Access method and device
By temporarily allocating IP addresses and leases on BRAS devices, the problem of clients repeatedly making online requests during the authentication waiting process is solved, achieving resource conservation and improved user experience.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- NEW H3C TECH CO LTD
- Filing Date
- 2023-04-28
- Publication Date
- 2026-05-05
AI Technical Summary
When BRAS-level 802.1X authentication and IPoE Web authentication are deployed simultaneously on a BRAS device, the client repeatedly sends online requests while waiting for authentication, resulting in wasted communication resources and a poor user experience.
After receiving the client's online request, the device temporarily assigns a temporary IP address and lease, and receives a renewal request before the temporary lease expires, triggering the client to select the target authentication method and send the online request again.
This reduces the waste of communication resources, improves the user experience, and avoids the problem of clients being unable to access the target network in a timely manner.
Smart Images

Figure CN116436900B_ABST
Abstract
Description
Technical Field
[0001] This specification relates to the field of communication technology, and in particular to an access method and apparatus. Background Technology
[0002] BRAS (Broadband Remote Access Server) level 802.1x authentication is a technology that provides 802.1x (access control and authentication protocol) access authentication on BRAS devices. It uses 802.1x as an authentication method for IPoE (IP over Ethernet). On a BRAS, 802.1x and IPoE can work together to enable client access. Specifically, 802.1x is used for authentication and authorization, while IPoE is used for billing.
[0003] When both BRAS-level 802.1X authentication and IPoE Web authentication are deployed on a BRAS, if the BRAS device receives an online request from a client first, it will temporarily cache the request. It will then wait until it confirms that the client has not selected 802.1X authentication before processing the online request and assigning an IP address. Before the BRAS device begins processing the online request, the client does not receive an IP address, causing the client to repeatedly send online requests, resulting in wasted communication resources and a poor user experience. Summary of the Invention
[0004] To overcome the problems existing in related technologies, this specification provides an access method and device.
[0005] According to a first aspect of the embodiments of this specification, an access method is provided, applied to a device, the method comprising: receiving a first online request sent by a client; allocating a temporary IP address for the client in a first address pool according to the first online request, and configuring a temporary lease for the temporary IP address; sending a first online response to the client, the first online response including the temporary IP address and the temporary lease; receiving a renewal request sent by the client; and if the client selects a target access authentication method for authentication, sending a first renewal response to the client to trigger the client to send the first online request again.
[0006] According to a second aspect of the embodiments of this specification, an access method is provided, applied to a client, the method comprising: sending a first online request to a device, such that the device allocates a temporary IP address for the client in a first address pool according to the first online request, and configures a temporary lease for the temporary IP address; receiving a first online response sent by the device, the first online response including the temporary IP address and the temporary lease; sending a renewal request to the device before the temporary lease expires; receiving a first renewal response sent by the device; and sending the first online request to the device again according to the first renewal response.
[0007] According to a third aspect of the embodiments of this specification, a client access device is provided, applied to a device, the device comprising: a first receiving module, configured to receive a first online request sent by a client; a first allocation module, configured to allocate a temporary IP address to the client in a first address pool according to the first online request, and configure a temporary lease for the temporary IP address; a first sending module, configured to send a first online response to the client, the first online response including the temporary IP address and the temporary lease; a second receiving module, configured to receive a renewal request sent by the client; and a second sending module, configured to send a first renewal response to the client if the client does not select to authenticate using a target access authentication method, thereby triggering the client to resend the first online request.
[0008] According to a fourth aspect of the embodiments of this specification, a client access device is provided, applied to a client. The device includes: a third sending module, configured to send a first online request to a device, so that the device allocates a temporary IP address to the client in a first address pool according to the first online request and configures a temporary lease for the temporary IP address; a third receiving module, configured to receive a first online response sent by the device, the first online response including the temporary IP address and the temporary lease; a fourth sending module, configured to send a renewal request to the device when the temporary lease expires; a fourth receiving module, configured to receive a first renewal response sent by the device; and a fifth sending module, configured to send the first online request to the device again according to the first renewal response.
