A terminal authentication method and apparatus, an access device, and a medium

By sending request messages to multiple authentication servers and receiving the first response message to confirm successful terminal access, the problem of access device authentication failure caused by authentication server failure was resolved, ensuring that the terminal can access the network normally.

CN119605127BActive Publication Date: 2025-11-21NEW H3C TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202380009578.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-29
Publication Date
2025-11-21
Estimated Expiration
2043-06-29

AI Technical Summary

Technical Problem

In the 802.1X protocol, if the authentication server malfunctions, the access device will not be able to receive the authentication success message, resulting in the terminal access authentication failure and inability to access network resources.

Method used

The access device sends authentication request messages to multiple authentication servers respectively. If it receives the first response message from any authentication server, it sends an access authentication success message to the terminal and, if necessary, sends a message including authentication parameters so that the authentication server can verify the user's identity information.

Benefits of technology

Even if some authentication servers fail, the access device can still confirm the successful access of the terminal through the first response message, avoiding terminal online failure and ensuring the continuity of the authentication process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119605127B_ABST
    Figure CN119605127B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a terminal authentication method and device, an access device and a medium, and relate to the technical field of communication. The method is applied to an access device, and includes: sending a first message to each authentication server in a plurality of authentication servers, the first message being used to request the authentication server to perform access authentication on a terminal; if a second message sent by any authentication server is received and the second message is the first second message sent by the plurality of authentication servers after receiving the first message, sending a third message to the terminal, the second message and the third message both being used to indicate that the terminal access authentication is successful. In this way, the problem of terminal online failure caused by server failure can be avoided.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of communication, and in particular to a terminal authentication method and device, an access device and a medium. BACKGROUND

[0002] The 802.1X protocol is a port-based network access control protocol, that is, the terminal is authenticated on the port of the local area network access device, so as to control the access of the terminal to the network resources. In the 802.1X protocol, the Extensible Authentication Protocol (EAP) can be used to realize the interaction of authentication information between the terminal, the access device and the authentication server.

[0003] When the terminal needs to access the network resources, the terminal can send an EAP message to the access device. The access device can encapsulate the user identity information carried in the EAP message in an access authentication message and send the access authentication message to the authentication server. The authentication server can check the user identity information. If the check is passed, the authentication server returns an authentication success message to the access device, and the authentication success message carries the user's permission information. After receiving the authentication success message, the access device grants the user corresponding permissions based on the permission information, so that the terminal can access the network resources.

[0004] However, if the authentication server fails, the access device cannot receive the authentication success message returned by the authentication server, and thus cannot obtain the user's permission information, resulting in that the terminal access authentication fails and the terminal cannot access the network resources. SUMMARY

[0005] Embodiments of the present application provide a terminal authentication method, device, access device and medium, which can avoid the problem of terminal online failure caused by server failure. The specific technical solutions are as follows:

[0006] In a first aspect, the embodiments of the present application provide a terminal authentication method, which is applied to an access device, and the method comprises the following steps:

[0007] sending a first message to each of a plurality of authentication servers, wherein the first message is used to request the authentication server to perform access authentication on the terminal;

[0008] If a second message sent by any one of the authentication servers is received and the second message is the first second message sent by the authentication servers after receiving the first message, a third message is sent to the terminal, wherein the second message and the third message are both used to indicate that the terminal access authentication is successful.

[0009] In a possible implementation, after the first message is sent to the plurality of authentication servers, the method further includes:

[0010] If the fourth message sent by any one of the authentication servers is received and the fourth message is the first fourth message sent by the plurality of authentication servers after the first message is received, a fifth message is sent to the terminal, the fifth message includes authentication parameters, and the authentication parameters are carried in an EAP message included in the fourth message.

[0011] The sixth message sent by the terminal is received, the sixth message includes user identity information, and the user identity information is encrypted by using the authentication parameters.

[0012] The seventh message is sent to each of the authentication servers respectively, the seventh message includes the sixth message and the EAP message, so that the authentication servers verify the user identity information based on the authentication parameters.

[0013] In a possible implementation, after the first message is sent to the plurality of authentication servers, the method further includes:

[0014] If the eighth messages sent by the same number of authentication servers as the plurality of authentication servers are received within a first preset time period, and the authentication results carried in each of the eighth messages indicate that the terminal fails in access authentication, the authentication results of each of the servers on the terminal are recorded as access authentication failure respectively.

[0015] The ninth message is sent to the terminal, and the ninth message is used to indicate that the terminal fails in access authentication.

[0016] In a possible implementation, after the first message is sent to the plurality of authentication servers, the method further includes:

[0017] If no message sent by any one of the authentication servers is received after the first preset time period is reached, the authentication results of each of the servers on the terminal are recorded as authentication server unreachable respectively.

[0018] The ninth message is sent to the terminal, and the ninth message is used to indicate that the terminal fails in access authentication.

[0019] In a possible implementation, after the first message is sent to the plurality of authentication servers, the method further includes:

[0020] If the eighth messages sent by a first number of authentication servers are received within a first preset time period, and the authentication results carried in each of the eighth messages indicate that the terminal fails in access authentication, the authentication results of the first number of authentication servers on the terminal are recorded as access authentication failure respectively.

[0021] if no message sent by a second number of authentication servers in the plurality of authentication servers is received after the first preset time length, record the authentication result of the second number of authentication servers on the terminal as authentication server unreachable respectively;

[0022] send a ninth message or a tenth message to the terminal, the ninth message is used to indicate that the terminal access authentication fails, the tenth message is used to indicate that the terminal access authentication succeeds, and the sum of the first number and the second number is equal to the number of the plurality of authentication servers.

[0023] In a possible implementation, after the first message is sent to the plurality of authentication servers, the method further includes:

[0024] if the same number of eighth messages as the number of the plurality of authentication servers is received within a second preset time length, and the authentication result carried in each eighth message indicates that the terminal access authentication fails, record the authentication result of each server on the terminal as access authentication failure respectively;

[0025] send a ninth message to the terminal, the ninth message is used to indicate that the terminal access authentication fails.

[0026] In a possible implementation, after the first message is sent to the plurality of authentication servers, the method further includes:

[0027] if no message sent by any authentication server is received after the second preset time length, record the authentication result of each server on the terminal as authentication server unreachable respectively;

[0028] send a ninth message to the terminal, the ninth message is used to indicate that the terminal access authentication fails.

[0029] In a possible implementation, after the first message is sent to the plurality of authentication servers, the method further includes:

[0030] if the third number of eighth messages sent by authentication servers is received within a second preset time length, and the authentication result carried in each eighth message indicates that the terminal access authentication fails, record the authentication result of the third number of authentication servers on the terminal as access authentication failure respectively;

[0031] if no message sent by a fourth number of authentication servers in the plurality of authentication servers is received after the second preset time length, record the authentication result of the fourth number of authentication servers on the terminal as authentication server unreachable respectively;

[0032] The terminal is sent a ninth message or a tenth message, the ninth message is used to indicate that the terminal access authentication fails, the tenth message is used to indicate that the terminal access authentication succeeds, and the sum of the third quantity and the fourth quantity is equal to the number of the plurality of authentication servers.

[0033] In a possible implementation, the seventh message includes an EAP message attribute, and the EAP message attribute is used to carry the EAP message.

[0034] In a possible implementation, the EAP message attribute has a preset length.

[0035] If the length of the EAP message is greater than the preset length, the seventh message includes a plurality of EAP message attributes, and the EAP message is carried in the plurality of EAP message attributes in a fragmented form.

[0036] In a possible implementation, the access device is connected with a plurality of groups of authentication servers, and the sending of the first message to the plurality of authentication servers includes:

[0037] selecting a group of authentication servers from the plurality of groups of authentication servers in a load sharing manner, and sending the first message to the selected group of authentication servers; or

[0038] selecting a preset number of authentication servers from each group of authentication servers included in the plurality of groups of authentication servers in a load sharing manner, and sending the first message to the selected authentication servers.

[0039] In a second aspect, an embodiment of the present application provides a terminal authentication device, which is applied to an access device, and includes:

[0040] a sending module, configured to send a first message to each authentication server in a plurality of authentication servers, the first message being used to request the authentication server to perform access authentication on a terminal;

[0041] a receiving module, configured to, if a second message sent by any authentication server is received and the second message is a first second message sent after the plurality of authentication servers receive the first message, trigger the sending module to send a third message to the terminal, the second message and the third message both being used to indicate that the terminal access authentication succeeds.

[0042] In a possible implementation, the receiving module is further configured to trigger the sending module to send a fifth message to the terminal if the fourth message sent by any one of the authentication servers is received and the fourth message is the first fourth message sent by the authentication servers after the first message is received, and the fifth message comprises authentication parameters, and the authentication parameters are carried in an EAP message included in the fourth message.

[0043] The receiving module is further configured to receive a sixth message sent by the terminal, and the sixth message comprises user identity information, and the user identity information is encrypted by using the authentication parameters.

[0044] The sending module is further configured to send a seventh message to each of the authentication servers respectively, and the seventh message comprises the sixth message and the EAP message, so that the authentication servers verify the user identity information based on the authentication parameters.

[0045] In a possible implementation, the apparatus further comprises a recording module.

[0046] The receiving module is further configured to trigger the recording module to record, respectively, authentication results of the terminal by each of the servers as access authentication failure if the same number of eighth messages as the number of the authentication servers are received within a first preset time length, and the authentication results carried in each of the eighth messages indicate that the terminal fails in access authentication.

[0047] The sending module is further configured to send a ninth message to the terminal, and the ninth message is used to indicate that the terminal fails in access authentication.

[0048] In a possible implementation, the recording module is further configured to record, respectively, authentication results of the terminal by each of the servers as authentication server unreachable if no message sent by any one of the authentication servers is received after the first preset time length is reached.

[0049] The sending module is further configured to send a ninth message to the terminal, and the ninth message is used to indicate that the terminal fails in access authentication.

[0050] In a possible implementation, the receiving module is further configured to trigger the recording module to record, respectively, authentication results of the terminal by the first number of authentication servers as access authentication failure if the eighth messages sent by the first number of authentication servers are received within a first preset time length, and the authentication results carried in each of the eighth messages indicate that the terminal fails in access authentication.

[0051] The recording module is further configured to, after the first preset time length is reached, record authentication results of the second number of authentication servers on the terminal as authentication servers being unreachable if no message sent by the second number of authentication servers in the plurality of authentication servers is received.

[0052] The sending module is further configured to send a ninth message or a tenth message to the terminal, the ninth message being used to indicate that the terminal access authentication fails, and the tenth message being used to indicate that the terminal access authentication succeeds, a sum of the first number and the second number being equal to a number of the plurality of authentication servers.

[0053] In a possible implementation, the receiving module is further configured to, if the same number of eighth messages as the number of the plurality of authentication servers is received within a second preset time length, and authentication results carried in each eighth message all indicate that the terminal access authentication fails, trigger the recording module to record authentication results of each server on the terminal as access authentication failing.

[0054] The sending module is further configured to send a ninth message to the terminal, the ninth message being used to indicate that the terminal access authentication fails.

[0055] In a possible implementation, the recording module is further configured to, after the second preset time length is reached, record authentication results of each server on the terminal as authentication servers being unreachable if no message sent by any authentication server is received.

[0056] The sending module is further configured to send a ninth message to the terminal, the ninth message being used to indicate that the terminal access authentication fails.

[0057] In a possible implementation, the receiving module is further configured to, if a third number of authentication servers send eighth messages within the second preset time length, and authentication results carried in each eighth message all indicate that the terminal access authentication fails, trigger the recording module to record authentication results of the third number of authentication servers on the terminal as access authentication failing.

[0058] The recording module is further configured to, after the second preset time length is reached, record authentication results of a fourth number of authentication servers in the plurality of authentication servers on the terminal as authentication servers being unreachable if no message sent by the fourth number of authentication servers is received.

[0059] The sending module is further configured to send a ninth message or a tenth message to the terminal, the ninth message is used to indicate that the terminal access authentication fails, and the tenth message is used to indicate that the terminal access authentication succeeds, and a sum of the third quantity and the fourth quantity is equal to a quantity of the plurality of authentication servers.

[0060] In a possible implementation, the seventh message comprises an EAP message attribute, and the EAP message attribute is used to carry the EAP message.

