An authentication method and device, electronic equipment and storage medium

By introducing multi-layered network isolation, including access authentication domains and device management service domains, and utilizing single-packet authentication ports and random port mechanisms, the problem of network device port information leakage in open network environments is solved. This enables secure and controllable access to the device management service domain, improving the security and management convenience of network devices.

CN118611937BActive Publication Date: 2025-11-25CHINA UNITED NETWORK COMM GRP CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410742903.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-07
Publication Date
2025-11-25
Estimated Expiration
2044-06-07

AI Technical Summary

Technical Problem

In open network environments, port information of network devices is easily leaked, leading to security risks. Existing secure access management solutions have limitations and cannot effectively protect the security of the device management service domain.

Method used

By receiving authentication requests through the access authentication domain, determining the single-packet authentication port of the firewall, sending authentication messages to the device management service domain, and opening random ports after the user device is successfully authenticated, the single-packet authentication service is used for network isolation and authentication to ensure secure access to the device management service domain.

Benefits of technology

It enables secure and accurate access to the device management service domain in an open network environment, prevents port exposure in unauthenticated situations, improves the security and management convenience of network devices, and avoids network security threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118611937B_ABST
    Figure CN118611937B_ABST
Patent Text Reader

Abstract

The application discloses an authentication method and device, electronic equipment and a storage medium, and relates to the field of network security. The method is applied to a network device and includes the following steps: receiving an authentication request from a user device through an access authentication domain; determining a single packet authentication port of a firewall setting through the access authentication domain, and sending an authentication message to a device management service domain through the single packet authentication port, where the authentication message is used for authenticating the user device; in the case that the user is authenticated, opening a random port on the firewall, and sending authentication passing information to the user device through the random port, so that the user device accesses the network through the random port.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security, specifically to an authentication method, device, electronic device, and storage medium. Background Technology

[0002] Protecting network devices (such as switches and routers) from exposure in open network environments like the Internet has always been a key focus in the field of network security. As the importance of network security continues to grow, the secure access management of network devices is becoming increasingly crucial.

[0003] Currently, user devices can access network devices through open networks. However, in open network environments, when user devices access network devices, the port information of the network devices is easily leaked, which may lead to other devices using the same port to continue accessing the network devices, thus posing security risks. Summary of the Invention

[0004] This application provides an authentication method, apparatus, electronic device, and storage medium to improve the security of user equipment when accessing network devices.

[0005] To achieve the above objectives, this application adopts the following technical solution:

[0006] Firstly, an authentication method is provided, applied to a network device. The network device includes an access authentication domain and a device management service domain, which are isolated by multiple layers of network and further separated by a firewall. The method includes: receiving an authentication request from a user device through the access authentication domain; determining the single-packet authentication port configured on the firewall through the access authentication domain, and sending an authentication message to the device management service domain through the single-packet authentication port, the authentication message being used to authenticate the user device; and, if the user device is successfully authenticated, opening a random port on the firewall and sending authentication success information to the user device through the random port, enabling the user device to access the network through the random port.

[0007] In this application, authentication requests from user devices are received through an access authentication domain. The access authentication domain determines the single-packet authentication port configured on the firewall, and an authentication message is sent to the device management service domain through this port. This authentication message is used to authenticate the user device. If the user device is successfully authenticated, a random port is opened on the firewall, and authentication success information is sent to the user device through this random port, enabling the user device to access the network through the random port. Therefore, compared to current methods for accessing network devices deployed in open networks, the technical solution of this application can achieve more secure and accurate access to the device management service domain.

[0008] In one possible implementation, the above-mentioned "determining the single-packet authentication port set by the access authentication domain" specifically includes: determining the authentication port number of the firewall by the access authentication domain, and determining the single-packet authentication port set by the firewall based on the authentication port number.

[0009] In one possible implementation, the aforementioned "authentication message is an SPA message" specifically includes: controlling the access authentication domain to encrypt a preset key and a random number using a preset encryption algorithm to obtain an SPA key; encapsulating preset parameters based on the SPA to obtain an SPA message, wherein the preset parameters include one or more of the following: SPA key, user equipment identifier, random number, timestamp, user equipment IP address, and authentication port number.

[0010] In one possible implementation, the aforementioned "device management service domain has single packet authentication service and management interface service, the single packet authentication service is used to authenticate user equipment, and the management interface service is used to provide network access service for user equipment; sending authentication messages to the device management service domain through the single packet authentication port" specifically includes: sending authentication messages to the knocking port corresponding to the single packet authentication service through the single packet authentication port; the knocking port is the port set up by the single packet authentication service for receiving authentication messages.

