Terminal device service identification allocation method, device, medium and product
By interacting between network devices and terminal devices to allocate and confirm service identifiers, the security and privacy issues in terminal device address configuration are resolved, enabling more secure and private allocation of configuration information and improving the security and privacy protection capabilities of network devices.
Patent Information
- Application Number
- CN202410444504.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-12
- Publication Date
- 2026-01-16
- Estimated Expiration
- 2044-04-12
AI Technical Summary
In existing technologies, configuring terminal device addresses at the edge poses a risk of address leakage or theft, resulting in poor user privacy and weak security.
By interacting between network devices and terminal devices, service identifiers are allocated and confirmed. Pre-set service information and authentication information are used to ensure the accuracy and security of service identifiers. A new request-response allocation process for negotiating ARN ID/label is added to the NCP negotiation process. Combined with the random allocation mechanism of the identifier information pool, secure configuration of terminal devices is achieved.
It improves the security and privacy of terminal devices, ensures the accuracy of service identifiers, reduces the risk of address leakage and theft, and enhances the security and privacy protection capabilities of network devices.
Smart Images

Figure CN118802840B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to network communication technology, in particular to a terminal device service identifier allocation method, device, medium and product. BACKGROUND
[0002] In the related art, in the terminal device address allocation process, the network segment (for example, province, city, etc.) corresponding to the terminal device is determined according to a specific rule, and then the address of the terminal device in the network segment is determined. However, the related art has the disadvantage that the address of the terminal device is configured on the edge side according to the network segment where the terminal device is located, and there is a risk of address leakage or address theft, poor privacy and weak security of the user corresponding to the terminal device. SUMMARY
[0003] Therefore, the embodiments of the present application provide a terminal device service identifier allocation method, device, medium and product, which aims to effectively configure terminal devices with more secure and private configuration information.
[0004] The technical scheme of the embodiments of the present application is implemented as follows:
[0005] The embodiments of the present application provide a terminal device service identifier allocation method, applied to a network device connected with a terminal device of a user, and the method comprises:
[0006] receiving a first configuration request sent by the terminal device; the first configuration request is used to query the service identifier of the terminal device, and the service identifier is used to represent the service subscribed by the user;
[0007] allocating first configuration information to the terminal device based on the first configuration request; the first configuration information carries the service identifier of the terminal device;
[0008] receiving a second configuration request sent by the terminal device; the second configuration request carries the service identifier of the terminal device; the second configuration request is used to confirm whether the service identifier of the terminal device is accurate;
[0009] sending first confirmation information to the terminal device based on the second configuration request; the first confirmation information is used to represent whether the service identifier of the terminal device is accurate.
[0010] In the above scheme, the first configuration request carries the identification information of the terminal device, and the first configuration information is allocated to the terminal device based on the first configuration request, which comprises:
[0011] determining the service type information corresponding to the terminal device according to the preset service information and the identification information of the terminal device; the preset service information comprises the service type information corresponding to the preset terminal device.
[0012] determining a service identity of the terminal device based on the service type information;
[0013] allocating the service identity as the first configuration information to the terminal device.
[0014] In the above scheme, the first confirmation information is sent to the terminal device based on the second configuration request, comprising:
[0015] In the case that the service identity of the terminal device carried in the second configuration request matches the service identity of the terminal device carried in the first configuration information, the first confirmation information representing that the service identity of the terminal device is accurate is sent to the terminal device.
[0016] In the above scheme, before the first configuration request sent by the terminal device is received, the method further comprises:
[0017] querying the authentication information sent by the terminal device based on preset subscription information to obtain a query result; the preset subscription information comprises service type information of a service subscribed by a preset user;
[0018] If the query result represents that the user has subscribed services, the service type information of the subscribed services is recorded as the service type information corresponding to the terminal device in the preset service information; the preset service information is used to determine the first configuration information.
[0019] In the above scheme, the first configuration request sent by the terminal device is received, comprising:
[0020] The first configuration request sent by the terminal device is received according to a preset protocol; wherein the first configuration request comprises one or more of the following: protocol type, protocol length and service identity corresponding domain of the preset protocol.
[0021] Embodiments of the present application provide a terminal device service identity allocation method, applied to a terminal device, the terminal device is connected with a network device, and the method comprises:
[0022] sending a first configuration request to the network device; the first configuration request is used to query a service identity of the terminal device; the service identity is used to represent a service subscribed by a user;
[0023] receiving first configuration information allocated by the network device; the first configuration information carries the service identity of the terminal device;
[0024] sending a second configuration request to the network device based on the first configuration information; the second configuration request carries a service identifier of the terminal device; and the second configuration request is used to confirm whether the service identifier of the terminal device is accurate.
[0025] receiving first confirmation information sent by the network device; the first confirmation information is used to represent whether the service identifier of the terminal device is accurate.
[0026] In the above solution, before the first configuration request is sent to the network device, the method further comprises:
[0027] sending authentication information to the network device; the authentication information comprises identification information and password information of the terminal device;
[0028] receiving second confirmation information sent by the network device; the second confirmation information is used to represent that the terminal device passes the authentication.
[0029] Or, receiving third confirmation information sent by the network device; the third confirmation information is used to represent that the terminal device fails to pass the authentication.
[0030] In the above solution, the first configuration request sent to the network device comprises:
[0031] sending the first configuration request to the network device according to a preset protocol; wherein the first configuration request comprises one or more of a protocol type, a protocol length and a domain corresponding to the service identifier of the preset protocol.
[0032] Embodiments of the present application provide a network device, comprising a processor and a memory for storing a computer program capable of running on the processor, wherein,
[0033] The processor is configured to execute the steps of the terminal device service identifier allocation method when the computer program is running.
[0034] Embodiments of the present application provide a terminal device, comprising a processor and a memory for storing a computer program capable of running on the processor, wherein,
[0035] The processor is configured to execute the steps of the terminal device service identifier allocation method when the computer program is running.
[0036] Embodiments of the present application provide a storage medium, the storage medium stores a computer program, and the computer program is executed by a processor to implement the steps of the terminal device service identifier allocation method on the network device side or the steps of the terminal device service identifier allocation method on the terminal device side.
