Network connection method, apparatus and system
By parsing and authenticating the authentication messages of access devices in the cloud gateway device, it ensures that only legitimate devices can access the network, thus solving the problem of unauthorized device access in the cloud broadband network and achieving higher network security.
Patent Information
- Application Number
- CN202211563600.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-07
- Publication Date
- 2026-01-30
- Estimated Expiration
- 2042-12-07
AI Technical Summary
In cloud broadband networks, unauthorized devices can access the network through cloud gateway devices, increasing network security risks.
The cloud gateway device receives the authentication message of the device to be connected sent by the access device, and determines the authentication information of the device to be connected through parsing and authentication processing. If the authentication result meets the conditions, a network protocol address is allocated to establish a connection.
This effectively prevents unauthorized devices from accessing the network, reduces network security risks, and improves network security.
Smart Images

Figure CN116015746B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of communication, in particular to a network connection method, device and system. BACKGROUND
[0002] With the continuous development of communication technology, people's requirements for communication network quality are getting higher and higher. In order to meet people's demand for network quality, cloud broadband network emerges as the times require.
[0003] Cloud broadband provides three-in-one services of access, storage and computing power. When users use cloud broadband services, they no longer enter the big network through traditional broadband, but directly access the edge cloud closest to themselves and form a closed loop. By deeply integrating cloud applications and access network broadband, network quality is improved and user's online perception is improved. In the current application scenario of cloud broadband network, when an electronic device initiates a network access request to a cloud gateway device through a network cable or WIFI, the cloud gateway device will directly allow the electronic device to access the network. Since the legality of the electronic device is not authenticated in the network access process, illegal devices can also access the network through the cloud gateway device, thereby increasing the network security risk. SUMMARY
[0004] The present application provides a network connection method, device and system for alleviating the technical problem of current high network security risk.
[0005] In order to solve the above technical problems, the present application provides the following technical solutions:
[0006] The present application provides a network connection method applied to a cloud gateway device, wherein the cloud gateway device is connected with an access device, and the network connection method comprises:
[0007] Receiving a to-be-connected device authentication message sent by the access device based on a network connection request; the network connection request comprises a network connection request initiated by a to-be-connected device;
[0008] Determining to-be-connected device authentication information based on the to-be-connected device authentication message;
[0009] Authenticating the to-be-connected device authentication information to obtain an authentication result;
[0010] If the authentication result meets a network connection condition, a network protocol address is allocated to the to-be-connected device, so that the to-be-connected device establishes a connection with a target network based on the network protocol address.
[0011] The step of determining to-be-connected device authentication information based on the to-be-connected device authentication message comprises:
[0012] Determining a target field in the to-be-connected device authentication message;
[0013] Obtaining the to-be-connected device authentication information in the target field.
[0014] The step of obtaining the to-be-connected device authentication information in the target field comprises:
[0015] Obtaining the encrypted authentication information in the target field.
[0016] Decrypting the encrypted authentication information to obtain the to-be-connected device authentication information.
[0017] The step of obtaining the encrypted authentication information in the target field comprises:
[0018] Parsing the target field to extract the encrypted authentication information in the target field.
[0019] The step of decrypting the encrypted authentication information to obtain the to-be-connected device authentication information comprises:
[0020] Decrypting the encrypted authentication information to obtain the physical address of the to-be-connected device.
[0021] Taking the physical address as the to-be-connected device authentication information.
[0022] The step of decrypting the encrypted authentication information to obtain the to-be-connected device authentication information further comprises:
[0023] Decrypting the encrypted authentication information to obtain the unique identification code of the to-be-connected device.
[0024] Taking the unique identification code as the to-be-connected device authentication information.
[0025] The encrypted authentication information comprises a target authentication account allocated by the cloud gateway device for the access device.
[0026] The step of authenticating the to-be-connected device authentication information to obtain an authentication result comprises:
[0027] Comparing the to-be-connected device authentication information with reference authentication information to obtain a comparison result.
[0028] Taking the comparison result as the authentication result.
