An access authentication method and device
Patent Information
- Application Number
- CN202211468201.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-22
- Publication Date
- 2026-09-04
- Estimated Expiration
- 2042-11-22
AI Technical Summary
[0004]可见,在这种802.1X认证流程中,AAA服务器需要与无线终端进行多次交互才能知晓无线终端EAP认证方式,这就导致整个802.1X认证流程耗时较长,进而影响相关用户的接入体验
[0023]在本申请实施例中,AAA服务器在接收到来自无线终端的携带有该无线终端的身份信息的第一EAP响应报文的情形下,不再逐一地将自身支持的EAP认证方式发送给无线终端,即,与无线终端进行多次尝试交互,直到尝试到无线终端支持的EAP认证方式,而是向无线终端发送用于请求无线终端支持的EAP认证方式的第一EAP请求报文,即,主动请求无线终端支持的EAP认证方式,这样一来,AAA服务器可以基于无线终端支持的EAP认证方式和自身支持的EAP认证方式,来确定无线终端需要使用的EAP认证方式,并向无线终端发起确定出的EAP认证方式对应的802.1X认证流程。
Smart Images

Figure CN115835205B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to an access authentication method and apparatus. Background Technology
[0002] With the widespread adoption of mobile devices, Wireless Local Area Networks (WLANs) have become widely used. For network security reasons, 802.1X authentication technology is typically used in WLANs to authenticate wireless devices that need to access the network.
[0003] Currently, in one 802.1X authentication process, when the Authentication, Authorization, Accounting (AAA) server receives an Extensible Authentication Protocol (EAP) request message carrying the identity information of any wireless terminal connected to the access device, the AAA server cannot identify the EAP authentication methods supported by the wireless terminal. In this case, the AAA server typically includes the EAP authentication methods it supports in the EAP request message and sends it to the wireless terminal through the access device. Subsequently, if the wireless terminal determines that it does not support the EAP authentication method carried in the relevant EAP request message, it sends an EAP response message to the AAA server through the access device to indicate that the wireless terminal does not support the relevant EAP authentication method. If it determines that it supports the EAP authentication method carried in the relevant EAP request message, it then sends an EAP response message to the AAA server through the access device to negotiate the EAP authentication method, and continues the subsequent 802.1X authentication process.
[0004] As can be seen, in this 802.1X authentication process, the AAA server needs to interact with the wireless terminal multiple times to know the wireless terminal's EAP authentication method. This results in the entire 802.1X authentication process taking a long time, which in turn affects the access experience of relevant users. Summary of the Invention
[0005] To overcome the problems existing in related technologies, this application provides an access authentication method and apparatus.
[0006] According to a first aspect of the embodiments of this application, an access authentication method is provided, the method being applied to an AAA server, the method comprising:
[0007] When the access device receives a first EAP response message carrying the identity information of any wireless terminal connected to the access device, the access device sends a first EAP request message to the wireless terminal to request the wireless terminal to support an EAP authentication method.
[0008] If the access device receives a second EAP response message from the wireless terminal carrying an EAP authentication method supported by the wireless terminal, then based on the EAP authentication methods supported by the wireless terminal and the EAP authentication methods supported by the wireless terminal, the access device determines the EAP authentication method that the wireless terminal needs to use, and initiates an 802.1X authentication process corresponding to the determined EAP authentication method to the wireless terminal. The second EAP response message is sent by the wireless terminal to the AAA server through the access device when it receives the first EAP request message through the access device and determines that it has enabled the function of sending its supported EAP authentication methods.
[0009] If the access device receives a first EAP denial response message from the wireless terminal, the access device initiates an existing 802.1X authentication process to the wireless terminal. The first EAP denial response message is sent by the wireless terminal to the AAA server through the access device when it receives the first EAP request message through the access device and determines that it has not enabled the function of sending the EAP authentication method it supports.
[0010] According to a second aspect of the embodiments of this application, an access authentication method is provided, the method being applied to a wireless terminal, the method comprising:
[0011] After sending a first EAP response message carrying the identity information of the wireless terminal to the AAA server through the access device, if the access device receives a first EAP request message from the AAA server requesting the wireless terminal, it determines whether it has enabled the function of sending the EAP authentication method it supports.
[0012] When the determination result is yes, the access device sends a second EAP response message carrying its supported EAP authentication method to the AAA server, so that when the AAA server receives the second EAP response message from the wireless terminal through the access device, it determines the EAP authentication method that the wireless terminal needs to use based on the EAP authentication methods supported by the wireless terminal and its own supported EAP authentication methods, and initiates the 802.1X authentication process corresponding to the determined EAP authentication method to the wireless terminal through the access device.
[0013] If the determination result is negative, the access device sends a first EAP negative response message to the AAA server to indicate that the wireless terminal has not enabled the function of sending its supported EAP authentication methods. This allows the AAA server to initiate the existing 802.1X authentication process to the wireless terminal when it receives the first EAP negative response message from the wireless terminal through the access device.
[0014] According to a third aspect of the embodiments of this application, an access authentication device is provided, the device being applied to an AAA server, the device comprising:
[0015] The first processing module is configured to, when receiving a first EAP response message carrying the identity information of any wireless terminal from any wireless terminal connected to the access device via the access device, send a first EAP request message to the wireless terminal via the access device to request the wireless terminal to support an EAP authentication method.
[0016] The second processing module is configured to, when receiving a second EAP response message from the wireless terminal carrying an EAP authentication method supported by the wireless terminal through the access device, determine the EAP authentication method that the wireless terminal needs to use based on the EAP authentication methods supported by the wireless terminal and its own supported EAP authentication methods, and initiate an 802.1X authentication process corresponding to the determined EAP authentication method to the wireless terminal through the access device. The second EAP response message is sent by the wireless terminal to the AAA server through the access device when it receives the first EAP request message through the access device and determines that it has enabled the function of sending its own supported EAP authentication methods.