[0009] According to a fifth aspect of the embodiments of this specification, this disclosure provides a network device including a processor and a machine-readable storage medium storing machine-executable instructions that can be executed by the processor, the processor being prompted by the machine-executable instructions to perform the method provided in the first aspect of this disclosure.
[0010] In a sixth aspect, this disclosure provides a network device including a processor and a machine-readable storage medium storing machine-executable instructions that can be executed by the processor, the processor being prompted by the machine-executable instructions to perform the method provided in the second aspect of this disclosure.
[0011] The technical solutions provided in the embodiments of this specification may include the following beneficial effects:
[0012] In the embodiments described in this specification, upon receiving an online request from a client, the device can temporarily assign a temporary IP address and a temporary lease to the client. Therefore, after receiving the temporary IP address and temporary lease, the client will not repeatedly send online requests, reducing the waste of communication resources and improving the user experience.
[0013] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this specification. Attached Figure Description
[0014] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this specification and, together with the description, serve to explain the principles of this specification.
[0015] Figure 1 This is a schematic diagram of a system architecture illustrated in this specification according to an exemplary embodiment.
[0016] Figure 2 This is a flowchart illustrating an access method according to an exemplary embodiment of this specification.
[0017] Figure 3 This is a flowchart illustrating an access method according to an exemplary embodiment of this specification.
[0018] Figure 4 This is a block diagram illustrating an access device according to an exemplary embodiment of this specification.
[0019] Figure 5 This is a block diagram illustrating another access device according to an exemplary embodiment of this specification.
[0020] Figure 6 This is a schematic diagram of a network device illustrated in this specification according to an exemplary embodiment. Detailed Implementation
[0021] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numerals in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this specification. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this specification as detailed in the appended claims.
[0022] The terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to be limiting of this specification. The singular forms “a,” “the,” and “the” as used in this specification and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any and all possible combinations of one or more of the associated listed items.
[0023] It should be understood that although the terms first, second, third, etc., may be used in this specification to describe various information, this information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, without departing from the scope of this specification, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to determination."
[0024] The following combination Figure 1 The system architecture for which the access methods and devices can be applied in the embodiments of this specification will be described. It should be noted that the following are merely examples of system architectures, and the access methods and devices in the embodiments of this specification can also be used in other system architectures.
[0025] Figure 1 This is a schematic diagram of a system architecture illustrated in this specification according to an exemplary embodiment.
[0026] like Figure 1 As shown, the system architecture may include a client 110, a device 120, and an authentication server 130.
[0027] According to embodiments of this disclosure, client 110 may be a user terminal requesting access to the target network, and may be authenticated by device 120. Client 110 may have client software supporting 802.1X authentication installed.
[0028] According to embodiments of this disclosure, device 120 can be used to control network devices accessed by client 110, such as a BRAS (Broadband Remote Access Server). Device 120 is located between client 110 and authentication server 130, and can provide client 110 with a port (physical port or logical port) to access the target network, and can authenticate the connected client 110 through interaction with authentication server 130.
[0029] According to embodiments of this disclosure, the authentication server 130 can be used to authenticate, authorize, and account for the client 110. For example, it can be a RADIUS (Remote Authentication Dial-In User Service) server. The authentication server 130 can verify the legitimacy of the client 110 based on the client authentication information sent by the device 120, and notify the device 120 of the verification result, which then decides whether to allow the client 110 to access the system. According to another embodiment of this disclosure, the role of the authentication server 130 can also be replaced by the device 120, that is, the device 120 performs local authentication, authorization, and accounting for the client 110.
[0030] The access method described in the embodiments of this specification will now be explained in detail.
[0031] Figure 2 This is a flowchart illustrating an access method according to an exemplary embodiment of this specification.
[0032] like Figure 2 As shown, the access method may include steps 210 to 250. This access method may, for example, be executed by the device shown above.
[0033] In step 210, the first online request sent by the client is received.