[0029] The network protocol address includes a target IP address used for connecting a target network, and the step of assigning the network protocol address to the device to be connected to enable the device to be connected to establish a connection with the target network based on the network protocol address includes:
[0030] If the authentication result indicates that the reference authentication information includes the authentication information of the device to be connected, it is determined that the authentication result satisfies the network connection condition, and the target IP address is determined based on the authentication message of the device to be connected.
[0031] The target IP address is assigned to the device to be connected to enable the device to be connected to establish a connection with the target network based on the target IP address.
[0032] The application further provides a network connection device applied to a cloud gateway device, wherein the cloud gateway device is connected with an access device, and the network connection device comprises:
[0033] A receiving module is configured to receive an authentication message of a device to be connected sent by the access device based on a network connection request; the network connection request includes a network connection request initiated by the device to be connected.
[0034] A determining module is configured to determine authentication information of the device to be connected based on the authentication message of the device to be connected.
[0035] An authentication module is configured to authenticate the authentication information of the device to be connected to obtain an authentication result.
[0036] A connecting module is configured to assign a network protocol address to the device to be connected if the authentication result satisfies a network connection condition, to enable the device to be connected to establish a connection with a target network based on the network protocol address.
[0037] The application further provides a network connection system, comprising a device to be connected, an access device and a cloud gateway device.
[0038] The device to be connected is configured to initiate a network connection request to the access device.
[0039] The access device is configured to receive the network connection request sent by the device to be connected, insert authentication information of the device to be connected in the network connection request to generate an authentication message of the device to be connected, and send the authentication message of the device to be connected to the cloud gateway device.
[0040] The cloud gateway device is configured to receive a device authentication message sent by the access device based on the network connection request, determine the device authentication information based on the device authentication message, authenticate the device authentication information, obtain an authentication result, and if the authentication result meets the network connection conditions, allocate a network protocol address to the device to be connected so that the device to be connected can establish a connection with the target network based on the network protocol address.
[0041] This application provides a network connection method, apparatus, and system applied to a cloud gateway device. The cloud gateway device connects to an access device. First, it receives a connection request sent by the access device based on a network connection request. This network connection request includes a network connection request initiated by the device to be connected. Then, it determines the authentication information of the device to be connected based on the connection request, and authenticates this information to obtain an authentication result. If the authentication result meets the network connection conditions, a network protocol address is assigned to the device to be connected, enabling the device to establish a connection with the target network based on the network protocol address. Since the cloud gateway device authenticates the connection request's corresponding connection request after the device to be connected initiates the network connection request, it can determine the legitimacy of the device to be connected based on whether the authentication result meets the network connection conditions. Only when the device is deemed legitimate is it allowed to access the target network, thus effectively preventing unauthorized devices from accessing the network and significantly reducing network security risks. Attached Figure Description
[0042] The technical solution and other beneficial effects of this application will become apparent from the following detailed description of specific embodiments in conjunction with the accompanying drawings.
[0043] Figure 1 This is a flowchart illustrating the network connection method provided in the embodiments of this application.
[0044] Figure 2 This is a schematic diagram of a network connection method provided in an embodiment of this application.
[0045] Figure 3 This is a schematic diagram of the network connection device provided in the embodiments of this application.
[0046] Figure 4 This is a schematic diagram of the network connection system provided in the embodiments of this application. Detailed Implementation
[0047] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0048] This application provides a network connection method, apparatus, and system.
[0049] like Figure 1 As shown, Figure 1 This is a flowchart illustrating a network connection method provided in an embodiment of this application. The method is applied to a cloud gateway device, which is connected to an access device. The cloud gateway device serves as an interface between the electronic device and the cloud platform, and can analyze and process the interactive data between the electronic device and the cloud platform. The access device connects the electronic device to the cloud platform, enabling the electronic device to access the network. The specific process can be as follows:
[0050] S101. Receive the authentication message of the device to be connected sent by the access device based on the network connection request, the network connection request including the network connection request initiated by the device to be connected.
[0051] Among them, the device to be connected is an electronic device that needs to access the network (e.g., smartphone, computer, etc.), the network connection request is a message used to request access to the network, and the device authentication message is used to determine whether the device to be connected is legitimate.
[0052] Specifically, in the current optical access network process, after an electronic device initiates a network access request to the cloud gateway device via a network cable or Wi-Fi, the cloud gateway device will directly allow the electronic device to access the network. Since the legitimacy of the electronic device is not authenticated during the network access process, unauthorized devices can also access the network through the cloud gateway device, thus posing a threat to network security.