[0017] The third processing module is used to initiate an existing 802.1X authentication process to the wireless terminal through the access device when it receives a first EAP negative response message from the wireless terminal through the access device. The first EAP negative response message is sent by the wireless terminal to the AAA server through the access device when it receives the first EAP request message through the access device and determines that it has not enabled the function of sending the EAP authentication method it supports.
[0018] According to a fourth aspect of the embodiments of this application, an access authentication device is provided, the device being applied to a wireless terminal, the device comprising:
[0019] The judgment module is used to determine whether it has enabled the function of sending the EAP authentication method it supports after sending the first EAP response message carrying the identity information of the wireless terminal to the AAA server through the access device, if the access device receives a first EAP request message from the AAA server to request the wireless terminal.
[0020] The first processing module is configured to, when the judgment result of the judgment module is yes, send a second EAP response message carrying its supported EAP authentication method to the AAA server through the access device, so that when the AAA server receives the second EAP response message from the wireless terminal through the access device, it determines the EAP authentication method that the wireless terminal needs to use based on the EAP authentication methods supported by the wireless terminal and its own supported EAP authentication methods, and initiates the 802.1X authentication process corresponding to the determined EAP authentication method to the wireless terminal through the access device;
[0021] The second processing module is configured to, when the judgment result of the judgment module is negative, send a first EAP negative response message to the AAA server through the access device, indicating that the wireless terminal has not enabled the function of sending its supported EAP authentication methods, so that when the AAA server receives the first EAP negative response message from the wireless terminal through the access device, it initiates the existing 802.1X authentication process to the wireless terminal through the access device.
[0022] The technical solutions provided by the embodiments of this application may include the following beneficial effects:
[0023] In this embodiment, when the AAA server receives a first EAP response message from a wireless terminal carrying the wireless terminal's identity information, it no longer sends the EAP authentication methods it supports to the wireless terminal one by one, i.e., it tries to interact with the wireless terminal multiple times until it finds an EAP authentication method supported by the wireless terminal. Instead, it sends a first EAP request message to the wireless terminal to request the EAP authentication method supported by the wireless terminal. In other words, it actively requests the EAP authentication method supported by the wireless terminal. In this way, the AAA server can determine the EAP authentication method that the wireless terminal needs to use based on the EAP authentication methods supported by the wireless terminal and the EAP authentication methods it supports, and initiate the 802.1X authentication process corresponding to the determined EAP authentication method to the wireless terminal.
[0024] It is evident that this 802.1X authentication process can significantly reduce the number of authentication interactions between the AAA server and the wireless terminal, thereby greatly shortening the authentication time of the entire 802.1X authentication process and improving the access experience for relevant users.
[0025] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application. Attached Figure Description
[0026] The accompanying drawings, which are incorporated in and form part of this application, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0027] Figure 1 This is one of the flowcharts illustrating an access authentication method provided in an embodiment of this application;
[0028] Figure 2 A second schematic flowchart illustrating an access authentication method provided in an embodiment of this application;
[0029] Figure 3 A schematic diagram of some fields of the first EAP request message provided in the embodiments of this application;
[0030] Figure 4 The third schematic diagram of an access authentication method provided in this application embodiment;
[0031] Figure 5 This is one of the structural schematic diagrams of an access authentication device provided in an embodiment of this application;
[0032] Figure 6 This is a second schematic diagram of the structure of an access authentication device provided in an embodiment of this application;
[0033] Figure 7 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0034] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0035] The terminology used in this application is for the purpose of describing particular embodiments only and is not intended to be limiting of the application. The singular forms “a,” “the,” and “the” used in this application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any or all possible combinations of one or more of the associated listed items.
[0036] It should be understood that although the terms first, second, third, etc., may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, without departing from the scope of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the words “if” or “suppose” as used herein may be interpreted as “when…” or “when…”.
[0037] The embodiments of this application will now be described in detail.
[0038] This application provides an access authentication method, which is applied to an AAA server, such as... Figure 1 As shown, the method may include the following steps:
[0039] S11. When the access device receives a first EAP response message carrying the identity information of any wireless terminal connected to the access device, the access device sends a first EAP request message to the wireless terminal to request the wireless terminal to support an EAP authentication method.
[0040] In this step, the access device can be either a fat access point (AP) or an access controller (AC).
[0041] S12. If the access device receives a second EAP response message from the wireless terminal carrying the EAP authentication method supported by the wireless terminal, then based on the EAP authentication methods supported by the wireless terminal and the EAP authentication methods supported by the access device, the access device determines the EAP authentication method that the wireless terminal needs to use, and initiates the 802.1X authentication process corresponding to the determined EAP authentication method to the wireless terminal through the access device.
[0042] In this step, the second EAP response message is sent by the wireless terminal to the AAA server through the access device after receiving the first EAP request message through the access device and determining that it has enabled the function of sending the EAP authentication method it supports.
[0043] S13. If the access device receives the first EAP negative response message from the wireless terminal, then the access device initiates the existing 802.1X authentication process to the wireless terminal.
[0044] In this step, the first EAP negative response message is an EAP negative response message used to indicate that the wireless terminal has not enabled the function of sending the EAP authentication method it supports. It is sent by the wireless terminal to the AAA server through the access device when it receives the first EAP request message through the access device and determines that it has not enabled the function of sending the EAP authentication method it supports.
[0045] Specifically, in step S11 above, the first EAP response message is actually sent by the access device to the AAA server when it receives the first EAP response message (which can be called an EAP-Response / Identity message) sent by the wireless terminal carrying the identity information of the wireless terminal. The first EAP response message is encapsulated in a Remote Authentication Dial-In User Service (RADIUS) access request message.
[0046] Here, the identity information of the wireless terminal may include the username information of the wireless terminal, etc.
[0047] Furthermore, in step S11 above, when the AAA server sends a first EAP request message to the wireless terminal via the access device to request the wireless terminal to support EAP authentication methods, the format of the field in the first EAP request message that instructs the wireless terminal to fill in the EAP authentication methods supported by the wireless terminal (referred to as the support EAP Methods field) can be as follows: Figure 2 As shown.
