A terminal authorization method and apparatus
Patent Information
- Application Number
- CN202211320629.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-26
- Publication Date
- 2026-09-04
- Estimated Expiration
- 2042-10-26
AI Technical Summary
[0004]本申请提供了一种终端授权方法及装置,用以解决现有技术中存在的无法精细化控制终端网络访问权限的问题
[0046]综上可知,本申请实施例提供的终端授权方法,应用于授权服务器,所述授权服务器上预先设置有AP组与授权策略之间的映射关系;所述方法包括:接收接入控制器AC发送的目标终端的计费报文,其中,所述计费报文中携带有所述目标终端接入的目标接入点AP信息;基于所述目标AP信息,确定与所述目标AP相关联的目标授权策略;将所述目标授权策略发送给所述AC,以使得所述AC基于所述目标授权策略控制所述目标终端。
Smart Images

Figure CN115767543B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network communication technology, and in particular to a terminal authorization method and apparatus. Background Technology
[0002] With the widespread adoption of wireless networks, various wireless application scenarios are emerging. For example, the AC device and server (Portal+AAA) are connected to the core device, the AP uses centralized forwarding, the network access permissions of buildings A / B / C are different, buildings A / B / C use the same SSID (Service Set Identifier), the authentication point is on the AC device, and Portal authentication is enabled.
[0003] When a terminal roams wirelessly between buildings A, B, and C, since all buildings use the same SSID, the terminal typically does not re-initiate DHCP requests or re-authenticate when switching between access points. Therefore, the terminal retains its original IP address and network access permissions. In other words, in the above scenario, it is impossible to accurately restrict the terminal's network permissions during wireless roaming. Summary of the Invention
[0004] This application provides a terminal authorization method and apparatus to solve the problem in the prior art that it is impossible to finely control terminal network access permissions.
[0005] In a first aspect, this application provides a terminal authorization method applied to an authorization server, wherein the authorization server has a pre-configured mapping relationship between AP groups and authorization policies; the method includes:
[0006] Receive a billing message from the target terminal sent by the access controller AC, wherein the billing message carries the target access point (AP) information to which the target terminal is connected;
[0007] Based on the target AP information, determine the target authorization policy associated with the target AP;
[0008] The target authorization policy is sent to the AC so that the AC controls the target terminal based on the target authorization policy.
[0009] Optionally, the method further includes:
[0010] When a change is detected in the AP information carried in the billing message of the target terminal sent by the AC, the step of determining the target authorization policy associated with the target AP based on the target AP information is executed.
[0011] Optionally, an AP group includes AP information of several APs belonging to that AP group; the step of determining the target authorization policy associated with the target AP based on the target AP information includes:
[0012] Based on the target AP information, determine the target AP group to which the target AP belongs;
[0013] Based on the target AP group and the mapping relationship between the AP group and the authorization policy, the target authorization policy associated with the AP group is determined;
[0014] The target authorization policy is determined as the authorization policy associated with the target AP.
[0015] Secondly, this application provides an authorization control method applied to an access controller (AC), the method comprising:
[0016] Detect whether the target terminal's current access point has changed;
[0017] When the target terminal is detected to have switched from another access point (AP) to the target AP, a billing message carrying the target AP information is sent to the authorization controller, so that the authorization server can determine the target authorization policy associated with the target AP based on the target AP information and send the target authorization policy to the AC;
[0018] The system receives the target authorization policy sent by the authorization controller and controls the target terminal based on the target authorization policy.
[0019] Optionally, the step of controlling the target terminal based on the target authorization policy includes:
[0020] Based on the terminal access permissions included in the target authorization policy, adjust the access permissions of the target terminal.
[0021] Thirdly, this application provides a terminal authorization device applied to an authorization server, wherein the authorization server has a pre-configured mapping relationship between AP groups and authorization policies; the device includes:
[0022] The receiving unit is used to receive the billing message of the target terminal sent by the access controller AC, wherein the billing message carries the target access point AP information accessed by the target terminal;
[0023] The determining unit is configured to determine the target authorization policy associated with the target AP based on the target AP information;
[0024] The sending unit is configured to send the target authorization policy to the AC, so that the AC controls the target terminal based on the target authorization policy.
