A user online method, device, equipment, medium, product and network system

By specifying the user's IP address and subnet mask through attributes 8 and 9 of the RADIUS protocol, the problem of difficulty in tracing the source caused by the random allocation of IP addresses when users go online is solved, enabling rapid user location and security management, and improving the utilization rate of IP addresses and the efficiency of supervision.

CN118827624BActive Publication Date: 2025-11-21CHINA MOBILE COMM GRP SHAANXI CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410635156.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-05-21
Publication Date
2025-11-21
Estimated Expiration
2044-05-21

AI Technical Summary

Technical Problem

When a user goes online, the random allocation of IP addresses in existing technologies makes it difficult to trace the user's origin, making it impossible to locate the corresponding user through the IP address, which affects network security management and supervision.

Method used

By using attributes 8 and 9 of the RADIUS protocol, the user's IP address and subnet mask are specified, thus saving the correspondence between users and IP addresses, ensuring that the assigned IP address is fixed each time, and recording the user's usage history to achieve fast and efficient user traceability.

Benefits of technology

It enables rapid user location and traceability, facilitates network security management for operators, expands regulatory means, and achieves accurate user profiling through user traffic analysis, thereby improving the utilization rate of IP addresses.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118827624B_ABST
    Figure CN118827624B_ABST
Patent Text Reader

Abstract

The application discloses a user online method, device, equipment, medium, product and network system. In the user online method, the server finds the target attribute value corresponding to the target user identifier in response to the IP address acquisition request of the user to be online, thereby determining the corresponding target IP address and target subnet mask, and assigning them to the user to be online. Through the 8th attribute and the 9th attribute in the RADIUS protocol, the IP address and the subnet mask of the user can be specified, the server can save the corresponding relationship between the user and the IP address, after the user uses the target IP address to be online, the user can be traced through the target IP address, the user can be quickly located, the network security management of the operator is facilitated, and the supervision means is expanded. According to the analysis on the user traffic, the user accurate image is realized, and data support is provided.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application belongs to the technical field of communication, and particularly relates to a user online method, device, equipment, medium and product. BACKGROUND

[0002] When a user is online through a terminal, a server needs to allocate an Internet Protocol Address (IP address) to the user. Taking a traditional enterprise broadband as an example, its business logic is consistent with that of a home broadband (Point-to-Point Protocol over Ethernet (PPPOE) mode), the user takes an IP address from a public IP address pool for use, the IP address is recycled after the user is offline, and is allocated again when the user is online next time.

[0003] Because an IP address is randomly taken from a public IP address pool for use by the user, the allocated address may be the same as the last time or different. The result of random allocation of the IP address is that the IP address of the user is not fixed, which makes it difficult to trace the user through the IP address and locate the corresponding user through the IP address. SUMMARY

[0004] Embodiments of the present application provide a user online method, device, equipment, medium, product and network system, which can realize fast and efficient user tracing and user rapid positioning.

[0005] In one aspect, the present application provides a user online method applied to a server, and the method comprises the following steps.

[0006] Receiving an IP address acquisition request sent by a user to be online; the acquisition request carries a target user identifier of the user to be online;

[0007] In response to the acquisition request, if the target user identifier is pre-allocated with attribute values of an 8th attribute and a 9th attribute in a Remote Authentication Dial In User Service (RADIUS) protocol, searching for a target attribute value corresponding to the target user identifier; the attribute value of the 8th attribute of the RADIUS protocol is used to indicate IP addresses corresponding to different user identifiers, and the attribute value of the 9th attribute of the RADIUS protocol is used to indicate subnet masks corresponding to different user identifiers;

[0008] According to the target attribute value, determining a target IP address and a target subnet mask corresponding to the user to be online;

[0009] return the target IP address and the target subnet mask to the user to be logged in, so that the user to be logged in logs in through the target IP address.

[0010] On the other hand, after receiving the IP address acquisition request sent by the user to be logged in, the method further comprises:

[0011] In response to the acquisition request, determining the target IP address from the IP addresses currently idle in the gateway to which the user to be logged in belongs, in the case that the target user identifier is not pre-assigned with an attribute value;

[0012] Determining the target subnet mask based on the target IP address;

[0013] Returning the target IP address and the target subnet mask to the user to be logged in, so that the user to be logged in logs in through the target IP address, and assigning the target attribute value corresponding to the target user identifier based on the target IP address and the target subnet mask.

[0014] On the other hand, after the user to be logged in logs in through the target IP address, the method further comprises:

[0015] Saving the use record of the target IP address by the user to be logged in; wherein the use record comprises the log-in time of the target IP address, the use duration of the target IP address, and the log-off time of the target IP address.

[0016] On the other hand, the target attribute value assigned to the user identifier is cleared in the case that any of the following conditions is met:

[0017] The user has not logged in through the target IP address within a preset duration since the last time the target IP address is used;

[0018] An IP address recovery instruction of the user is received.