[0061] In a possible implementation, the EAP message attribute has a preset length.

[0062] If the length of the EAP message is greater than the preset length, the seventh message comprises a plurality of EAP message attributes, and the EAP message is carried in the plurality of EAP message attributes in a fragmented form.

[0063] In a possible implementation, the access device is connected with a plurality of groups of authentication servers; the sending module is further configured to select a group of authentication servers from the plurality of groups of authentication servers in a load sharing manner, and send the first message to the selected group of authentication servers; or,

[0064] The sending module is further configured to select a preset quantity of authentication servers from each group of authentication servers included in the plurality of groups of authentication servers in a load sharing manner, and send the first message to the selected authentication servers.

[0065] In a third aspect, an embodiment of the present application provides an access device, which comprises:

[0066] a processor;

[0067] a transceiver;

[0068] a machine readable storage medium, which stores machine executable instructions capable of being executed by the processor; the machine executable instructions cause the processor to perform the following steps:

[0069] send, by the transceiver, a first message to each authentication server in a plurality of authentication servers, the first message being used to request the authentication server to perform terminal access authentication;

[0070] if a second message sent by any authentication server is received by the transceiver and the second message is a first second message sent by the plurality of authentication servers after the first message is received, send, by the transceiver, a third message to a terminal, the second message and the third message both being used to indicate that the terminal access authentication succeeds.

[0071] In a possible implementation, the machine executable instructions further cause the processor to perform the following steps:

[0072] If a fourth message sent by any one of the authentication servers is received through the transceiver, and the fourth message is the first fourth message sent by the authentication servers after the first message is received, a fifth message is sent to the terminal through the transceiver, the fifth message comprising authentication parameters, the authentication parameters being carried by an EAP message included in the fourth message.

[0073] A sixth message sent by the terminal is received through the transceiver, the sixth message comprising user identity information, the user identity information being encrypted by the authentication parameters.

[0074] A seventh message is sent to each of the authentication servers through the transceiver, the seventh message comprising the sixth message and the EAP message, so that the authentication servers verify the user identity information based on the authentication parameters.

[0075] In a possible implementation, the machine executable instructions further cause the processor to perform the following steps:

[0076] If the same number of eighth messages as the number of the authentication servers are received through the transceiver within a first preset time length, and the authentication results carried by each of the eighth messages indicate that the terminal fails in access authentication, the authentication result of each of the servers on the terminal is recorded as access authentication failure.

[0077] A ninth message is sent to the terminal through the transceiver, the ninth message being used to indicate that the terminal fails in access authentication.

[0078] In a possible implementation, the machine executable instructions further cause the processor to perform the following steps:

[0079] If no message sent by any one of the authentication servers is received after the first preset time length is reached, the authentication result of each of the servers on the terminal is recorded as authentication server unreachable.

[0080] A ninth message is sent to the terminal through the transceiver, the ninth message being used to indicate that the terminal fails in access authentication.

[0081] In a possible implementation, the machine executable instructions further cause the processor to perform the following steps:

[0082] If the first number of authentication servers sends the eighth message within the first preset time period, and each eighth message carries an authentication result indicating that the terminal fails in access authentication, the authentication result of each of the first number of authentication servers for the terminal is recorded as access authentication failure;

[0083] If no message sent by the second number of authentication servers in the plurality of servers is received after the first preset time period, the authentication result of each of the second number of authentication servers for the terminal is recorded as authentication server unreachable;

[0084] The ninth message or the tenth message is sent to the terminal through the transceiver, the ninth message is used to indicate that the terminal fails in access authentication, the tenth message is used to indicate that the terminal succeeds in access authentication, and the sum of the first number and the second number is equal to the number of the plurality of authentication servers.

[0085] In a possible implementation, the machine-executable instructions further cause the processor to perform the following steps:

[0086] If the same number of eighth messages as the number of the plurality of authentication servers is received through the transceiver within the second preset time period, and each eighth message carries an authentication result indicating that the terminal fails in access authentication, the authentication result of each server for the terminal is recorded as access authentication failure;

[0087] The ninth message is sent to the terminal through the transceiver, and the ninth message is used to indicate that the terminal fails in access authentication.

[0088] In a possible implementation, the machine-executable instructions further cause the processor to perform the following steps:

[0089] If no message sent by any authentication server is received after the second preset time period, the authentication result of each server for the terminal is recorded as authentication server unreachable.

[0090] The ninth message is sent to the terminal through the transceiver, and the ninth message is used to indicate that the terminal fails in access authentication.

[0091] In a possible implementation, the machine-executable instructions further cause the processor to perform the following steps:

[0092] If the third number of authentication servers sends the eighth message within the second preset time period, and each eighth message carries an authentication result indicating that the terminal fails in access authentication, the authentication result of each of the third number of authentication servers for the terminal is recorded as access authentication failure.

[0093] If the fourth number of authentication servers in the plurality of servers do not send the message to the terminal after the second preset time length, the authentication result of the fourth number of authentication servers to the terminal is recorded as an authentication server being unreachable.

[0094] The transceiver sends a ninth message or a tenth message to the terminal, the ninth message is used to indicate that the terminal access authentication fails, the tenth message is used to indicate that the terminal access authentication succeeds, and the sum of the third number and the fourth number is equal to the number of the plurality of authentication servers.

[0095] In a possible implementation, the seventh message includes an EAP message attribute, and the EAP message attribute is used to carry the EAP message.

[0096] In a possible implementation, the EAP message attribute has a preset length.

[0097] If the length of the EAP message is greater than the preset length, the seventh message includes a plurality of EAP message attributes, and the EAP message is carried in the plurality of EAP message attributes in a fragmented form.

[0098] In a possible implementation, the access device is connected with a plurality of groups of authentication servers, and the machine-executable instructions cause the processor to perform the following steps:

[0099] selecting a group of authentication servers from the plurality of groups of authentication servers in a load sharing manner, and sending the first message to the selected group of authentication servers through the transceiver; or

[0100] selecting a preset number of authentication servers from each group of authentication servers included in the plurality of groups of authentication servers in a load sharing manner, and sending the first message to the selected authentication servers through the transceiver.

[0101] In a fourth aspect, an embodiment of the present application provides a machine-readable storage medium, which stores machine-executable instructions, when called and executed by a processor, the machine-executable instructions cause the processor to implement the method in the first aspect.

[0102] In a fifth aspect, an embodiment of the present application provides a computer program product, which causes the processor to implement the method in the first aspect.

[0103] According to the technical scheme, the access device can send the first message for requesting the access authentication of the terminal to multiple authentication servers, if the second message sent by any authentication server is received, and the second message is the first second message received by the multiple authentication servers, the third message can be sent to the terminal, and the second message and the third message are both used for indicating that the access authentication is successful. It can be seen that the access device can send the first message to multiple authentication servers, even if some authentication servers are faulty, as long as the second message replied by any authentication server is received, and the second message is the first second message, the third message can be replied to the terminal, and the authentication process of the terminal will not be affected, and the problem of the terminal online failure caused by the server failure can be avoided. BRIEF DESCRIPTION OF DRAWINGS

[0104] The accompanying drawings, which are included to provide a further understanding of the application and are incorporated in and constitute a part of this application, illustrate embodiments of the application and serve to explain the principles of the application, and do not limit the application.

[0105] Figure 1 An exemplary schematic diagram of an EAP relay processing mechanism provided by an embodiment of the application;

[0106] Figure 2 An exemplary schematic diagram of an EAP termination processing mechanism provided by an embodiment of the application;

[0107] Figure 3 An exemplary schematic diagram of a networking system provided by an embodiment of the application;

[0108] Figure 4 A flowchart of a terminal authentication method provided by an embodiment of the application;

[0109] Figure 5 An exemplary schematic diagram of a first terminal authentication method provided by an embodiment of the application;

[0110] Figure 6 An exemplary schematic diagram of a second terminal authentication method provided by an embodiment of the application;

[0111] Figure 7 An exemplary schematic diagram of a third terminal authentication method provided by an embodiment of the application;

[0112] Figure 8 An exemplary schematic diagram of a fourth terminal authentication method provided by an embodiment of the application;

[0113] Figure 9 A structural schematic diagram of a terminal authentication device provided by an embodiment of the application;

[0114] Figure 10A structural schematic diagram of an access device is provided for an embodiment of the present application. DETAILED DESCRIPTION

[0115] For the purpose, technical solutions, and advantages of the present application to be more clearly and obviously understood, the present application is further described in detail below with reference to the drawings and embodiments. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art belong to the scope of protection of the present application.

[0116] For the purpose, technical solutions, and advantages of the present application to be more clearly and obviously understood, the present application is further described in detail below with reference to the drawings and embodiments. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art belong to the scope of protection of the present application.

[0117] Authentication, Authorization, and Accounting (AAA) is a management mechanism of network security, which provides three security functions of authentication, authorization, and accounting.

[0118] Authentication: confirms the identity of a user accessing a network remotely, and judges whether the user is a legal network user.

[0119] Authorization: gives different permissions to different users, and limits the services that can be used by the users. For example, an administrator can grant an office user the permission to access and print files in a server, and other users do not have this permission.

[0120] Accounting: records all operations of a user in the process of using network services, including the type of services used, the starting time, data traffic, etc., which are used to collect and record the use of network resources by the user, and can realize charging based on time and traffic. The charging function can monitor the network.

[0121] The Remote Authentication Dial-In User Service (RADIUS) protocol combines the processes of authentication and authorization. The RADIUS protocol is a distributed information interaction protocol, which can be applied to a networking system including terminals and authentication servers. The authentication servers can protect the network from unauthorized users based on the RADIUS protocol. The RADIUS protocol is applied in a network environment with high security requirements and allowing users to access remotely. The RADIUS protocol defines the message format and message transmission mechanism of RADIUS, and specifies that the User Datagram Protocol (UDP) is used as the transport layer protocol for encapsulating RADIUS messages. Among them, the UDP port 1812 can be used as an authentication / authorization port, and the port 1813 can be used as a charging port.

[0122] In a system applying 802.1X protocol, the interaction of authentication information between a terminal, an access device and an authentication server can be implemented based on EAP. The EAP supports multiple authentication methods. For example, Message-Digest algorithm 5-Challenge (MD5-Challenge), Extensible Authentication Protocol-Transport Layer Security (EAP-TLS), Protected Extensible Authentication Protocol (PEAP), etc.

[0123] In the terminal authentication process, the terminal can encapsulate EAP packets in a data frame using Extensible Authentication Protocol over Local Area Network (EAPOL) encapsulation format, and send the data frame to the access device.

[0124] The access device can interact with the authentication server through an EAP relay processing mechanism or an EAP termination processing mechanism.

[0125] The EAP relay processing mechanism refers to that the access device relays the received EAP packets.

[0126] As shown in FIG. 1, Figure 1 Figure 1 An example shows one terminal, one access device and one authentication server, which can be a RADIUS server.

[0127] In the EAP relay processing mechanism, EAP authentication is performed between the terminal and the authentication server. In the EAP verification process, the terminal sends EAP packets to the access device, which are EAP packets over LAN encapsulated using Extensible Authentication Protocol over Local Area Network encapsulation format. The access device can relay the received EAP packets to obtain relayed EAP packets, which are EAP packets over RADIUS encapsulated using Extensible Authentication Protocol over Remote Authentication Dial in User Service Protocol encapsulation format, and send the encapsulated EAP packets to the authentication server.

[0128] ​In the above process, the authentication server acts as the EAP server to process the EAP messages sent by the terminal, and the access device is equivalent to a relay device used to relay the EAP messages sent by the terminal.

[0129] The EAP termination mechanism refers to the termination process performed by the access device on the received EAP messages.

[0130] like Figure 2 As shown, Figure 2 An example is shown, comprising a terminal, an access device, and an authentication server.

[0131] In the EAP termination mechanism, authentication between the terminal and the access device is performed using EAP authentication, while authentication between the access device and the authentication server is performed using either Password Authentication Protocol (PAP) authentication or Challenge Handshake Authentication Protocol (CHAP) authentication. Specifically, the terminal sends an EAP message to the access device, which is an EAP packet over LAN encapsulated using the Extensible Authentication Protocol over LAN (RADIUS) encapsulation format. The access device then encapsulates the user identity information carried in the EAP message within a standard Remote Authentication Dial-In User Service (RADIUS) message and sends this RADIUS message to the authentication server.

