Device authentication method and apparatus, computer device, and storage medium

By querying authentication records at the switch port and sending the authentication results to the adjacent switch, the network consumption and time extension problems caused by independent switch authentication are solved, achieving rapid access and improved security.

CN115883142BActive Publication Date: 2025-10-17ZHEJIANG IND & IND LINGCHUANG TECHNOLOGY CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202211427079.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-15
Publication Date
2025-10-17
Estimated Expiration
2042-11-15

AI Technical Summary

Technical Problem

In an 802.1X-based network access system, independent switch authentication increases network consumption, prolongs the time it takes for terminal devices to gain full network access, and degrades user experience.

Method used

By querying the authentication record at the target switch port, if no authentication data is found, authentication processing is performed and the results are sent to the adjacent switch and centralized management server to avoid repeated authentication.

Benefits of technology

It saves network consumption, shortens the time it takes for terminal devices to gain full network access, optimizes user experience, and identifies and prevents MAC cloning attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115883142B_ABST
    Figure CN115883142B_ABST
Patent Text Reader

Abstract

The application relates to a device authentication method and device, a computer device and a storage medium. The method comprises the following steps: in the case that a target exchange port receives message data sent by a target device, querying target authentication data corresponding to the target device in a target authentication record corresponding to the target exchange port; in the case that the target authentication data is not queried in the target authentication record, performing authentication processing on the target device to obtain a corresponding authentication result; and sending the authentication result to a neighboring switch and a centralized management server, so that the neighboring switch and the centralized management server obtain the authentication result corresponding to the target device, and when the second boundary switch receives corresponding message data of the target device, the target device does not need to be repeatedly authenticated, thereby saving network consumption generated by the second boundary switch in authentication, shortening the time for the target device to obtain global network access, and optimizing user experience.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of computer, and particularly relates to a device authentication method and device, a computer device and a storage medium. BACKGROUND

[0002] In an 802.1X-based network access system, a switch functions as a proxy to implement access control on all terminal devices accessing the network. Since each switch is traditionally an independent network entity and has no association with each other, when a terminal device passes authentication on one switch, its packet can be forwarded to other switches. Once all switches start authentication, it means that each switch needs to authenticate each terminal device in the network. This greatly increases the network consumption caused by authentication, prolongs the time for the terminal device to obtain full-network access, and reduces user experience. SUMMARY

[0003] To solve the above technical problems, the present application provides a device authentication method and device, a computer device and a storage medium.

[0004] In a first aspect, the present application provides a device authentication method, comprising:

[0005] In a case where it is detected that a target switch port receives packet data sent by a target device, target authentication data corresponding to the target device is queried in a target authentication record corresponding to the target switch port, wherein the target switch port is any one switch port of the first boundary switch, and the target authentication record comprises authentication data that passes authentication from the target switch port;

[0006] In a case where the target authentication data is not queried in the target authentication record, authentication processing is performed on the target device to obtain a corresponding authentication result;

[0007] The authentication result is sent to a neighboring switch and a centralized management server, so that a second boundary switch quickly responds according to the target authentication data in a case where the packet data is received, wherein the neighboring switch is another boundary switch in a local area network where the first boundary switch is located, and the second boundary switch comprises the neighboring switch.

[0008] In a second aspect, the present application provides a device authentication device, comprising:

[0009] The query module is configured to, in response to detecting that a target exchange port receives a packet data sent by a target device, query target authentication data corresponding to the target device in a target authentication record corresponding to the target exchange port, wherein the target exchange port is any exchange port of the first boundary switch, and the target authentication record comprises authentication data that has passed authentication from the target exchange port.

[0010] The authentication module is configured to, in response to failing to query the target authentication data in the target authentication record, perform authentication processing on the target device to obtain a corresponding authentication result.

[0011] The sending module is configured to send the authentication result to a neighboring switch and a centralized management server, so that a second boundary switch, which comprises the neighboring switch, quickly responds according to the target authentication data in response to receiving the packet data.

[0012] In a third aspect, a computer device is provided, which comprises a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the following steps when executing the computer program:

[0013] In response to detecting that a target exchange port receives a packet data sent by a target device, the target authentication data corresponding to the target device is queried in a target authentication record corresponding to the target exchange port, wherein the target exchange port is any exchange port of the first boundary switch, and the target authentication record comprises authentication data that has passed authentication from the target exchange port.

[0014] In response to failing to query the target authentication data in the target authentication record, the target device is subjected to authentication processing to obtain a corresponding authentication result.

[0015] The authentication result is sent to a neighboring switch and a centralized management server, so that a second boundary switch, which comprises the neighboring switch, quickly responds according to the target authentication data in response to receiving the packet data.

