Communication method and device

By searching online user entries based on source IP addresses in the firewall and applying corresponding policies to process packets, the problem of RADIUS single sign-on being unable to support multiple types of users and multiple management domains is solved, achieving efficient user authentication and management.

CN119172126BActive Publication Date: 2025-10-03NEW H3C TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411223383.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-02
Publication Date
2025-10-03
Estimated Expiration
2044-09-02

AI Technical Summary

Technical Problem

Existing RADIUS single sign-on cannot support diverse user scenarios and differentiated configurations of multiple RADIUS management domains, resulting in inefficient user authentication and management.

Method used

By receiving service packets on the firewall and searching for online user entries based on the source IP address, the firewall applies the corresponding user policy to process the packet if the entry exists, and discards the packet if the entry does not exist. The firewall then generates online user entries using RADIUS protocol packets, thus avoiding repeated configuration of user authentication information.

Benefits of technology

It implements effective user message processing in scenarios with multiple types of users and multiple RADIUS management domains, simplifies the configuration and authentication process, and improves the efficiency and flexibility of user authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119172126B_ABST
    Figure CN119172126B_ABST
Patent Text Reader

Abstract

The present application provides a communication method and apparatus, which is applied to a firewall. The method includes: receiving a service message, wherein the service message includes a source IP address; based on the source IP address, locally searching whether there is an online user table entry that matches the source IP address; if so, processing the service message using a user policy corresponding to the online user table entry; if not, discarding the service message.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a communication method and device. Background Art

[0002] Remote Authentication Dial-In User Service (RADIUS) is the most widely used authentication, authorization, and accounting (AAA) protocol. AAA is a management framework and, therefore, can be implemented using a variety of protocols. In practice, RADIUS is the most commonly used protocol for AAA implementation.

[0003] RADIUS single sign-on means that the enterprise has deployed the RADIUS authentication mechanism. After being authenticated by the RADIUS server, the enterprise can directly access network resources without the need for authentication by the firewall.

[0004] During RADIUS authentication, the Network Access Server (NAS) acts as a proxy client for the RADIUS server, submitting authentication information (e.g., username and password) to the RADIUS server. Once the authentication information is successfully verified, the NAS exchanges accounting messages with the RADIUS server. The firewall parses the accounting messages to determine the correspondence between the user and the IP address, allowing the user to log online at the firewall.

[0005] However, the existing RADIUS single sign-on also exposes the following defects: 1) The existing RADIUS single sign-on can only configure one RADIUS attribute value as the user name, and does not support multiple types of user scenarios, such as: different types of user names, one using a mobile phone number as the user name; one using an IMSI number as the user name; 2) The existing RADIUS single sign-on can only configure one set of RADIUS management domains (the overall system environment that integrates the RADIUS server, RADIUS client, and managed users, address + port + shared key + aging time), does not support authentication in different RADIUS management domains, and cannot formulate differentiated configurations for different RADIUS management domains. Summary of the Invention

[0006] In view of this, the present application provides a communication method and apparatus to solve the problem that the existing RADIUS single sign-on does not support scenarios with multiple types of users and scenarios with multiple RADIUS management domains.

[0007] In a first aspect, the present application provides a communication method, which is applied to a firewall, and includes:

[0008] receiving a service message including a source IP address;

[0009] According to the source IP address, searching locally to see if there is an online user entry matching the source IP address;

[0010] If so, the service message is processed according to the user policy corresponding to the online user entry;

[0011] If not, the service message is discarded.

[0012] In a second aspect, the present application provides a communication device, which is applied to a firewall, and includes:

[0013] A receiving unit, configured to receive a service message, wherein the service message includes a source IP address;

[0014] A search unit, configured to search locally for an online user entry matching the source IP address based on the source IP address;

[0015] a processing unit, configured to process the service message according to a user policy corresponding to the online user entry, if the service message exists;

[0016] A discarding unit is used to discard the service message if it does not exist.

[0017] In a third aspect, the present application provides a network device comprising a processor and a machine-readable storage medium, wherein the machine-readable storage medium stores machine-executable instructions that can be executed by the processor, and the processor is prompted by the machine-executable instructions to execute the method provided in the first aspect of the present application.

[0018] Therefore, by applying the communication method and device provided by the present application, the firewall receives a business message, which includes a source IP address; based on the source IP address, the firewall locally searches whether there is an online user table entry that matches the source IP address; if so, the firewall processes the business message through the user policy corresponding to the online user table entry; if not, the firewall discards the business message.