[0034] According to embodiments of this disclosure, a first online request can be used to request access to a target network for a client. The target network can be, for example, a wide area network (WAN), a local area network (LAN), or a metropolitan area network (MAN), or any combination thereof. The first online request may, for example, include a DHCP online request.
[0035] In step 220, according to the first online request, a temporary IP address is allocated to the client in the first address pool, and a temporary lease is configured for the temporary IP address.
[0036] According to embodiments of this disclosure, the first address pool can be the address pool of the front domain. A client can enter the front domain within the lease period of a temporary lease based on a temporary IP address. The front domain can be the domain that the client can access before access authentication. The back domain can be the domain that the client can access after access authentication.
[0037] According to embodiments of this disclosure, the lease period of a temporary lease can be set according to actual needs. For example, a shorter lease period, such as 2 minutes, can be set for a temporary lease.
[0038] In step 230, a first online response is sent to the client. The first online response includes a temporary IP address and a temporary lease.
[0039] According to embodiments of this disclosure, the first online response can be a response to the aforementioned first online request. The first online response may include a temporary IP address and a temporary lease. The device can send the temporary IP address and temporary lease to the client via the first online response. The client can then enter the front domain based on the temporary IP address during the lease period.
[0040] In step 240, a renewal request is received from the client.
[0041] According to embodiments of this disclosure, before the temporary lease allocated to the client expires, the client can send a renewal request to the device to request an extension of the temporary lease period.
[0042] In step 250, if the client selects the target access authentication method for authentication, a first renewal response is sent to the client to trigger the client to send the first online request again.
[0043] According to embodiments of this disclosure, the first renewal response can be a response to a renewal request. When the client selects a target access authentication method for authentication, after receiving a first online request resent by the client, the device can authorize the client to access the target network based on the resent first online request and the authentication result of the target access authentication.
[0044] According to embodiments of this disclosure, the client can support multiple access authentication methods. One of these methods can be selected as the target access authentication method, while the others serve as candidate authentication methods. The client can choose whether to authenticate using the target access authentication method. If the client does not select the target access authentication method, a candidate access authentication method can be used for authentication. For example, the target access authentication method may include 802.1x authentication. Candidate access authentication methods may include IPoE Web authentication.
[0045] Some network topologies use wired 802.1X authentication due to historical reasons. However, with the growth of network scale and the widespread adoption of mobile smart terminals, there is a desire to upgrade the network without changing the existing internet access habits of 802.1X users. This requires meeting the new IPoE Web wireless access requirements while simplifying the network structure for easier management and maintenance. To address these hybrid networking needs, both 802.1X and IPoE Web authentication can be deployed simultaneously on the device.
[0046] Based on this, if the device first receives a DHCP (Dynamic Host Configuration Protocol) connection request from the client, it will temporarily cache the DHCP connection request and proactively notify clients supporting 802.1x authentication to perform 802.1x authentication first via EAP (Extensible Authentication Protocol). If the terminal does not perform 802.1x authentication, the BRAS device will wait for a certain period of time until the user continues to fail to perform 802.1x authentication before re-performing IPoE authentication. Subsequently, the user can authenticate and connect via IPoE Web.
[0047] Because the BRAS device needs to wait a certain amount of time before determining whether IPoE authentication can be performed (i.e., before starting to process DHCP connection requests and assign IP addresses to clients), the client will not receive an assigned IP address before the BRAS device begins processing the connection request. Therefore, it will repeatedly send DHCP connection requests, wasting communication resources. Furthermore, some clients will stop sending DHCP connection requests after multiple failed attempts to obtain an IP address. Other clients will increase the retransmission interval after failing to obtain an IP address through DHCP connection requests. Therefore, repeated attempts to send DHCP connection requests will cause the retransmission interval to become increasingly longer, preventing the client from connecting to the target network in a timely manner.
[0048] According to embodiments of this disclosure, upon receiving an online request from a client, the device can temporarily assign a temporary IP address and a temporary lease to the client. Therefore, after receiving the temporary IP address and temporary lease, the client will not repeatedly send online requests, reducing waste of communication resources and improving user experience. Additionally, it can prevent the client from being unable to access the target network in a timely manner.
