Access authentication method, device and system
The authentication request message is generated and sent through AP, and network address translation is used to reduce the computing burden of wireless controllers, solving the problem of large-scale user concurrent access authentication in WLAN system, achieving efficient distributed authentication, and improving system performance.
Patent Information
- Application Number
- CN202110476215.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-04-29
- Publication Date
- 2025-08-01
- Estimated Expiration
- 2041-04-29
AI Technical Summary
In existing WLAN systems, wireless controllers lack computing resources during large-scale user concurrent access authentication and cannot meet the concurrent access needs.
The access point (AP) obtains user authentication information, and generates authentication request messages based on the docking parameter configuration information between the wireless controller and the authentication server, and then transmits them to the wireless controller through the network address, reducing the computing burden of the wireless controller and realizing distributed authentication.
Without changing the existing WLAN deployment mode, the cooperation between multiple APs and wireless controllers has alleviated the computing pressure of wireless controllers, met the concurrent access authentication needs of large-scale users, and improved the overall performance and processing efficiency of the authentication system.
Smart Images

Figure CN115278660B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of wireless communication technologies, and particularly to an access authentication method, apparatus, and system. Background Art
[0002] Wireless Local Area Network (WLAN) user access authentication is a user-based security access management mechanism that controls access to WLAN users based on user authentication information. WLAN typically adopts a network architecture including an Access Point (AP) and an Access Controller (AC). The AC uniformly manages the APs in the WLAN through the Control and Provisioning of Wireless Access Points Protocol (CAPWAP).
[0003] Currently, in WLAN, generally the AC serves as the access authentication point for WLAN users. The AC obtains the user authentication information of the WLAN user terminals associated with the AP and completes the authentication of WLAN users together with the authentication server. Among them, the WLAN user terminal can also be referred to as a Station (STA).
[0004] However, with the large-scale deployment of APs, the number of WLAN users that the AC needs to authenticate is increasing. Due to the limited computing resources of the AC, it currently cannot meet the concurrent access authentication requirements of a large number of users. Summary of the Invention
[0005] This application provides an access authentication method, apparatus, and system, which can solve the problem that the current concurrent access authentication requirements of a large number of users cannot be met.
[0006] In a first aspect, an access authentication method is provided. The method includes: The AP obtains the user authentication information of the STA associated with the AP. The AP generates an authentication request message according to the docking parameter configuration information between the wireless controller and the authentication server. The authentication request message includes the user authentication information, the source address of the authentication request message is the address of the AP, and the destination address of the authentication request message is the address of the authentication server. The AP sends the authentication request message to the wireless controller.
[0007] In this application, the AP obtains the user authentication information of the STA associated with the AP, generates an authentication request message according to the docking parameter configuration information between the wireless controller and the authentication server, and then sends the authentication request message to the wireless controller. After the wireless controller performs network address translation processing on the authentication request message, it can be sent to the authentication server, reducing the computing overhead of the wireless controller. Without changing the existing WLAN deployment method, distributed authentication is achieved through multiple APs, alleviating the computing pressure on the wireless controller, enabling multiple APs to cooperate with the wireless controller to meet the concurrent access authentication requirements of a large number of users, and improving the overall performance of the authentication system.
[0008] Optionally, the docking parameter configuration information includes security parameters and message encapsulation information between the wireless controller and the authentication server. Among them, the security parameters include the key between the wireless controller and the authentication server, and this key is usually a shared key. The key includes a data key and / or a message authentication code key. The message encapsulation information is used to indicate which attributes the message sent by the wireless controller to the authentication server specifically carries, the encapsulation format of each attribute, and which attributes need to be encrypted, etc.
[0009] Optionally, the authentication request message includes a RADIUS message. For example, the RADIUS message can be the inner message of the authentication request message. The value of the NAS-IP address field of the RADIUS message is the address of the wireless controller.
[0010] Optionally, the authentication request message further includes a target indication, and the target indication is used to indicate that the wireless controller performs network address translation processing on the authentication request message. Optionally, the target indication is in the CAPWAP header of the authentication request message, and this target indication is used to indicate that the wireless controller performs network address translation processing on the inner message in the authentication request message.
[0011] In this application, by carrying the target indication in the CAPWAP header of the authentication request message sent by the AP, the wireless controller can determine whether to perform network address translation processing on the inner message after parsing the CAPWAP header of the authentication request message, which can improve the processing efficiency of the wireless controller.
[0012] Optionally, the implementation process of the AP sending the authentication request message to the wireless controller includes: the AP sends the authentication request message to the wireless controller through the CAPWAP tunnel.
[0013] Optionally, the AP also receives the encrypted docking parameter configuration information from the wireless controller. The AP decrypts the encrypted docking parameter configuration information using the security parameters between the AP and the wireless controller to obtain the docking parameter configuration information.
[0014] In this application, the wireless controller encrypts the docking parameter configuration information with the authentication server and then sends it to the AP, which can reduce the risk of the docking parameter configuration information being stolen during transmission, improve the transmission security of the docking parameter configuration information, and further improve the authentication reliability of the access authentication system.
[0015] In a second aspect, an access authentication method is provided. The method includes: the wireless controller receives a first authentication request message from the AP. The first authentication request message includes a target indication and user authentication information of the STA associated with the AP. The target indication is used to indicate that the wireless controller performs network address translation processing on the first authentication request message. The source address of the first authentication request message is the address of the AP, and the destination address of the first authentication request message is the address of the authentication server. The wireless controller performs network address translation processing on the first authentication request message based on the target indication to obtain a second authentication request message. The source address of the second authentication request message is the address of the wireless controller, and the destination address of the second authentication request message is the address of the authentication server. The wireless controller sends the second authentication request message to the authentication server.
[0016] In this application, by carrying a target indication in the message sent by the AP, the wireless controller can determine whether to perform network address translation processing on the message by parsing the message, and can distinguish the authentication message from other data messages or service messages.
[0017] Optionally, a network address translation table is stored in the wireless controller. The network address translation table includes the mapping relationship between the address of the AP and the port number of the AP and the port number of the wireless controller.
[0018] Optionally, the network address translation table further includes the address of the wireless controller. Then the network address translation table includes the mapping relationship between the address of the AP and the port number of the AP and the address of the wireless controller and the port number of the wireless controller.
[0019] Optionally, the AP and the wireless controller communicate through a CAPWAP tunnel. The address of the AP in the network address translation table includes the address of the AP in the CAPWAP header and / or the address of the AP in the inner message header. For example, the network address translation table includes the mapping relationship between the address of the AP in the CAPWAP header, the address of the AP in the inner message header, and the port number of the AP and the port number of the wireless controller. Or, the network address translation table includes the mapping relationship between the address of the AP in the CAPWAP header, the address of the AP in the inner message header, and the port number of the AP and the address of the wireless controller and the port number of the wireless controller.
[0020] Optionally, the first authentication request message includes a RADIUS message, and the value of the NAS-IP address field of the RADIUS message is the address of the wireless controller.
[0021] Optionally, the process of the wireless controller receiving the first authentication request message from the AP includes: the wireless controller receives the first authentication request message from the AP through the CAPWAP tunnel, and the target indication is in the CAPWAP header of the first authentication request message.
[0022] In this application, by carrying the target indication in the CAPWAP header of the authentication request message sent by the AP, the wireless controller can determine whether to perform network address translation processing on the inner-layer message after parsing the CAPWAP header of the authentication request message, which can improve the processing efficiency of the wireless controller.
[0023] Optionally, the wireless controller encrypts the docking parameter configuration information between the wireless controller and the authentication server using the security parameters between the wireless controller and the AP. The wireless controller sends the encrypted docking parameter configuration information to the AP.
[0024] Optionally, the docking parameter configuration information includes the security parameters and message encapsulation information between the wireless controller and the authentication server.
[0025] In a third aspect, an AP is provided. The AP includes a plurality of functional modules, and the plurality of functional modules interact with each other to implement the methods in the first aspect and its various embodiments above. The plurality of functional modules can be implemented based on software, hardware, or a combination of software and hardware, and the plurality of functional modules can be arbitrarily combined or divided based on the specific implementation.