[0011] In one possible implementation, a password is generated using a time-based one-time password algorithm through the single-packet authentication port in the firewall, and a first hash value is obtained after hashing the password; the received authentication message is hashed through the single-packet authentication service to obtain a second hash value; if the first hash value and the second hash value match, the user equipment authentication is confirmed to be successful.

[0012] In one possible implementation, the above-mentioned "opening a random port on the firewall when the user equipment is successfully authenticated" specifically includes: sending an indication message to the firewall when the user equipment is successfully authenticated; the indication message is used to indicate that the user equipment has been successfully authenticated; and receiving a response message from the firewall, the response message being used to indicate the random port.

[0013] In one possible implementation, the random port is closed after the user device finishes accessing the device.

[0014] Secondly, an authentication device is provided for use in network equipment. This authentication device can implement the authentication methods described above or in various possible designs. For example, the authentication device may have the function of executing the aforementioned authentication methods, which can be implemented by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the aforementioned functions. For example, the authentication device includes a control unit and a processing unit.

[0015] The control unit is used to receive authentication requests from user equipment through the access authentication domain.

[0016] The control unit is also used to determine the single-packet authentication port configured by the access authentication domain, and send authentication messages to the device management service domain through the single-packet authentication port. The authentication messages are used to authenticate the user equipment.

[0017] The processing unit is used to open a random port on the firewall when the user equipment is successfully authenticated, and send authentication information to the user equipment through the random port so that the user equipment can access the network through the random port.

[0018] In one possible implementation, the control unit is specifically used to determine the firewall's authentication port number through the access authentication domain, and to determine the open single-packet authentication port set by the firewall based on the authentication port number. The control unit encrypts a preset key and a random number using a preset encryption algorithm to obtain an SPA key; it then encapsulates preset parameters based on the SPA to obtain an SPA message. The preset parameters include one or more of the following: the SPA key, the user equipment identifier, the random number, the timestamp, the user equipment's IP address, and the authentication port number. The unit then sends an authentication message to the doorknocking port corresponding to the guaranteed authentication service through the open single-packet authentication port; the doorknocking port is the port set by the single-packet authentication service to indicate the port for receiving authentication messages.

[0019] In one possible implementation, the processing unit is specifically configured to generate a password using a time-based one-time cipher algorithm through a single-packet authentication port in the firewall, and perform a hash operation on the password to obtain a first hash value; perform a hash operation on the received authentication message through a single-packet authentication service to obtain a second hash value; if the first hash value and the second hash value match, the user equipment authentication is deemed successful. If the user equipment authentication is successful, an indication message is sent to the firewall to indicate successful authentication; the indication message indicates successful authentication; and a response message is received from the firewall, which indicates the random port. After the user equipment access ends, the random port is closed.

[0020] The specific implementation of this authentication device can be found in the processing methods provided in the first aspect or any possible design of the first aspect, and will not be repeated here. Therefore, the provided authentication device can achieve the same beneficial effects as the first aspect or any possible design of the first aspect.

[0021] Thirdly, an electronic device is provided. This electronic device can perform the functions described in the above aspects or possible designs. These functions can be implemented in hardware. For example, in one possible design, the electronic device may include a processor and a communication interface. The processor can be used to support the electronic device in performing the functions described in the first aspect or any possible design of the first aspect.

[0022] In another possible design, the electronic device may further include a memory for storing necessary computer execution instructions and data. When the electronic device is running, the processor executes the computer execution instructions stored in the memory to cause the electronic device to perform the first aspect or any of the possible authentication methods involved in the first aspect.

[0023] Fourthly, a computer-readable storage medium is provided, which may be a readable non-volatile storage medium storing computer instructions or programs that, when executed on a computer, enable the computer to perform the authentication methods described in the first aspect or any of the possible methods described above.

[0024] Fifthly, a computer program product containing instructions is provided, which, when run on a computer, enables the computer to perform the authentication methods described in the first aspect or any of the aforementioned aspects.

[0025] Sixthly, a chip system is provided, including a processor and a communication interface, which can be used to implement the functions performed by the first aspect or any possible determination device of the first aspect. In one possible design, the chip system further includes a memory for storing program instructions and / or data. The chip system may be composed of chips or may include chips and other discrete devices, without limitation.

