Access control method, apparatus, device, and storage medium

By introducing an authentication-free access module into the Radius system, automatic fault detection and handling are achieved, solving the reliability problem of the Radius system during faults, ensuring the normal operation of user services, and improving the system's reliability.

CN118827082BActive Publication Date: 2025-12-09CHINA MOBILE COMM GRP CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311085090.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-08-25
Publication Date
2025-12-09
Estimated Expiration
2043-08-25

AI Technical Summary

Technical Problem

The existing Radius system fails, preventing legitimate users from completing authentication. The wired broadband authentication system has poor reliability, lacks fault detection and automatic repair capabilities, and affects the normal use of services.

Method used

Introducing an authentication-free access module into the Radius system enables automatic fault detection and activates the authentication-free access module when a device malfunctions, ensuring normal operation of user services.

Benefits of technology

This improves the reliability of the Radius system's authentication service, ensuring that user services can continue normally in the event of equipment failure, thus enhancing the system's reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118827082B_ABST
    Figure CN118827082B_ABST
Patent Text Reader

Abstract

The application discloses an access control method and device, electronic equipment and a storage medium. The method is applied to a first device including a first authentication-free pass-through module, and the method comprises the following steps: receiving a user access authentication request forwarded by a second device; in response to the user access authentication request, detecting a fault state of the first device; if the first device is in the fault state, starting the first authentication-free pass-through module, and sending a first authentication result of passing authentication to the second device based on the first authentication-free pass-through module. In this way, automatic detection of the fault of the first device is realized, and when the first device is faulty, the first authentication-free pass-through module is controlled to be started, so that the service of the user can be normally performed, and the reliability of the authentication service is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of communication, and in particular to an access control method and device, equipment and a storage medium. BACKGROUND

[0002] With the continuous development of Internet technology, when an operator develops a wired broadband service, in order to protect network security, authentication is usually performed through a Radius (Remote Authentication Dial In User Service) to ensure that the accessed user is a legal user.

[0003] However, if the Radius system fails, the above scheme will result in the legal user being unable to complete authentication, and the reliability of the wired broadband authentication system is poor, thereby resulting in the service being unable to be used. SUMMARY

[0004] Therefore, the embodiments of the present application provide an access control method, device, equipment and storage medium, aiming to improve the reliability of the wired broadband authentication system.

[0005] The technical scheme of the embodiments of the present application is as follows:

[0006] In a first aspect, the embodiments of the present application provide an access control method applied to a first device, wherein the first device comprises a first authentication-free pass module, and the method comprises the following steps:

[0007] receiving a user access authentication request forwarded by a second device;

[0008] in response to the user access authentication request, detecting a fault state of the first device; if the first device is in the fault state, starting the first authentication-free pass module, and sending a first authentication result of passing authentication to the second device based on the first authentication-free pass module.

[0009] In some embodiments, the first device comprises an availability detection module, and the step of detecting the fault state of the first device in response to the user access authentication request comprises:

[0010] in response to the user access authentication request, calling the availability detection module;

[0011] determining the fault state of the first device based on the availability detection module detecting the availability of the first device; the fault state represents whether the availability of the first device is normal.

[0012] In some embodiments, the method further comprises:

[0013] If not in the fault state, authenticating the user access request and generating the first authentication result or a second authentication result of rejecting authentication to the second device.

[0014] In a second aspect, the embodiments of the present application provide an access control method for a second device, the second device comprising a second authentication-passing module, the method comprising:

[0015] obtaining a user access authentication request sent by a user device;

[0016] In response to the user access authentication request sent by the user device, determining whether there is a target device in communication with the second device among the at least two first devices; if yes, forwarding the user access authentication request to the target device;

[0017] If not, starting the second authentication-passing module and sending a first authentication result of passing authentication to the user device based on the second authentication-passing module.

[0018] In some embodiments, the at least two first devices comprise a primary authentication device and a backup authentication device, and the forwarding the user access authentication request to the target device comprises:

[0019] If the primary authentication device is in communication with the second device, determining the address information of the target device as the address information of the primary authentication device;

[0020] If the primary authentication device is not in communication with the second device and the backup authentication device is in communication with the second device, determining the address information of the target device as the address information corresponding to the backup authentication device in communication with the second device;

[0021] Based on the address information of the target device, forwarding the user access authentication request to the target device.

[0022] In some embodiments, the determining whether there is a target device in communication with the second device among the at least two first devices comprises:

[0023] obtaining a set of address information, the set of address information comprising address information of each first device among the at least two first devices;

[0024] If each address information in the set of address information is not connectable, determining that there is no target device in communication with the second device;

[0025] If the address information of at least one first device in the set of address information is connectable, determining that there is a target device in communication with the second device.

[0026] In a third aspect, the embodiments of the present application provide an access control device, applied to a first device, the first device comprising a first authentication-passing module, and the device comprising:

[0027] a first obtaining module, configured to receive a user access authentication request forwarded by a second device;

[0028] a control module, configured to, in response to the user access authentication request, detect a fault state of itself, and if the first device is in the fault state, start the first authentication-passing module;

[0029] the first authentication-passing module, configured to send a first authentication result of passing authentication to the second device.

[0030] In a fourth aspect, the embodiments of the present application provide an access control device, applied to a second device, the second device comprising a second authentication-passing module, and the device comprising:

[0031] a second obtaining module, configured to obtain a user access authentication request sent by a user device;

[0032] a first determining module, configured to, in response to the user access authentication request sent by the user device, determine whether there is a target device in communication with the second device among at least two first devices, and if yes, forward the user access authentication request to the target device, and if not, start the second authentication-passing module;

[0033] the second authentication-passing module, configured to send a first authentication result of passing authentication to the user device.

