Broadband authentication control method, device and electronic equipment

By performing direct authentication and delayed authentication on authentication requests in a broadband metropolitan area network, the overload problem caused by authentication storms is solved, thereby improving user experience and operator profits.

CN116389025BActive Publication Date: 2025-09-26CHINA TELECOM CORP LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202211624202.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-15
Publication Date
2025-09-26
Estimated Expiration
2042-12-15

AI Technical Summary

Technical Problem

In a broadband metropolitan area network (MAN) environment, external authentication attacks or network device disconnection can cause a sharp increase in the number of IP authentications, leading to RADIUS, BRAS, vBRAS, or NAS overloads, increased authentication delays, and even unresponsive authentication, severely impacting user experience.

Method used

In the event of an authentication storm, the RADIUS server directly authenticates the account that initiated the authentication request and restricts authorization. It sends a restricted authorization instruction, including the account ID, feature flag, random offline duration, and random message sending duration. It also delays authentication based on the login device type and the feature identifier in the billing update message. The NAS controls the account connection status based on the change instruction.

Benefits of technology

Quickly respond to authentication requests, shorten user connection waiting time, improve user experience, disperse authentication storms, protect operator interests, prevent duplicate dialing, and improve user connection efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116389025B_ABST
    Figure CN116389025B_ABST
Patent Text Reader

Abstract

The present invention provides a broadband authentication control method, device and electronic device, which relate to the field of broadband technology, including: when it is determined that an authentication storm occurs, the account that initiates the authentication request is directly authenticated and authorized, and the authorization restriction instruction of each authenticated account is sent to the NAS, and the corresponding rate is sent to the login device according to the type identifier of the login device in the authentication request; the billing update message is received and determined whether to delay the authentication according to whether the feature identifier is carried, and the change instruction is sent to the NAS according to the result of the delayed authentication. The present invention not only protects the normal interests of the operator, but also disperses and delays a large number of instantaneous authentication requests during the authentication storm, quickly responds to all authentication requests, shortens the user connection waiting time, and ensures the efficiency of the user connection. It will not aggravate the IP authentication storm situation, prevents repeated authentication, and provides users with better service quality.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of broadband technology, and in particular to a broadband authentication control method, device and electronic equipment. Background Art

[0002] As one of the important core network elements in optical broadband networks, the authentication system in my country currently basically uses the RADIUS (Remote Authentication Dial In User Service) protocol. Through the RADIUS protocol, it interacts with BRAS (Broadband Remote Access Server), vBRAS (Virtual Broadband Remote Access Server) or NAS (Network Attached Server) to implement broadband user authentication, authorization, billing, and authorization changes.

[0003] In the current broadband metropolitan area network environment, when there are problems such as external authentication attacks and network device disconnection, the number of IP authentications will suddenly increase and rise sharply, causing RADIUS, BRAS, vBRAS or NAS in the authentication system to overload, increase authentication delays, and even unresponsive authentication.

[0004] At the same time, the dial-up client that does not respond to authentication will automatically repeat the dialing, further aggravating the IP authentication storm and seriously affecting the customer's experience. Summary of the Invention

[0005] In view of the above problems, the present invention is proposed to provide a broadband authentication control method, device and electronic device that overcome the above problems or at least partially solve the above problems.

[0006] In a first aspect, a broadband authentication control method is provided, wherein the broadband authentication control method is applied to a RADIUS server, and the broadband authentication control method includes:

[0007] If an authentication storm is detected, the account initiating the authentication request is directly authenticated and authorized, and a restricted authorization instruction for each authenticated account is sent to the NAS. The service parameters of the restricted authorization instruction include: account identification, feature flag, random offline duration, and random message sending duration;

[0008] According to the type identifier of the login device in the authentication request, the corresponding rate is issued to the login device;

[0009] Upon receiving a billing update message from the NAS, determining whether to perform delayed authentication on the account corresponding to the account identifier in the billing update message based on whether the billing update message carries the characteristic identifier, the billing update message being generated and sent by the NAS based on the random message sending duration or the normal message sending duration;

[0010] According to the result of the delayed authentication, a change instruction is sent to the NAS, so that the NAS controls the connection status of the account.

[0011] Optionally, directly authenticating the account that initiated the authentication request and restricting authorization means:

[0012] Without comparing the account information in the authentication request with the user credentials corresponding to the account identifier in the database, the characteristic flag, the random offline duration, and the random message sending duration are directly added to the business parameters of the authorization instruction to form the business parameters of the restricted authorization instruction together with the account identifier.

[0013] Optionally, according to the type identifier of the login device in the authentication request, issuing a corresponding rate to the login device includes:

[0014] Identifying the type of the login device according to the type identifier;

[0015] If the type identification is successful, the rate that guarantees its basic application requirements is issued to the login device;

[0016] If the type identification is unsuccessful, the login device is determined to be an unknown device, and a preset rate is sent to the unknown device.

[0017] Optionally, determining whether to perform delayed authentication on an account corresponding to an account identifier in the billing update message according to whether the feature identifier is carried in the billing update message includes:

[0018] If the billing update message carries the characteristic identifier, performing the delayed authentication on the account corresponding to the account identifier in the billing update message;

[0019] If the billing update message does not carry the characteristic identifier, the billing update is performed on the account corresponding to the account identifier in the billing update message without performing the delayed authentication.

[0020] Optionally, performing the delayed authentication on the account corresponding to the account identifier in the billing update message includes:

[0021] Extracting account information corresponding to the account identifier;

[0022] Obtain the user credentials corresponding to the account identifier in the database;

[0023] comparing the account information with the user credentials;

[0024] Sending a change instruction to the NAS according to a result of the delayed authentication includes:

[0025] If the account information and the user credentials are correctly compared, determining that the account has passed the delayed authentication;

[0026] When the account passes the delayed authentication, a change instruction representing precise authorization is sent to the NAS;

[0027] If the comparison between the account information and the user credentials is incorrect, determining that the account has failed the delayed authentication;

[0028] If the account fails the delayed authentication, a change instruction for disconnecting the account is sent to the NAS.

[0029] In a second aspect, a broadband authentication control method is provided, wherein the broadband authentication control method is applied to a NAS, and the broadband authentication control method includes:

[0030] Receiving a restricted authorization instruction from a RADIUS server, wherein the restricted authorization instruction is issued by the RADIUS server after the RADIUS server directly authenticates and restricts authorization for the account initiating the authentication request when determining that an authentication storm has occurred. The service parameters of the restricted authorization instruction include: account identifier, feature flag, random offline duration, and random message sending duration;

[0031] According to the random message sending time length, when the random message sending time length is reached, sending an accounting update message to the RADIUS server, where the accounting update message carries the account identifier and the feature flag; or

[0032] According to a normal message sending time length, when the normal message sending time length is reached, sending an accounting update message to the RADIUS server, where the accounting update message carries the account identifier;

[0033] receiving a change instruction from the RADIUS server, where the change instruction is generated and sent by the RADIUS server according to a result of delayed authentication;

[0034] Determining, according to the change instruction, whether to disconnect the account to control the account to go offline or to control the account to remain connected;

[0035] In the case that the change instruction is not received, whether to disconnect the account is determined according to the random offline duration, so as to control the account to go offline or control the account to remain connected.