[0048] exist Figure 2 In the configuration, the Type field has a value of 254, indicating that it is an ExpandedType field; the Vendor-Id field has the vendor ID; the Vendor-Type field has the value corresponding to the vendor's expanded type; and the Client EAP field has a value of 1, indicating that... Figure 2 The fields in the field indicate which EAP authentication methods the wireless terminal supports; the length field is the length of the EAP Methods field (also known as the EAP authentication method); the EAP Methods field is the value corresponding to the EAP authentication method supported by the wireless terminal.
[0049] Here, the EAP Methods field can have one or more values. In one example, the value is 13 when the EAP authentication method is Extensible Authentication Protocol-Transport Layer Security (EAP-TLS); 21 when the EAP authentication method is Extensible Authentication Protocol-Tunneled Transport Layer Security (EAP-TTLS); and 25 when the EAP authentication method is Protected Extensible Authentication Protocol (PEAP).
[0050] It should be noted that in step S11 above, when the AAA server sends the first EAP request message (which can be called EAP-Request / support EAPmethods) to the wireless terminal through the access device to request the wireless terminal to support the EAP authentication method, it first encapsulates the first EAP request message in a RADIUS access-challenge message and sends it to the access device, which then sends the first EAP request message to the wireless terminal.
[0051] Specifically, in step S12 above, the second EAP response message is actually sent by the access device to the AAA server when it receives the second EAP response message (which can be called EAP-Response / support EAP methods message) sent by the wireless terminal, which carries the EAP authentication method supported by the wireless terminal. The second EAP response message is encapsulated in a RADIUS Access-Request message.
[0052] For example, the content of the field containing the EAP authentication method carried in the second EAP response message mentioned above can be shown in Table 1.
[0053] Type 254 Vendor-Id A Vendor-Type 200 Client EAP 1 Length 2 Client EAP 25
[0054] Table 1
[0055] Additionally, in step S12 above, the AAA server can determine the EAP authentication method required by the wireless terminal in the following ways:
[0056] Choose the EAP authentication method that is supported by both the wireless terminal and the terminal itself, from the EAP authentication methods supported by the wireless terminal and the EAP authentication methods supported by the terminal itself.
[0057] Choose one EAP authentication method from the selected options and select it as the EAP authentication method required by the wireless terminal.
[0058] In this determination method, when the AAA server selects an EAP authentication method from the available options, if only one EAP authentication method is available, the AAA server will determine the selected EAP authentication method as the EAP authentication method required by the wireless terminal. If multiple EAP authentication methods are available, the AAA server can randomly select one from the available options and determine it as the EAP authentication method required by the wireless terminal. Of course, other methods can also be used to select an EAP authentication method from the available options, which will not be listed here.
[0059] Here, the determined EAP authentication method can be EAP-TLS authentication, EAP-TTLS authentication, or PEAP authentication.
[0060] Of course, this application is not limited to the above-mentioned EAP certification methods, and they will not be listed one by one here.
[0061] It should be noted that in step S12 above, the specific initiation operation of the AAA server to initiate the 802.1X authentication process corresponding to the determined EAP authentication method to the wireless terminal through the access device is existing technology and will not be described in detail here.
[0062] It should be further noted that, in this embodiment of the application, after the AAA server completes the above step S11, if it subsequently receives an EAP-Response / Nak (also known as an EAP negative response message) from the wireless terminal through the access device, it means that the wireless terminal has not enabled the function of sending its supported EAP authentication methods. In this case, the AAA server still processes according to the existing process, that is, it carries its supported EAP authentication methods in the EAP request message one by one and sends them to the wireless terminal through the access device.
[0063] Furthermore, in this embodiment of the application, in order to further shorten the authentication time of the entire 802.1X authentication process, the AAA server can also perform either of the following two operations:
[0064] The first operation: Before sending the first EAP request message to the wireless terminal through the access device to request the wireless terminal to support the EAP authentication method, determine whether the local device has a record of the first EAP authentication method recently used by the wireless terminal.
[0065] If the determination result is negative, the step of sending the first EAP request message to the wireless terminal through the access device is executed.
[0066] When the judgment result is yes, the access device initiates the 802.1X authentication process corresponding to the first EAP authentication method to the wireless terminal, and when the access device receives the second EAP negative response message from the wireless terminal, the access device initiates the existing 802.1X authentication process to the wireless terminal.
[0067] The second EAP negative response message is sent by the wireless terminal to the AAA server through the access device when it receives the first second EAP request message corresponding to the first EAP authentication method from the AAA server through the access device and determines that it no longer supports the first EAP authentication method.
[0068] The second operation: Before determining the EAP authentication method that the wireless terminal needs to use, check whether the local system records the second EAP authentication method recently used by the wireless terminal.
[0069] If the result is negative, proceed to determine the EAP authentication method that the wireless terminal needs to use based on the EAP authentication methods supported by the wireless terminal and the EAP authentication methods it supports.
[0070] If the judgment result is yes, and the second EAP authentication method is included among the EAP authentication methods supported by the wireless terminal, then the second EAP authentication method is determined as the EAP authentication method that the wireless terminal needs to use, and the 802.1X authentication process corresponding to the determined EAP authentication method is initiated to the wireless terminal through the access device.
[0071] If the second EAP authentication method is not included in the EAP authentication methods supported by the wireless terminal, then select an EAP authentication method supported by both the wireless terminal and itself from the EAP authentication methods supported by the wireless terminal and the EAP authentication methods supported by the wireless terminal. Then, select one EAP authentication method from the selected EAP authentication methods and determine it as the EAP authentication method to be used by the wireless terminal. Then, initiate the 802.1X authentication process corresponding to the determined EAP authentication method to the wireless terminal through the access device, and change the locally recorded second EAP authentication method to the determined EAP authentication method.
