step 211 of method 200, wherein the fourth IPv6 address corresponds to temporary IPv6 address 0 and the MAC address corresponds to MAC address 1.

[0497] In one implementation, determining the second authorization policy corresponding to the fourth IPv6 address includes: determining the user's access permissions based on the correspondence between the MAC address and the user's access permissions; and determining the second authorization policy corresponding to the fourth IPv6 address based on the user's access permissions.

[0498] In this case, the second authorization strategy in method 800 can correspond to authorization strategy 0 in method 200.

[0499] In one implementation, the fourth message is an authentication request message.

[0500] In this embodiment, when the authentication point receives a first packet carrying a first IPv6 address and MAC address from the terminal device, it will, upon determining that the first IPv6 address is a new IPv6 address, send the first IPv6 address and MAC address to the authentication server. The authentication server then determines a first authorization policy to be sent to the policy enforcement point (i.e., the gateway) based on this first IPv6 address. Since the first authorization policy sent by the authentication server is determined based on the first IPv6 address (i.e., the new IPv6 address), after the policy enforcement point receives the aforementioned first authorization policy, the terminal device's service packets can be transmitted through the policy enforcement point to the address or network segment that allows the user access. Therefore, even if the terminal device's IPv6 address changes, the service will not be interrupted.

[0501] like Figure 9 The diagram shows the access management method 900 proposed in this application, which is executed by an authentication point. This access management method 900 can be applied to the aforementioned... Figure 3 The method 300 described in the corresponding embodiment, and the aforementioned Figure 4 The steps performed by the authentication point in the method 400 described in the corresponding embodiment. The access management method 900 includes:

[0502] Step 901, determining that a first IPv6 address in multiple IPv6 addresses of a terminal device is invalid.

[0503] Step 902, sending a first message to an authentication server.

[0504] The first message carries the first IPv6 address, and the first message includes first indication information, the first indication information being used to indicate that the first IPv6 address is an invalid IPv6 address.

[0505] The first IPv6 address in the method 900 can correspond to the temporary IPv6 address 2 in the method 500; the first message in the method 900 can correspond to the message 3 in the method 500; and the first indication information in the method 900 can correspond to the indication information 1 in the method 500.

[0506] In an implementation manner, the first indication information is further used to indicate that the authentication server revokes an authorization policy corresponding to the first IPv6 address.

[0507] In an implementation manner, before the first message is sent to the authentication server, the method further includes: sending a probe message, a destination address of the probe message being the first IPv6 address; and in response to that no response message from the first IPv6 address is received for the probe message, determining that the first IPv6 address is invalid.

[0508] The probe message in the method 900 can correspond to the probe message 1 in the method 500; and the response message in the method 900 can correspond to the response message 1 in the method 500.

[0509] In an implementation manner, the method further includes: determining that a second IPv6 address in multiple IPv6 addresses of the terminal device is invalid; and sending a second message to the authentication server, the first message including the second IPv6 address and second indication information, the second indication information being used to indicate that the second IPv6 address is an invalid IPv6 address.

[0510] As shown in FIG. 10, an access management method 1000 is provided in the present application, and the method 1000 is executed by an authentication server. The access management method 1000 can be applied to the method 300 introduced in the foregoing corresponding embodiments, the method 400 introduced in the foregoing corresponding embodiments, and the steps executed by the authentication server in the method 400 introduced in the foregoing corresponding embodiments. The authentication server stores a corresponding relationship between multiple IPv6 addresses of a terminal device, a MAC address of the terminal device, and access permissions of a user using the terminal device, and the access management method 1000 includes the following steps. Figure 10 Figure 3 Figure 4

[0511] ​​​Step 1001: Receive the first message from the authentication point.

[0512] The first message includes a first IPv6 address among multiple IPv6 addresses of the terminal device and a first indication message, which indicates that the first IPv6 address is an invalid IPv6 address.

[0513] In this method, the first IPv6 address in method 1000 can correspond to the temporary IPv6 address 2 in method 500; the first message in method 1000 can correspond to the message 3 in method 500; and the first indication information in method 1000 can correspond to the indication information 1 in method 500.

[0514] Step 1002: Send the first revocation instruction to the policy execution point.

[0515] The first revocation instruction carries the first IPv6 address and is used to instruct the policy enforcement point to revoke the authorization policy corresponding to the first IPv6 address.

[0516] In this method, the first cancellation instruction can correspond to cancellation instruction 1 in method 500.

[0517] In one implementation, the first instruction information is further used to instruct the authentication server to revoke the authorization policy corresponding to the first IPv6 address.

[0518] In one implementation, the method further includes: receiving a second message from an authentication point, the second message carrying a second IPv6 address, the second message including second indication information, the second indication information being used to indicate that the second IPv6 address is an invalid IPv6 address; and sending a second revocation indication to a policy enforcement point, the second revocation indication carrying the second IPv6 address, the second revocation indication being used to instruct the policy enforcement point to revoke the authorization policy corresponding to the second IPv6 address.