[0026] The technical effects of any of the design methods in aspects two through six are similar to those in aspect one, and will not be repeated here. Attached Figure Description

[0027] Figure 1 This application provides a schematic diagram of the structure of a network device according to an embodiment of the present application.

[0028] Figure 2 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application;

[0029] Figure 3 A flowchart illustrating an authentication method provided in an embodiment of this application;

[0030] Figure 4 A flowchart illustrating another authentication method provided in an embodiment of this application;

[0031] Figure 5 A flowchart illustrating another authentication method provided in an embodiment of this application;

[0032] Figure 6A flowchart illustrating another authentication method provided in an embodiment of this application;

[0033] Figure 7 This is a schematic diagram of the structure of an authentication device provided in an embodiment of this application. Detailed Implementation

[0034] To enable those skilled in the art to better understand the technical solutions of this disclosure, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings.

[0035] It should be noted that the terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this disclosure described herein can be implemented in orders other than those illustrated or described herein. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this disclosure. Rather, they are merely examples of apparatuses and methods consistent with some aspects of the embodiments of this application as detailed in the appended claims.

[0036] It should also be understood that the term "comprising" indicates the presence of the described feature, whole, step, operation, element and / or component, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements and / or components.

[0037] The system architecture and business scenarios described in the embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the emergence of new business scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.

[0038] Protecting network devices (switches, routers, etc.) from exposure in open network environments such as the Internet has always been a key focus in the field of network security. With the increasing emphasis on network security, the secure access management of network devices is becoming increasingly important. Currently, the main types of secure access management solutions for network devices are as follows:

[0039] (1) Service interfaces are only open to open network environments such as the Internet. The management interface of the network device is physically isolated from the open network environment of the service interface. Users must be inside the network device management network or access the network device management network through VPN or other means to access the network device management interface.

[0040] (2) Open management interfaces in open network environments such as the Internet, but adopt stricter security measures, such as setting up IP whitelists and using security certificate login.

[0041] The above solutions all have certain limitations:

[0042] (1) The method of managing network access by network devices limits the convenience of managing network devices and collecting information;

[0043] (2) Using VPN access devices to manage the network increases investment costs and requires network management users to install VPN software, which is inconvenient. In addition, if business management regulations do not allow VPN access in the network management network, this method cannot be used.

[0044] (3) The approach of opening the management interface but strengthening the access security policy is problematic because the management interface is exposed in the open network, which poses a greater risk of network security threats. In most cases, this approach is restricted by business management regulations and cannot be adopted.

[0045] In view of this, embodiments of this application provide an authentication method, which is applied to a network device, and the method includes:

[0046] The system receives authentication requests from user devices through the access authentication domain; determines the single-packet authentication port configured on the firewall through the access authentication domain, and sends an authentication message to the device management service domain through the single-packet authentication port. The authentication message is used to authenticate the user device; if the user device is successfully authenticated, a random port is opened in the firewall, and authentication success information is sent to the user device through the random port, so that the user device can access the network through the random port.

[0047] Thus, when a user device authenticates through the access authentication domain, the firewall authenticates the user device's authentication request through a dynamic single-packet authentication port. Since the single-packet authentication service does not return any data packets to the interface proxy service program and the user when SPA authentication fails, the network device can avoid exposing any network ports without authentication. This ensures network isolation between the device's core system and the authentication program during the authentication process, and guarantees secure and controllable user access after authentication is completed.

[0048] In one example, such as Figure 1 The diagram shown is a structural schematic of a network device according to an embodiment of this application. The network device may include an access authentication domain and a device management service domain. The access authentication domain and the device management service domain are isolated by a Layer 2 network, and a firewall is also installed between them.

[0049] The access authentication domain can be used to receive authentication requests from user devices and determine the Single Packet Authentication (SPA) port configured on the firewall.

[0050] The Device Management Service domain can be used to authenticate user devices upon receiving authentication messages, and provide management interface services for users to access if the user device is successfully authenticated.

[0051] In one example, such as Figure 1 As shown, the access authentication domain can include interface proxy services.

[0052] Among them, the interface proxy service can be used to calculate the SPA key by using a preset key and a random number during user authentication, and package it together with the user device's identifier, random number, timestamp, and authentication port number into an authentication message, and send it to the single packet authentication service in the device management service domain.

[0053] In one example, such as Figure 1 As shown, the device management service domain can include single-package authentication service and management interface service.