[0132] To avoid terminal access authentication failures due to authentication server malfunctions, this application provides a terminal authentication method, which can be applied to, for example... Figure 3 The network system shown.

[0133] In this embodiment of the application, the access device can connect to multiple authentication servers. Figure 3 The example shows authentication server 1, authentication server 2, authentication server 3, access device, and terminal.

[0134] The terminal accesses the network through an access device, which is connected to authentication server 1, authentication server 2 and authentication server 3 respectively.

[0135] When a terminal accesses network resources, it needs to go through an access device. The terminal can send an EAP message to the access device to request access authentication. The access device can send an authentication request message to the authentication server through the EAP relay processing mechanism or the EAP termination mechanism. This authentication request message can be the EAP packets over LAN or RADIUS message described above.

[0136] The authentication server can perform access authentication on the terminal based on the user identity information carried in the authentication request message. If the access authentication is successful, the authentication server sends an authentication success message carrying user permission information to the access device. Then, the access device can grant the user corresponding permissions according to the user permission information. In this way, the access device can release the traffic within the user permission range, so that the terminal can access network resources.

[0137] It should be noted that in the embodiments of the present application, the terminal can be a mobile phone, a computer, a switch or other network device that applies to access network resources, and other electronic devices that can apply to access network resources, can also be a telephone, a printer that uses an Internet Protocol (IP) or a Media Access Control (MAC) address as an identity credential, and can also be an electronic device for managing an access device. The terminal generally refers to an electronic device that needs to access network resources and an electronic device for managing an access device.

[0138] The access device generally refers to a switch, a router, an Access Point (AP), an Access Controller (AC), a firewall, and other network devices that support user access authentication.

[0139] The terminal authentication method provided by the embodiments of the present application is described in detail below.

[0140] As shown in Figure 4 The present application provides a terminal authentication method, which is applied to an access device, and the method comprises the following steps:

[0141] S401, a first message is sent to each of a plurality of authentication servers.

[0142] The first message is used to request the authentication server to perform access authentication on the terminal. As an example, the first message can be an Access-Request message.

[0143] The first message carries user identity information of a user, and the authentication server can parse the first message to obtain the user identity information and perform authentication on the terminal based on the parsed user identity information.

[0144] S402, if a second message sent by any one of the authentication servers is received and the second message is the first second message sent by the plurality of authentication servers after receiving the first message, a third message is sent to the terminal.

[0145] The second message and the third message are both used to indicate that the terminal access authentication is successful. As an example, the second message can be an access accept (Access-Accept) message, and the third message can be an EAP success (EAP-Success) message.

[0146] The access device can simultaneously send the first message to each of the plurality of authentication servers. After each authentication server receives the first message, the authentication server performs terminal authentication based on the first message. If the authentication is successful, the authentication server returns a second message to the access device. Accordingly, the access device can receive a plurality of second messages. When the first second message is received, the access device can send a third message to the terminal. When the second and subsequent second messages are received, the access device does not need to repeatedly send the third message to the terminal.

[0147] With the above technical solution, the access device can send a first message to request the plurality of authentication servers to perform access authentication on the terminal. If a second message sent by any one of the authentication servers is received, and the second message is the first second message received by the plurality of authentication servers, the access device can send a third message to the terminal. The second message and the third message are both used to indicate that the access authentication is successful. As can be seen, the access device can send the first message to the plurality of authentication servers. Even if some of the authentication servers fail, as long as a second message returned by any one of the authentication servers is received, and the second message is the first second message, the access device can return a third message to the terminal, which does not affect the authentication process of the terminal, and can avoid the problem of terminal online failure caused by server failure.

[0148] In another embodiment of the present application, in a scenario using an EAP relay processing mechanism, after the step S401 of sending the first message to each of the plurality of authentication servers, the method further includes:

[0149] Step 1: If a fourth message sent by any one of the authentication servers is received, and the fourth message is the first fourth message sent by the plurality of authentication servers after receiving the first message, a fifth message is sent to the terminal.

[0150] The fifth message includes authentication parameters carried by an EAP message included in the fourth message.

[0151] The authentication parameter can be information such as an algorithm suite of a Transport Layer Security (TLS) tunnel, a random number (Random) in a Server Hello message, or a Challenge parameter of a Microsoft Challenge-Handshake Authentication Protocol version 2 (MSCHAPv2).

[0152] For example, the fourth message can be an Access-Challenge message, and the fifth message can be an EAP-request message. In the case where the fourth message is an Access-Challenge message, the authentication parameter can be a Challenge parameter, and accordingly, the fifth message also carries the Challenge parameter.

[0153] It should be noted that the fourth message is a message encapsulated in an EAP OR format, and the access device can obtain the EAP message encapsulated in the first fourth message and record the EAP message.

[0154] The EAP message is specifically encapsulated in an EAP-Message attribute of the fourth message, and the access device can extract the EAP-Message attribute, record the EAP-Message attribute as a server-EAP-Message attribute, and store it locally. In this way, the EAP message in the fourth message is equivalent to being stored.

[0155] Step 2, the access terminal sends a sixth message.

[0156] The sixth message includes user identity information, and the user identity information is encrypted by the authentication parameter. For example, the user identity information can be a password input by the user. In the case where the authentication parameter is a Challenge parameter, the terminal can obtain the Challenge parameter from the fifth message and encrypt the password input by the user based on the Challenge parameter to obtain an encrypted password. Then the encrypted password is encapsulated in the sixth message.

[0157] For example, the sixth message can be an EAP-Response message.

[0158] Step 3, the terminal sends a seventh message to each authentication server, and the seventh message includes the sixth message and an EAP message, so that the authentication server verifies the user identity information based on the authentication parameter.

[0159] As an example, the seventh message can be an Access-Request message.

[0160] The seventh message includes an EAP message (EAP-Message) attribute, which is used to carry an EAP message. The length of the EAP message attribute is a preset length. If the length of the EAP message is greater than the preset length, the seventh message includes multiple EAP message attributes, and the EAP message is carried in the multiple EAP message attributes in a fragmented form.

[0161] As an example, the preset length can be 253 bytes, that is, when the length of an EAP message exceeds 253 bytes, the access device encapsulates the fragmented EAP message in multiple EAP message attributes. The attribute number of the EAP-Message attribute can be assigned according to actual conditions, such as assigning an attribute number value that is not currently used, for example, 239. The application embodiments do not make specific limitations on the attribute number value, and the data type carried is Octets (octets).

[0162] In the embodiments of the present application, the above-mentioned EAP-Message attribute is newly added in the seventh message, and the newly added EAP-Message attribute can be a Server-EAP-Message attribute. The Server-EAP-Message attribute is used to carry the EAP message in the Server-EAP-Message attribute recorded by the access device after receiving the first fourth message in step 1.

[0163] According to the protocol, the seventh message also includes a Client-EAP-Message attribute, which is used to carry the sixth message.

[0164] After each authentication server receives the seventh message, it obtains the EAP message from the Server-EAP-Message attribute and the authentication parameters carried by the EAP message. It also obtains the sixth message from the Client-EAP-Message attribute and the user identity information carried by the sixth message.

[0165] It should be noted that the Server-EAP-Message attribute and the Client-EAP-Message attribute are both EAP-Message attributes. In the embodiments of the present application, in order to distinguish the two EAP-Message attributes carried in the seventh message, the two EAP-Message attributes are referred to as the Server-EAP-Message attribute and the Client-EAP-Message attribute. The name of the EAP-Message attribute is not limited in the embodiments of the present application.

[0166] It can be understood that the authentication parameters generated by each authentication server are different, and each authentication server locally stores the authentication parameters generated by itself. The authentication parameters obtained by the authentication server from the seventh message can be different from the locally stored authentication parameters.

[0167] Since the user identity information carried in the seventh message is encrypted by using the authentication parameters carried in the seventh message, in order to correctly verify the user identity information, the authentication server needs to update the locally stored authentication parameters to the authentication parameters carried in the seventh message, and then encrypt the locally stored user identity information by using the updated authentication parameters. If the encrypted user identity information is the same as the user identity information obtained from the seventh message, the terminal access authentication is passed.

[0168] For example, the multiple authentication servers include an authentication server 1, an authentication server 2 and an authentication server 3, the authentication server 1 locally stores authentication parameters 1, the authentication server 2 locally stores authentication parameters 2, and the authentication server 3 locally stores authentication parameters 3.

[0169] The first fourth message received by the access device is sent by the authentication server 1, the EAP message encapsulated in the Server-EAP-Message attribute of the seventh message is the same as the EAP message in the fourth message, that is, the authentication parameters carried in the seventh message are the authentication parameters 1, and the user identity information carried in the seventh message is encrypted by using the authentication parameters 1.

[0170] If the authentication server 1 fails or the network between the authentication server 1 and the access device is unreachable, the authentication server 1 cannot receive the seventh message, while the authentication server 2 and the authentication server 3 can receive the seventh message.

[0171] Since the user identity information carried in the seventh message is encrypted by using the authentication parameters 1, after receiving the seventh message, the authentication server 2 verifies the user identity information by using the locally stored authentication parameters 2, which will cause authentication failure. Therefore, the Server-EAP-Message attribute in the seventh message carries the EAP message, the authentication server 1 can obtain the authentication parameters 1 from the EAP message, and use the authentication parameters 1 to overwrite the locally stored authentication parameters 2, and then use the authentication parameters 1 to authenticate the user identity information carried in the seventh message.

[0172] Similarly, after receiving the seventh message, the authentication server 3 obtains the authentication parameters 1 from the seventh message, uses the authentication parameters 1 to overwrite the locally stored authentication parameters 3, and then uses the authentication parameters 3 to authenticate the user identity information carried in the seventh message.

[0173] It can be seen that by adding the Server-EAP-Message attribute in the seventh message, the synchronization of the authentication parameters between different authentication servers is realized, so that the authentication server can use the correct authentication parameters to authenticate the user identity information, avoiding the problem of access authentication failure caused by the use of incorrect authentication parameters by the authentication server, thereby avoiding the problem of long-time network access failure of the user and improving the user experience. Moreover, although the data synchronization channel can be established between the authentication servers, the real-time synchronization of the authentication parameters cannot be realized by using the data synchronization channel between the authentication servers. In the embodiment of the application, the authentication parameters are carried in the seventh message sent by the access device, so that the authentication server can obtain the correct authentication parameters when authenticating the user identity, and the problem of authentication failure caused by the failure of timely synchronization of the authentication parameters can be avoided.

[0174] It should be noted that in the scenario of using the EAP relay processing mechanism, there can be multiple interactive processes of user information authentication between the terminal and the authentication server, and each interactive process is used to authenticate different identity information of the user. The number of interactions and the identity information of the user to be authenticated each time can be referred to the related protocol, and the embodiment of the application does not limit this.

[0175] Continuing the above example, if the authentication server 2 and the authentication server 3 are both authenticated, the access device can also send a continue authentication message to the access device, and the EAP message encapsulated in the continue authentication message also carries the authentication parameters. The access device still records the EAP message in the first continue authentication message received, and the subsequent process is similar to the above steps 1 to 3, until the access device receives the first second message, and sends a third message to the terminal.

[0176] As an optional implementation, after generating the authentication parameters, the authentication server can carry the authentication parameters by using a newly added Radius attribute, and when sending the seventh message to multiple authentication servers subsequently, the authentication parameters can also be carried by using the newly added Radius attribute. In this way, the problem of authentication failure caused by the failure of timely synchronization of the authentication parameters can also be avoided, but the method of synchronizing the authentication parameters by using the Server-EAP-Message attribute introduced in the above embodiment is more secure and easier to implement.

[0177] In the scenario of using the EAP relay processing mechanism, after sending the first message to multiple authentication servers, the terminal access authentication fails in the following three cases, which are described as follows:

[0178] Case 1: If the same number of eighth messages as the number of authentication servers are received within the first preset time period, the authentication result of each server to the terminal is recorded as access authentication failure, and a ninth message is sent to the terminal.

[0179] The first preset time length can be set according to experience. The authentication result carried by each eighth message indicates that the terminal access authentication fails, and the ninth message is used to indicate that the terminal access authentication fails. As an example, the eighth message is an access-reject message, and the ninth message is an EAP-failure message.