[0519] like Figure 11 The diagram shows the access management method 1100 proposed in this application, which is executed by an authentication point. This access management method 1100 can be applied to the aforementioned... Figure 3 The method 300 described in the corresponding embodiment, and the aforementioned Figure 4 The steps performed by the authentication point in method 400 described in the corresponding embodiment. The access management method 1100 includes:

[0520] Step 1101: Determine that the first IPv6 address among the multiple IPv6 addresses of the terminal device is invalid.

[0521] The first IPv6 address is the last IPv6 address used by the terminal device.

[0522] Step 1102: Send the first message to the authentication server.

[0523] The first message includes a first instruction message, which is used to instruct the user of the terminal device corresponding to the first IPv6 address to go offline.

[0524] In this method, the first IPv6 address in method 1100 can correspond to the temporary IPv6 address 1 in method 600; the first message in method 1100 can correspond to message 4 in method 600; and the first indication information in method 1100 can correspond to indication information 2 in method 600.

[0525] In one implementation, the first instruction information is further used to instruct the authentication server to revoke the authorization policies corresponding to all IPv6 addresses associated with the user.

[0526] In one implementation, the first message includes at least one of the following: the user identifier corresponding to the first IPv6 address; or, the MAC address corresponding to the first IPv6 address; or, all IPv6 addresses corresponding to the user corresponding to the first IPv6 address.

[0527] In one implementation, determining that a first IPv6 address among a plurality of IPv6 addresses of a terminal device is invalid includes: sending a probe message whose destination address is the first IPv6 address; and determining that the first IPv6 address is invalid in response to not receiving a response message from the first IPv6 address for the probe message.

[0528] In this method, the probe message in method 1100 can correspond to probe message 1 in method 500; the response message in method 1100 can correspond to response message 1 in method 500.

[0529] like Figure 12 The diagram shows the access management method 1200 proposed in this application, which is executed by an authentication server. This access management method 1200 can be applied to the aforementioned... Figure 3 The method 300 described in the corresponding embodiment, and the aforementioned Figure 4 The steps performed by the authentication server in method 400 described in the corresponding embodiment. The authentication server stores the correspondence between multiple IPv6 addresses of the terminal device, the MAC address of the terminal device, and the access permissions of users using the terminal device. The access management method 1200 includes:

[0530] Step 1201: Receive the first message from the authentication point.

[0531] The first message includes first indication information, the first indication information being used to indicate that a user of a terminal device corresponding to the first IPv6 address is offline, and the first IPv6 address being the last used IPv6 address of the terminal device.

[0532] Step 1202, sending a revocation indication to a policy enforcement point.

[0533] The revocation indication is used to instruct the policy enforcement point to revoke authorization policies corresponding to all IPv6 addresses of the user corresponding to the first IPv6 address.

[0534] The first IPv6 address in the method 1200 can correspond to the temporary IPv6 address 1 in the method 600; the first message in the method 1200 can correspond to the message 4 in the method 600; the first indication information in the method 1200 can correspond to the indication information 2 in the method 600; and the revocation indication in the method 1200 can correspond to the revocation indication 2 in the method 600.

[0535] In an implementation manner, the first indication information is further used to instruct the authentication server to revoke authorization policies corresponding to all IPv6 addresses of the user corresponding to the first IPv6 address.

[0536] In an implementation manner, the first message includes at least one of the following: a user identifier of the user corresponding to the first IPv6 address; or a MAC address corresponding to the first IPv6 address; or all IPv6 addresses of the user corresponding to the third IPv6 address.

[0537] In an implementation manner, the revocation indication carries all IPv6 addresses of the user corresponding to the third IPv6 address.

[0538] In addition, the embodiment of the present application further provides a communication device 1300, as shown in Figure 13 , Figure 13 a structural schematic diagram of a communication device provided by the embodiment of the present application.

[0539] The communication device 1300 can be used to execute the method 200, the method 300, the method 400, the method 500, the method 600, the method 700, the method 800, the method 900, the method 1000, the method 1100 or the method 1200 in the above embodiments.

[0540] As shown in Figure 13 , the communication device 1300 can include a processor 1310, a memory 1320 and a transceiver 1330. The processor 1310 is coupled to the memory 1320, and the processor 1310 is coupled to the transceiver 1330.

[0541] The transceiver 1330 can also be referred to as a transceiving unit, a transceiver, a transceiving device, etc. Optionally, a device in the transceiving unit for implementing a receiving function can be regarded as a receiving unit, and a device in the transceiving unit for implementing a sending function can be regarded as a sending unit, i.e., the transceiving unit includes the receiving unit and the sending unit, the receiving unit can also be referred to as a receiver, an input port, a receiving circuit, etc., and the sending unit can be referred to as a transmitter, a transmitter, or a transmitting circuit, etc. For example, the transceiver 1330 can be an optical module.

[0542] The processor 1310 can be a central processing unit (CPU), a network processor (NP), or a combination thereof. The processor can also be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The PLD can be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. The processor 1310 can refer to one processor or can include a plurality of processors.