[0034] In a fifth aspect, the embodiments of the present application provide an electronic device, comprising a processor and a memory for storing a computer program capable of running on the processor, wherein,

[0035] the processor is configured to, when running the computer program, execute the steps of the method in the first aspect and the second aspect.

[0036] In a sixth aspect, the embodiments of the present application provide an access control authentication system, comprising a first device and a second device, wherein the number of the first devices is at least two, the second device is in communication connection with the first devices, the first devices are configured to execute the steps of the method in the first aspect, and the second device is configured to execute the steps of the method in the second aspect.

[0037] The technical scheme provided by the embodiment of the application is applied to a first device, the first device comprises a first authentication-passing-free module, and the method comprises the following steps: receiving a user access authentication request forwarded by a second device; in response to the user access authentication request, detecting a fault state of the first device; if the first device is in the fault state, starting the first authentication-passing-free module, and sending a first authentication result of passing authentication to the second device based on the first authentication-passing-free module. In this way, automatic detection of the fault of the first device is realized, and when the first device is in fault, the first authentication-passing-free module is started, so that the service of the user can be normally performed, and the reliability of the authentication service is improved. BRIEF DESCRIPTION OF DRAWINGS

[0038] Figure 1 A flowchart of an access control method provided by an embodiment of the application is shown in the figure.

[0039] Figure 2 A flowchart of an access control method provided by another embodiment of the application is shown in the figure.

[0040] Figure 3 A structure diagram of a wired broadband authentication system to which the related technology of an application example of the application is applied is shown in the figure.

[0041] Figure 4 A structure diagram of a wired broadband authentication system architecture in an application example of the application is shown in the figure.

[0042] Figure 5 A structure diagram of a Radius server device in an application example of the application is shown in the figure.

[0043] Figure 6 A structure diagram of a Radius client device in an application example of the application is shown in the figure.

[0044] Figure 7 An authentication flowchart of a wired broadband authentication system in an application example of the application is shown in the figure.

[0045] Figure 8 A structure diagram of an access control device provided by an embodiment of the application is shown in the figure.

[0046] Figure 9 A structure diagram of another access control device provided by an embodiment of the application is shown in the figure.

[0047] Figure 10 A structure diagram of an electronic device provided by an embodiment of the application is shown in the figure. DETAILED DESCRIPTION

[0048] The application will be described in further detail below with reference to the drawings and embodiments.

[0049] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used in the description herein is for describing particular embodiments only and is not intended to be limiting of the application.

[0050] The access control method provided by the embodiments of the present application can be applied to an access control authentication system, which comprises at least two first devices and a second device in communication connection with the first devices. The system is applied to access control, and can control the starting of the authentication-passing module when a fault occurs in the access control authentication system, thereby ensuring normal service of the user and improving the reliability of the authentication service.

[0051] The embodiments of the present application provide an access control method applied to a first device, which comprises an authentication-passing module. The first device can be a Radius server device in a Radius system, as shown in the drawing, and the method comprises the following steps. Figure 1

[0052] Step 110: receiving a user access authentication request forwarded by a second device.

[0053] The second device can be a Radius client device in the Radius system. The second device can forward the user access authentication request to the first device, and the first device receives the user access authentication request forwarded by the second device.

[0054] Step 120: detecting a fault state of the first device in response to the user access authentication request, and starting the first authentication-passing module and sending a first authentication result of authentication passing to the second device based on the first authentication-passing module if the first device is in the fault state.

[0055] The first device triggers a fault detection function in response to the user access authentication request to detect the fault state of the first device, and starts the first authentication-passing module if the first device is in the fault state.

[0056] The first authentication-passing module is used to control the first device to not need to perform authentication or to pass the authentication by default under a specific condition, i.e., when the first device is in the fault state, thereby avoiding the influence of the fault of the first device on normal service.

[0057] The first device sends the first authentication result of authentication passing to the second device based on the first authentication-passing module. The first authentication-passing module of the first device can construct a user access authentication request passing reply message to reply the authentication request passing message to the second device as the first authentication result. ​

[0058] The technical scheme provided by the embodiments of the present application is applied to a first device, and the first device comprises a first authentication-pass-through module. The method comprises the following steps: receiving a user access authentication request forwarded by a second device; in response to the user access authentication request, detecting a fault state of the first device; if the first device is in the fault state, starting the first authentication-pass-through module, and sending a first authentication result of passing authentication to the second device based on the first authentication-pass-through module. In this way, automatic detection of the fault of the first device is realized, and when the first device is in the fault state, the first authentication-pass-through module is started, so that the service of the user can be normally performed, and the reliability of the authentication service is improved.

[0059] In some embodiments, the first device comprises an availability detection module, and the detection of the fault state of the first device in response to the user access authentication request comprises the following steps:

[0060] In response to the user access authentication request, the availability detection module is called.

[0061] The availability of the first device is detected based on the availability detection module, and the fault state of the first device is determined. The fault state represents whether the availability of the first device is normal.

[0062] Here, the first device further comprises the availability detection module, which is used to realize the availability detection of the first device. In response to the user access authentication request, the first device can call the availability detection module, detect the availability of the first device based on the availability detection module, and determine the fault state of the first device. The fault state represents whether the availability of the first device is normal. The availability here refers to the ability of the device to ensure that the device service can be continuously available.