[0037] The embodiment of the present application provides a computer program product, comprising a computer program, which implements the steps of the terminal device service identifier allocation method on the network device side or the steps of the terminal device service identifier allocation method on the terminal device side when executed by a processor.
[0038] The embodiment of the present application provides a terminal device service identifier allocation method, applied to a network device connected with a terminal device of a user, comprising the following steps: receiving a first configuration request sent by the terminal device; the first configuration request is used for querying a service identifier of the terminal device, and the service identifier is used for representing a service subscribed by the user; allocating first configuration information to the terminal device based on the first configuration request; the first configuration information carries the service identifier of the terminal device; receiving a second configuration request sent by the terminal device; the second configuration request carries the service identifier of the terminal device; the second configuration request is used for confirming whether the service identifier of the terminal device is accurate; sending first confirmation information to the terminal device based on the second configuration request; and the first confirmation information is used for representing whether the service identifier of the terminal device is accurate. By adopting the technical scheme of the embodiment of the present application, the network device can receive the first configuration request sent by the terminal device and used for querying the service identifier of the terminal device, determine the first configuration information of the terminal device according to the first configuration request, compare the first configuration information with the second configuration request sent by the terminal device and carrying the service identifier, send the first confirmation information to the terminal device, confirm whether the service identifier of the terminal device is accurate, and complete the address allocation of the terminal device. In this way, the configuration information with higher security and privacy can be configured for the terminal device in combination with the service subscribed by the user. BRIEF DESCRIPTION OF DRAWINGS
[0039] Figure 1 The embodiment of the present application provides a network device side terminal device service identifier allocation method flowchart;
[0040] Figure 2 The embodiment of the present application provides a network device side terminal device service identifier allocation method flowchart;
[0041] Figure 3 The embodiment of the present application provides a network device side terminal device service identifier allocation method flowchart;
[0042] Figure 4 The embodiment of the present application provides a network device side terminal device service identifier allocation method flowchart;
[0043] Figure 5 The embodiment of the present application provides a network device side terminal device service identifier allocation method flowchart;
[0044] Figure 6A schematic diagram of the implementation process of the working principle of the ARN scheme in the related art is shown in FIG. 1.
[0045] Figure 7 A schematic diagram of the method flow of the user authentication stage in an application example of the present application is shown in FIG. 2.
[0046] Figure 8 A schematic diagram of the method flow of the NCP negotiation in an application example of the present application is shown in FIG. 3.
[0047] Figure 9 A schematic diagram of the message format in an application example of the present application is shown in FIG. 4.
[0048] Figure 10 A schematic diagram of the structure of the network device in an embodiment of the present application is shown in FIG. 5.
[0049] Figure 11 A schematic diagram of the structure of the terminal device in an embodiment of the present application is shown in FIG. 6. DETAILED DESCRIPTION
[0050] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used in the description herein is for describing particular embodiments only and is not intended to be limiting of the application.
[0051] Embodiments of the present application provide a terminal device service identity allocation method, device, medium and product, aiming to effectively configure terminal devices with configuration information that is more secure and private.
[0052] Embodiments of the present application provide a terminal device service identity allocation method, which is applied to a network device connected with a terminal device, such as shown in FIG. 1, and the method comprises the following steps. Figure 1
[0053] Step 101: receiving a first configuration request sent by a terminal device; the first configuration request is used to query the service identity of the terminal device, and the service identity is used to represent the service subscribed by a user.
[0054] Exemplarily, the terminal device service identity allocation method can be determined according to actual conditions, which is not limited herein. As an example, the terminal device service identity allocation method can be a Point-to-Point Protocol over Ethernet (PPPoE) application response network method.
[0055] Exemplarily, the network device can be a Broadband Remote Access Server (BRAS) device. The terminal device can be a user terminal device, and specifically can be a Personal Computer (PC) device.
[0056] Exemplarily, the first configuration request can be a Configure-request sent by the terminal device to the network device, and the service identifier in the first configuration request is Null. It can be understood that the service subscribed by the user can be a service enabling an Application Responsive Networking (ARN) technology. The service identifier can be label information / ARN ID information, and the service identifier can be determined according to the service subscribed by the user.
[0057] In the embodiment of the application, in addition to the negotiation of an Internet Protocol (IP) address in a Network Control Protocol (NCP) negotiation process, a request-response distribution process for negotiating an ARN ID / label is newly added.
[0058] In an application example, before receiving the first configuration request sent by the terminal device, the method further includes:
[0059] receiving authentication information sent by the terminal device; the authentication information including identification information and password information of the terminal device;
[0060] if the authentication information matches preset authentication information, sending second confirmation information to the terminal device; the second confirmation information being used to indicate that the terminal device passes authentication, and the preset authentication information including authentication information of a preset terminal device;
[0061] if the authentication information does not match the preset authentication information, sending third confirmation information to the terminal device; the third confirmation information being used to indicate that the terminal device does not pass authentication.
[0062] Exemplarily, the authentication information can be carried in an authentication request sent by the terminal device to the network device, and the authentication request can be an Authentication-Request; the identification information of the terminal device can be username information of a user corresponding to the terminal device, and the password information can be password information corresponding to the username information. It can be understood that the preset terminal device can be a terminal device allowed to be authenticated by the network device. The preset authentication information includes authentication information of the preset terminal device, and it can be understood that the preset authentication information at least includes a corresponding relationship between the preset terminal device and the authentication information.
[0063] Exemplarily, the network device can match the authentication information with the preset authentication information through a first protocol, where the first protocol can be a password authentication protocol (PAP). The PAP is a two-way handshake protocol, which authenticates a user through a username and a password, and transmits the username and the password in a clear text mode, and is suitable for an environment with relatively low network security requirement.
[0064] In the embodiments of the present application, the process of matching the authentication information with the preset authentication information through the first protocol can also be performed through the interaction between the network device and a control device. Specifically, the network device can send the authentication information to the control device; the control device matches the authentication information with the preset authentication information to obtain second confirmation information or third confirmation information; the control device sends the second confirmation information or the third confirmation information to the network device; the network device receives the second confirmation information or the third confirmation information sent by the control device; and the network device sends the second confirmation information or the third confirmation information to the terminal device. The control device can be a controller device, an authentication, authorization and accounting (AAA) server device, or a remote authentication dial-in user server (RADIUS) device.