[0053] To avoid the above situation, in this embodiment, as follows: Figure 2 As shown, when a user clicks the "Access Network" button 2002 on the network connection interface 2001 of the device to be connected, the device to be connected immediately initiates a network connection request. The access device receives the network connection request, processes it to generate an authentication message for the device to be connected, and then sends the authentication message to the cloud gateway device. The cloud gateway device determines whether the device to be connected is legitimate based on the authentication message. If the device is deemed legitimate, it is allowed to access the network; if it is deemed illegitimate, it is denied access. This effectively prevents unauthorized devices from accessing the network and provides security for the network.
[0054] Furthermore, OLT (Optical Line Terminal) equipment and ONU (Optical Network Unit) equipment are the core components of optical access networks. The OLT equipment connects to the ONU equipment (the downstream device of the OLT equipment) to implement functions such as control and management of the ONU equipment. The ONU equipment consists of core functional circuits, power supply and management common units, and communication interfaces. Its core functions include distributing information from electronic devices and information to be transmitted to electronic devices. In practical applications, OLT equipment and ONU equipment are usually used together to enable electronic devices to access the network via optical access.
[0055] Specifically, in this embodiment, the network connection request is a DHCP (Dynamic Host Configuration Protocol) message. The access device includes an OLT device. In addition, an ONU device connected to the OLT device is also provided. After the device to be connected initiates a DHCP message, the ONU device first receives the DHCP message and then forwards the DHCP message to the OLT device so that the OLT device can process the DHCP message to generate an authentication message for the device to be connected. The OLT device then sends the authentication message for the device to be connected to the cloud gateway device.
[0056] S102. Determine the authentication information of the device to be connected based on the authentication message of the device to be connected.
[0057] Among them, the authentication information of the device to be connected is the information in the authentication message of the device to be connected that plays the role of device authentication.
[0058] Specifically, after the ONU device forwards the network connection request to the OLT device, the OLT device first parses the device information of the device to be connected based on the network connection request. Based on this device information, the authentication information of the device to be connected can be determined, and this authentication information is inserted into the target field of the network connection request. The network connection request with the inserted authentication information is then used as the authentication message for the device to be connected. In this embodiment, the target field in the authentication message for the device to be connected is first determined, and then the authentication information of the device to be connected in the target field is obtained. Optionally, the OPTION82 field in the network connection request message can be used as the target field. In practical applications, if the OPTION82 field has been used for other purposes, other DHCP extended fields can be used as the target fields.
[0059] Considering that the authentication information of the device to be connected may be illegally tampered with during the transmission of the authentication message, the reliability of the authentication information received by the cloud gateway device is low, which will affect the subsequent device authentication results. Therefore, it is necessary to ensure the reliability of the authentication information of the device to be connected during the transmission process.
[0060] Therefore, in this embodiment, a preset encryption algorithm is distributed to the OLT device in advance, and a preset decryption algorithm is distributed to the cloud gateway device. After the OLT device inserts the authentication information of the device to be connected into the target field of the authentication message of the device to be connected, it encrypts the authentication information of the device to be connected according to the preset encryption algorithm to generate encrypted authentication information. Then, it sends the authentication message of the device to be connected with the encrypted authentication information to the cloud gateway device. The cloud gateway device first obtains the encrypted authentication information in the target field of the authentication message of the device to be connected (for example, it parses the target field to extract the encrypted authentication information in the target field), and then decrypts the encrypted authentication information according to the preset decryption algorithm to obtain accurate and reliable authentication information of the device to be connected.
[0061] Optionally, a unique authentication account is pre-set for each LAN (Local Area Network) in each region, and each authentication account is stored in the cloud gateway device. The cloud gateway device then distributes each authentication account to the OLT device. In this embodiment, the encrypted authentication information includes the target authentication account (i.e., the authentication account corresponding to the LAN in the region where the device to be connected is located). After receiving the device authentication message sent by the device to be connected, the OLT device determines the device authentication information and the LAN in the region where the device is located, and determines the corresponding target authentication account based on the LAN in the region to bind the device authentication information to the target authentication account. At the same time, the device authentication information is encrypted according to a preset encryption algorithm to generate the target authentication account, and the target authentication account is sent to the cloud gateway device. The cloud gateway device decrypts the target authentication account according to a preset decryption algorithm to obtain the device authentication information bound to the target authentication account.