[0072] Regardless of which of the above operation procedures the AAA server performs, after performing the step of determining the EAP authentication method that the wireless terminal needs to use based on the EAP authentication methods supported by the wireless terminal and the EAP authentication methods it supports, the AAA server will also record the determined EAP authentication method as the EAP authentication method most recently used by the wireless terminal.
[0073] In this embodiment of the application, the AAA server can record the EAP authentication methods recently used by the wireless terminal in various ways. In one example, the AAA server can record the EAP authentication methods recently used by the wireless terminal in a table format, as shown in Table 2 below.
[0074]
[0075] Table 2
[0076] It should be noted that when recording the most recently used EAP authentication method of a wireless terminal in Table 2, the AAA server will also change the time of the most recently used EAP authentication method of any wireless terminal when changing the locally recorded EAP authentication method (which may be the time when the corresponding EAP authentication method was changed).
[0077] It should be further noted that, in this embodiment of the application, in order to avoid the AAA server recording too much information and occupying too many device resources, the AAA server can perform aging processing on all the EAP authentication methods recently used by all wireless terminals recorded locally according to the set aging time.
[0078] Here, the aging time can be set by the administrator according to the actual needs of the network where the AAA server is located, and configured in advance on the AAA server.
[0079] The above describes the implementation process of the access authentication method from the perspective of the AAA server. The following describes the implementation process of the access authentication method from the perspective of the wireless terminal.
[0080] This application also provides an access authentication method, which is applied to a wireless terminal, such as... Figure 2 As shown, the method may include the following steps:
[0081] S21. After sending the first EAP response message carrying the identity information of the wireless terminal to the AAA server through the access device, if the access device receives a first EAP request message from the AAA server to request the wireless terminal, it determines whether it has enabled the function of sending the EAP authentication method it supports; if the determination result is yes, proceed to step S22; if the determination result is no, proceed to step S23.
[0082] S22. Send a second EAP response message carrying the EAP authentication method it supports to the AAA server through the access device, so that when the AAA server receives the second EAP response message from the wireless terminal through the access device, it determines the EAP authentication method that the wireless terminal needs to use based on the EAP authentication methods supported by the wireless terminal and the EAP authentication methods it supports, and initiates the 802.1X authentication process corresponding to the determined EAP authentication method to the wireless terminal through the access device.
[0083] S23. Send a first EAP negative response message to the AAA server through the access device to indicate that the wireless terminal has not enabled the function of sending its supported EAP authentication methods, so that when the AAA server receives the first EAP negative response message from the wireless terminal through the access device, it initiates the existing 802.1X authentication process to the wireless terminal through the access device.
[0084] It should be noted that, in this embodiment of the application, after the wireless terminal sends a first EAP response message carrying the wireless terminal's identity information to the AAA server through the access device, it can also perform the following operations:
[0085] If the access device receives the first second EAP request message corresponding to the target EAP authentication method from the AAA server and determines that the target EAP authentication method is no longer supported, then the access device sends a second EAP negative response message to the AAA server to indicate that the wireless terminal does not support the target EAP authentication method. This will enable the AAA server to initiate the existing 802.1X authentication process to the wireless terminal when it receives the second EAP negative response message from the wireless terminal through the access device.
[0086] The target EAP authentication method is the EAP authentication method most recently used by the wireless terminal that is recorded locally by the AAA server. The target EAP authentication method is determined by the AAA server when it receives a third EAP response message carrying identity information from the wireless terminal through the access device and does not record the target EAP authentication method locally, based on the EAP authentication methods supported by the wireless terminal carried in the fourth EAP response message from the wireless terminal received through the access device and the EAP authentication methods supported by the server itself.
[0087] The specific process for determining the target EAP authentication method has been described from the perspective of the AAA server and will not be detailed here.
[0088] It should be further noted that, in the embodiments of this application, for a wireless terminal, after sending a first EAP response message carrying the identity information of the wireless terminal to the AAA server through the access device, if the access device receives a first second EAP request message from the AAA server corresponding to the target EAP authentication method, and determines that the target EAP authentication method is currently supported, then in this case, the wireless terminal can continue to process according to the existing processing procedure.
[0089] If the access device receives the first second EAP request message corresponding to the target EAP authentication method from the AAA server, and determines that the target EAP authentication method is no longer supported, it means that the EAP authentication method supported by the wireless terminal has been changed by the administrator. In this case, the wireless terminal will send a second EAP negative response message to the AAA server through the access device to indicate that the wireless terminal does not support the target EAP authentication method, so that the AAA server can initiate the existing 802.1X authentication process to the wireless terminal through the access device.
[0090] The following is combined with Figure 4 The above access authentication method is explained in detail, and the specific implementation process is as follows:
[0091] Step 1: When the wireless terminal needs to perform 802.1X authentication, it sends an Extensible Authentication Protocol over LAN (EAPoL) Start message to the fat AP it is connected to. The wireless terminal and the fat AP exchange information through the EAPoL protocol.
[0092] Step 2: The fat AP sends an EAP-Request / Identity message to the wireless terminal to notify the wireless terminal to send its identity information (e.g., the wireless terminal's username information).
[0093] Step 3: The wireless terminal carries its own identity information in the EAP-Response / Identity message and sends it to the fat AP.
[0094] Step four: When the fat AP receives the EAP-Response / Identity message, it encapsulates the EAP-Response / Identity message in a RADIUS Access-Request message and sends it to the AAA server.
[0095] Step 5: When the AAA server receives the RADIUS Access-Request message, it encapsulates the EAP-Request / support EAP methods message, which is used to request the wireless terminal to support EAP authentication methods, into a RADIUSAccess-Challenge message and sends it to the access device.
[0096] Step 6: When the access device receives the RADIUS Access-Challenge message, it sends the EAP-Request / support EAP methods message to the wireless terminal.
[0097] Step 7: When the wireless terminal receives the EAP-Request / support EAP methods message, it finds that it has enabled the function of sending the EAP authentication methods it supports. At this time, the wireless terminal sends an EAP-Response / support EAP methods message to the fat AP, carrying the EAP authentication methods it supports (e.g., PEAP authentication method).