[0065] Exemplarily, the second confirmation information can be authentication-ACK information. If the authentication information matches the preset authentication information, the second confirmation information is sent to the terminal device. The identification information of the authentication information can be searched in the preset authentication information to obtain a search result. If the search result indicates that the identification information of the authentication information exists in the preset authentication information, it is determined whether the password information of the authentication information is consistent with the password information of the preset authentication information to obtain a determination result. If the determination result indicates that the password information of the authentication information is consistent with the password information of the preset authentication information, it is determined that the authentication information matches the preset authentication information. The second confirmation information is generated, and the second confirmation information is sent to the terminal device.
[0066] Exemplarily, the third confirmation information can be authentication-NAK information. If the authentication information does not match the preset authentication information, the third confirmation information is sent to the terminal device. The identification information of the authentication information can be searched in the preset authentication information to obtain a search result. If the search result indicates that the identification information of the authentication information does not exist in the preset authentication information, it is determined that the authentication information does not match the preset authentication information. The third confirmation information is generated, and the third confirmation information is sent to the terminal device.
[0067] In some embodiments, if the authentication information does not match the preset authentication information, the third confirmation information is sent to the terminal device, and if the search result represents that the identification information of the authentication information does not exist in the preset authentication information, it is determined whether the password information of the authentication information is consistent with the password information of the preset authentication information, and a determination result is obtained; if the determination result represents that the password information of the authentication information is not consistent with the password information of the preset authentication information, it is determined that the authentication information does not match the preset authentication information; the third confirmation information is generated; and the third confirmation information is sent to the terminal device.
[0068] In an application example, before receiving the first configuration request sent by the terminal device, the method further comprises:
[0069] The authentication information sent by the terminal device is queried based on preset subscription information, and a search result is obtained; the preset subscription information includes service type information of a service subscribed by a preset user;
[0070] If the search result represents that the user exists a subscribed service, the service type information of the subscribed service is recorded in the preset service information as service type information corresponding to the terminal device; and the preset service information is used to determine the first configuration information.
[0071] By way of example, the subscription service of the preset terminal device can be understood as enabling the ARN service of the user of the preset terminal device. The service type information can be type information to which the service subscribed by the user belongs, which is not limited herein. As an example, the service type information can be a delay level type to which the service subscribed by the user belongs. The preset subscription information includes service type information of a service subscribed by a preset user, which can be understood as that the preset subscription information at least includes authentication information of the preset terminal device, service identification of the service subscribed by the preset user, and service type information to which the service belongs, and further includes a corresponding relationship among the authentication information of the preset terminal device, the service identification of the service subscribed by the preset user, and the service type information to which the service belongs.
[0072] By way of example, the authentication information sent by the terminal device is queried based on the preset subscription information, and a search result is obtained, which can be that the identification information of the authentication information is queried in the preset subscription information, and a search result is obtained; if the search result represents that the identification information of the authentication information exists in the preset subscription information, it is determined that the user exists a subscribed service; in some embodiments, the service subscribed by the user can be determined based on the identification information of the authentication information in the preset subscription information. Recording the service type information of the terminal device can be applying a flag bit of the label or updating a user category relationship table.
[0073] In some embodiments, if the query result represents that the identification information of the authentication information does not exist in the preset subscription information, it is determined that the user does not subscribe to the service, and the user does not subscribe to the service is recorded in the preset service information.
[0074] In the embodiment of the application, information is acquired in the user online authentication process to determine whether the user enables the ARN service. If the user enables the ARN service, a flag bit indicating that the user needs to use an application response label or a user category relationship table is recorded on the network side device.
[0075] In an application example, a first configuration request sent by a terminal device is received, and the first configuration request includes:
[0076] According to a preset protocol, a first configuration request sent by a terminal device is received, and the first configuration request includes at least one of a protocol type, a protocol length, and a service identification corresponding domain of the preset protocol.
[0077] Exemplarily, the preset protocol can be NCP, and negotiation through the NCP is mainly negotiation of network layer parameters of a Point-to-Point Protocol (PPP) message. The protocol type of the preset protocol can include an Internet Protocol Control Protocol (IPCP), an Internet Protocol v6 Control Protocol (IPv6CP), and the like, and the most common one is the IPCP protocol. The protocol length of the preset protocol can be a message length occupied by each protocol type in the message. The service identification corresponding domain can be an optional domain in the message for accommodating the service identification. It can be understood that the service identification is Null in the first configuration request, which represents that the domain for accommodating the service identification in the message is Null. In some embodiments, a new information domain can be added in the message, and the new information domain can include at least one of the protocol type, the protocol length, and the service identification corresponding domain of the preset protocol.
[0078] In the embodiment of the application, a new information domain is added in the message format of the NCP (such as the IPCP and the IPv6CP), and the protocol type, the protocol length, and the optional domain of the service identification are set in the new information domain, so that the service identification is added in the message format, and the length and the optional domain are correspondingly added.
[0079] Step 102: based on the first configuration request, first configuration information is allocated to the terminal device, and the first configuration information carries a service identification of the terminal device.
[0080] Exemplarily, the network device can determine the identification information of the terminal device based on the first configuration request; determine the service subscribed by the user and the service type information to which the service belongs according to the identification information of the terminal device; match the corresponding service identifier for the terminal device based on the service type information; and send the service identifier as the first configuration information to the terminal device.
[0081] In an application example, the first configuration request carries the identification information of the terminal device, and the first configuration information is allocated to the terminal device based on the first configuration request, including:
[0082] determine the service type information corresponding to the terminal device according to the preset service information and the identification information of the terminal device; the preset service information includes the service type information corresponding to the preset terminal device;
[0083] determine the service identifier of the terminal device based on the service type information;
[0084] allocate the service identifier as the first configuration information to the terminal device.
[0085] Exemplarily, the network device can parse the first configuration request sent by the terminal device to obtain the identification information of the terminal device; the network device can also determine the identification information of the terminal device based on the authentication information sent by the terminal device, and is not limited to determining the identification information of the terminal device through the first configuration request.