[0062] Specifically, when obtaining the authentication information of the device to be connected based on the encrypted authentication information, in one embodiment, the encrypted authentication information is decrypted to obtain the physical address (i.e., MAC address) of the device to be connected, and this physical address is used as the authentication information of the device to be connected. For example, if the encrypted authentication information is decrypted to obtain the physical address of the device to be connected as "00:09:5B:EC:EE:F2", then "00:09:5B:EC:EE:F2" is used as the authentication information of the device to be connected.
[0063] In another embodiment, the encrypted authentication information is decrypted to obtain a unique identifier (UUID) for the device to be connected, and this unique identifier is used as the authentication information for the device to be connected. For example, the encrypted authentication information is decrypted to obtain a unique identifier "419E4178DC28E" for the device to be connected, and "419E4178DC28E" is used as the authentication information for the device to be connected.
[0064] S103. Authenticate the authentication information of the device to be connected and obtain the authentication result.
[0065] The authentication result is used to identify whether the device to be connected is a legitimate or illegitimate device.
[0066] Specifically, in this embodiment, the cloud gateway device stores device information for all legitimate devices corresponding to each target authentication account. The device information corresponding to the target authentication account within the LAN range of the device to be connected is used as reference authentication information (including at least the physical address or unique identifier). For example, the reference authentication information is the physical address of the legitimate device.
[0067] "00:09:5B:EC:EE:F2", "A12:B:C3:4D:E5:6F", "00-16-EA-AE-3C-40" and "52:54:00:3B:CA:3F"; the reference authentication information is the unique identifier of a legitimate device.
[0068] “32AC5862EF19B”, “235C5623B56AF”, “162E2132CE32F” and “124B3541DE20A”.
[0069] Next, the authentication information of the device to be connected is compared with the reference authentication information to obtain the comparison result, and this comparison result is used as the authentication result. It should be noted that the format of the authentication information of the device to be connected is the same as that of the reference authentication information. That is, when the physical address is used as the reference authentication information, the authentication information of the device to be connected is the physical address of the device to be connected; when the unique identifier is used as the reference authentication information, the authentication information of the device to be connected is the unique identifier of the device to be connected.
[0070] S104. If the authentication result meets the network connection conditions, the network protocol address is assigned to the device to be connected, so that the device to be connected can establish a connection with the target network based on the network protocol address.
[0071] Among them, network connection conditions are the basis for determining whether the device to be connected has the right to access the network (i.e., whether it is a legitimate device).
[0072] Specifically, when the authentication result meets the network connection requirements, it indicates that the device to be connected is a legitimate device. Therefore, the cloud gateway device assigns a network protocol address (NAT) to the device to establish a connection with the target network based on the NAT, allowing the device to access the internet normally. Conversely, if the authentication result fails to meet the network connection requirements, it indicates that the device to be connected is an illegitimate device. The cloud gateway device does not assign a NAT to the device, preventing it from accessing the target network. This facilitates more effective management of network devices by network maintenance personnel and prevents network security threats. Optionally, the NAT can be the target IP address, and the target network can be the LAN network within the area where the device to be connected is located.
[0073] Furthermore, in this embodiment, if the authentication result indicates that the reference authentication information includes the authentication information of the device to be connected, then it is determined that the authentication result meets the network connection conditions, and the target IP address is determined based on the authentication message of the device to be connected, so as to allocate the target IP address to the device to be connected, so that the device to be connected can establish a connection with the target network based on the target IP address.
[0074] For example, the reference authentication information is the physical address of a legitimate device:
[0075] “00:09:5B:EC:EE:F2”, “A12:B:C3:4D:E5:6F”, “00-16-EA-AE-3C-40”, and “52:54:00:3B:CA:3F” represent the authentication information of the device to be connected, which is the physical address of the device.