[0019] On the other hand, the application embodiment provides a network system, comprising:

[0020] At least one terminal, connected with the server, for sending an IP address acquisition request to the server in response to the operation of the user to be logged in;

[0021] The server is configured to implement the user log-in method.

[0022] On the other hand, the network system further comprises a three-layer virtual private network and a passive optical network connected with each other.

[0023] The terminal accesses the passive optical network, and the server accesses the three-layer virtual private network.

[0024] In still another aspect, an embodiment of the present application provides a user online device, applied to a server, the device comprising:

[0025] a receiving module, configured to receive an IP address obtaining request sent by a user to be online; the obtaining request carrying a target user identifier of the user to be online;

[0026] a searching module, configured to search for a target attribute value corresponding to the target user identifier in response to the obtaining request, in a case where the target user identifier is pre-assigned with attribute values of an 8th attribute and a 9th attribute in a RADIUS protocol; the attribute value of the 8th attribute in the RADIUS protocol being used to indicate IP addresses corresponding to different user identifiers, and the attribute value of the 9th attribute in the RADIUS protocol being used to indicate subnet masks corresponding to different user identifiers;

[0027] a determining module, configured to determine a target IP address and a target subnet mask corresponding to the user to be online according to the target attribute value;

[0028] a sending module, configured to return the target IP address and the target subnet mask to the user to be online, so that the user to be online logs in through the target IP address.

[0029] In still another aspect, an embodiment of the present application provides a user online device, the device comprising: a processor and a memory storing computer program instructions;

[0030] the processor implements the user online method described above when executing the computer program instructions.

[0031] In still another aspect, an embodiment of the present application provides a computer readable storage medium, the computer readable storage medium storing computer program instructions, the computer program instructions being executed by a processor to implement the user online method described above.

[0032] In still another aspect, an embodiment of the present application provides a computer program product, instructions in the computer program product being executed by a processor of an electronic device to cause the electronic device to perform the user online method described above.

[0033] In the user online method of the embodiment of the present application, the server responds to the IP address acquisition request of the user to be online, and in the case that the target attribute value corresponding to the target user identifier is found, the target IP address and the target subnet mask are determined and assigned to the user to be online. After obtaining the target IP address and the target subnet mask, the user to be online can be online through the target IP address. In this way, the IP address corresponding to each user is recorded, so that the IP address assigned by the server to a user is fixed each time. According to the eighth attribute and the ninth attribute in the RADIUS protocol, the IP address and the subnet mask of the user can be specified, so that the server can save the corresponding relationship between the user and the IP address. After the user is online through the target IP address, the user can be traced through the target IP address, the user can be quickly located, the network security management of the operator is facilitated, and the supervision means is expanded. According to the analysis of the user traffic, the user portrait is accurately drawn, and data support is provided. BRIEF DESCRIPTION OF DRAWINGS

[0034] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed to be used in the embodiments of the present application will be briefly introduced. Those skilled in the art can obtain other drawings according to these drawings without creating any creative labor.

[0035] Figure 1 A flowchart of a user online method provided by an embodiment of the present application is shown;

[0036] Figure 2 A schematic diagram of the interaction between the user and the server is shown;

[0037] Figure 3 A flowchart of a user IP address allocation method provided by an embodiment of the present application is shown;

[0038] Figure 4 A specific implementation flowchart of user tracing provided by the present application is shown;

[0039] Figure 5 A timing diagram of the user online flow is shown;

[0040] Figure 6 A schematic diagram of a PPPoE user access network is shown;

[0041] Figure 7 A network topology diagram of the user access server is shown;

[0042] Figure 8 A hardware structure diagram of a user online device provided by an embodiment of the present application is shown. DETAILED DESCRIPTION

[0043] The features and exemplary embodiments of the various aspects of the present application will be described in detail below with reference to the drawings. The following detailed description is merely intended to explain the present application, and is not intended to limit the present application. The present application can be implemented without some of the specific details. The following description of the embodiments is merely provided to give a better understanding of the present application by showing examples of the present application.

[0044] It should be noted that the terms such as first and second, etc., are merely intended to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between such entities or operations. Also, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that processes, methods, articles or devices including a series of elements not only include those elements, but also include other elements not explicitly listed or inherent to such processes, methods, articles or devices. Without more limitations, the elements defined by the statement "include" do not exclude the presence of other identical elements in the processes, methods, articles or devices including the elements.

[0045] In the conventional scheme, users access the network through a data line, which uses a point-to-point link, and each user occupies a user channel, which seriously wastes IP addresses, and the address utilization rate is only 25%. For example, a user is allocated an IP address of 192.168.1.0 / 30, according to the protocol, there are a total of 4 IP addresses in the network segment, one of which is a network address, one is a broadcast address, one is used by the user gateway, and the user actually has only one IP address, and the user IP address utilization rate is only 25%.

