Network access method, device, electronic device and storage medium

By implementing restricted processing functions and MAC address authentication on network devices, combined with verification of network access authentication information, the problem of preventing untrusted terminals from accessing the network in the home LAN is solved, and an effective anti-scratch network effect is achieved.

CN119561792BActive Publication Date: 2025-05-09XINHUASAN INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510115820.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-24
Publication Date
2025-05-09
Estimated Expiration
2045-01-24

AI Technical Summary

Technical Problem

In home LAN scenarios such as fiber-to-room (FTTR) networking or access controller (AC) and access point (AP) networking, how to effectively prevent untrusted terminals from accessing the network and achieve the need to prevent scratch networks.

Method used

After the monitoring terminal is connected to the network device, the terminal's traffic restriction processing function is enabled and data packets are refused to pass through the network. Based on the MAC address of the terminal, determine whether it is a trusted terminal. If so, the restriction function can be turned off and new network access authentication information can be generated. If not, the terminal is requested to provide network access authentication information and determine its trustworthiness through verification.

Benefits of technology

It realizes that only trusted terminals can access the network, significantly improving the effect of anti-scratch network, and solving the problem of unsatisfactory anti-scratch network effect when MAC address changes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119561792B_ABST
    Figure CN119561792B_ABST
Patent Text Reader

Abstract

The embodiments of the present application provide a network access method, device, electronic device and storage medium. In the present application, when a terminal is detected to access a network device, the restriction processing function corresponding to the terminal is enabled to deny data packets from the terminal from passing through the network. First, the terminal is determined to be a trusted terminal that is allowed to access the network based on the MAC address of the terminal. If it is determined that the terminal is not a trusted terminal, the network access authentication information replied by the terminal is further used to determine whether the terminal is a trusted terminal. Only when it is determined that the terminal is a trusted terminal, the restriction processing function corresponding to the terminal is turned off. In this way, only trusted terminals can access the network, that is, anti-freeloading is achieved, and the problem of unsatisfactory anti-freeloading effect when the MAC address changes is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a network access method, device, electronic device and storage medium. Background Art

[0002] In home LAN scenarios such as Fiber To The Room (FTTR) networking, or access controller (AC) and access point (AP) networking, only trusted terminals are expected to access the network. Therefore, there is a need to prevent untrusted terminals from accessing the network (that is, there is a need to prevent freeloading).

[0003] Therefore, how to prevent freeloading is a technical problem that needs to be solved urgently. Summary of the invention

[0004] In view of this, the embodiments of the present application provide a network access method, device, electronic device, and storage medium to achieve the purpose of preventing untrusted terminals from accessing the network.

[0005] The present invention provides a network access method, which is applied to a network device. The method includes:

[0006] When it is detected that a terminal is connected to a network device, the restriction processing function corresponding to the terminal is enabled to refuse data packets from the terminal to pass through the network;

[0007] Determine whether the terminal is a trusted terminal that is allowed to access the network based on the terminal's media access control MAC address;

[0008] If yes, then turn off the restriction processing function corresponding to the terminal to allow the data message from the terminal to pass through the network, generate new network access authentication information corresponding to the MAC address and send it to the terminal for storage;

[0009] If not, a request is made to the terminal to obtain network access authentication information. If the network access authentication information replied by the terminal is received, and based on the network access authentication information replied by the terminal, it is determined that the terminal is a trusted terminal allowed to access the network, then the restriction processing function corresponding to the terminal is closed to allow data packets from the terminal to pass through the network, and new network access authentication information is generated and sent to the terminal for storage.

[0010] The embodiment of the present application also provides a network access device, which is applied to a network device, and includes:

[0011] The restriction module is used to enable the restriction processing function corresponding to the terminal when it detects that the terminal is connected to the network device, so as to refuse the data message from the terminal to pass through the network;

[0012] An authentication module, used to determine whether the terminal is a trusted terminal allowed to access the network based on the media access control MAC address of the terminal;

[0013] If yes, then turn off the restriction processing function corresponding to the terminal to allow the data message from the terminal to pass through the network, generate new network access authentication information corresponding to the MAC address and send it to the terminal for storage;

[0014] If not, a request is made to the terminal to obtain network access authentication information. If the network access authentication information replied by the terminal is received, and based on the network access authentication information replied by the terminal, it is determined that the terminal is a trusted terminal allowed to access the network, then the restriction processing function corresponding to the terminal is closed to allow data packets from the terminal to pass through the network, and new network access authentication information is generated and sent to the terminal for storage.

[0015] An embodiment of the present application also provides an electronic device, comprising: a processor and a computer-readable storage medium for storing computer program instructions, wherein the computer program instructions, when executed by the computer-readable storage medium, enable the processor to execute the steps of the above method.

[0016] An embodiment of the present application also provides a machine-readable storage medium, which stores computer program instructions. When the computer program instructions are executed, the steps of the above method can be implemented.