[0063] Exemplarily, the availability detection module can detect whether the CPU, the memory, the database and each processing module of the first device are normal, confirm whether the first device can normally perform the user legitimacy authentication process, and thus generate the availability result of whether the first device is in the fault state, so as to determine the fault state of the first device. The fault state represents whether the availability of the first device is normal.

[0064] In some embodiments, the method further comprises the following steps:

[0065] If the first device is not in the fault state, the user access request is authenticated, and a first authentication result or a second authentication result of refusing authentication is generated and sent to the second device.

[0066] Here, when the first device is not in the fault state, the first device can normally perform the user legitimacy authentication process, the user access request is authenticated, and a first authentication result or a second authentication result of refusing authentication is generated and sent to the second device.

[0067] The embodiment of the present application further provides an access control method, applied to a second device, the second device comprising a second authentication-free pass module, the second device being a Radius client device in a Radius system, as shown in the figure, the method comprising the following steps: Figure 2

[0068] Step 210: obtaining a user access authentication request sent by a user device.

[0069] Here, the user device can be a mobile phone, a tablet computer, a notebook computer or other devices. When the user device needs to access a network, the second device obtains the user access authentication request sent by the user device.

[0070] Step 220: in response to the user access authentication request sent by the user device, determining whether there is a target device in communication with the second device in at least two first devices; if yes, forwarding the user access authentication request to the target device; if no, starting the second authentication-free pass module and sending a first authentication result of authentication pass to the user device based on the second authentication-free pass module.

[0071] Here, in order to ensure that the authentication business can be carried out normally, the first device can be set to at least two, so as to avoid that in the case of only one first device, the legal user authentication fails due to the first device failure.

[0072] Here, in response to the user access authentication request sent by the user device, the second device determines whether there is a target device in communication with the second device in at least two first devices. Exemplarily, the second device further comprises a communication detection module for communication detection between the second device and at least one first device, and the second device calls the communication detection module in response to the user access authentication request sent by the user device to determine whether there is a target device in communication with the second device in at least two first devices.

[0073] Here, if yes, it is determined that at least two first devices are in communication with the second device, and the second device forwards the user access authentication request to the target device, the target device being a first device in communication with the second device in at least two first devices;

[0074] If no, it is determined that at least two first devices are not in communication with the second device, i.e. the communication is not normal, and the second device starts the second authentication-free pass module and sends a first authentication result of authentication pass to the user device based on the second authentication-free pass module.

[0075] ​The technical scheme provided by the embodiment of the application is applied to a second device, the second device comprises a second authentication-passing module, and the method comprises the following steps: obtaining a user access authentication request sent by a user device; determining, in response to the user access authentication request sent by the user device, whether there is a target device in communication with the second device among at least two first devices; if yes, forwarding the user access authentication request to the target device; if no, starting the second authentication-passing module, and sending a first authentication result of passing authentication to the user device based on the second authentication-passing module. In this way, the second device controls the starting of the second authentication-passing module when it is determined that there is no target device in communication with the second device, thereby ensuring that the user's service can proceed normally and improving the reliability of the authentication service.

[0076] In some embodiments, the at least two first devices comprise a primary authentication device and a backup authentication device, and forwarding the user access authentication request to the target device comprises:

[0077] If the primary authentication device is in communication with the second device, the address information of the target device is determined as the address information of the primary authentication device.

[0078] If the primary authentication device is not in communication with the second device and the backup authentication device is in communication with the second device, the address information of the target device is determined as the address information corresponding to the backup authentication device in communication with the second device.

[0079] The user access authentication request is forwarded to the target device based on the address information of the target device.

[0080] Here, the number of the first devices is at least two, and the second device is in communication with the at least two first devices, that is, the second device can normally communicate with the at least two first devices, at this time, the second device needs to determine the address information of the target device and forward the user access authentication request to the target device based on the address information of the target device. The target device here is the first device in communication with the second device among the at least two first devices.

[0081] Here, when it is determined that the second device can normally communicate with the at least two first devices, the determination of the address of the target device can be determined by the user or automatically determined by the device. For example, when the second device can communicate with the at least two first devices, the user can select the address of the target device among the at least two devices. The second device can also determine the address information of the target device based on a preset determination rule.

[0082] Here, the at least two first devices comprise a primary authentication device and a backup authentication device, and the backup authentication device and the primary authentication device are 1:1 primary-backup backup. This is to ensure that in the case of only the primary authentication device, the user authentication fails due to the failure of the primary authentication device.

[0083] Here, the second device detects whether the main authentication device is in communication, and at this time, whether other standby authentication devices are in communication with the second device, the second device determines the address information of the target device as the address information of the main authentication device.

[0084] Here, when the second device detects that the main authentication device is not in communication, at this time, the main authentication device is unavailable, and the second device is in communication with a standby authentication device, the second device determines the address information of the target device as the address information corresponding to the standby authentication device in communication with the second device, that is, the address information of the target device is the address information corresponding to the standby authentication device that can be connected, and here, the address of the target device can be one or multiple, and the user can determine the address information of the target device among the standby authentication devices that can be connected according to a preset determination rule.

[0085] In some embodiments, determining whether there is a target device in communication with the second device among the at least two first devices includes:

[0086] Obtaining a set of address information, the set of address information including address information of each first device among the at least two first devices;

[0087] If each address information in the set of address information is not connectable, it is determined that there is no target device in communication with the second device;

[0088] If the address information of at least one first device in the set of address information is connectable, it is determined that there is a target device in communication with the second device.

