A method, apparatus, equipment and medium for handling abnormal offline processes

By monitoring user connection drops in a zero-trust network and clearing resources and sending exception messages when such drops occur, the problem of resource waste caused by user network outages is solved, and timely release and improved utilization of resources are achieved.

CN116506504BActive Publication Date: 2026-04-03NEW H3C SECURITY TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-04-21
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

In a zero-trust network, when a user loses internet access, the gateway cannot proactively release resources, leading to resource waste and impacting other users' services.

Method used

When a network device detects an abnormal disconnection of a user's connection, it clears the user's access resources and sends an exception message to the controller. After receiving the offline message, it deletes the user's information to ensure the timely release of resources.

Benefits of technology

This avoids resource waste, improves the resource utilization of network equipment, maintains the consistency of user states, and does not violate the design principles of zero-trust networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116506504B_ABST
    Figure CN116506504B_ABST
Patent Text Reader

Abstract

This application provides a method, apparatus, device, and medium for handling abnormal offline events, relating to the field of communication technology. The method includes: upon detecting an abnormal disconnection of the tunnel between the gateway and the target user, clearing the authorized user access resources of the target user; sending a target message indicating an abnormality with the target user to the controller; and upon receiving the offline message from the controller, deleting the target user's user information. In this way, during a user's network outage, the gateway can promptly release the resources allocated to that user, avoiding resource waste.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a method, apparatus, device and medium for handling abnormal offline processes. Background Technology

[0002] Software-defined perimeter (SDP) is a network security solution, also known as zero-trust networking. When using applications, it allows for the deployment of a security perimeter for the application when needed, moving away from traditional network security based on physical firewall boundaries surrounding the internal network. While physical perimeter networks always trust the internal network to be secure, zero-trust network security redefines security. It breaks the limitations of physical boundaries, treating everything within the network as untrusted, and constantly verifying the legitimacy and compliance of user identities and devices. By verifying user identities and resource authorization, it achieves secure network access and prevents attackers from seeing targets within the network, thus hindering their attacks.

[0003] Currently, user online / offline management in zero-trust networks involves interaction between the user and the controller. The controller notifies the gateway of user online or offline status. The general process is as follows: the user sends a login request to the controller for authentication; after successful authentication, the controller sends online information to the gateway; similarly, the user offline process involves the controller notifying the gateway to go offline, and the gateway then deleting the online user's information. In other words, the gateway does not proactively send offline notifications or delete online information. However, this model presents the following problem: if the user experiences a sudden network outage, the tunnel between the user and the gateway will be broken. The user may then attempt to send an offline notification to the controller via a client or browser. However, because the user is offline, the offline notification will not reach the controller. Consequently, the controller and gateway will still record the user as online, leading to wasted resources as the controller and gateway continue to allocate resources to provide services to that user. For example, after a user comes online, the gateway will allocate corresponding storage resources based on the user's online status and the user authorization resource information fed back by the controller. However, when the user's network is disconnected, the resources allocated to that user cannot be released, resulting in wasted resources and potentially affecting the business of other normal users.

[0004] Therefore, how to ensure that the gateway can release the resources allocated to a user in a timely manner during a user's network outage, thus avoiding resource waste, is one of the technical issues worth considering. Summary of the Invention

[0005] In view of this, this application provides a method, apparatus, device and medium for handling abnormal offline events, so that the gateway can release the resources allocated to the user in a timely manner during the user's network outage, thereby avoiding resource waste.

[0006] Specifically, this application is implemented through the following technical solution:

[0007] According to a first aspect of this application, an abnormal offline handling method is provided, applied in a network device, the method comprising:

[0008] When an abnormal disconnection is detected between the target user and the user, the user's authorized access resources are cleared.

[0009] Send a target message to the controller indicating that the target user is abnormal;

[0010] After receiving the offline message from the controller, the user information of the target user is deleted.

[0011] Optionally, the abnormal offline handling method provided in this embodiment may further include:

[0012] Receive the online message sent by the controller indicating that the target user has re-entered the network;

[0013] Based on the online message, the controller re-saves the user access resources authorized for the target user and saves the user information of the target user.