[0017] It can be seen from the above technical scheme that in this embodiment, when it is monitored that the terminal is accessing the network device, the restriction processing function corresponding to the terminal is enabled to refuse the data message from the terminal to pass through the network. First, it is determined based on the MAC address of the terminal whether the terminal is a trusted terminal allowed to access the network. When it is determined based on the MAC address of the terminal that the terminal is not a trusted terminal allowed to access the network, network access authentication information is requested from the terminal. By determining whether the network access authentication information replied by the terminal is received, and when the network access authentication information replied by the terminal is received, whether the terminal is a trusted terminal is further determined by the network access authentication information replied by the terminal. Only when it is determined that the terminal is a trusted terminal allowed to access the network, the restriction processing function corresponding to the terminal is turned off. This ensures that only trusted terminals can access the network, that is, anti-freeloading is achieved.

[0018] Furthermore, when it is determined based on the terminal's MAC address that the terminal is not a trusted terminal allowed to access the network, whether the terminal is a trusted terminal is further determined based on the network access authentication information replied by the terminal. This makes it possible to further determine whether the terminal is a trusted terminal even if the verification result based on the terminal MAC address is inaccurate (for example, the MAC address of the trusted terminal has changed, causing it to be determined as an untrusted terminal), through the network access authentication information of the terminal. This solves the problem of unsatisfactory anti-freeloading effect when the MAC address changes, that is, it significantly improves the anti-freeloading effect. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] Figure 1 A network architecture diagram of the FTTR network provided in the embodiment of the present application;

[0020] Figure 2 A flowchart of a network access method provided in an embodiment of the present application;

[0021] Figure 3 Another schematic diagram of a flow chart of a network access method provided in an embodiment of the present application;

[0022] Figure 4 An interactive flow chart of the initialization phase provided by an embodiment of the present application;

[0023] Figure 5A and 5B An interactive flow chart of the whitelist authentication phase provided in an embodiment of the present application;

[0024] Figure 6 A schematic diagram of the structure of the device provided in the embodiment of the present application;

[0025] Figure 7 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0026] In order to enable those skilled in the art to better understand the technical solutions provided by the embodiments of the present application and to make the above-mentioned purposes, features and advantages of the embodiments of the present application more obvious and understandable, the technical solutions in the embodiments of the present application are further described in detail below in conjunction with the accompanying drawings.

[0027] Before introducing the method provided in the embodiment of the present application, the FTTR networking provided in the embodiment of the present application is described first:

[0028] See also Figure 1 , Figure 1 This is a network architecture diagram of the FTTR network provided in the embodiment of the present application.

[0029] like Figure 1As shown, the FTTR network includes a master device and multiple slave devices. One optical port of the master device is connected to the central office OLT device, and the other optical port is connected to multiple slave devices through an optical splitter.

[0030] Among them, the slave device has radio frequency capability and can provide Wi-Fi services for terminals such as mobile phones and laptops; the master device can optionally have radio frequency capability to provide Wi-Fi services.

[0031] It should be noted that the solution provided in the embodiment of the present application is not only applicable to the above-mentioned FTTR networking, but also to local area network networking such as AC+AP networking, passive optical network (Passive Optical Network, PON) gateway (commonly known as optical modem) networking, wireless router networking, etc. For the sake of convenience of explanation, the FTTR network will be used as an example for explanation.

[0032] The method provided in the application example is described in detail below:

[0033] See also Figure 2 , Figure 2 A flowchart of a method provided by an embodiment of the present application. As an embodiment, the method is applied to a network device, such as a master device in an FTTR network or a slave device with a WI-FI function in an FTTR network.

[0034] like Figure 2 As shown, the process may include the following steps:

[0035] S201, when it is detected that a terminal is connected to a network device, a restriction processing function corresponding to the terminal is enabled to deny data packets from the terminal from passing through the network.

[0036] In this embodiment, this device does not perform MAC address verification during the process of the terminal accessing the network device (that is, during the process of the terminal going online), but first completes the access (that is, completes the online and key negotiation processes first) and then performs MAC address verification, that is, executes the following steps S202 to S204 in this embodiment.

[0037] In this embodiment, the restriction processing function corresponding to the terminal is enabled. There are many specific implementation methods. For example, as an embodiment, iptables, ebtables, acl and other methods are used to restrict the data packets of the terminal so that the data packets are not forwarded to the network server or other network devices in the network.

[0038] S202: Determine whether the terminal is a trusted terminal that is allowed to access the network based on the media access control MAC address of the terminal.

[0039] In this embodiment, the MAC address of the terminal can be obtained from an association request message when the terminal accesses the network device.

[0040] If the judgment result of step S202 is yes, then execute the following step S203 ; if the judgment result of step S202 is no, then execute the following step S204 .

[0041] In this embodiment, there are many specific implementation methods for the above step 202. For example, as an embodiment, it is determined whether there is a whitelist entry matching the MAC address in the locally stored whitelist, and then the terminal is determined to be a trusted terminal. If not, then the terminal is determined to be not a trusted terminal. Here, the whitelist entry matching the MAC address refers to the whitelist entry containing the MAC address.

[0042] S203, turning off the restriction processing function corresponding to the terminal to allow data packets from the terminal to pass through the network, generating new network access authentication information corresponding to the MAC address and sending it to the terminal for storage.