[0019] This allows firewalls configured with RADIUS single sign-on to process user service packets in scenarios with multiple user types and multiple RADIUS management domains. The firewall can share authenticated user data with the RADIUS server and generate online user entries using the various attributes included in RADIUS protocol packets. This eliminates the need for reconfiguration of extensive user authentication information and secondary authentication on the firewall, simplifying the configuration and authentication process. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] Figure 1 A flow chart of a communication method provided in an embodiment of the present application;

[0021] Figure 2 This is a diagram of the billing request message format provided in an embodiment of the present application;

[0022] Figure 3 The billing request message provided in the embodiment of the present application includes a format diagram of the billing status;

[0023] Figure 4 The charging request message provided in the embodiment of the present application includes a format diagram of the first standard attribute;

[0024] Figure 5 The charging request message provided in the embodiment of the present application includes a format diagram of the second standard attribute;

[0025] Figure 6 The charging request message provided in the embodiment of the present application includes a format diagram of a first private attribute;

[0026] Figure 7 The format diagram of the billing request message provided in the embodiment of the present application includes the user IP address;

[0027] Figure 8 The format diagram of the billing response message provided in the embodiment of the present application;

[0028] Figure 9 A schematic diagram of a network suitable for a communication method provided in an embodiment of the present application;

[0029] Figure 10 A signaling diagram of the communication method provided in an embodiment of the present application;

[0030] Figure 11 A structural diagram of a communication device provided in an embodiment of the present application;

[0031] Figure 12 The network device hardware structure provided in the embodiment of the present application. DETAILED DESCRIPTION

[0032] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.

[0033] The terms used in this application are for the purpose of describing specific embodiments only and are not intended to limit this application. As used in this application and the appended claims, the singular forms "a," "an," "the," and "the" are intended to include the plural forms, unless the context clearly indicates otherwise. It should also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the corresponding listed items.

[0034] It should be understood that although the terms first, second, third, etc. may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from each other. For example, without departing from the scope of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining".

[0035] The communication method provided in the embodiment of the present application is described in detail below. Figure 1 , Figure 1 This is a flow chart of a communication method provided in an embodiment of the present application. The method is applied to a firewall, which may be located within a server. The communication method provided in an embodiment of the present application may include the following steps.

[0036] Step 110: Receive a service message, where the service message includes a source IP address.

[0037] Specifically, when a user pre-accesses the Internet, a user terminal used by the user generates a service message including a source IP address, which is the address of the user terminal. The user terminal sends the service message to the firewall.

[0038] After receiving the service message, the firewall obtains the source IP address from it.

[0039] Step 120: Based on the source IP address, locally search whether there is an online user entry matching the source IP address.

[0040] Specifically, according to the description of step 110, after obtaining the source IP address from the service message, the firewall searches locally for an online user entry matching the source IP address.

[0041] If there is an online user entry matching the source IP address, the firewall executes step 130 ; if there is no online user entry matching the source IP address, the firewall executes step 140 .

[0042] Step 130: If yes, process the service message according to the user policy corresponding to the online user entry;

[0043] Specifically, as described in step 120, if there is an online user entry matching the source IP address, the firewall determines that the user has registered with it and obtains the user name or user ID from the online user entry. The service message is processed using the user policy corresponding to the user name or user ID.

[0044] In the embodiment of the present application, the user policy specifically refers to an action executed on a user's message, for example, allowing the user's message, discarding the user's message, etc. The firewall can allow or discard the user message according to the user policy.

[0045] Step 140: If the service message does not exist, discard the service message.

[0046] Specifically, according to the description of step 120, if there is no online user entry matching the source IP address, the firewall determines that the user is not registered within itself and discards the service message.

[0047] Therefore, by applying the communication method provided by the present application, the firewall receives a business message, which includes a source IP address; based on the source IP address, the firewall searches locally to see whether there is an online user table entry that matches the source IP address; if so, the firewall processes the business message through the user policy corresponding to the online user table entry; if not, the firewall discards the business message.

[0048] This allows firewalls configured with RADIUS single sign-on to process user service packets in scenarios with multiple user types and multiple RADIUS management domains. The firewall can share authenticated user data with the RADIUS server and generate online user entries using the various attributes included in RADIUS protocol packets. This eliminates the need for reconfiguration of extensive user authentication information and secondary authentication on the firewall, simplifying the configuration and authentication process.

[0049] Optionally, in an embodiment of the present application, the firewall will also perform a process of receiving a configuration file before receiving a service message.