[0026] In a fourth aspect, a wireless controller is provided. The wireless controller includes a plurality of functional modules, and the plurality of functional modules interact with each other to implement the methods in the second aspect and its various embodiments above. The plurality of functional modules can be implemented based on software, hardware, or a combination of software and hardware, and the plurality of functional modules can be arbitrarily combined or divided based on the specific implementation.
[0027] In a fifth aspect, an access point is provided, including: a processor and a transceiver;
[0028] The processor is used to call a computer program and cooperate with the transceiver to implement the methods in the first aspect and its various embodiments above.
[0029] In a sixth aspect, a wireless controller is provided, including: a processor and a transceiver;
[0030] The processor is used to call a computer program and cooperate with the transceiver to implement the methods in the second aspect and its various embodiments above.
[0031] In a seventh aspect, an access authentication system is provided, including: an access point as described in the third aspect or the fifth aspect, a wireless controller as described in the fourth aspect or the sixth aspect, and an authentication server; wherein, the wireless controller is connected to the authentication server.
[0032] In an eighth aspect, a computer-readable storage medium is provided, on which instructions are stored. When the instructions are executed by a processor of an access point, the methods in the first aspect and its various embodiments are implemented; or when the instructions are executed by a processor of a wireless controller, the methods in the second aspect and its various embodiments are implemented.
[0033] In a ninth aspect, a chip is provided. The chip includes programmable logic circuits and / or program instructions. When the chip runs, the methods in the first aspect and its various embodiments or the methods in the second aspect and its various embodiments are implemented. Description of the Drawings
[0034] Figure 1 is a schematic structural diagram of an access authentication system provided by an embodiment of the present application;
[0035] Figure 2 is a schematic flowchart of an access authentication method provided by an embodiment of the present application;
[0036] Figure 3 is a schematic structural diagram of an authentication request message provided by an embodiment of the present application;
[0037] Figure 4 is a schematic structural diagram of an authentication request message encapsulated with a CAPWAP header provided by an embodiment of the present application;
[0038] Figure 5 is for Figure 4 is a schematic diagram of the process of performing network address translation processing on the shown authentication request message;
[0039] Figure 6 is a schematic structural diagram of an authentication response message provided by an embodiment of the present application;
[0040] Figure 7 is for Figure 6 is a schematic diagram of the process of performing network address translation processing on the shown authentication response message;
[0041] Figure 8 is a schematic structural diagram of an authentication response message encapsulated with a CAPWAP header provided by an embodiment of the present application;
[0042] Figure 9 is a schematic structural diagram of an AP provided by an embodiment of the present application;
[0043] Figure 10 It is a schematic structural diagram of another AP provided by an embodiment of the present application;
[0044] Figure 11 It is a schematic structural diagram of a wireless controller provided by an embodiment of the present application;
[0045] Figure 12 It is a schematic structural diagram of another wireless controller provided by an embodiment of the present application;
[0046] Figure 13 It is a block diagram of an AP provided by an embodiment of the present application;
[0047] Figure 14 It is a block diagram of a wireless controller provided by an embodiment of the present application. Detailed implementation manners
[0048] To make the objectives, technical solutions and advantages of the present application clearer, the following will further describe the embodiments of the present application in detail with reference to the accompanying drawings.
[0049] AAA is the abbreviation of authentication, authorization and accounting. After the operator authenticates the user identity through the AAA system, corresponding permissions are granted according to the service category applied for by the user when opening an account. When the user uses network resources, the corresponding device in the AAA system counts the resources occupied by the user and charges the corresponding fees.
[0050] Currently, IEEE 802.1X authentication is usually adopted for WLAN user access authentication. 802.1X authentication is an application of the extensible authentication protocol (EAP) authentication, and its main purpose is to solve the problem of LAN user access authentication. The 802.1X protocol is a network access control protocol based on interfaces. "Network access control based on interfaces" means that at the interface level of the LAN access device, the access device controls the user's access to network resources through authentication.
[0051] In the 802.1X authentication system, a three-party authentication mechanism based on "client", "access device" and "authentication server" is usually adopted. The client is an entity located at one end of the local area network segment, generally a user terminal, and the user can initiate 802.1X authentication by starting the client software. The access device is another entity located at one end of the local area network segment, which is used to authenticate the connected client. The access device is usually a network device that supports the 802.1X protocol, and it provides an interface for the client to access the local area network. The authentication server is connected to the access device, and the authentication server is an entity that provides authentication services for the access device. The authentication server is used to authenticate, authorize and charge users. The authentication server is usually a remote authentication dial in user service (RADIUS) server. In a WLAN, the client can be a STA, and the access device can be a wireless controller.
[0052] Among them, the client supports the extensible authentication protocol over LAN (EAPOL). The 802.1X authentication system uses EAP to implement the exchange of authentication information between the client, the access device and the authentication server. The interaction form of EAP messages between entities is as follows: between the client and the access device, the EAP message uses the EAPOL encapsulation format and is directly carried in the LAN environment. Between the access device and the authentication server, the EAP relay method or the EAP termination method can be used to exchange EAP messages. Taking the authentication server as a RADIUS server as an example, the EAP relay method means that the EAP message is relayed by the access device. The access device encapsulates the EAP message using the RADIUS protocol to obtain an EAP over RADIUS (EAPOR) message, and sends the EAPOR message to the RADIUS server for authentication. The EAP termination method means that the access device encapsulates the user authentication information in the RADIUS message and uses the password authentication protocol (PAP) or the challenge handshake authentication protocol (CHAP) method to authenticate with the RADIUS server, that is, the access device and the RADIUS server use the RADIUS message containing PAP or CHAP attributes for authentication interaction. The specific authentication process between the client, the access device and the authentication server can refer to the 802.1X protocol, and the embodiments of the present application will not be elaborated herein.
[0053] Since most of the current user access authentication processing procedures are completed on access devices, limited by the computing resources of access devices, the current concurrent access authentication requirements of a large number of users cannot be met. In response to this, the embodiments of this application provide an access authentication method for WLAN users. In a scenario where a wireless controller is used as an authentication point and connected to an authentication server, the AP obtains the user authentication information of the STA associated with the AP, generates an authentication request message according to the docking parameter configuration information between the wireless controller and the authentication server, and then sends the authentication request message to the wireless controller. After performing network address translation (NAT) processing on the authentication request message, the wireless controller can send it to the authentication server, reducing the computing overhead of the wireless controller. Without changing the existing WLAN deployment method, distributed authentication is achieved through multiple APs, alleviating the computing pressure on the wireless controller, enabling multiple APs to cooperate with the wireless controller to meet the concurrent access authentication requirements of a large number of users, and improving the overall performance of the authentication system.
[0054] Figure 1 It is a schematic structural diagram of an access authentication system provided by the embodiments of this application. As Figure 1 shown, the access authentication system includes: AP101A - 101C (collectively referred to as AP 101), a wireless controller 102, and an authentication server 103. The number of APs in the figure is only used for illustrative purposes and does not limit the access authentication system provided by the embodiments of this application.
[0055] AP 101 is a network device with a WLAN chip or a system on a chip (SoC) chip for WLAN. For example, AP 101 can be a router or a switch, etc. AP 101 in the embodiments of this application can be a fit AP. The AP is used to provide wireless access services based on the WLAN protocol for the STA associated with the AP. The STA is a wireless terminal with a WLAN chip. For example, the STA can be a smart phone, a laptop computer, or a smart wearable device, etc.