[0098] Step 8: When the fat AP receives the EAP-Response / support EAP methods message, it encapsulates the EAP-Response / support EAP methods message in a RADIUS Access-Request message and sends it to the AAA server.
[0099] Step 9: Upon receiving the RADIUS Access-Request message, the AAA server determines the EAP authentication method required by the wireless terminal based on the EAP authentication methods supported by the wireless terminal carried in the EAP-Response / support EAP methods message and its own supported EAP authentication methods. Assuming the determined EAP authentication method is PEAP, the AAA server initiates the 802.1X authentication process corresponding to the PEAP authentication method to the wireless terminal through the fat AP. First, it sends a RADIUS Access-Challenge message carrying the EAP-Request / PEAP message to the fat AP. Subsequent authentication procedures are based on existing technology and will not be detailed here.
[0100] As can be seen from the above technical solutions, in this embodiment, when the AAA server receives a first EAP response message from a wireless terminal carrying the identity information of the wireless terminal, it no longer sends the EAP authentication methods it supports to the wireless terminal one by one. Instead, it sends a first EAP request message to the wireless terminal to request the EAP authentication methods supported by the wireless terminal. That is, it actively requests the EAP authentication methods supported by the wireless terminal. In this way, the AAA server can determine the EAP authentication method that the wireless terminal needs to use based on the EAP authentication methods supported by the wireless terminal and the EAP authentication methods it supports, and initiate the 802.1X authentication process corresponding to the determined EAP authentication method to the wireless terminal.
[0101] It is evident that this 802.1X authentication process can significantly reduce the number of authentication interactions between the AAA server and the wireless terminal, thereby greatly shortening the authentication time of the entire 802.1X authentication process and improving the access experience for relevant users.
[0102] Based on the same inventive concept, this application also provides an access authentication device, which is applied to an AAA server, and its structural schematic diagram is shown below. Figure 5 As shown, it specifically includes:
[0103] The first processing module 51 is configured to send a first EAP request message to the wireless terminal through the access device when it receives a first EAP response message carrying the identity information of the wireless terminal from any wireless terminal connected to the access device through the access device, and sends a first EAP request message to the wireless terminal through the access device to request the wireless terminal to support an EAP authentication method.
[0104] The second processing module 52 is configured to, when receiving a second EAP response message from the wireless terminal carrying an EAP authentication method supported by the wireless terminal through the access device, determine the EAP authentication method that the wireless terminal needs to use based on the EAP authentication methods supported by the wireless terminal and the EAP authentication methods it supports, and initiate an 802.1X authentication process corresponding to the determined EAP authentication method to the wireless terminal through the access device. The second EAP response message is sent by the wireless terminal to the AAA server through the access device when it receives the first EAP request message through the access device and determines that it has enabled the function of sending its supported EAP authentication methods.
[0105] The third processing module 53 is used to initiate an existing 802.1X authentication process to the wireless terminal through the access device when the access device receives a first EAP negative response message from the wireless terminal. The first EAP negative response message is sent by the wireless terminal to the AAA server through the access device when the wireless terminal receives the first EAP request message through the access device and determines that it has not enabled the function of sending the EAP authentication method it supports.
[0106] Preferably, the second processing module 52 is specifically used to determine the EAP authentication method required by the wireless terminal in the following manner:
[0107] Select an EAP authentication method that is supported by both the wireless terminal and itself, from the EAP authentication methods supported by the wireless terminal and the EAP authentication methods supported by itself.
[0108] Choose one EAP authentication method from the selected options and determine it as the EAP authentication method required by the wireless terminal.
[0109] Preferably, the device further includes:
[0110] Fourth processing module ( Figure 5 (not shown in the image), used to determine whether the first EAP authentication method recently used by the wireless terminal is recorded locally before the first processing module 51 sends a first EAP request message to the wireless terminal through the access device to request the wireless terminal to support an EAP authentication method.
[0111] If the determination result is negative, the second processing module 52 is triggered to execute the step of sending the first EAP request message to the wireless terminal through the access device;
[0112] When the determination result is yes, the access device initiates the 802.1X authentication process corresponding to the first EAP authentication method to the wireless terminal, and when the access device receives the second EAP negative response message from the wireless terminal, the access device initiates the existing 802.1X authentication process to the wireless terminal.
[0113] The second EAP negative response message is sent by the wireless terminal to the AAA server through the access device when it receives the first second EAP request message corresponding to the first EAP authentication method from the AAA server through the access device and determines that it no longer supports the first EAP authentication method.
[0114] Preferably, the device further includes:
[0115] Fifth processing module ( Figure 5 (not shown in the image), used to determine whether the second EAP authentication method recently used by the wireless terminal is recorded locally before the second processing module 52 determines the EAP authentication method that the wireless terminal needs to use;
[0116] If the determination result is negative, the second processing module 52 is triggered to execute the step of determining the EAP authentication method that the wireless terminal needs to use based on the EAP authentication methods supported by the wireless terminal and the EAP authentication methods it supports.
[0117] If the determination result is yes, and the wireless terminal supports a second EAP authentication method among the EAP authentication methods, then the second EAP authentication method is determined as the EAP authentication method that the wireless terminal needs to use, and the access device initiates the 802.1X authentication process corresponding to the determined EAP authentication method to the wireless terminal.
[0118] If the second EAP authentication method is not included among the EAP authentication methods supported by the wireless terminal, then the EAP authentication method supported by both the wireless terminal and itself is selected from the EAP authentication methods supported by the wireless terminal and the EAP authentication methods supported by the wireless terminal. One EAP authentication method is selected from the selected EAP authentication methods and determined as the EAP authentication method to be used by the wireless terminal. The 802.1X authentication process corresponding to the determined EAP authentication method is initiated to the wireless terminal through the access device, and the locally recorded second EAP authentication method is changed to the determined EAP authentication method.