[0543] Furthermore, the aforementioned memory 1320 is primarily used to store software programs and data. The memory 1320 can exist independently, connected to the processor 1310. Optionally, the memory 1320 can be integrated with the processor 1310, for example, integrated within one or more chips. The memory 1320 can store program code executing the technical solutions of the embodiments of this application, and its execution is controlled by the processor 1310. The various types of computer program code being executed can also be considered as drivers for the processor 1310. The memory 1320 may include volatile memory, such as random-access memory (RAM); the memory may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid-state drive (SSD); the memory 1320 may also include combinations of the above types of memory. The memory 1320 may refer to a single memory or may include multiple memories.

[0544] In one implementation, memory 1320 stores computer-readable instructions, which include multiple software modules, such as a sending module 1321, a processing module 1322, and a receiving module 1323. After executing each software module, processor 1310 can perform corresponding operations according to the instructions of each software module. In this embodiment, the operation performed by a software module actually refers to the operation performed by processor 1310 according to the instructions of the software module.

[0545] It should be understood that the aforementioned Figure 2 , Figure 3 , Figure 4 , Figure 5 , Figure 6 , Figure 7 , Figure 8 , Figure 9 , Figure 10 , Figure 11 and Figure 12 The authentication points in the corresponding method embodiments can all be based on this embodiment. Figure 13 The structure of the communication device 1300 shown.

[0546] Exemplarily, when the communication apparatus 1300 is configured to perform the method 300 of the above embodiment, the receiving module 1323 is configured to receive the message 1 from the terminal device. The sending module 1321 is configured to send the message 2 to the authentication server. The processing module 1322 is configured to determine that the temporary IPv6 address 1 is a new temporary IPv6 address, and determine that the user corresponding to the temporary IPv6 address 1 is online.

[0547] Exemplarily, when the communication apparatus 1300 is configured to perform the method 500 of the above embodiment, the sending module 1321 is configured to send the probe message 1 to the temporary IPv6 address 2, and send the message 3 to the authentication server. The processing module 1322 is configured to determine that the temporary IPv6 address 2 is invalid when there is no response message based on the probe message 1.

[0548] Exemplarily, when the communication apparatus 1300 is configured to perform the method 600 of the above embodiment, the sending module 1321 is configured to send the probe message 2 to the temporary IPv6 address 1, and send the message 4 to the authentication server. The processing module 1322 is configured to determine that the user corresponding to the temporary IPv6 address 1 is offline when there is no response message based on the probe message 2.

[0549] The rest can refer to the method of the authentication point in the above embodiment, which will not be repeated here.

[0550] It should also be understood that the foregoing Figure 2 , Figure 3 , Figure 4 , Figure 5 , Figure 6 , Figure 7 , Figure 8 , Figure 9 , Figure 10 , Figure 11 and Figure 12 corresponding method embodiments of the authentication server can also be based on the structure of the communication apparatus 1300 shown in the embodiment. Figure 13

[0551] Exemplarily, when the communication apparatus 1300 is configured to perform the method 300 of the above embodiment, the receiving module 1323 is configured to receive the message 2 from the authentication point. The sending module 1321 is configured to send the authorization policy 1 to the policy enforcement point. The processing module 1322 is configured to store the temporary IPv6 address 1 and the MAC address 1 in correspondence, and determine that the authorization policy 1 corresponding to the temporary IPv6 address 1.

[0552] Exemplarily, when the communication apparatus 1300 is configured to perform the method 400 of the above embodiment, the processing module 1322 is further configured to determine that the user corresponding to the temporary IPv6 address 1 is online.

[0553] ​Exemplarily, when the communication apparatus 1300 is configured to perform the method 500 of the above embodiments, the receiving module 1323 is configured to receive the message 3 from the authentication point. The sending module 1321 is configured to send the revocation indication 1 to the policy enforcement point; and send the revocation indication 2 to the policy enforcement point. The processing module 1322 is configured to determine whether the temporary IPv6 address 2 is the latest temporary IPv6 address; and determine all the temporary IPv6 addresses of the user corresponding to the temporary IPv6 address 2.

[0554] Exemplarily, when the communication apparatus 1300 is configured to perform the method 600 of the above embodiments, the receiving module 1323 is configured to receive the message 4 from the authentication point. The sending module 1321 is configured to send the revocation indication 2 to the policy enforcement point. The processing module 1322 is configured to determine whether the temporary IPv6 address 1 is the latest temporary IPv6 address; and determine all the temporary IPv6 addresses of the user corresponding to the temporary IPv6 address 1.

[0555] The rest can refer to the method of the authentication server in the above embodiments, which will not be repeated here.

[0556] In addition, the embodiment of the present application further provides a communication apparatus 1400, which can be used for performing the method 200, the method 300, the method 400, the method 500, the method 600, the method 700, the method 800, the method 900, the method 1000, the method 1100 or the method 1200 in the above embodiments. Figure 14 Figure 14 The communication apparatus 1400 provided by the embodiment of the present application is a structure diagram of a communication apparatus. The communication apparatus 1400 comprises a transceiver unit 1401 and a processing unit 1402. The communication apparatus 1400 can be used for performing the method 200, the method 300, the method 400, the method 500, the method 600, the method 700, the method 800, the method 900, the method 1000, the method 1100 or the method 1200 in the above embodiments.