[0056] The wireless controller 102 can also be referred to as a WLAN controller. When the AP 101 communicates with the wireless controller 102 through a CAPWAP tunnel, the wireless controller 102 can be an access controller. For example, the wireless controller 102 can specifically be an access device such as a switch or a gateway. Multiple APs 101 are respectively connected to the wireless controller 102 in a wired manner. The wireless controller 102 is used to manage the APs 101. The responsibility of the wireless controller 102 is to control the connection status of the STA with the network according to the current authentication status of the STA. The wireless controller 102 usually has two types of ports: a controlled port and an uncontrolled port. Among them, the device connected to the controlled port can only access network resources after passing authentication. While the device connected to the uncontrolled port can directly access network resources without passing authentication. In the embodiments of the present application, the STA is connected to the controlled port of the wireless controller 102 through the AP 101 to achieve access control for WLAN users. The authentication server 103 is connected to the uncontrolled port of the wireless controller 102 to ensure normal communication between the authentication server 103 and the wireless controller 102.
[0057] The authentication server 103 can be a single server, or can be a server cluster containing multiple servers, or can be a cloud computing platform. The authentication server 103 is used to cooperate with the wireless controller 102 during the authentication process to provide authentication services for WLAN users. The authentication server 103 is usually a RADIUS server. The RADIUS server is used to perform RADIUS authentication on WLAN users. The authentication server 103 can store usernames and passwords, as well as corresponding authorization information. The authentication server 103 can provide authentication services to multiple wireless controllers 102, so as to achieve centralized management of WLAN users. The authentication server 103 is also used to manage audit data sent from the wireless controller 102, etc.
[0058] In the embodiments of the present application, the authentication server 103 is connected to the wireless controller 102, that is, the authentication server 103 is configured to perform authentication interaction with the wireless controller 102. The docking parameter configuration information between the wireless controller 102 and the authentication server 103 is set in the wireless controller 102. Optionally, the docking parameter configuration information between the wireless controller 102 and the authentication server 103 includes the security parameters and packet encapsulation information between the wireless controller 102 and the authentication server 103.
[0059] Among them, the security parameters include the key between the wireless controller 102 and the authentication server 103, which is usually a shared key (i.e., a symmetric key). The key between the wireless controller 102 and the authentication server 103 may include a data key and / or a message authentication code key. The data key is used to encrypt and decrypt the original data that the sender wants to transmit to the receiver. For example, the sender can use the data key to encrypt the payload field of the packet. Correspondingly, the receiver uses the data key to decrypt the payload field of the packet. The message authentication code key is used to generate a message authentication code, which is used to authenticate the integrity (not tampered with) and reliability (not false data forged) of the message. The packet encapsulation information is used to indicate which attributes the packet sent by the wireless controller 102 to the authentication server 103 specifically carries, the encapsulation format of each attribute, and which attributes need to be encrypted, etc.
[0060] Optionally, the docking parameter configuration information between the wireless controller 102 and the authentication server 103 further includes the Internet Protocol (IP) address of the authentication server 103 and / or the port number of the authentication server 103, etc. Among them, the port number of the authentication server 103 refers to the port number of the port used by the authentication server 103 to communicate with the wireless controller 102.
[0061] In the embodiment of the present application, the authentication server 103 is connected to the wireless controller 102. That is, for the authentication server 103, the authentication point is the wireless controller 102. If the wireless controller 102 serves as the authentication point, in order to ensure the security and reliability of authentication, the docking parameter configuration information between the wireless controller 102 and the authentication server 103 is generally only stored in the wireless controller 102, and the wireless controller 102 will not inform it to any other device to prevent any other device from impersonating the authentication point. In the embodiment of the present application, if the wireless controller 102 wants to share the access authentication processing flow with the AP 101, it sends the docking parameter configuration information between the wireless controller 102 and the authentication server 103 to the AP 101. That is, the wireless controller 102 needs to inform the AP 101 of the information required to be used in the access authentication process, and then the AP 101 serves as the actual authentication point.
[0062] Therefore, before the access authentication system in the embodiments of the present application performs access authentication on WLAN users, the wireless controller 102 may encrypt the docking parameter configuration information between the wireless controller 102 and the authentication server 103 by using the security parameters between the wireless controller 102 and the AP 101, and then send the encrypted docking parameter configuration information to the AP 101. After receiving the encrypted docking parameter configuration information from the wireless controller 102, the AP 101 decrypts the encrypted docking parameter configuration information by using the security parameters between the AP 101 and the wireless controller 102 to obtain the docking parameter configuration information between the wireless controller 102 and the authentication server 103.
[0063] Optionally, the security parameters between the AP 101 and the wireless controller 102 may be negotiated in advance or may be pre-configured between the two. The security parameters between the AP 101 and the wireless controller 102 may be a symmetric key, or may also be a pair of asymmetric keys.
[0064] In the embodiments of the present application, the wireless controller encrypts the docking parameter configuration information with the authentication server and then sends it to the AP, which can reduce the risk of the docking parameter configuration information being stolen during transmission, improve the transmission security of the docking parameter configuration information, and thus improve the authentication reliability of the access authentication system.
[0065] In the access authentication system provided by the embodiments of the present application, the wireless controller 102 may support centralized authentication and cooperate with the distributed authentication of the AP 101. The wireless controller 102 supporting centralized authentication means that, using the current access authentication method, the wireless controller 102 completes the access authentication processing flow. The wireless controller 102 cooperating with the AP 101 to support distributed authentication means that, using the access authentication method provided by the embodiments of the present application, the AP 101 completes the main access authentication processing flow, and the wireless controller 102 is responsible for summarizing and connecting to the authentication server 103. The wireless controller 102 only sends the docking parameter configuration information to the AP 101 that supports distributed authentication. For example, in the access authentication system as Figure 1 shown, the AP 101A and the AP 101B support distributed authentication, and the AP 101C does not support distributed authentication. Then, the wireless controller 102 sends the docking parameter configuration information between the wireless controller 102 and the authentication server 103 to the AP 101A and the AP 101B respectively, and the access authentication processing flow of the STA associated with the AP 101C is completed by the wireless controller 102.
[0066] Optionally, if the authentication server is a RADIUS server, the 802.1X protocol stack and the RADIUS protocol stack may be configured in the AP 101 that supports distributed authentication.
[0067] Figure 2 It is a schematic flowchart of an access authentication method provided by an embodiment of the present application. This method can be applied to an access authentication system as shown in Figure 1 the following figure. As shown in Figure 2 the following figure, this method includes:
[0068] Step 201: The AP obtains the user authentication information of the STA associated with the AP.
[0069] In a possible implementation, the user authentication information includes a username and a password. The AP receives the user authentication information sent by the STA. In this implementation, the access authentication process can be triggered by the STA. After the STA is successfully associated with the AP, the STA actively sends an EAPOL-Start frame to trigger the authentication. Or, the access authentication process can also be triggered by the AP. After the STA is successfully associated with the AP, the AP actively sends an EAP-Request / Identity frame of Identity type to the STA to trigger the authentication. If the AP does not receive a response from the STA within the set duration, it resends this frame.
[0070] In another possible implementation, the user authentication information includes the Media Access Control (MAC) address and / or the IP address of the STA. After receiving the frame sent by the STA, the AP actively extracts the MAC address and / or the IP address of the STA from the frame.
[0071] Step 202: The AP generates a first authentication request message according to the docking parameter configuration information between the wireless controller and the authentication server.
[0072] This first authentication request message includes the user authentication information. The source address of this first authentication request message is the address of the AP, and the destination address is the address of the authentication server. The source port number in this first authentication request message is the port number of the AP, and the destination port number is the port number of the authentication server. This first authentication request message is encapsulated using the security parameters between the wireless controller and the authentication server based on the message encapsulation information agreed or negotiated between the wireless controller and the authentication server. For example, various attributes agreed or negotiated between the wireless controller and the authentication server are encapsulated in this first authentication request message, and the attributes that need to be encrypted during the negotiation are encrypted.
