A method for verifying home broadband account login and logical channel
By analyzing the user's PPPoE dialing data and asset management resource data, identifying and rectifying the VLAN identity of duplicate users, the problem of mutual access between different users in the operator network is solved, and the efficiency of problem tracking is improved.
Patent Information
- Application Number
- CN202211077665.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-05
- Publication Date
- 2025-05-20
- Estimated Expiration
- 2042-09-05
AI Technical Summary
In operator networks, it is difficult for the prior art to effectively distinguish the VLAN identifiers of different users, resulting in difficulty in tracking problems and problem-tracking between different users.
By obtaining the user's PPPoE dial data, extracting and analyzing account data, VLAN data and other information, mining duplicate users in real time, and combining asset management resource data, it provides a basis for rectification for duplicate users and solves the problem of mutual access between different users.
Effectively locate and eliminate fake abnormal users, ensure that the business is not affected, real distinction between different users, and improve the efficiency of problem tracking.
Smart Images

Figure CN115442142B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of broadband user management, and particularly to a method for auditing the login of a home broadband account on the same logical channel. Background Art
[0002] When China Mobile Communications Operator provides Internet access services through Ethernet, it is necessary to manage customer identification in a refined manner. Moreover, with the development of new services (such as Triple-Play, Wholesale, VPN (Virtual Private Network), etc.), the operator also needs to segment the services to provide different pipelines and QoS (Quality of Service) policies differently.
[0003] Currently, in the access network of China Mobile Communications Network, the QinQ technology (802.1Q-in-802.1Q, also known as Stacked VLAN or Double VLAN, a technology for expanding the VLAN space) is mainly used to identify users. The QinQ technology means encapsulating the user's private network VLAN (Virtual Local Area Network) tag in the public network VLAN tag, enabling the packet to traverse the operator's backbone network with two layers of VLAN tags. In the public network, it propagates only according to the outer VLAN tag, and the private network VLAN tag is shielded. In this way, not only the data flow is differentiated, but also since the private network VLAN tag is transparently transmitted, different user VLAN tags can be reused, as long as the outer VLAN tag is unique in the public network. In fact, the available number of VLAN tags is also increased.
[0004] In the QinQ technology, users or user networks are usually divided by physical ports. When multiple different users access the same port with different VLANs, the users cannot be distinguished. In addition, the previous QinQ solution is an application of a simple layer-2 VPN. In the operator's access environment, it is often necessary to distinguish users according to the user's application or access location (device). Therefore, in the operator's network, it is necessary to assign a unique VLAN to the access users to facilitate problem tracking and prevent mutual access between different users, and use the outer VLAN tag to distinguish the user's application; or use the outer tag to distinguish different access locations in the access environment, and use the inner and outer VLAN tags to uniquely identify an access user.
[0005] QinQ provides a cheap and simple Layer 2 VPN solution. It does not require the support of signaling protocols and can be implemented through pure static configuration. When statically configuring VLAN tags, duplicates will cause mutual access between different users and also make it inconvenient to trace problems.
[0006] QinQ technology has been adopted in existing operator access networks. To ensure the consistency of customer-wide VLAN configurations, dynamic VLAN protocols (such as GVRP, VTP, etc.) are used to identify the inner and outer VLANs of users. At the same time, packets are transparently transmitted through the operator network. Since BPDU (Bridge Protocol Data Unit) packets are Layer 2 control packets of bridge devices (basically encapsulated with LLC (Logical Link Control)), which are related to the device globally and do not carry VLAN tags, a mechanism is needed to transmit users' Layer 2 control packets, thus introducing the concept of BPDU Tunnel (Cisco: Layer 2 Protocol Tunneling), and the users' Layer 2 control packets are propagated through the Tunnel.