[0043] In this embodiment, the network access authentication information corresponding to the MAC address includes: a token corresponding to the MAC address, and a current timestamp for generating the network access authentication information. The specific implementation method of generating the network access authentication information corresponding to the MAC address in step S203 may be: generating a token and generating a current timestamp. In this embodiment, after generating the token and the generated current timestamp, the method further includes: replacing the token and timestamp corresponding to the MAC address stored in the whitelist entry with the generated token and current timestamp, so as to update the whitelist entry matching the MAC address in the whitelist.

[0044] In this embodiment, there are many ways to generate the token in specific implementations. For example, a string of characters can be randomly selected from a character set, and the string generated each time is different. It must also be a hash operation to obtain a value. Of course, other ways to generate tokens are also possible, as long as the tokens are different each time, and this application does not specifically limit it.

[0045] S204, request the terminal to obtain network access authentication information. If the network access authentication information replied by the terminal is received, and based on the network access authentication information replied by the terminal, it is determined that the terminal is a trusted terminal allowed to access the network, then the restriction processing function corresponding to the terminal is closed to allow data packets from the terminal to pass through the network, and new network access authentication information is generated and sent to the terminal for storage.

[0046] In this embodiment, if the network access authentication information replied by the terminal is not received within the set time, or if the information replied by the terminal indicates that the network access authentication information does not exist, the terminal is controlled to go offline. If it is determined based on the network access authentication information replied by the terminal that the terminal is not a trusted terminal allowed to access the network, the terminal is controlled to go offline.

[0047] In this embodiment, based on the network access authentication information replied by the terminal, there are many specific implementation methods for determining whether the terminal is a trusted terminal that is allowed to access the network. For example, as an embodiment, it is determined whether there is a whitelist entry in the locally stored whitelist that matches the token and timestamp replied by the terminal. If so, it is determined that the terminal is a trusted terminal. If not, it is determined that the terminal is not a trusted terminal. Here, the whitelist entry that matches the token and timestamp replied by the terminal refers to the whitelist entry of the token and timestamp sent by the packet terminal.

[0048] Specifically, the specific implementation method of requesting network access authentication information from the terminal can be: sending a White list check request to the terminal, the White list check request is used to request network access authentication information, if a White list check response is received from the terminal in response to the White list check request, the White list check response carries the above-generated token and timestamp. Then, based on the carried token and timestamp, it is determined whether the terminal is a trusted terminal.

[0049] After the above-mentioned White list check request is sent, if the White list check response from the terminal is not received after T1 time (for example, 1 second), the request is retransmitted twice at a time interval of T1. If the White list check response from the terminal is still not received, or if the terminal reply information is received, and the information indicates that there is no network access authentication information, the first terminal is controlled to go offline.

[0050] The specific implementation method of generating the network access authentication information corresponding to the MAC address in this step S203 can be: generating a token and generating a current timestamp. In this embodiment, after generating the token and the generated current timestamp, the method also includes: replacing the MAC address, token and timestamp stored in the whitelist item with the obtained MAC address of the terminal, the generated new token and the new timestamp, so as to update the whitelist item in the whitelist that matches the token and timestamp replied by the terminal. That is, the existing whitelist item in the whitelist that matches the token and timestamp replied by the terminal is deleted, and the current MAC address of the terminal, the currently generated token and the generated current timestamp are added to the whitelist.

[0051] In this embodiment, the specific implementation method of sending the network access authentication information to the terminal in the above steps S203 and S204 can be: sending a white list check pass instruction White list check ok to the terminal, and White list check ok carries the above generated token and timestamp. The terminal receives White list check ok, obtains the token and timestamp from White list check ok, deletes the local token and local timestamp previously saved locally, and saves the newly obtained token and timestamp (that is, uses the obtained token and timestamp to update the local token and local timestamp saved locally), so that when receiving the White list check request later, the updated local token and local timestamp are carried in the White list check response (that is, to determine whether the terminal is a trusted terminal based on the updated local token and local timestamp).

[0052] It should be noted that any whitelist entry in the whitelist includes at least a MAC address, a token corresponding to the MAC address, and a timestamp. The initial whitelist entry is created during the initialization process, and the specific initialization process will be described later, so it will not be repeated here.

[0053] It should also be noted that the above steps S202, S203 and S204 are not limited to the whitelist in their specific implementation, but can also implement MAC address verification and network access authentication information verification through a blacklist. The implementation logic is opposite to that of the above specific implementation methods, which will not be elaborated here.

[0054] So far, completed Figure 2 The process shown.

[0055] pass Figure 2It can be seen from the shown process and the above technical scheme that in this embodiment, when it is monitored that the terminal is accessing the network device, the restriction processing function corresponding to the terminal is enabled to deny data packets from the terminal from passing through the network. First, it is determined based on the MAC address of the terminal whether the terminal is a trusted terminal allowed to access the network. When it is determined based on the MAC address of the terminal that the terminal is not a trusted terminal allowed to access the network, network access authentication information is requested from the terminal. By determining whether the network access authentication information replied by the terminal is received, and when the network access authentication information replied by the terminal is received, it is further determined whether the terminal is a trusted terminal through the network access authentication information replied by the terminal. Only when it is determined that the terminal is a trusted terminal allowed to access the network, the restriction processing function corresponding to the terminal is turned off. This ensures that only trusted terminals can access the network, that is, anti-freeloading is achieved.