[0016] In a fourth aspect, a computer readable storage medium is provided, which stores a computer program, and the computer program is executed by a processor to implement the following steps:

[0017] In a case that the target exchange port receives the packet data sent by the target device, the target authentication data corresponding to the target device is queried in a target authentication record corresponding to the target exchange port, wherein the target exchange port is any exchange port of the first boundary switch, and the target authentication record includes authentication data that passes authentication from the target exchange port.

[0018] In a case that the target authentication data is not queried in the target authentication record, an authentication process is performed on the target device to obtain a corresponding authentication result.

[0019] The authentication result is sent to a neighboring switch and a centralized management server, so that the second boundary switch quickly responds according to the target authentication data in a case that the packet data is received, wherein the neighboring switch is another boundary switch in a local area network where the first boundary switch is located, and the second boundary switch includes the neighboring switch.

[0020] In a case that the target exchange port receives the packet data sent by the target device, the target authentication data corresponding to the target device is queried in a target authentication record corresponding to the target exchange port, wherein the target exchange port is any exchange port of the first boundary switch, and the target authentication record includes authentication data that passes authentication from the target exchange port. In a case that the target authentication data is not queried in the target authentication record, an authentication process is performed on the target device to obtain a corresponding authentication result. The authentication result is sent to a neighboring switch and a centralized management server, so that the second boundary switch quickly responds according to the target authentication data in a case that the packet data is received, wherein the neighboring switch is another boundary switch in a local area network where the first boundary switch is located, and the second boundary switch includes the neighboring switch.

[0021] The authentication result of the target device is sent to the neighboring switch and the centralized management server through the first boundary switch, so that the neighboring switch and the centralized management server obtain the authentication result corresponding to the target device. In a case that the second boundary switch receives the corresponding packet data of the target device, the target device does not need to be repeatedly authenticated, and can be quickly responded based on the received authentication result, so as to save network consumption generated by the authentication of the second boundary switch, shorten the time for the target device to obtain network access, and optimize user experience. BRIEF DESCRIPTION OF DRAWINGS

[0022] The accompanying drawings, which are incorporated herein and form part of the specification, illustrate embodiments consistent with the present application and, together with the description, further serve to explain the principles of the application.

[0023] In order to make the technical solutions of the embodiments of the present application or the prior art clearer, the accompanying drawings needed in the embodiments or prior art description will be briefly introduced. Obviously, those skilled in the art can obtain other drawings according to these drawings without any creative effort.

[0024] Figure 1 An application environment diagram of the device authentication method in one embodiment;

[0025] Figure 2 A flowchart of the device authentication method in one embodiment;

[0026] Figure 3 A flowchart of the device authentication method in one embodiment;

[0027] Figure 4 A structural block diagram of the device authentication apparatus in one embodiment;

[0028] Figure 5 An internal structure diagram of the computer device in one embodiment. DETAILED DESCRIPTION

[0029] In order to make the technical solutions of the embodiments of the present application or the prior art clearer, the accompanying drawings needed in the embodiments or prior art description will be briefly introduced. Obviously, those skilled in the art can obtain other drawings according to these drawings without any creative effort.

[0030] Figure 1 An application environment diagram of the device authentication method in one embodiment. Refer to Figure 1, the device authentication method is applied to a device authentication system. The device authentication system includes an access device 110, a centralized management server, and a communication network 120. The access device 110, the centralized management server 130, and the communication network 120 are connected via a network. The access device 110 can specifically be a device that supports the MAC-BASED access method or a terminal that supports the installation of authentication client software. The device that supports the MAC-BASED access method can specifically be a printer, a scanner, etc. The terminal can specifically be a desktop terminal or a mobile terminal. The mobile terminal can specifically be at least one of a mobile phone, a tablet computer, a laptop computer, etc. The communication network 120 includes at least one local area network, and the local area network includes multiple boundary switches. A trust relationship is established between the boundary switches in the same local area network. Each boundary switch includes at least one switching port. The boundary switch receives message data sent by the target device through the switching port and forwards the message data sent by the target device if the authentication of the target device is successful.

[0031] The centralized management server 130 is used to manage all edge switches in all local area networks, and can be implemented by using an independent server or a server cluster consisting of multiple servers.

[0032] In one embodiment, Figure 2 A schematic diagram of a device authentication method in an embodiment, referring to Figure 2 , provides a device authentication method. This embodiment mainly uses the method applied to a first edge switch as an example to illustrate the device authentication method. The device authentication method specifically includes the following steps:

[0033] Step S210: When it is detected that the target switch port receives the message data sent by the target device, the target authentication data corresponding to the target device is searched in the target authentication record corresponding to the target switch port.