[0050] Specifically, the user (or administrator) may send at least one configuration file to the firewall, each configuration file including at least one configuration policy, and each configuration policy is used to instruct the firewall to obtain the user name from different attributes included in the billing request message.

[0051] For example, the configuration file 1 is as follows.

[0052] user-identity sso radius profile 1

[0053] server-ip 1.1.1.1port 1813shared-key 111

[0054] online-user aging-time 1440

[0055] user-name attribute-id 31match-attribute-id 30value abc

[0056] user-name attribute-id vendor-specific 10415 1match-attribute-id30value123

[0057] In configuration file 1, the listening address, port, shared key, and aging time of online user entries for RADIUS protocol packets are configured.

[0058] Configuration file 1 also configures two policies for obtaining the user name. For example, Policy 1: If the value of Standard Attribute No. 30 in the Accounting Request message is XXX, the value of Standard Attribute No. 31 in the Accounting Request message is used as the user name. Policy 2: If the value of Standard Attribute No. 30 in the Accounting Request message is YYY, the value of Attribute No. 1 of the vendor's private attributes in the Accounting Request message is used as the user name.

[0059] Optionally, in an embodiment of the present application, before receiving the service message, the firewall will also execute the process of receiving the accounting request message sent by the NAS.

[0060] Specifically, before a user uses a user terminal to access the Internet, the user terminal first interacts with the RADIUS server through the NAS for user access authentication. After the NAS determines that the RADIUS server has successfully authenticated the user using the user terminal, the NAS starts the billing function.

[0061] The NAS generates and sends an Accounting Request message to RADIUS. Simultaneously, the NAS also sends an Accounting Request message to the firewall. It should be noted that the process by which the user terminal interacts with the RADIUS server through the NAS for access authentication, the NAS determines that the RADIUS server has successfully authenticated the user terminal, and then generates and sends an Accounting Request message to RADIUS is identical to the existing process described above and will not be repeated here.

[0062] The firewall receives the accounting request message from the NAS and obtains the destination IP address. The firewall determines whether the destination IP address is the IP address configured for the local machine (i.e., the firewall). If so, the firewall obtains the verification code from the accounting request message and verifies it.

[0063] If the verification code passes the verification, the firewall continues to obtain the user name and user IP address from the accounting request message. After obtaining the user name and user IP address, the firewall generates an online user table entry based on the user name and user IP address.

[0064] Optionally, in an embodiment of the present application, the above-mentioned charging request message includes an attribute field, and the attribute field includes a first standard attribute and a second standard attribute.

[0065] The specific process of the above firewall obtaining the user name from the accounting request message is as follows:

[0066] The firewall first obtains the first standard attribute from the accounting request message and sequentially identifies whether the value of the first standard attribute matches (i.e., is identical to) the value of standard attribute No. 30 in a configuration policy included in the configuration file. It is understood that multiple configuration files can be configured within the firewall, and each configuration file contains multiple configuration policies, which the firewall identifies sequentially.

[0067] If the value of the first standard attribute matches the first configuration policy, then according to the first configuration policy, the firewall uses the value of the second standard attribute as the user name.

[0068] Optionally, in an embodiment of the present application, the above-mentioned charging request message includes an attribute field, and the attribute field includes a first standard attribute and a first private attribute.

[0069] The specific process of the above firewall obtaining the user name from the accounting request message is as follows:

[0070] The firewall first obtains the first standard attribute from the accounting request message and sequentially identifies whether the value of the first standard attribute matches (i.e., is identical to) the value of standard attribute No. 30 in a configuration policy included in the configuration file. It is understood that multiple configuration files can be configured within the firewall, and each configuration file contains multiple configuration policies, which the firewall identifies sequentially.

[0071] If the value of the first standard attribute matches the second configuration policy, then according to the second configuration policy, the firewall uses the value of the first private attribute as the user name.

[0072] Optionally, in an embodiment of the present application, the above-mentioned charging request message includes an attribute field, and the attribute field includes a third standard attribute.

[0073] The specific process of the above firewall obtaining the user IP address from the accounting request message is as follows:

[0074] The firewall obtains the user IP address from the third standard attribute.

[0075] Optionally, in an embodiment of the present application, the configuration file further includes an online user aging time, and the online user aging time corresponds to each configuration file;

[0076] The specific process of the firewall generating online user entries based on the user name and user IP address is as follows:

[0077] Based on the user name, the firewall assigns a user ID to the user indicated by the user name. For example, user 1 is assigned a user ID of 123, user 2 is assigned a user ID of xyz, and so on.