[0073] For example, the IP address of the AP is 1.1.1.1, and the port number of the port used by the AP to communicate with the wireless controller is 1111. The IP address of the wireless controller is 2.2.2.2, and the port number pool of the wireless controller is collectively referred to as 2222, which includes the port numbers of the ports used to communicate with the authentication server and the port numbers of the ports used to communicate with the AP. The IP address of the authentication server is 3.3.3.3, and the port number of the port used by the authentication server to communicate with the wireless controller is 1645. Figure 3 is a schematic structural diagram of a first authentication request message provided by an embodiment of the present application. As Figure 3 shown, the transport layer protocol adopted by the first authentication request message is the User Datagram Protocol (UDP), the source port number is 1111, the destination port number is 1645, the source IP address is 1.1.1.1, the destination IP address is 3.3.3.3, and the MAC sublayer is implemented using the 802.3 protocol. The first authentication request message further includes a RADIUS payload, and the user authentication information is in the RADIUS payload.
[0074] As a device that provides wireless access services to STAs, an AP originally only forwards frames between the STA and the wireless controller during the access authentication process of the STA and does not process the frames. That is, the wireless controller obtains the user authentication information of the STA and generates an authentication request message based on the docking parameter configuration information between the wireless controller and the authentication server. Obviously, the AP does not obtain the docking parameter configuration information between the wireless controller and the authentication server either. In order to reduce the burden on the wireless controller for access authentication of the STA in this application, the wireless controller sends the docking parameter configuration information between the wireless controller and the authentication server to the AP, and the AP generates an authentication request message based on the docking parameter configuration information between the wireless controller and the authentication server and sends the authentication request message to the wireless controller. Subsequently, after the wireless controller obtains the authentication request message from the AP, it only needs to perform simple network address translation processing on the authentication request message to obtain a message that can be sent to the authentication server, greatly reducing the processing burden of the wireless controller during the access authentication process. For the authentication server, the authentication server is connected to the wireless controller and only communicates with the wireless controller during the access authentication process. The communication messages between the two are also generated based on the docking parameter configuration information between the wireless controller and the authentication server. Therefore, the authentication server does not perceive that the actual authentication point is transferred to the AP. That is, for the authentication server, the authentication point is always the wireless controller. Therefore, the access authentication method provided in this application can be directly applied to the scenario where the authentication server is connected to the wireless controller without changing the device or deployment method connected to the authentication server. Additionally, if the authentication server is directly connected to the AP, that is, for the authentication server, the AP serves as the authentication point. Since the number of APs is much larger than the number of wireless controllers, the number of authentication points that need to perform authentication interaction with the authentication server will increase sharply, resulting in a relatively large communication burden on the authentication server. The access authentication method provided in this application maintains the original deployment method of connecting the authentication server to the wireless controller, and through the cooperation between the AP and the wireless controller, it reduces the burden on the wireless controller for access authentication of the STA, and at the same time does not increase the number of authentication points on the authentication server side.
[0075] Optionally, the first authentication request message includes a RADIUS message. The value of the network access server (NAS) IP address field of the RADIUS message is the address of the wireless controller. The address of the wireless controller in the NAS-IP field of the RADIUS message can be the IP address of the wireless controller. Among them, the first authentication request message may include an inner message and an outer message header encapsulated outside the inner message. The RADIUS message may be the inner message in the first authentication request message. It should be noted that for the authentication request message including the outer message header and the inner message mentioned in the embodiments of the present application, without special indication, the source address and destination address of the authentication request message both refer to the source address and destination address of the inner message, and the source port number and destination port number in the authentication request message also both refer to the source port number and destination port number in the inner message.
[0076] Optionally, the first authentication request message includes a target indication. The target indication is used to instruct the wireless controller to perform network address translation processing on the first authentication request message.
[0077] Step 203, the AP sends the first authentication request message to the wireless controller.
[0078] Optionally, the AP sends the first authentication request message to the wireless controller through a CAPWAP tunnel. Then the first authentication request message includes a CAPWAP header. After the AP generates the inner message according to the docking parameter configuration information between the wireless controller and the authentication server, it performs CAPWAP tunnel encapsulation on the inner message to obtain the first authentication request message, and then sends the first authentication request message to the wireless controller. The source address in the CAPWAP header is the address of the AP, and the destination address is the address of the wireless controller. Among them, the address of the AP in the CAPWAP header and the address of the AP in the inner message header may be the same address or different addresses.
[0079] Optionally, the target indication is in the CAPWAP header of the first authentication request message. For example, Figure 4 is a schematic structural diagram of a first authentication request message encapsulated with a CAPWAP header provided by an embodiment of the present application. Among them, the inner message in the first authentication request message is Figure 3 the message shown. As Figure 4 shown, the source address in the CAPWAP header of the first authentication request message is 1.1.1.1, and the destination address is 2.2.2.2. The CAPWAP header of the first authentication request message carries a flag "NAT" as the target indication to instruct the wireless controller to perform network address translation processing on the first authentication request message.
[0080] Alternatively, the AP may also establish an Internet Protocol Security (IPSec) tunnel with the wireless controller and send a first authentication request message to the wireless controller through the IPSec tunnel. The embodiments of the present application do not limit the type of the tunnel used to transmit the authentication message between the AP and the wireless controller.
[0081] Step 204: The wireless controller performs network address translation processing on the first authentication request message to obtain a second authentication request message.
[0082] The source address of the second authentication request message is the address of the wireless controller, and the destination address of the second authentication request message is the address of the authentication server. The source port number in the second authentication request message is the port number of the wireless controller, and the destination port number in the second authentication request message is the port number of the authentication server. The wireless controller performs network address translation processing on the first authentication request message, that is, the wireless controller modifies the source address in the first authentication request message to the address of the wireless controller and modifies the source port number in the first authentication request message to the port number of the wireless controller.
[0083] Optionally, the first authentication request message includes a target indication, and the wireless controller performs network address translation processing on the first authentication request message based on the target indication. Alternatively, a matching rule is configured in the wireless controller, and the matching rule may be in the form of an access control list (ACL) for example. The matching rule indicates that network address translation processing is performed on a message whose destination address is the address of the authentication server and / or whose destination port is the port of the authentication server. For a message that does not carry a target indication and whose destination address is not the authentication server, the wireless controller forwards it normally according to the routing table after receiving the message.
[0084] Optionally, after receiving the first authentication request message from the AP through the CAPWAP tunnel, the wireless controller first performs CAPWAP tunnel decapsulation on the first authentication request message to strip the inner message, and then performs network address translation processing on the inner message to obtain a second authentication request message. That is, in addition to performing network address translation processing on the first authentication request message, the wireless controller may also perform CAPWAP tunnel decapsulation on the first authentication request message.
[0085] For example, Figure 5 is a schematic diagram of the process of performing network address translation processing on the Figure 4 shown first authentication request message. As Figure 5As shown, in the second authentication request packet obtained after conversion, the source port number is 2222, the destination port number is 1645, the source IP address is 2.2.2.2, and the destination IP address is 3.3.3.3.
[0086] In the embodiment of the present application, by carrying a target indication in the CAPWAP header of the authentication request packet sent by the AP, the wireless controller can determine whether to perform network address translation processing on the inner-layer packet after parsing the CAPWAP header of the authentication request packet, which can improve the processing efficiency of the wireless controller.
[0087] Optionally, a network address translation table is stored in the wireless controller. The network address translation table includes the mapping relationship between the address of the AP and the port number of the AP and the port number of the wireless controller. For example, it can be expressed as: Among them, the port number of the AP refers to the port number of the source port used by the AP to send the authentication request packet to the wireless controller and / or the port number of the destination port used by the AP to receive the authentication response packet from the wireless controller. The port number of the wireless controller refers to the port number of the source port used by the wireless controller to send the authentication request packet to the authentication server and / or the port number of the destination port used by the wireless controller to receive the authentication response packet from the authentication server.