[0086] Exemplarily, the preset service information includes the service type information corresponding to the preset terminal device, which can be understood as that the preset service information at least includes the identification information of the preset terminal device, the service type information corresponding to the preset terminal device, and further includes the correspondence between the identification information of the preset terminal device and the service type information.
[0087] Exemplarily, the service type information corresponding to the terminal device can be determined according to the preset service information and the identification information of the terminal device, which can be searching for the identification information in the preset service information to determine the service type information corresponding to the identification information, and determining the service type information corresponding to the identification information as the service type information corresponding to the terminal device.
[0088] Exemplarily, determining the service identity of the terminal device based on the service type information can be determining a preset type service identity corresponding to the service type information; and one service identity in a plurality of service identities of the preset type service identity is allocated to the terminal device. The preset type service identity can be a service identity pool including a plurality of service identities, and the plurality of service identities in the preset type service identity correspond to the same type of service type information. The first X bits of each service identity in the preset type service identity can be the same, and the plurality of service identities in the preset type service identity can correspond to the same type of service type information by setting the first X bits of the service identity to be the same. It can be understood that the allocation of one service identity in the plurality of service identities of the preset type service identity to the terminal device can be achieved by a random allocation manner.
[0089] Exemplarily, determining the service identity of the terminal device based on the service type information can be determining a preset type service identity corresponding to the service type information; and one service identity in a plurality of service identities of the preset type service identity is allocated to the terminal device. The preset type service identity can be a service identity pool including a plurality of service identities, and the plurality of service identities in the preset type service identity correspond to the same type of service type information. The first X bits of each service identity in the preset type service identity can be the same, and the plurality of service identities in the preset type service identity can correspond to the same type of service type information by setting the first X bits of the service identity to be the same. It can be understood that the allocation of one service identity in the plurality of service identities of the preset type service identity to the terminal device can be achieved by a random allocation manner.
[0090] In the embodiment of the present application, a service identity pool including a plurality of service identities is configured, and a service identity is allocated to the terminal device in the service identity pool.
[0091] In the embodiment of the present application, the service type information corresponding to the terminal device is determined according to the preset service information and the identification information of the terminal device; the preset service information includes the service type information corresponding to the preset terminal device; the process of determining the service identity of the terminal device based on the service type information can also be performed by the network device interacting with the control device, specifically, the network device can send a first configuration request to the control device; the control device determines the service type information corresponding to the terminal device according to the preset service information and the identification information of the terminal device; the preset service information includes the service type information corresponding to the preset terminal device; the service identity of the terminal device is determined based on the service type information; the control device sends the identification information as the first configuration information to the network device; and the network device sends the first configuration information to the terminal device.
[0092] Step 103: receiving a second configuration request sent by the terminal device; the second configuration request carries the service identity of the terminal device; and the second configuration request is used to confirm whether the service identity of the terminal device is accurate.
[0093] Exemplarily, in the negotiation process through the NCP, the terminal device and the network device negotiate the address allocation service stage requirements multiple times to determine the agreement that both parties can accept. The network device can send the first configuration information to the terminal device multiple rounds, and correspondingly, the network device can receive the second configuration request sent by the terminal device multiple rounds, and match the second configuration request with the first configuration information multiple rounds.
[0094] Step 104: sending first confirmation information to the terminal device based on the second configuration request; the first confirmation information is used to represent whether the service identity of the terminal device is accurate.
[0095] Exemplarily, the matching result can be obtained by matching the second configuration request with the first configuration information; in the case that the matching result represents that the service identity of the terminal device carried in the second configuration request matches the service identity of the terminal device carried in the first configuration information, the first confirmation information representing that the service identity of the terminal device is accurate is generated, and the first confirmation information representing that the service identity of the terminal device is accurate is sent to the terminal device.
[0096] Exemplarily, in the case that the matching result represents that the service identity of the terminal device carried in the second configuration request does not match the service identity of the terminal device carried in the first configuration information, the first confirmation information representing that the service identity of the terminal device is inaccurate is generated, the first configuration information is re-sent to the terminal device, the second configuration request sent by the terminal device is received, and the second configuration request and the first configuration information are matched based on the second configuration request and the first configuration information, until the matching result represents that the service identity of the terminal device carried in the second configuration request matches the service identity of the terminal device carried in the first configuration information, and the first confirmation information representing that the service identity of the terminal device is accurate is sent to the terminal device.
[0097] In an application example, the first confirmation information is sent to the terminal device based on the second configuration request, including:
[0098] In the case that the service identity of the terminal device carried in the second configuration request matches the service identity of the terminal device carried in the first configuration information, the first confirmation information representing that the service identity of the terminal device is accurate is sent to the terminal device.
[0099] Exemplarily, the service identity of the terminal device carried in the second configuration request matches the service identity of the terminal device carried in the first configuration information, which can be that the service identity of the terminal device carried in the second configuration request is consistent with the service identity of the terminal device carried in the first configuration information.
[0100] The embodiment of the present application provides a terminal device service identity allocation method, which is applied to a terminal device, and the terminal device is connected with a network device, as shown in the figure. Figure 2 The method comprises the following steps:
[0101] Step 201: sending a first configuration request to a network device; the first configuration request is used to query a service identity of a terminal device; the service identity is used to represent a service subscribed by a user.
[0102] Exemplarily, the network device can be a BRAS device. The terminal device can be a user terminal device, and specifically can be a PC device. The first configuration request can be a Configure-request sent by the terminal device to the network device, and the service identity in the first configuration request is Null. It can be understood that the service identity can be determined according to the service subscribed by the user.
[0103] In an application example, before the first configuration request is sent to the network device, the method further includes:
[0104] sending authentication information to the network device; the authentication information includes identification information and password information of the terminal device;
[0105] receiving second confirmation information sent by the network device; the second confirmation information is used to represent that the terminal device passes the authentication;
[0106] Or, receiving third confirmation information sent by the network device; the third confirmation information is used to represent that the terminal device does not pass the authentication.