[0078] The firewall obtains the user group information corresponding to the user name from the local computer. For example, user 1 belongs to the development group, user 2 belongs to the test group, and so on. The firewall generates at least one online user entry. Each online user entry includes the user ID, user name, user IP address, user group information, and online user aging time.

[0079] In an embodiment of the present application, after the firewall assigns a user ID to the user, each user ID can be stored through a HASH table. Similarly, each obtained user IP address can also be stored through a HASH table; online user table entries are also stored through a HASH table.

[0080] In this embodiment of the present application, the online user entry also records the update time of the online user aging time. For example, after the online user entry is generated, the update time is the creation time. The firewall can subsequently refresh the online user aging time upon receiving other RADIUS protocol messages. When the online user aging time expires, the firewall deletes the corresponding online user entry.

[0081] Optionally, in the embodiment of the present application, the above-mentioned billing request message also includes a billing status. After receiving the billing request message, the firewall will also execute the process of sending a billing response message.

[0082] Specifically, after the firewall identifies the destination IP address as the IP address configured for the local machine (i.e., the firewall), it also obtains the billing status from the billing request message. The firewall identifies the billing status and determines the current operation type based on the different values ​​of the billing status.

[0083] For example, if the value of the billing status is 1, it means that the current operation is billing start; if the value of the billing status is 2, it means that the current operation is billing stop.

[0084] Based on the billing status, the firewall generates and sends a billing response message to the NAS to inform the NAS that it has started the corresponding operation type.

[0085] It is understandable that the firewall may send the accounting response message before generating the online user entry.

[0086] Optionally, the configuration file further includes a shared key corresponding to each acquisition strategy. In an embodiment of the present application, the billing response message includes a type code, an identifier, a length, and a check code, which is obtained by performing an MD5 calculation on the type code, the identifier, the length, and the check code included in the billing request message using the shared key.

[0087] In the above embodiments, the fields and field values ​​included in the accounting request message are described. The above accounting request message is described in detail below.

[0088] like Figure 2 As shown, Figure 2 This is a diagram of the format of the billing request message provided in the embodiment of the present application. Figure 2 In the example, the charging request message includes an ETH header, an IP header, a UDP header, and a payload. The payload includes a type code field (occupying 1B), an identifier field (occupying 1B), a length field (occupying 2B), a checksum field (occupying 16B), and multiple attribute fields.

[0089] Among them, the value of the type code field (for example, 4), the value of the identifier field, the value of the length field, and the value of the check code field can be configured according to the existing RADIUS protocol and actual networking conditions, and will not be repeated here.

[0090] Each attribute field can carry multiple TLV structures, each of which is used to carry standard attributes or private attributes. The number of standard attributes or private attributes is multiple.

[0091] like Figure 3 As shown, Figure 3 The billing request message provided in the embodiment of the present application includes a format diagram of the billing status. Figure 3The ETH, IP, and UDP headers are omitted; only the payload is shown. The TLV carried in the attribute field includes a Type field (occupying 1B), a Length field (occupying 1B), and a Value field. The Type field has a value of 40, indicating that the standard attribute No. 40 carried by this TLV is the billing status. The Value field can have multiple values ​​to represent different billing statuses.

[0092] For example: the value of the type field is 40, the value of the value field is 1, which indicates the start of billing (Start); the value of the type field is 40, the value of the value field is 2, which indicates the stop of billing (Stop); the value of the type field is 40, the value of the value field is 3, which indicates the update of billing (Interim-Update), etc. Different values ​​of the specific value field represent different billing states and can be set according to actual conditions.

[0093] like Figure 4 As shown, Figure 4 The charging request message provided in the embodiment of the present application includes a format diagram of the first standard attribute. Figure 4 The ETH, IP, and UDP headers are omitted; only the payload is shown. The TLV carried in the attribute field includes a type field, a length field, and a value field. The type field value is 30, indicating that the TLV carries standard attribute number 30. The value field value is a configured value, for example, zwdggg.cuzw.gd.

[0094] like Figure 5 As shown, Figure 5 The charging request message provided in the embodiment of the present application includes a format diagram of the second standard attribute. Figure 5 The ETH header, IP header, and UDP header are omitted; only the payload is shown. The TLV carried in the attribute field includes a type field (occupying 1B), a length field (occupying 1B), and a value field. The type field has a value of 31, indicating that the TLV carries standard attribute number 31. The value field contains a mobile phone number string, for example, 8615612345678.