[0088] Optionally, if the AP and the wireless controller communicate through a CAPWAP tunnel, the address of the AP in the network address translation table may include the address of the AP in the CAPWAP header and / or the address of the AP in the inner-layer packet header. If the address of the AP in the CAPWAP header is the same as the address of the AP in the inner-layer packet header, the network address translation table includes one address of the AP: the address of the AP in the CAPWAP header or the address of the AP in the inner-layer packet header. If the address of the AP in the CAPWAP header is different from the address of the AP in the inner-layer packet header, the network address translation table includes two addresses of the AP: the address of the AP in the CAPWAP header and the address of the AP in the inner-layer packet header. That is, the network address translation table includes the mapping relationship between the address of the AP in the CAPWAP header, the address of the AP in the inner-layer packet header, and the port number of the AP and the port number of the wireless controller. For example, it can be expressed as:
[0089] For multiple APs with the same address, the source address (AP address) in the inner-layer packet header of the packet sent to the wireless controller through the CAPWAP tunnel is the same, but the source address (AP address) in the CAPWAP header is different. In the embodiment of the present application, by adding the address of the AP in the CAPWAP header to the network address translation table, the wireless controller can support network address translation in the scenario of overlapping AP addresses.
[0090] Optionally, the network address translation table further includes the address of the wireless controller. Then, the network address translation table includes the mapping relationship between the address and port number of the AP and the address and port number of the wireless controller. For example, it can be expressed as: Alternatively, the network address translation table includes the mapping relationship between the address of the AP in the CAPWAP header, the address of the AP in the inner message header, the port number of the AP, and the address and port number of the wireless controller. For example, it can be expressed as:
[0091] In one implementation, the port number of the wireless controller corresponding to the same AP in the network address translation table is fixed. The wireless controller can allocate a fixed port number for communicating with the authentication server for this AP when the AP goes online, improving the performance of subsequent network address translation processing by the wireless controller.
[0092] In another implementation, the port numbers of the wireless controllers corresponding to each AP in the network address translation table are dynamically allocated. After receiving the authentication request message from the AP, the wireless controller establishes a session table, which includes the port number of the port that the applied-for wireless controller uses to communicate with the authentication server. The session table has an aging duration. The wireless controller uses the port number of the wireless controller in the session table to replace the source port number in the authentication request message received from this AP within this aging duration. In this implementation, there is no need to change the AP online process, and the AP can access the STA after going online. Additionally, in a non-concurrent scenario, different APs can use the same port at different times, saving port resources.
[0093] Step 205: The wireless controller sends a second authentication request message to the authentication server.
[0094] This second authentication request message includes user authentication information. The wireless controller sends the second authentication request message to the authentication server through the port for communicating with the authentication server.
[0095] Optionally, after receiving the second authentication request message sent by the wireless controller, the authentication server can perform the following steps 206 to 208.
[0096] Step 206: The authentication server authenticates the STA based on the user authentication information in the second authentication request message.
[0097] Optionally, the user authentication information includes a username and a password. The corresponding relationship between the username and the password is stored in the authentication server, and the authentication server can verify the authenticity of the username and password in the user authentication information. Or, the user authentication information includes a MAC address, and the authentication server can verify the authenticity of this MAC address.
[0098] Step 207: The authentication server generates a first authentication response message according to the docking parameter configuration information between the authentication server and the wireless controller.
[0099] The first authentication response message includes an authentication result. The authentication result indicates success or failure of authentication. Optionally, if the authentication result indicates successful authentication, the first authentication response message further includes user authorization information. The source address of the first authentication response message is the address of the authentication server, and the destination address of the first authentication response message is the address of the wireless controller. The source port number in the first authentication response message is the port number of the authentication server, and the destination port number in the first authentication request message is the port number of the wireless controller.
[0100] For example, please refer to the example in step 202. Figure 6 is a schematic structural diagram of a first authentication response message provided by an embodiment of the present application. As Figure 6 shown, the transport layer protocol adopted by the first authentication response message is UDP, the source port number is 1645, the destination port number is 2222, the source IP address is 3.3.3.3, the destination IP address is 2.2.2.2, and the MAC sublayer is implemented using the 802.3 protocol. The first authentication response message further includes a RADIUS payload, and the authentication result is in the RADIUS payload.
[0101] Step 208: The authentication server sends the first authentication response message to the wireless controller.
[0102] The authentication server sends the first authentication response message to the wireless controller through the port for communicating with the wireless controller.
[0103] Step 209: The wireless controller performs network address translation processing on the first authentication response message to obtain a second authentication response message.
[0104] The source address of the second authentication response message is the address of the authentication server, and the destination address of the second authentication response message is the address of the AP. The source port number in the second authentication response message is the port number of the authentication server, and the destination port number in the second authentication response message is the port number of the AP. The wireless controller performs network address translation processing on the first authentication response message, that is, the wireless controller modifies the destination address in the first authentication response message to the address of the AP and modifies the destination port number in the first authentication response message to the port number of the AP.
[0105] For example, Figure 7 is Figure 6 a schematic diagram of the process of performing network address translation processing on the first authentication response message shown. As Figure 7As shown, in the converted message, the source port number is 1645, the destination port number is 1111, the source IP address is 3.3.3.3, and the destination IP address is 1.1.1.1.
[0106] Step 210: The wireless controller sends a second authentication response message to the AP.
[0107] Optionally, the wireless controller sends the second authentication response message to the AP through the CAPWAP tunnel. The wireless controller performs network address translation processing on the first authentication response message to obtain an inner message, and performs CAPWAP tunnel encapsulation on the inner message to obtain the second authentication response message, and then sends the second authentication response message to the AP. The source address in the CAPWAP header of the second authentication response message is the address of the wireless controller, and the destination address is the address of the AP. Among them, the address of the AP in the CAPWAP header and the address of the AP in the inner message header can be the same address or different addresses. It should be noted that for the authentication response message including the outer message header and the inner message mentioned in the embodiments of the present application, without special indication, the source address and destination address of the authentication response message both refer to the source address and destination address of the inner message, and the source port number and destination port number in the authentication response message also both refer to the source port number and destination port number in the inner message.
[0108] For example, Figure 8 is a schematic structural diagram of a second authentication response message encapsulated with a CAPWAP header provided by an embodiment of the present application. Among them, the inner message in the second authentication response message is Figure 7 the message obtained after network address translation in Figure 8 As shown, the source address in the CAPWAP header is 2.2.2.2, and the destination address is 1.1.1.1.
[0109] Step 211: In response to the authentication result in the second authentication response message indicating successful authentication, the AP sends an authentication success frame to the STA; or, in response to the authentication result in the second authentication response message indicating failed authentication, the AP sends an authentication failure frame to the STA.
[0110] After the AP receives the second authentication response message from the wireless controller through the CAPWAP tunnel, it first performs CAPWAP tunnel decapsulation on the received second authentication response message, strips to obtain the inner message, and then parses the inner message. If the authentication result in the inner message indicates successful authentication, the AP sends an authentication success frame to the STA, and the AP also sends user table entry information to the wireless controller. The user table entry information includes the correspondence between the identifier of the STA and the user authorization information, which can be used by the wireless controller for traffic management and network resource management of the STA. If the authentication result in the inner message indicates failed authentication, the AP sends an authentication failure frame to the STA.
[0111] In the following embodiments of this application, taking the user authentication information including the username and password as an example, the implementation process of the access authentication method provided by the embodiments of this application will be exemplarily described:
[0112] In S1, the AP sends an authentication request frame 1 to the STA, and this authentication request frame is used to request to obtain the username of the STA.
[0113] Optionally, this authentication request frame 1 is an EAP request frame of the Identity type (EAP-Request / Identity).
[0114] In one implementation manner, the access authentication process is triggered by the STA. After the STA is successfully associated with the AP, when the user needs to access the external network, the 802.1X client on the STA is opened, and the username and password that have been applied for and registered are input, and a connection request is initiated. At this time, the STA sends an EAPOL-Start frame to the AP through the 802.1X client, starting an access authentication process. After receiving the EAPOL-Start frame from the STA, the AP sends an authentication request frame 1 to the STA to request to obtain the username of the STA.
[0115] In another implementation manner, the access authentication process is triggered by the AP. After the STA is successfully associated with the AP, the AP actively sends an authentication request frame 1 to the STA to request to obtain the username of the STA.
[0116] In S2, the STA sends an authentication response frame 1 based on this authentication request frame 1 to the AP, and this authentication response frame 1 includes the username.
[0117] Optionally, this authentication response frame 1 is an EAP response (EAP-Response / Identity) frame of the Identity type.