[0076] Since the authentication information includes the physical address of the device to be connected ("00:09:5B:EC:EE:F2"), the authentication result is determined to meet the network connection requirements. Based on the authentication message of the device to be connected, the target IP address is determined to be 183.94.135.226, and this IP address is assigned to the device to enable it to access the target network based on this IP address. Figure 2 As shown, at this time, the network connection interface 2001 will display the connected network icon 2003, and the user can then use the device to be connected to access the Internet.
[0077] Furthermore, in this embodiment, if the authentication result does not meet the network connection conditions (i.e., the authentication result indicates that the reference authentication information does not include the authentication information of the device to be connected), the device information of the device to be connected is written into a blacklist. The device to be connected corresponding to the device information stored in the blacklist cannot initiate a network connection request again. Therefore, the cloud gateway device and the access device do not need to process it repeatedly, thereby effectively reducing the workload of the cloud gateway device and the access device and improving their working efficiency. Optionally, the blacklist is stored in the cloud gateway device, which grants it the permission to prohibit initiating network connection requests.
[0078] As described above, the network connection method provided in this application is applied to a cloud gateway device. This cloud gateway device connects with an access device. First, it receives a connection request message from the access device, which includes a network connection request initiated by the device to be connected. Then, it determines the authentication information of the device to be connected based on the connection request message and authenticates this information to obtain an authentication result. If the authentication result meets the network connection conditions, a network protocol address is assigned to the device to be connected, enabling the device to establish a connection with the target network based on the network protocol address. Since the cloud gateway device authenticates the connection request message after the device to be connected initiates the network connection request, it can determine the legitimacy of the device based on whether the authentication result meets the network connection conditions. Only when the device is deemed legitimate is it allowed to access the target network, thus effectively preventing unauthorized devices from accessing the network and significantly reducing network security risks.
[0079] Based on the methods described in the above embodiments, this embodiment will be further described from the perspective of a network connection device.
[0080] Please see Figure 3 , Figure 3 This application provides a network connection device that is applied to a cloud gateway device and connected to an access device. The network connection device may include: a receiving module 10, a determining module 20, an authentication module 30, and a connection module 40, wherein:
[0081] (1) Receiver module 10
[0082] The receiving module 10 is used to receive the authentication message of the device to be connected sent by the access device based on the network connection request, which includes the network connection request initiated by the device to be connected.
[0083] (2) Determine module 20
[0084] The determination module 20 is used to determine the authentication information of the device to be connected based on the authentication message of the device to be connected.
[0085] Specifically, the determining module 20 is used for:
[0086] Determine the target fields in the authentication message of the device to be connected;
[0087] Retrieve the authentication information of the device to be connected from the target field.
[0088] Specifically, module 20 is also used for:
[0089] Retrieve the encrypted authentication information from the target field;
[0090] The encrypted authentication information is decrypted to obtain the authentication information of the device to be connected.
[0091] Furthermore, module 20 is also used for:
[0092] The target field is parsed to extract the encrypted authentication information.
[0093] Module 20 can also be used for:
[0094] The encrypted authentication information is decrypted to obtain the physical address of the device to be connected.
[0095] Use the physical address as authentication information for the device to be connected.
[0096] Module 20 can also be used for:
[0097] The encrypted authentication information is decrypted to obtain the unique identifier of the device to be connected.
[0098] Use the unique identifier as the authentication information for the device to be connected.
[0099] The encrypted authentication information includes the target authentication account assigned by the cloud gateway device to the access device.
[0100] (3) Authentication Module 30
[0101] The authentication module 30 is used to authenticate the authentication information of the device to be connected and obtain the authentication result.
[0102] Specifically, the authentication module 30 is used for:
[0103] The authentication information of the device to be connected is compared with the reference authentication information to obtain the comparison result;
[0104] The comparison result will be used as the authentication result.
[0105] (4) Connection module 40
[0106] The connection module 40 is used to assign a network protocol address to the device to be connected if the authentication result meets the network connection conditions, so that the device to be connected can establish a connection with the target network based on the network protocol address.
[0107] The network protocol address includes the target IP address used to connect to the target network, and the connection module 40 is specifically used for:
[0108] If the authentication result indicates that the reference authentication information includes the authentication information of the device to be connected, it is determined that the authentication result meets the network connection conditions, and the target IP address is determined based on the authentication message of the device to be connected.