[0107] Exemplarily, the authentication information can be carried in an authentication request sent by the terminal device to the network device, and the authentication request can be an Authentication-Request. The identification information of the terminal device can be username information, and the password information can be password information corresponding to the username information. The second confirmation information can be Authentication-ACK information. The third confirmation information can be Authentication-NAK information.
[0108] In an application example, the first configuration request sent to the network device includes:
[0109] sending the first configuration request to the network device according to a preset protocol; wherein the first configuration request includes at least one or more of a protocol type, a protocol length of the preset protocol, and a domain corresponding to the service identity.
[0110] Exemplarily, the preset protocol can be NCP, and the negotiation through the NCP mainly negotiates network layer parameters of a PPP message. The protocol type of the preset protocol can include IPCP, IPv6CP, and the like, and the most common one is the IPCP protocol. The protocol length of the preset protocol can be the message length occupied by each protocol type in the message. The domain corresponding to the service identifier can be an optional domain in the message for accommodating the service identifier. It can be understood that the service identifier is Null in the first configuration request, which means that the domain for accommodating the service identifier in the message is Null. In some embodiments, an information domain can be added in the message, and the added information domain can include one or more of the protocol type, the protocol length, and the domain corresponding to the service identifier of the preset protocol.
[0111] Step 202: receiving first configuration information distributed by a network device; the first configuration information carries a service identifier of a terminal device.
[0112] Exemplarily, in the negotiation process through the NCP, the terminal device and the network device negotiate multiple times on the address allocation service stage requirement to determine the agreement that both parties can receive. The terminal device can receive the first configuration information sent by the network device in multiple rounds.
[0113] Step 203: sending a second configuration request to the network device based on the first configuration information; the second configuration request carries the service identifier of the terminal device; and the second configuration request is used to confirm whether the service identifier of the terminal device is accurate.
[0114] Exemplarily, the first configuration information can be parsed to obtain the service identifier in the first configuration information, the second configuration request is generated based on the service identifier, and the second configuration request is sent to the network device. Correspondingly, the terminal device can send the second configuration request to the network device in multiple rounds.
[0115] Step 204: receiving first confirmation information sent by the network device; the first confirmation information is used to indicate whether the service identifier of the terminal device is accurate.
[0116] Exemplarily, if the terminal device sends the second configuration request to the network device and receives the first confirmation information indicating that the service identifier of the terminal device is accurate, the terminal device stops sending the first configuration request to the network device, or stops receiving the first configuration information distributed by the network device, or stops sending the second configuration request to the network device.
[0117] Exemplarily, if the terminal device receives first confirmation information indicating that the service identity of the terminal device is inaccurate or does not receive the first confirmation information sent by the network device after sending the second configuration request to the network device, the terminal device re-receives the first configuration information sent by the network device, sends the second configuration request to the network device based on the first configuration information, and receives the first confirmation information sent by the network device and indicating that the service identity of the terminal device is accurate.
[0118] The terminal device service identity allocation method of the embodiment of the application is exemplarily described below in combination with an application example.
[0119] In the related art, the PPPoE user online process needs to go through two stages of PPPoE negotiation and PPP negotiation, wherein the PPP negotiation includes stages of Link Control Protocol (LCP) negotiation, Challenge Handshake Authentication Protocol (CHAP) / PAP authentication, and NCP negotiation. As shown in Figure 3 The working principle implementation process of PPPoE includes one or more of the following stages: a discovery stage, a session stage, LCP negotiation to establish a link, CHAP / PAP authentication, NCP negotiation, user online, charging, and detection.
[0120] After the LCP negotiation is completed, the authentication stage is entered, which includes two authentication modes of PAP authentication and CHAP authentication. As shown in Figure 4 The implementation process of PAP authentication includes: the authenticated party sends an authentication request (Authenticate-Request) to the authenticating party, and the authentication request carries the username and password of the authenticated party; the authenticating party sends an authentication pass (Authenticate-ACK) information to the authenticated party, and the authentication pass information indicates that the username and password of the authenticated party are completely correct and the authentication is passed; or the authenticating party sends an authentication failure (Authenticate-NCK) information to the authenticated party, and the authentication failure information indicates that the username or password of the authenticated party is incorrect and the authentication is failed.
[0121] In some embodiments, the authentication stage can adopt a Remote Authentication Dial-In User Service (RADIUS) authentication mode, and the specific implementation process includes: a RADIUS client (router or access server) in the network device receives a username and a password, and sends an authentication request to a RADIUS server; after the RADIUS server receives a legal request, the authentication is completed, and the required user authorization information is returned to the client.
[0122] The NCP negotiation mainly negotiates network layer parameters of the PPP message, such as IPCP, IPv6CP, etc., wherein the most common is the IPCP protocol. The PPPoE user mainly obtains an IP address or an IP address segment for accessing a network through the IPCP protocol.
[0123] The IPCP negotiation process is negotiated based on a PPP state machine. As shown in Figure 5 the user (User) and the network device (Device) negotiate, exchange configuration information through Configure-Request, Configure-ACK, Configure-NAK, etc., and finally the IPCP state changes from an initial or closed state to an opened state. The condition for the IPCP state to change to the opened state must be that the sender and the receiver have both sent and received the confirmation message.
[0124] In the IPCP negotiation process, the negotiation message can contain multiple options, i.e., parameters, such as an Internet Protocol Address (IPAddress), a gateway, a mask, etc. The rejection or denial of each option does not affect the success of the IPCP negotiation, and in addition, the IPCP also supports option-free negotiation.
[0125] The IPv6CP is a network control protocol. The IPv6CP is mainly responsible for configuring both ends of a point-to-point link terminal, enabling and disabling an IPv6 protocol module, and negotiable parameters include an interface number (ID) and an IPv6 compression protocol. The IPv6CP uses the same packet exchange mechanism as the LCP. However, only when the PPP reaches the network layer protocol stage, the IPv6CP packet can be exchanged. The IPv6CP packet received before reaching this stage needs to be discarded.