[0557] In one example, the communication apparatus 1400 can perform the method 300 in the above embodiments. When the communication apparatus 1400 is configured to perform the method 300 in the above embodiments, the communication apparatus 1400 corresponds to the authentication point in the method 300. The transceiver unit 1401 is configured to perform the transceiving operation performed by the authentication point in the method 300. The processing unit 1402 is configured to perform the operation performed by the authentication point in the method 300, except the transceiving operation. For example, the transceiver unit 1401 is configured to receive the message 1 from the terminal device; and send the message 2 to the authentication server. The processing unit 1402 is configured to determine that the temporary IPv6 address 1 is a new temporary IPv6 address; and determine that the user corresponding to the temporary IPv6 address 1 is online.

[0558] ​In one example, the communication apparatus 1400 can perform the method 300 in the above embodiments, when the communication apparatus 1400 is configured to perform the method 300 in the above embodiments, the communication apparatus 1400 corresponds to the authentication server in the method 300. The transceiver unit 1401 is configured to perform the transceiving operations performed by the authentication server in the method 300. The processing unit 1402 is configured to perform the operations performed by the authentication server in the method 300 other than the transceiving operations. For example, the transceiver unit 1401 is configured to receive the message 2 from the authentication point; send the authorization policy 1 to the policy enforcement point. The processing unit 1402 is configured to store the temporary IPv6 address 1 and the MAC address 1 correspondingly; determine the authorization policy 1 corresponding to the temporary IPv6 address 1.

[0559] In one example, the communication apparatus 1400 can perform the method 500 in the above embodiments, when the communication apparatus 1400 is configured to perform the method 500 in the above embodiments, the communication apparatus 1400 corresponds to the authentication point in the method 500. The transceiver unit 1401 is configured to perform the transceiving operations performed by the authentication point in the method 500. The processing unit 1402 is configured to perform the operations performed by the authentication point in the method 500 other than the transceiving operations. For example, the transceiver unit 1401 is configured to send the probe message 1 to the temporary IPv6 address 2; send the message 3 to the authentication server. The processing unit 1402 is configured to determine that the temporary IPv6 address 2 is invalid when there is no response message based on the probe message 1.

[0560] In one example, the communication apparatus 1400 can perform the method 500 in the above embodiments, when the communication apparatus 1400 is configured to perform the method 500 in the above embodiments, the communication apparatus 1400 corresponds to the authentication server in the method 500. The transceiver unit 1401 is configured to perform the transceiving operations performed by the authentication server in the method 500. The processing unit 1402 is configured to perform the operations performed by the authentication server in the method 500 other than the transceiving operations. For example, the transceiver unit 1401 is configured to receive the message 3 from the authentication point; send the revocation indication 1 to the policy enforcement point; send the revocation indication 2 to the policy enforcement point. The processing unit 1402 is configured to determine whether the temporary IPv6 address 2 is the latest temporary IPv6 address; determine all the temporary IPv6 addresses of the user corresponding to the temporary IPv6 address 2.

[0561] In one example, the communication apparatus 1400 can perform the method 600 in the above embodiments, when the communication apparatus 1400 is configured to perform the method 600 in the above embodiments, the communication apparatus 1400 corresponds to the authentication point in the method 600. The transceiver unit 1401 is configured to perform the transceiving operation performed by the authentication point in the method 600. The processing unit 1402 is configured to perform the operation performed by the authentication point in the method 600, except the transceiving operation. For example, the transceiver unit 1401 is configured to send the probe packet 2 to the temporary IPv6 address 1; send the packet 4 to the authentication server. The processing unit 1402 is configured to determine that the user corresponding to the temporary IPv6 address 1 is offline when there is no response packet based on the probe packet 2.

[0562] In one example, the communication apparatus 1400 can perform the method 600 in the above embodiments, when the communication apparatus 1400 is configured to perform the method 600 in the above embodiments, the communication apparatus 1400 corresponds to the authentication server in the method 600. The transceiver unit 1401 is configured to perform the transceiving operation performed by the authentication server in the method 600. The processing unit 1402 is configured to perform the operation performed by the authentication server in the method 600, except the transceiving operation. For example, the transceiver unit 1401 is configured to receive the packet 4 from the authentication point; send the revocation indication 2 to the policy enforcement point. The processing unit 1402 is configured to determine whether the temporary IPv6 address 2 is the latest temporary IPv6 address; determine whether the temporary IPv6 address 1 is the latest temporary IPv6 address; determine all the temporary IPv6 addresses of the user corresponding to the temporary IPv6 address 1.

[0563] Further, the embodiments of the present application also provide a communication system, which comprises an authentication point and an authentication server. Optionally, the communication system further comprises a terminal device. Wherein, the structure of the authentication point and the authentication server can be as shown in the foregoing Figure 13 or Figure 14 . The authentication point is configured to perform the method of the authentication point in the foregoing Figure 2 , Figure 3 , Figure 4 , Figure 5 , Figure 6 , Figure 7 , Figure 8 , Figure 9 , Figure 10 , Figure 11 and Figure 12 corresponding embodiments. The authentication server is configured to perform the method of the authentication server in the foregoing Figure 2 , Figure 3 , Figure 4 , Figure 5 , Figure 6 , Figure 7 , Figure 8 , Figure 9 , Figure 10 corresponding embodiments.Figure 11 and Figure 12 Method of the authentication server in the corresponding embodiment.