[0095] like Figure 6 As shown, Figure 6 The charging request message provided in the embodiment of the present application includes a format diagram of the first private attribute. Figure 6The ETH, IP, and UDP headers are omitted; only the payload is shown. The TLV carried in the attribute field includes a type field (1B), a length field (1B), and a value field. A type field value of 26 indicates that the TLV carries a private attribute. The value field carries the vendor ID (4B) and data. The vendor ID, for example, 10315, carries the sub-TLV structure, which includes a type field (1B), a length field (1B), and a value field. A type field value of 1 indicates that the sub-TLV carries private attribute number 1. Private attribute number 1 can be used to carry a text-formatted IMSI, which uniquely identifies a device such as a camera, sensor, or smartwatch. The value field carries the country code (for example, 460 for China, 3B), the carrier (for example, 01 for China Unicom, 2B), and a numeric identifier (for example, 2020000738).

[0096] like Figure 7 As shown, Figure 7 The billing request message provided in the embodiment of the present application includes a format diagram of the user's IP address. Figure 7 The ETH, IP, and UDP headers are omitted; only the payload is shown. The TLV carried in the attribute field includes a type field (occupying 1B), a length field (occupying 1B), and a value field. The type field has a value of 8, indicating that the eighth standard attribute carried by this TLV is the user IP address. The value field carries the IPv4 address.

[0097] like Figure 8 As shown, Figure 8 The format diagram of the billing response message provided in the embodiment of the present application. It can be understood that the billing response message also includes the ETH header, IP header, UDP header and payload. Figure 8 The payload includes a type code field (occupies 1B), an identifier field (occupies 1B), a length field (occupies 2B), and a check code field (occupies 16B).

[0098] Among them, the value of the type code field (for example, 5), the value of the identifier field (the same as the value of the identifier field in the billing request message), the value of the length field, and the value of the check code field (obtained by performing MD5 calculation on the type code, identifier, length, and check code included in the billing request message using a shared key) can be configured according to the existing RADIUS protocol and actual networking conditions and are not repeated here.

[0099] In an embodiment of the present application, the firewall includes multiple modules, each module performs different business functions, and the functions of multiple modules are combined to complete the steps performed by the firewall in the aforementioned embodiment.

[0100] like Figure 9 As shown, Figure 9 This is a network diagram suitable for the communication method provided in an embodiment of the present application. The network includes user device A, user device B, NAS, a RADIUS server, and a firewall. User device A can be specifically represented as a user terminal used by user 1, and user device B can be specifically represented as a camera used by user 2. User 1 and user 2 are both employees of different departments within the enterprise, with user 1 in the development department and user 2 in the testing department.

[0101] The firewall internally includes a registration module, a user account data management module, an online user data management module, a RADIUS parsing module, and a security policy module. The registration module is used to store user account data; the user account data management module is used to maintain and manage user account data; the RADIUS protocol parsing module is used to receive, parse according to the configuration file, and respond to RADIUS protocol messages to obtain data such as user names and IP addresses; the online user data management module is used to create, update, delete, and age online user entries, and provides a query interface for online user entries; the security policy module is used to determine the user to whom a service message belongs based on the service characteristics (e.g., IP address, MAC address, etc.) included in the service message, and to decide whether to allow or block the service message based on the security policy configuration corresponding to the user.

[0102] Therefore, in the embodiment of the present application, regardless of whether the users belong to the same department or different departments, and regardless of whether the types of devices used by the users are the same or different, in the networking, the firewall can obtain the values ​​of different attributes from the RADIUS protocol message as the user name through the configuration file, generate online user table entries of different departments and different types, and process the business messages of different departments and different types of users.

[0103] The communication method provided in the embodiment of the present application is described in detail below. Figure 10 , Figure 10 A signaling diagram of the communication method provided in an embodiment of the present application.

[0104] Step 1000: The user device performs user access authentication interaction with the RADIUS server through the NAS.

[0105] Step 1001: The firewall configures the RADIUS single sign-on function and starts the RADIUS protocol message listening service.

[0106] Step 1002: NAS starts the billing function.

[0107] Step 1003: NAS starts interacting with the RADIUS server and the firewall for accounting.

[0108] Specifically, after receiving the accounting request message, the firewall obtains the destination IP address from it. The firewall determines whether the destination IP address is the IP address configured for the local machine (i.e., the firewall). If so, the firewall obtains the verification code from the accounting request message and verifies the verification code.