[0054] Among them, the single packet authentication service can be used to authenticate user equipment by receiving authentication messages through the knocking port to determine whether the user equipment authentication is successful; the management interface service can be used to provide network access services to user equipment.

[0055] Figure 1 The network device shown can be used Figure 2 The shown composition structure, or including Figure 2 The components shown. Figure 2 This is a schematic diagram illustrating the composition of an electronic device 200 provided in an embodiment of this application. The electronic device 200 can be a chip or a system-on-a-chip in a server. For example... Figure 2 As shown, the electronic device 200 includes a processor 201, a communication interface 202, and a communication line 203.

[0056] Furthermore, the electronic device 200 may also include a memory 204. The processor 201, memory 204, and communication interface 202 can be connected via a communication line 203.

[0057] The processor 201 can be a CPU, a general-purpose processor, a network processor (NP), a digital signal processor (DSP), a microprocessor, a microcontroller, a programmable logic device (PLD), or any combination thereof. The processor 201 can also be other devices with processing capabilities, such as circuits, devices, or software modules, without limitation.

[0058] Communication interface 202 is used to communicate with other devices or other communication networks. These other communication networks can be Ethernet, radio access network (RAN), wireless local area networks (WLAN), etc. Communication interface 202 can be a module, circuit, communication interface, or any device capable of enabling communication.

[0059] Communication line 203 is used to transmit information between the various components included in electronic device 200.

[0060] Memory 204 is used to store instructions. These instructions can be computer programs.

[0061] The memory 204 can be a read-only memory (ROM) or other type of static storage device that can store static information and / or instructions; it can also be a random access memory (RAM) or other type of dynamic storage device that can store information and / or instructions; it can also be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, etc., without limitation.

[0062] It should be noted that the memory 204 can exist independently of the processor 201 or can be integrated with the processor 201. The memory 204 can be used to store instructions, program code, or some data, etc. The memory 204 can be located inside or outside the electronic device 200, without limitation. The processor 201 is used to execute the instructions stored in the memory 204 to implement the field configuration method provided in the following embodiments of this application.

[0063] In one example, processor 201 may include one or more CPUs, for example, Figure 2 CPU0 and CPU1 in the CPU.

[0064] As an optional implementation, the electronic device 200 includes multiple processors, for example, besides Figure 2 In addition to processor 201, it may also include processor 207.

[0065] As an optional implementation, the electronic device 200 also includes an output device 205 and an input device 206. For example, the input device 206 is a device such as a keyboard, mouse, microphone, or joystick, and the output device 205 is a device such as a display screen or speaker.

[0066] It should be noted that electronic device 200 can be a desktop computer, laptop computer, network server, mobile phone, tablet computer, wireless terminal, embedded device, chip system, or something else. Figure 2 Equipment with a similar structure. Furthermore... Figure 2 The composition shown does not constitute a basis for this. Figure 1 The limitations of each device in the process, except Figure 2 In addition to the components shown, Figure 1 The device may include more or fewer components than illustrated, or combine certain components, or have different component arrangements.

[0067] In this embodiment of the application, the chip system may be composed of chips or may include chips and other discrete devices.

[0068] Furthermore, the actions, terms, etc., involved in the various embodiments of this application can be referenced interchangeably without limitation. The message names or parameter names in the messages exchanged between the various devices in the embodiments of this application are merely examples, and other names may be used in specific implementations without limitation.

[0069] To facilitate a clear description of the technical solutions in the embodiments of this application, the terms "first" and "second" are used in the embodiments of this application to distinguish identical or similar items with essentially the same function and effect. Those skilled in the art will understand that the terms "first" and "second" do not limit the quantity or execution order, and the terms "first" and "second" are not necessarily different.

[0070] It should be noted that, in this application, the terms "exemplary" or "for example" are used to indicate that something is being described as an example, illustration, or illustration. Any embodiment or design described as "exemplary" or "for example" in this application should not be construed as being more preferred or advantageous than other embodiments or design solutions. Specifically, the use of terms such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.

[0071] In this application, "at least one" means one or more, and "more than one" means two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can mean: A alone, A and B simultaneously, or B alone, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple.

[0072] The following is combined Figure 1 The network device shown illustrates the authentication method provided in the embodiments of this application. The actions, terminology, etc., involved in the various embodiments of this application can be referenced interchangeably without limitation. The message names or parameter names in the messages exchanged between devices in the embodiments of this application are merely examples; other names may be used in specific implementations without limitation. The actions involved in the various embodiments of this application are merely examples; other names may be used in specific implementations. For example, "included in" in the embodiments of this application can be replaced with "carried on" or "carried in," etc.