[0056] Furthermore, when it is determined based on the terminal's MAC address that the terminal is not a trusted terminal allowed to access the network, whether the terminal is a trusted terminal is further determined based on the network access authentication information replied by the terminal. This makes it possible to further determine whether the terminal is a trusted terminal even if the verification result based on the terminal MAC address is inaccurate (for example, the MAC address of the trusted terminal has changed, causing it to be determined as an untrusted terminal), through the network access authentication information of the terminal. This solves the problem of unsatisfactory anti-freeloading effect when the MAC address changes, that is, it significantly improves the anti-freeloading effect.

[0057] Combine the following Figure 3 , the network access method provided by this application is described with each whitelist entry in the whitelist as a MAC address, a token and a timestamp corresponding to the MAC address, and network access authentication information as a token and a timestamp:

[0058] like Figure 3 As shown, the process may include the following steps:

[0059] S301, when it is detected that a first terminal is connected to the network device, a restriction processing function corresponding to the first terminal is enabled to deny data packets from the first terminal from passing through the network.

[0060] In this embodiment, the first terminal is any terminal that needs to access the network.

[0061] In this embodiment, enabling the traffic restriction processing function corresponding to the first terminal means prohibiting the data message of the first terminal from being sent to the network.

[0062] S302: Determine whether there is a whitelist entry matching the MAC address in the currently stored whitelist.

[0063] In this embodiment, each whitelist entry includes a MAC address, a token corresponding to the address, and a timestamp. It should be noted that each initial whitelist entry in the whitelist is obtained during the initialization process, and the whitelist entries in the subsequent whitelists will be updated with the terminal authentication and scheduled update process.

[0064] If the judgment result of step S302 is yes, then the following step S303 is executed; if the judgment result of step S302 is no, then the following step S304 is executed.

[0065] S303, determine that the first terminal passes the authentication, turn off the restriction processing function corresponding to the first terminal to allow data packets from the first terminal to pass through the network, and create a new token for the MAC address, update the whitelist entry based on the new token and the current timestamp, and perform subsequent authentication of the first terminal based on the updated whitelist entry.

[0066] S304, requesting the first terminal for the local token and local timestamp corresponding to the network device identifier SSID stored in the first terminal, and if receiving the local token and local timestamp replied by the terminal, determining whether there is a whitelist entry matching the local token and local timestamp in the currently stored whitelist.

[0067] If the judgment result of step S304 is yes, the following step S305 is executed; if the judgment result of step S304 is no, the first terminal fails the authentication, and the first terminal is controlled to go offline.

[0068] In this embodiment, the whitelist entry that matches the local token and the local timestamp refers to a whitelist entry that has the local token and the local timestamp sent by the first terminal.

[0069] S305, turn off the restriction processing function corresponding to the first terminal to allow data packets from the first terminal to pass through the network, and assign a token to the MAC address, update the whitelist entry based on the MAC address, token and current timestamp, and perform subsequent authentication of the first terminal based on the updated whitelist entry.

[0070] After executing the above steps S303 and S305, execute step S306.

[0071] S306, after updating the whitelist entry, the allocated token and current timestamp are sent to the first terminal, so that the first terminal updates the locally stored local token and local timestamp based on the token and the current timestamp, and performs subsequent authentication of the first terminal based on the updated local token and local timestamp.

[0072] In this embodiment, the specific implementation method of sending the allocated token and current timestamp to the first terminal may be: sending a white list check pass instruction White list check ok to the terminal, so that the first terminal obtains the allocated token and current timestamp carried in White list check ok.

[0073] From the above description, it can be seen that in this embodiment, after accessing this network device, the data message of the first terminal is prohibited from being sent to the network. Only after the first terminal passes the authentication, the prohibition is lifted to allow the first terminal to access the network. This provides a solid foundation for only terminals allowed in the whitelist to access the network.

[0074] Furthermore, firstly, by determining whether there is a list entry matching the MAC address in the currently stored whitelist, whether the first terminal can access the network service is authenticated. When there is no list entry matching the MAC address of the first terminal in the currently stored whitelist, the first terminal is triggered to send the locally stored local token and local timestamp corresponding to the network to which the device is connected. By determining whether there is a list entry matching the local token and local timestamp in the currently stored whitelist, whether the first terminal can access the network is authenticated. Then, the token and timestamp in the whitelist are always consistent with the token and timestamp stored by the terminal. This ensures that even if the MAC address of the first terminal changes, causing the current MAC address to not match the record in the list entry, authentication can be performed through the local token and local timestamp of the terminal, which solves the problem of whitelist invalidation under the changed MAC address.

[0075] The above describes in detail the network access method provided by this application using token and timestamp as network access authentication information.

[0076] The above initialization process is described in detail below:

[0077] As an embodiment, before the above step S201, when it is detected that the terminal is connected to the network device, it is determined whether to add the online terminal to the whitelist based on the network demand. If yes, a whitelist item matching the MAC address of the terminal is added to the whitelist; the whitelist item includes the MAC address of the terminal and the network authentication information corresponding to the MAC address of the terminal; and the corresponding restriction processing function of the enabled terminal is continued to be executed to refuse the data message from the terminal to pass through the network. If not, the corresponding restriction processing function of the enabled terminal is continued to be executed to refuse the data message from the terminal to pass through the network.