[0089] Here, the second device pre-stores the set of address information, and here, the address information includes address information of each first device among the at least two first devices. When determining whether there is a target device in communication with the second device among the at least two first devices, the second device can determine whether there is a target device in communication with the second device among the at least two first devices based on the set of address information.

[0090] Here, the second device can send a connectivity detection packet to the address of each first device in the set of address information. For each first device, if the second device does not receive a reply after N consecutive packets (the value of N can be adjusted as needed), it is determined that the first device is not connectable. If each address information in the set of address information is not connectable, it is determined that there is no target device in communication with the second device, that is, the at least two first devices are not in a communication state, that is, not connectable. For each first device, if the second device receives a reply after N consecutive packets (the value of N can be adjusted as needed), it is determined that the first device is connectable. If the address information of at least one first device in the set of address information is connectable, it is determined that the at least two first devices are in a communication state, that is, it is determined that there is a target device in communication with the second device.

[0091] The embodiments of the present application will be described below in conjunction with an application example.

[0092] When an operator develops a cable broadband service, in order to ensure that the access user is a legal user who has paid and to guarantee network security, a cable broadband authentication system, i.e. a remote user dial-up authentication system (Radius), is needed to authenticate the user and to provide service to the user who passes the authentication. The Radius system includes two parts, a Radius client and a Radius server, which cooperate to complete the authentication work. The structure diagram of the cable broadband authentication system of the related art is shown in FIG. 1. Currently, the typical access mode of the cable broadband service is as follows: the user accesses a broadband remote access server (BRAS) device through a transmission network, accesses the operator's Internet network through the BRAS device, and further realizes access to related services. The BRAS device is used as a Radius client, and the Radius server is a separately set device. Specifically, the cable broadband user authentication process based on the above-mentioned architecture access mode is as follows: Figure 3

[0093] 1. The user initiates an authentication request to the Radius client.

[0094] 2. After receiving the authentication request of the user, the Radius client queries its configuration and obtains the address of the Radius server. The Radius client sends the authentication request of the user to the Radius server according to the address of the Radius server.

[0095] 3. After receiving the request of the user, the Radius server confirms the authentication request information, returns an accepted authentication message to the Radius client if the authentication is passed, or returns a rejected authentication message to the Radius client if the authentication is not passed.

[0096] 4. After receiving the authentication message returned by the Radius server, the Radius client notifies the corresponding user of the authentication result. If the authentication result is passed, the user can continue the subsequent normal service use process. If the authentication result is not passed, the user is notified of the reason for not passing, and the authentication process ends.

[0097] ​However, with the above architecture, the Radius client cannot know the status of the Radius server. When the Radius server itself fails or the network connection between the Radius client and the Radius server fails, the Radius client cannot receive the authentication result message replied by the Radius server, the legitimate user cannot complete the authentication, and the service cannot be used. That is, the existing architecture and technology have poor reliability of the wired broadband authentication system, lack of fault perception and repair capability, and are easy to affect the normal use of the service.

[0098] Therefore, the present application provides a high-reliability wired broadband authentication system authentication processing method and device, aiming to solve the problem of poor reliability of the existing wired broadband authentication system, inability to perceive faults, insufficient reliability, lack of automatic repair capability, and possible service damage in case of failure.

[0099] In the present application, the access control authentication system is a wired broadband authentication system. First, the wired broadband authentication system architecture is redesigned, and based on the new system architecture, the wired broadband authentication system authentication process is designed to realize automatic detection and processing of system failure, and the system reliability is significantly improved.

[0100] The structure diagram of the wired broadband authentication system architecture of the present application is shown in Figure 4 As shown in the system architecture, a standby Radius server device is added based on Figure 3 to realize 1:1 master-slave backup of the Radius server device. That is, the present application includes a user (i.e., the user device), a master Radius server device, a standby Radius server device (i.e., the first device), and a Radius client device (i.e., the second device).

[0101] Based on the above system architecture, the present application adds a connectivity detection module, an availability detection module, and a first authentication-free pass-through module in the Radius server device (the first device) and the Radius client device (the second device), adjusts the address configuration and selection module function, realizes automatic detection and processing of faults, and reduces the risk of failure and the impact on the service.

[0102] The present application provides a structure diagram of the Radius server device (the first device), as shown in Figure 5As shown in the figure, the Radius server device includes a processor, a communication interface, a clock module and a memory, and the parts are connected through a bus. The communication interface is used for monitoring, receiving and sending data messages, the memory stores an operating system and program code, and the program realizes the function instructions of the receiving unit, the sending unit and the processing unit. The processor calls the code in the memory through the operating system, and the processor includes an availability detection module and a first authentication-free pass-through module.

[0103] In the application example, (1) an availability detection module is added to the Radius server, which can realize self-availability detection of the Radius server to detect the fault state of the Radius server itself. The processing flow of the availability detection module is as follows:

[0104] Input: None.

[0105] Processing process: Detect whether the CPU, memory, database and each processing module of the Radius server are normal, and confirm whether the user legitimacy authentication process can be normally performed.

[0106] (2) A first authentication-free pass-through module is added to the Radius server, a first authentication-free pass-through process is designed, and under specific conditions, the client does not need to be authenticated or the authentication is passed by default, so as to avoid the influence of authentication system failure on normal business. The detailed processing flow of the module is as follows:

[0107] Input: None.

[0108] Processing process: According to the related information of the initiator of the authentication request, an authentication request pass-through reply message is constructed.

[0109] Output: Reply to the requester with an authentication request pass-through message.