[0049] Figure 3 This is a flowchart illustrating an access method according to an exemplary embodiment of this specification.
[0050] like Figure 3As shown, the access method may include steps 310 to 350. This access method may, for example, be executed by the client described above.
[0051] In step 310, a first online request is sent to the device.
[0052] According to embodiments of this disclosure, when a user wishes to access a target network, they can send a first online request to the device via a client to request online access to resources within the target network. The first online request may, for example, include a DHCP online request.
[0053] According to embodiments of this disclosure, after receiving a first online request, the device allocates a temporary IP address to the client from a first address pool and configures a temporary lease for the temporary IP address. The device can then send a first online response to the client, which may include the temporary IP address and the temporary lease.
[0054] In step 320, the first online response is sent by the receiving device.
[0055] According to embodiments of this disclosure, after receiving a first online response from the device, the client can parse the first online response to obtain a temporary IP address and a temporary lease. The client can then access the front domain based on the temporary IP address and the temporary lease.
[0056] In step 330, a renewal request is sent to the device before the temporary lease expires.
[0057] According to embodiments of this disclosure, the client can send a renewal request to the device at any time before the expiration of the temporary lease, requesting the device to renew the temporary lease. The client can send the renewal request proactively or according to instructions from the device.
[0058] In step 340, the first renewal response is sent by the receiving device.
[0059] According to embodiments of this disclosure, the client can also select an access authentication method for going online. The access authentication method may include a target access authentication method and candidate access authentication methods. For example, the target access authentication method may include 802.1x authentication. Candidate access authentication methods may include IPoE Web authentication. Therefore, after receiving a renewal request, if the client selects the target access authentication method for authentication, the device can send a first renewal response to the client, instructing the client to proceed with the online process corresponding to the target access authentication method.
[0060] In step 350, based on the first renewal response, a first online request is sent to the device again.
[0061] According to embodiments of this disclosure, after receiving a first online request resent by the client, the device can authorize the client to access the target network based on the resent first online request and the authentication result corresponding to the target access authentication method.
[0062] According to embodiments of this disclosure, the client can be authenticated using the target access authentication method by the device itself. Alternatively, the client can be authenticated using the target access authentication method by a device other than the device itself, and then the authentication result can be sent to the device. This other device may, for example, include the authentication server described above.
[0063] Optionally, after step 210, the device may also send a notification message to the client. This notification message can be used to prompt the client whether to select the target authentication method.
[0064] For example, the target authentication method can be 802.1x authentication. The device can proactively send a notification message via EAP (Extensible Authentication Protocol) to notify clients that support 802.1x to use the 802.1x authentication method.
[0065] Optionally, after step 230, the device may also send a forced update message to the client. The forced update message can be used to instruct the client to send a renewal request.
[0066] For example, a forced update message may include a FORCERENEW (RFC 3203) message. For devices using DHCPv4, after 802.1x authentication and going online, the device can proactively send a unicast FORCERENEW message to the client. Upon receiving this message, the client will send a renewal request to the device. Upon receiving the renewal request, the device can reply with a corresponding renewal response, thereby quickly triggering the client to resend the online request.
[0067] Optionally, the first renewal response can be used to indicate renewal failure. Based on this, after receiving the first renewal response, the client can resend the first online request according to the first renewal response. After receiving the resent first online request from the client, the device can allocate a target IP address for the client from the second address pool according to the resent first online request, and configure a target lease for the target IP address. The second address pool can be, for example, a different address pool than the first address pool, and the second address pool can correspond to the target authentication method. For example, the target authentication method can include 802.1x authentication, and the second address pool can be, for example, an address pool of the 802.1x authentication domain. Then, the device can send a second online response to the client, which can include the target IP address and the target lease. After receiving the second online response, the client can access the target network according to the target IP address and target lease in the second online response.
[0068] For example, in the case of DHCPv4 address allocation, the first renewal response may include a DHCP NAK message. For instance, in response to a renewal request sent by a client, the device may reply with a DHCP NAK message. Upon receiving the DHCP NAK message, the client will resend the online request to request an IP address. After receiving the resent online request, the device can allocate an IP address from a second address pool, configure a lease for that IP address, and make it available for client use.