[0126] In the related art, the options of IPv6CP negotiation only support the negotiation of interface ID, and do not support the negotiation of IPv6 compression protocol. In an IPv6 network, both a PPP user and an IP over Ethernet (IPoE) user need to use a Neighbor Discovery Protocol (ND) protocol or a Dynamic Host Configuration Protocol for IPv6 (DHCPv6) to complete the allocation of global unicast addresses and configuration information, and use an allocation prefix (IA_PD) option of the DHCPv6 protocol to complete the allocation of a Local Area Network (LAN) port IPv6 prefix in a Customer Premise Equipment (CPE) routing mode of a wireless terminal access device.
[0127] With the emergence of services with diversified network requirements such as ultra-low latency and high reliability, differentiated guarantee requirements are put forward for the network, and various capabilities of the current network such as slicing and on-the-fly detection cannot effectively open to users, resulting in the inability to provide corresponding guarantees for applications. Existing application awareness technical solutions, such as Access Point Name (APN), will bring a large burden to the network and involve a series of problems such as user privacy, and therefore, a differentiated service guarantee technical solution with small network burden and safety and effectiveness needs to be researched to comprehensively improve the diversified service guarantee capability of the network.
[0128] The user side carries label information identifying network capabilities through existing message fields such as the flow label of SRv6, 20 bits, etc.; and the network side provides corresponding service guarantees by identifying the label information and combining new network capabilities such as slicing and Generalized Segment Routing over IPv6 (G-SRv6 Policy) policies, etc.
[0129] The network ARN ID is mainly applied on the network boundary service access point. The access point is, for example, a provider edge (PE), a broadband remote access server (BRAS) / broadband network gateway (BNG) of an operator. After receiving a network service subscription demand of a user, the controller sets a corresponding color for segment routing policy (SR Policy) routing according to the user demand, obtains a corresponding tunnel / slice, generates an ARN ID, and identifies the user according to user source address information or link information, and then delivers <user, contract> to the network boundary service access point PE and associates it with the network resource <slice / tunnel, routing policy>, so as to complete the network side configuration. On the user side terminal device, the controller finds the corresponding device according to the user, and then delivers the ARN ID information. The user can also bind the ARN ID through an access control list (ACL), specify a link, and the like, and the user side packet is marked with the ARN ID. The present application requires the user to actively add the ARN ID in the packet, as shown in Figure 6 Figure 6 It can be seen that the ARN ID can be equivalent to the routing policy Color (directly corresponding to the Color of the SR Policy), and after the user packet carrying the ARN ID information enters the network boundary service access point device (hereinafter referred to as PE), the PE can obtain the user information according to the source IP, and then perform legality verification on the ARN ID, and then map the ARN ID to a specific network tunnel / slice.
[0130] In order to solve the problem that the address of the user is configured on the edge side in the related art, there is a risk of address leakage or address theft, the user privacy is poor, and the security is weak. The present application embodiment formulates a complete distribution management mechanism based on the label of the identification network and the application capability, randomly distributes the address and the label for the user through the address pool and the label pool, guarantees the uniqueness and the safety of the label through the negotiation between the operator and the user, and fully considers the existing user access side device capability implementation.
[0131] The specific implementation process of the present application embodiment is as follows:
[0132] Step 1: The user subscribes to the ARN / high value service guarantee service on the portal interface, and the controller / AAA server records the subscription relationship table between the user and the enabled service.
[0133] Step 2: User authentication stage.
[0134] Through PAP authentication, the authentication process is as shown in Figure 7
[0135] Step 701: The terminal sends an Authentication-Request to the BRAS device.
[0136] Exemplarily, the terminal can be the authenticated party, and the BRAS device can be the authenticating party. The authenticated party sends the username and password of the terminal to the authenticating party. The authenticating party checks whether the user exists according to the user table of the terminal.
[0137] Step 702: The BRAS device sends an Authenticate-ACK to the terminal.
[0138] Step 703: The BRAS device sends an Authenticate-NAK to the terminal.
[0139] In steps 702 and 703, if the authenticating party checks that the user exists according to the user table of the terminal, the authenticating party checks whether the password is correct. If the password is correct, the authenticating party sends an Authenticate-ACK message to the terminal, and notifies the terminal that the terminal has been allowed to enter the next stage negotiation. If the password is incorrect, the authenticating party sends an Authenticate-NAK message to the terminal, and notifies the terminal that the terminal authentication fails. If the authenticating party checks that the terminal does not exist according to the user table of the terminal, the authenticating party sends an Authenticate-NAK message to the terminal, and notifies the terminal that the terminal authentication fails.
[0140] The original process further includes the following steps:
[0141] Step 704: The BRAS device sends a query request to the controller / AAA and RADIUS server.
[0142] Step 705: The controller / AAA and RADIUS server send a reply request to the BRAS device.
[0143] Step 706: The BRAS device records the user and ARN enabling relationship table.
[0144] In steps 704, 705 and 706, the controller or AAA server can be linked to obtain information to determine whether the user enables the ARN service. If the user enables the ARN service, the flag bit of the user needing to use the application response label or the user category relationship table (distinguishing ARN users and non-ARN users) is recorded on the user side device such as the BRAS and CPE. Steps 704, 705 and 706 can be performed after the user authentication passes, and if the authentication fails, the query is not needed.
[0145] The message format of the user authentication stage includes one or more of Transmission Control Protocol (TCP) / User Datagram Protocol (UDP) protocol information, IP protocol information, PPP (carrying username, password) protocol information, and Ethernet (ETH) protocol information.
[0146] Step 3, NCP negotiation process.
[0147] The label pool (label is the ARN ID in the foregoing description) is configured on the BRAS device / controller, wherein the same type of service can be set to have the same X bits, and the same type of label pool is used to allocate a specific label to different users. Alternatively, a specific label is directly allocated to different users in the label pool. The specific negotiation process is as shown in Figure 8
[0148] Step 801: The terminal sends a Configure-request to the BRAS device.
[0149] Exemplarily, the IP address carried in the Configure-request is 0, and the label is empty. The Configure-request is in the form of Configure-Request (0.0.0.0, Null).
[0150] Step 802: The BRAS device returns a Configure-NAK to the terminal.