[0014] Optionally, if the target message includes an abnormal status identifier, then before sending the target message indicating that the target user has an abnormality to the controller, the following steps are also included:

[0015] The target message is encapsulated according to the message format used for communication between the network device and the controller, and the abnormal status identifier is filled into the setting field of the target message.

[0016] Optionally, the target message may also include the target user's token and the network device's device identifier.

[0017] According to a second aspect of this application, an abnormal offline processing device is provided, disposed in a network device, the device comprising:

[0018] The clearing module is used to clear the user access resources authorized by the target user when it detects that the connection between the target user and the target user has been abnormally disconnected.

[0019] The sending module is used to send a target message to the controller indicating that the target user is abnormal;

[0020] The deletion module is used to delete the user information of the target user after receiving the offline message of the target user from the controller.

[0021] Optionally, the abnormal offline processing device provided in this embodiment may further include:

[0022] The receiving module is used to receive the online message sent by the controller indicating that the target user has re-entered the network;

[0023] The storage module is used to re-save the user access resources authorized by the controller for the target user based on the online message, and to save the user information of the target user.

[0024] Optionally, the target message includes an abnormal status identifier; the device further includes:

[0025] An encapsulation module is used to encapsulate the target message according to the message format used for communication between the network device and the controller before the sending module sends the target message indicating that the target user is abnormal to the controller, so as to fill the abnormal status identifier in the set field of the target message.

[0026] Optionally, the target message may also include the target user's token and the network device's device identifier.

[0027] According to a third aspect of this application, a network device is provided, including a processor and a machine-readable storage medium storing a computer program executable by the processor, the processor being prompted by the computer program to perform the method provided in the first aspect of the embodiments of this application.

[0028] According to a fourth aspect of this application, a machine-readable storage medium is provided, which stores a computer program that, when invoked and executed by a processor, causes the processor to perform the method provided in the first aspect of the embodiments of this application.

[0029] The beneficial effects of the embodiments of this application are as follows:

[0030] The abnormal offline handling method, apparatus, device, and medium provided in this application, when detecting an abnormal disconnection of the connection between a network device and a target user, clears the user access resources authorized by the target user; sends a target message indicating that the target user is abnormal to the controller; and deletes the user information of the target user after receiving the offline message from the controller. In this way, when a network device detects an abnormal disconnection of the communication connection with a target user, it releases the corresponding resources in the network device by deleting the target user's user access resources on the network device, avoiding resource waste; at the same time, it allows the network device to have more resources to provide services to other users, improving the resource utilization rate of the network device. Attached Figure Description

[0031] Figure 1 This is a flowchart illustrating an abnormal offline handling method provided in an embodiment of this application;

[0032] Figure 2 This is a schematic diagram of the structure of an abnormal offline processing device provided in an embodiment of this application;

[0033] Figure 3 This is a schematic diagram of the hardware structure of a network device that implements an abnormal offline handling method according to an embodiment of this application. Detailed Implementation

[0034] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application.

[0035] The terminology used in this application is for the purpose of describing particular embodiments only and is not intended to be limiting of the application. The singular forms “a,” “the,” and “the” used herein are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any and all possible combinations of one or more of the corresponding listed items.

[0036] It should be understood that although the terms first, second, third, etc., may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, without departing from the scope of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to determination."

[0037] The abnormal offline handling method provided in this application will be explained in detail below.

[0038] See Figure 1 , Figure 1 This is a flowchart of an abnormal offline handling method provided in this application. This method can be applied to network devices, including but not limited to gateway devices. When implementing the above method, the network device may include the following steps:

[0039] S101. When it is detected that the connection between the target user and the target user is abnormally disconnected, clear the user access resources that the target user has authorized.

[0040] In this step, because network devices in a zero-trust network do not have the authority to actively add or remove users, under abnormal circumstances, the lack of such authority on the gateway can lead to excessive resource consumption and waste. Therefore, this embodiment proposes that the network device monitor the connection status between itself and the target user it is communicating with. Thus, when the network device detects an abnormal disconnection of its communication connection with a user (referred to as the target user for convenience), to prevent the target user from excessively consuming network device resources after the abnormal disconnection, this embodiment proposes that the network device can delete the user access resources that provided access to the target user. This avoids excessive resource consumption by the abnormal user.