[0069] For example, in the case of DHCPv6 address allocation, the first renewal response may include a reply message carrying a NoBinding status code. For instance, in response to a renewal request from a client, the device may reply with a reply message carrying a NoBinding status code. According to RFC 3315, upon receiving a NoBinding reply message, the client will resend a Request message. Optionally, the lease period of this reply message can be 0, allowing the client to immediately send a Request message upon receipt. If the Request message received by the device carries an address, the device may reply with a NotOnLink status code. According to RFC 3315, upon receiving a NotOnLink reply message, the client will resend a Request message without an address or resend a Solicit message to the device. Subsequently, upon receiving a Request or Solicit message, the device can allocate an IP address from a second address pool, configure a lease for that IP address, and make it available for client use. If the Request message received by the device does not carry an address, the device can allocate an IP address from the second address pool, configure a lease for that IP address, and make it available for client use.
[0070] Optionally, if the client fails to select a target access authentication method within a predetermined time period after receiving the first online request, the device can also perform candidate access authentication on the client. The predetermined time period can be set according to actual needs.
[0071] If the client passes the candidate access authentication, the device can configure a first lease for the temporary IP address. The lease term of the first lease can be set according to actual needs. For example, in this embodiment, the lease term of the first lease can be longer than the lease term of the temporary lease. Then, a second renewal response is sent to the client in response to the renewal request. The second renewal response may include the temporary IP address and the first lease. The client can receive the second renewal response from the device and then access the target network based on the temporary IP address and the first lease in the second renewal response.
[0072] Alternatively, if the client passes the candidate access authentication, the device can send a third renewal response to the client in response to the renewal request. This third renewal response can be used to prompt the client to resend the first access request. The device can receive the resent first access request from the client, allocate a formal IP address to the client from the first address pool based on the resent first online request, and configure a second lease for the formal IP address. The lease term of the second lease can be set according to actual needs. For example, the lease term of the second lease can be longer than the lease term of the temporary lease. Then, a third online response corresponding to the resent first online request is sent to the client, whereby the third online response includes the formal IP address and the second lease. The client can receive the third online response from the device and then access the target network based on the formal IP address and the target second lease in the third online response.
[0073] Corresponding to the embodiments of the foregoing methods, this specification also provides embodiments of the apparatus and the terminal to which it is applied.
[0074] Figure 4 This is a block diagram illustrating an access device according to an exemplary embodiment of this specification. Figure 4 As shown, this device can be applied, for example, to the device shown above. The device may include a first online request receiving module 410, a first allocation module 420, a first online response sending module 430, a second receiving module 440, and a second sending module 450.
[0075] The first online request receiving module 410 can be used to receive the first online request sent by the client.
[0076] The first allocation module 420 can be used to allocate a temporary IP address to the client in the first address pool according to the first online request, and configure a temporary lease for the temporary IP address.
[0077] The first online response sending module 430 can be used to send the first online response to the client. The first online response includes a temporary IP address and a temporary lease.
[0078] The second receiving module 440 can be used to receive renewal requests sent by the client.
[0079] The second sending module 450 can be used to send a first renewal response to the client if the client does not select to authenticate using the target access authentication method, so as to trigger the client to send the first online request again.
[0080] Optionally, the above apparatus may further include a notification sending module, used to send a notification message to the client after receiving the first online request, the notification message being used to prompt the client whether to select to authenticate using the target authentication method.
[0081] Optionally, the above apparatus may further include an update sending module, which, after sending a first online response to the client, sends a forced update message to the client, the forced update message being used to instruct the client to send a renewal request.
[0082] Optionally, the first renewal response can be used to indicate renewal failure. The above apparatus may further include a second online request receiving module, a second allocation module, and a second online response sending module. The second online request receiving module is used to receive the first online request resent by the client. The second allocation module is used to allocate a target IP address to the client from a second address pool based on the resent first online request, and configure a target lease for the target IP address. The second online response sending module is used to send a second online response to the client, the second online response including the target IP address and the target lease, so that the client can access the target network based on the target IP address and the target lease.