[0036] Optionally, determining whether to disconnect the account according to the change instruction to control the account to go offline or to control the account to remain connected includes:

[0037] If the change instruction represents precise authorization, determining not to disconnect the account so as to control the account to remain connected, the change instruction is sent by the RADIUS server when the account information and the user credentials corresponding to the account identifier in the database are correctly compared;

[0038] If the change instruction indicates disconnecting the account connection, it is determined to disconnect the account connection to control the account offline. The change instruction is sent by the RADIUS server when the account information and the user credentials corresponding to the account identifier in the database are incorrectly compared.

[0039] Optionally, determining not to disconnect the account so as to control the account to remain connected includes:

[0040] The business parameters of the restricted authorization instruction corresponding to the account are changed through the CoA protocol, and the business parameters of the restricted authorization instruction corresponding to the account are modified to the business parameters corresponding to the normal authorization instruction, so as to control the account to maintain the connection.

[0041] Optionally, determining to disconnect the account to control the account offline includes:

[0042] The business parameters of the restriction authorization instruction corresponding to the account are changed through the DM protocol, and the business parameters of the restriction authorization instruction corresponding to the account are modified to the business parameters corresponding to the disconnection instruction to control the account to go offline.

[0043] Optionally, when the change instruction is not received, determining whether to disconnect the account according to the random offline duration to control the account to go offline or control the account to remain connected includes:

[0044] If the change instruction is not received and the random offline duration corresponding to the account has not been reached, determine not to disconnect the account, so as to control the account to remain connected;

[0045] If the change instruction is not received and the random offline time period corresponding to the account is reached, it is determined to disconnect the account to control the account to go offline.

[0046] In a third aspect, a broadband authentication control method is provided, wherein the broadband authentication control method is applied to a broadband system, wherein the broadband system includes: a RADIUS server and a NAS, and the broadband authentication control method includes:

[0047] If an authentication storm is detected, the RADIUS server directly authenticates the account that initiated the authentication request and restricts authorization. The server then sends a restricted authorization instruction for each authenticated account to the NAS. The service parameters of the restricted authorization instruction include: account identifier, feature flag, random offline duration, and random message sending duration.

[0048] The RADIUS server sends a corresponding rate to the login device according to the type identifier of the login device in the authentication request;

[0049] The NAS receives the restricted authorization instruction and, based on the random message sending time period, sends an accounting update message to the RADIUS server when the random message sending time period is reached, the accounting update message carrying the account identifier and the feature flag; or

[0050] The NAS sends an accounting update message to the RADIUS server according to a normal message sending time duration, when the normal message sending time duration is reached, where the accounting update message carries the account identifier;

[0051] When the RADIUS server receives the accounting update message, determining whether to perform delayed authentication on the account corresponding to the account identifier in the accounting update message according to whether the accounting update message carries the feature identifier;

[0052] The RADIUS server sends a change instruction to the NAS according to a result of the delayed authentication;

[0053] The NAS receives the change instruction and determines, based on the change instruction, whether to disconnect the account to control the account to go offline or to control the account to remain connected;

[0054] When the NAS does not receive the change instruction, it determines whether to disconnect the account according to the random offline duration to control the account to go offline or control the account to remain connected.

[0055] In a fourth aspect, a broadband authentication control device is provided, wherein the broadband authentication control device is applied to a RADIUS server, and the broadband authentication control device includes:

[0056] The authentication and authorization module is used to directly authenticate and restrict authorization to the account initiating the authentication request when an authentication storm is determined to have occurred, and send a restricted authorization instruction for each authenticated account to the NAS. The service parameters of the restricted authorization instruction include: account identification, feature flag, random offline duration, and random message sending duration;

[0057] A sending module, configured to send a corresponding rate to the login device according to the type identifier of the login device in the authentication request;

[0058] an authentication module, configured to, upon receiving a billing update message from the NAS, determine, based on whether the billing update message carries the characteristic identifier, whether to perform delayed authentication on the account corresponding to the account identifier in the billing update message, the billing update message being generated and sent by the NAS based on the random message sending duration or the normal message sending duration;

[0059] The change instruction sending module is configured to send a change instruction to the NAS according to a result of the delayed authentication, so that the NAS controls the connection status of the account.

[0060] Optionally, the sending module is specifically configured to:

[0061] Identifying the type of the login device according to the type identifier;

[0062] If the type identification is successful, the rate that guarantees its basic application requirements is issued to the login device;

[0063] If the type identification is unsuccessful, the login device is determined to be an unknown device, and a preset rate is sent to the unknown device.

[0064] Optionally, the authentication module is specifically used to:

[0065] If the billing update message carries the characteristic identifier, performing the delayed authentication on the account corresponding to the account identifier in the billing update message;

[0066] If the billing update message does not carry the characteristic identifier, the billing update is performed on the account corresponding to the account identifier in the billing update message without performing the delayed authentication.

[0067] Optionally, the sending change instruction module is specifically configured to:

[0068] If the account information and the user credentials are correctly compared, determining that the account has passed the delayed authentication;

[0069] When the account passes the delayed authentication, a change instruction representing precise authorization is sent to the NAS;

[0070] If the comparison between the account information and the user credentials is incorrect, determining that the account has failed the delayed authentication;

[0071] If the account fails the delayed authentication, a change instruction for disconnecting the account is sent to the NAS.

[0072] In a fifth aspect, a broadband authentication control device is provided, wherein the broadband authentication control device is applied to a NAS, and the broadband authentication control device includes:

[0073] An authorization instruction receiving module is configured to receive a restricted authorization instruction from a RADIUS server. The restricted authorization instruction is issued by the RADIUS server after the RADIUS server directly authenticates and restricts authorization of the account initiating the authentication request when determining that an authentication storm has occurred. The service parameters of the restricted authorization instruction include: account identifier, feature flag, random offline duration, and random message sending duration;

[0074] an update message sending module, configured to send an accounting update message to the RADIUS server according to the random message sending time period, when the random message sending time period is reached, the accounting update message carrying the account identifier and the feature flag; or

[0075] According to a normal message sending time length, when the normal message sending time length is reached, sending an accounting update message to the RADIUS server, where the accounting update message carries the account identifier;

[0076] a change instruction receiving module, configured to receive a change instruction from the RADIUS server, wherein the change instruction is generated and sent by the RADIUS server according to a result of delayed authentication;

[0077] An instruction control module, configured to determine, based on the change instruction, whether to disconnect the account to control the account to go offline or to control the account to remain connected;

[0078] The duration control module is used to determine whether to disconnect the account according to the random offline duration when the change instruction is not received, so as to control the account to go offline or control the account to remain connected.