[0046] In order to improve the address utilization rate, an enterprise broadband mode is proposed, which has the same business logic as the home broadband (PPPOE mode), and users dial into the operator broadband remote access server (BRAS) device through a username and password, and the BRAS uniformly allocates IP addresses to each user in the user address pool, and the IP address pool is shared by all users. The user applies for an IP address each time he logs in, and the IP address is released immediately when the user logs out. Since the IP address pool is shared by all users, the IP address is randomly allocated, and the IP address is different each time, which makes it difficult to identify and locate users through IP addresses, and it is difficult to trace the source of network security incidents.

[0047] Therefore, it is necessary to improve the user IP address allocation method, realize user IP address fixation, assign a fixed IP address to the user, realize one-to-one correspondence between the IP address and the user name, realize fast identification and tracing of the user, and meet the user network security requirements.

[0048] To solve the above technical problems, the embodiments of the present application provide a user online method, device, equipment, medium, product and network system. First, the user online method provided by the embodiments of the present application is introduced.

[0049] Figure 1 The flowchart of the user online method provided by one embodiment of the present application is shown. As shown in Figure 1 The method comprises the following steps S101-S104:

[0050] S101: receiving an IP address acquisition request sent by a user to be online.

[0051] The target user identifier of the user to be online is carried in the acquisition request. When the user needs to be online, the terminal sends an IP address acquisition request to the server. After the server receives the acquisition request, the target user identifier in the request is acquired. Generally, the user to be online sends the acquisition request to the server, which carries the user's own account opening information. The account opening information can be used as the user identifier.

[0052] S102: in response to the acquisition request, if the target user identifier is pre-assigned with attribute values of the 8th attribute and the 9th attribute in the RADIUS protocol, the target attribute value corresponding to the target user identifier is found.

[0053] The attribute value of the 8th attribute (Framed-IP-Address) of the RADIUS protocol is used to indicate the IP address corresponding to different user identifiers, and the attribute value of the 9th attribute (Framed-IP-Netmask) of the RADIUS protocol is used to indicate the subnet mask corresponding to different user identifiers. As mentioned above, after the server receives the acquisition request, the target user identifier (such as the account opening information of the user to be online) is analyzed from the request, and then it is judged whether the target user identifier is pre-assigned with attribute values of the 8th attribute and the 9th attribute in the RADIUS protocol. If not, temporary allocation is needed; if yes, the target attribute value corresponding to the target user identifier is found in the self memory.

[0054] S103: determining the target IP address and the target subnet mask corresponding to the user to be online according to the target attribute value.

[0055] S104: return the target IP address and target subnet mask to the user to be online, so that the user to be online logs in through the target IP address.

[0056] For S103 and S104, because the user logs in while needing the IP address and the subnet mask, the attribute field information carrying the attribute No. 8 and No. 9 of the RADIUS protocol needs to be issued, which contains two target attribute values corresponding to the target IP address and the target subnet mask, and finally converts the IP address and the subnet mask to the user to be online.

[0057] Generally, after the PPPOE user dials in the BRAS device, the BRAS device dynamically allocates the IP address to the user according to the preset user IP pool, and when the user logs out, the BRAS device recycles the IP address of the offline user. When the user logs in again, the NAS device randomly allocates the IP address to the user, and the IP address allocated by the user each time is not the same. In this way, as long as the NAS address pool can meet the maximum concurrency, the user address demand can be met, and the IP address can be saved.

[0058] But the industry user requires that the user and the IP address are one-to-one corresponding, and each user uses a fixed IP address. Therefore, we need to use the attribute No. 8 and No. 9 in the RADIUS protocol to realize the IP address fixing of the operator enterprise broadband PPPOE user. Figure 2 The schematic diagram of the interaction between the user and the server is shown in the following figure: Figure 2 As shown in the figure, the user 1 is connected with the network access server 2, the network access server interacts with the RADIUS server 3, and finally the target IP address and the target subnet mask of the user 1 are determined.

[0059] The following table describes the specific parameters of the attributes used in the present scheme:

[0060] Table 1 attribute No. 8

[0061]

[0062]

[0063] Table 2 attribute No. 9

[0064]

[0065]

[0066] In the user online method of this application embodiment, the server responds to the IP address acquisition request of the user to be online. Given pre-allocated target attribute values ​​for attributes 8 and 9 of the RADIUS protocol, the server finds the target attribute value corresponding to the target user identifier, thereby determining the corresponding target IP address and target subnet mask, and assigns them to the user to be online. After obtaining the target IP address and target subnet mask, the user can go online using the target IP address. This method records the IP address corresponding to each user, ensuring that the IP address assigned to a user by the server is fixed each time. This technical solution, through attributes 8 and 9 of the RADIUS protocol, can specify the user's IP address and subnet mask, enabling the server to save the correspondence between users and IP addresses. After a user goes online using their target IP address, the server can quickly and efficiently trace the user's origin, enabling rapid user location, facilitating network security management for operators, and expanding monitoring methods. Based on the analysis of user traffic, accurate user profiling is achieved, providing data support.