[0180] The access device locally stores a user table of each user. In the embodiment of the application, the access device can set a server table in the user table of the user currently being authenticated. The server table includes basic information of each authentication server in the above plurality of authentication servers and the returned authentication result. The basic information can include the IP address, port number and shared key of the authentication server. The authentication result can be authentication success, authentication failure or continue authentication.

[0181] It can be understood that the access device can record the authentication result corresponding to the authentication server sending the eighth message as authentication failure for each eighth message received within the first preset time length. If the authentication results of the plurality of authentication servers are all recorded as authentication failure, the ninth message can be sent to the terminal.

[0182] Case 2, if no message sent by any authentication server is received after the first preset time length is reached, the authentication result of each server to the terminal is recorded as authentication server unreachable, and the ninth message is sent to the terminal.

[0183] If no message sent by any authentication server is received after the first preset time length is reached, it means that each authentication server in the plurality of authentication servers does not respond to the first message, which can be that the plurality of authentication servers are all faulty or that the network between the access device and the authentication servers is unreachable. In combination with the server table introduced in case 1, for each authentication server, if no message returned by the authentication server is received after the first preset time length is reached, the authentication result corresponding to the authentication server in the server table can be recorded as authentication server unreachable.

[0184] If the authentication results of the plurality of authentication servers are all recorded as authentication server unreachable, the ninth message can be sent to the terminal.

[0185] Case 3, if the eighth message sent by the first number of authentication servers is received within the first preset time length, and the authentication result carried by each eighth message indicates that the terminal access authentication fails, the authentication result of the first number of authentication servers to the terminal is recorded as access authentication failure.

[0186] After the first preset time length is reached, if the message sent by the second number of authentication servers in the plurality of servers is not received, the authentication result of the second number of authentication servers to the terminal is recorded as the authentication server being unreachable, respectively.

[0187] The ninth message or the tenth message is sent to the terminal, the ninth message is used to indicate that the terminal access authentication fails, the tenth message is used to indicate that the terminal access authentication succeeds, and the sum of the first number and the second number is equal to the number of the plurality of authentication servers.

[0188] According to the introduction in case 1 and case 2, for each authentication server in the plurality of authentication servers, if the eighth message sent by the authentication server is received within the first preset time length, the authentication result corresponding to the authentication server is recorded as authentication failure; if the message sent by the authentication server is not received after the first preset time length, the authentication result corresponding to the authentication server is recorded as the authentication server being unreachable.

[0189] In addition, if the second message sent by the authentication server is received within the first preset time length, the authentication result corresponding to the authentication server is recorded as authentication success; if the message sent by the authentication server to indicate continuing authentication is received within the first preset time length, the authentication result corresponding to the authentication server is recorded as continuing authentication. It can be understood that in the case of multiple interaction processes, if there is continuing authentication in the authentication results corresponding to the plurality of authentication servers, the access device needs to update the authentication results of each authentication server in each subsequent interaction process according to the above method.

[0190] If the authentication results of the plurality of authentication servers are partially recorded as access authentication failure, and the authentication results of the other authentication servers are all recorded as the authentication server being unreachable, the ninth message or the tenth message can be sent to the terminal.

[0191] If the escape strategy is configured in the access device, the tenth message can be sent to the terminal to allow the terminal to access the network resource; if the escape strategy is not configured, the ninth message is sent to the terminal to refuse the terminal to access the network resource. The configuration method and strategy content of the escape strategy are not limited in the embodiment of the application, and can be referred to the related EAP authentication protocol.

[0192] As an example, if the access device is connected with 5 authentication servers, the access device receives the eighth message sent by 3 authentication servers within the first preset time length after sending the first message to the 5 authentication servers, and does not receive the message sent by the other 2 authentication servers, the authentication results corresponding to the 3 authentication servers are all recorded as authentication failure, the authentication results of the 2 authentication servers are recorded as the authentication server being unreachable, and then the access device sends the ninth message or the tenth message to the terminal.

[0193] With the method, the access device can simultaneously send the first message to each of the plurality of authentication servers respectively, and record the access authentication result of each authentication server to the terminal. After receiving the second message replied by any authentication server, the third message can be replied to the terminal, thereby reducing the waiting time of the terminal. In the case that the plurality of authentication servers all fail in authentication, the terminal is notified of the access authentication failure, thereby avoiding the problem of the terminal access authentication failure or too long waiting time caused by the failure of part of the authentication servers or network unreachability.

[0194] In the scenario of using the EAP termination processor mechanism, after sending the first message to the plurality of authentication servers, the terminal access authentication failure can be determined in the following three cases, which are described as follows.

[0195] Case 1, if the same number of eighth messages as the number of the plurality of authentication servers are received within the second preset time length, and the authentication result carried by each eighth message indicates that the terminal access authentication fails, then the authentication result of each server to the terminal is recorded as access authentication failure respectively, and the ninth message is sent to the terminal.

[0196] The second preset time length can be set according to experience. The authentication result carried by each eighth message indicates that the terminal access authentication fails, and the ninth message is used to indicate that the terminal access authentication fails. As an example, the eighth message is an access reject (Access-Reject) message, and the ninth message is an EAP failure (EAP-Failure) message.

[0197] The access device locally stores a user table of each user. In the embodiment of the application, the access device can set a server table in the user table of the user currently being authenticated. The server table includes the basic information of each authentication server in the plurality of authentication servers and the replied authentication result. The basic information can include the IP address, port number and shared key of the authentication server. The authentication result can be authentication success, authentication failure or continue authentication.

[0198] It can be understood that the access device can record the authentication result of the authentication server corresponding to each eighth message received within the first preset time length as authentication failure. If the authentication result of the plurality of authentication servers is all recorded as authentication failure, the ninth message can be sent to the terminal.

[0199] Case 2, after the second preset time length is reached, if no message sent by any authentication server is received, the authentication result of each server to the terminal is recorded as authentication server unreachable respectively, and the ninth message is sent to the terminal.

[0200] After the first preset time length is reached, if no message sent by any authentication server is received, it indicates that each of the plurality of authentication servers does not respond to the first message, which can be that all the plurality of authentication servers are faulty or that the network between the access device and the authentication servers is unreachable. In combination with the server table introduced in case 1, for each authentication server, if no message sent by the authentication server is received after the first preset time length is reached, the authentication result corresponding to the authentication server in the server table can be recorded as authentication server unreachable.

[0201] If the authentication results of the plurality of authentication servers are all recorded as authentication server unreachable, the ninth message can be sent to the terminal.

[0202] Case 3, if the eighth message sent by the third number of authentication servers is received within the second preset time length, and the authentication result carried in each eighth message indicates that the terminal access authentication fails, the authentication result of the third number of authentication servers to the terminal is recorded as access authentication failure respectively.

[0203] After the second preset time length is reached, if no message sent by the fourth number of authentication servers in the plurality of servers is received, the authentication result of the fourth number of authentication servers to the terminal is recorded as authentication server unreachable respectively.

[0204] The ninth message or the tenth message is sent to the terminal, the ninth message is used to indicate that the terminal access authentication fails, the tenth message is used to indicate that the terminal access authentication succeeds, and the sum of the third number and the fourth number is equal to the number of the plurality of authentication servers.

[0205] In combination with the introduction in case 1 and case 2, for each authentication server in the plurality of authentication servers, if the eighth message sent by the authentication server is received within the first preset time length, the authentication result corresponding to the authentication server is recorded as authentication failure; if no message sent by the authentication server is received after the first preset time length, the authentication result corresponding to the authentication server is recorded as authentication server unreachable.

[0206] In addition, if the second message sent by the authentication server is received within the first preset time length, the authentication result corresponding to the authentication server is recorded as authentication success; if the message sent by the authentication server to indicate continuous authentication is received within the first preset time length, the authentication result corresponding to the authentication server is recorded as continuous authentication. If the authentication results of the plurality of authentication servers are all recorded as authentication failure, the ninth message can be sent to the terminal.

[0207] With the method, the access device can simultaneously send the first message to each of the plurality of authentication servers respectively, and record the access authentication result of each authentication server to the terminal. After receiving the second message returned by any authentication server, the third message is returned to the terminal, thereby reducing the waiting time of the terminal. In the case that all the authentication servers fail to authenticate, the terminal is notified of the access authentication failure, thereby avoiding the problem of access authentication failure or too long waiting time of the terminal caused by the failure of part of the authentication servers or network unavailability.

[0208] In another embodiment of the present application, the access device is connected with a plurality of groups of authentication servers, and each group of authentication servers includes at least one authentication server. Then, the step of sending the first message to each of the plurality of authentication servers respectively can be implemented as follows:

[0209] The authentication servers are selected from the plurality of groups of authentication servers in a load sharing manner, and the first message is sent to the selected group of authentication servers; or a preset number of authentication servers are selected from each group of authentication servers in a load sharing manner, and the first message is sent to the selected authentication servers.

[0210] In the embodiment of the present application, for the scenario of large number of user online and concurrency, the authentication servers connected with the access device can be grouped in advance, and the IP address of each group of authentication servers is stored in the access device.

[0211] In this way, after the terminal initiates the access authentication to the access device, the terminal can select the authentication server in a load sharing manner.

[0212] For example, the access device is connected with three groups of authentication servers, and each group of authentication servers includes three authentication servers.

[0213] In one implementation, if the load pressure of the first group of authentication servers is small, the three authentication servers included in the first group of authentication servers are taken as the plurality of authentication servers in the above embodiment, and the first message is sent to the three authentication servers respectively.

[0214] In another implementation, if the load pressure of the authentication server A in the first group of authentication servers, the authentication server B in the second group of authentication servers and the authentication server C in the third group of authentication servers is small, the authentication server A, the authentication server B and the authentication server C are taken as the plurality of authentication servers in the above embodiment, and the first message is sent to the authentication server A, the authentication server B and the authentication server C respectively.

[0215] Any load sharing algorithm can be used to select the authentication server in the embodiment of the present application, which is not limited in the present application.

[0216] By using the method, the problem that multiple terminals simultaneously initiate access authentication and the access device simultaneously sends authentication request messages for the multiple terminals to all authentication servers can be avoided, the access authentication request of different terminals can be distributed to different servers, and the processing pressure of a single authentication server is reduced.

[0217] The EAP termination processing mechanism and the EAP relay processing mechanism in the embodiments of the present application are described below in combination with specific examples.

[0218] Taking the EAP termination processing mechanism as an example, the terminal authentication method provided in the embodiments of the present application is introduced. Taking the connection of the access device with the authentication server 1 and the authentication server 2 as an example, as shown in FIG. 1, the method includes the following steps. Figure 5

[0219] S501, a user logs in.

[0220] S502, the terminal sends an EAP-Start message to the access device, and correspondingly, the access device receives the EAP-Start message.

[0221] The terminal starts an access authentication process after the user logs in the terminal, and then the terminal sends the EAP-Start message to the access device. The EAP-Start message can be an 802.1x protocol message, a Point to Point Protocol (PPP) message, a Dynamic Host Configuration Protocol (DHCP) message, or various service messages such as a MAC address authentication message. That is, the EAP-Start message generally refers to a message that can trigger the access device to perform access authentication.

[0222] After the access device receives the EAP-Start message, the access device creates a user table entry for the user in a local user table, and the user table entry is used to store user information. Specifically, the user table entry takes the MAC address of the terminal as a key, and stores the interface and VLAN information of the terminal.

[0223] S503, the access device sends an EAP-Request-Identity message to the terminal, and correspondingly, the terminal receives the EAP-Request-Identity message.

[0224] The EAP-Request-Identity message is used to request the username of the terminal.

[0225] ​S504, the terminal sends an EAP-Response-Identity message to the access device, and correspondingly, the access device receives the EAP-Response-Identity message.

[0226] The EAP-Response-Identity message includes a username input by a user on the terminal. The access device can obtain the username from the EAP-Response-Identity message, and search for the username in a pre-stored username list. If the username is found, an MD5 Challenge is randomly generated.

[0227] S505, the access device sends an EAP-Request-MD5-Challenge message to the terminal, and correspondingly, the terminal receives the EAP-Request-MD5-Challenge message.

[0228] The EAP-Request-MD5-Challenge message includes the MD5 Challenge generated by the access device.