[0109] If the verification code passes the verification, the firewall continues to obtain the first standard attribute from the accounting request message, for example, standard attribute No. 30. The firewall sequentially identifies whether the value of standard attribute No. 30 matches (i.e., is the same as) the value of standard attribute No. 30 in a configuration policy included in the configuration file.

[0110] If the value of standard attribute No. 30 matches configuration policy 1, then according to configuration policy 1, the firewall obtains the second standard attribute, for example, standard attribute No. 31, from the billing request message. The firewall uses the value of standard attribute No. 31, for example, 8615612345678, as the user name. The firewall continues to obtain the third standard attribute from the billing request message. Obtain the user IP address from the third standard attribute, for example, 1.1.1.1. After obtaining the user name, the firewall assigns a user ID to the user indicated by the user name based on the user name, for example, the user ID is 123. From the registration module, the firewall obtains the user group information corresponding to the user name, for example, the user belongs to the development department.

[0111] If the value of standard attribute No. 30 matches configuration policy 2, then according to configuration policy 2, the firewall obtains the first private attribute from the billing request message, for example, private attribute No. 26. The firewall uses the value carried by private attribute No. 26, for example, IMSI, 460012020000738, as the user name. The firewall continues to obtain the third standard attribute from the billing request message. It obtains the user IP address from the third standard attribute, for example, 2.2.2.2. After obtaining the user name, the firewall assigns a user ID to the user indicated by the user name based on the user name, for example, the user ID is xyz. The firewall obtains the user group information corresponding to the user name from the local computer, for example, the user belongs to the testing department.

[0112] It is understandable that after obtaining the accounting status, identifier, and check code from the accounting request message, the firewall can generate an accounting response message and send it to the NAS.

[0113] Step 1004: The firewall generates an online user entry.

[0114] Specifically, the firewall generates an online user entry 1, which includes the user ID (123), user name (8615612345678), user IP address (1.1.1.1), user group information (development department), and online user aging time (1440 minutes). The online user aging time is obtained from the configuration file.

[0115] The firewall generates online user entry 2, which includes the user ID (xyz), user name (460012020000738), user IP address (2.2.2.2), user group information (testing department), and online user aging time (720 minutes). The online user aging time is obtained from the configuration file.

[0116] Step 1005: The firewall receives the service message 1 sent by the user equipment.

[0117] Step 1006: The firewall allows service packet 1 to pass.

[0118] Specifically, any user device sends service packet 1 to the firewall, from which the firewall obtains source IP address 1. Based on source IP address 1, the firewall locally searches for an online user table entry corresponding to source IP address 1, for example, online user table 1.

[0119] The firewall obtains the user name or user ID from online user table 1 and confirms that the user is registered on the firewall. It then passes service packet 1 based on user policy 1 corresponding to the user name or user ID.

[0120] Step 1007: The NAS interacts with the RADIUS server and the firewall for accounting update.

[0121] Step 1008: The firewall refreshes the aging time of the online user entry.

[0122] Specifically, the online user entry also records the update time of the online user aging time. For example, after the online user entry is generated, the update time is the creation time. In another example, the firewall periodically updates the update time, or updates the update time based on other received RADIUS protocol messages, and identifies whether the online user entry's aging time has expired (the current time minus the refresh time gives the online user entry's existing time).

[0123] Step 1009: The NAS performs accounting stop interaction with the RADIUS server and the firewall respectively.

[0124] Step 1010: The firewall deletes the online user entry.

[0125] Specifically, the firewall identifies whether the aging time of the online user entry has arrived. If so, the firewall deletes the online user entry.

[0126] Step 1011: The firewall receives the service message 2 sent by the user equipment.

[0127] Step 1012: The firewall discards service message 2.

[0128] Specifically, any user device sends service packet 2 to the firewall, from which the firewall obtains source IP address 2. Based on source IP address 2, the firewall does not find an online user entry corresponding to source IP address 2 in its local table. The firewall discards service packet 2.

[0129] Based on the same inventive concept, the present application also provides a communication device corresponding to the communication method. Figure 11 , Figure 11 A communication device provided in an embodiment of the present application is applied to a firewall, and includes:

[0130] The receiving unit 1110 is configured to receive a service message, wherein the service message includes a source IP address;

[0131] A search unit 1120 is configured to search locally for an online user entry matching the source IP address based on the source IP address;

[0132] a processing unit 1130 configured to process the service message according to the user policy corresponding to the online user entry, if the service message exists;

[0133] The discarding unit 1140 is configured to discard the service message if the service message does not exist.