[0110] The application example also provides a structure schematic diagram of a Radius client device (second device), as shown in the figure. Figure 6 As shown in the figure, the Radius client device includes a processor, a communication interface, a clock module and a memory, and the parts are connected through a bus. The communication interface is used for monitoring, receiving and sending data messages, the memory stores an operating system and program code, and the program realizes the function instructions of the receiving unit, the sending unit and the processing unit. The processor calls the code in the memory through the operating system, and the processor includes an availability detection module and a first authentication-free pass-through module.

[0111] In the application example, (1) an availability detection module is added to the Radius server, which can realize self-availability detection of the Radius server to detect the fault state of the Radius server itself. The processing flow of the availability detection module is as follows:

[0112] Input: detection destination address.

[0113] Process: The module initiates a connectivity detection packet to the detection destination address. If no reply is received for N consecutive packets (N can be adjusted according to requirements), it is determined that the connectivity is abnormal, otherwise it is determined that the connectivity is normal.

[0114] Output: detection result, whether the connectivity is normal.

[0115] (2) A second free authentication pass-through module is added to the Radius client device, and a second free authentication pass-through process is designed to achieve that the client does not need authentication or default authentication passes under certain conditions, avoiding the impact of authentication system failure on normal business. The detailed processing flow of this module is as follows:

[0116] Input: None.

[0117] Process: According to the relevant information of the initiator of the authentication request, an authentication request pass reply packet is constructed.

[0118] Output: reply to the requester with an authentication request pass packet.

[0119] In addition, in the Radius client device, the Radius server address configuration and selection module function is adjusted to support configuration of two primary and backup Radius server addresses.

[0120] According to the above system architecture, the module is added and adjusted according to the above design. In this way, based on the architecture, device and apparatus of the above wired broadband authentication system, the authentication process of the wired broadband authentication system in the application example is as shown in Figure 7 By this method and system, the problem that the user cannot use the wired broadband service caused by the wired broadband authentication failure due to the single point failure of the Radius server device, the single point failure of the Radius client device and the failure between the Radius server and the client can be effectively avoided.

[0121] The specific steps are as follows:

[0122] Here, the IP address of the primary Radius server (i.e. the primary authentication device mentioned above) is recorded as address A, and the IP address of the backup Radius server (i.e. the backup authentication device mentioned above) is recorded as address B. The address information set is the set of the primary Radius server device and the backup Radius server, i.e. the set of address A and address B.

[0123] Step 701: The user initiates an authentication request (i.e. the user access authentication request mentioned above) to the Radius client device.

[0124] Here, the user equipment initiates a user access authentication request to the Radius client equipment when it needs to access the network.

[0125] Step 702: The Radius client equipment acquires the authentication request sent by the user.

[0126] After receiving the access authentication request of the user equipment, the Radius client equipment calls the connectivity detection module to detect the connectivity state of the Radius server equipment, i.e., to determine whether there is a target device in communication with the second device among the at least two first devices, in the application example, including two Radius server equipment, i.e., the primary Radius server equipment (i.e., the primary authentication device) and the standby Radius server equipment (i.e., the standby authentication device).

[0127] Step 703: The Radius client equipment detects whether it is connected.

[0128] Here, in the application example, based on the processing flow of the connectivity detection module, based on the address A and the address B in the address set, whether there is a target device in communication with the second device among the at least two first devices, i.e., detecting the connectivity of the Radius client equipment with the primary Radius server equipment and the standby Radius server equipment, i.e., connectivity.

[0129] 1. If yes, the address information of at least one first device in the address information set is connectable, then it is determined that the connectivity of the at least two first devices with the second device is established.

[0130] In the application example, the connectivity of the primary Radius server equipment address A is detected first. That is, after the connectivity detection module sends N detection messages (N can be adjusted according to the value) to the primary Radius server equipment based on the address A, if the Radius client equipment does not receive a reply, it is determined that the primary Radius server equipment is not connectable. If the Radius client equipment receives a reply, it is determined that the primary Radius server equipment is connectable.

[0131] (1) If the primary authentication device is in communication with the second device, it is determined that the address information of the target device is the address information of the primary authentication device;

[0132] If the address A is connectable, the address information of the target Radius server is the address information A of the primary authentication device, i.e., the Radius client equipment sends the authentication request of the user to the address A, and enters step 705.

[0133] (2) If the primary authentication device is not connected with the second device and the standby authentication device is connected with the second device, the address information of the target device is determined as the address information corresponding to the standby authentication device connected with the second device.

[0134] If the address A connectivity is abnormal, the connectivity detection module is called to detect the connectivity of the standby Radius server device address B. If the address B connectivity is normal, the address information of the target Radius server is the address information B of the standby authentication device, i.e., the standby Radius server device, and the Radius client device sends an authentication request of the user to the address B, and enters step 705.

[0135] Here, when the standby Radius server device is multiple, the second device can be connected with multiple standby Radius server devices, and the user can select the address of the target Radius server in the multiple standby Radius server devices. The address information of the target Radius server device can also be determined by the Radius client device based on a preset determination rule.

[0136] 2. If no, the address information in the address information set is not connectable, and it is determined that at least two first devices are not connected with the second device.

[0137] If the connectivity of the address A and the address B is not normal, i.e., not connectable, at least two first devices are not connected with the second device, and step 704 is executed.

[0138] Step 704: The Radius client device starts a second authentication exemption module.