[0067] Typically, when a user first logs in, the server does not assign a corresponding IP address. The server cannot find the corresponding target IP address, and the user cannot log in. Therefore, if the target user identifier has not been pre-assigned attribute values, it is necessary to determine the target IP address from multiple IP addresses and assign it to the user. Figure 3 This illustration shows a flowchart of a user IP address allocation method provided in one embodiment of this application; as shown Figure 3 As shown, the method includes the following steps:

[0068] S301: In response to the request, determine the target IP address from the currently available IP addresses of the gateway to which the user to be connected belongs.

[0069] When a user waiting to log in sends an IP address retrieval request via their terminal, the server, upon receiving the request, will assign a corresponding IP address to the user if the target user identifier in the request has not been pre-assigned an attribute value. Specifically, this can be done by identifying available IP addresses from the IP addresses of the gateway to which the user belongs, and then selecting a target IP address from these available IP addresses.

[0070] S302: Determine the target subnet mask based on the target IP address.

[0071] Since users need both an IP address and a subnet mask to go online, based on the target IP address determined above, it is necessary to further determine the corresponding subnet mask, i.e., the target subnet mask.

[0072] S303: return the target IP address and the target subnet mask to the user to be online, so that the user to be online logs in through the target IP address, and the target user identifier is assigned a corresponding target attribute value based on the target IP address and the target subnet mask.

[0073] After the target IP address and the target subnet mask are determined, the target IP address and the target subnet mask are returned to the user to be online, and the user to be online can log in through the target IP address. And the 8th attribute and the 9th attribute of the RADIUS protocol are assigned values based on the target IP address and the target subnet mask, that is, the target attribute value corresponding to the target user identifier.

[0074] The embodiment provides a user target attribute value allocation scheme. Through the scheme, the allocation of the target attribute value and the distribution of the IP address can be completed when the user logs in for the first time, and the determination of the IP address corresponding to the user to be online is quickly and efficiently completed.

[0075] In addition, in actual application, there is a demand for user tracing, that is, finding the corresponding user through the IP address, which requires saving the behavior of the user using the IP address.

[0076] Specifically, the embodiment provides a scheme, after the user to be online logs in through the target IP address, the use record of the user to be online to the target IP address is saved; wherein the use record includes the target IP address online time, the target IP address use duration and the target IP address offline time.

[0077] Through the scheme provided by the embodiment, the use record of the user to the IP address is saved, and the user using the IP address can be quickly and efficiently found in the subsequent tracing process, so that the user positioning is realized.

[0078] In specific implementation, there may be user logout and the like, at this time, if the target attribute value allocated to the user is still retained, unnecessary occupation of the corresponding IP address will be caused, and IP address waste is caused. Therefore, the IP address needs to be recycled when the user no longer uses the IP address.

[0079] The embodiment provides a scheme, in any one of the following cases, the target attribute value allocated to the user identifier is cleared:

[0080] The user does not log in through the target IP address within a preset time duration since the last use of the target IP address;

[0081] The IP address recycling instruction of the user is received.

[0082] In the scheme provided in the embodiment, part of the IP addresses are recovered. First, if a user does not log in for a long time, it is indicated that the user account may not be used any more, and then the corresponding IP address can be recovered. In addition, if the user logs out, the server can be sent an IP address recovery instruction. Through the scheme provided in the embodiment, the IP address can be prevented from being invalidly occupied, and thus the address utilization rate is improved.

[0083] Figure 4 A specific implementation process diagram of user tracing provided in the application is shown in FIG. 1. Figure 4 As shown in FIG. 1, the tracing specifically includes the following steps: S401: a PPPOE user initiates an online request. S402: the PPPOE user dials into a Layer 3 Virtual Private Network (L3VPN) of a metropolitan area network. S403: a 3A server returns a fixed IP address through a RADIUS attribute. S404: precise tracing of the user is realized through a cloud platform.

[0084] The technology specifically used in the application is PPPOE+L3VPN+Radius, which utilizes an existing PON network of an operator, realizes enterprise broadband user fixed IP mode of the user service through deployment of L3VPN service in a metropolitan area network and customized modification of 3A, and achieves the purpose of fast and precise tracing of the user.

[0085] Here, the online process of a PPPOE user is briefly described. Figure 5 A timing diagram of the user online process is shown in FIG. 2. Figure 5 As shown in FIG. 2, the PPPOE user online needs to go through two stages, a PPPOE discovery stage and a PPP session stage. The discovery stage mainly selects a PPPOE server and determines a session identifier Session ID to be established. The PPP session stage executes a standard PPP process, including a Link Control Protocol (LCP) negotiation, Password Authentication Protocol (PAP) / Challenge Handshake Authentication Protocol (CHAP) authentication and Network Control Protocol (NCP) negotiation.

[0086] Figure 6 A networking schematic diagram of PPPOE user access is shown in FIG. 3. Figure 6As shown, the PPPoE protocol adopts a client Client / Server mode, and the basic roles in the PPPoE network are a PPPoE Client (user), a PPPoE Server operator server, and a RADIUS device.