[0118] In S3, the AP generates an authentication request message 1 according to the docking parameter configuration information between the wireless controller and the authentication server, and this authentication request message 1 includes the username.
[0119] Optionally, this authentication request message 1 includes a RADIUS message, and this RADIUS message can be, for example, a RADIUS Access-Request message. The source address of this authentication request message 1 is the address of the AP, and the destination address of this authentication request message 1 is the address of the authentication server. The source port number in this authentication request message 1 is the port number of the AP, and the destination port number in this authentication request message 1 is the port number of the authentication server.
[0120] In S4, the AP sends the authentication request message 1 to the wireless controller through the CAPWAP tunnel.
[0121] In S5, the wireless controller performs network address translation processing on the authentication request message 1 to obtain the authentication request message 2.
[0122] The source address of the authentication request message 2 is the address of the wireless controller, and the destination address of the authentication request message 2 is the address of the authentication server. The source port number in the authentication request message 2 is the port number of the wireless controller, and the destination port number in the authentication request message 2 is the port number of the authentication server.
[0123] In S6, the wireless controller sends the authentication request message 2 to the authentication server, and the authentication request message 2 includes the username.
[0124] In S7, the authentication server determines the password corresponding to the username in the authentication request message 2 according to the stored correspondence between the username and the password, and encrypts the password with a randomly generated MD5 Challenge to obtain the password ciphertext 1; at the same time, generates an authentication response message 1 according to the docking parameter configuration information between the authentication server and the wireless controller, and the authentication response message 1 includes the MD5 Challenge.
[0125] Optionally, the authentication response message 1 is a RADIUS message, for example, it can be a RADIUS Access-Challenge message. The source address of the authentication response message 1 is the address of the authentication server, and the destination address of the authentication response message 1 is the address of the wireless controller. The source port number in the authentication response message 1 is the port number of the authentication server, and the destination port number in the authentication request message 1 is the port number of the wireless controller.
[0126] In S8, the authentication server sends the authentication response message 1 to the wireless controller.
[0127] In S9, the wireless controller performs network address translation processing on the authentication response message 1 to obtain the authentication response message 2.
[0128] The source address of the authentication response message 2 is the address of the authentication server, and the destination address of the authentication response message 2 is the address of the AP. The source port number in the authentication response message 2 is the port number of the authentication server, and the destination port number in the authentication response message 2 is the port number of the AP.
[0129] In S10, the wireless controller sends the authentication response message 2 to the AP through the CAPWAP tunnel.
[0130] The authentication response message 2 includes the MD5 Challenge.
[0131] In S11, the AP sends an authentication request frame 2 to the STA, and the authentication request frame 2 includes the MD5Challenge in the authentication response message 2.
[0132] Optionally, the authentication request frame 2 is an EAP request frame of the MD5 Challenge type (EAP-Request / MD5Challenge).
[0133] In S12, the STA encrypts the password in the user authentication information using the MD5 Challenge to obtain the password ciphertext 2.
[0134] In S13, the STA sends an authentication response frame 2 based on the authentication request frame 2 to the AP, and the authentication response frame 2 includes the password ciphertext 2.
[0135] Optionally, the authentication response frame 2 is an EAP response (EAP-Response / MD5Challenge) frame of the MD5 Challenge type.
[0136] In S14, the AP generates an authentication request message 3 according to the docking parameter configuration information between the wireless controller and the authentication server, and the authentication request message 3 includes the password ciphertext 2.
[0137] Optionally, the authentication request message 1 includes a RADIUS message, and the RADIUS message can be, for example, a RADIUSAccess-Request message. The source address of the authentication request message 3 is the address of the AP, and the destination address of the authentication request message 3 is the address of the authentication server. The source port number in the authentication request message 3 is the port number of the AP, and the destination port number in the authentication request message 3 is the port number of the authentication server.
[0138] In S15, the AP sends the authentication request message 3 to the wireless controller through the CAPWAP tunnel. <{
[0139] In S16, the wireless controller performs network address translation processing on the authentication request message 3 to obtain an authentication request message 4.
[0140] The source address of the authentication request message 4 is the address of the wireless controller, and the destination address of the authentication request message 4 is the address of the authentication server. The source port number in the authentication request message 4 is the port number of the wireless controller, and the destination port number in the authentication request message 4 is the port number of the authentication server.
[0141] In S17, the wireless controller sends the authentication request message 4 to the authentication server, and the authentication request message 4 includes the password ciphertext 2.
[0142] In S18, the authentication server compares the ciphertext of password 1 and the ciphertext of password 2. If they are the same, it determines that the STA is a legitimate user and continues with S19; if they are different, it determines that the STA is an illegitimate user.
[0143] After the authentication server determines that the STA is a legitimate user, it continues with the following step S19:
[0144] In S19, the authentication server sends an access success message 1 to the wireless controller.
[0145] Optionally, the access success message 1 is a RADIUS message, for example, it can be a RADIUS Access - Accept message. The source address of the access success message 1 is the address of the authentication server, and the destination address is the address of the wireless controller. The source port number in the access success message 1 is the port number of the authentication server, and the destination port number is the port number of the wireless controller.
[0146] In S20, the authentication server sends an access success message 1 to the wireless controller.
[0147] In S21, the wireless controller performs network address translation on the access success message 1 to obtain an access success message 2.
[0148] The source address of the access success message 2 is the address of the authentication server, and the destination address is the address of the AP. The source port number in the access success message 2 is the port number of the authentication server, and the destination port number is the port number of the AP.
[0149] In S22, the wireless controller sends the access success message 2 to the AP through the CAPWAP tunnel.
[0150] In S23, the AP generates an authentication success frame based on the access success message 2, and this authentication success frame indicates that the STA has successfully accessed.
[0151] In S24, the AP sends the authentication success frame to the STA.
[0152] Optionally, the access success message 1 and the access success message 2 also include user authorization information. The AP also sends user table entry information to the wireless controller through the CAPWAP tunnel. This user table entry information includes the correspondence between the identifier of the STA and the user authorization information, which can be used by the wireless controller for traffic management and network resource management of the STA. Accordingly, the wireless controller sets the port corresponding to the STA to the authorized state, allowing the STA to access the network through this port.
[0153] The above embodiments of the present application take the 802.1X authentication method for authenticating WLAN users as an example for illustration. In actual applications, this access authentication method can also be used for MAC address authentication. Any person skilled in the art within the technical scope disclosed in the present application can easily think of variable methods, which should all be covered within the protection scope of the present application, so no further elaboration will be made.
[0154] In summary, in the access authentication method provided by the embodiments of the present application, the AP obtains the user authentication information of the STA associated with the AP, generates an authentication request message according to the docking parameter configuration information between the wireless controller and the authentication server, and then sends the authentication request message to the wireless controller. After the wireless controller performs network address translation processing on the authentication request message, it can be sent to the authentication server, reducing the computing overhead of the wireless controller. Without changing the existing WLAN deployment method, distributed authentication is achieved through multiple APs, alleviating the computing pressure of the wireless controller, enabling multiple APs to cooperate with the wireless controller to meet the concurrent access authentication requirements of a large number of users, and improving the overall performance of the authentication system. In addition, by carrying a target indication in the CAPWAP header of the message sent by the AP to indicate that the wireless controller performs network address translation processing on the message, the wireless controller can determine whether it needs to perform network address translation processing on the message after parsing the CAPWAP header of the message, which can improve the processing efficiency of the wireless controller.
[0155] Figure 9 It is a schematic structural diagram of an AP provided by an embodiment of the present application. The AP can be the AP 101A or AP 101B in the access authentication system as Figure 1 shown. As Figure 9 shown, the AP 90 includes:
[0156] An obtaining module 901, configured to obtain the user authentication information of the STA associated with the AP.
[0157] A generating module 902, configured to generate an authentication request message according to the docking parameter configuration information between the wireless controller and the authentication server. The authentication request message includes the user authentication information, the source address of the authentication request message is the address of the AP, and the destination address of the authentication request message is the address of the authentication server.