[0109] Assign a target IP address to the device to be connected, so that the device to be connected can establish a connection with the target network based on the target IP address.
[0110] In practice, each of the above units can be implemented as an independent entity or can be arbitrarily combined to be implemented as the same or several entities. For the specific implementation of each of the above units, please refer to the previous method embodiments, which will not be repeated here.
[0111] As described above, the network connection device provided in this application is applied to a cloud gateway device. This cloud gateway device connects to an access device. First, the receiving module 10 receives an authentication message from the access device based on a network connection request. This network connection request includes a network connection request initiated by the device to be connected. Then, the determining module 20 determines the authentication information of the device to be connected based on the authentication message. Next, the authentication module 30 authenticates the authentication information to obtain an authentication result. If the authentication result meets the network connection conditions, the connection module 40 assigns a network protocol address to the device to be connected, enabling the device to establish a connection with the target network based on the network protocol address. Since the cloud gateway device authenticates the authentication message corresponding to the network connection request after the device to be connected initiates the network connection request, it can determine whether the device to be connected is legitimate based on whether the authentication result meets the network connection conditions. Only when the device is deemed legitimate is the device allowed to access the target network, thus effectively preventing unauthorized devices from accessing the network and effectively reducing network security risks.
[0112] Accordingly, embodiments of the present invention also provide a network connection system, including a device to be connected, an access device, and a cloud gateway device. The device to be connected initiates a network connection request to the access device. The access device receives the network connection request from the device to be connected, inserts authentication information of the device to be connected into the network connection request to generate an authentication message for the device to be connected, and sends the authentication message to the cloud gateway device. The cloud gateway device receives the authentication message from the access device based on the network connection request, determines the authentication information of the device to be connected based on the authentication message, authenticates the authentication information of the device to be connected, obtains an authentication result, and if the authentication result meets the network connection conditions, assigns a network protocol address to the device to be connected, so that the device to be connected can establish a connection with the target network based on the network protocol address.
[0113] Specifically, such as Figure 4 As shown, the network connection system includes: a device to be connected 41, an access device 42, and a cloud gateway device 43. The device to be connected 41 first executes step S401: initiating a network connection request to the access device 42. Then, the access device 42 executes step S402: inserting the authentication information of the device to be connected into the network connection request to generate an authentication message for the device to be connected. After that, it executes step S403: sending the authentication message to the cloud gateway device 43. Then, the cloud gateway device 43 executes step S404: determining the authentication information of the device to be connected based on the authentication message, and authenticating the authentication information of the device to be connected to obtain the authentication result. If the authentication result meets the network connection conditions, it executes step S405: assigning a network protocol address to the device to be connected 41, so that the device to be connected 41 executes step S406: establishing a connection with the target network based on the network protocol address.
[0114] This network connection system can achieve the beneficial effects that any network connection method provided in the embodiments of the present invention can achieve, as detailed in the preceding embodiments, and will not be repeated here.
[0115] As described above, the network connection system provided in this application includes a device to be connected, an access device, and a cloud gateway device. The device to be connected initiates a network connection request to the access device. The access device receives the network connection request from the device to be connected, inserts the device's authentication information into the request to generate an authentication message, and sends the authentication message to the cloud gateway device. The cloud gateway device receives the authentication message from the access device based on the network connection request, determines the device's authentication information based on the message, authenticates the authentication information, and obtains an authentication result. If the authentication result meets the network connection conditions, a network protocol address is assigned to the device to be connected, enabling the device to establish a connection with the target network based on the network protocol address. Since the cloud gateway device authenticates the authentication message corresponding to the network connection request after the device to be connected initiates the request, it can determine the legitimacy of the device based on whether the authentication result meets the network connection conditions. Only when the device is deemed legitimate is it allowed to access the target network, thus effectively preventing unauthorized devices from accessing the network and significantly reducing network security risks.
[0116] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by instructions, or by instructions controlling related hardware. These instructions can be stored in a computer-readable storage medium and loaded and executed by a processor. Therefore, embodiments of the present invention provide a storage medium storing multiple instructions that can be loaded by a processor to execute the steps in any of the network connection methods provided in the embodiments of the present invention.