[0139] When the connectivity detection of the Radius client device with the address A and the address B is not normal, the second authentication exemption module is started, and the first authentication result of authentication passing is sent to the user device based on the second authentication exemption module, i.e., the Radius client device starts the second authentication exemption module, skips the subsequent authentication process, and directly sends an authentication passing message to the user device, and enters step 710. In this way, the Radius client device detects the connectivity with at least two Radius server devices, determines that it is not connected, i.e., not in a connected state, controls the start of the second authentication exemption module, thereby ensuring that the user's business can be normally performed, and improving the reliability of the authentication service.

[0140] Step 705: The target Radius server obtains the authentication request of the user forwarded by the Radius client device.

[0141] Here, the target Radius server can be a primary Radius server device or a backup Radius server device, which is determined based on the address of the target Radius server determined by the Radius client device.

[0142] In response to the user access authentication request, the failure state of the first device is detected; if the first device is in a failure state, the first authentication pass-through module is started, and a first authentication result of passing authentication is sent to the second device based on the first authentication pass-through module.

[0143] Step 706: The target Radius server determines whether its availability is normal.

[0144] In response to the user access authentication request, the availability detection module is called;

[0145] Based on the availability detection module detecting the availability of the first device, an availability result indicating whether the first device is in a failure state is generated.

[0146] After receiving the user request, the target Radius server calls the availability detection module to detect its availability. The availability detection module can confirm whether the first device can normally perform the user legitimacy authentication process by detecting whether the CPU, memory, database, and various processing modules of the target Radius server are normal, thereby determining the failure state of the first device; the failure state represents whether the availability of the first device is normal.

[0147] (1) If not, the first device is not in a failure state, the user access request is authenticated, and a first authentication result or a second authentication result of rejecting authentication is generated to the second device.

[0148] If the availability of the target Radius server is normal, the first device is not in a failure state, and step 707 is performed.

[0149] (2) If not, the first device is in a failure state, the first authentication pass-through module is started, and a first authentication result of passing authentication is sent to the second device based on the first authentication pass-through module.

[0150] If the availability of the target Radius server is not normal, the first device is in a failure state, and step 708 is performed. In this way, the failure of the target Radius server device is automatically detected, and when the target Radius server device fails, the first authentication pass-through module is started to ensure that the user's business can proceed normally, and the reliability of the authentication service is improved

[0151] Step 707: The target Radius server performs authentication.

[0152] The target RADIUS server initiates normal authentication request processing, confirms the authentication request information based on the authentication request module, and sends the corresponding authentication result to the RADIUS client device, proceeding to step 709. If authentication succeeds, it returns an "accept authentication" message (i.e., successful authentication) to the RADIUS client device, resulting in a first authentication result; if authentication fails, it returns a "reject authentication" message (i.e., rejected authentication) to the RADIUS client device, resulting in a second authentication result. Then, it proceeds to step 709.

[0153] Step 708: The target Radius server device starts the first authentication-free module.

[0154] When the availability detection module of the Radius server reports that its own availability is abnormal, the Radius server activates the first authentication-free access module, skips the authentication process for users, and directly sends an authentication pass message, i.e., the first authentication result, to the Radius client device, and proceeds to step 709.

[0155] Step 709: The Radius client device receives the authentication result sent by the target Radius server device.

[0156] After receiving the authentication result returned by the target Radius server device, the Radius client device notifies the corresponding user to execute step 710.

[0157] Step 710: The user receives the authentication result sent by the Radius client device.

[0158] Based on the first successful authentication result, the user can successfully access the network and continue with normal business operations. If the authentication result is unsuccessful, i.e., a second authentication result of rejection is received, the user is notified of the reason for the failure, and the authentication process ends.

[0159] To implement the method of the embodiments of this application, the embodiments of this application also provide an access control device, which corresponds to the above-described access control method. The steps in the embodiments of the above-described access control method are also fully applicable to the embodiments of this access control device. For example... Figure 8 As shown, the access control device 800 is applied to a first device, which includes a first authentication-free access module. The access control device 800 includes a first acquisition module 810, a control module 820, and a first authentication-free access module 830. The first acquisition module 810 is used to receive user access authentication requests forwarded by a second device. The control module 820 is used to acquire and detect its own fault status in response to the user access authentication request. If it is in a fault state, it activates the first authentication-free access module. The first authentication-free access module 830 is used to send a first authentication result that has passed authentication to the second device.

[0160] In some embodiments, the access control device 800 further includes a calling module 840 and a second determining module 850. The calling module 840 is used to call the availability detection module in response to a user access authentication request. The generating module 850 is used to detect the availability of the first device based on the availability detection module and determine its own fault status. The fault status indicates whether the availability of the first device is normal.

[0161] In some embodiments, the generation module 850 is further configured to, if not in a fault state, authenticate the user access request and generate a first authentication result or a second authentication result that rejects authentication to the second device.

[0162] In practical applications, the first acquisition module 810, control module 820, first authentication-free access module 830, calling module 840, and second determination module 850 can be implemented by the processor in the access control device. Of course, the processor needs to run the computer program in the memory to implement its functions.

[0163] To implement the method of the embodiments of this application, the embodiments of this application also provide an access control device, which corresponds to the above-described access control method. The steps in the embodiments of the above-described access control method are also fully applicable to the embodiments of this access control device. For example... Figure 9 As shown, the access control device 900 is applied to a second device, which includes a second authentication-free access module. The access control device 900 includes: a second acquisition module 910, a first determination module 920, and a second authentication-free access module 930. The second acquisition module 910 is used to acquire a user access authentication request sent by a user equipment. The first determination module 920 is used to determine, in response to the user access authentication request sent by the user equipment, whether there is a target device connected to the second device among at least two first devices. If so, the user access authentication request is forwarded to the target device. If not, the second authentication-free access module is activated. The second authentication-free access module 930 is used to send a first authentication result that has passed authentication to the user equipment.