[0229] S506, the terminal sends an EAP-Response-MD5-Challenge message to the access device, and correspondingly, the access device receives the EAP-Response-MD5-Challenge message.

[0230] After receiving the EAP-Request-MD5-Challenge message, the terminal obtains the MD5 Challenge from the EAP-Request-MD5-Challenge message, and encrypts the password input by the user by using the MD5 Challenge, to obtain an encrypted password.

[0231] The EAP-Response-MD5-Challenge message carries the encrypted password.

[0232] S507, the access device sends an Access-Request message to the authentication server 1 and the authentication server 2, and correspondingly, the authentication server 1 and the authentication server 2 receive the Access-Request message.

[0233] The Access-Request message includes the username, the encrypted password, and the MD5 Challenge.

[0234] The authentication server 1 and the authentication server 2 can obtain the username, the encrypted password and the MD5 Challenge from the Access-Request message, obtain the password corresponding to the username locally, encrypt the password obtained locally by using the MD5 Challenge, and then compare the encrypted result with the encrypted password obtained from the Access-Request message. If the two are consistent, the terminal access authentication succeeds; if the two are inconsistent, the terminal access authentication fails.

[0235] In the embodiment, it is assumed that the authentication server 1 succeeds in the terminal access authentication, and the authentication server 2 fails in the terminal access authentication. After the authentication server 1 completes the authentication, S508 is performed, and after the authentication server 2 completes the authentication, S509 is performed.

[0236] In addition, the access device can determine the user table item corresponding to the terminal according to the MAC address of the terminal, and create a server table in the corresponding user table item, where the server table is used to store the authentication result fed back by each authentication server.

[0237] S508, the authentication server 1 sends an Access-Accept (Access-Accept) message to the access device, and correspondingly, the access device receives the Access-Accept message.

[0238] After the access device receives the Access-Accept message, the authentication result corresponding to the authentication server 1 in the server table is recorded as access authentication success. After S508, S510 is performed.

[0239] S509, the authentication server 2 sends an Access-Reject (Access-Reject) message to the access device, and correspondingly, the access device receives the Access-Reject message.

[0240] The Access-Reject message is used to indicate that the authentication server 2 fails in the terminal access authentication, and after the access device receives the Access-Reject message, the authentication result corresponding to the authentication server 2 in the server table is recorded as access authentication failure.

[0241] S510, the access device sends an EAP-Success (EAP-Success) message to the terminal, and correspondingly, the terminal receives the EAP-Success message.

[0242] The EAP-Success message is used to indicate that the authentication server succeeds in the terminal authentication.

[0243] S511, the terminal is successfully online.

[0244] At this point, the terminal is successfully online, and the subsequent access device can access network resources.

[0245] By using the above method, the access device can send Access-Request messages to multiple authentication servers at the same time. The access device receives an Access-Accept message returned by any authentication server, and then returns an EAP-Success message to the terminal. If there is a failure or a busy authentication server, the access device does not need to wait for the Access-Accept message returned by the authentication server, but can notify the terminal of the successful access authentication after receiving the first Access-Accept message. In this way, the speed of terminal access to the network can be improved, and the user experience of network access can be improved.

[0246] In addition, since the access device receives an Access-Accept message returned by any authentication server, it can determine that the terminal access authentication is successful. In the case where the access authentication result of each authentication server for the terminal is access authentication failure, the terminal access authentication is determined to fail. This can avoid the terminal access authentication failure caused by the failure or busy of part of the authentication servers.

[0247] It should be noted that, Figure 5 In the case of EAP protocol message, in the case of only one interaction between the access device and the authentication server to complete the authentication of the terminal, if the access authentication process between the terminal and the access device is performed by using other non-EAP protocols such as PPP, Http / Https message, the method introduced in the Figure 5 can also be used to realize fast access authentication.

[0248] Taking the EAP relay processing mechanism as an example, the terminal authentication method provided by the embodiments of the present application is introduced. Taking the connection between the access device and the authentication server 1 and the authentication server 2 as an example, as shown in Figure 6 , the method includes the following steps:

[0249] S601, a user logs in.

[0250] S602, the terminal sends an EAP-Start message to the access device, and the access device receives the EAP-Start message.

[0251] For the introduction of the EAP-Start message, please refer to the related description in the above S502, which will not be repeated here.

[0252] S603, the access device sends an EAP-Request-Identity message to the terminal, and correspondingly, the terminal receives the EAP-Request-Identity message.

[0253] The EAP-Request-Identity message is used to request the username of the terminal.

[0254] S604, the terminal sends an EAP-Response-Identity message to the access device, and correspondingly, the access device receives the EAP-Response-Identity message.

[0255] The EAP-Response-Identity message includes the username.

[0256] S605, the access device sends an Access-Request message to the authentication server 1 and the authentication server 2, and correspondingly, the authentication server 1 and the authentication server 2 receive the Access-Request message.

[0257] The Access-Request message is a message encapsulated by using the RADIUS protocol, and the Access-Request message includes a Client-EAP-Message attribute, and the EAP-Response-Identity message is encapsulated in the Client-EAP-Message attribute.

[0258] In addition, the access device can determine the user table item corresponding to the terminal according to the MAC address of the terminal, and create a server table in the corresponding user table item, where the server table is used to store the authentication result fed back by each authentication server.

[0259] After receiving the Access-Request message, the authentication server 1 and the authentication server 2 can negotiate the authentication mode with the terminal, and the specific negotiation mode can refer to the related protocol, which is not limited in the embodiments of the application. If the authentication server 1 and the authentication server 2 both need to continue to authenticate the terminal, the authentication server 1 performs S606, and the authentication server 2 performs S607.

[0260] S606, the authentication server 1 sends an Access-challenge message to the access device, and correspondingly, the access device receives the Access-challenge message.

[0261] Wherein, the authentication server 1 receives the Access-Request message, can obtain the username from the Access-Request message, and searches the username in the pre-stored username list, if the username is found, a Challenge is randomly generated, for example, Challenge 1.

[0262] Wherein, the Access-challenge message is a message of the RADIUS protocol, the Access-challenge message includes the Client-EAP-Message attribute, and the EAP message is encapsulated in the Client-EAP-Message attribute, and the EAP message carries the Challenge 1.

[0263] S607, the authentication server 2 sends the Access-challenge message to the access device, and correspondingly, the access device receives the Access-challenge message.

[0264] Wherein, the authentication server 2 receives the Access-Request message, can obtain the username from the Access-Request message, and searches the username in the pre-stored username list, if the username is found, a Challenge is randomly generated, for example, Challenge 2.

[0265] Wherein, the Access-challenge message is a message of the RADIUS protocol, the Access-challenge message includes the Client-EAP-Message attribute, and the EAP message is encapsulated in the Client-EAP-Message attribute, and the EAP message carries the Challenge 2.

[0266] It can be understood that the access device receives the Access-challenge messages replied by the authentication server 1 and the authentication server 2 at different times, and the access device can execute S608 after receiving the first Access-challenge message.

[0267] It should be noted that after the access device receives the first Access-challenge message, the access device extracts the Client-EAP-Message attribute of the Access-challenge message, and records the Client-EAP-Message as the Server-EAP-Message attribute.

[0268] In the current interaction, if the access device receives other Access-challenge messages, it can query whether the Server-EAP-Message attribute has been recorded locally, and if yes, it need not be recorded repeatedly.

[0269] Since the authentication server 1 and the authentication server 2 reply with Access-challenge messages, the access device can record the access authentication results of the authentication server 1 and the authentication server 2 in the server table as continuing authentication respectively.

[0270] S608. The access device sends an EAP-Request message to the terminal, and correspondingly, the terminal receives the EAP-Request message.

[0271] Taking the first Access-challenge message received by the access device as an example, the EAP-Request message carries Challenge1.

[0272] S609. The terminal sends an EAP-Response message to the access device, and correspondingly, the access device receives the EAP-Response message.

[0273] The terminal can obtain Challenge1 from the EAP-Request message, calculate an MD5 value by using Challenge1, the username and the password input by the user, and encapsulate the MD5 value in the EAP-Response message.

[0274] S610. The access device sends an Access-Request message to the authentication server 1 and the authentication server 2, and correspondingly, the authentication server 2 receives the Access-Request message.

[0275] The Access-challenge message is a message of the RADIUS protocol, and the Access-challenge message includes a Client-EAP-Message attribute and a Server-EAP-Message attribute.

[0276] The EAP-Response message in S610 is encapsulated in the Client-EAP-Message attribute, and an EAP message is encapsulated in the Server-EAP-Message attribute, where the EAP message is the EAP message in the Server-EAP-Message attribute recorded by the access device in S606, and the EAP message carries Challenge1.

[0277] Wherein, the authentication server 1 and the authentication server 2 receive the Access-Request message, and each parses the Server-EAP-Message attribute first to obtain the Challenge 1, and covers the locally stored Challenge by using the Challenge 1.

[0278] It can be understood that the updated Challenge of the authentication server 1 is still Challenge 1, and the authentication server 2 updates the locally stored Challenge from Challenge 2 to Challenge 1.

[0279] The authentication server 1 and the authentication server 2 can parse the MD5 value from the Client-EAP-Message attribute, and obtain the password corresponding to the user stored locally, then calculate an MD5 value by using the Challenge 1, the username and the locally stored password, and compare the calculated MD5 value with the MD5 value parsed from the Client-EAP-Message attribute. If they are consistent, it means that the authentication is passed; if they are not consistent, it means that the authentication fails.

[0280] After the authentication server 1 and the authentication server 2 receive the Access-Request message, it is assumed that the authentication server 1 authenticates the user identity information successfully, and the authentication server 2 fails to authenticate the user identity information, then the authentication server 1 executes S611, and the authentication server 2 executes S612.

[0281] S611, the authentication server 1 sends an Access-Accept (Access-Accept) message to the access device, and correspondingly, the access device receives the Access-Accept message.

[0282] Wherein, the Access-Accept message is used to indicate that the access authentication is successful, and the Access-Accept message does not carry the EAP-Message attribute.

[0283] After the access device receives the Access-Accept message, it can record the authentication result of the authentication server 1 as the access authentication success in the server table.

[0284] After S611, S613 is executed.

[0285] S612, the authentication server 2 sends an Access-Reject (Access-Reject) message to the access device, and correspondingly, the access device receives the Access-Reject message.

[0286] Wherein, the Access-reject message is used to indicate that the authentication fails.

[0287] After receiving the Access-reject message, the access device records the authentication result corresponding to the authentication server 2 as access authentication failure in the server table.

[0288] S613, the access device sends an EAP-Success message to the terminal, and correspondingly, the terminal receives the EAP-Success message.

[0289] At this point, the user is successfully online and can access network resources.

[0290] It should be noted that after S610, if the authentication server 1 does not reply within a timeout period, the authentication result corresponding to the authentication server 1 in the server table can be recorded as authentication server unreachable. And receiving the Access-reject message returned by the authentication server 2, the authentication result corresponding to the authentication server 2 in the server table is recorded as access authentication failure.

[0291] In this case, part of the authentication servers are unreachable, part of the authentication servers fail authentication, and the access device does not receive any Access-Accept message returned by the authentication server. Then, whether to allow the user to access network resources can be determined according to a preconfigured policy. For example, if an escape strategy is configured on the access device, an escape process can be triggered to send an EAP-Success message to the terminal, thereby allowing the terminal to access network resources. If no escape strategy is configured, an EAP authentication failure message can be returned to the terminal to deny the user to access network resources.

[0292] Figure 6 Taking an EAP relay processing mechanism based on MD5 as an example, the role of the newly added Server-EAP-Message attribute in the embodiments of the present application is illustrated, and the detailed process of the EAP relay processing mechanism can refer to the standard EAP relay authentication process.

[0293] By using the above method, the access device can use the Server-EAP-Message attribute to carry the challenge parameter generated by one authentication server, so that other authentication servers can also use the challenge parameter carried by the Server-EAP-Message attribute to authenticate the user identity information. Even if the authentication server generating the challenge parameter fails, it will not affect the access authentication process of the terminal, and the problem of terminal online failure caused by server failure can be avoided. Moreover, it will not affect the access authentication speed of the terminal, thereby avoiding the influence of the user's online speed and online result, and improving the user's network access experience.