[0007] Normally, BPDU Tunnel is implemented as follows: when a Tunnel port receives a user's BPDU, it modifies the destination MAC (Media Access Control) to a multicast MAC, and then adds the Tag information of the VLAN to which the user belongs to the protocol packet. The multicast MAC ensures that the packet is broadcast within the VLAN and at the same time indicates that this packet is a BPDU-Tunnel packet. When the switch receives this packet, it sends it to the CPU for processing, restores its BPDU identity, and based on the VLAN information to which the user belongs in the packet, sends the packet to the corresponding customer network.
[0008] Using dynamic VLAN protocols realizes the maximum rational utilization of resources. However, in reality, there are also cases where different users directly configure the same VLAN identifier, resulting in the inability to distinguish different access users. Summary of the Invention
[0009] The object of the present invention is to provide a method for auditing the login of a home broadband account on the same logical channel, aiming at the problem of duplicate VLAN identifiers dynamically configured in the BRAS (Broadband Remote Access Server) and OLT (Optical Line Terminal) for different users in the access network. Based on the authentication data of PPPoE (Point-to-Point Protocol over Ethernet), it analyzes the data, real-time mines the users with duplicates, and combines information such as the corresponding asset management resource allocation and installation and maintenance services of the users to provide a basis for rectification for the users with duplicates, so as to solve the problem of mutual access between different users and facilitate the tracking of subsequent problems.
[0010] The technical solution adopted by the present invention to solve the above technical problems is to provide a method for auditing the login of a home broadband account on the same logical channel, including:
[0011] Obtain the PPPoE dial test data of at least two users, screen out the login request messages from the PPPoE dial test data, and obtain at least two groups of first messages;
[0012] For each group of the first messages, extract the User-Name data therein to obtain account data; extract the NAS-IP-Address data therein to obtain brasIP data; extract the NAS-Port-Id data therein to obtain the outer VLAN data and the inner VLAN data;
[0013] Obtain the asset management resource data, and perform correlation analysis on the account data and the asset management resource data to obtain the OLT_IP data and OLT_PON data associated with the user;
[0014] Form a first data combination with the brasIP data, the outer VLAN data, the inner VLAN data, the OLT_IP data and the OLT_PON data;
[0015] For any two users among the at least two users, compare their first data combinations. If they are exactly the same, determine the users as abnormally logged-in users.
[0016] In a possible implementation manner, the step of obtaining the PPPoE dial test data of at least two users, screening out the login request messages from the PPPoE dial test data, and obtaining at least two groups of first messages includes:
[0017] Obtain the PPPoE test data of at least two users, and filter out the packets with Code = Accounting-Request and Acct-Status-Type = Start from the PPPoE test data to obtain at least two groups of first packets.
[0018] In a possible implementation manner, after comparing the first data combinations of any two users among the at least two users and determining that the users are abnormal login users if they are exactly the same, the method further includes:
[0019] For the first packets corresponding to the abnormal login users, extract the Acct-Session-Id data therein to obtain the prefecture-level city data; extract the datetime data therein to obtain the online time data; extract the Calling-Station-Id data therein to obtain the MAC address data;
[0020] Use the prefecture-level city data, online time data, and MAC address data to perform the rectification operation for the same logical channel login audit.
[0021] In a possible implementation manner, the using the prefecture-level city data, online time data, and MAC address data to perform the rectification operation for the same logical channel login audit includes:
[0022] For each value of the first data combination, count the number of corresponding abnormal login users, and set the priority for each value of the first data combination according to the number of corresponding abnormal login users;
[0023] In the order of the priority, use the prefecture-level city data, online time data, and MAC address data to perform the rectification operation for the same logical channel login audit.