[0564] In the implementation process, each step of the above method can be completed by integrated logic circuit of hardware in the processor or instructions in the form of software. The steps of the method disclosed by the embodiments of the present application can be directly embodied as execution completed by a hardware processor, or executed by a combination of hardware and software modules in the processor. The software module can be located in a mature storage medium in the art such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, register, etc. The storage medium is located in the memory, and the processor reads the information in the memory and combines the hardware to complete the steps of the above method. To avoid repetition, it will not be described in detail here. It should also be understood that the first, second, third, fourth and various numerical numbers involved herein are only for the convenience of differentiation, and do not limit the scope of the embodiments of the present application.

[0565] It should be understood that the term "and / or" herein only describes the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B can represent the three cases of A alone, A and B together, and B alone. In addition, the character " / " herein generally represents an "or" relationship between the associated objects before and after it.

[0566] It should be understood that in various embodiments of the present application, the size of the serial number of each process described above does not mean the execution order, and the execution order of each process should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0567] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the system, device and unit described above can refer to the corresponding process in the foregoing method embodiments, which will not be described here.

[0568] The above embodiments are only used to illustrate the technical solutions of the present application, but not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for part of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. An access management method characterized by comprising: The method is performed by an authentication point, and the method comprises: After a terminal device completes access authentication, a first message sent by the terminal device is received, the first message comprising a first IPv6 address of the terminal device and a MAC address of the terminal device, the first IPv6 address being a new temporary IPv6 address of the terminal device, the authentication point storing the MAC address, and the first IPv6 address not existing in one or more temporary IPv6 addresses corresponding to the MAC address; In response to determining that the first IPv6 address is a new IPv6 address, a second message is sent to an authentication server, the second message comprising the first IPv6 address and the MAC address, the second message indicating that the authentication server determines an authorization policy according to the first IPv6 address.

2. The method of claim 1, wherein, Before receiving the first message, the authentication point does not store a correspondence between the MAC address and the first IPv6 address.

3. The method according to claim 1 or 2, characterized in that, After receiving the first message, the method further comprises: Storing the correspondence between the MAC address and the first IPv6 address.

4. The method according to any one of claims 1 or 2, characterized in that, Before receiving the first message, the authentication point stores a correspondence between the MAC address and at least one IPv6 address, the at least one IPv6 address being an IPv6 address that the terminal device is using or has used before sending the first message.

5. The method of claim 3, wherein, The authentication point stores a first correspondence table, the first correspondence table comprising the correspondence between the MAC address and the first IPv6 address.

6. The method of claim 4, wherein, The authentication point stores a first correspondence table, the first correspondence table comprising the correspondence between the MAC address and at least one IPv6 address.

7. The method of claim 1, 2, 5, or 6, wherein, Before receiving the first message, the authentication point stores a correspondence between the MAC address and user information.

8. The method of claim 7, wherein, The authentication point stores a second correspondence table, the second correspondence table comprising the correspondence between the MAC address and the user information.

9. The method of claim 5, wherein, The authentication point stores a second correspondence table, the second correspondence table comprising the correspondence between the MAC address and user information.

10. The method of claim 9, wherein, The second correspondence table further comprises the correspondence between the MAC address and the first IPv6 address.

11. The method of claim 7, wherein, The user information comprises a user identifier.

12. The method of claim 7, wherein, The user information comprises user state information.

13. The method of any one of claims 1, 2, 5, 6, or 8-12, wherein, Before sending the second message, the method further comprises: Determining that a user corresponding to the first IPv6 address is online.

14. The method of any one of claims 5, 6, 9, or 10, wherein, The first correspondence table is a neighbor discovery table or a neighbor discovery probe table.

15. The method of any one of claims 8 to 10, wherein, The second correspondence table is a neighbor discovery table or a neighbor discovery probe table.

16. The method of any one of claims 1, 2, 5, 6, or 8-12, wherein, The second message is used to indicate that the first IPv6 address is a new IPv6 address.

17. The method of claim 16, wherein, The second message comprises first indication information, the first indication information being used to indicate that the first IPv6 address is a new IPv6 address.

18. The method of any one of claims 1, 2, or 5, wherein, The second message is further used to indicate that the authentication server determines a first authorization policy according to the first IPv6 address, the first authorization policy comprising access rights of the terminal device corresponding to the first IPv6 address.

19. The method of any one of claims 1, 2, or 5, wherein, The second message is not an authentication request message.

20. The method of any one of claims 1, 2, or 5, wherein, The second message is a charging message.

21. The method of any one of claims 1, 2, or 5, wherein, The first message is a neighbor solicitation (NS) message.

22. The method of any one of claims 1, 2, or 5, wherein, The method further includes: sending a third message to an authentication server when a second IPv6 address of a plurality of IPv6 addresses of the terminal device is invalid, the third message including the second IPv6 address and second indication information, the second indication information indicating that the second IPv6 address is an invalid IPv6 address.