[0034] The target switching port is any switching port of the first edge switch, and the target authentication record includes authentication data passed from the target switching port.

[0035] Specifically, the first border switch can be any border switch in any local area network, the target device can be any access device 110, the message data can contain a physical address (MAC) corresponding to the target device, each switching port of the border switch can correspond to an authentication record, the authentication record can be used to record authentication data of different devices passing through the switching port, the authentication data can include a physical address of the device and an authentication state of the switching port after performing authentication processing on the device, the authentication state can include authentication passing and authentication failing, and the target authentication record can be an authentication record corresponding to the target switching port. In the target authentication record, the corresponding target authentication data is queried based on the target physical address in the message data to determine whether the target switching port has performed authentication processing on the current target device.

[0036] In step S220, in the case where the target authentication data is not queried in the target authentication record, the target device is authenticated to obtain a corresponding authentication result.

[0037] Specifically, in the case where the target authentication data is not queried in the target authentication record, it indicates that the target switching port has not performed authentication processing on the target device, i.e., the target device is a new device for the target switching port. Therefore, the target switching port needs to perform authentication processing on the target device to obtain a corresponding authentication result, which is used to indicate authentication passing, authentication failing or clone attack, and the clone attack is used to indicate that the target device is an illegal access device.

[0038] In step S230, the authentication result is sent to a neighboring switch and a centralized management server 130, so that a second border switch can quickly respond according to the target authentication data in the case where the message data is received. The neighboring switch can be other border switches in the local area network where the first border switch is located, and the second border switch can include the neighboring switch.

[0039] Specifically, the first boundary switch sends the obtained authentication result about the target device to the adjacent switch and the centralized management server 130, i.e., informs the adjacent switch and the centralized management server 130 of the authentication result corresponding to the target device. The second boundary switch includes the adjacent switch and / or the remote switch, and the remote switch is a boundary switch in a different local area network from the first boundary switch. When the adjacent switch or the remote switch receives the packet data corresponding to the target physical address of the target device, the adjacent switch can quickly respond according to the authentication result sent by the first boundary switch, and the remote switch can obtain the authentication result corresponding to the target device from the centralized server. Whether the adjacent switch or the remote switch, it is not necessary to perform repeated authentication processing on the target device, thereby saving the network consumption generated by the adjacent switch and / or the remote switch in repeated authentication of the target device, shortening the time for the target device to obtain the global access, and optimizing the user experience.

[0040] In one embodiment, after the target authentication data corresponding to the target device is queried in the target authentication record corresponding to the target switch port, the method further includes:

[0041] In the case that the target authentication data corresponding to the target device is queried in the target authentication record, and the target authentication state in the target authentication data is authentication passed, the packet data is forwarded for processing; or,

[0042] In the case that the target authentication data corresponding to the target device is queried in the target authentication record, and the target authentication state in the target authentication data is authentication failed, the packet data is rejected for forwarding and discarded.

[0043] Specifically, when the target authentication data corresponding to the target device is queried in the target authentication record, it indicates that the target switch port has performed authentication processing on the target device. In the case that the target authentication state in the target authentication data is authentication passed, the packet data sent by the target device can be directly forwarded, i.e., the Client_Active_Time is refreshed and the packet data is handed over to the protocol stack for further forwarding processing. In the case that the target authentication state in the target authentication data is authentication failed, it indicates that the target switch port does not support providing packet forwarding service for the target device, and then the packet data sent by the target device is rejected for forwarding and discarded.

[0044] In one embodiment, the target authentication data includes a target authentication state and a target activity state, and the authentication processing on the target device to obtain the corresponding authentication result includes:

[0045] In a case that the target authentication state and the target activity state of the target device are not found in the device database or the target authentication state is authentication failure, an inquiry message is generated and sent to the adjacent switch, and a corresponding authentication result is determined according to a feedback result of the adjacent switch, wherein the inquiry message is used to query and obtain the target authentication data, and the inquiry message includes the target physical address of the target device.

[0046] In a case that the target authentication state and the target activity state of the target device are not found in the device database or the target authentication state is authentication failure, an inquiry message is generated and sent to the adjacent switch, and a corresponding authentication result is determined according to a feedback result of the adjacent switch, wherein the inquiry message is used to query and obtain the target authentication data, and the inquiry message includes the target physical address of the target device.

[0047] Specifically, the device database includes authentication records corresponding to each switch port of the first boundary switch and authentication records broadcasted by other adjacent switches. Since the target authentication data corresponding to the target device is not found in the target authentication record corresponding to the target switch port, the target authentication data corresponding to the target device is queried in the device database corresponding to the first boundary switch, to determine whether the other switch ports of the first boundary switch or other adjacent switches have performed authentication processing on the target device.