[0083] Optionally, the above apparatus may further include a candidate authentication module, a first configuration module, and a second renewal response sending module. The candidate authentication module can be used to perform candidate access authentication on the client if, within a predetermined time period after receiving the first online request, the client fails to select a target access authentication method for authentication. The first configuration module can be used to configure a first lease for the temporary IP address if the client passes the candidate access authentication. The second renewal response sending module can be used to send a second renewal response to the client in response to the renewal request. The second renewal response includes the temporary IP address and the first lease, enabling the client to access the target network based on the temporary IP address and the first lease.
[0084] Alternatively, the above apparatus may further include a candidate authentication module, a third renewal response sending module, a second online request receiving module, a second configuration module, and a third online response sending module. The third renewal response sending module can be used to send a third renewal response to the client in response to the renewal request if the client passes the candidate access authentication, so that the client can resend the first access request. The second online request receiving module can be used to receive the first access request resent by the client. The second configuration module can be used to allocate a formal IP address to the client from the first address pool based on the resent first online request, and configure a second lease for the formal IP address. The third online response sending module can be used to send a third online response to the client corresponding to the resent first online request, wherein the third online response includes the formal IP address and the second lease, so that the client accesses the target network based on the formal IP address and the target second lease.
[0085] Figure 5This is a block diagram illustrating another access device according to an exemplary embodiment of this specification. Figure 5 As shown, this device can be applied, for example, to the client described above. The device may include a first online request sending module 510, a first online response receiving module 520, a renewal request sending module 530, a first renewal response receiving module 540, and a first online request retransmission module 550.
[0086] The first online request sending module 510 can be used to send a first online request to the device so that the device can allocate a temporary IP address to the client in the first address pool according to the first online request and configure a temporary lease for the temporary IP address.
[0087] The first online response receiving module 520 can be used to receive the first online response sent by the device. The first online response includes a temporary IP address and a temporary lease.
[0088] The renewal request sending module 530 can be used to send a renewal request to the device when the temporary lease expires.
[0089] The first renewal response receiving module 540 can be used to receive the first renewal response sent by the device.
[0090] The first online request retransmission module 550 can be used to resend the first online request to the device based on the first renewal response.
[0091] Optionally, the above apparatus may further include a second renewal response receiving module, a second online request sending module, and a first access module. The second renewal response receiving module can be used to receive a second renewal response from the device, wherein the second renewal response indicates renewal failure. The second online request sending module can be used to send a second online request to the device based on the second renewal response, so that the device allocates a target IP address to the client in the second address pool and configures a target lease for the target IP address based on the second online request. The second online response receiving module can be used to receive a second online response from the device, wherein the second online response includes the target IP address and the target lease. The first access module can be used to access the target network based on the target IP address and the target lease.
[0092] Optionally, the above-mentioned apparatus may further include a third online response receiving module and a second access module. The third online response receiving module is used to receive a third online response from the device, wherein the third online response includes a temporary IP address and a first lease. The second access module is used to access the target network based on the temporary IP address and the first lease.
[0093] Alternatively, the above-described apparatus may further include a third online response receiving module and a third access module. The third online response receiving module can be used to receive a third online response from the device, wherein the third online response may include a formal IP address and a second lease. The third access module can be used to access the target network based on the formal IP address and the target second lease.
[0094] According to embodiments of this disclosure, by applying the access device provided in these embodiments, upon receiving an online request from a client, the device can temporarily allocate a temporary IP address and a temporary lease to the client. Therefore, after receiving the temporary IP address and temporary lease, the client will not repeatedly send online requests, reducing the waste of communication resources. Furthermore, it can prevent the client from being unable to access the target network in a timely manner.