[0078] In the specific implementation, one implementation method is implemented through the following steps:

[0079] When the whitelist function is turned off on this device, each terminal is allowed to go online first, and then based on network requirements, the MAC of the terminal allowed to access the network is added to the whitelist through the online terminal list or manual input. After that, when it is determined to initialize (that is, when the whitelist function is turned on), each online terminal currently connected to this device is traversed. If the MAC address of the terminal exists in the whitelist, a token is assigned to the MAC address, and the token and the current timestamp are added to the whitelist to form an initial whitelist entry with the existing MAC address. The token and timestamp are sent to the terminal through the whitelist token update message, so that the terminal saves the token and timestamp as a local token and local timestamp. If the MAC address of the terminal does not exist in the MAC address list configured in the whitelist, the terminal is controlled to go offline. After all online terminals connected to this device are traversed, the initialization of this device is completed. Among them, after the initialization of this device is completed, each terminal that has not been offline also completes the initialization of the terminal synchronously.

[0080] It should be noted that if the terminal subsequently connected to the network is a terminal whose MAC will be changed every time it is associated, it is required that all the terminals subsequently connected to the network need to go online first.

[0081] Of course, for terminals that do not change their MAC addresses every time they go online, such as private MAC addresses, that is, they change every T2 time, the above method can also be used to initialize the device and the terminal. It should be noted that the terminal with a private MAC address needs to be online when initializing.

[0082] During the operation of the device, it may be necessary to add a terminal (explained as the second terminal) to the whitelist, and the terminal also needs to be initialized. That is, if all online terminals currently connected to the device do not include the second terminal, the terminal initialization of the second terminal is achieved through the following steps:

[0083] When the whitelist function of this device is turned off, let the second terminal go online and add the MAC address of the second terminal to the whitelist. Then, after turning on the whitelist function, assign a token to the MAC address, add the token and the current timestamp to the whitelist and form an initial whitelist entry with the existing MAC address. And send the token and timestamp to the second terminal through the whitelist token update message, so that the second terminal saves the token and timestamp as the local token and local timestamp corresponding to the network (the network is represented by the SSID) to which this device is connected, which is stored locally by the second terminal. This completes the terminal initialization of the second terminal.

[0084] In the specific implementation, another implementation method is achieved through the following steps:

[0085] For the third terminal, when the third terminal comes online, if the MAC address of the third terminal exists in the MAC address list configured in the whitelist, but there is no token and timestamp corresponding to the MAC address, a token is assigned to the MAC address, and the token and the current timestamp are added to the whitelist to form an initial whitelist entry with the existing MAC address; and the token and timestamp are sent to the third terminal so that the third terminal saves the token and timestamp as a local token and local timestamp to complete the terminal initialization of the third terminal.

[0086] It should be noted that the third terminal is not a terminal that changes its MAC address every time it goes online, such as a private MAC address, that is, it changes once every T2 time. A terminal that changes its MAC address every time it associates cannot use the second initialization method.

[0087] Of course, if a newly added fourth terminal needs to join the network later, and the fourth terminal uses a private MAC address, the initialization of the fourth terminal also adopts the initialization method of the third terminal.

[0088] From the above description, it can be seen that after the network equipment and terminal complete the initialization, the whitelist is obtained, which provides a solid foundation for subsequent authentication based on the whitelist.

[0089] The above initialization process is described in detail.

[0090] In order to further explain the method provided by the present application, the following is combined with Figure 4 , Figure 5A as well as Figure 5B The solution provided in this application is described in more detail by way of specific embodiments.

[0091] In this embodiment, it is specifically divided into two phases: an initialization phase and a whitelist authentication phase.

[0092] The first stage, the initialization stage, combines Figure 4 As shown, the process includes the following steps:

[0093] 1. For terminals whose MACs change with each association, bring each terminal online with the whitelist function turned off. Then, based on network requirements, add the terminal MAC to the whitelist through the online terminal list or manual input, and turn on the whitelist function when each terminal is online.

[0094] 2. When the whitelist function is turned on, the network device traverses all current online terminals (such as the first terminal). If a MAC address is matched in the whitelist, a token is generated for it, and the timestamp corresponding to the generated token is recorded. Both are stored in the whitelist item corresponding to the MAC, and the terminal is notified through a White list token update message.

[0095] 3. When the MAC of a terminal (such as the second terminal) needs to be added to the whitelist, when the whitelist function is turned off on this device, the second terminal is allowed to go online and the MAC address of the second terminal is added to the whitelist. Then, after the whitelist function is turned on, a token is assigned to the MAC address, and the token and the current timestamp are added to the whitelist to form an initial whitelist entry with the existing MAC address. The token and timestamp are sent to the second terminal through the whitelist token update message, so that the second terminal saves the token and timestamp as the local token and local timestamp corresponding to the SSID stored locally by the second terminal.

[0096] and / or,

[0097] 4. For terminals that do not change their MAC every time they go online, when the whitelist function is not enabled, add the terminal MAC to the whitelist through the online terminal list or manual input. At this time, the whitelist is only configured with the MAC list.