[0119] Preferably, the device further includes:
[0120] Recording module ( Figure 5 (Not shown in the image), is used to record the determined EAP authentication method as the most recently used EAP authentication method of the wireless terminal after the second processing module 52 performs the step of determining the EAP authentication method that the wireless terminal needs to use based on the EAP authentication methods supported by the wireless terminal and the EAP authentication methods it supports.
[0121] Preferably, the device further includes:
[0122] Aging module ( Figure 5 (Not shown in the image), used to age out all locally recorded EAP authentication methods recently used by wireless terminals according to a set aging time.
[0123] Preferably, the determined EAP authentication method is EAP-TLS authentication, EAP-TTLS authentication, or PEAP authentication.
[0124] This application also provides an access authentication device, which is applied to a wireless terminal, and its structural schematic diagram is shown below. Figure 6 As shown, it specifically includes:
[0125] The judgment module 61 is used to determine whether it has enabled the function of sending the EAP authentication method it supports after sending the first EAP response message carrying the identity information of the wireless terminal to the AAA server through the access device. If the access device receives a first EAP request message from the AAA server to request the wireless terminal, the module 61 is used to determine whether it has enabled the function of sending the EAP authentication method it supports.
[0126] The first processing module 62 is configured to, when the judgment result of the judgment module 61 is yes, send a second EAP response message carrying its own supported EAP authentication method to the AAA server through the access device, so that when the AAA server receives the second EAP response message from the wireless terminal through the access device, it determines the EAP authentication method that the wireless terminal needs to use based on the EAP authentication methods supported by the wireless terminal and its own supported EAP authentication methods, and initiates the 802.1X authentication process corresponding to the determined EAP authentication method to the wireless terminal through the access device;
[0127] The second processing module 63 is configured to, when the judgment result of the judgment module 61 is negative, send a first EAP negative response message to the AAA server through the access device to indicate that the wireless terminal has not enabled the function of sending its supported EAP authentication methods, so that when the AAA server receives the first EAP negative response message from the wireless terminal through the access device, it initiates the existing 802.1X authentication process to the wireless terminal through the access device.
[0128] Preferably, the method further includes:
[0129] Third processing module ( Figure 6 (Not shown in the image) is used to, after the judgment module sends a first EAP response message carrying the identity information of the wireless terminal to the AAA server through the access device, if the access device receives a first second EAP request message corresponding to the target EAP authentication method from the AAA server and determines that the target EAP authentication method is not currently supported, then the access device sends a second EAP negative response message to the AAA server to indicate that the wireless terminal does not support the target EAP authentication method, so that when the AAA server receives the second EAP negative response message from the wireless terminal through the access device, it initiates the existing 802.1X authentication process to the wireless terminal through the access device;
[0130] The target EAP authentication method is the EAP authentication method most recently used by the wireless terminal that is recorded locally by the AAA server. The target EAP authentication method is determined by the AAA server when it receives a third EAP response message carrying the identity information from the wireless terminal through the access device, and the target EAP authentication method is not recorded locally. This determination is based on the EAP authentication methods supported by the wireless terminal carried in the fourth EAP response message from the wireless terminal received through the access device, and the EAP authentication methods supported by the AAA server itself.
[0131] As can be seen from the above technical solutions, in this embodiment, when the AAA server receives a first EAP response message from a wireless terminal carrying the identity information of the wireless terminal, it no longer sends the EAP authentication methods it supports to the wireless terminal one by one. Instead, it sends a first EAP request message to the wireless terminal to request the EAP authentication methods supported by the wireless terminal. That is, it actively requests the EAP authentication methods supported by the wireless terminal. In this way, the AAA server can determine the EAP authentication method that the wireless terminal needs to use based on the EAP authentication methods supported by the wireless terminal and the EAP authentication methods it supports, and initiate the 802.1X authentication process corresponding to the determined EAP authentication method to the wireless terminal.
[0132] It is evident that this 802.1X authentication process can significantly reduce the number of authentication interactions between the AAA server and the wireless terminal, thereby greatly shortening the authentication time of the entire 802.1X authentication process and improving the access experience for relevant users.
[0133] This application also provides an electronic device, such as... Figure 7 As shown, it includes a processor 71 and a machine-readable storage medium 72, the machine-readable storage medium 72 storing machine-executable instructions that can be executed by the processor 71, the processor 71 being prompted by the machine-executable instructions to implement the steps of the above-described access authentication method.
[0134] The aforementioned machine-readable storage medium may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage device. Optionally, the machine-readable storage medium may also be at least one storage device located remotely from the aforementioned processor.
[0135] The processors mentioned above can be general-purpose processors, including central processing units (CPUs), network processors (NPs), etc.; they can also be digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.
[0136] In another embodiment provided in this application, a computer-readable storage medium is also provided, which stores a computer program that, when executed by a processor, implements the steps of the access authentication method described above.
[0137] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.
Claims
1. An access authentication method, characterized in that, The method is applied to an AAA server, and the method includes: When the access device receives a first EAP response message carrying the identity information of any wireless terminal connected to the access device, the access device sends a first EAP request message to the wireless terminal to request the wireless terminal to support an EAP authentication method. The first EAP request message includes a field for instructing the wireless terminal to fill in the EAP authentication method supported by the wireless terminal. If the access device receives a second EAP response message from the wireless terminal carrying an EAP authentication method supported by the wireless terminal, then based on the EAP authentication methods supported by the wireless terminal and the EAP authentication methods supported by the wireless terminal, the access device determines the EAP authentication method that the wireless terminal needs to use, and initiates an 802.1X authentication process corresponding to the determined EAP authentication method to the wireless terminal. The second EAP response message is sent by the wireless terminal to the AAA server through the access device when it receives the first EAP request message through the access device and determines that it has enabled the function of sending its supported EAP authentication methods. If the access device receives a first EAP denial response message from the wireless terminal, the access device initiates an existing 802.1X authentication process to the wireless terminal. The first EAP denial response message is sent by the wireless terminal to the AAA server through the access device when it receives the first EAP request message through the access device and determines that it has not enabled the function of sending the EAP authentication method it supports.