[0079] Optionally, the instruction control module is specifically used to:

[0080] If the change instruction represents precise authorization, determining not to disconnect the account so as to control the account to remain connected, the change instruction is sent by the RADIUS server when the account information and the user credentials corresponding to the account identifier in the database are correctly compared;

[0081] If the change instruction indicates disconnecting the account connection, it is determined to disconnect the account connection to control the account offline. The change instruction is sent by the RADIUS server when the account information and the user credentials corresponding to the account identifier in the database are incorrectly compared.

[0082] Optionally, the instruction control module is further specifically configured to:

[0083] The business parameters of the restricted authorization instruction corresponding to the account are changed through the CoA protocol, and the business parameters of the restricted authorization instruction corresponding to the account are modified to the business parameters corresponding to the normal authorization instruction, so as to control the account to maintain the connection.

[0084] Optionally, the instruction control module is further specifically configured to:

[0085] The business parameters of the restriction authorization instruction corresponding to the account are changed through the DM protocol, and the business parameters of the restriction authorization instruction corresponding to the account are modified to the business parameters corresponding to the disconnection instruction to control the account to go offline.

[0086] Optionally, the duration control module is specifically configured to:

[0087] If the change instruction is not received and the random offline duration corresponding to the account has not been reached, determine not to disconnect the account, so as to control the account to remain connected;

[0088] If the change instruction is not received and the random offline time period corresponding to the account is reached, it is determined to disconnect the account to control the account to go offline.

[0089] According to a sixth aspect, an electronic device is provided, including:

[0090] one or more processors; and

[0091] One or more machine-readable media having instructions stored thereon, which, when executed by the one or more processors, cause the electronic device to execute the broadband authentication control method as described in any one of the first aspects; or

[0092] When executed by the one or more processors, the electronic device executes the broadband authentication control method as described in any one of the second aspects.

[0093] This application has the following advantages:

[0094] In the present invention, when it is determined that an authentication storm has occurred, the account that initiated the authentication request is directly authenticated and authorized, and the authorization restriction instruction for each authenticated account is sent to the NAS; according to the type identifier of the login device in the authentication request, the corresponding rate is sent to the login device.

[0095] This approach eliminates the need to limit authentication speed, set up a large buffer, or discard authentication request messages that exceed processing capacity. It allows for rapid response to all authentication requests, shortening user connection wait times and improving user experience.

[0096] After direct authentication, when a billing update message is received from NAS, it is determined whether to perform delayed authentication on the account corresponding to the account identifier in the billing update message based on whether the billing update message carries a feature identifier; based on the result of the delayed authentication, a change instruction is sent to NAS to enable NAS to control the connection status of the account.

[0097] This approach delays authentication for accounts that are directly authenticated or have limited authorization, while also billing. This not only protects the operator's profitability but also disperses and delays the large number of transient authentication requests during authentication storms, ensuring efficient user connections. Because dial-up clients that respond to authentication will no longer automatically repeat their calls, IP authentication storms are prevented, duplicate authentication is prevented, and improved service quality is provided to users. BRIEF DESCRIPTION OF THE DRAWINGS

[0098] Various other advantages and benefits will become apparent to those skilled in the art upon reading the detailed description of the preferred embodiment below. The accompanying drawings are for illustration purposes only and are not to be considered as limiting the present invention. The same reference symbols are used throughout the drawings to represent the same components. In the drawings:

[0099] Figure 1 This is a flow chart of a broadband authentication control method according to an embodiment of the present invention;

[0100] Figure 2 is another flow chart of a broadband authentication control method according to an embodiment of the present invention;

[0101] Figure 3 This is an overview of the authentication and authorization flow chart in an embodiment of the present invention;

[0102] Figure 4 This is a block diagram of a broadband authentication control device according to an embodiment of the present invention;

[0103] Figure 5 This is another block diagram of a broadband authentication control device according to an embodiment of the present invention. DETAILED DESCRIPTION

[0104] In order to make the above-mentioned objects, features and advantages of the present invention more clearly understood, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain the present invention, are only part of the embodiments of the present invention, not all of the embodiments, and are not intended to limit the present invention.

[0105] The inventors discovered that in current broadband metropolitan area network environments, when faced with external authentication attacks or network device disconnections, the number of IP authentications can suddenly and dramatically increase. This can lead to overloads in the RADIUS, BRAS, vBRAS, or NAS authentication systems, increased authentication delays, and even unresponsive authentication. Furthermore, dial-up clients that fail to respond will automatically re-dial, further exacerbating the IP authentication storm and severely impacting user experience.

[0106] The inventors have further studied and found that there are currently two main methods to solve the above problems:

[0107] The first method is to set a limit on the authentication speed on the NAS side. When an authentication storm occurs, authentication request messages that exceed the processing speed are directly discarded.

[0108] The second method is to set a limit on the authentication speed or a large buffer area on the Radius server side in exchange for the time of response authentication.

[0109] Regardless of which of these solutions is used, in actual operations, especially on large networks, when authentication storms occur, the number of authentication requests is enormous. Simply discarding authentication request packets that exceed processing capacity will obviously result in a large number of authentication requests being discarded, preventing a large number of users from connecting to the network. The dial-up clients used by these users will then automatically repeat the dial-up process, further exacerbating the IP authentication storm and creating a vicious cycle. Furthermore, limiting the authentication speed will obviously lead to low authentication efficiency and long user wait times.

[0110] Setting a large cache area does not necessarily meet the needs of caching a large number of authentication requests. At the same time, the cache area has the risk of being disabled. Even if it is not enabled, a large number of authentication requests in the cache area still need to be authenticated and processed one by one, which is equivalent to limiting the authentication speed. It will also lead to problems such as low authentication efficiency and long user waiting time.

[0111] In response to the above problems, the inventors have creatively proposed the broadband authentication control method of the present invention after extensive research. The broadband authentication control method proposed in the present invention is explained and illustrated in detail below.

[0112] Reference Figure 1, shows a flow chart of a broadband authentication control method according to an embodiment of the present invention, the broadband authentication control method is applied to a RADIUS server, and the broadband authentication control method includes:

[0113] Step 101: When it is determined that an authentication storm has occurred, the account that initiated the authentication request is directly authenticated and authorized, and a restricted authorization instruction for each authenticated account is sent to the NAS. The business parameters of the restricted authorization instruction include: account identification, feature flag, random offline time, and random message sending time.