[0098] 5. After the whitelist function is enabled, the whitelist of each terminal that has not been online lacks the token and timestamp information corresponding to the terminal MAC. When the terminal uses the MAC to go online for the first time after the whitelist is enabled, the whitelist matches the MAC, and the token and timestamp corresponding to the MAC address do not exist. The network device generates a token for the MAC and records the timestamp, updates the whitelist, and synchronizes it to the terminal through the White list token update message.

[0099] 6. When the terminal's MAC needs to be added to the whitelist, repeat steps 4 and 5 above.

[0100] The second stage, the whitelist authentication stage, combines Figure 5A and 5B As shown, the process includes the following steps:

[0101] 1. After the terminal completes the online and key negotiation, the terminal is online and the corresponding restriction processing function of the terminal is enabled to refuse the data packets from the terminal to pass through the network. If its MAC address directly hits the MAC address in the whitelist, the terminal is authenticated successfully, and the corresponding restriction processing function of the terminal is turned off to allow the data packets from the terminal to continue to pass through the network. The network device generates a token and records the timestamp, updates the whitelist item in the whitelist corresponding to the MAC, and then synchronizes the token and timestamp to the terminal through Whitelist check ok, and the terminal saves the new token and new timestamp.

[0102] 2. If the terminal MAC address is not in the current whitelist, a White list check request is sent to the terminal with an empty request content.

[0103] 3. After receiving the White list check request sent by the network device, the terminal replies with a White list check response, which must include the token of the network SSID previously saved by the terminal and the corresponding timestamp.

[0104] 4. The network device verifies the token and timestamp sent by the terminal. If a whitelist entry with the token and timestamp is found in the whitelist, the restriction processing function corresponding to the terminal is turned off to allow data packets from the terminal to pass through the network, a new token and a new timestamp are generated, the whitelist entry corresponding to the original token and the original timestamp is deleted, and the current MAC of the terminal, the new token, and the new timestamp are saved as a new whitelist entry.

[0105] 5. The network device replies to the terminal with White list check ok, carrying a new token and a new timestamp.

[0106] 6. After the terminal receives the White list check ok, it overwrites the original token and timestamp corresponding to the SSID with the new token and new timestamp.

[0107] 7. In step 3 above, after the White list check request is sent, if no White list check response is received from the terminal after T1 time, it is retransmitted twice at a time interval of T1. If no response message is received from the terminal, the terminal is controlled to go offline according to authentication failure.

[0108] The method provided in the embodiment of the present application is described above. The device provided in the embodiment of the present application is described below:

[0109] See also Figure 6 , Figure 6 The device structure diagram provided in the embodiment of the present application is as follows. As an example, the device is applied to a network access device, such as Figure 6 As shown, the device 600 includes: a restriction module 601 and an authentication module 602 .

[0110] The restriction module 601 is used to enable the restriction processing function corresponding to the terminal when it is detected that the terminal is connected to the network device, so as to refuse the data message from the terminal to pass through the network;

[0111] An authentication module 602, used to determine whether the terminal is a trusted terminal allowed to access the network based on the media access control MAC address of the terminal;

[0112] If yes, then turn off the restriction processing function corresponding to the terminal to allow the data message from the terminal to pass through the network, generate new network access authentication information corresponding to the MAC address and send it to the terminal for storage;

[0113] If not, a request is made to the terminal to obtain network access authentication information. If the network access authentication information replied by the terminal is received, and based on the network access authentication information replied by the terminal, it is determined that the terminal is a trusted terminal allowed to access the network, then the restriction processing function corresponding to the terminal is closed to allow data packets from the terminal to pass through the network, and new network access authentication information is generated and sent to the terminal for storage.

[0114] As an embodiment, determining whether the terminal is a trusted terminal allowed to access the network based on the media access control MAC address of the terminal includes:

[0115] Determine whether there is a whitelist entry matching the MAC address in the locally stored whitelist; the whitelist entry matching the MAC address contains the MAC address;

[0116] If it exists, the terminal is determined to be a trusted terminal;

[0117] If not present, it is determined that the terminal is not a trusted terminal.

[0118] As an embodiment, the network access authentication information corresponding to the MAC address includes: a token corresponding to the MAC address, and a current timestamp of generating the network access authentication information;

[0119] Wherein, determining whether the terminal is a trusted terminal allowed to access the network based on the network access authentication information replied by the terminal includes:

[0120] Determine whether there is a whitelist entry in the locally stored whitelist that matches the token and timestamp replied by the terminal; the whitelist entry that matches the token and timestamp replied by the terminal includes the token and timestamp;

[0121] If it exists, the terminal is determined to be a trusted terminal;

[0122] If not present, it is determined that the terminal is not a trusted terminal.

[0123] As an embodiment, when there is a whitelist entry matching the MAC address in the locally stored whitelist, after generating new network access authentication information corresponding to the MAC address, the method further includes: replacing the token and timestamp corresponding to the MAC address stored in the whitelist entry with the generated new token and new timestamp to update the whitelist entry matching the MAC address in the whitelist;

[0124] or,

[0125] When there is a whitelist entry in the locally stored whitelist that matches the token and timestamp replied by the terminal, after generating new network access authentication information, the method also includes: replacing the MAC address, token and timestamp stored in the whitelist entry with the MAC address of the terminal, the generated new token and the new timestamp, so as to update the whitelist entry in the whitelist that matches the token and timestamp replied by the terminal.