[0095] Based on the same inventive concept, this disclosure also provides a network device. Figure 6 This is a schematic diagram illustrating a network device according to an exemplary embodiment of this specification. Figure 6 As shown, the network device may include a processor 610, a transceiver 620, and a machine-readable storage medium 630. The machine-readable storage medium 630 stores machine-executable instructions that can be executed by the processor 610. The processor 610 is prompted by the machine-executable instructions to execute the access method provided in the embodiments of this disclosure. (The foregoing...) Figure 4 , Figure 5 The access device shown can be adopted as follows: Figure 6 The hardware structure of the network device shown is implemented.
[0096] The aforementioned computer-readable storage medium 630 may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage device. Optionally, the computer-readable storage medium 630 may also be at least one storage device located remotely from the aforementioned processor 610.
[0097] The processor 610 mentioned above can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.
[0098] In this embodiment of the present disclosure, the processor 610 reads the machine-executable instructions stored in the machine-readable storage medium 630, and is prompted by the machine-executable instructions to enable the processor 610 itself and the transceiver 620 to execute the access method described in the foregoing embodiments of the present disclosure.
[0099] In addition, this disclosure provides a machine-readable storage medium 630 that stores machine-executable instructions. When called and executed by the processor 610, the machine-executable instructions cause the processor 610 itself and the transceiver 620 to execute the access method described in the foregoing embodiments of this disclosure.
[0100] The specific implementation process of the functions and roles of each module in the above device can be found in the implementation process of the corresponding steps in the above method, and will not be repeated here.
[0101] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to in the description of the method embodiments. The device embodiments described above are merely illustrative. The modules described as separate components may or may not be physically separate, and the components shown as modules may or may not be physical modules, that is, they may be located in one place or distributed across multiple network modules. Some or all of the modules can be selected to achieve the purpose of the solution in this specification according to actual needs. Those skilled in the art can understand and implement this without creative effort.
[0102] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.
[0103] Other embodiments of this specification will readily occur to those skilled in the art upon consideration of the specification and practice of the invention claimed herein. This specification is intended to cover any variations, uses, or adaptations that follow the general principles of this specification and include common knowledge or customary techniques in the art not claimed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this specification are indicated by the following claims.
[0104] It should be understood that this specification is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this specification is limited only by the appended claims.
[0105] The above description is merely a preferred embodiment of this specification and is not intended to limit this specification. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this specification should be included within the scope of protection of this specification.
Claims
1. An access method, characterized in that, The method is applied to the device side, and the method includes: Receive the first online request sent by the client; Based on the first online request, a temporary IP address is allocated to the client from the first address pool, and a temporary lease is configured for the temporary IP address; Send a first online response to the client, the first online response including the temporary IP address and the temporary lease; Receive the renewal request sent by the client; If the client selects the target access authentication method for authentication, a first renewal response is sent to the client to trigger the client to send the first online request again; If, within a predetermined time period after receiving the first online request, the client fails to select the target access authentication method for authentication, then candidate access authentication will be performed on the client. If the client passes the candidate access authentication, then a first lease is configured for the temporary IP address; Send a second renewal response to the client in response to the renewal request. The second renewal response includes the temporary IP address and the first lease, so that the client can access the target network based on the temporary IP address and the first lease; or, If the client passes the candidate access authentication, a third renewal response is sent to the client in response to the renewal request, so that the client sends the first access request again; Receive the first access request sent again by the client; Based on the first online request sent again, a formal IP address is allocated to the client from the first address pool, and a second lease is configured for the formal IP address; A third online response corresponding to the resent first online request is sent to the client, wherein the third online response includes the official IP address and the second lease, so that the client accesses the target network based on the official IP address and the second lease.
2. The method according to claim 1, characterized in that, After receiving the first online request sent by the client, the method further includes: A notification message is sent to the client, which prompts the client whether to select the target access authentication method for authentication.
3. The method according to claim 1, characterized in that, After sending the first online response to the client, the method further includes: A forced update message is sent to the client, which instructs the client to send a renewal request.