[0114] In embodiments of the present invention, a RADIUS server can determine whether an authentication storm is currently occurring using a variety of methods. For example, one method is as follows: the RADIUS server can check the queue length of authentication requests in the cache during any period of time, determine the growth value of authentication requests during that period, and thus determine the growth rate of authentication requests during that period. If the growth rate of authentication requests exceeds a certain threshold, an authentication storm is determined to have occurred. If the growth rate of authentication requests does not exceed the threshold, an authentication storm is determined not to have occurred, and authentication and authorization will continue in the normal manner.

[0115] If the RADIUS server determines that an authentication storm has occurred, all accounts that initiated authentication requests will be directly authenticated and authorized with restrictions. That is, the current normal authentication method will no longer be used. Instead, all accounts will be authenticated first, and then these accounts will be authorized, which is different from the current normal authorization method after normal authentication. This authorization method is also different from the normal authorization method after normal authentication. It sends a restricted authorization instruction to the NAS for each account that has passed authentication. The business parameters of this restricted authorization instruction are different from the current business parameters, including: account identification, feature flag, random offline time, and random message sending time. Among them, the account identification is a business parameter that must be present after normal authorization, while the feature flag, random offline time, and random message sending time are different from the business parameters after normal authorization.

[0116] Based on the above description, it can be seen that in the embodiment of the present invention, directly authenticating and approving the account that initiated the authentication request and restricting authorization specifically refers to:

[0117] The account information in the authentication request is not compared with the user credentials corresponding to the account identifier in the database. That is, the normal authentication method is not adopted. Instead, the characteristic flag, random offline time and random message sending time are directly added to the business parameters of the authorization instruction to form the business parameters of the restricted authorization instruction together with the account identifier.

[0118] Step 102: According to the type identifier of the login device in the authentication request, the corresponding rate is sent to the login device.

[0119] In an embodiment of the present invention, after direct authentication and special authorization, the RADIUS server may send a corresponding rate to the login device based on the type identifier of the login device in the authentication request. In a possible embodiment, this step specifically includes:

[0120] Step S1: Identify the type of login device according to the type identifier;

[0121] Step S2: If the type identification is successful, the rate that guarantees its basic application requirements is issued to the login device;

[0122] Step S3: If the type identification is unsuccessful, it is determined that the login device is an unknown device, and a preset rate is sent to the unknown device.

[0123] Authentication requests typically carry the device type identifier, but some may not. Therefore, the device type is first identified based on the device type identifier. After successful identification, the basic application rate requirements for different device types vary. For example, a Class 1 IPTV device has a basic application rate requirement of 100 Mbps, a Class 2 IPTV device has a basic application rate requirement of 50 Mbps, and a Class 1 optical modem has a basic application rate requirement of 20 Mbps. Therefore, based on the device type, the RADIUS server sends a guaranteed basic application rate to the device.

[0124] If the RADIUS server cannot identify the type of the login device, it determines that the login device is an unknown device and sends a preset rate to the unknown device. The preset rate is a set lower rate.

[0125] Step 103: When receiving a billing update message from the NAS, determine whether to delay authentication of the account corresponding to the account identifier in the billing update message based on whether the billing update message carries a characteristic identifier. The billing update message is generated and sent by the NAS based on the random message sending duration or the normal message sending duration.

[0126] According to the general process, after an account logs in to the device and the network connection is successful, billing will begin. The NAS or similar devices with NAS functions will periodically send billing update messages to the RADIUS server according to the set time. After receiving this message, the RADIUS server will update the billing of the account corresponding to the account identifier in the message.

[0127] If it is a normally authenticated account, the NAS will periodically send the accounting update message corresponding to the normally authenticated account to the RADIUS server according to the pre-set normal message sending time, for example, 600 seconds. The accounting update message will not carry the feature identifier because the service parameters corresponding to the normally authenticated account do not have a feature identifier.

[0128] If the account is specially authorized during the authentication storm, the NAS will send the accounting update message corresponding to the specially authorized account to the RADIUS server periodically according to the random message sending time during the special authorization, for example: 30 minutes. The accounting update message will carry the feature identifier because the service parameters corresponding to the account have the feature identifier.

[0129] Based on the above description, the NAS can generate different accounting update messages based on the random message sending duration or the normal message sending duration. The RADIUS server receives the messages in the following ways:

[0130] If the billing update message carries a characteristic identifier, then the account corresponding to the account identifier in the billing update message is authenticated with delay;

[0131] If the billing update message does not carry the characteristic identifier, the billing update is performed on the account corresponding to the account identifier in the billing update message without delaying the authentication.

[0132] This is because accounts with signature identifiers are directly authenticated with restricted authorization. This ensures that users are prioritized for network access during authentication storms, improving user experience. However, whether a user can connect to the network depends on factors such as unpaid bills or blacklisted users. Therefore, the RADIUS server subsequently performs delayed authentication for the account. Upon receiving a billing update message, the RADIUS server performs a normal authentication process for the restricted authorization account, rather than performing the normal authentication process upon receiving the initial authentication request. This is known as delayed authentication. This essentially distributes the large number of authentication requests received during an authentication storm over time, prioritizing user connection. Subsequent delayed authentication determines whether the user can continue to connect to the network, thus mitigating the authentication storm. Once the authentication storm subsides, normal processing can be resumed.

[0133] That is, the delayed authentication of the account corresponding to the account identifier in the billing update message specifically includes:

[0134] Step T1: extract the account information corresponding to the account identifier;

[0135] Step T2: Obtain the user credentials corresponding to the account identifier in the database;

[0136] Step T3: Compare the account information and user credentials.

[0137] The above steps T1 to T3 are equivalent to a normal authentication of the account with restricted authorization.

[0138] Step 104: Send a change instruction to the NAS based on the result of the delayed authentication, so that the NAS controls the connection status of the account.

[0139] As described in step 103 above, the RADIUS server subsequently performs delayed authentication on the account with limited authorization, and performs a normal authentication on the account with limited authorization according to the normal authentication process when receiving the accounting update message. Based on the result of this delayed authentication, the RADIUS server sends a change instruction to the NAS so that the NAS controls the connection status of the account, whether it can continue to connect to the network or not. Specifically:

[0140] If the account information and user credentials are correctly compared, the account is determined to have passed the delayed authentication; if the account has passed the delayed authentication, the RADIUS server sends a change instruction indicating accurate authorization to the NAS.

[0141] If the comparison between the account information and the user credentials is incorrect, it is determined that the account has failed the delayed authentication; if the account has failed the delayed authentication, the RADIUS server sends a change instruction to the NAS indicating that the account connection is disconnected.

