A device access authentication method, apparatus and system
By maintaining an authentication server in the network environment, constructing a CPE topology using transmission parameters, and dynamically adjusting the communication path, the high cost and complexity of multi-server access authentication are solved, achieving optimal path device access authentication, and improving communication efficiency and management ease of use.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- BEIJING QINGWANG TECH CORP
- Filing Date
- 2024-06-04
- Publication Date
- 2026-04-21
AI Technical Summary
In existing technologies, the use of multiple authentication servers for device access authentication results in high operating and maintenance costs, management complexity, and inconvenience in configuration updates, and batch configuration updates cannot be achieved.
By maintaining an authentication server in the network environment, constructing a CPE topology map using transmission parameters, determining the optimal path for device access authentication, and dynamically adjusting the communication path by comprehensively considering tunnel latency, packet loss rate, and weighted calculation of traffic data.
It enables the rapid determination of the optimal device access authentication path between the CPE and the authentication server in dynamic situations, reducing costs, improving communication efficiency, and simplifying management processes.
Smart Images

Figure CN118474020B_ABST
Abstract
Description
Technical Field
[0001] This article relates to the field of communication technology, and in particular to a device access authentication method, apparatus and system. Background Technology
[0002] Currently, when users authenticate device access through their user terminals, network access is typically achieved through Customer Premise Equipment (CPE) located on the user's side. These CPEs usually exist in the form of hardware devices and are often deployed at the exit point of the user's enterprise network, that is, the public network exit point of the user's enterprise network. Users outside the enterprise network can access the internal enterprise network through the address of the enterprise network exit point.
[0003] Currently, multiple authentication servers need to be maintained for device access authentication of user terminals on the CPE side, resulting in high operation and maintenance costs. Furthermore, since multiple authentication servers are used for device access authentication, daily management of each server is required, increasing management complexity and costs. Moreover, when updating configurations for multiple authentication servers, batch configuration updates are often not supported or are inconvenient to perform, leading to additional costs associated with updating the authentication server configurations.
[0004] Determining the communication path between the CPE and the authentication server is a pressing technical issue that needs to be addressed when reducing the number of authentication servers used for device access authentication during maintenance. Summary of the Invention
[0005] To address the issue of determining the communication path between the CPE and the authentication server when reducing the number of authentication servers required for device access authentication in existing technologies, this paper provides a device access authentication method, apparatus, and system. This achieves the goal of maintaining only one authentication server while ensuring that each CPE communicates with the terminal device via the optimal path, thereby reducing multiple costs and improving the communication efficiency between the CPE and the authentication server.
[0006] To solve the above-mentioned technical problems, the specific technical solution presented in this paper is as follows:
[0007] On one hand, this embodiment provides a device access authentication method, applied to a network environment including multiple CPEs and an authentication server, wherein the authentication server communicates with a target CPE among the multiple CPEs, including,
[0008] In response to receiving an access authentication request, the transmission parameters corresponding to each of the CPEs are determined, wherein the access authentication request is sent by the requesting CPE among the multiple CPEs;
[0009] Based on the transmission parameters, the connectivity of the edges in the pre-constructed CPE topology graph is determined and processed to obtain the target CPE topology graph. The CPE topology graph includes multiple nodes and multiple edges, and the edges are used to connect nodes to indicate that they are connected to the two CPEs corresponding to the two connected nodes.
[0010] Based on the transmission parameters and the weights corresponding to the transmission parameters, determine the index value of each edge in the target CPE topology graph; and
[0011] Based on the aforementioned index values, the target path in the target CPE topology map is determined to be the device access authentication path, starting from the request node corresponding to the requesting CPE and ending at the target node corresponding to the target CPE.
[0012] Furthermore, the transmission parameters corresponding to the CPE include at least one candidate CPE connected to the CPE, the tunnel delay for communicating with each candidate CPE, the packet loss rate for communicating with each candidate CPE, and the traffic data for communicating with each candidate CPE.
[0013] Furthermore, the transmission parameters corresponding to the CPE include at least one candidate CPE connected to the CPE, and the packet loss rate for communicating with each candidate CPE. The step of determining and processing the connectivity of edges in the pre-constructed CPE topology graph based on the transmission parameters to obtain the target CPE topology graph includes:
[0014] For each edge in the first candidate path of the pre-constructed CPE topology graph, starting from the request node and ending at the target node, the packet loss rate corresponding to the edge is determined from the transmission parameters, and it is determined whether the packet loss rate is greater than or equal to a preset threshold; and
[0015] If the target packet loss rate is determined to be greater than or equal to the preset threshold, the target edge corresponding to the target packet loss rate is disconnected to obtain the target CPE topology graph.
[0016] Furthermore, based on the transmission parameters and the weights corresponding to the transmission parameters, the index value of each edge in the target CPE topology graph is determined as follows:
[0017] From the transmission parameters, determine the tunnel delay, packet loss rate, and traffic data corresponding to each edge; and
[0018] The index value is obtained by weighting the tunnel delay, the packet loss rate, and the traffic data using the weights.
[0019] Furthermore, the weights include packet loss rate weights and traffic data weights, wherein the weighted calculation of the tunnel latency, packet loss rate, and traffic data to obtain the indicator value includes:
[0020] Calculate the product of the packet loss rate weight and the packet loss rate to obtain the first data;
[0021] Calculate the product of the traffic data weight and the traffic data to obtain the second data; and
[0022] The index value is obtained by summing the first data, the second data, and the tunnel delay.
[0023] Furthermore, based on the aforementioned indicator values, the target path in the target CPE topology map, starting from the request node corresponding to the requesting CPE and ending at the target node corresponding to the target CPE, is determined as the device access authentication path, including:
[0024] Starting from the requesting node, determine at least one first candidate node that is directly connected to the requesting node from the target CPE topology graph;
[0025] Based on the index value corresponding to the edge connecting the request node and each of the first candidate nodes, a next-hop node is determined from the at least one first candidate node;
[0026] If it is determined that the next hop node is not the target node, the next hop node is used as the request node, and the step of determining the next hop node is executed repeatedly until the next hop node is the target node, so as to construct the target path based on the request node, all next hop nodes and the target node.