[0073] It should be noted that the executing entity of this application embodiment can be... Figure 1 The network device mentioned can also be a component within the network device, such as a chip or a system-on-a-chip. The following description uses a network device as an example to illustrate the method provided in the embodiments of this application.

[0074] Figure 3 This is a flowchart illustrating an authentication method according to an exemplary embodiment, such as... Figure 3 As shown, the authentication method includes the following steps:

[0075] S301. Network devices receive authentication requests from user devices through the access authentication domain.

[0076] The access authentication domain is a separate layer network within this network device. This domain has the following characteristics: it is completely isolated from the device management service domain on the Layer 2 network; communication between it and the device management service domain is isolated by a firewall; only the interface proxy service runs in the access authentication domain, which can proxy user devices' access to the network device to the device management service domain; the access authentication domain does not store any data or configuration information.

[0077] Specifically, the authentication request is an authentication request from the user equipment to the network device through an open network.

[0078] In one example, a user equipment initiates an authentication request to a network device in an open network. For instance, the user enters a username and password from the user equipment; the access authentication domain receives the authentication request through an interface proxy service.

[0079] S302. The network device determines the single-packet authentication port configured in the firewall through the access authentication domain, and sends authentication messages to the device management service domain through the single-packet authentication port.

[0080] The authentication message is used to authenticate the user equipment. The authentication message is an SPA message, which is generated based on a random number-based one-time password (HMAC-based One-Time Password, HOTP) algorithm. For details, please refer to... Figure 4 The description of the embodiments shown is omitted here.

[0081] In one possible implementation, the network device can determine the firewall's authentication port number by accessing the authentication domain, and then determine the single-packet authentication port set by the firewall based on the authentication port number.

[0082] The authentication port number indicates the single-packet authentication port configured in the firewall. This single-packet authentication port is used to send authentication messages to the device management service domain.

[0083] In one example, a network device can generate a port number using a preset encryption algorithm through an access authentication domain, and use that port number as the authentication port number for the firewall.

[0084] The preset encryption algorithm can be a one-time password (TOTP) algorithm.

[0085] In another possible implementation, after determining the firewall's authentication port number, the network device can determine the firewall's single-packet authentication port based on that port number and send an authentication message to that single-packet authentication port. After passing through the single-packet authentication port, the firewall can send an authentication message to the device management service domain based on a preset knocking port.

[0086] The knock port is set up based on the single-package authentication service in the device management service domain.

[0087] In one example, the firewall can use the TOTP algorithm to calculate timestamps, user device IP addresses, etc., to generate a temporary password. This temporary password is then hashed to obtain a first hash value. This first hash value can be used as the port number for the knocking port.

[0088] It should be noted that, in this embodiment of the application, in order to ensure port security, the temporary password and port number in the single-packet authentication port opened in the firewall can be updated periodically.

[0089] S303. If the user equipment is successfully authenticated, open a random port on the firewall and send authentication information to the user equipment through the random port so that the user equipment can access the network through the random port.

[0090] The random port is used by user devices to access the device management interface in the device management service domain.

[0091] In one possible implementation, after generating a first hash value through the firewall, the network device can perform a hash operation on the received authentication message using a single-packet authentication service to obtain a second hash value. For example, the single-packet authentication service can calculate the SPA key based on the timestamp in the received SPA message, the user device's IP address, and the service password stored internally by the single-packet authentication service, and then perform a hash operation on the SPA key to obtain the second hash value.

[0092] If the first hash value and the second hash value match, the user equipment authentication is successful. If the first hash value and the second hash value do not match, the user equipment authentication fails.

[0093] In one possible implementation, when the user equipment is successfully authenticated, the network device sends an instruction message to the firewall through the device management service domain; correspondingly, the network device receives a response message from the firewall through the device management service domain.

[0094] The indication information is used to indicate that the user equipment has been successfully authenticated; the response message is used to indicate the random port.

[0095] In this embodiment of the application, when the user equipment is successfully authenticated, the network device can notify the firewall to open a random port and send information indicating the random port to the access authentication domain through the knocking port, so that when the access authentication domain receives the user equipment's access request, it can send the access request to the device management service domain through the random port.