[0087] Passive Optical Network (PON) is the main technology for fiber broadband access. PON is composed of an Optical Line Terminal (OLT), an Optical Distribution Network (ODN), and an Optical Network Unit (ONU). The OLT is a local device. The user-side device includes an Optical Network Terminal (ONT) and an ONU.

[0088] The ONT is usually used by a single user and is also commonly known as a modem, a Fiber To The Office (FTTO), and a Fiber To The Home (FTTH) user terminal. The ONU is usually shared by multiple users and is mainly used in Fiber To The Building (FTTB). The user-side device can also be collectively referred to as an ONU. The ODN refers to a passive optical distribution network composed of an access optical cable line and an optical splitter between the OLT and the ONU.

[0089] Carrier metropolitan area network: The construction of the metropolitan area network is mainly based on IP technology and provides a series of integrated services such as voice, data, and video access in a city, so as to meet the network needs of all government agencies, enterprises and institutions, and individual families in various application scenarios in the city. This scheme uses VPN technology in the metropolitan area network to realize user traffic penetration in the metropolitan area network and extends user services to all corners of the province through the metropolitan area network.

[0090] The carrier 3A server provides network services, and Authentication / Authorization / Accounting (AAA) is a management mechanism for network security, which provides three security functions of authentication, authorization, and accounting.

[0091] The PPPoE discovery phase refers to the allocation of a Session ID for user access by the device, which is used to identify a PPPoE virtual link between a user and the device.

[0092] The PPPoE Client broadcasts a PPPoE Active Discovery Initiation (PPPoE PADI) packet, which contains the service type information that the user wants to obtain.

[0093] All PPPoE Servers in the Ethernet receive the initiation packet and compare the requested service with the service that they can provide. The PPPoE Server that can provide the service for the PPPoE Client sends back a PPPoE Active Discovery Offer (PPPoE PADO) packet.

[0094] The PPPoE Client can receive multiple PADO packets from the PPPoE Servers. The PPPoE Client selects a PPPoE Server that meets certain conditions from the PPPoE Servers that return the PADO packets and sends a PPPoE Active Discovery Request (PPPoE PADR) (non-broadcast) packet to the selected PPPoE Server, which encapsulates the required service information in the PADR packet.

[0095] After receiving the PADR packet, the selected PPPoE Server generates a unique session identifier to identify the PPPoE session between the PPPoE Client and the PPPoE Server and returns a PPPoE Active Discovery Session-confirmation (PPPoE PADS) packet to the PPPoE Client, which contains the unique session identifier. If no error occurs, the PPPoE Client and the PPPoE Server enter the PPP session stage.

[0096] The PPP session stage includes the LCP negotiation, PAP / CHAP authentication, and NCP negotiation stages.

[0097] In the LCP negotiation, the PPPoE Client and the PPPoE Server send LCP Configure-Request packets to each other.

[0098] After receiving the Configure-Request packets, the two parties make appropriate responses according to the support of the negotiation options in the packets. If both parties return Configure-ACK, it indicates that the LCP link is successfully established.

[0099] After the LCP link is successfully established, the PPPoE Server periodically sends an LCP Echo-Request packet to the PPPoE Client, and then receives an Echo-Reply packet returned by the PPPoE Client, to detect whether the LCP link is normal, so as to maintain the LCP connection.

[0100] In the PAP / CHAP authentication, PAP is a two-handshake protocol, which authenticates a user by a username and a password, and the username and the password are transmitted in a clear text mode. The PPPoE Server (or a RADIUS server) checks whether the username and the password are correct according to a user table of the local end. The PAP is suitable for an environment with a relatively low network security requirement.

[0101] CHAP authentication is a three-handshake protocol, which also checks whether the username and the password are correct according to a user table of the local end by the PPPoE Server (or the RADIUS server). However, the CHAP authentication mode only transmits the username on the network, and does not transmit the user password, so the security is higher than that of the PAP.

[0102] The main function of the NCP negotiation is to negotiate the network layer parameters of the PPP packet, such as the IPCP and the IPv6CP. The PPPoE Client mainly obtains an IP address or an IP address segment of an access network by the IPCP protocol. After the NCP negotiation is successful, the PPPoE Client is online, and at this time, the PPPoE Server sends a charging request packet to the RADIUS server, to charge the PPPoE Client by the RADIUS server.

[0103] To solve the above technical problems, the embodiment of the present application further provides a network system, comprising:

[0104] At least one terminal, connected with the server, configured to send an IP address acquisition request to the server in response to an operation of a user to be online;

[0105] The server is configured to implement the user online method in the above embodiment.

[0106] Since the network system provided by the embodiment corresponds to the user online method provided by the above embodiment, the network system has the same effect as the user online method, and thus will not be described herein.

[0107] In actual application, the network connected between the server and the terminal is various, and in order to ensure the stability and efficiency of signal interaction, the network system further comprises an L3VPN network and a PON network connected with each other; the terminal accesses the PON network, and the server accesses the L3VPN network.

[0108] PON networks enable network extension and ensure stable and efficient signal transmission. L3VPN significantly improves network deployment speed without requiring a dedicated network, and it simplifies management, freeing users from involvement in complex network design, planning, and management.