[0158] A sending module 903, configured to send the authentication request message to the wireless controller.
[0159] Optionally, the docking parameter configuration information includes the security parameters and message encapsulation information between the wireless controller and the authentication server.
[0160] Optionally, the authentication request message includes a RADIUS message, and the value of the NAS-IP address field in the RADIUS message is the address of the wireless controller.
[0161] Optionally, the authentication request message further includes a target indication for indicating that the wireless controller performs network address translation processing on the authentication request message.
[0162] Optionally, the sending module 903 is configured to send the authentication request message to the wireless controller through a CAPWAP tunnel.
[0163] Optionally, as Figure 10 shown, the AP 90 further includes: a receiving module 904 for receiving the encrypted docking parameter configuration information from the wireless controller; a decrypting module 905 for decrypting the encrypted docking parameter configuration information by using the security parameters between the AP and the wireless controller to obtain the docking parameter configuration information.
[0164] Figure 11 is a schematic structural diagram of a wireless controller provided by an embodiment of the present application. The wireless controller may be the wireless controller 102 in the access authentication system as Figure 1 shown. As Figure 11 shown, the wireless controller 110 includes:
[0165] a receiving module 1101 for receiving a first authentication request message from an AP. The first authentication request message includes a target indication and user authentication information of an STA associated with the AP. The target indication is used to indicate that the wireless controller performs network address translation processing on the first authentication request message. The source address of the first authentication request message is the address of the AP, and the destination address of the first authentication request message is the address of the authentication server.
[0166] an address translation module 1102 for performing network address translation processing on the first authentication request message based on the target indication to obtain a second authentication request message. The source address of the second authentication request message is the address of the wireless controller, and the destination address of the second authentication request message is the address of the authentication server.
[0167] a sending module 1103 for sending the second authentication request message to the authentication server.
[0168] Optionally, a network address translation table is stored in the wireless controller. The network address translation table includes the mapping relationship between the address of the AP and the port number of the AP and the port number of the wireless controller.
[0169] Optionally, the network address translation table includes the mapping relationship between the address of the AP and the port number of the AP and the address of the wireless controller and the port number of the wireless controller.
[0170] Optionally, communication between the AP and the wireless controller is through a CAPWAP tunnel, and the address of the AP in the network address translation table includes the address of the AP in the CAPWAP header and / or the address of the AP in the inner message header.
[0171] Optionally, the first authentication request message includes a RADIUS message, and the value of the NAS-IP field in the RADIUS message is the address of the wireless controller.
[0172] Optionally, the receiving module 1101 is configured to receive, through the CAPWAP tunnel, the first authentication request message from the AP, and the target is indicated in the CAPWAP header of the first authentication request message.
[0173] Optionally, as Figure 12 shown, the wireless controller further includes: an encryption module 1104, configured to encrypt the docking parameter configuration information between the wireless controller and the authentication server by using the security parameters between the wireless controller and the AP. A sending module 1103 is further configured to send the encrypted docking parameter configuration information to the AP.
[0174] Optionally, the docking parameter configuration information includes the security parameters and message encapsulation information between the wireless controller and the authentication server.
[0175] Regarding the device in the above embodiments, the specific manners in which each module performs operations have been described in detail in the embodiments related to the method, and will not be elaborated here.
[0176] An embodiment of the present application provides an AP, including: a processor and a transceiver;
[0177] The processor is configured to call a computer program and cooperate with the transceiver to implement the actions performed by the AP in the above method embodiments.
[0178] For example, Figure 13 is a block diagram of an AP provided by an embodiment of the present application. As Figure 13 shown, the AP 130 includes: a processor 1301 and a transceiver 1302. The transceiver 1302 is configured to perform the transceiver actions of the AP in the above method embodiments under the control of the processor 1301.
[0179] Optionally, the AP 130 further includes a memory 1303, a communication bus 1304, and a communication interface 1305.
[0180] The processor 1301 may be a central processing unit (CPU).
[0181] The communication bus 1304 may include a path for transmitting information between the above components.
[0182] The memory 1303 can be a read-only memory (ROM) or a random access memory (RAM). For example, the ROM can specifically be an electrically erasable programmable read-only memory (EEPROM) or a compact disc read-only memory (CD-ROM). The memory 1303 can also be an optical disc storage, a magneto-optical disc storage (including a compact disc, a laser disc, an optical disc, a digital versatile disc, a Blu-ray disc, etc.), a magnetic disk, or other magnetic storage devices, or any other medium that can be used to carry or store program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 1303 can exist independently and be connected to the processor 1301 through the communication bus 1304. The memory 1303 can also be integrated with the processor 1301.
[0183] Among them, the memory 1303 is used to store the program code for executing the solution of this application and is controlled by the processor 1301 to execute. The processor 1,301 is used to execute the program code stored in the memory 1303. The program code can include one or more software modules. These one or more software modules can be Figure 9 or Figure 10 the software modules provided in any of the embodiments.
[0184] The communication interface 1305, using the transceiver 1302, is used to communicate with other devices or communication networks, such as a STA or a wireless controller.
[0185] In a specific implementation, as an embodiment, the AP can include multiple processors. The processors here can refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).
[0186] Optionally, the 802.1X protocol stack and the RADIUS protocol stack are configured in the AP.
[0187] An embodiment of this application provides a wireless controller, including: a processor and a transceiver;
[0188] The processor is used to call a computer program and cooperate with the transceiver to implement the actions performed by the wireless controller in the above method embodiments.
[0189] For example, Figure 14 is a block diagram of a wireless controller provided by an embodiment of this application. As Figure 14As shown in the figure, the wireless controller 140 includes: a processor 1401 and a transceiver 1402. The transceiver 1402 is configured to perform the receiving and transmitting operations of the wireless controller in the above method embodiments under the control of the processor 1401.
[0190] Optionally, the wireless controller 140 further includes a memory 1403, a communication bus 1404, and a communication interface 1405.
[0191] The processor 1401 may be a central processing unit (CPU).
[0192] The communication bus 1404 may include a path for transmitting information between the above components.
[0193] The memory 1403 may be a ROM or a RAM. For example, the ROM may specifically be an EEPROM or a CD-ROM. The memory 1403 may also be an optical disc storage, a compact disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), a magnetic disk, or any other magnetic storage device, or any other medium that can be used to carry or store program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 1403 may exist independently and be connected to the processor 1401 through the communication bus 1404. The memory 1403 may also be integrated with the processor 1401.
[0194] Among them, the memory 1403 is used to store the program code for implementing the solution of this application and is controlled by the processor 1401 to execute. The processor 1401 is used to execute the program code stored in the memory 1403. The program code may include one or more software modules. These one or more software modules may be Figure 9 or Figure 10 any software module provided in any of the embodiments.
[0195] The communication interface 1405, using the transceiver 1402, is used to communicate with other devices or communication networks, such as a wireless controller or an authentication server, and the authentication server may be a RADIUS server.
[0196] In a specific implementation, as an embodiment, the wireless controller may include multiple processors. Here, the processor may refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).
[0197] Optionally, an 802.1X protocol stack and a RADIUS protocol stack are configured in the wireless controller.
[0198] This application embodiment also provides an access authentication system, including: as Figure 9 、 Figure 10or Figure 13 the AP shown, such as Figure 11 , Figure 12 or Figure 14 the wireless controller shown, and an authentication server. Among them, the wireless controller is connected to the authentication server.
[0199] The embodiment of the present application also provides a computer-readable storage medium, on which instructions are stored. When the instructions are executed by the processor of the AP, the actions performed by the AP in the above method embodiment are implemented; or when the instructions are executed by the processor of the wireless controller, the actions performed by the wireless controller in the above method embodiment are implemented.
[0200] Those of ordinary skill in the art can understand that all or part of the steps to implement the above embodiments can be completed by hardware, or can be completed by a program instructing related hardware. The program can be stored in a computer-readable storage medium. The storage medium mentioned above can be a read-only memory, a magnetic disk or an optical disc, etc.