2. The method according to claim 1, characterized in that, The EAP authentication method required for the wireless terminal is determined by the following methods: Select an EAP authentication method that is supported by both the wireless terminal and itself, from the EAP authentication methods supported by the wireless terminal and the EAP authentication methods supported by itself. Choose one EAP authentication method from the selected options and determine it as the EAP authentication method required by the wireless terminal.
3. The method according to claim 1, characterized in that, Before sending a first EAP request message to the wireless terminal via the access device to request the wireless terminal to support an EAP authentication method, the method further includes: Determine whether the local system records the first EAP authentication method most recently used by the wireless terminal; If the determination result is negative, the step of sending the first EAP request message to the wireless terminal through the access device is executed. When the determination result is yes, the access device initiates the 802.1X authentication process corresponding to the first EAP authentication method to the wireless terminal, and when the access device receives the second EAP negative response message from the wireless terminal, the access device initiates the existing 802.1X authentication process to the wireless terminal. The second EAP negative response message is sent by the wireless terminal to the AAA server through the access device when it receives the first second EAP request message corresponding to the first EAP authentication method from the AAA server through the access device and determines that it no longer supports the first EAP authentication method.
4. The method according to claim 1, characterized in that, Before determining the EAP authentication method that the wireless terminal needs to use, the method further includes: Determine whether the local system records the second EAP authentication method recently used by the wireless terminal; If the determination result is negative, the step of determining the EAP authentication method that the wireless terminal needs to use is executed based on the EAP authentication methods supported by the wireless terminal and the EAP authentication methods supported by the wireless terminal itself; If the determination result is yes, and the second EAP authentication method is included among the EAP authentication methods supported by the wireless terminal, then the second EAP authentication method is determined as the EAP authentication method that the wireless terminal needs to use, and the 802.1X authentication process corresponding to the determined EAP authentication method is initiated to the wireless terminal through the access device. If the second EAP authentication method is not included among the EAP authentication methods supported by the wireless terminal, then an EAP authentication method supported by both the wireless terminal and itself is selected from the EAP authentication methods supported by the wireless terminal and the EAP authentication methods supported by the wireless terminal. One EAP authentication method is selected from the selected EAP authentication methods and determined as the EAP authentication method to be used by the wireless terminal. The 802.1X authentication process corresponding to the determined EAP authentication method is initiated to the wireless terminal through the access device, and the second EAP authentication method recorded locally is changed to the determined EAP authentication method.
5. The method according to claim 3 or 4, characterized in that, After performing the step of determining the EAP authentication method that the wireless terminal needs to use based on the EAP authentication methods supported by the wireless terminal and the EAP authentication methods it supports, the method further includes: The determined EAP authentication method is recorded as the second EAP authentication method most recently used by the wireless terminal.
6. The method according to claim 5, characterized in that, The method further includes: According to the set aging time, the EAP authentication methods recently used by all wireless terminals recorded locally are aged out.
7. An access authentication method, characterized in that, The method is applied to a wireless terminal, and the method includes: After sending a first EAP response message carrying the identity information of the wireless terminal to the AAA server through the access device, if the access device receives a first EAP request message from the AAA server requesting the wireless terminal, it determines whether it has enabled the function of sending the EAP authentication method it supports. The first EAP request message includes a field for instructing the wireless terminal to fill in the EAP authentication method supported by the wireless terminal. When the determination result is yes, the access device sends a second EAP response message carrying its supported EAP authentication method to the AAA server, so that when the AAA server receives the second EAP response message from the wireless terminal through the access device, it determines the EAP authentication method that the wireless terminal needs to use based on the EAP authentication methods supported by the wireless terminal and its own supported EAP authentication methods, and initiates the 802.1X authentication process corresponding to the determined EAP authentication method to the wireless terminal through the access device. If the determination result is negative, the access device sends a first EAP negative response message to the AAA server to indicate that the wireless terminal has not enabled the function of sending its supported EAP authentication methods. This allows the AAA server to initiate the existing 802.1X authentication process to the wireless terminal when it receives the first EAP negative response message from the wireless terminal through the access device.
8. The method according to claim 7, characterized in that, After sending a first EAP response message carrying the identity information of the wireless terminal to the AAA server via the access device, the method further includes: If the access device receives the first second EAP request message corresponding to the target EAP authentication method from the AAA server and determines that the target EAP authentication method is no longer supported, then the access device sends a second EAP negative response message to the AAA server to indicate that the wireless terminal does not support the target EAP authentication method. This allows the AAA server to initiate the existing 802.1X authentication process to the wireless terminal when it receives the second EAP negative response message from the wireless terminal through the access device. The target EAP authentication method is the EAP authentication method most recently used by the wireless terminal that is recorded locally by the AAA server. The target EAP authentication method is determined by the AAA server when it receives a third EAP response message carrying the identity information from the wireless terminal through the access device, and the target EAP authentication method is not recorded locally. This determination is based on the EAP authentication methods supported by the wireless terminal carried in the fourth EAP response message from the wireless terminal received through the access device, and the EAP authentication methods supported by the AAA server itself.
9. An access authentication device, characterized in that, The device is used in an AAA server, and the device includes: The first processing module is configured to, when receiving a first EAP response message carrying the identity information of any wireless terminal connected to the access device through the access device, send a first EAP request message to the wireless terminal through the access device to request the wireless terminal to support an EAP authentication method. The first EAP request message includes a field for instructing the wireless terminal to fill in the EAP authentication method supported by the wireless terminal. The second processing module is configured to, when receiving a second EAP response message from the wireless terminal carrying an EAP authentication method supported by the wireless terminal through the access device, determine the EAP authentication method that the wireless terminal needs to use based on the EAP authentication methods supported by the wireless terminal and its own supported EAP authentication methods, and initiate an 802.1X authentication process corresponding to the determined EAP authentication method to the wireless terminal through the access device. The second EAP response message is sent by the wireless terminal to the AAA server through the access device when it receives the first EAP request message through the access device and determines that it has enabled the function of sending its own supported EAP authentication methods. The third processing module is used to initiate an existing 802.1X authentication process to the wireless terminal through the access device when it receives a first EAP negative response message from the wireless terminal through the access device. The first EAP negative response message is sent by the wireless terminal to the AAA server through the access device when it receives the first EAP request message through the access device and determines that it has not enabled the function of sending the EAP authentication method it supports.