[0117] The storage medium may include: read-only memory (ROM), random access memory (RAM), disk or optical disk, etc.
[0118] Since the instructions stored in the storage medium can execute the steps of any of the network connection methods provided in the embodiments of the present invention, the beneficial effects achievable by any of the network connection methods provided in the embodiments of the present invention can be realized, as detailed in the preceding embodiments, and will not be repeated here. The specific implementation of each of the above operations can be found in the preceding embodiments, and will not be repeated here.
[0119] In summary, although the present application has disclosed the preferred embodiments as described above, the above preferred embodiments are not intended to limit the present application. Those skilled in the art can make various modifications and refinements without departing from the spirit and scope of the present application. Therefore, the scope of protection of the present application shall be determined by the scope defined in the claims.
Claims
1. A network connection method characterized by, The application is applied to a cloud gateway device connected with an access device including an OLT device, and the network connection method includes: receiving a to-be-connected device authentication message sent by the access device based on a network connection request; the network connection request includes a network connection request initiated by a to-be-connected device; determining to-be-connected device authentication information based on the to-be-connected device authentication message; authenticating the to-be-connected device authentication information to obtain an authentication result, wherein device information corresponding to a target authentication account of a LAN network in a range where the to-be-connected device is located is taken as reference authentication information, and the to-be-connected device authentication information is compared with the reference authentication information to obtain the authentication result; if the authentication result meets a network connection condition, a network protocol address is allocated to the to-be-connected device to enable the to-be-connected device to establish a connection with a target network based on the network protocol address; wherein the ONU device receives the network connection request and forwards it to the access device, the access device determines a LAN network in an area where the to-be-connected device is located, determines a corresponding target authentication account according to the LAN network in the area where the to-be-connected device is located, encrypts the to-be-connected device authentication information according to a preset encryption algorithm to generate encrypted authentication information, and sends the encrypted authentication information to the cloud gateway device, which decrypts the encrypted authentication information according to a preset decryption algorithm to obtain to-be-connected device authentication information having a binding relationship with the target authentication account; the to-be-connected device authentication information is inserted into a target field of the to-be-connected device authentication message and then encrypted according to the preset encryption algorithm; Each LAN network in each area is provided with a unique authentication account, and each authentication account is stored in the cloud gateway device, which allocates each authentication account to the access device. The target authentication account is the authentication account corresponding to the LAN network in the area where the to-be-connected device is located.
2. The network connection method according to claim 1, wherein, The step of determining to-be-connected device authentication information based on the to-be-connected device authentication message includes: determining a target field in the to-be-connected device authentication message; obtaining to-be-connected device authentication information in the target field.
3. The network connection method according to claim 2, wherein, The step of obtaining to-be-connected device authentication information in the target field includes: obtaining encrypted authentication information in the target field; decrypting the encrypted authentication information to obtain the to-be-connected device authentication information.
4. The network connection method according to claim 3, wherein, The step of obtaining encrypted authentication information in the target field includes: performing analysis processing on the target field to extract the encrypted authentication information in the target field.
5. The network connection method according to claim 3, wherein, The step of decrypting the encrypted authentication information to obtain the to-be-connected device authentication information includes: decrypting the encrypted authentication information to obtain a physical address of the to-be-connected device; taking the physical address as the to-be-connected device authentication information.
6. The network connection method according to claim 3, wherein, The step of decrypting the encrypted authentication information to obtain the to-be-connected device authentication information further includes: decrypting the encrypted authentication information to obtain a unique identification code of the to-be-connected device; The unique identification code is taken as the authentication information of the device to be connected.
7. The method of claim 4-6, wherein, The encrypted authentication information includes a target authentication account number allocated by the cloud gateway device for the access device.
8. The network connection method according to claim 7, wherein, The step of authenticating the authentication information of the device to be connected to obtain an authentication result includes: comparing the authentication information of the device to be connected with reference authentication information to obtain a comparison result; The comparison result is taken as the authentication result.