[0294] As an example, the method provided by the embodiments of the present application is also applicable to a PEAP-MSCHAPv2 authentication mode. In the PEAP-MSCHAPv2 authentication process, the access device can also simultaneously perform authentication procedures with multiple authentication servers, and carry a Server-EAP-Message attribute in an Access-Request message sent to the authentication servers in each round, so as to synchronize authentication information among the multiple authentication servers.

[0295] As shown in Figure 7 , the PEAP-MSCHAPv2 authentication process specifically includes the following steps:

[0296] S701, a user logs in.

[0297] S702, the terminal sends an EAP-Start (EAP start) message to the access device, and correspondingly, the access device receives the EAP-Start message.

[0298] For the introduction of the Start message, reference can be made to the related description in S502 above, which will not be repeated here.

[0299] S703, the access device sends an EAP-Request-Identity (EAP identity request) message to the terminal, and correspondingly, the terminal receives the EAP-Request-Identity message.

[0300] The EAP-Request-Identity message is used to request to obtain the username of the terminal.

[0301] S704, the terminal sends an EAP-Response-Identity (EAP identity reply) message to the access device, and correspondingly, the access device receives the EAP-Response-Identity message.

[0302] For the PEAP-MSCHAPv2 mode, the EAP-Response-Identity message includes an outer username of the terminal, which can not be the real username of the user.

[0303] S705, the access device sends an Access-Request (access request) message to the authentication server 1 and the authentication server 2, and correspondingly, the authentication server 1 and the authentication server 2 receive the Access-Request message.

[0304] The Access-Request message is a message encapsulated by using a RADIUS protocol, and the Access-Request message includes a Client-EAP-Message attribute, and the Client-EAP-Message attribute encapsulates a Response-Identity message.

[0305] In addition, the access device can determine a user entry corresponding to the terminal according to the MAC address of the terminal, and create a server table in the corresponding user entry, where the server table is used to store the authentication result fed back by each authentication server.

[0306] After receiving the Access-Request message, the authentication server 1 and the authentication server 2 can negotiate an authentication mode with the terminal. The specific negotiation mode can refer to the related protocol, and the embodiment of the application does not limit this. Assuming that the default authentication mode configured on the authentication server is PEAP-MSCHAPv2, the authentication server 1 performs S706, and the authentication server 2 performs S707.

[0307] S706, the authentication server 1 sends an Access-challenge message to the access device, and correspondingly, the access device receives the Access-challenge message.

[0308] S707, the authentication server 2 sends an Access-challenge message to the access device, and correspondingly, the access device receives the Access-challenge message.

[0309] The Access-challenge messages sent by the authentication server 1 and the authentication server 2 are both messages encapsulated by using a RADIUS protocol, and the Access-challenge message includes an EAP-Message attribute, and the EAP-Message attribute encapsulates an EAP message, and the EAP message carries a PEAP authentication method.

[0310] The PEAP authentication methods carried in the EAP messages encapsulated by the authentication server 1 and the authentication server 2 are different.

[0311] The access device can perform S708 after receiving the Access-challenge message sent by the first authentication server. That is, the access device can perform S708 after S706.

[0312] S708, the access device sends an EAP-Request message to the terminal. Correspondingly, the terminal receives the EAP-Request message.

[0313] The EAP-Request message can be specifically a Request-EAP-PEAP message, and the Request-EAP-PEAP message is used to notify the terminal of the PEAP authentication method.

[0314] S709, the terminal sends an EAP-Response message to the access device. Correspondingly, the access device receives the EAP-Response message.

[0315] The EAP-Response message can be specifically a Response-TLS-Client-Hello message.

[0316] If the authentication method of the terminal is consistent with the PEAP authentication method announced by the Request-EAP-PEAP message, the terminal sends a Response-TLS-Client-Hello message, and the Response-TLS-Client-Hello message is a response message carrying a TLS ClientHello message, and the message is used to trigger the establishment of a TLS tunnel with the authentication server.

[0317] The TLS-Client-Hello message contains a random number generated by the client.

[0318] S710, the access device sends an Access-Request message to the authentication server 1 and the authentication server 2 respectively.

[0319] The access device receives the Response-TLS-Client-Hello message, encapsulates the message into a Client-EAP-Message attribute, encapsulates the previously recorded Server-EAP-Message attribute into the Access-Request message, and sends the Access-Request message to the authentication server 1 and the authentication server 2.

[0320] The authentication server 1 receives the Access-Request and performs S711, and the authentication server 2 receives the Access-Request and performs S712.

[0321] S711, the authentication server 1 sends an Access-challenge message to the access device. Correspondingly, the access device receives the Access-challenge message.

[0322] The authentication server 1 can parse the TLS Client Hello message encapsulated in the Access-Request message, create a TLS session, encapsulate a Server Hello 1 message, a Server Certificate message and a Server Hello Done message in the EAP-Message attribute of the Access-challenge message, and send to the access device.

[0323] The Server Hello 1 message contains a random number 1 generated by the authentication server 1, and the authentication server 1 records the random number 1 in the TLS session.

[0324] The authentication server 2 sends an Access-challenge message to the access device, and the access device receives the Access-challenge message.

[0325] The authentication server 2 can parse the TLS Client Hello message encapsulated in the Access-Request message, create a TLS session, encapsulate a Server Hello 2 message, a Server Certificate message and a Server Hello Done message in the EAP-Message attribute of the Access-challenge message, and send to the access device.

[0326] The Server Hello 2 message contains a random number 2 generated by the authentication server 2, and the authentication server 2 records the random number 2 in the TLS session.

[0327] The authentication server 1 and the authentication server 2 deploy the same certificate, and encapsulate the same Server Certificate and Server Hello Done message, but the random numbers generated by the authentication server 1 and the authentication server 2 are different, so the Server Hello 1 message and the Server Hello 2 message are different.

[0328] The embodiments of the present application do not limit the execution sequence between S711 and S712, and in the embodiments of the present application, the access device receives the Access-challenge message sent by the authentication server 2 first, and after the access device receives the Access-challenge message sent by the authentication server 2, records the EAP-Message attribute in the Access-challenge message as a Server-EAP-Message2 attribute, and executes S713.

[0329] S713, the access device sends an EAP-Request message to the terminal. Correspondingly, the terminal receives the EAP-Request message.

[0330] The EAP-Request message includes the above-mentioned Server-EAP-Message2 attribute, which contains the Server Hello2 message and the internal random number 2.

[0331] S714, the terminal sends an EAP-Response message to the access device. Correspondingly, the access device receives the EAP-Response message.

[0332] The EAP-Response message includes a TLS Client Key Exchange message, a Change Cipher Spec message and an Encrypted Handshake Message message, so as to perform algorithm and key exchange.

[0333] S715, the access device sends an Access-Request message to the authentication server 1 and the authentication server 2 respectively.

[0334] The Access-Request message includes a Client-EAP-Message attribute and a Server-EAP-Message2 attribute, and the Client-EAP-Message attribute encapsulates the EAP-Response message in S714.

[0335] After receiving the Access-Request message, the authentication server 1 performs S716, and after receiving the Access-Request message, the authentication server 2 performs S717.

[0336] S716, the authentication server 1 sends an Access-challenge message to the access device. Correspondingly, the access device receives the Access-challenge message.

[0337] After receiving the Access-Request message, the authentication server 1 parses the Client-EAP-Message attribute and the Server-EAP-Message2 attribute, encapsulates the Change Cipher Spec message and the Encrypted Handshake Message message into an Access-Challenge message, and sends the Access-Challenge message to the access device.

[0338] Further, the authentication server 1 compares the random number 1 recorded in the local TLS session with the random number 2 in the Server Hello2 message in the Server-EAP-Message2 attribute, and replaces the random number 1 recorded in the local TLS session with the random number 2.

[0339] The terminal and each authentication server generate a symmetric key and a message authentication code in the handshake message by using the random number in the TLS Client Hello message and the random number 2 in the Server Hello2 message. The authentication server 1 and the authentication server 2 use the same random number 2, can simultaneously establish a TLS tunnel with the terminal, and make the terminal unaware of the existence of the two authentication servers.

[0340] S717. The authentication server 2 sends an Access-challenge message to the access device. Correspondingly, the access device receives the Access-challenge message.

[0341] After receiving the Access-Request message, the authentication server 2 parses the Client-EAP-Message attribute and the Server-EAP-Message2 attribute, encapsulates the Change Cipher Spec message and the Encrypted Handshake Message message into an Access-Challenge message, and sends the Access-Challenge message to the access device.

[0342] Further, the authentication server 2 compares the random number 2 recorded in the local TLS session with the random number 2 in the Server Hello2 message in the Server-EAP-Message2 attribute, and does not replace the random number 2.

[0343] The embodiments of the present application do not limit the execution sequence between S716 and S717. After S715, after the access device receives the first Access-challenge message, the access device records the EAP-Message attribute in the Access-challenge message as a Server-EAP-Message3 attribute, and executes S718.

[0344] S718, the access device sends an EAP-Request message to the terminal. Correspondingly, the terminal receives the EAP-Request message.

[0345] The EAP-Request message includes the Server-EAP-Message3 attribute mentioned above.

[0346] S719, the terminal sends an EAP-Response message to the access device. Correspondingly, the access device receives the EAP-Response message.

[0347] The EAP-Response message is an EAP-PEAP response message, and the establishment of the TLS tunnel in the first phase of PEAP authentication is completed. The second phase of MSCHAPv2 authentication is started subsequently.

[0348] S720, the access device sends an Access-Request message to the authentication server 1 and the authentication server 2 respectively.

[0349] The Access-Request message carries the Client-EAP-Message attribute and the Server-EAP-Message3. The EAP-Response message in S719 is encapsulated in the Client-EAP-Message attribute.

[0350] After receiving the Access-Request message, the authentication server 1 performs S721, and the authentication server performs S722 after receiving the Access-Request message.

[0351] S721, the authentication server 1 sends an Access-challenge message to the access device. Correspondingly, the access device receives the Access-challenge message.

[0352] Assuming that the authentication server 1 is running normally, the authentication server 1 can encapsulate the Access-Challenge message and send it to the access device. The access device can record the EAP-Message attribute carried in the Access-Challenge message as the Server-EAP-Message4 attribute, and perform S723.

[0353] S722, the authentication server 2 sends an Access-Reject message to the access device. Correspondingly, the access device receives the Access-Reject message.

[0354] Suppose the authentication server 2 internal component fails at this time, and the terminal authentication is rejected, then an Access-Reject message is encapsulated and sent to the access device.

[0355] It should be noted that in the entire authentication process, authentication server failure may occur at each link, resulting in the authentication server sending an Access-Reject message to the access device. In this process, the authentication server 2 failure in the second stage MSCHAPv2 authentication process is taken as an example.

[0356] S723, the access device terminal sends an EAP-Request message. Correspondingly, the terminal receives the EAP-Request message.

[0357] The EAP-Request message encapsulates a Server-EAP-Message4 attribute, which carries a user identity request message encrypted by TLS.

[0358] After receiving the Access-Reject message from the authentication server 2, the access device records the authentication result of the authentication server 2 as authentication failure, and will not send an Access-Request message to the authentication server 2 in the future.

[0359] S724, the terminal sends an EAP-Response message to the access device. Correspondingly, the access device receives the EAP-Response message.

[0360] The EAP-Response message carries the user identity information encrypted by TLS, i.e. the inner username (real username).

[0361] S725, the access device sends an Access-Request message to the authentication server 1. Correspondingly, the authentication server 1 receives the Access-Request message.

[0362] The Access-Request message carries a Client-EAP-Message attribute and a Server-EAP-Message4 attribute. The Client-EAP-Message attribute encapsulates the EAP-Response message in S724.

[0363] S726, the authentication server 1 sends an Access-challenge message to the access device. Correspondingly, the access device receives the Access-challenge message.

[0364] The authentication server 1 parses the Client-EAP-Message attribute and the Server-EAP-Message4 attribute, and since the authentication information in the subsequent Server-EAP-Message4 attribute is the same as the authentication information recorded locally by the authentication server 1, the subsequent Server-EAP-Message4 attribute will not be replaced.

[0365] The Access-Challenge message contains authentication sub-method negotiation information encrypted by TLS, for example, the authentication sub-method negotiation information is MS-CHAPv2.