[0027] Furthermore, based on the aforementioned indicator values, the target path in the target CPE topology map, starting from the request node corresponding to the requesting CPE and ending at the target node corresponding to the target CPE, is determined as the device access authentication path, including:
[0028] Based on the aforementioned index values, determine the transmission values of each second candidate path in the target CPE topology map, starting from the request node corresponding to the requesting CPE and ending at the target node corresponding to the target CPE; and
[0029] The second candidate path corresponding to the smallest transmission value among the multiple transmission values is determined as the device access authentication path.
[0030] Furthermore, based on the aforementioned index values, the transmission values for each second candidate path in the target CPE topology map, starting from the request node corresponding to the requesting CPE and ending at the target node corresponding to the target CPE, include:
[0031] Based on the index values, determine at least one edge included in each second candidate path starting from the request node and ending at the target node, and the index value corresponding to each edge; and
[0032] For each of the second candidate paths, the sum of the index values corresponding to each edge included in the second candidate path is determined as the transmission value.
[0033] Furthermore, the methods for constructing the pre-built CPE topology map include:
[0034] Determine the static transmission parameters corresponding to each CPE;
[0035] Based on the static transmission parameters, a static CPE topology graph is constructed, wherein the static CPE topology graph includes multiple static nodes and multiple static edges, and the static edges are used to connect static nodes to indicate that the two static CPEs corresponding to the two connected static nodes are connected.
[0036] Based on the static transmission parameters and the static weights corresponding to the static transmission parameters, determine the static index value of each static edge;
[0037] For each static node in the static CPE topology graph, based on the static index value, multiple third candidate paths are determined, starting from the static node and ending at the static target node corresponding to the target CPE, in order to construct the pre-built CPE topology graph.
[0038] Furthermore, for each static node in the static CPE topology graph, based on the static index value, multiple third candidate paths are determined, starting from the static node and ending at the static target node corresponding to the target CPE, including:
[0039] For each static node in the static CPE topology graph, determine multiple optional paths starting from the static node and ending at the static target node corresponding to the target CPE;
[0040] Based on the static index values, determine the static transmission value corresponding to each of the optional paths; and
[0041] Multiple target static transmission values are selected from the static transmission values, and the optional path corresponding to each target static transmission value is determined as the third candidate path.
[0042] Based on the same inventive concept, this embodiment also provides a device access authentication apparatus, applied to a network environment including multiple CPEs and an authentication server, wherein the authentication server communicates with a target CPE among the multiple CPEs, including a first determining module, configured to determine transmission parameters corresponding to each of the CPEs in response to receiving an access authentication request, wherein the access authentication request is sent by the requesting CPE among the multiple CPEs;
[0043] The judgment and processing module is used to judge and process the connectivity of the edges of the pre-constructed CPE topology graph according to the transmission parameters to obtain the target CPE topology graph, wherein the CPE topology graph includes multiple nodes and multiple edges, and the edges are used to connect nodes to indicate that they are connected to the two CPEs corresponding to the two connected nodes.
[0044] The second determining module is used to determine the index value of each edge in the target CPE topology graph based on the transmission parameters and the weights corresponding to the transmission parameters.
[0045] The third determining module, based on the indicator value, determines the target path in the target CPE topology map, which starts from the request node corresponding to the requesting CPE and ends at the target node corresponding to the target CPE, as the device access authentication path.
[0046] Based on the same inventive concept, this embodiment also provides a device access authentication system, including multiple CPEs, an authentication server, and a central controller. The authentication server communicates with a target CPE among the multiple CPEs, and the multiple CPEs can communicate with each other individually, and each CPE communicates with the central controller.
[0047] The CPE is used to receive user access authentication requests sent by user terminals and to send transmission data to the central controller; when the CPE receives a user access authentication request, it processes the user access authentication request to obtain an access authentication request and sends the access authentication request to the central controller.
[0048] The central controller is used to receive the access authentication request, determine the transmission parameters corresponding to each CPE; based on the transmission parameters, perform edge connectivity judgment and processing on a pre-constructed CPE topology graph to obtain a target CPE topology graph, wherein the CPE topology graph includes multiple nodes and multiple edges, the edges being used to connect nodes to represent a connection between two CPEs corresponding to two connected nodes; based on the transmission parameters and the weights corresponding to the transmission parameters, determine the index value of each edge in the target CPE topology graph; based on the index value, determine the target path in the target CPE topology graph, starting from the request node corresponding to the requesting CPE and ending at the target node corresponding to the target CPE, as the device access authentication path; determine the transmission CPE corresponding to each node included in the device access authentication path, and send the device access authentication path to each transmission CPE; and
[0049] The transmission CPE is used to receive the device access authentication path in order to transmit authentication data of the user terminal that sent the user access authentication request.
[0050] On the other hand, this embodiment also provides a computer device, including a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the method executed by the central controller described above.
[0051] Finally, this embodiment also provides a computer storage medium storing a computer program, which, when run by the processor of a computer device, executes the method described above for execution by the central controller.
[0052] Using the embodiments described herein, the current network environment includes multiple CPEs and an authentication server. The authentication server communicates with target CPEs among the multiple CPEs. Upon receiving an access authentication request, it determines the transmission parameters corresponding to each CPE. Based on the transmission parameters, it performs edge connectivity judgment and processing on a pre-constructed CPE topology graph to obtain a target CPE topology graph. Based on the transmission parameters and their corresponding weights, it determines the index value of each edge in the target CPE topology graph. Based on the index values, it determines the target path in the target CPE topology graph, starting from the request node corresponding to the requesting CPE and ending at the target node corresponding to the target CPE, as the device access authentication path. This achieves the goal of maintaining only one authentication server for device access authentication. Furthermore, when determining the device access authentication path between the CPE and the authentication server, it comprehensively considers the current transmission parameters of the CPEs to determine the optimal device access authentication path, rather than transmitting data according to a pre-determined communication path based on a static situation with no traffic. This enables real-time and rapid determination of the optimal device access authentication path between the CPE and the authentication server even in dynamic situations, thereby maximizing cost savings and improving communication efficiency. Attached Figure Description
[0053] To more clearly illustrate the technical solutions in the embodiments or prior art described herein, the accompanying drawings used in the description of the embodiments or prior art will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this article. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0054] Figure 1 The diagram shown is a schematic of a device access authentication system according to an embodiment of this article;
[0055] Figure 2 The diagram shown is a flowchart of a device access authentication method according to an embodiment of this paper;
[0056] Figure 3 The diagram shown is a flowchart of a method for determining index values according to an embodiment of this paper;
[0057] Figure 4A The diagram shown is a flowchart of a device access authentication path method according to an embodiment of this paper;
[0058] Figure 4B The diagram shown is a flowchart of another embodiment of a device access authentication path method.