[0025] Optionally, the device further includes a detection unit:
[0026] When the detection unit detects a change in the AP information carried in the billing message of the target terminal sent by the AC, the determination unit performs the step of determining the target authorization policy associated with the target AP based on the target AP information.
[0027] Optionally, an AP group includes AP information of several APs belonging to that AP group; when determining the target authorization policy associated with the target AP based on the target AP information, the determining unit is specifically used for:
[0028] Based on the target AP information, determine the target AP group to which the target AP belongs;
[0029] Based on the target AP group and the mapping relationship between the AP group and the authorization policy, the target authorization policy associated with the AP group is determined;
[0030] The target authorization policy is determined as the authorization policy associated with the target AP.
[0031] Fourthly, this application provides an authorization control device applied to an access controller AC, the device comprising:
[0032] The detection unit is used to detect whether the target terminal's current access AP has changed;
[0033] The sending unit, when the detection unit detects that the target terminal has switched from another access point (AP) to the target AP, is used to send a billing message carrying the target AP information to the authorization controller, so that the authorization server determines the target authorization policy associated with the target AP based on the target AP information and sends the target authorization policy to the AC;
[0034] The receiving unit is used to receive the target authorization policy sent by the authorization controller;
[0035] A control unit is used to control the target terminal based on the target authorization policy.
[0036] Optionally, when controlling the target terminal based on the target authorization policy, the control unit is specifically used for:
[0037] Based on the terminal access permissions included in the target authorization policy, adjust the access permissions of the target terminal.
[0038] Fifthly, embodiments of this application provide a terminal authorization device, which includes:
[0039] Memory, used to store program instructions;
[0040] A processor is configured to invoke program instructions stored in the memory and execute the steps of the method as described in any one of the first aspects above, according to the obtained program instructions.
[0041] In a sixth aspect, embodiments of this application also provide a computer-readable storage medium storing computer-executable instructions for causing the computer to perform the steps of the method as described in any of the first aspects above.
[0042] Seventhly, embodiments of this application provide a terminal authorization device, the terminal authorization device comprising:
[0043] Memory, used to store program instructions;
[0044] A processor is configured to invoke program instructions stored in the memory and execute the steps of the method as described in any one of the second aspects above, according to the obtained program instructions.
[0045] Eighthly, embodiments of this application also provide a computer-readable storage medium storing computer-executable instructions for causing the computer to perform the steps of the method as described in any of the second aspects above.
[0046] In summary, the terminal authorization method provided in this application is applied to an authorization server, which has a pre-configured mapping relationship between AP groups and authorization policies. The method includes: receiving a billing message of a target terminal sent by an access controller (AC), wherein the billing message carries target access point (AP) information accessed by the target terminal; determining a target authorization policy associated with the target AP based on the target AP information; and sending the target authorization policy to the AC so that the AC controls the target terminal based on the target authorization policy.
[0047] Using the terminal authorization method provided in this application embodiment, in wireless application scenarios where the same SSID is used in multiple areas and the network control permissions of the multiple areas are different, when a terminal roams wirelessly from one area to another, the network access permissions of the terminal can be dynamically adjusted on the AC side without the need for terminal re-authentication, thereby achieving fine-grained management of the terminal's network access permissions. Attached Figure Description
[0048] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments of this application or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this application. For those skilled in the art, other drawings can be obtained based on these drawings of the embodiments of this application.
[0049] Figure 1 A detailed flowchart of a terminal authorization method provided in an embodiment of this application;
[0050] Figure 2 A detailed flowchart of another terminal authorization method provided in this application embodiment;
[0051] Figure 3 This is a schematic diagram of the structure of a terminal authorization device provided in an embodiment of this application;
[0052] Figure 4 This is a schematic diagram of another terminal authorization device provided in an embodiment of this application;
[0053] Figure 5 This application provides a schematic diagram of the hardware architecture of a terminal authorization device.