[0134] Optionally, the receiving unit is further configured to receive a charging request message sent by the NAS, wherein the charging request message includes a destination IP address and a check code;

[0135] The apparatus further includes: an acquisition unit (not shown in the figure), configured to acquire a user name and a user IP address from the accounting request message if the destination IP address is the IP address of the firewall and the verification code passes verification;

[0136] A generating unit (not shown in the figure) is used to generate the online user entry according to the user name and the user IP address.

[0137] Optionally, the receiving unit 1110 is further configured to receive at least one configuration file input by a user, each configuration file including at least one configuration policy, and each configuration policy being configured to instruct to obtain the user name from different attributes included in the billing request message.

[0138] Optionally, the charging request message includes an attribute field, and the attribute field includes a first standard attribute and a second standard attribute;

[0139] The acquiring unit (not shown in the figure) is specifically configured to, if the value of the first standard attribute matches a first configuration policy of the at least one configuration policy, use the value of the second standard attribute as the user name according to the first configuration policy.

[0140] Optionally, the charging request message includes an attribute field, and the attribute field includes a first standard attribute and a first private attribute;

[0141] The acquiring unit (not shown in the figure) is specifically configured to, if the value of the first standard attribute matches a second configuration policy among the at least one configuration policy, use the value of the first private attribute as the user name according to the second configuration policy.

[0142] Optionally, the charging request message includes an attribute field, and the attribute field includes a third standard attribute;

[0143] The acquiring unit (not shown in the figure) is specifically configured to acquire the user IP address from the third standard attribute.

[0144] Optionally, the configuration file further includes an online user aging time, and the online user aging time corresponds to each configuration file;

[0145] The generating unit (not shown in the figure) is specifically configured to assign a user ID to the user indicated by the user name according to the user name;

[0146] Obtaining user group information corresponding to the user name;

[0147] Generate the online user entry, where the online user entry includes the user ID, the user name, the user IP address, the group information to which the user belongs, and the online user aging time.

[0148] Optionally, the billing request message further includes a billing status;

[0149] The apparatus further includes: a sending unit (not shown in the figure), configured to send a charging response message to the NAS according to the charging status.

[0150] Optionally, the configuration file further includes a shared key, and the shared key corresponds to each acquisition strategy;

[0151] The accounting response message includes a type code, an identifier, a length, and a check code, and the check code is obtained by performing MD5 calculation on the type code, the identifier, the length, and the check code included in the accounting request message using the shared key.

[0152] Therefore, by applying the communication device provided by the present application, the firewall receives a service message, which includes a source IP address; based on the source IP address, the firewall locally searches whether there is an online user table entry that matches the source IP address; if so, the firewall processes the service message through the user policy corresponding to the online user table entry; if not, the firewall discards the service message.

[0153] This allows firewalls configured with RADIUS single sign-on to process user service packets in scenarios with multiple user types and multiple RADIUS management domains. The firewall can share authenticated user data with the RADIUS server and generate online user entries using the various attributes included in RADIUS protocol packets. This eliminates the need for reconfiguration of extensive user authentication information and secondary authentication on the firewall, simplifying the configuration and authentication process.

[0154] Based on the same inventive concept, the embodiment of the present application further provides a network device, such as Figure 12 As shown, it includes a processor 1210, a transceiver 1220 and a machine-readable storage medium 1230, the machine-readable storage medium 1230 stores machine-executable instructions that can be executed by the processor 1210, and the processor 1210 is prompted by the machine-executable instructions to execute the communication method provided in the embodiment of the present application. Figure 11 The communication device shown can be used as Figure 12 The network device hardware structure shown is implemented.

[0155] The computer-readable storage medium 1230 may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage device. Alternatively, the computer-readable storage medium 1230 may be at least one storage device located remotely from the processor 1210.

[0156] The processor 1210 may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.

[0157] In the embodiment of the present application, the processor 1210 reads the machine-executable instructions stored in the machine-readable storage medium 1230, and the machine-executable instructions enable the processor 1210 itself and call the transceiver 1220 to execute the communication method described in the aforementioned embodiment of the present application.

[0158] In addition, an embodiment of the present application provides a machine-readable storage medium 1230, which stores machine-executable instructions. When called and executed by the processor 1210, the machine-executable instructions prompt the processor 1210 itself and the calling transceiver 1220 to execute the communication method described in the aforementioned embodiment of the present application.