23. The method of claim 22, wherein, The second indication information is further used to instruct the authentication server to revoke an authorization policy corresponding to the second IPv6 address.

24. The method of claim 22, wherein, Before the third message is sent to the authentication server, the method further includes: sending a first probe message, a destination address of the first probe message being the second IPv6 address; in response to not receiving a first response message from the second IPv6 address for the first probe message, determining that the second IPv6 address is invalid.

25. The method of claim 1, 2, 5, or 6, wherein, The method further includes: determining that a third IPv6 address of a plurality of IPv6 addresses of the terminal device is invalid, the third IPv6 address being a last used IPv6 address of the terminal device; sending a fourth message to an authentication server, the fourth message including third indication information, the third indication information indicating that a user using the terminal device corresponding to the third IPv6 address is offline.

26. The method of claim 25, wherein, The third indication information is further used to instruct the authentication server to revoke authorization policies corresponding to all IPv6 addresses corresponding to the user.

27. The method of claim 25, wherein, The fourth message includes at least one of: a user identifier corresponding to the third IPv6 address; or, a MAC address corresponding to the third IPv6 address; or, all IPv6 addresses of the user corresponding to the third IPv6 address.

28. The method of claim 25, wherein, Determining that a third IPv6 address of a plurality of IPv6 addresses of the terminal device is invalid includes: sending a second probe message, a destination address of the second probe message being the third IPv6 address; in response to not receiving a second response message from the third IPv6 address for the second probe message, determining that the third IPv6 address is invalid.

29. The method of claim 1, 2, 5, or 6, wherein, Before the first message sent by the terminal device is received, the method further includes: receiving a fifth message sent by a terminal device, the fifth message including a fourth IPv6 address of the terminal device and the MAC address; sending a sixth message to the authentication server, the sixth message including the fourth IPv6 address and the MAC address, the sixth message being used to instruct the authentication server to send a second authorization policy to a policy enforcement point according to the fourth IPv6 address, the second authorization policy including access rights of the terminal device corresponding to the fourth IPv6 address.

30. The method of claim 29, wherein, The sixth message is an authentication request message.

31. An access management method, characterized by, The method is performed by an authentication server and includes: after a terminal device completes access authentication, receiving a first message from an authentication point, the first message including a first IPv6 address of the terminal device and a MAC address of the terminal device, the first IPv6 address being a new temporary IPv6 address of the terminal device; determining, according to the MAC address, that the first IPv6 address is a new IPv6 address; sending, to a policy enforcement point, a first authorization policy corresponding to the first IPv6 address, the first authorization policy including access rights of the terminal device corresponding to the first IPv6 address.

32. The method of claim 31, wherein, Before receiving the first packet, the authentication server does not store a correspondence between the MAC address and the first IPv6 address.

33. The method of claim 31 or 32, wherein, Before receiving the first packet, the method further includes: storing the correspondence between the MAC address and the first IPv6 address.

34. The method of claim 31 or 32, wherein, Before receiving the first packet, the authentication server stores a correspondence between the MAC address and at least one IPv6 address, the at least one IPv6 address being an IPv6 address that the terminal device was using or had used before using the first IPv6 address.

35. The method of claim 33, wherein, The authentication server stores a first correspondence table, the first correspondence table including the correspondence between the MAC address and the first IPv6 address.

36. The method of claim 34, wherein, The authentication server stores a first correspondence table, the first correspondence table including the correspondence between the MAC address and at least one IPv6 address.

37. The method of claim 31 or 32, wherein, Before receiving the first packet, the authentication server stores a correspondence between the MAC address and user information.

38. The method of claim 37, wherein, The authentication server stores a second correspondence table, the second correspondence table being configured to store the correspondence between the MAC address and the user information.

39. The method of claim 35, wherein, The authentication server stores a second correspondence table, the second correspondence table including the correspondence between the MAC address and user information.

40. The method of claim 39, wherein, The second correspondence table further includes the correspondence between the MAC address and the first IPv6 address.

41. The method of claim 37, wherein, The user information includes a user identifier.

42. The method of claim 37, wherein, The user information includes access rights of a user.

43. The method of claim 31 or 32, wherein, Before receiving the first packet, the authentication server stores a correspondence between a user identifier and the access rights.

44. The method of claim 43, wherein, The authentication server stores a second correspondence table, the second correspondence table being configured to store the correspondence between the user identifier and the access rights.

45. The method of claim 37, wherein, The user information includes user state information.

46. The method of claim 31 or 32, wherein, After determining, according to the MAC address, that the first IPv6 address is a new IPv6 address, and before sending, to a policy enforcement point, a first authorization policy corresponding to the first IPv6 address, the method further includes: determining that a user corresponding to the first IPv6 address is online.

47. The method of claim 31 or 32, wherein, After determining, according to the MAC address, that the first IPv6 address is a new IPv6 address, and before sending, to a policy enforcement point, a first authorization policy corresponding to the first IPv6 address, the method further includes: determining, according to the MAC address, access rights of a user corresponding to the first IPv6 address; determining the first authorization policy according to the first IPv6 address and the access rights.