[0096] In this embodiment, the firewall may be configured with a whitelist. This whitelist includes address information for the access authentication domain. That is, when the firewall receives an access request forwarded from another domain, it will not open a random port. Alternatively, based on this whitelist, the firewall may only open a single-packet authentication port for the access authentication domain; if the user equipment authentication is successful, the firewall may open a random port for the access authentication domain.

[0097] In one example, an interface proxy service can be used to proxy management ports such as SSH / HTTP. For instance, the interface proxy service can proxy user device access to random ports opened by the firewall, enabling the user device to access the device management interface in the device management service domain through these random ports.

[0098] In one example, if a user device terminates its management session or times out, the management interface service can instruct the firewall to close any open random ports.

[0099] based on Figure 3 In this technical solution, the network device receives authentication requests from user devices through an access authentication domain. The network device determines the single-packet authentication port configured on the firewall through the access authentication domain and sends an authentication message to the device management service domain through this port. If the user device successfully authenticates, a random port is opened on the firewall, and authentication success information is sent to the user device through this random port, enabling the user device to access the network. Thus, compared to current methods for accessing network devices deployed in open networks, this technical solution provides a more secure and accurate way to access the device management interface in the device management service domain.

[0100] In some embodiments, such as Figure 4 As shown, the authentication method provided in this application embodiment may further include: S401-S402.

[0101] S401. The network device control access authentication domain uses a preset encryption algorithm to encrypt a preset key and a random number to obtain the SPA key.

[0102] In one example, the interface proxy service in the access authentication domain calculates the SPA key using a preset key and a random number, based on a one-time password algorithm using the random number, during user authentication.

[0103] S402. The network device encapsulates the preset parameters based on the SPA to obtain the SPA message.

[0104] In one example, the interface proxy service in the access authentication domain encapsulates the SPA key with preset parameters to obtain the SPA message.

[0105] The preset parameters include one or more of the following: SPA key, user equipment identifier, random number, timestamp, user equipment IP address, and authentication port number.

[0106] based on Figure 4 In this technical solution, the network device controls the access authentication domain by encrypting a preset key and a random number using a preset encryption algorithm to obtain an SPA key; the network device then encapsulates preset parameters based on the SPA to obtain the SPA message. This allows for accurate acquisition of user equipment authentication requests.

[0107] In one embodiment, such as Figure 5 As shown, the authentication method provided in this application may include:

[0108] S501. The user equipment sends an authentication request to the access authentication domain. Correspondingly, the access authentication domain receives the authentication request from the user equipment.

[0109] S502. The access authentication domain encapsulates the received authentication request to obtain an SPA message, and sends the SPA message to the single-packet authentication service through the firewall's single-packet authentication port. Correspondingly, the single-packet authentication service receives the SPA message from the access authentication domain.

[0110] The SPA message includes relevant information about the user equipment, such as the user equipment's IP address and the timestamp corresponding to when the user equipment sent the authentication request.

[0111] S503, the single-packet authentication service parses the SPA message and authenticates the user equipment based on the parsed SPA message.

[0112] S504. When the user equipment is successfully authenticated, the single-packet authentication service sends authentication success information to the access authentication domain through a random port.

[0113] The specific implementation methods and technical effects of S501 to S504 can be referred to the description of the above embodiments, and will not be repeated here.

[0114] In one embodiment, such as Figure 6 As shown, the authentication method provided in this application may also include:

[0115] S601. Network devices open single-packet authentication ports through firewalls.

[0116] S602. Network devices receive authentication requests from user devices through the access authentication domain.

[0117] S603. The access authentication domain encapsulates the received authentication request to obtain an SPA message, and sends the SPA message to the single-packet authentication service in the device management service domain through the single-packet authentication port in the firewall. Correspondingly, the single-packet authentication service receives the SPA message from the access authentication domain.

[0118] S604. The single-packet authentication service parses the SPA message and authenticates the user equipment based on the parsed SPA message.

[0119] S605. When the user equipment is successfully authenticated, the network device sends the first instruction information to the firewall through the single packet authentication service; accordingly, the firewall receives the first instruction information from the single packet authentication service and opens a random port.

[0120] The first instruction information is used to instruct the firewall to open random ports.

[0121] S606. Network devices send a random port number of the firewall to the access authentication domain through the single packet authentication service; correspondingly, the access authentication domain receives the random port number sent by the single packet authentication service.

[0122] S607. Network devices send authentication pass information to user equipment through the access authentication domain.