[0366] S727, the access device sends an EAP-Request message to the terminal. Correspondingly, the terminal receives the EAP-Request message.

[0367] The EAP-Request message carries authentication sub-method negotiation information encrypted by TLS.

[0368] S728, the terminal sends an EAP-Response message to the access device. Correspondingly, the access device receives the EAP-Response message.

[0369] After receiving the authentication sub-method negotiation information, if the terminal confirms that the authentication sub-method can be used, the terminal replies with an EAP-Response message indicating that the authentication sub-method can be used.

[0370] S729, the access device sends an Access-Request message to the authentication server 1. Correspondingly, the authentication server 1 receives the Access-Request message.

[0371] S730, the authentication server 1 sends an Access-Challenge message to the access device. Correspondingly, the access device receives the Access-Challenge message.

[0372] The authentication server 1 can generate and record MS-CHAPv2 Challenge information and encapsulate it into the Access-Challenge message.

[0373] It can be understood that if the authentication server 2 does not fail in the above process, the access device needs to record the EAP-EAP-Message attribute in the Access-Challenge message as a Server-EAP-Message attribute, so as to synchronize the Server-EAP-Message attribute to the authentication server 2 subsequently.

[0374] S731, the access device sends an EAP-Request message to the terminal. Correspondingly, the terminal receives the EAP-Request message.

[0375] The EAP-Request message carries MS-CHAPv2 Challenge information encrypted by TLS.

[0376] S732, the terminal sends an EAP-Response message to the access device. Correspondingly, the access device receives the EAP-Response message.

[0377] After the terminal parses the MS-CHAPv2 Challenge, it randomly generates Peer-Challenge, and generates NT-Reponse1 information using its own username, password, MS-CHAPv2 Challenge and Peer-Challenge. The Peer-Challenge and NT-Reponse1 information are encrypted by TLS and encapsulated into the EAP-Response message, and sent to the access device.

[0378] S733, the access device sends an Access-Request message to the authentication server 1. Correspondingly, the authentication server 1 receives the Access-Request message.

[0379] S734, the authentication server 1 sends an Access-Challenge message to the access device. Correspondingly, the access device receives the Access-Challenge message.

[0380] The authentication server 1 parses the Peer-Challenge and NT-Reponse1 information, generates NT-Reponse2 information using its own recorded MS-CHAPv2 Challenge and username, password, and parsed Peer-Challenge information. Then it compares NT-Reponse1 and NT-Reponse2, and if they are consistent, it determines that the user authentication is successful. Then it generates Auth-String1 information according to the username, password, MS-CHAPv2 Challenge, Peer-Challenge and NT-Reponse2, and encapsulates the Auth-String1 information in the Access-Challenge message.

[0381] S735, the access device sends an EAP-Request message to the terminal. Correspondingly, the terminal receives the EAP-Request message. The EAP-Request message carries Auth-String1 information.

[0382] S736, the terminal sends an EAP-Response message to the access device. Correspondingly, the access device receives the EAP-Response message.

[0383] The terminal generates Auth-String2 by using the NT-Response1, the username, the password, the MS-CHAPv2 Challenge, and the Peer-Challenge recorded by itself by using the same method, and compares Auth-String2 with Auth-String1 parsed out, and if they are consistent, the terminal passes the verification of the authentication server 1.

[0384] The EAP-Response message carries Auth-String2.

[0385] S737, the access device sends an Access-Request message to the authentication server 1. Correspondingly, the authentication server 1 receives the Access-Request message.

[0386] The Access-Request message includes a Client-EAP-Message attribute, and the Client-EAP-Message attribute carries the EAP-Response message in S736.

[0387] S738, the authentication server 1 sends an Access-Accept message to the access device. Correspondingly, the access device receives the Access-Accept message.

[0388] The authentication server 1 can parse Auth-String2 from the Access-Request message, compare Auth-String2 with Auth-String1 recorded, and if they are consistent, determine that the user passes the authentication, and reply with the Access-Accept message.

[0389] After receiving the Access-Accept message, the access device records the authentication result of the authentication server 1 as authentication success.

[0390] S739, the access device sends an EAP-Success message to the terminal. Correspondingly, the terminal receives the EAP-Success message.

[0391] And the access device passes terminal traffic and allows the terminal to access network resources.

[0392] It should be noted that the embodiments of the present application are not limited to the EAP authentication process based on 802.1X, and the method provided by the embodiments of the present application is also applicable to the EAP relay authentication process of Web / portal users based on Http / Https.

[0393] It should be noted that in the process of Figure 6 and Figure 7 If the authentication server also generates private data for verifying the access device, the authentication server can encapsulate a standard Radius attribute in the Access-challenge message.

[0394] The attribute name of the standard Radius attribute can be State attribute, the attribute number can be 24, the data type is octets, and the value of the State attribute is the private data described above.

[0395] The access device can record the State attribute value carried by the Access-challenge message sent by each authentication server, and the access device also encapsulates the standard Radius attribute in the message sent to each authentication server subsequently, and carries the State attribute value of the authentication server, so that the authentication server verifies whether the access device is legal based on the State attribute, prevents fake access devices from performing illegal authentication, and improves network security.

[0396] In another embodiment of the present application, if the Server-EAP-Message attribute is not used to synchronize authentication parameters, an EAP termination processing mechanism can be used instead of the EAP relay processing mechanism, so that only one interaction is required between the access device and the authentication server. In this way, there is no problem of switching authentication servers in the access authentication process, and the problem of access authentication failure due to the fact that the authentication parameters are not synchronized in time after switching the authentication server can also be avoided.

[0397] The implementation of using the EAP termination processing mechanism instead of the EAP relay processing mechanism is described in detail below.

[0398] Based on Figure 7 , the EAP relay processing mechanism can be changed to the EAP termination processing mechanism, so that the access device does not need to use the Server-EAP-Message attribute to synchronize authentication parameters. As shown in Figure 8 , the specific steps include the following steps:

[0399] S801, the user logs in.

[0400] S802, the terminal sends an EAP-Start message to the access device, and correspondingly, the access device receives the EAP-Start message.

[0401] S803, the access device sends an EAP-Request-Identity message to the terminal, and correspondingly, the terminal receives the EAP-Request-Identity message.

[0402] S804, the terminal sends an EAP-Response-Identity message to the access device, and correspondingly, the access device receives the EAP-Response-Identity message.

[0403] In S805-S816, the messages sent by the access device to the terminal are all EAP-Request messages, and the messages sent by the terminal to the access device are all EAP-Response messages.

[0404] In S805, the EAP-Request message is specifically a Request-EAP-PEAP message, which is used to notify the terminal of the PEAP authentication method.

[0405] In S806, the EAP-Response message is specifically a Response-TLS-Client-Hello message. If the authentication method of the terminal is consistent with the PEAP authentication method notified by the Request-EAP-PEAP message, the terminal replies to the Response-TLS-Client-Hello message. The Response-TLS-Client-Hello message is used to trigger the negotiation of establishing a TLS tunnel with the authentication server, and carries the random number information generated by the client.

[0406] After the access device receives the Response-TLS-Client-Hello message, the access device parses the TLS Client Hello message encapsulated in the Access-Request message, creates a TLS session, and generates a random number 1, which is recorded in the TLS session information.

[0407] In S807, the EAP-Request message includes a Server Hello message, a Server Certificate message and a Server Hello Done message. The Server Hello message includes the random number 1.

[0408] In S808, the EAP-Response message includes a TLS Client Key Exchange message, a Change Cipher Spec message and an Encrypted Handshake Message message, so as to perform algorithm and key exchange with the access device.

[0409] In S809, the EAP-Request message includes a Change Cipher Spec message and an Encrypted Handshake Message message.

[0410] In S810, the EAP-Response message is an EAP-PEAP response message, and thus the TLS tunnel between the terminal and the access device is established in the first phase of PEAP authentication. The second phase of MSCHAPv2 authentication is started subsequently.

[0411] In S811, the EAP-Request message carries a user identity request message encrypted by TLS.

[0412] In S812, the EAP-Response message carries user identity information encrypted by TLS, i.e. inner username (real username).

[0413] In S813, the EAP-Request message carries authentication sub-method negotiation information encrypted by TLS, for example, the authentication sub-method negotiation information is MS-CHAPv2.

[0414] In S814, the EAP-Response message is used to indicate that the terminal can use the authentication sub-method in S813.

[0415] In S815, the EAP-Request message carries MS-CHAPv2-Challenge information encrypted by TLS.

[0416] In S816, the EAP-Response message carries Peer-Challenge and NT-Response1 information encrypted by TLS. The Peer-Challenge is randomly generated by the terminal, and the NT-Response1 information is generated by the terminal based on the username, password, MS-CHAPv2-Challenge and Peer-Challenge.

[0417] After the access device acquires the Peer-Challenge and NT-Reponse1 information, it encapsulates an EAP-Request message. The EAP-Request message encapsulates two radius attributes, MS-CHAP-Challenge attribute and MS-CHAP2-Response attribute. The MS-CHAP-Challenge attribute encapsulates the MS-CHAPv2-Challenge, and the MS-CHAP2-Response attribute encapsulates the Peer-Challenge and NT-Reponse1 information. Compared with the flow of Figure 7 , the flow of Figure 8 does not need to extend the EAP-Message attribute in the Access-Request message. Then the access device performs S817 and S818 respectively.

[0418] S817, the access device sends an Access-Request message to the authentication server 1, and the authentication server 1 receives the Access-Request message.

[0419] The authentication server 1 analyzes the Peer-Challenge and NT-Reponse1 information, and then compares the NT-Reponse1 with the NT-Reponse2 generated by itself. If they are consistent, it is determined that the user authentication is successful. Then, according to the username, password, MS-CHAPv2-Challenge, Peer-Challenge and NT-Reponse2, the authentication server 1 generates Auth-String1 information, encapsulates the Auth-String1 information in an Access-Challenge message, and then performs S820.

[0420] S818, the access device sends an Access-Request message to the authentication server 2, and the authentication server 2 receives the Access-Request message.

[0421] Suppose that the internal components of the authentication server 2 fail at this time, and the terminal authentication is rejected, then an Access-Reject message is encapsulated, and S819 is performed.

[0422] S819, the authentication server 2 sends an Access-Reject message to the access device. Correspondingly, the access device receives the Access-Reject message.

[0423] S820, the authentication server 1 sends an Access-Accept message to the access device. Correspondingly, the access device receives the Access-Accept message.

[0424] S821, the access device sends an EAP-Request message to the terminal. Correspondingly, the terminal receives the EAP-Request message. The EAP-Request message carries the Auth-String1 information.

[0425] S822, the terminal sends an EAP-Response message to the access device. Correspondingly, the access device receives the EAP-Response message.

[0426] The terminal generates Auth-String2 by using the NT-Response1, the username, the password, the MS-CHAPv2 Challenge, and the Peer-Challenge recorded by itself by using the same method, and compares the Auth-String2 with the parsed Auth-String1. If the Auth-String2 is consistent with the Auth-String1, the terminal passes the verification of the authentication server 1.

[0427] The Access-Request message carries the Auth-String2. The access device parses the Auth-String2 from the Access-Request message, compares the Auth-String2 with the recorded Auth-String1, and determines that the user passes the authentication if the Auth-String2 is consistent with the Auth-String1.

[0428] S823, the access device sends an EAP-Success message to the terminal. Correspondingly, the terminal receives the EAP-Success message.

[0429] In addition, the access device releases the terminal traffic and allows the terminal to access network resources.

[0430] By using the above method, the access device can replace the authentication server to establish a TLS tunnel with the terminal. In the authentication process, the access device and the authentication server only need to interact once, so the method does not involve different authentication servers with multiple interactions, does not need to synchronize the authentication parameters between the authentication servers, and can avoid the problem of terminal online failure caused by server failure.

[0431] It should be noted that, Figure 7 and Figure 8 The processes of the above two embodiments are two exemplary processes provided by the embodiments of the present application. Figure 7 In the process of the authentication server, the synchronization of the authentication parameters between the authentication servers is achieved by adding the Server-EAP-Message attribute. Figure 8The access device replaces the authentication server to establish a TLS tunnel with the terminal, thereby avoiding multiple interactions between the access device and the authentication server.