48. The method of claim 31 or 32, wherein, After determining that the first IPv6 address is a new IPv6 address according to the MAC address, before sending the first authorization policy corresponding to the first IPv6 address to the policy enforcement point, the method further comprises: determining a user identifier of a user corresponding to the first IPv6 address according to the MAC address; determining an access right of the user according to the user identifier; determining the first authorization policy according to the first IPv6 address and the access right.

49. The method of claim 31 or 32, wherein, The first message is used to indicate that the first IPv6 address is a new IPv6 address.

50. The method of claim 49, wherein, The first message comprises first indication information, which is used to indicate that the first IPv6 address is a new IPv6 address.

51. The method of claim 50, wherein, The first indication information is further used to indicate that the authentication server determines the first authorization policy according to the first IPv6 address.

52. The method of claim 31 or 32, wherein, The first message is not an authentication request message.

53. The method of claim 31 or 32, wherein, The first message is a charging message.

54. The method of claim 31 or 32, wherein, The method further comprises: receiving a second message from the authentication point, the second message comprising a second IPv6 address and second indication information, the second indication information being used to indicate that the second IPv6 address is an invalid IPv6 address, the second IPv6 address being one of a plurality of IPv6 addresses of the terminal device; sending a first revocation indication to the policy enforcement point, the first revocation indication being used to instruct the policy enforcement point to revoke an authorization policy corresponding to the second IPv6 address, the first revocation indication comprising the second IPv6 address.

55. The method of claim 54, wherein, The second indication information is further used to instruct the authentication server to revoke an authorization policy corresponding to the second IPv6 address.

56. The method of claim 31 or 32, wherein, The method further comprises: receiving a third message from the authentication point, the third message comprising third indication information, the third indication information being used to indicate that a user of a terminal device corresponding to a third IPv6 address is offline, the third IPv6 address being a last used IPv6 address of the terminal device; sending a second revocation indication to the policy enforcement point, the second revocation indication being used to instruct the policy enforcement point to revoke authorization policies corresponding to all IPv6 addresses of the user.

57. The method of claim 56, wherein, The third indication information is further used to instruct the authentication server to revoke authorization policies corresponding to all IPv6 addresses of the user.

58. The method of claim 56, wherein, The third message comprises at least one of: a user identifier of the user corresponding to the third IPv6 address; or, a MAC address corresponding to the third IPv6 address; or, all IPv6 addresses of the user corresponding to the third IPv6 address.

59. The method of claim 56, wherein, The second revocation indication comprises all IPv6 addresses of the user corresponding to the third IPv6 address.

60. The method of claim 31 or 32, wherein, Before the authentication server receives the first message from the authentication point, the method further comprises: receiving a fourth message from the authentication point, the fourth message comprising a fourth IPv6 address of the terminal device and the MAC address; determining that the fourth IPv6 address is a new IPv6 address according to the MAC address; sending a second authorization policy corresponding to the fourth IPv6 address to a policy enforcement point, the second authorization policy comprising an access right of the terminal device corresponding to the fourth IPv6 address.

61. The method of claim 60, wherein, The fourth message is an authentication request message.

62. An access management method, comprising: The method is performed by an authentication point, and the method comprises: determining that a first IPv6 address in a plurality of IPv6 addresses of a terminal device is invalid, the authentication point storing a MAC address of the terminal device and the first IPv6 address being in one or more temporary IPv6 addresses corresponding to the MAC address; sending a first message to an authentication server, the first message comprising the first IPv6 address and first indication information, the first indication information being used to indicate that the first IPv6 address is an invalid IPv6 address, and the first indication information being used to instruct the authentication server to revoke an authorization policy of the first IPv6 address.

63. The method of claim 62, wherein, The first indication information is also used to instruct the authentication server to revoke an authorization policy corresponding to the first IPv6 address.

64. The method of claim 62 or 63, wherein, The determining that the first IPv6 address in the plurality of IPv6 addresses of the terminal device is invalid comprises: sending a probe message, a destination address of the probe message being the first IPv6 address; in response to no response message from the first IPv6 address being received for the probe message, determining that the first IPv6 address is invalid.

65. The method of claim 62 or 63, wherein, The method further comprises: when a second IPv6 address in the plurality of IPv6 addresses is invalid, sending a second message to the authentication server, the first message comprising the second IPv6 address and second indication information, the second indication information being used to indicate that the second IPv6 address is an invalid IPv6 address.

66. An access management method, comprising: The method is performed by an authentication server, the authentication server storing a plurality of IPv6 addresses of a terminal device, a MAC address of the terminal device, and a correspondence between access rights of a user using the terminal device, and the method comprises: receiving a first message from an authentication point, the authentication point storing the MAC address of the terminal device and a first IPv6 address being in one or more temporary IPv6 addresses corresponding to the MAC address, the first message comprising the first IPv6 address in the plurality of IPv6 addresses and first indication information, the first indication information being used to indicate that the first IPv6 address is an invalid IPv6 address, and the first indication information being used to instruct the authentication server to revoke an authorization policy of the first IPv6 address; sending a first revocation instruction to a policy enforcement point, the first revocation instruction comprising the first IPv6 address, the first revocation instruction being used to instruct the policy enforcement point to revoke an authorization policy corresponding to the first IPv6 address.