[0054] Figure 6 This is a schematic diagram of the hardware architecture of another terminal licensing device provided in an embodiment of this application. Detailed Implementation
[0055] The terminology used in the embodiments of this application is for the purpose of describing particular embodiments only and is not intended to limit the application. The singular forms “a,” “the,” and “the” as used in this application and claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to any and all possible combinations comprising one or more of the associated listed items.
[0056] It should be understood that although the terms first, second, third, etc., may be used to describe various information in embodiments of this application, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, without departing from the scope of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" may also be interpreted as "when," "when," or "in response to a determination."
[0057] In practical applications, with the development of networks, various wireless application scenarios are emerging. In the scenario of terminal wireless roaming, if each area uses the same SSID and each area is assigned different network access permissions, if a terminal roams from area 1 to area 2, since area 1 and area 2 use the same SSID, the terminal will not re-initiate a DHCP request or re-authenticate. Therefore, the terminal still retains its original IP address and network access permissions. In other words, the terminal in area 2 can still have the network access permissions assigned when authenticating in area 1, and it is impossible to accurately restrict the terminal's network access permissions in area 2.
[0058] For example, see Figure 1 The diagram shown is a detailed flowchart of a terminal authorization method provided in an embodiment of this application. This method is applied to an authorization server, which has a pre-configured mapping relationship between AP groups and authorization policies. The method includes the following steps:
[0059] Step 100: Receive the billing message of the target terminal sent by the access controller AC, wherein the billing message carries the target access point (AP) information accessed by the target terminal.
[0060] In this embodiment of the application, before performing step 100, the wireless terminal performs Portal authentication through AP, AC, Portal server and authorization server (e.g., AAA server). The AAA server sends the authorization policy to the AC connected to the AP (e.g., AP1) accessed by the wireless terminal based on preset rules.
[0061] After confirming that the wireless terminal has passed Portal authentication, the AC sends an accounting message to the AAA server. This accounting message carries the information of AP1. When the wireless terminal roams from area 1 to area 2, the AP accessed by the wireless terminal changes from AP1 to AP2. The AC can detect the change in the AP accessed by the wireless terminal. At this time, when the AC subsequently sends an accounting message to the AAA server, this accounting message carries the information of AP2.
[0062] Step 110: Based on the target AP information, determine the target authorization policy associated with the target AP.
[0063] In this embodiment of the application, the authorization server receives billing messages of the target terminal periodically sent by the AC. Each billing message carries the AP information currently accessed by the target terminal. When the authorization server detects that the AP information carried in the billing message of the target terminal sent by the AC has changed, it performs the step of determining the target authorization policy associated with the target AP based on the target AP information.
[0064] In this embodiment of the application, an AP group includes AP information (e.g., AP identification information / AP address information) of several APs belonging to the AP group. Therefore, when determining the target authorization policy associated with the target AP based on the target AP information, a preferred implementation is as follows: based on the target AP information, determine the target AP group to which the target AP belongs; based on the target AP group and the mapping relationship between the AP group and authorization policies, determine the target authorization policy associated with the AP group; and determine the target authorization policy as the authorization policy associated with the target AP.
[0065] In this embodiment, if the target terminal switches its access point from AP1 to AP2, and AP1 and AP2 belong to the same AP group, then the authorization server does not need to perform subsequent steps. However, in practical applications, APs in different areas with different network access permissions generally belong to different AP groups, while APs in different areas with the same network access permissions can belong to the same AP group.
[0066] Once it is determined that AP1 and AP2 belong to different AP groups, the step of determining the target authorization policy associated with AP2 based on the AP2 information needs to be performed.
[0067] Step 120: Send the target authorization policy to the AC so that the AC controls the target terminal based on the target authorization policy.