[0059] Figure 5 The diagram shown is a flowchart of a method for constructing a pre-built CPE topology diagram according to an embodiment of this paper;
[0060] Figure 6A The diagram shown is a structural schematic of a device access authentication device according to an embodiment of this article;
[0061] Figure 6B The diagram shown is a structural schematic of a device access authentication device according to another embodiment of this paper;
[0062] Figure 7 The diagram shown is a structural schematic of the computer device in the embodiment of this article.
[0063] [Explanation of Figure Markers]:
[0064] 101. CPE;
[0065] 102. Authentication server;
[0066] 103. Central controller;
[0067] 601. First Determining Module;
[0068] 602. Judgment and processing module;
[0069] 603. Second Determination Module;
[0070] 604. The third determination module;
[0071] 605. Fourth Determination Module;
[0072] 606. First building block;
[0073] 607. The Fifth Determination Module;
[0074] 608. Second building block;
[0075] 702. Computer equipment;
[0076] 704. Processing equipment;
[0077] 706. Storage resources;
[0078] 708. Drive mechanism;
[0079] 710. Input / Output Module;
[0080] 712. Input devices;
[0081] 714. Output devices;
[0082] 716. Presentation equipment;
[0083] 718. Graphical User Interface;
[0084] 720. Network interface;
[0085] 722. Communication link;
[0086] 724. Communication bus. Detailed Implementation
[0087] The technical solutions in the embodiments described below will be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments described herein, and not all of the embodiments. Based on the embodiments described herein, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this document.
[0088] It should be noted that the terms "first," "second," etc., used in the specification, claims, and accompanying drawings herein are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, apparatus, product, or device that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or devices.
[0089] It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases the steps shown or described may be executed in a different order than that shown here.
[0090] like Figure 1The diagram illustrates a device access authentication system according to an embodiment of this document. It may include multiple CPEs 101, an authentication server 102, and a central controller 103. The authentication server 102 communicates with the target CPE among the multiple CPEs 101. The multiple CPEs 101 can communicate with each other individually, and each CPE 101 communicates with the central controller 103. Each CPE 101 receives user access authentication requests sent by user terminals and sends transmission data to the central controller 103. When a user needs to perform device access authentication through a user terminal, a user access authentication request (which may include, for example, a user identifier and an access request) is sent to the requesting CPE. When the requesting CPE receives the user access authentication request, it processes the request to obtain an access authentication request (which may include, for example, the requesting CPE identifier, user identifier, and access request, etc., information after processing the user access authentication request; this specification does not limit this information), and sends the access authentication request to the central controller 103. The central controller 103 receives the access authentication request, determines the transmission parameters corresponding to each CPE, and, based on the transmission parameters, processes the pre-built CPEs. The topology graph undergoes edge connectivity assessment and processing to obtain the target CPE topology graph. The CPE topology graph includes multiple nodes and edges, with edges connecting nodes to indicate connectivity between two CPEs corresponding to those nodes. Based on transmission parameters and their corresponding weights, an index value is determined for each edge in the target CPE topology graph. Based on these index values, a target path is determined in the target CPE topology graph, starting from the request node corresponding to the requesting CPE and ending at the target node corresponding to the target CPE. This path is then used as the device access authentication path. The corresponding transmission CPE is determined for each node included in the device access authentication path, and the device access authentication path is sent to each transmission CPE. The transmission CPE receives the device access authentication path to transmit authentication data (username, password, etc.) from the user terminal that sent the user access authentication request.
[0091] It should be noted that each CPE 101 also sends static transmission data (data in the absence of traffic transmission) to the central controller 103; the central controller 103 is also used to receive static transmission parameters corresponding to each CPE 101; based on the static transmission parameters, a static CPE topology graph is constructed, which includes multiple static nodes and multiple static edges. Static edges are used to connect static nodes to represent connections between two static CPEs corresponding to two connected static nodes; based on the static transmission parameters and the static weights corresponding to the static transmission parameters, the static index value of each static edge is determined; for each static node in the static CPE topology graph, based on the static index value, multiple third candidate paths are determined with the static node as the starting point and the target node corresponding to the target CPE as the ending point, in order to construct a pre-constructed CPE topology graph.
[0092] It should be noted that, Figure 1 The number of CPE101 in the diagram is for illustrative purposes only and does not limit the number of CPEs. Similarly, the connection of multiple CPEs is for illustrative purposes only and does not indicate that every two CPEs in the CPE topology diagram are connected.
[0093] In addition, communication can be achieved, for example, through a network, which may include a local area network (LAN), a wide area network (WAN), the Internet, or a combination thereof, and is connected to websites, user equipment (e.g., computing devices), and back-end systems.
[0094] Alternatively, the central controller may be a node of a cloud computing system (not shown in the figure), or the authentication server may be a separate cloud computing system comprising multiple computers interconnected by a network and operating as a distributed processing system.
[0095] Figure 2 The diagram shows a flowchart of a device access authentication method according to an embodiment of this paper. This diagram illustrates the process of determining the communication path between the requesting CPE and the authentication server, but based on conventional or non-creative labor, it may include more or fewer operational steps. The order of steps listed in the embodiment is merely one possible execution order among many and does not represent the only possible execution order. In actual system or device products, the methods shown in the embodiment or the accompanying drawings can be executed sequentially or in parallel. Specifically, as shown... Figure 2 As shown, the method may include:
[0096] S210: In response to receiving an access authentication request, determine the transmission parameters corresponding to each CPE;
[0097] S220: Based on the transmission parameters, perform edge connectivity judgment and processing on the pre-constructed CPE topology graph to obtain the target CPE topology graph;
[0098] S230, determine the index value of each edge in the target CPE topology graph based on the transmission parameters and the weights corresponding to the transmission parameters; and
[0099] S240, based on the indicator value, determine the target path in the target CPE topology map as the device access authentication path, which starts from the request node corresponding to the requesting CPE and ends at the target node corresponding to the target CPE.