[0041] Furthermore, since the network device itself does not have the authority to manage user online / offline status, it retains the target user's user information while clearing the user's access resources. Since user information generally occupies very little space, while user access resources occupy a relatively large amount of storage space, this embodiment can greatly save network device resources by deleting user access resources. Moreover, since the network device does not delete the target user's user information, it does not violate the original intention of the network device role design in zero-trust networks, that is, the network device does not actively force the target user to go offline.

[0042] It is worth noting that the aforementioned user access resources may include, but are not limited to, access permissions stored by network devices or granted by the controller to the target user. These access permissions may include, but are not limited to, access permissions granted by the controller to the target user to access applications (APP), application programming interfaces (APIs), etc.

[0043] S102. Send a target message to the controller indicating that the target user is abnormal.

[0044] In this step, since the network device cannot actively put the target user offline, in order to confirm whether the target user can go offline, the network device can send a target message indicating that the target user is abnormal to the controller managing the target user. Upon receiving this target message, the controller can determine whether the target user has already gone offline. Since the target user experienced a network outage due to an abnormality, the controller will determine that the target user is offline and will then send an offline message to the target user.

[0045] If the target user reconnects after a network outage, the controller may determine that the target user is online and send an online message to the network device to instruct the network device to re-save the target user's access resources so as to provide the corresponding services when the user accesses the network.

[0046] S103. After receiving the offline message of the target user from the controller, delete the user information of the target user.

[0047] In this step, when the controller sends a message indicating that the target user has logged off, the network device can delete the user information stored in the network device, thus realizing the user's logout operation. That is, after deleting the user information, even if the target user tries to access the network device, the network device will refuse the target user's access.

[0048] The abnormal offline handling method provided in this embodiment, when detecting an abnormal disconnection of the connection between the network device and the target user, clears the user access resources authorized by the target user; sends a target message indicating that the target user is abnormal to the controller; and deletes the user information of the target user after receiving the offline message from the controller. In this way, when the network device detects an abnormal disconnection of the communication connection with the target user, it releases the corresponding resources in the network device by deleting the target user's user access resources on the network device, avoiding resource waste; at the same time, it allows the network device to have more resources to provide services to other users, improving the resource utilization rate of the network device.

[0049] Optionally, based on the above embodiments, the abnormal offline handling method provided in this embodiment may further include the following process: receiving an online message from the controller indicating that the target user has re-entered the network; and according to the online message, re-saving the user access resources authorized by the controller for the target user and saving the user information of the target user.

[0050] Specifically, after a target user loses connection with a network device due to an anomaly, they may re-establish the connection once the anomaly is resolved. It's worth noting that this connection can, but is not limited to, a tunnel communication connection. Based on this, the target user will attempt to interact with the controller, i.e., send an online notification to the controller. Upon receiving this online notification and approving the target user's re-connection, the controller will confirm the target user's access resources and generate the target user's user information. Then, it will send an online message to the network device, instructing the network device to reallocate storage space for the target user to preserve the user access resources authorized by the controller and the target user's user information. For example, the online message can include the user access resources and user information so that the network device can promptly parse and save it.

[0051] It is worth noting that target users can establish or disconnect tunnel connections with network devices through clients or browsers, and send online or offline messages to the controller through clients or browsers.

[0052] Optionally, based on any of the above embodiments, in this embodiment, the target includes an abnormal state identifier; then before executing step S102, the following process may also be included: encapsulating the target message according to the message format for communication between the network device and the controller to fill the abnormal state identifier in the setting field of the target message.

[0053] Specifically, to facilitate the controller's identification of the target message sent by the network device, the target message is encapsulated using the message format corresponding to the communication protocol between the controller and the network device. An abnormal status identifier is then filled into the target message's configuration field before the message is sent to the controller. Upon receiving the target message, the controller can quickly parse the abnormal status identifier to determine if the target user is experiencing an abnormality and whether it needs to be placed offline. If it confirms that the target user needs to be offline, it can send an offline message to the network device.