10. The apparatus according to claim 9, characterized in that, The second processing module is specifically used to determine the EAP authentication method required by the wireless terminal in the following ways: Select an EAP authentication method that is supported by both the wireless terminal and itself, from the EAP authentication methods supported by the wireless terminal and the EAP authentication methods supported by itself. Choose one EAP authentication method from the selected options and determine it as the EAP authentication method required by the wireless terminal.
11. The apparatus according to claim 9, characterized in that, The device further includes: The fourth processing module is used to determine whether the first EAP authentication method recently used by the wireless terminal is recorded locally before the first processing module sends a first EAP request message to the wireless terminal through the access device to request the wireless terminal to support an EAP authentication method. If the determination result is negative, the second processing module is triggered to execute the step of sending the first EAP request message to the wireless terminal through the access device; When the determination result is yes, the access device initiates the 802.1X authentication process corresponding to the first EAP authentication method to the wireless terminal, and when the access device receives the second EAP negative response message from the wireless terminal, the access device initiates the existing 802.1X authentication process to the wireless terminal. The second EAP negative response message is sent by the wireless terminal to the AAA server through the access device when it receives the first second EAP request message corresponding to the first EAP authentication method from the AAA server through the access device and determines that it no longer supports the first EAP authentication method.
12. The apparatus according to claim 9, characterized in that, The device further includes: The fifth processing module is used to determine whether the second EAP authentication method recently used by the wireless terminal is recorded locally before the second processing module determines the EAP authentication method that the wireless terminal needs to use. If the determination result is negative, the second processing module is triggered to execute the step of determining the EAP authentication method that the wireless terminal needs to use based on the EAP authentication methods supported by the wireless terminal and the EAP authentication methods it supports. If the determination result is yes, and the second EAP authentication method is included among the EAP authentication methods supported by the wireless terminal, then the second EAP authentication method is determined as the EAP authentication method that the wireless terminal needs to use, and the 802.1X authentication process corresponding to the determined EAP authentication method is initiated to the wireless terminal through the access device. If the second EAP authentication method is not included among the EAP authentication methods supported by the wireless terminal, then an EAP authentication method supported by both the wireless terminal and itself is selected from the EAP authentication methods supported by the wireless terminal and the EAP authentication methods supported by the wireless terminal. One EAP authentication method is selected from the selected EAP authentication methods and determined as the EAP authentication method to be used by the wireless terminal. The 802.1X authentication process corresponding to the determined EAP authentication method is initiated to the wireless terminal through the access device, and the second EAP authentication method recorded locally is changed to the determined EAP authentication method.
13. The apparatus according to claim 11 or 12, characterized in that, The device further includes: The recording module is used to record the determined EAP authentication method as the most recently used EAP authentication method of the wireless terminal after the second processing module performs the step of determining the EAP authentication method that the wireless terminal needs to use based on the EAP authentication methods supported by the wireless terminal and the EAP authentication methods it supports.
14. An access authentication device, characterized in that, The device is used in a wireless terminal, and the device includes: The judgment module is used to determine whether it has enabled the function of sending the EAP authentication method it supports after sending a first EAP response message carrying the identity information of the wireless terminal to the AAA server through the access device, if the access device receives a first EAP request message from the AAA server to request the wireless terminal. The first EAP request message includes a field for instructing the wireless terminal to fill in the EAP authentication method supported by the wireless terminal. The first processing module is configured to, when the judgment result of the judgment module is yes, send a second EAP response message carrying its supported EAP authentication method to the AAA server through the access device, so that when the AAA server receives the second EAP response message from the wireless terminal through the access device, it determines the EAP authentication method that the wireless terminal needs to use based on the EAP authentication methods supported by the wireless terminal and its own supported EAP authentication methods, and initiates the 802.1X authentication process corresponding to the determined EAP authentication method to the wireless terminal through the access device; The second processing module is configured to, when the judgment result of the judgment module is negative, send a first EAP negative response message to the AAA server through the access device, indicating that the wireless terminal has not enabled the function of sending its supported EAP authentication methods, so that when the AAA server receives the first EAP negative response message from the wireless terminal through the access device, it initiates the existing 802.1X authentication process to the wireless terminal through the access device.
15. The apparatus according to claim 14, characterized in that, The device further includes: The third processing module is configured to, after the judgment module sends a first EAP response message carrying the identity information of the wireless terminal to the AAA server through the access device, if the access device receives a first second EAP request message corresponding to the target EAP authentication method from the AAA server and determines that the target EAP authentication method is not currently supported, then send a second EAP negative response message to the AAA server through the access device to indicate that the wireless terminal does not support the target EAP authentication method, so that when the AAA server receives the second EAP negative response message from the wireless terminal through the access device, it initiates the existing 802.1X authentication process to the wireless terminal through the access device. The target EAP authentication method is the EAP authentication method most recently used by the wireless terminal that is recorded locally by the AAA server. The target EAP authentication method is determined by the AAA server when it receives a third EAP response message carrying the identity information from the wireless terminal through the access device, and the target EAP authentication method is not recorded locally. This determination is based on the EAP authentication methods supported by the wireless terminal carried in the fourth EAP response message from the wireless terminal received through the access device, and the EAP authentication methods supported by the AAA server itself.
Citation Information
Patent Citations
Method, device and system for negotiating authentication methods
CN101753533A