[0100] The method described in this embodiment addresses a network environment comprising multiple CPEs and an authentication server. The authentication server communicates with a target CPE among the multiple CPEs. Upon receiving an access authentication request, it determines the transmission parameters corresponding to each CPE. Based on the transmission parameters, it performs edge connectivity judgment and processing on a pre-constructed CPE topology graph to obtain a target CPE topology graph. Based on the transmission parameters and their corresponding weights, it determines the index value of each edge in the target CPE topology graph. Based on the index values, it determines the target path in the target CPE topology graph, starting from the request node corresponding to the requesting CPE and ending at the target node corresponding to the target CPE, as the device access authentication path. This achieves device access authentication by maintaining only one authentication server. Furthermore, when determining the device access authentication path between the CPE and the authentication server, it comprehensively considers the current transmission parameters of the CPEs to determine the optimal path, rather than transmitting data according to a pre-determined communication path based on a static scenario with no traffic. This enables real-time and rapid determination of the optimal device access authentication path between the CPE and the authentication server even in dynamic situations, thereby maximizing cost savings and improving communication efficiency.
[0101] In this embodiment, the device access authentication method is applied to a network environment that includes multiple CPEs and an authentication server, and the authentication server communicates with a target CPE among the multiple CPEs.
[0102] When a user needs to access the network via their terminal, they send a user access authentication request to the CPE. This request may include, for example, a user identifier and an access request. Upon receiving the user access authentication request, the CPE processes it to obtain an access authentication request that the central controller can recognize and parse. This request may include, for example, information processed from the user access authentication request, such as the requesting CPE identifier, the user identifier, and the access request itself; however, this specification does not limit this specific information.
[0103] When the central controller receives an access authentication request, it determines the transmission parameters with each CPE. It should be noted that each CPE can send transmission parameters to the central controller in real time or periodically. Specifically, if the CPEs periodically send transmission parameters to the central controller, the central controller, upon receiving an access authentication request, sends a transmission parameter retrieval request to each CPE to obtain and determine the transmission parameters with each CPE, or determines the historical transmission parameters received from each CPE at the most recent time as the current transmission parameters.
[0104] Based on the determined transmission parameters, the connectivity of edges in the pre-constructed CPE topology graph is determined and processed to obtain the target CPE topology graph, which includes each candidate path. Both the pre-constructed and target CPE topologies consist of multiple nodes and multiple edges. Edges connect nodes to represent connections between two CPEs corresponding to two connected nodes. It is understood that the pre-constructed and target CPE topologies include the same number of nodes, but the number of edges may be the same or different. That is, if every edge in the pre-constructed CPE topology graph passes the connectivity test and no other edges are added, the pre-constructed and target CPE topologies are identical.
[0105] A pre-built CPE topology graph includes, under static conditions with no traffic, the paths that allow communication between each node corresponding to a CPE and the target node, forming a topology graph with multiple CPEs and multiple edges. For example, a pre-built CPE topology graph might include requesting node A, node B, node C, and target node D. Target node D communicates with the authentication server. Requesting node A is connected to node B, node B is connected to target node D, requesting node A is connected to node C, and node C is connected to target node D. This indicates that there are currently two communication paths: Path 1: Requesting node A, node B, and target node D; and Path 2: Requesting node A, node C, and target node D.
[0106] Based on the determined transmission parameters, the connectivity of edges in the pre-constructed CPE topology graph is determined and processed. For example, for all nodes in the pre-constructed CPE topology graph that have direct or indirect connections with the request node A, based on the transmission parameters corresponding to that node, it is determined whether the node should establish a connection with other nodes, or whether an existing connection (an edge with a connection) should be broken. For nodes that should establish a connection, an edge between the two nodes is constructed; for nodes that should break the connection, the edge between the two nodes is broken, thereby obtaining the target CPE topology graph. Specifically, based on the transmission parameters corresponding to the node, it is determined whether the node should establish a connection with other nodes, or whether an existing connection (edges with connections) should be broken. For example, based on the transmission parameters corresponding to the node, the index value of the edge connecting the node to each other node is determined, and the index values are sorted. If the edge corresponding to the index value of the first preset position (e.g., the first three or five in ascending order, this specification does not limit this) does not exist, it is determined that a connection should be established; otherwise, it is determined that a connection should not be established. Furthermore, after determining that there are edges greater than or equal to a preset number (e.g., three or five, this specification does not limit this) after edge construction, it is determined that the edge corresponding to the index value of the next preset position (e.g., the next one or two) should be broken; otherwise, it should not be broken. It should be noted that, for example, if the current node after edge construction only has edges smaller than a preset number, then the determination of whether the existing connection (edges with connections) should be broken is not performed. It is understood that the index value used as a factor for judgment is only one of many factors. Other factors can also be used to judge and process the connectivity of edges, and this manual does not limit this.
[0107] Transmission parameters may include multiple parameters, such as candidate CPEs connected to the current CPE, and data related to traffic transmission, such as tunnel delay between the current CPE and the candidate CPE. Weights are pre-assigned for each category of data included in the transmission parameters. For each edge in the target CPE topology graph, a corresponding index value is determined. It is understood that each edge has a direction, and each direction has a corresponding index value. Specifically, continuing the previous example, when requesting node A connects to node C (representing node A sending information to node C), the transmission parameters corresponding to requesting node A are determined, and the data corresponding to node C is determined from these transmission parameters. This data is then weighted to obtain the index value corresponding to the edge connecting requesting node A to node C.
[0108] Starting from the requesting node and ending at the target node, the optimal target path is determined based on the metric values, and this target path is used as the device access authentication path. It should be noted that the criterion for determining the optimal path could be, for example, minimum latency. Specifically, it could be based on the metric values to determine that the path has the shortest distance and the minimum latency, thus identifying this path as the target path.
[0109] According to another embodiment of this document, the transmission parameters corresponding to the CPE include at least one candidate CPE connected to the CPE, the tunnel latency, packet loss rate, and traffic data for each candidate CPE. Specifically, continuing the previous example, the transmission parameters of requesting node A may include the candidate CPE corresponding to node B and the candidate CPE corresponding to node C, the tunnel latency, packet loss rate, and traffic data when communicating with the candidate CPE corresponding to node B, and the tunnel latency, packet loss rate, and traffic data when communicating with the candidate CPE corresponding to node C. It is understood that in addition to the above multiple transmission data, other transmission data may also be included, and this specification does not limit this.