[0159] The implementation process of the functions and effects of each unit in the above-mentioned device is specifically described in the implementation process of the corresponding steps in the above-mentioned method, and will not be repeated here.

[0160] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to the partial description of the method embodiments. The device embodiments described above are merely schematic, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the present application scheme. A person of ordinary skill in the art can understand and implement it without paying any creative work.

[0161] As for the embodiments of the communication device and the machine-readable storage medium, since the method contents involved are basically similar to those of the aforementioned method embodiments, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiments.

[0162] The above description is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application shall be included in the scope of protection of the present application.

Claims

1. A communication method, characterized in that: The method is applied to a firewall, and includes: receiving a service message including a source IP address; According to the source IP address, searching locally to see if there is an online user entry matching the source IP address; If so, the service message is processed according to the user policy corresponding to the online user entry; If not, discard the service message; Before receiving the service message, the method further includes: Receive a billing request message sent by the NAS, wherein the billing request message includes a destination IP address and a check code; If the destination IP address is the IP address of the firewall and the verification code passes the verification, obtaining the user name and user IP address from the accounting request message; Generate the online user entry according to the user name and the user IP address; wherein, before receiving the service message, the method further includes: receiving at least one configuration file input by a user, each configuration file including at least one configuration policy, each configuration policy being used to instruct to obtain the user name from different attributes included in the accounting request message; The charging request message includes an attribute field, and the attribute field includes a first standard attribute and a second standard attribute; The acquiring the user name from the accounting request message specifically includes: If the value of the first standard attribute matches a first configuration policy of the at least one configuration policy, the value of the second standard attribute is used as the user name according to the first configuration policy.

2. The method according to claim 1, characterized in that The charging request message includes an attribute field, and the attribute field includes a first standard attribute and a first private attribute; The acquiring the user name from the accounting request message specifically includes: If the value of the first standard attribute matches a second configuration policy among the at least one configuration policy, the value of the first private attribute is used as the user name according to the second configuration policy.

3. The method according to claim 1, characterized in that The charging request message includes an attribute field, and the attribute field includes a third standard attribute; The obtaining of the user IP address from the accounting request message specifically includes: The user IP address is obtained from the third standard attribute.

4. The method according to claim 1, wherein The configuration file further includes an online user aging time, and the online user aging time corresponds to each configuration file; Generating the online user entry according to the user name and the user IP address specifically includes: According to the user name, assigning a user ID to the user indicated by the user name; Obtaining user group information corresponding to the user name; Generate the online user entry, where the online user entry includes the user ID, the user name, the user IP address, the group information to which the user belongs, and the online user aging time.

5. The method according to claim 1, wherein The billing request message also includes a billing status; The method further comprises: Send a billing response message to the NAS according to the billing status.

6. The method according to claim 5, characterized in that The configuration file further includes a shared key, wherein the shared key corresponds to each acquisition strategy; The accounting response message includes a type code, an identifier, a length, and a check code, and the check code is obtained by performing MD5 calculation on the type code, the identifier, the length, and the check code included in the accounting request message using the shared key.

7. A communication device, characterized in that: The device is applied to a firewall, and includes: A receiving unit, configured to receive a service message, wherein the service message includes a source IP address; A search unit, configured to search locally for an online user entry matching the source IP address based on the source IP address; a processing unit, configured to process the service message according to a user policy corresponding to the online user entry, if the service message exists; a discarding unit, configured to discard the service message if the service message does not exist; The receiving unit is further configured to receive a billing request message sent by the NAS, wherein the billing request message includes a destination IP address and a check code; The apparatus further includes: an acquiring unit, configured to acquire a user name and a user IP address from the accounting request message if the destination IP address is the IP address of the firewall and the verification code passes verification; A generating unit, configured to generate the online user entry according to the user name and the user IP address; The receiving unit is further configured to receive at least one configuration file input by a user, each configuration file including at least one configuration policy, each configuration policy being configured to instruct to obtain the user name from different attributes included in the billing request message; The charging request message includes an attribute field, and the attribute field includes a first standard attribute and a second standard attribute; The acquiring unit is specifically configured to, if the value of the first standard attribute matches a first configuration policy among the at least one configuration policy, use the value of the second standard attribute as the user name according to the first configuration policy.

Citation Information

Patent Citations

  • A method and device for secure access control based on user

    CN101087187A

  • Service session management method and device and electronic equipment

    CN110166570A