[0142] In the embodiment of the present invention, since the RADIUS server side adopts a method different from the current method for solving a large number of authentication requests when an authentication storm occurs, the corresponding NAS side also needs to adopt a broadband authentication control method different from the current method. Figure 2 The broadband authentication control method is applied to NAS, and the broadband authentication control method includes:

[0143] Step 201: Receive a restricted authorization instruction from the RADIUS server. The restricted authorization instruction is issued by the RADIUS server after the RADIUS server determines that an authentication storm has occurred and directly authenticates and restricts the authorization of the account that initiated the authentication request. The business parameters of the restricted authorization instruction include: account ID, feature flag, random offline duration, and random message sending duration.

[0144] Corresponding to the aforementioned step 101, when the RADIUS server determines that an authentication storm has occurred, it directly authenticates the account that initiated the authentication request and restricts authorization. The business parameters of the authorization restriction instruction include: account identification, feature flag, random offline time, and random message sending time, which will be received by the NAS.

[0145] Step 202: Based on the random message sending duration, when the random message sending duration is reached, a billing update message is sent to the RADIUS server, where the billing update message carries the account identifier and the characteristic flag; or based on the normal message sending duration, when the normal message sending duration is reached, a billing update message is sent to the RADIUS server, where the billing update message carries the account identifier.

[0146] Corresponding to the above explanations and instructions, NAS will send a billing update message to the RADIUS server based on the normal message sending time. When the normal message sending time is reached, it will also send a billing update message to the RADIUS server based on the random message sending time. When the random message sending time is reached, the NAS will send a billing update message to the RADIUS server. The difference is that the billing update message generated based on the random message sending time carries the account identifier and the feature flag; while the billing update message generated based on the normal message sending time only carries the account identifier, without the feature flag.

[0147] Step 203: Receive a change instruction from the RADIUS server. The change instruction is generated and sent by the RADIUS server according to the result of the delayed authentication.

[0148] Corresponding to the explanation and description of step 104, the RADIUS server performs delayed authentication on the restricted authorization account and sends a change instruction to the NAS according to the delayed authentication result.

[0149] Step 204: Determine whether to disconnect the account according to the change instruction to control the account to go offline or to control the account to remain connected.

[0150] After receiving the change instruction sent by the RADIUS server, the NAS determines whether to disconnect the account according to the change instruction to control the account to go offline or control the account to remain connected.

[0151] Specifically, as described in the aforementioned step 104, there are two types of change instructions: one type represents precise authorization, and the other type represents disconnection of an account.

[0152] If the change instruction represents precise authorization, the NAS determines not to disconnect the account connection to control the account to remain connected. The change instruction representing precise authorization is sent by the RADIUS server when the account information and the user credentials corresponding to the account identifier in the database are correctly compared. In one possible embodiment, precise authorization to achieve the goal of controlling the account connection to remain connected without disconnecting the account may include:

[0153] The CoA protocol changes the business parameters of the restricted authorization instruction corresponding to the account, modifying the business parameters of the restricted authorization instruction corresponding to the account to the business parameters of the normal authorization instruction, so as to control the account to maintain the connection. In other words, the CoA protocol silently modifies the business parameters of the restricted authorization instruction to the business parameters of the normal authorization instruction. This is equivalent to the restricted authorization account being converted into a normal authorized account after normal authentication, and the user can continue to maintain the network connection. This further improves the user experience without having to disconnect from the network and then reconnect to the network.

[0154] If the change instruction indicates disconnecting the account, the NAS determines to disconnect the account to control the account offline. The change instruction indicating disconnecting the account is sent by the RADIUS server when the account information and the user credentials corresponding to the account identifier in the database are incorrect. In one possible embodiment, disconnecting the account to achieve the purpose of disconnecting the account and controlling the account offline may include:

[0155] By changing the service parameters of the restricted authorization instruction corresponding to the account through the DM protocol, the service parameters of the restricted authorization instruction corresponding to the account are modified to the service parameters of the disconnection instruction to control the account offline. In other words, by modifying the service parameters of the restricted authorization instruction through the DM protocol to the service parameters of the disconnection instruction, the account with restricted authorization is kicked offline, and the user can no longer maintain network connection, thus avoiding losses to the operator and stopping losses in time.

[0156] Step 205: If no change instruction is received, determine whether to disconnect the account according to the random offline duration to control the account to go offline or to control the account to remain connected.

[0157] In the embodiment of the present invention, since the account with restricted authorization corresponds to a random offline time, the purpose of setting the random offline time is to allow the user to automatically log off after the corresponding offline time is up. Generally, this random offline time can be set to be longer and more dispersed to ensure that within the random offline time, the RADIUS server performs delayed authentication on all directly authenticated accounts. For example: when an authentication storm occurs, there are 100,000 authentication requests. The accounts corresponding to these 100,000 authentication requests are randomly distributed to log off within 2 hours to ensure that each account undergoes delayed authentication within its corresponding offline time. If it passes, the network connection is maintained; if it fails, the network connection is disconnected.

[0158] Considering the interests of operators, if the authentication storm is not successfully handled for a long time, users will be disconnected to protect the interests of operators. Moreover, since users have been connected to the network for a while and only some users are disconnected, rather than all users, user complaints and other issues can be reduced.

[0159] Through the above method, the RADIUS server and NAS work together to effectively cope with authentication storms, ensure the efficiency of user connections, quickly respond to all authentication requests, shorten user connection waiting time, improve user experience, and at the same time protect the normal interests of operators.

[0160] In one possible embodiment, the service parameters of the restricted authorization instruction in the broadband authentication control method of the present invention include: characteristic flag, random offline duration, and random message sending duration, which can be implemented in the following manner:

[0161] Parameter Class: 25 = "Overflow", where "Overflow" is a characteristic identifier. If the parameter corresponding to an account contains "Overflow", it indicates that the account is a restricted authorization account.

[0162] Parameter Session-Timeout: 27 = 600 + random(). This parameter corresponds to the random offline duration. The random value can be a number of seconds from 0 to 2 hours.

[0163] Parameter Acct-Interim-Interval: 85 = 1800 + random(). This parameter corresponds to the random message sending interval. The random value can be 0 to 3600 seconds. In this way, the NAS will send accounting update messages to the RADIUS server between 0.5 and 1.5 hours.

[0164] The above steps 101 to 104 and 201 to 205 can be summarized as follows: Figure 3 The authentication and authorization flow chart shown in the figure shows that the user dials up first, and the message buffer receives the authentication request. It first performs a basic blacklist check. If the user is on the blacklist, the authentication request is directly discarded. If the user is not on the blacklist, the next buffer is entered to determine whether an authentication storm has occurred.