[0109] Figure 7 A network topology diagram for user access to the server; such as Figure 7 As shown, after a user completes the PPPoE dial-up connection, the user needs to be imported into a dedicated VPN within the metropolitan area network (MAN). This requires pre-deploying an MPLS L3VPN network specific to this industry within the MAN to support users in that sector. After RADIUS returns a fixed IP address, user service traffic enters the L3VPN network deployed within the MAN. This traffic needs to be routed through routing policies to the exit device of the L3VPN interface with the user's private network, enabling access to the user's service platform.

[0110] Each metropolitan area network (MAN) BRAS device virtualizes a VPN instance and binds it to the user interconnection interface, enabling full connectivity between MAN BRAS. After completing the L3VPN deployment in the MAN, it forms a logical VPN network that is logically isolated from internet services.

[0111] In practical applications, users at various locations can be uniformly imported into the metropolitan area network's medical insurance VPN network. This VPN, provided to users via the operator's public network, acts as a private network for users, fulfilling their needs for inter-user communication (Spoke-PE) and access to the medical insurance cloud platform (Hub-PE). Using L3VPN significantly improves network deployment speed without requiring a dedicated network, and it simplifies management, eliminating the need for users to participate in the design, planning, and management of complex networks.

[0112] Users dial into the metropolitan area network (MAN) BRAS device via their ONU device. After authentication and billing authorization are obtained through the 3A server, users receive a fixed private IP address. User data is then transmitted via the PON network to the MAN BRAS, enters the corresponding VPN interface, and is then forwarded through the L3VPN network to the medical insurance L3VPN exit BRAS device, establishing connectivity with the medical insurance access router and enabling access to the province-wide unified platform. This system provides users with fixed IP addresses and isolates the industry's private network from the internet through VPN, ensuring secure and stable data transmission.

[0113] Users access the metropolitan area network (MAN) via the PON network. After receiving a specified fixed IP address from the RADIUS service, they access a dedicated L3VPN network through the nearest MAN node. The L3VPN network deployed in the MAN then directs user traffic to the industry user's private network, enabling users to access their private cloud.

[0114] After switching to PPPoE, this solution achieves a 99.2% address utilization rate (taking a Class C address as an example: 233 ÷ 255 = 0.992). Through a 3A authentication server and the operator's BRAS, using attributes 8 and 9 of the RADIUS protocol, fixed IP addresses are assigned to PPPoE users, achieving static address allocation. Fixed user IP addresses enable operators to quickly and efficiently trace user network security, and more importantly, assist regulatory authorities in identifying illegal users based on user behavior.

[0115] By fixing user addresses, we can achieve fast and efficient user security tracing, quickly locate users, facilitate network security management for operators, and expand user monitoring methods. Based on user traffic analysis, we can create precise user profiles, providing data support for secondary marketing.

[0116] By connecting the PON network to the metropolitan area network L3VPN, the extension of the operator's VPN network is realized, which greatly extends the scope of the L3VPN network extension.

[0117] By deploying L3VPN over a metropolitan area network, logical isolation between the user's private network and the internet can be achieved, making data more reliable and secure.

[0118] This application combines three technologies—PPPoE, Multi-Protocol Label Switching (MPLS), L3VPN, and RADIUS—and integrates PON, metropolitan area network (MAN), and enterprise private network to achieve service penetration and connectivity for users. Users access the network via PON, services are penetrated within the MAN via L3VPN, and finally, services converge and connect to the enterprise private network at a specific MAN exit, enabling enterprise users to quickly and conveniently access the enterprise business platform.

[0119] During the deployment process, enterprise users return a fixed business IP address to users through the RADIUS protocol, which maps user accounts to IP addresses one by one. This fixed IP address makes it easier for management units to trace and locate users, and at the same time, it allows for precise user profiling through user traffic analysis.

[0120] This method is implemented using a combination of the following three protocols:

[0121] PPPoE can be referred to as PPP protocol over Ethernet, applied in link layer. It provides point-to-point connection on Ethernet, establishes PPP session, and encapsulates PPP message into PPPoE message. PPPoE technology can connect users to remote access device, and provides good access control function, provides an economical user access technology, and realizes control on users. PPPoE uses Ethernet, provides remote user host access function, and can provide charging data of data transmission, solves practical application problems such as user online charging, and is widely applied in access operator network.

[0122] MPLS L3VPN is a PE-based L3VPN technology in operator VPN solution, which uses Border Gateway Protocol (BGP) to publish VPN route on service provider backbone network, and uses MPLS to forward VPN message on operator backbone network. MPLS L3VPN networking mode is flexible, good in scalability, and can conveniently support MPLS QoS and MPLS TE, and is widely applied in vertical industry private network.

[0123] RADIUS is a distributed, C / S architecture information interaction protocol, which can contain network interference from unauthorized access, and is commonly applied in various network environments which require high security and allow remote user access. RADIUS is originally an AAA protocol for dial-up users, and then adapts to various user access modes such as Ethernet access with the diversification of user access modes. It provides access service through authentication and authorization, and collects and records user use of network resources through charging.