[0068] Specifically, after determining the target authorization policy corresponding to the AP2 currently accessed by the target terminal, the authorization server sends the target authorization policy to the AC, so that the AC can adjust the network access permissions of the target terminal based on the target authorization policy.
[0069] In practical applications, the target authorization policy can be carried in the COA message sent by the authorization server to the AC. In this embodiment, no specific limitations are imposed.
[0070] In this way, when a terminal roams in different areas using the same SSID, the function of dynamically adjusting the terminal's network access permissions is realized without the terminal re-authenticating, thus meeting the need for fine-grained terminal permission control in different areas with the same SSID.
[0071] For example, see Figure 2 The diagram shown is a detailed flowchart of a terminal authorization method provided in an embodiment of this application. This method is applied to an access controller (AC) and includes the following steps:
[0072] Step 200: Detect whether the target terminal's current access AP has changed.
[0073] Step 210: When the target terminal is detected to have switched from another access point (AP) to the target AP, a billing message carrying the target AP information is sent to the authorization controller.
[0074] The authorization server determines the target authorization policy associated with the target AP based on the target AP information, and sends the target authorization policy to the AC;
[0075] Step 220: Receive the target authorization policy sent by the authorization controller, and control the target terminal based on the target authorization policy.
[0076] Specifically, when controlling the target terminal based on the target authorization policy, a preferred implementation is to adjust the access permissions of the target terminal based on the terminal access permissions included in the target authorization policy.
[0077] For example, see Figure 3 The diagram shown is a structural schematic of a terminal authorization device provided in an embodiment of this application. This device is applied to an authorization server, which has a pre-configured mapping relationship between AP groups and authorization policies. The device includes:
[0078] The receiving unit 30 is used to receive a billing message of the target terminal sent by the access controller AC, wherein the billing message carries the target access point AP information accessed by the target terminal;
[0079] The determining unit 31 is used to determine the target authorization policy associated with the target AP based on the target AP information;
[0080] The sending unit 32 is used to send the target authorization policy to the AC, so that the AC controls the target terminal based on the target authorization policy.
[0081] Optionally, the device further includes a detection unit:
[0082] When the detection unit detects a change in the AP information carried in the billing message of the target terminal sent by the AC, the determination unit 31 performs the step of determining the target authorization policy associated with the target AP based on the target AP information.
[0083] Optionally, an AP group includes AP information of several APs belonging to that AP group; when determining the target authorization policy associated with the target AP based on the target AP information, the determining unit 31 is specifically used for:
[0084] Based on the target AP information, determine the target AP group to which the target AP belongs;
[0085] Based on the target AP group and the mapping relationship between the AP group and the authorization policy, the target authorization policy associated with the AP group is determined;
[0086] The target authorization policy is determined as the authorization policy associated with the target AP.
[0087] For example, see Figure 4 The diagram shown is a structural schematic of a terminal authorization device provided in an embodiment of this application. This device is applied to an access controller (AC) and includes:
[0088] The detection unit 40 is used to detect whether the current access AP of the target terminal has changed;
[0089] Sending unit 41, when the detection unit detects that the target terminal has switched from other access points (APs) to the target AP, the sending unit is used to send a billing message carrying the target AP information to the authorization controller, so that the authorization server determines the target authorization policy associated with the target AP based on the target AP information, and sends the target authorization policy to the AC;
[0090] Receiving unit 42 is used to receive the target authorization policy sent by the authorization controller;
[0091] Control unit 43 is used to control the target terminal based on the target authorization policy.
[0092] Optionally, when controlling the steps of the target terminal based on the target authorization strategy, the control unit 43 is specifically used for:
[0093] Based on the terminal access permissions included in the target authorization policy, adjust the access permissions of the target terminal.