[0054] It should be noted that the message format for online and offline messages is also the same as the message format used for communication between network devices and the controller. In other words, the message format for target messages, online messages, and offline messages is consistent.

[0055] Based on this, the aforementioned field can, but does not need to, be the ActionType field. The value of the ActionType field varies depending on the message. For example, if the target user logs in via a client, the value of the ActionType field in the corresponding log-in message can be 0; if the target user logs in via a browser, the value of the ActionType field in the corresponding log-in message can be 2; and if the target user logs out, the value of the ActionType field in the corresponding log-out message can be 1. The aforementioned abnormal status identifier representing the target user's abnormality can be n, that is, the value of the ActionType field in the target message is n. On the one hand, it can indicate that the target user has abnormally disconnected, and on the other hand, it can indicate that the network device has cleared the user access resources of the target user recorded in the network device. In this way, the controller can easily determine the current status of the target user based on the value of the ActionType field in the target message.

[0056] Optionally, the message result of the message carrying the ActionType field can be as follows. In this example, since the value of the ActionType field is 1, it can be indicated that the target user is offline.

[0057]

[0058] It is worth noting that the above values ​​for the ActionType field are merely examples and do not constitute a limitation on the values ​​that can be taken for the ActionType field.

[0059] Optionally, based on the above embodiments, in this embodiment, the target message may also include the target user's token and the network device's device identifier, etc.

[0060] Specifically, since the controller can manage the online / offline status of users on multiple network devices, the same user can establish tunnel connections with multiple network devices to access services within the network. Therefore, to ensure accurate feedback to the controller on which network device the target user is abnormal, this embodiment proposes carrying a token representing the target user and a device identifier for identifying the network device in the target message. This allows the controller to accurately locate the corresponding target user and query whether the target user needs to be placed offline on the corresponding network device.

[0061] To better understand this embodiment, we will use the network device as the gateway device and take the interaction between user 1 and the network device and controller through a client as an example. The interaction process between the client, the gateway device, and the controller is roughly as follows:

[0062] Step 1: User 1 sends a login request to the controller to access the network where the controller is located.

[0063] Step 2: After receiving the login request, the controller will authenticate User 1. Once authentication is successful, the controller will assign an IP address to User 1. In addition, the controller will assign User 1 a list of resources that the user can access and the device identifier of the gateway device that can establish a tunnel connection, and send these to User 1 through the client.

[0064] Step 3: The controller will send the username of the authenticated user 1, the token assigned to user 1, the aforementioned IP address, and the user access resources assigned to the user by the controller, along with other information, to the gateway device corresponding to the aforementioned device identifier in the online message. This will enable the gateway device to store the aforementioned information upon receiving the online message.

[0065] The username of User 1, the token assigned to User 1, and the IP address mentioned above can be used as User 1's user information.

[0066] It should be noted that gateway devices are pre-registered with the controller so that the controller can manage the gateway devices and the users connected to them. In other words, one controller can manage multiple gateway devices.

[0067] Step 4: After receiving the gateway device identifier and the resource list from the controller via the client, User 1 can establish a tunnel connection with the gateway device corresponding to the device identifier using the assigned IP address. Once the tunnel connection is successfully established, User 1 can access the corresponding resources in the resource list assigned to them by the controller.

[0068] Step 5: When an anomaly occurs on User 1's side, causing the tunnel connection between the client and the gateway device to be broken, the gateway device can detect the disconnection. To avoid excessive resource waste caused by User 1's user access resources continuing to occupy the gateway device's storage space, the gateway device will delete User 1's user access resources from local storage. This not only frees up the gateway device's storage resources but also allows the gateway device to provide gateway services to new users, improving the gateway device's resource utilization.

[0069] Step 6: After clearing the user access resources of user 1, the gateway device will send a target message to the controller indicating that user 1 has an anomaly.