[0165] The controllability of the capacity is used as the judgment standard. If the capacity is controllable, the normal authentication process is carried out according to the normal process: hash record, whether to hash the record again for 3 seconds, etc. For details, please refer to the existing authentication process and will not be repeated here.

[0166] If the capacity exceeds the threshold, it is considered an authentication storm, and authorization is directly restricted and passed. The business parameters corresponding to the restricted authorization instruction are set: 25 (Class), 27 (Session-Timeout), 85 (Acct-Interim-Interval), and sent to the NAS after setting.

[0167] The NAS generates an accounting update message based on parameter 85 and sends it to the RADIUS server. After receiving the message, the RADIUS server determines whether to perform delayed authentication based on the presence of parameter 25, and sends a change instruction to the NAS based on the result of the delayed authentication. The NAS controls the user to maintain or disconnect the network connection according to the change instruction.

[0168] Based on the above broadband authentication control method, an embodiment of the present invention further provides a broadband authentication control method, which is applied to a broadband system, the broadband system including: a RADIUS server and a NAS, the broadband authentication control method including:

[0169] Step V1: If an authentication storm is detected, the RADIUS server directly authenticates the account that initiated the authentication request and restricts authorization. It then sends a restricted authorization instruction to the NAS for each authenticated account. The service parameters of the restricted authorization instruction include: account ID, feature flag, random offline duration, and random message sending duration.

[0170] The specific method of step V1 can refer to the explanation and description of the aforementioned step 101 and will not be repeated here.

[0171] Step V2: The RADIUS server sends a corresponding rate to the login device according to the type identifier of the login device in the authentication request.

[0172] The specific method of step V2 can refer to the explanation and description of the aforementioned step 102 and will not be repeated here.

[0173] Step V3: The NAS receives the restricted authorization instruction and, based on the random message sending time, sends an accounting update message to the RADIUS server when the random message sending time is reached. The accounting update message carries the account identifier and the characteristic flag; or, based on the normal message sending time, sends an accounting update message to the RADIUS server when the normal message sending time is reached. The accounting update message carries the account identifier.

[0174] The specific method of step V3 can refer to the explanation and description of the aforementioned step 202 and will not be repeated here.

[0175] Step V4: When the RADIUS server receives the accounting update message, it determines whether to perform delayed authentication on the account corresponding to the account identifier in the accounting update message according to whether the accounting update message carries the feature identifier.

[0176] The specific method of step V4 can refer to the explanation and description of the aforementioned step 103 and will not be repeated here.

[0177] Step V5: The RADIUS server sends a change instruction to the NAS based on the result of the delayed authentication.

[0178] The specific method of step V5 can refer to the explanation and description of the aforementioned step 104 and will not be repeated here.

[0179] Step V6: The NAS receives the change instruction and determines whether to disconnect the account based on the change instruction to control the account to go offline or to control the account to remain connected.

[0180] The specific method of step V6 can refer to the explanation and description of the above steps 203 to 204, and will not be repeated here.

[0181] Step V7: If the NAS does not receive a change instruction, it determines whether to disconnect the account based on the random offline duration to control the account offline or to control the account to remain connected.

[0182] The specific method of step V7 can refer to the explanation and description of the aforementioned step 205 and will not be repeated here.

[0183] Based on the above broadband authentication control method, the embodiment of the present invention also provides a broadband authentication control device, which is applied to a RADIUS server. Figure 4 , the broadband authentication control device includes:

[0184] The authentication and authorization module 410 is configured to directly authenticate and restrict authorization to the account initiating the authentication request if an authentication storm is detected, and to send a restricted authorization instruction to the NAS for each authenticated account. The service parameters of the restricted authorization instruction include: account identification, feature flag, random offline duration, and random message sending duration;

[0185] The sending module 420 is configured to send a corresponding rate to the login device according to the type identifier of the login device in the authentication request;

[0186] an authentication module 430 configured to, upon receiving a billing update message from the NAS, determine, based on whether the billing update message carries the characteristic identifier, whether to perform delayed authentication on the account corresponding to the account identifier in the billing update message, the billing update message being generated and sent by the NAS based on the random message sending duration or the normal message sending duration;

[0187] The change instruction sending module 440 is configured to send a change instruction to the NAS according to the result of the delayed authentication, so that the NAS controls the connection status of the account.

[0188] Optionally, the sending module 420 is specifically configured to:

[0189] Identifying the type of the login device according to the type identifier;

[0190] If the type identification is successful, the rate that guarantees its basic application requirements is issued to the login device;

[0191] If the type identification is unsuccessful, the login device is determined to be an unknown device, and a preset rate is sent to the unknown device.

[0192] Optionally, the authentication module 430 is specifically configured to:

[0193] If the billing update message carries the characteristic identifier, performing the delayed authentication on the account corresponding to the account identifier in the billing update message;

[0194] If the billing update message does not carry the characteristic identifier, the billing update is performed on the account corresponding to the account identifier in the billing update message without performing the delayed authentication.

[0195] Optionally, the sending change instruction module 440 is specifically configured to:

[0196] If the account information and the user credentials are correctly compared, determining that the account has passed the delayed authentication;

[0197] When the account passes the delayed authentication, a change instruction representing precise authorization is sent to the NAS;

[0198] If the comparison between the account information and the user credentials is incorrect, determining that the account has failed the delayed authentication;

[0199] If the account fails the delayed authentication, a change instruction for disconnecting the account is sent to the NAS.

[0200] Based on the above broadband authentication control method, the embodiment of the present invention further provides a broadband authentication control device, which is applied to NAS. Figure 5 , the broadband authentication control device includes:.

[0201] The authorization instruction receiving module 510 is configured to receive a restricted authorization instruction from a RADIUS server. The restricted authorization instruction is issued by the RADIUS server after the RADIUS server directly authenticates and restricts authorization to the account initiating the authentication request when determining that an authentication storm has occurred. The service parameters of the restricted authorization instruction include: account identifier, feature flag, random offline duration, and random message sending duration.

[0202] an update message sending module 520 configured to send an accounting update message to the RADIUS server based on the random message sending time period, when the random message sending time period is reached, the accounting update message carrying the account identifier and the characteristic flag; or to send an accounting update message to the RADIUS server based on the normal message sending time period 530, when the normal message sending time period is reached, the accounting update message carrying the account identifier;

[0203] a change instruction receiving module 530, configured to receive a change instruction from the RADIUS server, wherein the change instruction is generated and sent by the RADIUS server according to a result of delayed authentication;

[0204] The instruction control module 540 is used to determine whether to disconnect the account according to the change instruction to control the account to go offline or control the account to remain connected;

[0205] The duration control module 550 is further configured to determine whether to disconnect the account based on the random offline duration when the change instruction is not received, so as to control the account to go offline or to control the account to remain connected.