[0094] These units can be one or more integrated circuits configured to implement the above methods, such as one or more Application Specific Integrated Circuits (ASICs), one or more digital signal processors (DSPs), or one or more Field Programmable Gate Arrays (FPGAs). Alternatively, when one of these units is implemented using processing element scheduler code, the processing element can be a general-purpose processor, such as a Central Processing Unit (CPU) or other processor capable of calling program code. Furthermore, these units can be integrated together to form a system-on-a-chip (SOC).
[0095] Furthermore, regarding the terminal authorization device provided in this application embodiment, from a hardware perspective, the hardware architecture diagram of the terminal authorization device can be found in [reference needed]. Figure 5 As shown, the terminal authorization device may include: a memory 50 and a processor 51.
[0096] The memory 50 is used to store program instructions; the processor 51 calls the program instructions stored in the memory 50 and executes the method embodiment applied to the authorization controller as described above according to the obtained program instructions. The specific implementation method and technical effect are similar, and will not be described again here.
[0097] Optionally, this application also provides an authorization controller, including at least one processing element (or chip) for performing the above-described method embodiments applied to the authorization controller.
[0098] Optionally, this application also provides a program product, such as a computer-readable storage medium storing computer-executable instructions for causing the computer to perform the above-described method embodiments applied to an authorization controller.
[0099] Furthermore, regarding the terminal authorization device provided in this application embodiment, from a hardware perspective, the hardware architecture diagram of the terminal authorization device can be found in [reference needed]. Figure 6 As shown, the terminal authorization device may include: a memory 60 and a processor 61.
[0100] The memory 60 is used to store program instructions; the processor 61 calls the program instructions stored in the memory 60 and executes the method embodiment applied to the access controller as described above according to the obtained program instructions. The specific implementation and technical effects are similar, and will not be described again here.
[0101] Optionally, this application also provides an access controller, including at least one processing element (or chip) for performing the above-described method embodiments applied to the access controller.
[0102] Optionally, this application also provides a program product, such as a computer-readable storage medium storing computer-executable instructions for causing the computer to perform the above-described method embodiments applied to an access controller.
[0103] Here, a machine-readable storage medium can be any electronic, magnetic, optical, or other physical storage device that can contain or store information, such as executable instructions, data, etc. For example, a machine-readable storage medium can be: RAM (Random Access Memory), volatile memory, non-volatile memory, flash memory, storage drives (such as hard disk drives), solid-state drives, any type of storage disk (such as optical discs, DVDs, etc.), or similar storage media, or combinations thereof.
[0104] The systems, devices, modules, or units described in the above embodiments can be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer, which can take the form of a personal computer, laptop computer, cellular phone, camera phone, smartphone, personal digital assistant, media player, navigation device, email sending and receiving device, game console, tablet computer, wearable device, or any combination of these devices.
[0105] For ease of description, the above devices are described separately by function as various units. Of course, in implementing this application, the functions of each unit can be implemented in one or more software and / or hardware.
[0106] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, embodiments of this application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0107] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0108] Furthermore, these computer program instructions can also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in the process. Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0109] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0110] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.
Claims
1. A terminal authorization method, characterized in that, Applied to an authorization server, the authorization server has a pre-configured mapping relationship between AP groups and authorization policies. APs in different areas with the same network access permissions belong to the same AP group, and APs in different areas with different network access permissions belong to different AP groups. The method includes: Receive a billing message from the target terminal sent by the access controller AC, wherein the billing message carries the target access point AP information that the target terminal has accessed after being authenticated by the Portal; Based on the target AP information, a target authorization policy associated with the target AP is determined, and there is a mapping relationship between the target authorization policy and the target AP group to which the target AP belongs; The target authorization policy is sent to the AC so that the AC controls the network access permissions of the target terminal based on the target authorization policy.
2. The method as described in claim 1, characterized in that, The method further includes: When a change is detected in the AP information carried in the billing message of the target terminal sent by the AC, the step of determining the target authorization policy associated with the target AP based on the target AP information is executed.