[0126] As an embodiment, the authentication module is further specifically used for:

[0127] If the network access authentication information replied by the terminal is not received within the set time, or if the information replied by the terminal is received and the information indicates that the network access authentication information does not exist, the terminal is controlled to go offline.

[0128] As an embodiment, the device further includes:

[0129] A whitelist establishment module is used to determine whether to add a terminal to the whitelist based on network requirements after monitoring that the terminal is connected to a network device. If so, a whitelist entry matching the MAC address of the terminal is added to the whitelist; the whitelist entry includes the MAC address of the terminal and the network authentication information corresponding to the MAC address of the terminal; and enables the corresponding restriction processing function of the terminal to refuse data packets from the terminal to pass through the network;

[0130] If not, enable the restriction processing function corresponding to the terminal to deny the data message from the terminal to pass through the network;

[0131] As an embodiment, the authentication module is further configured to:

[0132] After generating new network access authentication information and sending it to the terminal for storage, the method further includes:

[0133] When the terminal accesses the network for a set period of time, the network access authentication information corresponding to the MAC address is updated, and the updated network access authentication information is sent to the terminal to update the network access authentication information stored in the terminal.

[0134] So far, completed Figure 6 Structural description of the device shown.

[0135] See also Figure 7 , Figure 7 This is a structural diagram of an electronic device provided in an embodiment of the present application. Figure 7 As shown, the hardware structure may include: a processor and a machine-readable storage medium, the machine-readable storage medium storing machine-executable instructions that can be executed by the processor; the processor is used to execute the machine-executable instructions to implement the method disclosed in the above example of this application.

[0136] Based on the same application concept as the above method, an embodiment of the present application also provides a machine-readable storage medium, on which a number of computer instructions are stored. When the computer instructions are executed by a processor, the method disclosed in the above example of the present application can be implemented.

[0137] Exemplarily, the above-mentioned machine-readable storage medium can be any electronic, magnetic, optical or other physical storage device, which can contain or store information, such as executable instructions, data, etc. For example, the machine-readable storage medium can be: RAM (Radom Access Memory), volatile memory, non-volatile memory, flash memory, storage drive (such as hard disk drive), solid state drive, any type of storage disk (such as optical disk, DVD, etc.), or similar storage medium, or a combination thereof.

[0138] The above is only an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the scope of the claims of the present application.

Claims

1. A network access method, characterized in that: The method is applied to a network device, and the method comprises: When a terminal is detected to be connected to the network device, a restriction processing function corresponding to the terminal is enabled to deny data packets from the terminal from passing through the network, the terminal and the network device are located in the same local area network, and the MAC address of the terminal in the local area network changes periodically; Determining whether the terminal is a trusted terminal allowed to access the network based on a media access control MAC address of the terminal; If so, the restriction processing function corresponding to the terminal is turned off to allow data packets from the terminal to pass through the network, and new network access authentication information corresponding to the MAC address is generated and sent to the terminal for storage; the network access authentication information includes: a token corresponding to the MAC address of the terminal, and a current timestamp of generating the network access authentication information; If not, then a request is made to the terminal to obtain network access authentication information. If the network access authentication information replied by the terminal is received, then based on the token and timestamp in the network access authentication information replied by the terminal, it is further determined whether the terminal is a trusted terminal. If it is determined that the terminal is a trusted terminal allowed to access the network, then the restriction processing function corresponding to the terminal is closed to allow data packets from the terminal to pass through the network, and new network access authentication information is generated and sent to the terminal for storage.

2. The method according to claim 1, characterized in that The determining, based on the media access control MAC address of the terminal, whether the terminal is a trusted terminal allowed to access the network comprises: Determine whether there is a whitelist entry matching the MAC address in the locally stored whitelist; the whitelist entry matching the MAC address contains the MAC address; If so, determining that the terminal is a trusted terminal; If not, it is determined that the terminal is not a trusted terminal.

3. The method according to claim 1, characterized in that The further determining whether the terminal is a trusted terminal based on the token and timestamp in the network access authentication information replied by the terminal includes: Determine whether there is a whitelist entry in the locally stored whitelist that matches the token and timestamp replied by the terminal; the whitelist entry that matches the token and timestamp replied by the terminal includes the token and the timestamp; If so, determining that the terminal is a trusted terminal; If not, it is determined that the terminal is not a trusted terminal.

4. The method according to claim 3, characterized in that When there is a whitelist entry matching the MAC address in the locally stored whitelist, after generating new network access authentication information corresponding to the MAC address, the method further includes: replacing the token and timestamp corresponding to the MAC address stored in the whitelist entry with the generated new token and new timestamp to update the whitelist entry matching the MAC address in the whitelist.

5. The method according to claim 3, characterized in that: When there is a whitelist entry in the locally stored whitelist that matches the token and timestamp replied by the terminal, after generating new network access authentication information, the method also includes: replacing the MAC address, token and timestamp stored in the whitelist entry with the MAC address of the terminal, the generated new token and the new timestamp, so as to update the whitelist entry in the whitelist that matches the token and timestamp replied by the terminal.