[0024] A method for auditing the same logical channel login of a home broadband account proposed by the present invention analyzes based on the PPPoE authentication data, real-time mines the users with duplicates, and combines the corresponding asset management resource allocation, installation and maintenance service, etc. information of the users to provide a basis for rectification for the users with duplicates, so as to solve the mutual access problem between different users and facilitate the subsequent problem tracking. According to the logical channel of "brasIP + outer VLAN + inner VLAN + OLT_IP + OLT_PON", it is possible to effectively locate the users whose actual services are affected, and effectively eliminate the false abnormal users that do not affect the actual services and are duplicates between different BRAS switches and different OLT-PON ports, so as to truly solve the mutual access problem between different users. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] Figure 1Flowchart of a method for auditing the login of a home broadband account on the same logical channel disclosed in an embodiment of the present invention;
[0026] Figure 2 Schematic diagram of PPPoE dial test data disclosed in an embodiment of the present invention. Detailed implementation manners
[0027] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0028] For the convenience of understanding the embodiments of the present invention, the following will further explain with specific embodiments in conjunction with the accompanying drawings. The embodiments do not constitute a limitation to the embodiments of the present invention.
[0029] Figure 1 Flowchart of a method for auditing the login of a home broadband account on the same logical channel disclosed in an embodiment of the present invention.
[0030] In step S101, obtain PPPoE dial test data of at least two users, and screen out the login request messages from the PPPoE dial test data to obtain at least two groups of first messages.
[0031] Specifically, obtain PPPoE dial test data of at least two users, and screen out the messages with Code = Accounting-Request and Acct-Status-Type = Start from the PPPoE dial test data to obtain at least two groups of first messages.
[0032] In step S102, for each group of the first messages, extract the User-Name data therein to obtain account data; extract the NAS-IP-Address data therein to obtain the brasIP data; extract the NAS-Port-Id data therein to obtain the outer VLAN data and the inner VLAN data.
[0033] Specifically, for the NAS-Port-Id data, its format is "trunk a / b / c:d.e", where a, b, c, d, and e are all numbers. Extract the number d between the colon and the dot to obtain the outer VLAN data, and extract the number e after the dot to obtain the inner VLAN data.
[0034] In step S103, obtain the asset management resource data, and perform an association analysis using the account data and the asset management resource data to obtain the OLT_IP data and OLT_PON data associated with the user.
[0035] In step S104, form a first data combination with the brasIP data, the outer VLAN data, the inner VLAN data, the OLT_IP data, and the OLT_PON data.
[0036] In step S105, for any two users among the at least two users, compare their first data combinations. If they are exactly the same, determine the users as abnormally logged-in users.
[0037] In some possible implementation manners, after step S105, there is also step S106: For the first packet corresponding to the abnormally logged-in user, extract the Acct-Session-Id data therein to obtain the city data; extract the datetime data therein to obtain the online time data; extract the Calling-Station-Id data therein to obtain the MAC address data.
[0038] And step S107: Use the city data, the online time data, and the MAC address data to perform the auditing and rectification operation for logging in to the same logical channel.
[0039] Specifically, for each value of the first data combination, count the number of abnormally logged-in users corresponding thereto, set priorities for each value of the first data combination according to the corresponding number of abnormally logged-in users; in the order of the priorities, use the city data, the online time data, and the MAC address data to perform the auditing and rectification operation for logging in to the same logical channel.
[0040] In some possible implementation manners, after step S107, there is also step S108: Analyze the situations of each abnormally logged-in user with the same channel authentication among the users with the FTTH access type, and combine the number of abnormally logged-in users to evaluate the urgency of the auditing and rectification operation for logging in to the same logical channel, and to evaluate the quality of the installation and maintenance work in each place.
[0041] Figure 2 It is a schematic diagram of the PPPoE dial test data disclosed in the embodiment of the present invention. It should be noted that, in order to protect the privacy of relevant users, some sensitive information in this embodiment Figure 2 has been desensitized and is not used to limit the protection scope of the present invention. Such as Figure 2As shown, it is the PPPoE dial test data corresponding to a user, where Code = Accounting-Request and Acct-Status-Type = Start, so this data is the first message. According to step S102, extract the User-Name data from it to obtain the account data "wzo***"; extract the NAS-IP-Address data from it to obtain the brasIP data "221.131.*.*"; extract the NAS-Port-Id data from it to obtain the outer VLAN data "1060" and the inner VLAN data "446".