[0110] According to another embodiment of this document, the transmission parameters corresponding to the CPE include at least one candidate CPE connected to the CPE, and the packet loss rate communicating with each candidate CPE; based on the transmission parameters, the connectivity judgment and processing of the edges in the pre-constructed CPE topology graph to obtain the target CPE topology graph includes: for each edge in the first candidate path in the pre-constructed CPE topology graph, starting from the request node and ending at the target node, determining the packet loss rate corresponding to the edge from the transmission parameters, and determining whether the packet loss rate is greater than or equal to a preset threshold; and if it is determined that the target packet loss rate is greater than or equal to the preset threshold, disconnecting the target edge corresponding to the target packet loss rate to obtain the target CPE topology graph.
[0111] A preset threshold is set to determine whether communication between two CPEs is secure. If the threshold is greater than or equal to the preset threshold, the communication between the two CPEs is considered insecure, and the nodes corresponding to these two CPEs should not be connected. If the connection (edge) exists, the connection is disconnected; otherwise, the edge is retained. Based on this, for each edge in the pre-constructed CPE topology graph, it is determined whether the packet loss rate corresponding to that edge is greater than or equal to the preset threshold. If the rate is greater than or equal to the preset threshold, the edge is disconnected; otherwise, the edge is retained to obtain the target CPE topology graph.
[0112] Figure 3 The diagram shown is a flowchart of a method for determining index values according to an embodiment of this paper. Figure 3The document describes a process for determining indicator values, but based on routine or non-creative labor, it may include more or fewer operational steps. Specifically, for example... Figure 3 As shown, the method may include:
[0113] S331: Determine the tunnel delay, packet loss rate, and traffic data corresponding to each edge from the transmission parameters;
[0114] S332: The tunnel delay, packet loss rate and traffic data are weighted and calculated to obtain the index value.
[0115] According to another embodiment of this paper, determining the tunnel latency, packet loss rate, and traffic data corresponding to each edge specifically involves: determining the transmission initiator node of that edge; determining the CPE corresponding to the initiator node as the CPE to be calculated; and from the transmission parameters corresponding to the CPE to be calculated, determining another CPE connected to that edge and the tunnel latency, packet loss rate, and traffic data corresponding to that CPE, and determining these three data as the tunnel latency, packet loss rate, and traffic data corresponding to that edge. Continuing the previous example, when requesting node A to send information to node C, the transmission initiator node is requesting node A.
[0116] For each type of data in tunnel latency, packet loss rate, and traffic data, a corresponding weight is configured in advance. For the determined tunnel latency, packet loss rate, and traffic data, the weights are used to perform a weighted summation to obtain the index value corresponding to that edge.
[0117] According to another embodiment of this article, the weights include packet loss rate weights and traffic data weights; the weights are used to perform weighted calculations on tunnel latency, packet loss rate, and traffic data to obtain the index value, including: calculating the product of packet loss rate weights and packet loss rate to obtain the first data; calculating the product of traffic data weights and traffic data to obtain the second data; and summing the first data, the second data, and tunnel latency to obtain the index value.
[0118] Pre-configure corresponding weights for packet loss rate and traffic data. These weights can be configured according to actual conditions, and this manual does not limit them. During the configuration process, you can refer to the importance of packet loss rate and traffic data relative to tunnel latency in this case to determine the weights of packet loss rate and traffic data when the weight of tunnel latency is 1.
[0119] Furthermore, the packet loss rate weight is multiplied by the packet loss rate to obtain the first data; the traffic data weight is multiplied by the traffic data to obtain the second data; the tunnel delay, the first data, and the second data are summed to obtain the index value corresponding to that edge.
[0120] Figure 4A The diagram shown is a flowchart of a device access authentication path method according to an embodiment of this paper. Figure 4AThe document describes a process for determining a device access authentication path, but based on conventional or non-creative labor, it may include more or fewer operational steps. Specifically, for example... Figure 4A As shown, the method may include:
[0121] S4141: Starting from the requesting node, determine at least one first candidate node that is directly connected to the requesting node from the target CPE topology graph;
[0122] S4142: Based on the index values corresponding to the edges of the connection request node and each first candidate node, determine the next hop node from at least one first candidate node;
[0123] S4143, if it is determined that the next hop node is not the target node, the next hop node is the request node, and the steps to determine the next hop node are executed repeatedly until the next hop node is the target node, so as to construct the target path based on the request node, all next hop nodes and the target node.
[0124] According to another embodiment of this article, determining the next hop node from at least one first candidate node based on the index value corresponding to the edge of the connection request node and each first candidate node specifically involves determining the edge corresponding to the minimum index value as the candidate edge, and the other node connected to the candidate edge as the first candidate node.
[0125] For example, in the target CPE topology graph, requesting node A is connected to node B, node B is connected to target node D, requesting node A is connected to node C, and node C is connected to target node D. For requesting node A, the first candidate nodes include nodes B and C. If the index value corresponding to the edge connecting requesting node A and node B is greater than the index value corresponding to the edge connecting requesting node A and node C, then node C is determined as the next-hop node. If node C is not the target node, then node C is used as the requesting node, and steps S4141 and S4142 are executed until the next-hop node is determined to be target node D. In this example, the determined target path is the path from requesting node A to node C to target node D.
[0126] Figure 4B The diagram shown is a flowchart of another embodiment of a device access authentication path method described in this paper. Figure 4B The document describes an alternative process for determining the device access authentication path, but based on conventional or non-creative labor, it may include more or fewer operational steps. Specifically, for example... Figure 4B As shown, the method may include:
[0127] S4241: Based on the index value, determine the transmission value of each second candidate path in the target CPE topology map, starting from the request node corresponding to the request CPE and ending at the target node corresponding to the target CPE;
[0128] S4242: Determine the second candidate path corresponding to the smallest transmission value among multiple transmission values as the device access authentication path.
[0129] According to another embodiment of this document, the second candidate path is all connectable paths between the requesting node and the target node. Specifically, in the target CPE topology graph, when requesting node A is connected to node B, node B is connected to target node D, requesting node A is connected to node C, and node C is connected to target node D, the second candidate path includes two paths: one is the path from requesting node A to node C to target node D, and the other is the path from requesting node A to node B to target node D.
[0130] For each second candidate path, the index value of each edge included in the second candidate path is determined, and the transmission value corresponding to each index value is calculated. Furthermore, the second candidate path corresponding to the minimum transmission value among multiple transmission values is determined as the device access authentication path.