[0164] In some embodiments, at least two first devices include a primary authentication device and a backup authentication device. The first determining module 920 is further configured to determine the address information of the target device as the address information of the primary authentication device if the primary authentication device is connected to the second device; and to determine the address information of the target device as the address information corresponding to the backup authentication device connected to the second device if the primary authentication device is not connected to the second device and the backup authentication device is connected to the second device. The access control device 900 further includes a forwarding module 940, which is further configured to forward the user access authentication request to the target device based on the address information of the target device.

[0165] In some embodiments, the second obtaining module 910 is further configured to obtain a set of address information, the set of address information comprising address information of each of the at least two first devices; and the first determining module 920 is further configured to determine that there is no target device that can communicate with the second device if none of the address information in the set of address information is connectable; and determine that there is a target device that can communicate with the second device if the address information of at least one of the first devices in the set of address information is connectable.

[0166] In practice, the second obtaining module 910, the first determining module 920, the second authentication-free passing module 930 and the forwarding module 940 can be implemented by a processor in the access control device. Of course, the processor needs to run a computer program in the memory to realize its functions.

[0167] It should be noted that the access control device provided by the above embodiments is only used for example to illustrate the division of the above program modules, and in actual application, the above processes can be completed by different program modules according to needs, that is, the internal structure of the device is divided into different program modules to complete all or part of the above processes. In addition, the access control device and the access control method provided by the above embodiments belong to the same concept, and the specific implementation process is described in the method embodiments, which will not be repeated here.

[0168] Based on the hardware implementation of the above program modules, and in order to realize the method of the embodiments of the present application, the embodiments of the present application also provide an electronic device. Figure 10 Only the exemplary structure of the access control device is shown, not all structures, and the required Figure 10 structure can be implemented.

[0169] As Figure 10 shown, the electronic device 1000 provided by the embodiments of the present application includes at least one processor 1001, a memory 1002, a user interface 1003 and at least one network interface 1004. The various components in the access control device 1000 are coupled together through a bus system 1005. It can be understood that the bus system 1005 is used to realize the connection and communication between the components. The bus system 1005 includes not only a data bus, but also a power bus, a control bus and a status signal bus. However, in order to clearly illustrate the concept, all kinds of buses are marked as the bus system 1005 in the Figure 10 .

[0170] The user interface 1003 can include a display, a keyboard, a mouse, a trackball, a click wheel, a key, a button, a touchpad or a touch screen, etc.

[0171] The memory 1002 in the embodiments of the present application is configured to store various types of data to support the operation of the access control device. Examples of the data include any computer programs used to operate on the access control device.

[0172] The access control method disclosed in the embodiments of the present application can be applied to or implemented by the processor 1001. The processor 1001 can be an integrated circuit chip having a processing capability of signals. In the implementation process, each step of the access control method can be completed by the integrated logic circuit or the instruction in the form of software in the processor 1001. The processor 1001 described above can be a general processor, a digital signal processor (DSP), or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, etc. The processor 1001 can implement or execute the methods, steps and logic block diagrams disclosed in the embodiments of the present application. The general processor can be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the embodiments of the present application, the hardware decoding processor can be directly implemented or executed by the hardware and software module combination in the decoding processor. The software module can be located in the storage medium, which is located in the memory 1002. The processor 1001 reads the information in the memory 1002 and combines the hardware to complete the steps of the access control method provided in the embodiments of the present application.

[0173] In the exemplary embodiments, the electronic device can be implemented by one or more application specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontrollers (MCUs), microprocessors (Microprocessors), or other electronic elements, for executing the foregoing methods.

[0174] It can be appreciated that the memory 1002 can be volatile memory or nonvolatile memory, or both. Access to memory 1002 by other components of the system 1000 can be controlled by a memory controller. Nonvolatile memory can be, for example, read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), a magnetic random access memory (MRAM), flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM). The magnetic surface memory can be a magnetic disc memory or a magnetic tape memory. Volatile memory can be, for example, random access memory (RAM), used as an external cache. By way of example, and not limitation, many forms of RAM can be used, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus random access memory (DRRAM).The memory described in the embodiments of the present application is intended to include, but not limited to, these and any other suitable types of memory.

[0175] In the example embodiments, the embodiments of the present application also provide an access control authentication system, comprising a first device and a second device, wherein the number of the first devices is at least two, and the second device is in communication connection with the first devices.

[0176] In the example embodiments, the embodiments of the present application also provide a storage medium, i.e. a computer storage medium, which can be specifically a computer readable storage medium, such as a memory 1002 storing a computer program, which can be executed by the processor 1001 of the electronic device to complete the steps of the method of the embodiments of the present application. The computer readable storage medium can be a ROM, a PROM, an EPROM, an EEPROM, a Flash Memory, a magnetic surface memory, an optical disc, or a CD-ROM memory, etc.

[0177] It should be noted that "first", "second", etc. are used to distinguish similar objects, and do not necessarily describe a specific order or sequence.

[0178] In addition, the technical solutions described in the embodiments of the present application can be arbitrarily combined without conflict.