[0048] In a case that the target authentication state and the target activity state of the target device are not found in the device database or the target authentication state is authentication failure, an inquiry message is generated and sent to the adjacent switch, and a corresponding authentication result is determined according to a feedback result of the adjacent switch, wherein the inquiry message is used to query and obtain the target authentication data, and the inquiry message includes the target physical address of the target device.

[0049] In the case that the target authentication state and the target activity state are not queried in the device database, it indicates that each switch port of the first border switch has not performed authentication processing on the target device, but the first border switch may not update the authentication data in the device database in time due to the time delay of sending authentication data by other adjacent switches, and the target device may have been authenticated by other adjacent border switches. Therefore, a corresponding inquiry message is generated according to the packet data, the inquiry message contains the target physical address of the target device, and the inquiry message is sent to the adjacent switch to inquire whether the adjacent switch has performed authentication processing on the target device, so as to determine the authentication result corresponding to the target device according to the feedback result of the adjacent switch.

[0050] In one embodiment, the authentication result corresponding to the target device is determined according to the feedback result of the adjacent switch, including:

[0051] In the case that the feedback result of the adjacent switch indicates that the target authentication state is authentication passed and the target activity state is online activity, an authentication result indicating a clone attack is obtained; or,

[0052] In the case that the feedback result of the adjacent switch indicates that the response is timed out or the target authentication data is not queried, the inquiry message is sent to the centralized management server 130, and the authentication result corresponding to the target device is determined according to the feedback result of the centralized management server 130.

[0053] Specifically, in the case that the feedback result returned by the adjacent switch indicates that the target authentication state is authentication passed and the target activity state is online activity, it indicates that the adjacent switch has performed authentication processing on the target device, or the adjacent switch obtains the target authentication data of the target device from other switches having a trust relationship with the adjacent switch, which all indicate that the target physical address corresponding to the target device has passed authentication and is still in an active state, that is, the actual access device corresponding to the target physical address is online accessing the network through the border switch, and therefore it is determined that the target device currently accessing the target switch port is a illegal access device. At this time, the first border switch can determine that the authentication result corresponding to the target device is a clone attack.

[0054] In the case that the response of the adjacent switch to the inquiry message is timed out or the feedback result returned by the adjacent switch indicates that the target authentication data is not queried, it indicates that the first border switch does not obtain the target authentication data corresponding to the target device from the adjacent switch, and then the first border switch continues to send the inquiry message to the centralized management server 130, and determines the authentication result corresponding to the target device according to the feedback result returned by the centralized management server 130.

[0055] In an embodiment, the determining the authentication result corresponding to the target device according to the feedback result of the centralized management server 130 comprises:

[0056] In a case where the feedback result returned by the centralized management server 130 indicates that the registration information corresponding to the target physical address, authenticating the target device according to the registration information to obtain an authentication result indicating that the authentication is passed; or,

[0057] In a case where the feedback result returned by the centralized management server 130 indicates that the target authentication state is passed and the target activity state is online activity, an authentication result indicating a clone attack is obtained.

[0058] Specifically, in a case where the feedback result returned by the centralized management server 130 indicates that the registration information corresponding to the target physical address, it indicates that the target device is an access device 110 that has not been subjected to authentication processing, the registration information includes a registration state of the target physical address, the registration state includes registered and unregistered, and then the target device is subjected to authentication processing according to the registration information corresponding to the target device to generate an authentication result indicating that the authentication is passed.

[0059] In a case where the feedback result returned by the centralized management server 130 indicates that the target authentication state is passed and the target activity state is online activity, it indicates that the target physical address corresponding to the target device has been authenticated and is currently in an active state, that is, the target physical address corresponding to the actual access device is online accessing the network through the border switch, and therefore it is determined that the target device currently accessing the target switching port based on the target physical address is a non-legal access device, at which time the first border switch can determine that the authentication result corresponding to the target device is a clone attack.

[0060] For the case where the authentication result corresponding to the target device is a clone attack in the above embodiment, the first border switch rejects the target device to access the first border switch through the target switching port, that is, it rejects to forward the packet data sent by the target device.

[0061] In an embodiment, after the authentication result indicating that the authentication is passed is obtained, the method further comprises:

[0062] generating authentication data corresponding to the target device according to the authentication result indicating that the authentication is passed, and saving the authentication data into the target authentication record;

[0063] sending a detection packet to the target device according to a preset period;

[0064] determining an updated activity state corresponding to the target device according to a packet response returned by the target device;

[0065] In a case that the updating activity state of the target device is offline, the authentication data corresponding to the target device in the target authentication record is deleted.