[0123] S608. User equipment accesses the management interface service in the device management service domain through a random port of the firewall.

[0124] S609. The user equipment terminates its access to the network device.

[0125] S610: The network device sends a second instruction to the firewall through the management interface service; accordingly, the firewall receives the second instruction from the management interface service and closes the random port.

[0126] The second instruction is used to instruct the firewall to close random ports.

[0127] The specific implementation methods and technical effects of S601 to S610 can be referred to the description of the above embodiments, and will not be repeated here.

[0128] This application embodiment can divide the field query device into functional modules or functional units according to the above method example. For example, each function can be divided into a separate functional module or functional unit, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or in software functional modules or functional units. The module or unit division in this application embodiment is illustrative and only represents one logical functional division; other division methods may be used in actual implementation.

[0129] When each function is assigned to a specific functional module, Figure 7 A schematic diagram of an authentication device 70 is shown, which can be used to perform the authentication method in the above embodiments. Figure 7 The authentication device 70 shown may include: a control unit 701 and a processing unit 702.

[0130] Control unit 701 is used to receive authentication requests from user equipment through an access authentication domain.

[0131] The control unit 701 is also used to determine the single-packet authentication port set by the access authentication domain, and send an authentication message to the device management service domain through the single-packet authentication port. The authentication message is used to authenticate the user equipment.

[0132] The processing unit 702 is used to open a random port on the firewall when the user equipment is successfully authenticated, and send authentication success information to the user equipment through the random port so that the user equipment can access the network through the random port.

[0133] In one possible implementation, the control unit 701 is specifically used to determine the firewall's authentication port number through the access authentication domain, and to determine the single-packet authentication port set by the firewall based on the authentication port number. A preset key and a random number are encrypted using a preset encryption algorithm through the access authentication domain to obtain an SPA key; preset parameters are encapsulated using the SPA to obtain an SPA message. The preset parameters include one or more of the following: the SPA key, the user equipment identifier, the random number, the timestamp, the user equipment's IP address, and the authentication port number. An authentication message is sent to the knocking port corresponding to the guaranteed authentication service through the single-packet authentication port; the knocking port is the port set by the single-packet authentication service to indicate the port for receiving authentication messages.

[0134] In one possible implementation, processing unit 702 is specifically configured to generate a password using a time-based one-time cipher algorithm through the single-packet authentication port in the firewall, and perform a hash operation on the password to obtain a first hash value; calculate an SPA key using the timestamp in the received authentication message, the user device's IP address, and the service password stored internally by the single-packet authentication service, and perform a hash operation on the SPA key to obtain a second hash value; if the first hash value matches the second hash value, the user device authentication is deemed successful. If the user device authentication is successful, an indication message is sent to the firewall to indicate successful authentication; a response message is received from the firewall, indicating the random port. After the user device access ends, the random port is closed.

[0135] This application also provides a computer-readable storage medium. All or part of the processes in the above method embodiments can be implemented by a computer program instructing related hardware. This program can be stored in the computer-readable storage medium, and when executed, it can include the processes of the above method embodiments. The computer-readable storage medium can be an internal storage unit of the authentication device (including a data sender and / or a data receiver) of any of the foregoing embodiments, such as the hard disk or memory of the authentication device. The computer-readable storage medium can also be an external storage device of the terminal device, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc., equipped on the terminal device. Further, the computer-readable storage medium can include both the internal storage unit of the authentication device and an external storage device. The computer-readable storage medium is used to store the computer program and other programs and data required by the authentication device. The computer-readable storage medium can also be used to temporarily store data that has been output or will be output.

[0136] It should be noted that the terms "first" and "second," etc., in the specification, claims, and drawings of this application are used to distinguish different objects, not to describe a specific order. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to these processes, methods, products, or apparatuses.

[0137] It should be understood that in this application, "at least one (item)" means one or more, "more than one" means two or more, "at least two (items)" means two or three or more, and "and / or" is used to describe the relationship between related objects, indicating that there can be three relationships. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the related objects before and after are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.

[0138] Through the above description of the embodiments, those skilled in the art can clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.

[0139] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another device, or some features may be ignored or not executed. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.

[0140] The units described as separate components may or may not be physically separate. A component shown as a unit can be one or more physical units; that is, it can be located in one place or distributed in multiple different locations. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0141] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0142] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solutions of the embodiments of this application, essentially, or the parts that contribute to the prior art, or all or part of the technical solutions, can be embodied in the form of a software product. This software product is stored in a storage medium and includes several instructions to cause a device (which may be a microcontroller, chip, etc.) or processor to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.