[0151] Exemplarily, the Configure-NAK carries the IP address and label / ARN ID value allocated to the terminal by the BRAS device. The Configure-NAK is in the form of Configure-NAK (10.1.1.1, label).
[0152] In some embodiments, before step 802, steps 803 and 804 are further included, wherein:
[0153] Step 803: The BRAS device forwards the Configure-request to the controller / AAA server.
[0154] Step 804: The controller / AAA server returns a Configure-NAK to the BRAS device.
[0155] In step 804, the Configure-NAK carries the IP address and label / ARN ID value allocated to the terminal by the controller / AAA server.
[0156] Step 805: The terminal sends a Configure-request to the BRAS device, carrying the IP address and label / ARN ID value assigned to the client by the server / controller / device.
[0157] Step 806: The BRAS device replies a Configure-ACK to the terminal.
[0158] Considering the risk of privacy leakage, the life cycle management of the ARN ID can be set, and the update of the ARN ID is automatically initiated (or manually configured to trigger) after a certain time, that is, the steps 801-806 are triggered.
[0159] The message format update in the NCP negotiation process is shown in the following table: Figure 9 As shown in the table, at least one information field is added, which includes a protocol type, which can be an IP CP protocol, and a protocol number 8021 of the IP CP protocol; the information field also includes a protocol length, which can be 3 of the IP CP protocol length; the information field also includes an optional field for carrying label related data; and the information field can also include identifier information. In other embodiments, the protocol type can also be an IPv6 CP protocol, and the protocol number of the IPv6 CP protocol is 8057.
[0160] To implement the method of the network device side of the embodiments of the present application, the embodiments of the present application provide a network device, Figure 10 only an exemplary structure of the network device is shown, and not all structures, and part or all of the structures can be implemented according to needs. Figure 10 The network device provided by the embodiments of the present application includes the following steps:
[0161] As shown in the table, at least one information field is added, which includes a protocol type, which can be an IP CP protocol, and a protocol number 8021 of the IP CP protocol; the information field also includes a protocol length, which can be 3 of the IP CP protocol length; the information field also includes an optional field for carrying label related data; and the information field can also include identifier information. In other embodiments, the protocol type can also be an IPv6 CP protocol, and the protocol number of the IPv6 CP protocol is 8057. Figure 10 As shown in the table, at least one information field is added, which includes a protocol type, which can be an IP CP protocol, and a protocol number 8021 of the IP CP protocol; the information field also includes a protocol length, which can be 3 of the IP CP protocol length; the information field also includes an optional field for carrying label related data; and the information field can also include identifier information. In other embodiments, the protocol type can also be an IPv6 CP protocol, and the protocol number of the IPv6 CP protocol is 8057. Figure 10 In the interests of brevity and clarity, all buses in the network device 1000 are denoted as the bus system 1004.
[0162] The user interface 1003 can include a display, a keyboard, a mouse, a trackball, a click wheel, a key, a button, a touchpad, or a touch screen, etc.
[0163] The memory 1002 in the embodiments of the present application is configured to store various types of data to support the operation of the network device. Examples of the data include any computer programs used for operation on the network device.
[0164] The terminal device service identifier allocation method of the network device disclosed in the embodiments of the present application can be applied in the processor 1001 or implemented by the processor 1001. The processor 1001 can be an integrated circuit chip with a signal processing capability. In the implementation process, each step of the terminal device service identifier allocation method of the network device can be completed by the integrated logic circuit of hardware in the processor 1001 or the instruction in the form of software. The processor 1001 described above can be a general processor, a digital signal processor (DSP), or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, etc. The processor 1001 can implement or execute the methods, steps and logic block diagrams disclosed in the embodiments of the present application. The general processor can be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the embodiments of the present application, the hardware coding processor can be directly implemented or executed by the hardware and software module combination in the coding processor. The software module can be located in the storage medium in the storage 1002, and the processor 1001 reads the information in the storage 1002 and combines the hardware to complete the steps of the terminal device service identifier allocation method of the network device provided in the embodiments of the present application.
[0165] In the exemplary embodiments, the network device 1000 can be implemented by one or more application specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field programmable gate arrays (FPGAs), general-purpose processors, controllers, micro controllers (MCUs), microprocessors (Microprocessors), or other electronic elements, to execute the foregoing method.
[0166] To implement the method on the terminal device side in the embodiments of the present application, the embodiments of the present application provide a terminal device, Figure 11 Only the exemplary structure of the terminal device is shown, not all structures, and the part or all structures can be implemented according to the needs. Figure 11 Only the exemplary structure of the terminal device is shown, not all structures, and the part or all structures can be implemented according to the needs.
[0167] As shown in Figure 11 the terminal device 1100 provided by the embodiments of the present application includes at least one processor 1101, a memory 1102 and a user interface 1103. The various components in the terminal device 1100 are coupled together by a bus system 1104. It can be understood that the bus system 1104 is used to realize the connection communication between the components. In addition to including a data bus, the bus system 1104 also includes a power bus, a control bus and a status signal bus. However, in order to clearly illustrate the present application, all the buses are marked as the bus system 1104 in the Figure 11 .
[0168] The user interface 1103 can include a display, a keyboard, a mouse, a trackball, a click wheel, a key, a button, a touchpad or a touch screen, etc.
[0169] The memory 1102 in the embodiments of the present application is used to store various types of data to support the operation of the terminal device. Examples of these data include any computer programs used for operation on the terminal device.
[0170] The terminal device service identity allocation method of the terminal device disclosed by the embodiments of the present application can be applied in the processor 1101 or implemented by the processor 1101. The processor 1101 can be an integrated circuit chip with signal processing capability. In the implementation process, the steps of the terminal device service identity allocation method of the terminal device can be completed by the integrated logic circuits or instructions in the form of software in the processor 1101. The processor 1101 described above can be a general purpose processor, a DSP, or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, etc. The processor 1101 can implement or execute the methods, steps and logic block diagrams disclosed in the embodiments of the present application. The general purpose processor can be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the embodiments of the present application, the hardware decoding processor can be directly embodied to execute the steps, or a combination of hardware and software modules in the decoding processor can be executed. The software module can be located in a storage medium, which is located in the memory 1102. The processor 1101 reads the information in the memory 1102 and combines the hardware to complete the steps of the terminal device service identity allocation method of the terminal device provided by the embodiments of the present application.