[0066] Specifically, the first border switch saves the authentication result of the authentication pass as the authentication data corresponding to the target device in the target authentication record corresponding to the target switch port, and listens to the detection packet sent by the target device through the hook function (RX-HOOK), i.e., periodically detects the target device. If the target device is an access device 110 supporting the MAC-BASED access mode, as long as the target device is normally online, the hook function will periodically receive the packet response to the detection packet from the target device. If the target device is an access device 110 installed with an authentication client software, in addition to the response to the detection packet, the hook function will also periodically receive the periodic repeated authentication related packets from the target device.

[0067] According to the time difference between the current packet response periodically returned by the target device and the last packet response, if the time difference is greater than or equal to the preset time length, it is determined that the updating activity state of the target device is offline; if the time difference is less than the preset time length, it is determined that the updating activity state of the target device is online. In a case that the updating activity state of the target device is offline, the authentication data corresponding to the target device in the target authentication record is deleted.

[0068] In an embodiment, before the authentication data corresponding to the target device in the target authentication record is deleted in a case that the updating activity state of the target device is offline, the method further comprises:

[0069] In a case that the closing state of the target switch port is closed, it is determined that the updating activity state of the target device is offline.

[0070] Specifically, the updating activity state of the target device can also be determined according to whether the closing state of the switch port accessed by the target device is closed. In a case that the closing state of the target switch port is closed, all devices accessed from the target switch port are determined to be offline, and the authentication data corresponding to the offline target device is deleted from the target authentication record.

[0071] Specifically, the target switch port of the border switch A, when authenticating the newly accessed access device 110, first checks whether there is a same MAC-A address in the local device database that has been authenticated and is in an active state through other switch ports. If yes, the currently newly accessed access device 110 is determined to be a clone attack and its access to the network is blocked, and the authentication process is terminated.

[0072] If border switch A fails to retrieve the authentication data corresponding to the MAC-A address locally, it sends a query message to other border switches in the same LAN to inquire about the authentication data corresponding to the MAC-A address of access device 110. After receiving the query, if the other border switches are the home border switches for the MAC-A address and the MAC-A address is active, they reply with the authentication data corresponding to the MAC-A address to border switch A. The home border switch indicates the border switch that provides switching services for access device 110 corresponding to the MAC address. If border switch A receives feedback from other border switches indicating that the MAC-A address has been authenticated and is active, it determines that the MAC-A address access is a cloning attack and blocks its access to the network, terminating the authentication process.

[0073] If border switch A fails to obtain authentication data corresponding to the MAC-A address from other border switches, it requests authentication data corresponding to the MAC-A address from the centralized management server 130. Centralized management server 130 queries the authentication data corresponding to the MAC-A address. If the authentication data has been authenticated and is active on another border authentication switch, it responds to border switch A with a cloning attack message. Otherwise, it responds with registration information based on the registration status of the MAC-A address. If border switch A receives a cloning attack message from the centralized management server 130 regarding the MAC-A address, it determines that the MAC-A address's access constitutes a cloning attack and blocks its access to the network, terminating the authentication process.

[0074] For example, Figure 3 As shown, a border machine indicates a border switch, and H-1, H-2, H-3, and H-4 indicate different access devices 110, respectively. After H-1 passes authentication at border machine 1, border machine 1 synchronizes H-1's authentication data with other border machines in LAN-A. The other border machines record H-1's authentication data at border machine 1 and add H-1's MAC address to a whitelist to quickly forward responses to messages initiated by H-1. When H-1 sends a message to H-4, the message passes through border machine 2 and border machine N in LAN-A. Because border machines 2 and N have already added H-1's MAC address to the corresponding whitelists based on H-1's authentication data sent by border machine 1, border machines 2 and N send the message directly to H-4. This avoids repeated authentication of H-1 by border machines 2 and N, saves network resources required for authentication, and improves data transmission efficiency.

[0075] After access device 110H-1 passes authentication at edge machine 1, edge machine 1 synchronizes H-1's authentication data with other edge machines in LAN-A and centralized management server 130. The other edge machines and centralized management server 130 record H-1's authentication data as having been authenticated at edge machine 1. Attacker H-1A attempts to access edge machine 1 by spoofing H-1's MAC address. Edge machine 1 detects that the MAC address has been authenticated and is active online, and denies H-1A's access, thus preventing the unauthorized access attack.

[0076] H-1A attempts to access from border machine N. Border machine N finds that this MAC address has been authenticated at border machine 1 and is in an online active state, so it denies H-1A's access, thus preventing the illegal access attack.