[0143] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any changes or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. An authentication method, characterized in that, The method is applied to network devices, which include an access authentication domain and a device management service domain. The access authentication domain and the device management service domain are isolated by multiple layers of network, and a firewall is also installed between them. The device management service domain has a single-packet authentication service and a management interface service. The single-packet authentication service is used to authenticate user devices, and the management interface service is used to provide network access services to the user devices. Authentication requests from user devices are received through the access authentication domain; The authentication port number of the firewall is determined by the access authentication domain, and the single packet authentication port set by the firewall is determined based on the authentication port number. An authentication message is sent to the door-knocking port corresponding to the single-packet authentication service through the single-packet authentication port; the door-knocking port is a port set up by the single-packet authentication service for receiving authentication messages, and the authentication message is used to authenticate the user equipment, and the authentication message is an SPA message; If the user equipment is successfully authenticated, a random port is opened on the firewall, and authentication information is sent to the user equipment through the random port, so that the user equipment can access the network through the random port. The access authentication domain is controlled to encrypt a preset key and a random number using a preset encryption algorithm to obtain the SPA key; The SPA message is obtained by encapsulating preset parameters based on the SPA. The preset parameters include one or more of the following: the SPA key, the identifier of the user equipment, the random number, the timestamp, the IP address of the user equipment, and the authentication port number.

2. The method according to claim 1, characterized in that, The method further includes: A password is generated using a time-based one-time password algorithm through the single-packet authentication port in the firewall, and a first hash value is obtained by hashing the password. The received authentication message is hashed using the single-packet authentication service to obtain a second hash value; If the first hash value matches the second hash value, the user equipment authentication is deemed successful.

3. The method according to claim 1, characterized in that, The step of opening a random port on the firewall when the user equipment authentication is successful includes: If the user equipment authentication is successful, an indication message is sent to the firewall; the indication message is used to indicate that the user equipment authentication is successful. Receive a response message from the firewall, the response message indicating the random port.

4. The method according to claim 3, characterized in that, The method further includes: After the user equipment access ends, the random port is closed.

5. An authentication device, characterized in that, The device is applied to network equipment, which includes an access authentication domain and a device management service domain. The access authentication domain and the device management service domain are isolated by multiple layers of network, and a firewall is also provided between them. The device management service domain has a single packet authentication service and a management interface service. The single packet authentication service is used to authenticate user equipment, and the management interface service is used to provide network access services for the user equipment. The device includes a control unit and a processing unit. The control unit is configured to receive authentication requests from user equipment through the access authentication domain; The control unit is further configured to determine the authentication port number of the firewall through the access authentication domain, and determine the single-packet authentication port set by the firewall according to the authentication port number; and send an authentication message to the knocking port corresponding to the single-packet authentication service through the single-packet authentication port. The knock port is a port set up by the single packet authentication service for receiving authentication messages. The authentication messages are used to authenticate the user equipment and are SPA messages. The processing unit is configured to, upon successful authentication of the user equipment, open a random port on the firewall and send authentication success information to the user equipment through the random port, thereby enabling the user equipment to access the network through the random port. The control unit is also used to control the access authentication domain to encrypt a preset key and a random number using a preset encryption algorithm to obtain an SPA key; The control unit is further configured to encapsulate preset parameters based on the SPA to obtain the SPA message. The preset parameters include one or more of the following: the SPA key, the identifier of the user equipment, the random number, the timestamp, the IP address of the user equipment, and the authentication port number.

6. An electronic device, characterized in that, include: A processor, a memory, and a communication interface; wherein the communication interface is used for communication of the electronic device; The memory is used to store one or more programs, the one or more programs including computer-executable instructions, which, when the electronic device is running, are executed by the processor to execute the computer-executable instructions stored in the memory to cause the electronic device to perform the method according to any one of claims 1-4.

7. A computer-readable storage medium, characterized in that, The readable storage medium stores instructions that, when executed, implement the method as described in any one of claims 1-4.

8. A computer program product, characterized in that, The computer program product includes instructions that, when executed on a computer, cause the computer to perform the method as described in any one of claims 1 to 4.

Citation Information

Patent Citations

  • Method and system for enhancing network security based on single packet authorization technology

    CN115801347A

  • Access control method, access control system, terminal and storage medium

    WO2023116791A1