3. The method as described in claim 2, characterized in that, An AP group includes AP information for several APs belonging to that AP group; The steps for determining the target authorization policy associated with the target AP based on the target AP information include: Based on the target AP information, determine the target AP group to which the target AP belongs; Based on the target AP group and the mapping relationship between the AP group and the authorization policy, the target authorization policy associated with the AP group is determined; The target authorization policy is determined as the authorization policy associated with the target AP.
4. An authorization control method, characterized in that, Applied to an access controller AC, the method includes: Detect whether the target terminal's current access AP has changed after Portal authentication; When a target terminal is detected to switch from another access point (AP) to the target AP, a billing message carrying the target AP information is sent to the authorization controller. This allows the authorization server to determine the target authorization policy associated with the target AP based on the target AP information and send the target authorization policy to the AC. The authorization server has a pre-set mapping relationship between AP groups and authorization policies. APs in different areas with the same network access permissions belong to the same AP group, and APs in different areas with different network access permissions belong to different AP groups. There is a mapping relationship between the target authorization policy and the target AP group to which the target AP belongs. The system receives the target authorization policy sent by the authorization controller and controls the network access permissions of the target terminal based on the target authorization policy.
5. The method as described in claim 4, characterized in that, The steps for controlling the network access permissions of the target terminal based on the target authorization policy include: Based on the terminal access permissions included in the target authorization policy, adjust the network access permissions of the target terminal.
6. A terminal authorization device, characterized in that, Applied to an authorization server, the authorization server has a pre-configured mapping relationship between AP groups and authorization policies. APs in different areas with the same network access permissions belong to the same AP group, and APs in different areas with different network access permissions belong to different AP groups. The device includes: The receiving unit is used to receive a billing message sent by the access controller AC after the target terminal has been authenticated by the Portal, wherein the billing message carries the target access point AP information accessed by the target terminal; The determining unit is configured to determine, based on the target AP information, a target authorization policy associated with the target AP, wherein there is a mapping relationship between the target authorization policy and the target AP group to which the target AP belongs; The sending unit is configured to send the target authorization policy to the AC, so that the AC controls the network access permissions of the target terminal based on the target authorization policy.
7. The apparatus as claimed in claim 6, characterized in that, The device also includes a detection unit: When the detection unit detects a change in the AP information carried in the billing message of the target terminal sent by the AC, the determination unit performs the step of determining the target authorization policy associated with the target AP based on the target AP information.
8. The apparatus as claimed in claim 7, characterized in that, An AP group includes AP information of several APs belonging to that AP group; when determining the target authorization policy associated with the target AP based on the target AP information, the determining unit is specifically used for: Based on the target AP information, determine the target AP group to which the target AP belongs; Based on the target AP group and the mapping relationship between the AP group and the authorization policy, the target authorization policy associated with the AP group is determined; The target authorization policy is determined as the authorization policy associated with the target AP.
9. An authorization control device, characterized in that, The device is applied to an access controller AC and includes: The detection unit is used to detect whether the current access AP of the target terminal after it has been authenticated by the Portal has changed; The sending unit, when the detection unit detects that the target terminal has switched from another access point (AP) to the target AP, is used to send a billing message carrying the target AP information to the authorization controller, so that the authorization server determines the target authorization policy associated with the target AP based on the target AP information and sends the target authorization policy to the AC. The authorization server has a pre-set mapping relationship between AP groups and authorization policies. APs in different areas with the same network access permissions belong to the same AP group, and APs in different areas with different network access permissions belong to different AP groups. There is a mapping relationship between the target authorization policy and the target AP group to which the target AP belongs. The receiving unit is used to receive the target authorization policy sent by the authorization controller; The control unit is used to control the network access permissions of the target terminal based on the target authorization policy.
10. The apparatus as claimed in claim 9, characterized in that, When controlling the target terminal based on the target authorization strategy, the control unit is specifically used for: Based on the terminal access permissions included in the target authorization policy, adjust the network access permissions of the target terminal.
Citation Information
Patent Citations
Method, system and equipment for controlling wireless user access
CN101765114A