[0077] H-1A attempts to access the edge machine 1'. The edge machine 1' queries the centralized management server 130 for the authentication data corresponding to the MAC address. The centralized management server 130 finds that this MAC address has been authenticated at the edge machine 1 and is in an active online state. It sends a reply message to the edge machine 1', reporting that H-1A is a clone attack. After receiving the reply, the edge machine 1' denies H-1A's access, thus preventing the illegal access attack.

[0078] In summary, implementing duplicate authentication immunity on non-home border switches without compromising security improves the speed at which legitimate devices access the network and reduces network and resource consumption caused by duplicate authentication. Furthermore, by synchronizing authentication data without impacting legitimate devices' access, MAC cloning attacks are identified, preventing unauthorized devices from accessing the network and disrupting the normal switching services of legitimate devices. This effectively denies access to the network to attackers using spoofed MAC addresses and prevents cross-LAN MAC cloning attacks, thus improving network security.

[0079] Figure 2 FIG. 1 is a flow chart of a device authentication method in one embodiment. It should be understood that although Figure 2 The steps in the flowchart are shown in sequence as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified in this document, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. In addition, Figure 2 At least part of the steps may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed in turn or alternately with other steps or at least part of the sub-steps or stages of other steps.

[0080] In one embodiment, as shown in Figure 4 An apparatus authentication device is provided, comprising:

[0081] The query module 310 is configured to query target authentication data corresponding to the target device in a target authentication record corresponding to a target switch port in a case where it is detected that the target switch port receives the packet data sent by the target device, the target switch port being any one of the switch ports of the first border switch, and the target authentication record including authentication data that has passed authentication from the target switch port.

[0082] The authentication module 320 is configured to perform authentication processing on the target device in a case where the target authentication data is not queried in the target authentication record, and obtain a corresponding authentication result.

[0083] The sending module 330 is configured to send the authentication result to a neighboring switch and a centralized management server 130, so that a second border switch quickly responds according to the target authentication data in a case where the packet data is received, the neighboring switch being another border switch in a local area network where the first border switch is located, and the second border switch including the neighboring switch.

[0084] In one embodiment, the device further comprises a processing module configured to:

[0085] In a case where the target authentication data corresponding to the target device is queried in the target authentication record, and a target authentication state in the target authentication data is authentication passed, the packet data is forwarded for processing; or,

[0086] In a case where the target authentication data corresponding to the target device is queried in the target authentication record, and a target authentication state in the target authentication data is authentication failed, the packet data is rejected and discarded.

[0087] In one embodiment, the authentication module 320 is specifically configured to:

[0088] In a case where the target authentication state and a target active state corresponding to the target device are queried in a device database, the target authentication state is authentication passed, and the target active state is online active, an authentication result indicating a clone attack is obtained, wherein the device database includes authentication records corresponding to each switch port of the first border switch; or,

[0089] In a case where the target authentication state and the target activity state are not queried in the device database, or the target authentication state is queried as authentication failure, an inquiry message is generated and sent to the adjacent switch, and a corresponding authentication result is determined according to a feedback result of the adjacent switch, wherein the inquiry message is used to query and obtain the target authentication data, and the inquiry message includes a target physical address of the target device.

[0090] In an embodiment, the authentication module 320 is specifically configured to:

[0091] In a case where the feedback result of the adjacent switch indicates that the target authentication state is authentication pass and the target activity state is online activity, an authentication result indicating a clone attack is obtained; or,

[0092] In a case where the feedback result of the adjacent switch indicates a response timeout or the target authentication data is not queried, the inquiry message is sent to the centralized management server 130, and a corresponding authentication result of the target device is determined according to a feedback result of the centralized management server 130.

[0093] In an embodiment, the authentication module 320 is specifically configured to:

[0094] In a case where the feedback result returned by the centralized management server 130 indicates that the target physical address corresponds to registration information, the target device is authenticated according to the registration information, and an authentication pass authentication result is obtained; or,

[0095] In a case where the feedback result returned by the centralized management server 130 indicates that the target authentication state is authentication pass and the target activity state is online activity, an authentication result indicating a clone attack is obtained.

[0096] In an embodiment, the processing module is further configured to:

[0097] According to the authentication pass authentication result, corresponding authentication data of the target device is generated and saved into the target authentication record;

[0098] A detection packet is sent to the target device at a preset period;

[0099] According to a packet response returned by the target device, an updated activity state corresponding to the target device is determined;

[0100] In a case where the updated activity state is offline, authentication data corresponding to the target device is deleted from the target authentication record.