[0171] In the exemplary embodiments, the terminal device 1100 can be implemented by one or more ASICs, DSPs, PLDs, CPLDs, FPGAs, general purpose processors, controllers, MCUs, Microprocessors, or other electronic elements, for executing the foregoing method.
[0172] It can be appreciated that the memory (memory 1002, memory 1102) can be volatile memory or nonvolatile memory, and can also include both volatile and nonvolatile memory. Among them, the nonvolatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a ferromagnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM); the magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM) used as an external cache. By way of example and not limitation, many forms of RAM can be used, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus random access memory (DRRAM).The memory described in the embodiments of the present application is intended to include, but not limited to, these and any other suitable types of memory.
[0173] In the example embodiments, the embodiments of the present application further provide a storage medium, specifically a computer readable storage medium, for example, the memory 1002 storing the computer program executable by the processor 1001 of the network device 1000, and the memory 1102 storing the computer program executable by the processor 1101 of the terminal device 1100, to complete the steps described in the method of the embodiments of the present application. The computer readable storage medium can be a ROM, a PROM, an EPROM, an EEPROM, a Flash Memory, a magnetic surface memory, an optical disc, or a CD-ROM, etc.
[0174] In the example embodiments, the embodiments of the present application further provide a computer program product, including a computer program executable by the processor 1001 of the network device 1000 or by the processor 1101 of the terminal device 1100 to complete the steps described in any of the foregoing methods.
[0175] It should be noted that "first", "second", etc. are used to distinguish similar objects, and do not necessarily describe a specific order or sequence.
[0176] In addition, the technical solutions described in the embodiments of the present application can be combined arbitrarily without conflict.
[0177] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto, any person skilled in the art can easily think of changes or replacements within the technical range disclosed in the present application, which should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A terminal device service identification allocation method, characterized by, The method is applied to a network device connected with a terminal device, and comprises the following steps: receiving a first configuration request sent by the terminal device; the first configuration request is used to query a service identity of the terminal device, and the service identity is used to represent a service subscribed by a user; allocating first configuration information to the terminal device based on the first configuration request; the first configuration information carries the service identity of the terminal device; receiving a second configuration request sent by the terminal device; the second configuration request carries the service identity of the terminal device; the second configuration request is used to confirm whether the service identity of the terminal device is accurate; sending first confirmation information to the terminal device based on the second configuration request; the first confirmation information is used to represent whether the service identity of the terminal device is accurate.
2. The method of claim 1, wherein, The first configuration request carries identification information of the terminal device, and the first configuration information is allocated to the terminal device based on the first configuration request, which comprises the following steps: determining service type information corresponding to the terminal device according to preset service information and the identification information of the terminal device; the preset service information comprises service type information corresponding to a preset terminal device; determining the service identity of the terminal device based on the service type information; allocating the service identity as the first configuration information to the terminal device.
3. The method of claim 1, wherein, The first confirmation information is sent to the terminal device based on the second configuration request, which comprises the following steps: if the service identity of the terminal device carried in the second configuration request matches the service identity of the terminal device carried in the first configuration information, sending the first confirmation information representing that the service identity of the terminal device is accurate to the terminal device.
4. The method of claim 1, wherein, Before receiving the first configuration request sent by the terminal device, the method further comprises the following steps: querying authentication information sent by the terminal device based on preset subscription information to obtain a query result; the preset subscription information comprises service type information to which a service subscribed by a preset user belongs; if the query result represents that the user has a subscribed service, recording the service type information to which the subscribed service belongs as service type information corresponding to the terminal device in preset service information; the preset service information is used to determine the first configuration information.
5. The method of claim 1, wherein, The first configuration request sent by the terminal device is received, which comprises the following steps: receiving the first configuration request sent by the terminal device according to a preset protocol; wherein the first configuration request comprises one or more of a protocol type, a protocol length and a domain corresponding to a service identity of the preset protocol.
6. A terminal device service identification allocation method, characterized by, The method is applied to a terminal device connected with a network device, and comprises the following steps: sending a first configuration request to the network device; the first configuration request is used to query a service identity of the terminal device; the service identity is used to represent a service subscribed by a user; receiving first configuration information allocated by the network device; the first configuration information carries the service identity of the terminal device; sending a second configuration request to the network device based on the first configuration information; the second configuration request carries a service identifier of the terminal device; and the second configuration request is used to confirm whether the service identifier of the terminal device is accurate. receiving first confirmation information sent by the network device; the first confirmation information is used to represent whether the service identifier of the terminal device is accurate.
7. The method of claim 6, wherein, Before the step of sending the first configuration request to the network device, the method further comprises: sending authentication information to the network device; the authentication information comprises identification information and password information of the terminal device; receiving second confirmation information sent by the network device; the second confirmation information is used to represent that the authentication of the terminal device is passed; or, receiving third confirmation information sent by the network device; the third confirmation information is used to represent that the authentication of the terminal device is not passed.
8. The method of claim 6, wherein, The step of sending the first configuration request to the network device comprises: sending the first configuration request to the network device according to a preset protocol; wherein the first configuration request comprises one or more of a protocol type, a protocol length and a domain corresponding to a service identifier of the preset protocol.
9. A network device, comprising: comprises: a processor and a memory for storing a computer program capable of running on the processor, wherein the processor is configured to execute the steps of the method of any one of claims 1 to 5 when running the computer program.
10. A terminal device, comprising: comprises: a processor and a memory for storing a computer program capable of running on the processor, wherein the processor is configured to execute the steps of the method of any one of claims 6 to 8 when running the computer program.
11. A storage medium having stored thereon a computer program, characterized in that The computer program is executed by the processor to implement the steps of the method of any one of claims 1 to 5, or to implement the steps of the method of any one of claims 6 to 8.
12. A computer program product comprising a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the method of any one of claims 1 to 5, or to implement the steps of the method of any one of claims 6 to 8.
Citation Information
Patent Citations
Information processing method, server, and storage medium
CN109389449A
Network service control method and device, and storage medium
CN117459568A