[0124] To solve the above technical problems, the embodiment of the application further provides a user online device applied to a server, comprising the following modules:

[0125] The receiving module is configured to receive an IP address acquisition request sent by a user to be online, and the acquisition request carries a target user identifier of the user to be online;

[0126] The searching module is configured to search for a target attribute value corresponding to the target user identifier in response to the acquisition request, in a case where the target user identifier is pre-assigned with attribute values of an 8th attribute and a 9th attribute in a RADIUS protocol; the attribute value of the 8th attribute in the RADIUS protocol is used to indicate IP addresses corresponding to different user identifiers, and the attribute value of the 9th attribute in the RADIUS protocol is used to indicate subnet masks corresponding to different user identifiers;

[0127] The determining module is configured to determine a target IP address and a target subnet mask corresponding to the user to be online according to the target attribute value.

[0128] The sending module is configured to return the target IP address and the target subnet mask to the user to be online, so that the user to be online logs in through the target IP address.

[0129] Figure 8 A hardware structure schematic diagram of a user online device provided by an embodiment of the present application is shown. As shown in the figure, the user online device can include a processor 801 and a memory 802 storing computer program instructions. Figure 8

[0130] Specifically, the processor 801 can include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or can be configured to implement one or more integrated circuits of the embodiments of the present application.

[0131] The memory 802 can include a mass storage for data or instructions. By way of example and not limitation, the memory 802 can include a hard disk drive (HDD), a floppy disk drive, a flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a universal serial bus (USB) drive or a combination of two or more of these. Where appropriate, the memory 802 can include removable or non-removable (or fixed) media. Where appropriate, the memory 802 can be internal or external to the integrated gateway disaster recovery device. In a particular embodiment, the memory 802 is non-volatile solid-state memory.

[0132] The memory 802 can include read-only memory (ROM), random access memory (RAM), a disk storage medium device, an optical storage medium device, a flash memory device, an electrical, optical, or other physical / tangible memory storage device. Thus, generally, the memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions that, when executed (e.g., by one or more processors), are operable to perform the operations described with reference to the methods according to an aspect of the present disclosure.

[0133] The processor 801 implements any one of the user online methods in the above embodiments by reading and executing the computer program instructions stored in the memory 802.

[0134] In one example, the user online device can further include a communication interface 803 and a bus 810. The processor 801, the memory 802, and the communication interface 803 are connected through the bus 810 and complete communication with each other. ​

[0135] The communication interface 803 is mainly configured to implement communication between modules, devices, units and / or equipment in the embodiments of the present application.

[0136] The bus 810 includes hardware, software, or both, that couples components of the user online device to each other in a communicative manner. By way of example and not limitation, the bus can include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an InfiniBand interconnect, a Low Pin Count (LPC) bus, a memory bus, a Micro Channel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association local (VLB) bus, or another suitable bus or a combination of two or more of these. Where appropriate, the bus 810 can include one or more buses. Although the present embodiments describe and show a particular bus, the present application contemplates any suitable bus or interconnect.

[0137] In addition, in combination with the user online method in the above embodiments, the present embodiments can provide a computer storage medium for implementation. The computer storage medium has computer program instructions stored thereon; the computer program instructions are executed by a processor to implement any of the user online methods in the above embodiments.

[0138] The present embodiments also provide a computer program product, including a computer program, which is executed by a processor to implement any of the user online methods in the above embodiments.

[0139] It needs to be clear that the present application is not limited to the specific configurations and processes described above and shown in the drawings. For the sake of brevity, detailed descriptions of well-known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method processes of the present application are not limited to the specific steps described and shown, and those skilled in the art can make various changes, modifications and additions, or change the order between steps, after understanding the spirit of the present application.

[0140] The functions shown in the above-described structural block diagrams can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application specific integrated circuits (ASICs), appropriate firmware, plug-ins, functional cards, and the like. When implemented in software, the elements of the present application are program or code segments that are used to perform the required tasks. The program or code segments can be stored in a machine-readable medium or transmitted through a data signal carried in a carrier wave over a transmission medium or communication link. The "machine-readable medium" can include any medium that can store or transfer information. Examples of the machine-readable medium include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, fiber optic medium, radio frequency (RF) links, and the like. The code segments can be downloaded via a computer network such as the Internet, an intranet, and the like.

[0141] It is also noted that the exemplary embodiments mentioned in the present application describe some methods or systems based on a series of steps or devices. However, the present application is not limited to the order of the above steps, that is, the steps can be performed in the order mentioned in the embodiments, or in an order different from the embodiments, or several steps can be performed simultaneously.