[0201] In the embodiments of the present application, the terms "first", "second" and "third" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance.
[0202] The term "and / or" in the present application is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this article generally represents an "or" relationship between the associated objects before and after.
Claims
1. An access authentication method, characterized in that, The method includes: An access point AP obtains user authentication information of a station STA associated with the AP; The AP generates an authentication request message according to docking parameter configuration information between a wireless controller and an authentication server. The authentication request message includes the user authentication information. The source address of the authentication request message is the address of the AP, and the destination address of the authentication request message is the address of the authentication server; The AP sends the authentication request message to the wireless controller. The authentication request message is used for the wireless controller to perform network address translation processing on the authentication request message and then send it to the authentication server.
2. The method according to claim 1, wherein The docking parameter configuration information includes security parameters and message encapsulation information between the wireless controller and the authentication server.
3. The method according to claim 1 or 2, characterized in that, The authentication request message includes a Remote Authentication Dial-In User Service (RADIUS) message. The value of the Network Access Service Internet Protocol Address field of the RADIUS message is the address of the wireless controller.
4. The method according to claim 1 or 2, characterized in that, The authentication request message includes a target indication for indicating that the wireless controller performs network address translation processing on the authentication request message.
5. The method according to claim 1 or 2, characterized in that, The AP sending the authentication request message to the wireless controller includes: The AP sends the authentication request message to the wireless controller through a Control And Provisioning of Wireless Access Points (CAPWAP) tunnel.
6. The method according to claim 1 or 2, characterized in that, The method further includes: The AP receives the encrypted docking parameter configuration information from the wireless controller; The AP decrypts the encrypted docking parameter configuration information by using security parameters between the AP and the wireless controller to obtain the docking parameter configuration information.
7. An access authentication method, characterized in that, The method includes: The wireless controller receives a first authentication request message from an access point AP. The first authentication request message includes a target indication and user authentication information of a station STA associated with the AP. The target indication is used for indicating that the wireless controller performs network address translation processing on the first authentication request message. The source address of the first authentication request message is the address of the AP, and the destination address of the first authentication request message is the address of the authentication server; The wireless controller performs network address translation processing on the first authentication request message based on the target indication to obtain a second authentication request message. The source address of the second authentication request message is the address of the wireless controller, and the destination address of the second authentication request message is the address of the authentication server; The wireless controller sends the second authentication request message to the authentication server.
8. The method according to claim 7, wherein A network address translation table is stored in the wireless controller. The network address translation table includes a mapping relationship between the address of the AP and the port number of the AP and the port number of the wireless controller.
9. The method according to claim 8, wherein The network address translation table includes a mapping relationship between the address of the AP and the port number of the AP and the address of the wireless controller and the port number of the wireless controller.
10. The method according to claim 8 or 9, characterized in that, The communication between the AP and the wireless controller is through a Control And Provisioning of Wireless Access Points (CAPWAP) tunnel. The address of the AP in the network address translation table includes the address of the AP in the CAPWAP header and / or the address of the AP in the inner message header.
11. The method according to any one of claims 7 to 9, characterized in that, The first authentication request message includes a Remote Authentication Dial-In User Service (RADIUS) message, and the value of the Network Access Service Internet Protocol Address field in the RADIUS message is the address of the wireless controller.
12. The method according to any one of claims 7 to 9, characterized in that, The wireless controller receives a first authentication request message from an access point (AP), including: The wireless controller receives the first authentication request message from the AP through the CAPWAP tunnel, and the destination indication is in the CAPWAP header of the first authentication request message.
13. The method according to any one of claims 7 to 9, characterized in that, The method further includes: The wireless controller encrypts the docking parameter configuration information between the wireless controller and the authentication server using the security parameters between the wireless controller and the AP. The wireless controller sends the encrypted docking parameter configuration information to the AP.
14. The method according to claim 13, wherein The docking parameter configuration information includes the security parameters and message encapsulation information between the wireless controller and the authentication server.
15. An access point AP, characterized in that, The AP includes: An acquisition module for acquiring user authentication information of a Station (STA) associated with the AP. A generation module for generating an authentication request message according to the docking parameter configuration information between the wireless controller and the authentication server. The authentication request message includes the user authentication information, the source address of the authentication request message is the address of the AP, and the destination address of the authentication request message is the address of the authentication server. A sending module for sending the authentication request message to the wireless controller, and the authentication request message is used for the wireless controller to perform network address translation processing on the authentication request message and then send it to the authentication server.
16. The AP according to claim 15, wherein The docking parameter configuration information includes the security parameters and message encapsulation information between the wireless controller and the authentication server.
17. The AP according to claim 15 or 16, characterized in that, The authentication request message includes a Remote Authentication Dial-In User Service (RADIUS) message, and the value of the Network Access Service Internet Protocol Address field in the RADIUS message is the address of the wireless controller.
18. The AP according to claim 15 or 16, characterized in that, The authentication request message includes a destination indication for indicating that the wireless controller performs network address translation processing on the authentication request message.
19. The AP according to claim 15 or 16, characterized in that, The sending module is used for: Sending the authentication request message to the wireless controller through a Control And Provisioning of Wireless Access Points (CAPWAP) tunnel.
20. The AP according to claim 15 or 16, characterized in that, The AP further includes: A receiving module for receiving the encrypted docking parameter configuration information from the wireless controller. A decryption module for decrypting the encrypted docking parameter configuration information using the security parameters between the AP and the wireless controller to obtain the docking parameter configuration information.
21. A wireless controller, characterized in that, The wireless controller includes: A receiving module, configured to receive a first authentication request message from an access point AP. The first authentication request message includes a target indication and user authentication information of a station STA associated with the AP. The target indication is used to instruct the wireless controller to perform network address translation processing on the first authentication request message. The source address of the first authentication request message is the address of the AP, and the destination address of the first authentication request message is the address of an authentication server. An address translation module, configured to perform network address translation processing on the first authentication request message based on the target indication to obtain a second authentication request message. The source address of the second authentication request message is the address of the wireless controller, and the destination address of the second authentication request message is the address of the authentication server. A sending module, configured to send the second authentication request message to the authentication server.
22. The wireless controller according to claim 21, wherein, A network address translation table is stored in the wireless controller. The network address translation table includes a mapping relationship between the address of the AP and the port number of the AP and the port number of the wireless controller.
23. The wireless controller according to claim 21 or 22, characterized in that, The first authentication request message includes a Remote Authentication Dial-In User Service (RADIUS) message. The value of the Network Access Service Internet Protocol Address field of the RADIUS message is the address of the wireless controller.
24. The wireless controller according to claim 21 or 22, characterized in that, The receiving module is configured to: Receive the first authentication request message from the AP through a Control And Provisioning of Wireless Access Points (CAPWAP) tunnel. The target indication is in the CAPWAP header of the first authentication request message.
25. The wireless controller according to claim 21 or 22, characterized in that, The wireless controller further includes: An encryption module, configured to encrypt the docking parameter configuration information between the wireless controller and the authentication server using the security parameters between the wireless controller and the AP. The sending module is further configured to send the encrypted docking parameter configuration information to the AP.
26. The wireless controller according to claim 25, characterized in that, The docking parameter configuration information includes the security parameters and message encapsulation information between the wireless controller and the authentication server.
27. An access point, characterized in that, It includes: A processor and a transceiver; The processor is configured to call a computer program to cooperate with the transceiver to implement the method according to any one of claims 1 to 6.
28. A wireless controller, characterized in that, It includes: A processor and a transceiver; The processor is configured to call a computer program to cooperate with the transceiver to implement the method according to any one of claims 7 to 14.
29. An access authentication system, characterized in that, It includes: An access point according to any one of claims 15 to 20, 27, a wireless controller according to any one of claims 21 to 26, 28, and an authentication server; wherein, the wireless controller is connected to the authentication server.
Citation Information
Patent Citations
Automatic authentication method, apparatus and system of wireless local area network (WLAN)
CN104349318A
Authentication method for supporting network switching in based on different devices at same time
CN1416241A