[0206] Optionally, the instruction control module 540 is specifically configured to:

[0207] If the change instruction represents precise authorization, determining not to disconnect the account so as to control the account to remain connected, the change instruction is sent by the RADIUS server when the account information and the user credentials corresponding to the account identifier in the database are correctly compared;

[0208] If the change instruction indicates disconnecting the account connection, it is determined to disconnect the account connection to control the account offline. The change instruction is sent by the RADIUS server when the account information and the user credentials corresponding to the account identifier in the database are incorrectly compared.

[0209] Optionally, the instruction control module 540 is further specifically configured to:

[0210] The business parameters of the restricted authorization instruction corresponding to the account are changed through the CoA protocol, and the business parameters of the restricted authorization instruction corresponding to the account are modified to the business parameters corresponding to the normal authorization instruction, so as to control the account to maintain the connection.

[0211] Optionally, the instruction control module 540 is further specifically configured to:

[0212] The business parameters of the restriction authorization instruction corresponding to the account are changed through the DM protocol, and the business parameters of the restriction authorization instruction corresponding to the account are modified to the business parameters corresponding to the disconnection instruction to control the account to go offline.

[0213] Optionally, the duration control module 550 is specifically configured to:

[0214] If the change instruction is not received and the random offline duration corresponding to the account has not been reached, determine not to disconnect the account, so as to control the account to remain connected;

[0215] If the change instruction is not received and the random offline time period corresponding to the account is reached, it is determined to disconnect the account to control the account to go offline.

[0216] Based on the above broadband authentication control method, an embodiment of the present invention further provides an electronic device, including:

[0217] one or more processors; and

[0218] One or more machine-readable media having instructions stored thereon, which, when executed by the one or more processors, cause the electronic device to execute the broadband authentication control method as described in any one of steps 101 to 104; or

[0219] When executed by the one or more processors, the electronic device executes the broadband authentication control method as described in any one of steps 201 to 205.

[0220] Through the above embodiments, the broadband authentication control method of the present invention, when it is determined that an authentication storm has occurred, directly authenticates and limits the authorization of the account that initiated the authentication request, and sends the restricted authorization instruction of each authenticated account to the NAS; according to the type identifier of the login device in the authentication request, the corresponding rate is sent to the login device.

[0221] This approach eliminates the need to limit authentication speed, set up a large buffer, or discard authentication request messages that exceed processing capacity. It allows for rapid response to all authentication requests, shortening user connection wait times and improving user experience.

[0222] After direct authentication, when a billing update message is received from NAS, it is determined whether to perform delayed authentication on the account corresponding to the account identifier in the billing update message based on whether the billing update message carries a feature identifier; based on the result of the delayed authentication, a change instruction is sent to NAS to enable NAS to control the connection status of the account.

[0223] This approach delays authentication for accounts that are directly authenticated or have limited authorization, while also billing. This not only protects the operator's profitability but also disperses and delays the large number of transient authentication requests during authentication storms, ensuring efficient user connections. Because dial-up clients that respond to authentication will no longer automatically repeat their calls, IP authentication storms are prevented, duplicate authentication is prevented, and improved service quality is provided to users.

[0224] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they become aware of the basic creative concepts. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present invention.

[0225] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that includes a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or terminal device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or terminal device that includes the element.

[0226] The technical solutions provided by the embodiments of the present invention are introduced in detail above. Specific examples are used herein to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core ideas. At the same time, for those skilled in the art, according to the ideas of the present invention, there may be changes in the specific implementation methods and application scopes. In summary, the contents of this specification should not be understood as limiting the present invention.

Claims

1. A broadband authentication control method, characterized in that: The broadband authentication control method is applied to a RADIUS server, and the broadband authentication control method includes: If an authentication storm is detected, the account initiating the authentication request is directly authenticated and authorization is restricted. A restricted authorization instruction for each authenticated account is sent to the NAS. The service parameters of the restricted authorization instruction include: account ID, feature ID, random offline duration, and random message sending duration. According to the type identifier of the login device in the authentication request, the corresponding rate is issued to the login device; upon receiving a billing update message from the NAS, determining, based on whether the billing update message carries the characteristic identifier, whether to perform delayed authentication on the account corresponding to the account identifier in the billing update message, the billing update message being generated and sent by the NAS based on the random message sending duration or the normal message sending duration; According to the result of the delayed authentication, a change instruction is sent to the NAS, so that the NAS controls the connection status of the account.

2. The broadband authentication control method according to claim 1, characterized in that: Directly authenticating and restricting authorization for the account that initiated the authentication request means: Without comparing the account information in the authentication request with the user credentials corresponding to the account identifier in the database, the feature identifier, the random offline duration, and the random message sending duration are directly added to the business parameters of the authorization instruction to form the business parameters of the restricted authorization instruction together with the account identifier.

3. The broadband authentication control method according to claim 1, wherein: According to the type identifier of the login device in the authentication request, a corresponding rate is issued to the login device, including: Identifying the type of the login device according to the type identifier; If the type identification is successful, the rate that guarantees its basic application requirements is issued to the login device; If the type identification is unsuccessful, the login device is determined to be an unknown device, and a preset rate is sent to the unknown device.

4. The broadband authentication control method according to claim 1, wherein: Determining whether to perform delayed authentication on an account corresponding to the account identifier in the billing update message according to whether the feature identifier is carried in the billing update message includes: If the billing update message carries the characteristic identifier, performing the delayed authentication on the account corresponding to the account identifier in the billing update message; If the billing update message does not carry the characteristic identifier, the billing update is performed on the account corresponding to the account identifier in the billing update message without performing the delayed authentication.

5. The broadband authentication control method according to claim 4, characterized in that: Performing the delayed authentication on the account corresponding to the account identifier in the billing update message includes: Extracting account information corresponding to the account identifier; Obtain the user credentials corresponding to the account identifier in the database; comparing the account information with the user credentials; Sending a change instruction to the NAS according to a result of the delayed authentication includes: If the account information and the user credentials are correctly compared, determining that the account has passed the delayed authentication; When the account passes the delayed authentication, a change instruction representing precise authorization is sent to the NAS; If the comparison between the account information and the user credentials is incorrect, determining that the account has failed the delayed authentication; If the account fails the delayed authentication, a change instruction for disconnecting the account is sent to the NAS.