[0142] The above-described aspects and implementations of the present application can be implemented, for example, using a computer program product, an apparatus, and / or a processing system that includes functional blocks that can be implemented using one or more software modules. For example, the computer program product or software elements of the present application can include at least one of a storage medium or memory device encoded with one or more computer programs that, when executed on one or more computing devices, perform at least a portion of the functions described herein. The computer program in the present disclosure can be implemented in a high level procedural or object oriented programming language to communicate with a processing system. The software elements can be any of an implementation comprising a standalone software package, a software routine, a program, a component of a program, either in source code, binary code, interpreted code, object oriented code, visual component, or another implementation. The software implementation can be any combination of code, data and / or code segments that perform particular tasks or implement specific abstract data types according to the methods and / or logic described herein. The above-described aspects and implementations of the present application can be implemented using a computer program product comprising a computer-readable medium having stored thereon a computer program having a plurality of code sections configured to carry out the methods described herein when the computer program is executed on a server or client computer.

[0143] The above merely describes a specific implementation of the present application. Those skilled in the art can clearly understand the specific working processes of the system, modules and units described above for the convenience and brevity of description, and can refer to the corresponding processes in the foregoing method embodiments, which will not be described herein again. It should be understood that the protection scope of the present application is not limited to this, and any person skilled in the art can easily think of various equivalent modifications or replacements within the technical range disclosed by the present application, and these modifications or replacements should be covered within the protection scope of the present application.

Claims

1. A method for user on-line, characterized in that, Applied to a server, the method comprises: receiving an acquisition request of an Internet Protocol (IP) address sent by a user to be online; the acquisition request carries a target user identifier of the user to be online; in response to the acquisition request, if the target user identifier is pre-assigned with attribute values of an 8th attribute and a 9th attribute in a Remote Authentication Dial In User Service (RADIUS) protocol, searching for target attribute values corresponding to the target user identifier; the attribute value of the 8th attribute in the RADIUS protocol is used to indicate IP addresses corresponding to different user identifiers, and the attribute value of the 9th attribute in the RADIUS protocol is used to indicate subnet masks corresponding to different user identifiers; determining target IP addresses and target subnet masks corresponding to the user to be online according to the target attribute values; returning the target IP addresses and the target subnet masks to the user to be online, so that the user to be online logs in through the target IP addresses.

2. The method of claim 1, wherein, After the receiving of the acquisition request of the IP address sent by the user to be online, the method further comprises: in response to the acquisition request, if the target user identifier is not pre-assigned with attribute values, determining the target IP addresses from currently idle IP addresses of a gateway to which the user to be online belongs; determining the target subnet masks based on the target IP addresses; returning the target IP addresses and the target subnet masks to the user to be online, so that the user to be online logs in through the target IP addresses, and the target user identifier is assigned with corresponding target attribute values based on the target IP addresses and the target subnet masks.

3. The method of claim 2, wherein, After the user to be online logs in through the target IP addresses, the method further comprises: saving a use record of the target IP addresses by the user to be online; the use record comprises a log-in time of the target IP addresses, a use duration of the target IP addresses, and a log-off time of the target IP addresses.

4. The method of claim 1, wherein, the target attribute values assigned to the user identifier are cleared in any of the following cases: the user does not log in through the target IP addresses within a preset duration since the last use of the target IP addresses; an IP address recovery instruction of the user is received.

5. A network system characterized by comprising: comprises: at least one terminal connected with a server, configured to send an acquisition request of an IP address to the server in response to an operation of a user to be online; the server is configured to implement the user online method according to any one of claims 1-4.

6. The network system of claim 5, wherein, The network system further comprises a three-layer virtual private network and a passive optical network connected with each other; the terminal accesses the passive optical network, and the server accesses the three-layer virtual private network.

7. A user on-line device, characterized by applied to a server, the device comprises: a receiving module, configured to receive an acquisition request of an IP address sent by a user to be online; the acquisition request carries a target user identifier of the user to be online; The searching module is configured to search for a target attribute value corresponding to the target user identifier in response to the acquisition request, in a case where the target user identifier is pre-assigned with attribute values of an attribute No. 8 and an attribute No. 9 in a RADIUS protocol, wherein the attribute value of the attribute No. 8 in the RADIUS protocol is used to indicate an IP address corresponding to different user identifiers, and the attribute value of the attribute No. 9 in the RADIUS protocol is used to indicate a subnet mask corresponding to different user identifiers; The determining module is configured to determine a target IP address and a target subnet mask corresponding to the user to be logged in according to the target attribute value; The sending module is configured to return the target IP address and the target subnet mask to the user to be logged in, so that the user to be logged in logs in through the target IP address.

8. A user online device, characterized by The device comprises a processor and a memory storing computer program instructions; The processor executes the computer program instructions to implement the user logging in method according to any one of claims 1-4.

9. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer program instructions, and the computer program instructions are executed by the processor to implement the user logging in method according to any one of claims 1-4.

10. A computer program product, characterised in that, The instructions in the computer program product are executed by the processor of the electronic device, so that the electronic device executes the user logging in method according to any one of claims 1-4.

Citation Information

Patent Citations

  • Method and system for negotiating internet protocol version 6 (IPv6) information

    CN102624707A

  • Address allocation method, device and system

    CN114079649A