[0070] It should be noted that after an anomaly occurs on User 1's side, User 1's client will attempt to communicate with the controller to notify the controller to put User 1 into an offline state. However, since User 1's network is disconnected, the client cannot notify the controller. Therefore, the controller will continue to believe that User 1 is online, which is inconsistent with User 1's actual state. To avoid this situation, the gateway device can send a target message to the controller to indicate that User 1 has an anomaly. Furthermore, to facilitate the controller's awareness of information about User 1, the target message can include User 1's token, the gateway device's device identifier, and the anomaly status identifier.

[0071] Step 7: After receiving the target message, the controller can parse the token and device identifier from the target message, and then confirm whether user 1 has a network abnormality. If it is determined that user 1 does have an abnormality, it will send an offline message to the gateway device, so that the gateway device will delete user 1's user information after receiving the offline message, and put user 1 in an offline state.

[0072] Optionally, the aforementioned clients may be, but are not limited to, authentication clients such as iNode clients.

[0073] This not only ensures consistency in user online status across gateway devices, controllers, and clients, but also allows the gateway device to release resources and improve resource utilization by autonomously clearing abnormal user authorization resource information. Furthermore, it adheres to the principle that gateway devices in zero-trust networks have no authority to actively allow users to go online or offline.

[0074] Based on the same inventive concept, this application also provides an abnormal offline processing device corresponding to the above-described abnormal offline processing method. The specific implementation of this abnormal offline processing device can be referred to the above description of the abnormal offline processing method, and will not be elaborated upon here.

[0075] See Figure 2 , Figure 2 An exemplary embodiment of this application provides an abnormal offline processing device, which is installed in a network device. The device includes:

[0076] The clearing module 201 is used to clear the user access resources authorized by the target user when it detects that the connection between the target user and the target user is abnormally disconnected.

[0077] Sending module 202 is used to send a target message to the controller indicating that the target user is abnormal;

[0078] The deletion module 203 is used to delete the user information of the target user after receiving the offline message of the target user from the controller.

[0079] In the abnormal offline processing device provided in this embodiment, when an abnormal disconnection of the connection with the target user is detected, the device clears the user access resources authorized by the target user; sends a target message indicating that the target user is abnormal to the controller; and deletes the user information of the target user after receiving the offline message from the controller. Thus, when an abnormal disconnection of the communication connection with the target user is detected, deleting the target user's user access resources on the network device releases the corresponding resources in the network device, avoiding resource waste; simultaneously, it allows the network device to have more resources to provide services to other users, improving the resource utilization rate of the network device.

[0080] Optionally, based on the above embodiments, the abnormal offline processing device provided in this embodiment may further include:

[0081] A receiving module (not shown in the figure) is used to receive the online message sent by the controller indicating that the target user has re-entered the network;

[0082] The storage module (not shown in the figure) is used to re-save the user access resources authorized by the controller for the target user and to save the user information of the target user according to the online message.

[0083] Optionally, based on any of the above embodiments, the target message in this embodiment includes an abnormal status identifier; furthermore, the abnormal offline processing device provided in this embodiment may also include:

[0084] An encapsulation module (not shown in the figure) is used to encapsulate the target message according to the message format used for communication between the network device and the controller before the sending module 202 sends the target message indicating that the target user is abnormal to the controller, so as to fill the abnormal status identifier in the set field of the target message.

[0085] Optionally, based on any of the above embodiments, the target message in this embodiment may further include the target user's token and the network device's device identifier.

[0086] This not only ensures consistency in user online status across gateway devices, controllers, and clients, but also allows the gateway device to release resources and improve resource utilization by autonomously clearing abnormal user authorization resource information. Furthermore, it adheres to the principle that gateway devices in zero-trust networks have no authority to actively allow users to go online or offline.

[0087] Based on the same inventive concept, embodiments of this application provide a network device, such as... Figure 3As shown, the device includes a processor 301 and a machine-readable storage medium 302. The machine-readable storage medium 302 stores a computer program executable by the processor 301. The processor 301 is prompted by the computer program to execute the abnormal offline handling method provided in any embodiment of this application. Furthermore, the network device also includes a communication interface 303 and a communication bus 304, wherein the processor 301, the communication interface 303, and the machine-readable storage medium 302 communicate with each other via the communication bus 304.