6. A broadband authentication control method, characterized in that: The broadband authentication control method is applied to NAS, and the broadband authentication control method includes: Receiving a restricted authorization instruction from a RADIUS server, wherein the restricted authorization instruction is issued by the RADIUS server after the RADIUS server directly authenticates and restricts authorization for the account initiating the authentication request when determining that an authentication storm has occurred. The service parameters of the restricted authorization instruction include: account identifier, feature identifier, random offline duration, and random message sending duration; According to the random message sending time length, when the random message sending time length is reached, sending an accounting update message to the RADIUS server, where the accounting update message carries the account identifier and the feature identifier; or According to a normal message sending time length, when the normal message sending time length is reached, sending an accounting update message to the RADIUS server, where the accounting update message carries the account identifier; receiving a change instruction from the RADIUS server, where the change instruction is generated and sent by the RADIUS server according to a result of delayed authentication; Determining, according to the change instruction, whether to disconnect the account to control the account to go offline or to control the account to remain connected; In the case that the change instruction is not received, whether to disconnect the account is determined according to the random offline duration, so as to control the account to go offline or control the account to remain connected.

7. The broadband authentication control method according to claim 6, characterized in that: Determining, according to the change instruction, whether to disconnect the account to control the account to go offline or to control the account to remain connected, includes: If the change instruction represents precise authorization, determining not to disconnect the account so as to control the account to remain connected, the change instruction is sent by the RADIUS server when the account information and the user credentials corresponding to the account identifier in the database are correctly compared; If the change instruction indicates disconnecting the account connection, it is determined to disconnect the account connection to control the account offline. The change instruction is sent by the RADIUS server when the account information and the user credentials corresponding to the account identifier in the database are incorrectly compared.

8. The broadband authentication control method according to claim 7, characterized in that: Determining not to disconnect the account so as to control the account to remain connected includes: The business parameters of the restricted authorization instruction corresponding to the account are changed through the CoA protocol, and the business parameters of the restricted authorization instruction corresponding to the account are modified to the business parameters corresponding to the normal authorization instruction, so as to control the account to maintain the connection.

9. The broadband authentication control method according to claim 7, characterized in that: Determining to disconnect the account to control the account offline includes: The business parameters of the restriction authorization instruction corresponding to the account are changed through the DM protocol, and the business parameters of the restriction authorization instruction corresponding to the account are modified to the business parameters corresponding to the disconnection instruction to control the account to go offline.

10. The broadband authentication control method according to claim 7, characterized in that: In the case where the change instruction is not received, determining whether to disconnect the account according to the random offline duration to control the account to go offline or control the account to remain connected includes: If the change instruction is not received and the random offline duration corresponding to the account has not been reached, determine not to disconnect the account, so as to control the account to remain connected; If the change instruction is not received and the random offline time period corresponding to the account is reached, it is determined to disconnect the account to control the account to go offline.

11. A broadband authentication control method, characterized in that: The broadband authentication control method is applied to a broadband system, wherein the broadband system includes a RADIUS server and a NAS. The broadband authentication control method includes: If an authentication storm is detected, the RADIUS server directly authenticates the account that initiated the authentication request and restricts authorization. The server then sends a restricted authorization instruction for each authenticated account to the NAS. The service parameters of the restricted authorization instruction include: account ID, feature ID, random offline duration, and random message sending duration. The RADIUS server sends a corresponding rate to the login device according to the type identifier of the login device in the authentication request; The NAS receives the restricted authorization instruction and, based on the random message sending time period, sends an accounting update message to the RADIUS server when the random message sending time period is reached, the accounting update message carrying the account identifier and the feature identifier; or The NAS sends an accounting update message to the RADIUS server according to a normal message sending time duration, when the normal message sending time duration is reached, where the accounting update message carries the account identifier; When the RADIUS server receives the accounting update message, determining whether to perform delayed authentication on the account corresponding to the account identifier in the accounting update message according to whether the accounting update message carries the feature identifier; The RADIUS server sends a change instruction to the NAS according to a result of the delayed authentication; The NAS receives the change instruction and determines, based on the change instruction, whether to disconnect the account to control the account to go offline or to control the account to remain connected; When the NAS does not receive the change instruction, it determines whether to disconnect the account according to the random offline duration to control the account to go offline or control the account to remain connected.

12. A broadband authentication control device, characterized in that: The broadband authentication control device is applied to a RADIUS server, and the broadband authentication control device includes: The authentication and authorization module is used to directly authenticate and restrict authorization for the account initiating the authentication request when an authentication storm is determined to have occurred, and send a restricted authorization instruction for each authenticated account to the NAS. The service parameters of the restricted authorization instruction include: account ID, feature ID, random offline duration, and random message sending duration; A sending module, configured to send a corresponding rate to the login device according to the type identifier of the login device in the authentication request; an authentication module, configured to, upon receiving a billing update message from the NAS, determine, based on whether the billing update message carries the characteristic identifier, whether to perform delayed authentication on the account corresponding to the account identifier in the billing update message, the billing update message being generated and sent by the NAS based on the random message sending duration or the normal message sending duration; The change instruction sending module is configured to send a change instruction to the NAS according to a result of the delayed authentication, so that the NAS controls the connection status of the account.

13. A broadband authentication control device, characterized in that: The broadband authentication control device is applied to NAS, and the broadband authentication control device includes: An authorization instruction receiving module is configured to receive a restricted authorization instruction from a RADIUS server. The restricted authorization instruction is issued by the RADIUS server after the RADIUS server directly authenticates and restricts authorization of the account initiating the authentication request when determining that an authentication storm has occurred. The service parameters of the restricted authorization instruction include: account identifier, feature identifier, random offline duration, and random message sending duration; a sending update message module, configured to send a billing update message to the RADIUS server according to the random message sending time period, when the random message sending time period is reached, the billing update message carrying the account identifier and the feature identifier; or According to a normal message sending time length, when the normal message sending time length is reached, sending an accounting update message to the RADIUS server, where the accounting update message carries the account identifier; a change instruction receiving module, configured to receive a change instruction from the RADIUS server, wherein the change instruction is generated and sent by the RADIUS server according to a result of delayed authentication; An instruction control module, configured to determine, based on the change instruction, whether to disconnect the account to control the account to go offline or to control the account to remain connected; The duration control module is used to determine whether to disconnect the account according to the random offline duration when the change instruction is not received, so as to control the account to go offline or control the account to remain connected.

14. An electronic device, characterized in that: include: one or more processors; and One or more machine-readable media having instructions stored thereon, which, when executed by the one or more processors, cause the electronic device to execute the broadband authentication control method according to any one of claims 1 to 5; or When executed by the one or more processors, the electronic device is caused to execute the broadband authentication control method according to any one of claims 6 to 10.

Citation Information

Patent Citations

  • Authentication and accounting method, device and system for local area network user, and network equipment

    CN102801538A

  • Method, device and system for processing authentication packet

    CN105553971A

  • Network configuration method and system

    CN110381521A