4. The method according to claim 1, characterized in that, The first renewal response is used to indicate renewal failure; the method further includes: Receive the first online request sent by the client again; Based on the first online request that is sent again, a target IP address is allocated to the client in the second address pool, and a target lease is configured for the target IP address; A second online response is sent to the client, the second online response including the target IP address and the target lease, so that the client can access the target network according to the target IP address and the target lease.
5. An access method, characterized in that, The method is applied to a client, and the method includes: Send a first online request to the device so that the device allocates a temporary IP address to the client from the first address pool according to the first online request and configures a temporary lease for the temporary IP address; Receive a first online response sent by the device, the first online response including the temporary IP address and the temporary lease; Before the expiration of the temporary lease, a renewal request is sent to the device. Receive the first renewal response sent by the device; Based on the first renewal response, the first online request is sent to the device again. Receive a second renewal response from the device, wherein the second renewal response includes the temporary IP address and the first lease; Access the target network based on the temporary IP address and the first lease; or, Receive a third online response from the device, wherein the third online response includes a formal IP address and a second lease; Access the target network based on the official IP address and the second lease.
6. The method according to claim 5, characterized in that, The first renewal response is used to indicate renewal failure; the method further includes: Based on the first renewal response, a second online request is sent to the device so that the device can allocate a target IP address for the client in the second address pool and configure a target lease for the target IP address. Receive a second online response from the device, wherein the second online response includes the target IP address and the target lease; Access the target network based on the target IP address and the target lease.
7. A client access device, characterized in that, The device is applied to the equipment end, and the device includes: The first online request receiving module is used to receive the first online request sent by the client. The first allocation module is used to allocate a temporary IP address to the client from the first address pool according to the first online request, and configure a temporary lease for the temporary IP address; The first online response sending module is used to send a first online response to the client, wherein the first online response includes the temporary IP address and the temporary lease; The second receiving module is used to receive the renewal request sent by the client; The second sending module is used to send a first renewal response to the client if the client does not select to authenticate using the target access authentication method, so as to trigger the client to send the first online request again. The device further includes: The candidate authentication module is used to perform candidate access authentication on the client if the client does not select the target access authentication method for authentication within a predetermined time after receiving the first online request. The first configuration module is used to configure a first lease for the temporary IP address if the client passes the candidate access authentication. The second renewal response sending module is used to send a second renewal response to the client in response to the renewal request. The second renewal response includes a temporary IP address and a first lease, so that the client can access the target network based on the temporary IP address and the first lease. Alternatively, the device may further include: The candidate authentication module is used to perform candidate access authentication on the client if the client does not select the target access authentication method for authentication within a predetermined time after receiving the first online request. The third renewal response sending module is used to send a third renewal response to the client in response to the renewal request if the client passes the candidate access authentication, so that the client can send the first access request again. The second online request receiving module is used to receive the first access request sent again by the client. The second configuration module is used to allocate a formal IP address to the client from the first address pool based on the first online request that is sent again, and to configure a second lease for the formal IP address. The third online response sending module is used to send a third online response to the client corresponding to the resent first online request. The third online response includes a formal IP address and a second lease, so that the client can access the target network based on the formal IP address and the second lease.
8. A client access device, characterized in that, The device is used on a client side, and the device includes: The first online request sending module is used to send a first online request to the device so that the device can allocate a temporary IP address to the client in the first address pool according to the first online request and configure a temporary lease for the temporary IP address. The first online response receiving module is used to receive the first online response sent by the device, wherein the first online response includes the temporary IP address and the temporary lease. The renewal request sending module is used to send a renewal request to the device when the temporary lease expires; The first renewal response receiving module is used to receive the first renewal response sent by the device. The first online request retransmission module is also used to send the first online request to the device again based on the first renewal response. The device further includes: The third online response receiving module is used to receive the third online response from the device, wherein the third online response includes a temporary IP address and a first lease. The second access module is used to access the target network based on the temporary IP address and the first lease. Alternatively, the device may further include: The third online response receiving module is used to receive the third online response from the device. The third online response includes the official IP address and the second lease. The third access module is used to access the target network based on the official IP address and the second lease.
Citation Information
Patent Citations
Address allocation method and device
CN113992629A