[0131] According to another embodiment of this document, determining the transmission value of each second candidate path in the target CPE topology graph, starting from the request node corresponding to the request CPE and ending at the target node corresponding to the target CPE, based on the index value, includes: determining at least one edge included in each second candidate path, starting from the request node and ending at the target node, and the index value corresponding to each edge; and for each second candidate path, determining the sum of the index values corresponding to each edge included in the second candidate path as the transmission value.
[0132] For example, for a second candidate path from requesting node A to node C to target node D, the index value of the edge connecting requesting node A to node C is determined, and the data obtained by adding the index value of the edge connecting node C to target node D is the transmission value corresponding to the second candidate path.
[0133] Figure 5 The diagram shown is a flowchart of a method for constructing a pre-built CPE topology map according to an embodiment of this paper. Figure 5 The document describes a process for constructing a pre-built CPE topology map, but based on conventional or non-creative labor, it may include more or fewer operational steps. Specifically, as... Figure 5 As shown, the method may include:
[0134] S510: Determine the static transmission parameters corresponding to each CPE;
[0135] S520: Construct a static CPE topology diagram based on static transmission parameters;
[0136] S530: Determine the static index value of each static edge based on the static transmission parameters and the static weights corresponding to the static transmission parameters;
[0137] S540: For each static node in the static CPE topology graph, based on the static index value, determine multiple third candidate paths starting from the static node and ending at the static target node corresponding to the target CPE, in order to construct a pre-built CPE topology graph.
[0138] According to another embodiment of this document, the method of determining the static transmission parameters corresponding to each CPE in S510 is similar to the method of determining the transmission parameters corresponding to each CPE in S210, and will not be repeated here. It should be noted that the difference between static transmission parameters and transmission parameters is that static transmission parameters are parameter data obtained when there is no traffic in the network environment, while transmission parameters are parameter data obtained when there is traffic transmission (i.e., data interaction) in the network environment. The data categories included in static transmission parameters and transmission parameters are, for example, the same.
[0139] For each CPE, determine the corresponding node and, based on the static transmission parameters corresponding to that CPE, determine the connection relationship between the nodes. The specific determination of the connection relationship can be referred to S220, and will not be elaborated on in this manual.
[0140] The method for determining static index values in S530 is similar to that in S230, and will not be described in detail here.
[0141] For each static node in the static CPE topology graph, based on the static index value, multiple third candidate paths are determined, starting from the static node and ending at the target node corresponding to the target CPE. Specifically, for each static node, at least one connecting node directly connected to that node is determined from the static CPE topology graph; based on the index value corresponding to the edge between the static node and each connecting node, multiple next-hop nodes are determined from the at least one connecting node; when the next-hop node is unique and is the static target node, multiple third candidate paths are determined to construct a pre-built CPE topology graph. Specifically, determining multiple next-hop nodes can be done by identifying another node connected to the edge corresponding to the index value of the previous threshold (e.g., the top three ranked nodes in ascending order) as the next-hop node, and repeating this process cyclically until the next-hop node is unique and is the static target node.
[0142] According to another embodiment of this document, for each static node in the static CPE topology graph, determining multiple third candidate paths starting from the static node and ending at the static target node corresponding to the target CPE based on static index values includes: for each static node in the static CPE topology graph, determining multiple optional paths starting from the static node and ending at the target node corresponding to the target CPE; determining a static transmission value corresponding to each optional path based on the static index values; and filtering multiple target static transmission values from the static transmission values, and determining the optional path corresponding to each target static transmission value as the third candidate path.
[0143] The optional path is any communicable path from each static node to the static target node. Determining the static transmission value corresponding to each optional path based on the static index value is similar to determining the transmission value in S4241, and will not be repeated here. Specifically, selecting multiple target static transmission values from the static transmission values can involve determining the static transmission value based on a pre-set position (e.g., the top three values sorted from smallest to largest).
[0144] Figure 6A The diagram shown is a structural schematic of a device access authentication device according to an embodiment of this paper. Figure 6A As shown, including,
[0145] The first determining module 601 is used to determine the transmission parameters corresponding to each CPE in response to receiving an access authentication request, wherein the access authentication request is sent by the requesting CPE among multiple CPEs;
[0146] The judgment and processing module 602 is used to judge and process the connectivity of the edges of the pre-constructed CPE topology graph according to the transmission parameters to obtain the target CPE topology graph. The CPE topology graph includes multiple nodes and multiple edges. The edges are used to connect nodes to represent that they are connected to the two CPEs corresponding to the two connected nodes.
[0147] The second determining module 603 is used to determine the index value of each edge in the target CPE topology graph based on the transmission parameters and the weights corresponding to the transmission parameters.
[0148] The third determining module 604, based on the indicator value, determines the target path in the target CPE topology map, which starts from the request node corresponding to the requesting CPE and ends at the target node corresponding to the target CPE, as the device access authentication path.
[0149] Since the principle of the above-mentioned device in solving the problem is similar to that of the above-mentioned method, the implementation of the above-mentioned device can refer to the implementation of the above-mentioned method, and the repeated parts will not be described again.
[0150] Figure 6BThe diagram shown is a structural schematic of a device access authentication device according to another embodiment of this paper. Figure 6A On the basis of, such as Figure 6B As shown, it also includes,
[0151] The fourth determining module 605 is used to determine the static transmission parameters corresponding to each CPE;
[0152] The first construction module 606 is used to construct a static CPE topology graph based on static transmission parameters. The static CPE topology graph includes multiple static nodes and multiple static edges. Static edges are used to connect static nodes to indicate that they are connected to two static CPEs corresponding to two connected static nodes.
[0153] The fifth determining module 607 is used to determine the static index value of each static edge based on the static transmission parameters and the static weights corresponding to the static transmission parameters.
[0154] The second construction module 608 is used to determine, based on static index values, multiple third candidate paths starting from the static node and ending at the target node corresponding to the target CPE for each static node in the static CPE topology graph, so as to construct a pre-built CPE topology graph.
[0155] Since the principle of the above-mentioned device in solving the problem is similar to that of the above-mentioned method, the implementation of the above-mentioned device can refer to the implementation of the above-mentioned method, and the repeated parts will not be described again.