[0088] The communication bus mentioned in the above network devices can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, only one thick line is used to represent it in the diagram, but this does not indicate that there is only one bus or one type of bus.

[0089] The communication interface is used for communication between the aforementioned network devices and other devices.

[0090] The machine-readable storage medium 302 described above can be a memory, which may include random access memory (RAM), DDR SRAM (Double Data Rate Synchronous Dynamic Random Access Memory), or non-volatile memory (NVM), such as at least one disk storage device. Optionally, the memory may also be at least one storage device located remotely from the aforementioned processor.

[0091] The processors mentioned above can be general-purpose processors, including central processing units (CPUs), network processors (NPs), etc.; they can also be digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.

[0092] For network devices and machine-readable storage media embodiments, since the methods involved are basically similar to those described in the foregoing method embodiments, the description is relatively simple, and relevant details can be found in the descriptions of the method embodiments.

[0093] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0094] The specific implementation process of the functions and roles of each unit / module in the above device can be found in the implementation process of the corresponding steps in the above method, and will not be repeated here.

[0095] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to in the description of the method embodiments. The device embodiments described above are merely illustrative. The units / modules described as separate components may or may not be physically separate. The components shown as units / modules may or may not be physical units / modules, that is, they may be located in one place or distributed across multiple network units / modules. Some or all of the units / modules can be selected to achieve the purpose of this application according to actual needs. Those skilled in the art can understand and implement this without creative effort.

[0096] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.

Claims

1. A method for handling abnormal offline processes, characterized in that, In network devices applied to zero-trust networks, the method includes: When an abnormal disconnection is detected between the target user and the target user, the user access resources authorized by the target user are cleared, while the user information of the target user is retained. Send a target message to the controller indicating that the target user is abnormal; After receiving the offline message from the controller, the user information of the target user is deleted.

2. The method according to claim 1, characterized in that, Also includes: Receive the online message sent by the controller indicating that the target user has re-entered the network; Based on the online message, the controller re-saves the user access resources authorized for the target user and saves the user information of the target user.

3. The method according to claim 1, characterized in that, The target message includes an abnormal status identifier; therefore, before sending the target message indicating that the target user has an abnormality to the controller, the following steps are also included: The target message is encapsulated according to the message format used for communication between the network device and the controller, and the abnormal status identifier is filled into the setting field of the target message.

4. The method according to claim 1, characterized in that, The target message also includes the target user's token and the network device's device identifier.

5. An abnormal offline processing device, characterized in that, The device, installed in a network device in a zero-trust network, includes: The clearing module is used to clear the user access resources authorized by the target user when it detects that the connection between the target user and the target user is abnormally disconnected, while retaining the user information of the target user. The sending module is used to send a target message to the controller indicating that the target user is abnormal; The deletion module is used to delete the user information of the target user after receiving the offline message of the target user from the controller.

6. The apparatus according to claim 5, characterized in that, Also includes: The receiving module is used to receive the online message sent by the controller indicating that the target user has re-entered the network; The storage module is used to re-save the user access resources authorized by the controller for the target user based on the online message, and to save the user information of the target user.

7. The apparatus according to claim 5, characterized in that, The target message includes an abnormal status identifier; the device further includes: An encapsulation module is used to encapsulate the target message according to the message format used for communication between the network device and the controller before the sending module sends the target message indicating that the target user is abnormal to the controller, so as to fill the abnormal status identifier in the set field of the target message.

8. The apparatus according to claim 5, characterized in that, The target message also includes the target user's token and the network device's device identifier.

9. A network device, characterized in that, The method includes a processor and a machine-readable storage medium storing a computer program executable by the processor, which is prompted by the computer program to perform the method according to any one of claims 1-4.

10. A machine-readable storage medium, characterized in that, The machine-readable storage medium stores a computer program that, when invoked and executed by a processor, causes the processor to perform the method described in any one of claims 1-4.

Citation Information

Patent Citations

  • Removing method for occupied network resource by user in wireless local network

    CN1645811A