67. The method of claim 66, wherein, The first indication information is also used to instruct the authentication server to revoke an authorization policy corresponding to the first IPv6 address.

68. The method of claim 66 or 67, wherein, The method further comprises: receiving a second packet from the authentication point, the second packet comprising a second IPv6 address of the plurality of IPv6 addresses and second indication information, the second indication information indicating that the second IPv6 address is an invalid IPv6 address; sending a second revocation indication to a policy enforcement point, the second revocation indication comprising the second IPv6 address, the second revocation indication instructing the policy enforcement point to revoke an authorization policy corresponding to the second IPv6 address.

69. An access management method, comprising: The method is performed by an authentication point, and the method comprises: determining that a first IPv6 address of a plurality of IPv6 addresses of a terminal device is invalid, the first IPv6 address being a last used IPv6 address of the terminal device, the authentication point storing a MAC address of the terminal device and the first IPv6 address being present in one or more temporary IPv6 addresses corresponding to the MAC address; sending a first packet to an authentication server, the first packet comprising first indication information, the first indication information indicating that a user using the terminal device corresponding to the first IPv6 address is offline, and the first indication information instructing the authentication server to revoke an authorization policy of all temporary IPv6 addresses corresponding to the terminal device.

70. The method of claim 69, wherein, The first indication information further instructs the authentication server to revoke an authorization policy corresponding to all IPv6 addresses of the user.

71. The method of claim 69 or 70, wherein, The first packet comprises at least one of: a user identifier corresponding to the first IPv6 address; or, a MAC address corresponding to the first IPv6 address; or, all IPv6 addresses of the user corresponding to the first IPv6 address.

72. The method of claim 69 or 70, wherein, The determining that the first IPv6 address of the plurality of IPv6 addresses of the terminal device is invalid comprises: sending a probe packet, a destination address of the probe packet being the first IPv6 address; in response to no response packet from the first IPv6 address being received in response to the probe packet, determining that the first IPv6 address is invalid.

73. An access management method, comprising: The method is performed by an authentication server, the authentication server storing a correspondence between a plurality of IPv6 addresses of a terminal device, a MAC address of the terminal device, and access rights of a user using the terminal device, and the method comprises: receiving a first packet from an authentication point, the authentication point storing a MAC address of the terminal device and a first IPv6 address being present in one or more temporary IPv6 addresses corresponding to the MAC address, the first packet comprising first indication information, the first indication information indicating that a user using the terminal device corresponding to the first IPv6 address is offline, and the first indication information instructing the authentication server to revoke an authorization policy of all temporary IPv6 addresses corresponding to the terminal device, the first IPv6 address being a last used IPv6 address of the terminal device; sending a revocation indication to a policy enforcement point, the revocation indication instructing the policy enforcement point to revoke an authorization policy corresponding to all IPv6 addresses of the user corresponding to the first IPv6 address.

74. The method of claim 73, wherein, The first indication information is further used for instructing the authentication server to revoke authorization policies corresponding to all IPv6 addresses of the user corresponding to the first IPv6 address.

75. The method of claim 73 or 74, wherein, The first message comprises at least one of the following: a user identifier of the user corresponding to the first IPv6 address; or, a MAC address corresponding to the first IPv6 address; or, all IPv6 addresses of the user corresponding to the first IPv6 address.

76. The method of claim 73 or 74, wherein, The revocation indication comprises all IPv6 addresses of the user corresponding to the first IPv6 address.

77. An authentication point, comprising: The authentication point comprises a processor and a memory, the processor and the memory are coupled, the memory stores a program, and when the program stored in the memory is executed by the processor, the authentication point implements the method in any one of claims 1 to 30, 62 to 65, and 69 to 72.

78. An authentication server, comprising: The authentication server comprises a processor and a memory, the processor and the memory are coupled, the memory stores a program, and when the program stored in the memory is executed by the processor, the authentication server implements the method in any one of claims 31 to 61, 66 to 68, and 73 to 76.

79. A computer readable storage medium comprising a computer program, the computer program being executed by a processor to implement the method in any one of claims 1 to 30, 62 to 65, and 69 to 72.

80. A computer readable storage medium comprising a computer program, the computer program being executed by a processor to implement the method in any one of claims 31 to 61, 66 to 68, and 73 to 76.

81. A communications device, characterized by The authentication point comprises a processor and a communication interface, and the processor is used to implement the method in any one of claims 1 to 30, 62 to 65, and 69 to 72.

82. A communications device, characterized by The authentication server comprises a processor and a communication interface, and the processor is used to implement the method in any one of claims 31 to 61, 66 to 68, and 73 to 76.

83. A communication system, characterized by The authentication point according to claim 77 and the authentication server according to claim 78.

Citation Information

Patent Citations

  • Address management method and system

    CN110022383A

  • Computerized techniques for network address assignment

    US20150237003A1