[0042] According to step S103, use the account data "wzo***" to perform correlation analysis with the asset management resource data to obtain the OLT_IP data and OLT_PON data associated with the user. Combine the brasIP data, outer VLAN data, inner VLAN data, OLT_IP data, and OLT_PON data to form a first data combination, and then compare it with the first data combinations of other users to find abnormal login users.
[0043] Assume this user is an abnormal login user, then according to step S106, extract the Acct-Session-Id data from it to obtain the city data "ZJWZH-M0426210600044694135eAAAZbw"; extract the datetime data from it to obtain the online time data "2022-04-15 09:00:05 160716"; extract the Calling-Station-Id data from it to obtain the MAC address data "c4:33:06:b3:*:*". It is used for subsequent step S107 to perform the same logical channel login audit and rectification operation, and step S108 to evaluate the quality of installation and maintenance work in each place.
[0044] When using the method described in the present invention to analyze and output the authentication data of the day according to the logical channel of "brasIP + outer VLAN + inner VLAN + OLT_IP + OLT_PON", in the case of multiple identical users, output such users and analyze the installation information of the users and the configuration information of the household line resources, so as to carry out targeted rectification subsequently. At the same time, analyze the abnormal user situations of the same channel authentication among the users of the FTTH access type, which can effectively evaluate the urgency of the same logical channel login audit and rectification, and evaluate the quality of installation and maintenance work in each place, further improving the user network perception quality and enhancing user satisfaction.
[0045] The specific embodiments described above further elaborate on the objective, technical solution and beneficial effects of the present invention. It should be understood that the above description is only the specific embodiments of the present invention and is not used to limit the protection scope of the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for verifying the same logical channel login of a household broadband account, characterized in that: The method comprises: Acquire PPPoE dial test data of at least two users, filter out login request messages from the PPPoE dial test data, and obtain at least two groups of first messages; For each group of first messages, extract the User-Name data therein to obtain the account data; extract the NAS-IP-Address data therein to obtain the brasIP data; extract the NAS-Port-Id data therein to obtain the outer VLAN data and the inner VLAN data; Obtain asset management resource data, use the account data and asset management resource data for correlation analysis, and obtain the OLT_IP data and OLT_PON data of the user; The brasIP data, outer VLAN data, inner VLAN data, OLT_IP data and OLT_PON data form a first data combination; For any two users among the at least two users, their first data combinations are compared, and if they are completely the same, the users are determined to be abnormal login users.
2. The method according to claim 1, characterized in that The step of obtaining PPPoE dial test data of at least two users, filtering the PPPoE dial test data to obtain login request messages, and obtaining at least two groups of first messages includes: PPPoE dial test data of at least two users are obtained, and messages with Code=Accounting-Request and Acct-Status-Type=Start are filtered out from the PPPoE dial test data to obtain at least two groups of first messages.
3. The method according to claim 1, characterized in that After comparing the first data combinations of any two users among the at least two users and determining the users as abnormal login users if the first data combinations are completely identical, the method further includes: For the first message corresponding to the abnormal login user, extract the Acct-Session-Id data therein to obtain the city data; extract the datetime data therein to obtain the online time data; extract the Calling-Station-Id data therein to obtain the MAC address data; Use the city data, online time data and MAC address data to perform the same logical channel login audit and rectification operations.
4. The method according to claim 3, characterized in that The use of the city data, online time data and MAC address data to perform the same logical channel login audit and rectification operation includes: For each value of the first data combination, count the corresponding number of abnormal login users, and set a priority for each value of the first data combination according to the corresponding number of abnormal login users; In the order of priority, the city data, online time data and MAC address data are used to perform the same logical channel login audit and rectification operations.
Citation Information
Patent Citations
Method and system for processing terminal disconnection and broadband remote access server
CN102142981A
Method and system for testing and accepting logical resources in FTTH mode
CN104144361A