[0179] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto, any person skilled in the art can easily think of changes or replacements within the technical range disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. An access control method, characterized in that, Applied to a first device, the first device including a first authentication-free access module and an availability detection module, the method includes: Receive user access authentication requests forwarded by the second device; In response to the user access authentication request, the device detects its own fault status; if it is in a fault status, it activates the first authentication-free access module and sends the first authentication result to the second device based on the first authentication-free access module. The step of detecting its own fault status in response to the user access authentication request includes: In response to the user access authentication request, the availability detection module is invoked; Based on the availability detection module, the availability of the first device is detected, and its fault status is determined; the fault status indicates whether the availability of the first device is normal. The user access authentication request is obtained by the second device from the user device. After the second device determines that there is a master authentication device connected to the second device among at least two first devices, the second device forwards the request to the first device as the target device based on the address information of the master authentication device. Alternatively, if the second device determines that the primary authentication device is not connected to the second device, and at least two of the first devices have a backup authentication device connected to the second device, the second device forwards the request to the first device as the target device based on the address information of the backup authentication device.

2. The method according to claim 1, characterized in that, The method further includes: If the device is not in a fault state, the user access request is authenticated, and the first authentication result or the second authentication result of rejecting authentication is generated and sent to the second device.

3. An access control method, characterized in that, Applied to a second device, the second device including a second authentication-free clearance module, the method includes: Obtain the user access authentication request sent by the user device; In response to a user access authentication request sent by the user equipment, determine whether there is a target device connected to the second device among at least two first devices; if so, forward the user access authentication request to the target device. If not, the second authentication-free access module is activated, and the first authentication result that has passed authentication is sent to the user equipment based on the second authentication-free access module; The at least two first devices include a primary authentication device and a backup authentication device, and the forwarding of the user access authentication request to the target device includes: If the primary authentication device is connected to the second device, then the address information of the target device is determined to be the address information of the primary authentication device; If the primary authentication device is not connected to the second device, and the backup authentication device is connected to the second device, then the address information of the target device is determined to be the address information corresponding to the backup authentication device connected to the second device. Based on the address information of the target device, the user access authentication request is forwarded to the target device; The user access authentication request, once acquired by the target device, causes the target device to invoke the availability detection module; based on the availability detection module, the target device's availability is detected, and its fault status is determined; the fault status indicates whether the target device's availability is normal. If the device is in a fault state, the first authentication-free release module of the target device is activated, and the first authentication result of successful authentication is sent to the second device based on the first authentication-free release module.

4. The method according to claim 3, characterized in that, Determining whether, among at least two of the first devices, there exists a target device connected to the second device includes: Obtain an address information set, wherein the address information set includes the address information of each of at least two first devices; If all the address information in the address information set is not connected, then it is determined that there is no target device connected to the second device; If the address information of at least one first device in the address information set is connectable, then it is determined that there is a target device connected to the second device.

5. An access control device, characterized in that, Applied to a first device, the first device including a first authentication-free release module and an availability detection module, the device includes: The first acquisition module is used to receive user access authentication requests forwarded by the second device; The control module is used to respond to the user access authentication request, detect its own fault status, and if it is in a fault state, activate the first authentication-free access module. The first authentication-free release module is used to send the first authentication result (if authentication is successful) to the second device; The calling module is used to invoke the availability detection module in response to a user access authentication request; The generation module is used to detect the availability of the first device based on the availability detection module and determine its own fault status; the fault status indicates whether the availability of the first device is normal. The user access authentication request is obtained by the second device from the user device. After the second device determines that there is a master authentication device connected to the second device among at least two first devices, the second device forwards the request to the first device as the target device based on the address information of the master authentication device. Alternatively, if the second device determines that the primary authentication device is not connected to the second device, and at least two of the first devices have a backup authentication device connected to the second device, the second device forwards the request to the first device as the target device based on the address information of the backup authentication device.

6. An access control device, characterized in that, Applied to a second device, the second device including a second authentication-free clearance module, the device comprising: The second acquisition module is used to acquire user access authentication requests sent by user equipment. The first determining module is configured to, in response to a user access authentication request sent by the user equipment, determine whether there is a target device connected to the second device among at least two first devices; if so, forward the user access authentication request to the target device; if not, activate the second authentication-free access module. The second authentication-free access module is used to send the first authentication result (if authentication is successful) to the user equipment; The first device includes a primary authentication device and a backup authentication device. The first determining module is also used to determine the address information of the target device as the address information of the primary authentication device if the primary authentication device is connected to the second device. If the primary authentication device is not connected to the second device, but the backup authentication device is connected to the second device, then the address information of the target device is determined to be the address information corresponding to the backup authentication device connected to the second device. The forwarding module is used to forward user access authentication requests to the target device based on the target device's address information; The user access authentication request, once acquired by the target device, causes the target device to invoke the availability detection module; based on the availability detection module, the target device's availability is detected, and its fault status is determined; the fault status indicates whether the target device's availability is normal. If the device is in a fault state, the first authentication-free release module of the target device is activated, and the first authentication result of successful authentication is sent to the second device based on the first authentication-free release module.

7. An electronic device, characterized in that, include: The processor and memory for storing computer programs that can run on the processor, wherein, The processor, when running a computer program, performs the steps of the method according to any one of claims 1 to 4.

8. An access control authentication system, characterized in that, The method includes a first device and a second device, wherein the number of the first devices is at least two, the second device is communicatively connected to the first devices, the first devices are used to perform the steps of the method as described in any one of claims 1 to 2, and the second devices are used to perform the steps of the method as described in any one of claims 3 to 4.

Citation Information

Patent Citations

  • Method and device for processing switch of authentication business, network appliance and communication system

    CN101465862A

  • A method and apparatus for interactive information forwarding

    CN102299859A