9. The network connection method according to claim 8, wherein, The network protocol address includes a target IP address for connecting a target network, and if the authentication result meets a network connection condition, a network protocol address is allocated to the device to be connected to enable the device to be connected to establish a connection with the target network based on the network protocol address. If the authentication result indicates that the reference authentication information includes the authentication information of the device to be connected, it is determined that the authentication result meets the network connection condition, and the target IP address is determined based on the authentication message of the device to be connected. The target IP address is allocated to the device to be connected to enable the device to be connected to establish a connection with the target network based on the target IP address.
10. A network connection device, characterized by The cloud gateway device is connected with an access device, and the access device includes an OLT device. The network connection device includes: a receiving module configured to receive an authentication message of a device to be connected sent by an access device based on a network connection request; the network connection request includes a network connection request initiated by a device to be connected; a determining module configured to determine authentication information of a device to be connected based on the authentication message of the device to be connected; an authentication module configured to authenticate the authentication information of the device to be connected to obtain an authentication result, wherein device information corresponding to a target authentication account number of a LAN network in a range in which the device to be connected is located is taken as reference authentication information, and the authentication information of the device to be connected is compared with the reference authentication information to obtain the authentication result; a connection module configured to allocate a network protocol address to the device to be connected if the authentication result meets a network connection condition, to enable the device to be connected to establish a connection with a target network based on the network protocol address; The ONU device receives the network connection request and forwards it to the access device. The access device determines a LAN network in a region in which the device to be connected is located, determines a corresponding target authentication account number based on the LAN network in the region in which the device to be connected is located, encrypts the authentication information of the device to be connected according to a preset encryption algorithm to generate encrypted authentication information, and sends the encrypted authentication information to the cloud gateway device. The cloud gateway device decrypts the encrypted authentication information according to a preset decryption algorithm to obtain authentication information of the device to be connected that has a binding relationship with the target authentication account number. The authentication information of the device to be connected is inserted into a target field of the authentication message of the device to be connected and then encrypted according to the preset encryption algorithm. The LAN networks in each region are respectively provided with a unique authentication account number, and each authentication account number is stored in the cloud gateway device. The cloud gateway device allocates each authentication account number to the access device, and the target authentication account number is the authentication account number corresponding to the LAN network in the region in which the device to be connected is located.
11. A network connection system, characterized by The application relates to a network connection method and device. The application comprises: a to-be-connected device, an access device and a cloud gateway device; the access device comprises an OLT device; the to-be-connected device is used for initiating a network connection request to the access device; the access device is used for receiving the network connection request sent by the to-be-connected device, inserting to-be-connected device authentication information into the network connection request to generate to-be-connected device authentication information, and sending the to-be-connected device authentication information to the cloud gateway device; the cloud gateway device is used for receiving the to-be-connected device authentication information sent by the access device based on the network connection request, determining to-be-connected device authentication information based on the to-be-connected device authentication information, authenticating the to-be-connected device authentication information to obtain an authentication result, and if the authentication result meets a network connection condition, allocating a network protocol address to the to-be-connected device to enable the to-be-connected device to establish a connection with a target network based on the network protocol address, wherein device information corresponding to a target authentication account of a LAN network in a range where the to-be-connected device is located is taken as reference authentication information, the to-be-connected device authentication information is compared with the reference authentication information to obtain the authentication result; the ONU device receives the network connection request and forwards the network connection request to the access device, the access device determines a LAN network in a region where the to-be-connected device is located, determines a corresponding target authentication account according to the LAN network in the region where the to-be-connected device is located, encrypts the to-be-connected device authentication information according to a preset encryption algorithm to generate encrypted authentication information, and sends the encrypted authentication information to the cloud gateway device, the cloud gateway device decrypts the encrypted authentication information according to a preset decryption algorithm to obtain to-be-connected device authentication information having a binding relationship with the target authentication account, the to-be-connected device authentication information is inserted into a target field of the to-be-connected device authentication information, and then the to-be-connected device authentication information is encrypted according to the preset encryption algorithm; the LAN network in each region is provided with a unique authentication account, each authentication account is stored in the cloud gateway device, the cloud gateway device allocates each authentication account to the access device, and the target authentication account is an authentication account corresponding to the LAN network in a region where the to-be-connected device is located.
Citation Information
Patent Citations
ONU equipment authentication method, OLT equipment and ONU equipment authentication system
CN108183910A