[0101] In an embodiment, the processing module is further configured to:

[0102] In a case where the closed state of the target exchange port is closed, it is determined that the update activity state corresponding to the target device is offline.

[0103] Figure 5 An internal structure diagram of a computer device in an embodiment is shown. The computer device can be a border switch in particular Figure 1 as shown in Figure 5 The computer device includes a processor, a memory, a network interface, an input device and a display screen connected through a system bus. The memory includes a non-volatile storage medium and an internal memory. The non-volatile storage medium of the computer device stores an operating system, and can also store a computer program which, when executed by the processor, can enable the processor to implement the device authentication method. The internal memory can also store a computer program which, when executed by the processor, can enable the processor to execute the device authentication method. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer overlaid on the display screen, or can be a key, trackball or touchpad provided on the shell of the computer device, or can be an external keyboard, touchpad or mouse, etc.

[0104] Those skilled in the art can understand that Figure 5 the structure shown in is only a block diagram of part of the structure related to the scheme of the present application, and does not constitute a limitation on the computer device to which the scheme of the present application is applied. The specific computer device can include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.

[0105] Figure 5 In an embodiment, the device authentication apparatus provided by the present application can be implemented in the form of a computer program which can run on the computer device as shown in Figure 4 The memory of the computer device can store various program modules constituting the device authentication apparatus, such as the query module 310, the authentication module 320 and the sending module 330 as shown in The computer program constituted by the various program modules enables the processor to execute the steps in the device authentication method of each embodiment of the present application described in the specification.

[0106] Figure 5 The computer device as shown in Figure 4The query module 310 in the device authentication apparatus shown performs, in a case where it is detected that a target exchange port receives packet data sent by a target device, querying target authentication data corresponding to the target device in a target authentication record corresponding to the target exchange port, wherein the target exchange port is any exchange port of the first boundary switch, and the target authentication record includes authentication data that has passed authentication from the target exchange port. The computer device can perform, via the authentication module 320, authentication processing on the target device in a case where the target authentication data is not queried in the target authentication record, to obtain a corresponding authentication result. The computer device can perform, via the sending module 330, sending the authentication result to a neighboring switch and a centralized management server 130, so that the second boundary switch, in a case where the packet data is received, responds quickly according to the target authentication data, wherein the neighboring switch is another boundary switch in a local area network where the first boundary switch is located, and the second boundary switch includes the neighboring switch.

[0107] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor, and the processor implements the method of any of the above embodiments when executing the computer program.

[0108] In one embodiment, a computer readable storage medium is provided, and the computer readable storage medium has stored thereon a computer program, and the computer program is executable by a processor to implement the method of any of the above embodiments.

[0109] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program. The program can be stored in a non-volatile computer readable storage medium, and when the program is executed, the processes of the above-mentioned embodiments of the methods can be included. Any reference to memory, storage, databases, or other media in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. As an illustration but not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.

[0110] It should be noted that the relational terms herein such as "first" and "second" and the like are used solely to distinguish one from another entity or action, without necessarily requiring or implying any such actual relationship or order between such entities or actions. Moreover, the terms "comprises", "comprising", or any other variations thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but can include other elements not expressly listed or inherent to such process, method, article, or apparatus. Without more limitations, an element defined by the statement "comprising a" does not exclude the existence of additional identical elements in the process, method, article, or apparatus that includes the element.

[0111] The above description is merely one specific implementation of the application. Many modifications and variations of the described embodiments can be apparent to those skilled in the art without departing from the spirit or scope of the application. Thus, it is intended that the present application cover modifications and variations of this implementation provided they come within the scope of the appended claims and their equivalents.

Claims

1. A device authentication method, characterized in that: Applied to a first edge switch, the method includes: When detecting that the target switch port receives the message data sent by the target device, querying the target authentication data corresponding to the target device in the target authentication record corresponding to the target switch port, wherein the target switch port is any switch port of the first edge switch, each switch port corresponds to an authentication record, and the target authentication record includes authentication data authenticated from the target switch port; If the target authentication data is not found in the target authentication record, performing authentication processing on the target device to obtain a corresponding authentication result; sending the authentication result to an adjacent switch and a centralized management server, and instructing a second border switch to quickly respond according to the target authentication data upon receiving the message data, wherein the adjacent switch is another border switch in the local area network where the first border switch is located, and the second border switch includes the adjacent switch; and a trust relationship is established between the second border switch and the first border switch; The performing authentication processing on the target device to obtain a corresponding authentication result includes: if the target authentication status and the target activity status are not found in a device database, or if the target authentication status is found to be authentication failed, generating and sending a query message to the adjacent switch, and determining a corresponding authentication result based on a feedback result from the adjacent switch; The determining the corresponding authentication result according to the feedback result of the adjacent switch includes: sending the query message to the centralized management server when the feedback result of the adjacent switch indicates a response timeout or failure to query the target authentication data, and determining the authentication result corresponding to the target device according to the feedback result of the centralized management server; The determining of the authentication result corresponding to the target device based on the feedback result of the centralized management server includes: when the feedback result returned by the centralized management server indicates the registration information corresponding to the target physical address, authenticating the target device according to the registration information to obtain an authentication result of passed authentication; or, when the feedback result returned by the centralized management server indicates that the target authentication status is passed authentication and the target activity status is online activity, obtaining an authentication result indicating a cloning attack.