[0156] like Figure 7 The diagram illustrates the structure of a computer device according to an embodiment of the present invention. The controller in this invention can be the computer device in this embodiment, executing the method described above. The computer device 702 may include one or more processing devices 704, such as one or more central processing units (CPUs), each of which can implement one or more hardware threads. The computer device 702 may also include any storage resource 706 for storing information of any kind, such as code, settings, data, etc. Non-limitingly, for example, the storage resource 706 may include any type of RAM, any type of ROM, flash memory, hard disk, optical disk, etc. More generally, any storage resource can use any technology to store information. Further, any storage resource can provide volatile or non-volatile retention of information. Further, any storage resource can represent a fixed or removable component of the computer device 702. In one case, when the processing device 704 executes associated instructions stored in any storage resource or combination of storage resources, the computer device 702 can perform any operation of the associated instructions. The computer device 702 also includes one or more drive mechanisms 708 for interacting with any storage resource, such as a hard disk drive mechanism, an optical disk drive mechanism, etc.
[0157] Computer device 702 may also include an input / output module 710 (I / O) for receiving various inputs (via input device 712) and providing various outputs (via output device 714). A specific output mechanism may include a presentation device 716 and an associated graphical user interface (GUI) 718. In other embodiments, the input / output module 710 (I / O), input device 712, and output device 714 may be omitted, and the device may function solely as a computer device within a network. Computer device 702 may also include one or more network interfaces 720 for exchanging data with other devices via one or more communication links 722. One or more communication buses 724 couple the components described above together.
[0158] Communication link 722 can be implemented in any way, such as via a local area network, a wide area network (e.g., the Internet), a point-to-point connection, or any combination thereof. Communication link 722 may include any combination of hardwired links, wireless links, routers, gateway functions, name servers, etc., governed by any protocol or combination of protocols.
[0159] Corresponding to Figures 2-5 In addition to the method described above, this embodiment also provides a computer-readable storage medium storing a computer program that is executed by a processor to perform the above steps.
[0160] This embodiment also provides a computer-readable instruction, wherein when the processor executes the instruction, the program therein causes the processor to perform the following: Figures 2-5 The method shown.
[0161] It should be understood that in the various embodiments of this document, the sequence number of each process does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this document.
[0162] It should also be understood that, in the embodiments herein, the term "and / or" is merely a description of the relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Additionally, the character " / " in this document generally indicates that the preceding and following associated objects have an "or" relationship.
[0163] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this document.
[0164] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0165] In the embodiments provided herein, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units described above is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the couplings or direct couplings or communication connections shown or discussed may be indirect couplings or communication connections through some interfaces, apparatuses, or units, or they may be electrical, mechanical, or other forms of connection.
[0166] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of the embodiments described herein, depending on actual needs.
[0167] Furthermore, the functional units in the various embodiments of this document can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0168] If the integrated units described above are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this paper, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this paper. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0169] This document uses specific embodiments to illustrate the principles and implementation methods of this document. The descriptions of the embodiments above are only for the purpose of helping to understand the methods and core ideas of this document. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this document. Therefore, the content of this specification should not be construed as a limitation of this document.
Claims
1. A device access authentication method, characterized in that, Applicable to a system comprising multiple CPEs and an authentication server, wherein the authentication server and the target CPEs are deployed in the same enterprise network, including: In response to receiving an access authentication request, the transmission parameters corresponding to each of the CPEs are determined, wherein the access authentication request is sent by the requesting CPE among the multiple CPEs; Based on the transmission parameters, the connectivity of the edges in the pre-constructed CPE topology graph is determined and processed to obtain the target CPE topology graph. The CPE topology graph includes multiple nodes and multiple edges, and the edges are used to connect nodes to indicate that they are connected to the two CPEs corresponding to the two connected nodes. Based on the transmission parameters and the weights corresponding to the transmission parameters, determine the index value of each edge in the target CPE topology graph; and Based on the aforementioned index values, the target path in the target CPE topology map, starting from the request node corresponding to the requesting CPE and ending at the target node corresponding to the target CPE, is determined as the device access authentication path. Specifically, based on the index values, the transmission value of each second candidate path in the target CPE topology map, starting from the request node corresponding to the requesting CPE and ending at the target node corresponding to the target CPE, is determined. The second candidate path corresponding to the minimum transmission value among the multiple transmission values is then determined as the device access authentication path.
2. The method according to claim 1, characterized in that, The transmission parameters corresponding to the CPE include at least one candidate CPE connected to the CPE, the tunnel delay for communicating with each candidate CPE, the packet loss rate for communicating with each candidate CPE, and the traffic data for communicating with each candidate CPE.
3. The method according to claim 1, characterized in that, The transmission parameters corresponding to the CPE include at least one candidate CPE connected to the CPE, and the packet loss rate for communicating with each candidate CPE. The step of determining and processing the connectivity of edges in a pre-constructed CPE topology graph based on the transmission parameters to obtain the target CPE topology graph includes: For each edge in the first candidate path of the pre-constructed CPE topology graph, starting from the request node and ending at the target node, the packet loss rate corresponding to the edge is determined from the transmission parameters, and it is determined whether the packet loss rate is greater than or equal to a preset threshold; and If the target packet loss rate is determined to be greater than or equal to the preset threshold, the target edge corresponding to the target packet loss rate is disconnected to obtain the target CPE topology graph.
4. The method according to claim 2, characterized in that, The step of determining the index value of each edge in the target CPE topology graph based on the transmission parameters and the weights corresponding to the transmission parameters includes: From the transmission parameters, determine the tunnel delay, packet loss rate, and traffic data corresponding to each edge; and The index value is obtained by weighting the tunnel delay, the packet loss rate, and the traffic data using the weights.
5. The method according to claim 4, characterized in that, The weights include packet loss rate weights and traffic data weights. The step of using these weights to perform a weighted calculation on the tunnel latency, packet loss rate, and traffic data to obtain the indicator value includes: Calculate the product of the packet loss rate weight and the packet loss rate to obtain the first data; Calculate the product of the traffic data weight and the traffic data to obtain the second data; and The index value is obtained by summing the first data, the second data, and the tunnel delay.
6. The method according to claim 1, characterized in that, The step of determining the target path in the target CPE topology map, which starts from the request node corresponding to the requesting CPE and ends at the target node corresponding to the target CPE, as the device access authentication path based on the indicator value includes: Starting from the requesting node, determine at least one first candidate node that is directly connected to the requesting node from the target CPE topology graph; Based on the index value corresponding to the edge connecting the request node and each of the first candidate nodes, a next-hop node is determined from the at least one first candidate node; If it is determined that the next hop node is not the target node, the next hop node is used as the request node, and the step of determining the next hop node is executed repeatedly until the next hop node is the target node, so as to construct the target path based on the request node, all next hop nodes and the target node.