6. The method according to claim 1, characterized in that The method further comprises: If the network access authentication information replied by the terminal is not received within the set time, or if the information replied by the terminal is received and the information indicates that the network access authentication information does not exist, the terminal is controlled to go offline.

7. The method according to claim 2, characterized in that Prior to the method, it further includes: after monitoring that a terminal accesses the network device, determining whether to add the terminal to a whitelist based on network requirements, and if so, adding a whitelist entry matching the MAC address of the terminal to the whitelist; the whitelist entry includes the MAC address of the terminal and network authentication information corresponding to the MAC address of the terminal; and enabling the restriction processing function corresponding to the terminal to deny data packets from the terminal from passing through the network; If not, enable the restriction processing function corresponding to the terminal to deny the data message from the terminal to pass through the network.

8. The method according to claim 1, characterized in that After generating new network access authentication information and sending it to the terminal for storage, the method further includes: When the terminal accesses the network for a set period of time, the network access authentication information corresponding to the MAC address is updated, and the updated network access authentication information is sent to the terminal to update the network access authentication information stored in the terminal.

9. A network access device, characterized in that: The device is applied to a network device, and the device comprises: A restriction module is used to enable a restriction processing function corresponding to the terminal when it is detected that the terminal is connected to the network device, so as to refuse data packets from the terminal to pass through the network, the terminal and the network device are located in the same local area network, and the MAC address of the terminal in the local area network changes regularly; an authentication module, configured to determine whether the terminal is a trusted terminal allowed to access the network based on a media access control MAC address of the terminal; If so, the restriction processing function corresponding to the terminal is turned off to allow data packets from the terminal to pass through the network, and new network access authentication information corresponding to the MAC address is generated and sent to the terminal for storage; the network access authentication information includes: a token corresponding to the MAC address of the terminal, and a current timestamp of generating the network access authentication information; If not, then a request is made to the terminal to obtain network access authentication information. If the network access authentication information replied by the terminal is received, then based on the token and timestamp in the network access authentication information replied by the terminal, it is further determined whether the terminal is a trusted terminal. If it is determined that the terminal is a trusted terminal allowed to access the network, then the restriction processing function corresponding to the terminal is closed to allow data packets from the terminal to pass through the network, and new network access authentication information is generated and sent to the terminal for storage.

10. The device according to claim 9, characterized in that The determining, based on the media access control MAC address of the terminal, whether the terminal is a trusted terminal allowed to access the network comprises: Determine whether there is a whitelist entry matching the MAC address in the locally stored whitelist; the whitelist entry matching the MAC address contains the MAC address; If so, determining that the terminal is a trusted terminal; If not, it is determined that the terminal is not a trusted terminal; and / or, Wherein, further determining whether the terminal is a trusted terminal based on the token and timestamp in the network access authentication information replied by the terminal includes: Determine whether there is a whitelist entry in the locally stored whitelist that matches the token and timestamp replied by the terminal; the whitelist entry that matches the token and timestamp replied by the terminal includes the token and the timestamp; If so, determining that the terminal is a trusted terminal; If not, it is determined that the terminal is not a trusted terminal; and / or, When there is a whitelist entry matching the MAC address in the locally stored whitelist, after generating new network access authentication information corresponding to the MAC address, the authentication module is further specifically used to: replace the token and timestamp corresponding to the MAC address stored in the whitelist entry with the generated new token and new timestamp, so as to update the whitelist entry matching the MAC address in the whitelist; and / or, When there is a whitelist entry in the locally stored whitelist that matches the token and timestamp replied by the terminal, after generating new network access authentication information, the authentication module is further specifically used to: replace the MAC address, token and timestamp stored in the whitelist entry with the MAC address of the terminal, the generated new token and the new timestamp, so as to update the whitelist entry in the whitelist that matches the token and timestamp replied by the terminal; and / or, The authentication module is also specifically used for: If the network access authentication information replied by the terminal is not received within the set time, or if the information replied by the terminal is received and the information indicates that there is no network access authentication information, then control the terminal to go offline; The device also includes: A whitelist establishment module is used to determine whether to add the terminal to the whitelist based on network requirements after monitoring that the terminal has accessed the network device, and if so, to add a whitelist entry matching the MAC address of the terminal to the whitelist; the whitelist entry includes the MAC address of the terminal and the network authentication information corresponding to the MAC address of the terminal; and enables the restriction processing function corresponding to the terminal to deny data packets from the terminal from passing through the network; If not, enabling a restricted traffic processing function corresponding to the terminal to deny data packets from the terminal from passing through the network; and / or, The authentication module is further used to: After generating new network access authentication information and sending it to the terminal for storage, when the terminal accesses the network for a set period of time, the network access authentication information corresponding to the MAC address is updated, and the updated network access authentication information is sent to the terminal to update the network access authentication information stored by the terminal.

11. An electronic device, characterized in that: The electronic device includes: Processor; and A computer-readable storage medium, wherein computer program instructions are stored in the computer-readable storage medium, and when the computer program instructions are executed by the processor, the processor is caused to perform the steps of the method according to any one of claims 1 to 8.

12. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer program instructions, which, when executed by a processor, enable the processor to perform the steps of the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Traffic filtering method and device and storage medium

    CN117081768A

  • Rapid establishment of a connection from multiple address locations

    US9860324B1