2. The method according to claim 1, characterized in that After querying the target authentication data corresponding to the target device in the target authentication record corresponding to the target switching port, the method further includes: When target authentication data corresponding to the target device is found in the target authentication record and the target authentication status in the target authentication data is authentication passed, forwarding the message data; or If the target authentication data corresponding to the target device is found in the target authentication record and the target authentication status in the target authentication data is authentication failure, the message data is refused to be forwarded and the message data is discarded.

3. The method according to claim 1, characterized in that The target authentication data includes a target authentication state and a target activity state, and the authentication process is performed on the target device to obtain a corresponding authentication result, further comprising: When the target authentication status and target activity status corresponding to the target device are queried in the device database, and the target authentication status is authentication passed and the target activity status is online active, an authentication result indicating a cloning attack is obtained, wherein the device database includes authentication records corresponding to each switching port of the first border switch; wherein the query message is used to query and obtain the target authentication data, and the query message includes the target physical address of the target device.

4. The method according to claim 3, characterized in that The determining of the corresponding authentication result according to the feedback result of the adjacent switch further includes: When the feedback result of the adjacent switch indicates that the target authentication state is authentication passed and the target activity state is online active, an authentication result indicating a cloning attack is obtained.

5. The method according to claim 1, wherein After obtaining the authentication result indicating that the authentication is successful, the method further includes: Generating authentication data corresponding to the target device according to the authentication result of the authentication, and saving it to the target authentication record; Sending a detection message to the target device according to a preset period; Determining an update activity status corresponding to the target device according to the message response returned by the target device; When the update activity status is offline, the authentication data corresponding to the target device is deleted from the target authentication record.

6. The method according to claim 1, characterized in that After obtaining the authentication result indicating a cloning attack, the method further includes: In a case where the closed state of the target switch port is closed, it is determined that the update activity state corresponding to the target device is offline.

7. A device authentication apparatus, characterized in that: The device comprises: a query module, configured to query target authentication data corresponding to the target device in a target authentication record corresponding to the target switch port when detecting that the target switch port receives message data sent by the target device, wherein the target switch port is any switch port of the first edge switch, each switch port corresponds to an authentication record, and the target authentication record includes authentication data authenticated from the target switch port; an authentication module, configured to perform authentication processing on the target device and obtain a corresponding authentication result if the target authentication data is not found in the target authentication record; The sending module is used to send the authentication result to the adjacent switch and the centralized management server, so that the second edge switch receives the message data according to the The target authentication data is quickly responded to, the adjacent switch is another edge switch in the local area network where the first edge switch is located, the second edge switch includes the adjacent switch; a trust relationship is established between the second edge switch and the first edge switch; The performing authentication processing on the target device to obtain a corresponding authentication result includes: if the target authentication status and the target activity status are not found in a device database, or if the target authentication status is found to be authentication failed, generating and sending a query message to the adjacent switch, and determining a corresponding authentication result based on a feedback result from the adjacent switch; The determining the corresponding authentication result according to the feedback result of the adjacent switch includes: sending the query message to the centralized management server when the feedback result of the adjacent switch indicates a response timeout or failure to query the target authentication data, and determining the authentication result corresponding to the target device according to the feedback result of the centralized management server; The determining of the authentication result corresponding to the target device based on the feedback result of the centralized management server includes: when the feedback result returned by the centralized management server indicates the registration information corresponding to the target physical address, authenticating the target device according to the registration information to obtain an authentication result of passed authentication; or, when the feedback result returned by the centralized management server indicates that the target authentication status is passed authentication and the target activity status is online activity, obtaining an authentication result indicating a cloning attack.

8. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Network access control method, system and device

    CN102158487A

  • Authentication sharing method and module for wireless routers inside local area network

    CN104320780A

  • Terminal access authentication method and system

    CN112615829A

  • Access and access strategy control method, device and system of wireless equipment

    CN114339756A