7. The method according to claim 1, characterized in that, The step of determining the transmission values of each second candidate path in the target CPE topology map, starting from the request node corresponding to the requesting CPE and ending at the target node corresponding to the target CPE, based on the indicator values, includes: Based on the index values, determine at least one edge included in each second candidate path starting from the request node and ending at the target node, and the index value corresponding to each edge; and For each of the second candidate paths, the sum of the index values corresponding to each edge included in the second candidate path is determined as the transmission value.
8. The method according to claim 1, characterized in that, The method for constructing the pre-built CPE topology map includes: Determine the static transmission parameters corresponding to each CPE; Based on the static transmission parameters, a static CPE topology graph is constructed, wherein the static CPE topology graph includes multiple static nodes and multiple static edges, and the static edges are used to connect static nodes to indicate that the two static CPEs corresponding to the two connected static nodes are connected. Based on the static transmission parameters and the static weights corresponding to the static transmission parameters, determine the static index value of each static edge; For each static node in the static CPE topology graph, based on the static index value, multiple third candidate paths are determined, starting from the static node and ending at the static target node corresponding to the target CPE, in order to construct the pre-built CPE topology graph.
9. The method according to claim 8, characterized in that, For each static node in the static CPE topology graph, based on the static index value, the determination of multiple third candidate paths starting from the static node and ending at the static target node corresponding to the target CPE includes: For each static node in the static CPE topology graph, determine multiple optional paths starting from the static node and ending at the static target node corresponding to the target CPE; Based on the static index values, determine the static transmission value corresponding to each of the optional paths; and Multiple target static transmission values are selected from the static transmission values, and the optional path corresponding to each target static transmission value is determined as the third candidate path.
10. A device access authentication device, characterized in that, Applicable to a system comprising multiple CPEs and an authentication server, wherein the authentication server and the target CPEs are deployed in the same enterprise network, including: The first determining module is configured to determine the transmission parameters corresponding to each of the CPEs in response to receiving an access authentication request, wherein the access authentication request is sent by the requesting CPE among a plurality of CPEs; The judgment and processing module is used to judge and process the connectivity of the edges of the pre-constructed CPE topology graph according to the transmission parameters to obtain the target CPE topology graph, wherein the CPE topology graph includes multiple nodes and multiple edges, and the edges are used to connect nodes to indicate that they are connected to the two CPEs corresponding to the two connected nodes. The second determining module is used to determine the index value of each edge in the target CPE topology graph based on the transmission parameters and the weights corresponding to the transmission parameters. The third determining module, based on the indicator value, determines the target path in the target CPE topology map, starting from the request node corresponding to the requesting CPE and ending at the target node corresponding to the target CPE, as the device access authentication path. Specifically, based on the indicator value, it determines the transmission value of each second candidate path in the target CPE topology map, starting from the request node corresponding to the requesting CPE and ending at the target node corresponding to the target CPE; and determines the second candidate path corresponding to the minimum transmission value among the multiple transmission values as the device access authentication path.
11. The apparatus according to claim 10, characterized in that, Also includes: The fourth determining module is used to determine the static transmission parameters corresponding to each CPE; The first construction module is used to construct a static CPE topology graph based on the static transmission parameters. The static CPE topology graph includes multiple static nodes and multiple static edges. The static edges are used to connect static nodes to indicate that the two static CPEs corresponding to the two connected static nodes are connected. The fifth determining module is used to determine the static index value of each static edge based on the static transmission parameters and the static weights corresponding to the static transmission parameters. The second construction module is used to determine, based on the static index value, multiple third candidate paths starting from the static node and ending at the static target node corresponding to the target CPE for each static node in the static CPE topology map, so as to construct the pre-constructed CPE topology map.
12. A device access authentication system, characterized in that, The system includes multiple CPEs, an authentication server, and a central controller, wherein the authentication server and the target CPEs are deployed in the same enterprise network, and the multiple CPEs can communicate with each other and each CPE can communicate with the central controller, including: The CPE is used to receive user access authentication requests sent by user terminals and to send transmission data to the central controller; when the CPE receives a user access authentication request, it processes the user access authentication request to obtain an access authentication request and sends the access authentication request to the central controller. The central controller is used to receive the access authentication request, determine the transmission parameters corresponding to each CPE; perform edge connectivity judgment and processing on a pre-constructed CPE topology graph according to the transmission parameters to obtain a target CPE topology graph, wherein the CPE topology graph includes multiple nodes and multiple edges, the edges are used to connect nodes to represent that they are connected to two CPEs corresponding to two connected nodes; determine the index value of each edge in the target CPE topology graph according to the transmission parameters and the weights corresponding to the transmission parameters; based on the index values, determine the target path in the target CPE topology graph that starts from the request node corresponding to the requesting CPE and ends at the target node corresponding to the target CPE as the device access authentication path, wherein, based on the index values, determine the transmission value of each second candidate path in the target CPE topology graph that starts from the request node corresponding to the requesting CPE and ends at the target node corresponding to the target CPE; determine the second candidate path corresponding to the minimum transmission value among the multiple transmission values as the device access authentication path; determine the transmission CPE corresponding to each node included in the device access authentication path, and send the device access authentication path to each transmission CPE; and The transmission CPE is used to receive the device access authentication path in order to transmit authentication data of the user terminal that sent the user access authentication request.
13. The system according to claim 12, characterized in that, Also includes: Each of the CPEs sends static transmission data to the central controller; The central controller is further configured to receive static transmission parameters corresponding to each CPE; construct a static CPE topology graph based on the static transmission parameters, wherein the static CPE topology graph includes multiple static nodes and multiple static edges, the static edges being used to connect static nodes to represent connections to two static CPEs corresponding to two connected static nodes; determine a static index value for each static edge based on the static transmission parameters and the static weights corresponding to the static transmission parameters; and for each static node in the static CPE topology graph, determine multiple third candidate paths starting from the static node and ending at a static target node corresponding to the target CPE based on the static index value, in order to construct the pre-constructed CPE topology graph.
14. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method described in any one of claims 1 to 9.
15. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the method described in any one of claims 1 to 9.
Citation Information
Patent Citations
Communication method, device and system
CN110582085A
Service data transmission method and device
CN111343093A
Network topology path calculation method, apparatus and device, and readable storage medium
CN116938794A