[0432] In Figure 7 and Figure 8 , after the authentication server, the access device and the terminal obtain the information for authentication, the specific authentication mode can refer to the provisions of the PEAP-MSCHAPv2 related protocol, and the embodiments of the application do not limit this.

[0433] Based on the same idea, the embodiments of the application provide a terminal authentication device, as shown in Figure 9 , the device is applied to an access device, and the device comprises:

[0434] The sending module 901 is configured to send a first message to each of the plurality of authentication servers, and the first message is used to request the authentication server to perform access authentication on the terminal.

[0435] The receiving module 902 is configured to trigger the sending module 901 to send a third message to the terminal if the second message sent by any one of the authentication servers is received and the second message is the first second message sent by the plurality of authentication servers after receiving the first message, and the second message and the third message are both used to indicate that the terminal access authentication is successful.

[0436] Optionally, the receiving module 902 is further configured to trigger the sending module 901 to send a fifth message to the terminal if the fourth message sent by any one of the authentication servers is received and the fourth message is the first fourth message sent by the plurality of authentication servers after receiving the first message, and the fifth message comprises authentication parameters, and the authentication parameters are carried by an EAP message included in the fourth message.

[0437] The receiving module 902 is further configured to receive a sixth message sent by the terminal, and the sixth message comprises user identity information, and the user identity information is encrypted by the authentication parameters.

[0438] The sending module 901 is further configured to send a seventh message to each of the authentication servers, and the seventh message comprises the sixth message and an EAP message, so that the authentication server verifies the user identity information based on the authentication parameters.

[0439] Optionally, the device further comprises a recording module:

[0440] The receiving module 902 is further configured to trigger the recording module to record the authentication result of each server on the terminal as access authentication failure if the same number of eighth messages as the number of the plurality of authentication servers is received within a first preset time length, and the authentication result carried by each eighth message indicates that the terminal access authentication fails.

[0441] The sending module 901 is further configured to send a ninth message to the terminal, where the ninth message is used to indicate that the terminal access authentication fails.

[0442] Optionally, the recording module is further configured to, if no message sent by any authentication server is received after the first preset time length is reached, record an authentication result of each server for the terminal as the authentication server being unreachable.

[0443] The sending module 901 is further configured to send a ninth message to the terminal, where the ninth message is used to indicate that the terminal access authentication fails.

[0444] Optionally, the receiving module 902 is further configured to, if the first number of eighth messages sent by the authentication servers are received within the first preset time length, and the authentication result carried in each eighth message indicates that the terminal access authentication fails, trigger the recording module to record the authentication result of the first number of authentication servers for the terminal as the access authentication failing.

[0445] The recording module is further configured to, if no message sent by the second number of authentication servers in the multiple authentication servers is received after the first preset time length is reached, record the authentication result of the second number of authentication servers for the terminal as the authentication server being unreachable.

[0446] The sending module 901 is further configured to send a ninth message or a tenth message to the terminal, where the ninth message is used to indicate that the terminal access authentication fails, the tenth message is used to indicate that the terminal access authentication succeeds, and the sum of the first number and the second number is equal to the number of the multiple authentication servers.

[0447] Optionally, the receiving module 902 is further configured to, if the same number of eighth messages as the number of the multiple authentication servers are received within the second preset time length, and the authentication result carried in each eighth message indicates that the terminal access authentication fails, trigger the recording module to record the authentication result of each server for the terminal as the access authentication failing.

[0448] The sending module 901 is further configured to send a ninth message to the terminal, where the ninth message is used to indicate that the terminal access authentication fails.

[0449] Optionally, the recording module is further configured to, if no message sent by any authentication server is received after the second preset time length is reached, record the authentication result of each server for the terminal as the authentication server being unreachable.

[0450] The sending module 901 is further configured to send a ninth message to the terminal, where the ninth message is used to indicate that the terminal access authentication fails.

[0451] Optionally, the receiving module 902 is further configured to trigger the recording module to record the authentication results of the third number of authentication servers on the terminal as access authentication failure respectively, if the eighth messages sent by the third number of authentication servers are received within the second preset time length, and the authentication results carried in each of the eighth messages indicate that the terminal access authentication fails.

[0452] The recording module is further configured to record the authentication results of the fourth number of authentication servers on the terminal as authentication server unreachable respectively, if no message sent by the fourth number of authentication servers in the plurality of servers is received after the second preset time length is reached.

[0453] The sending module 901 is further configured to send a ninth message or a tenth message to the terminal, the ninth message is used to indicate that the terminal access authentication fails, the tenth message is used to indicate that the terminal access authentication succeeds, and the sum of the third number and the fourth number is equal to the number of the plurality of authentication servers.

[0454] Optionally, the seventh message includes an EAP message attribute, and the EAP message attribute is used to carry the EAP message.

[0455] Optionally, the length of the EAP message attribute is a preset length.

[0456] If the length of the EAP message is greater than the preset length, the seventh message includes a plurality of EAP message attributes, and the EAP message is carried in the plurality of EAP message attributes in a fragmented form.

[0457] Optionally, the access device is connected with a plurality of groups of authentication servers.

[0458] The sending module 901 is further configured to select a group of authentication servers from the plurality of groups of authentication servers in a load sharing manner, and send the first message to the selected group of authentication servers; or

[0459] The sending module 901 is further configured to select a preset number of authentication servers from each group of authentication servers included in the plurality of groups of authentication servers in a load sharing manner respectively, and send the first message to the selected authentication servers.

[0460] Based on the same concept, the embodiment of the present application further provides an access device, as shown in the following figure: Figure 10 The access device includes:

[0461] a processor 1001;

[0462] a transceiver 1004;

[0463] a machine readable storage medium 1002, the machine readable storage medium 1002 stores machine executable instructions which can be executed by the processor 1001; the machine executable instructions cause the processor 1001 to execute the following steps:

[0464] The transceiver 1004 sends a first message to each of the plurality of authentication servers respectively, and the first message is used to request the authentication servers to perform access authentication on the terminal.

[0465] If the transceiver 1004 receives a second message sent by any one of the authentication servers, and the second message is the first second message sent by the plurality of authentication servers after receiving the first message, the transceiver 1004 sends a third message to the terminal, and the second message and the third message are both used to indicate that the terminal passes the access authentication.

[0466] Optionally, the machine-executable instructions further cause the processor 1001 to perform the following steps:

[0467] If the transceiver 1004 receives a fourth message sent by any one of the authentication servers, and the fourth message is the first fourth message sent by the plurality of authentication servers after receiving the first message, the transceiver 1004 sends a fifth message to the terminal, and the fifth message includes authentication parameters carried by the EAP message included in the fourth message.

[0468] The transceiver 1004 receives a sixth message sent by the terminal, and the sixth message includes user identity information encrypted by the authentication parameters.

[0469] The transceiver 1004 sends a seventh message to each of the authentication servers respectively, and the seventh message includes the sixth message and an EAP message, so that the authentication servers verify the user identity information based on the authentication parameters.

[0470] Optionally, the machine-executable instructions further cause the processor 1001 to perform the following steps:

[0471] If the transceiver 1004 receives the same number of eighth messages as the number of the authentication servers within a first preset time period, and each of the eighth messages carries an authentication result indicating that the terminal fails in the access authentication, it is recorded that each of the servers fails in the access authentication on the terminal.

[0472] The transceiver 1004 sends a ninth message to the terminal, and the ninth message is used to indicate that the terminal fails in the access authentication.

[0473] Optionally, the machine-executable instructions further cause the processor 1001 to perform the following steps:

[0474] After the first preset time period is reached, if no message sent by any one of the authentication servers is received, it is recorded that each of the servers is unreachable.

[0475] The transceiver 1004 sends a ninth message to the terminal, and the ninth message is used to indicate that the terminal fails in the access authentication.

[0476] Optionally, the machine executable instructions further cause the processor 1001 to perform the following steps:

[0477] If the first number of authentication servers send the eighth message to the terminal through the transceiver 1004 within the first preset time length, and the authentication result carried by each eighth message indicates that the terminal access authentication fails, then the authentication result of each of the first number of authentication servers to the terminal is recorded as access authentication failure.

[0478] After the first preset time length is reached, if no message sent by the second number of authentication servers in the plurality of servers is received, then the authentication result of each of the second number of authentication servers to the terminal is recorded as authentication server unreachable.

[0479] The ninth message or the tenth message is sent to the terminal through the transceiver 1004, the ninth message is used to indicate that the terminal access authentication fails, the tenth message is used to indicate that the terminal access authentication succeeds, and the sum of the first number and the second number is equal to the number of the plurality of authentication servers.

[0480] Optionally, the machine executable instructions further cause the processor 1001 to perform the following steps:

[0481] If the same number of eighth messages as the number of the plurality of authentication servers is received through the transceiver 1004 within the second preset time length, and the authentication result carried by each eighth message indicates that the terminal access authentication fails, then the authentication result of each of the servers to the terminal is recorded as access authentication failure.

[0482] The ninth message is sent to the terminal through the transceiver 1004, the ninth message is used to indicate that the terminal access authentication fails.

[0483] Optionally, the machine executable instructions further cause the processor 1001 to perform the following steps:

[0484] After the second preset time length is reached, if no message sent by any authentication server is received, then the authentication result of each of the servers to the terminal is recorded as authentication server unreachable.

[0485] The ninth message is sent to the terminal through the transceiver 1004, the ninth message is used to indicate that the terminal access authentication fails.

[0486] Optionally, the machine executable instructions further cause the processor 1001 to perform the following steps:

[0487] If the third number of authentication servers send the eighth message to the terminal through the transceiver 1004 within the second preset time length, and the authentication result carried by each eighth message indicates that the terminal access authentication fails, then the authentication result of each of the third number of authentication servers to the terminal is recorded as access authentication failure.

[0488] If the fourth number of authentication servers in the plurality of servers do not send the message to the terminal after the second preset time length, the authentication results of the fourth number of authentication servers on the terminal are recorded as the authentication servers being unreachable.

[0489] The ninth message or the tenth message is sent to the terminal through the transceiver 1004, the ninth message is used to indicate that the terminal access authentication fails, the tenth message is used to indicate that the terminal access authentication succeeds, and the sum of the third number and the fourth number is equal to the number of the plurality of authentication servers.

[0490] Optionally, the seventh message includes an EAP message attribute, and the EAP message attribute is used to carry the EAP message.

[0491] Optionally, the length of the EAP message attribute is a preset length.

[0492] If the length of the EAP message is greater than the preset length, the seventh message includes a plurality of EAP message attributes, and the EAP message is carried in the plurality of EAP message attributes in a fragmentation form.

[0493] Optionally, the access device is connected with a plurality of groups of authentication servers; and the machine-executable instructions cause the processor 1001 to perform the following steps:

[0494] selecting one group of authentication servers from the plurality of groups of authentication servers in a load sharing manner, and sending the first message to the selected group of authentication servers through the transceiver 1004; or

[0495] selecting a preset number of authentication servers from each group of authentication servers included in the plurality of groups of authentication servers in a load sharing manner, and sending the first message to the selected authentication servers through the transceiver 1004.

[0496] In the Figure 10 , a communication bus 1003 can also be included. The processor 1001, the machine-readable storage medium 1002, and the transceiver 1004 can communicate with each other through the communication bus 1003. The communication bus 1003 can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The communication bus can be divided into an address bus, a data bus, a control bus, etc.

[0497] The transceiver 1004 can be a wireless communication module, and the transceiver 1004 communicates data with other devices under the control of the processor 1001.

[0498] The machine readable storage medium 1002 can include a random access memory (RAM), and can also include a non-volatile memory (NVM), e.g., at least one disk storage. Additionally, the machine readable storage medium can be at least one storage apparatus that is remotely located from the aforementioned processor(s).

[0499] The processor 1001 can be a general processor, including a central processing unit (CPU), a network processor (NP), etc.; can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic component, a discrete hardware component.

[0500] Based on the same inventive concept, according to the terminal authentication method provided by the embodiments of the present application, the embodiments of the present application further provide a machine readable storage medium, which stores machine executable instructions capable of being executed by a processor. The processor is prompted by the machine executable instructions to implement the steps of the terminal authentication method.

[0501] In yet another embodiment provided by the present application, a computer program product containing instructions is provided, which, when running on a computer, causes the computer to perform the steps of the terminal authentication method in the above embodiments.

[0502] It should be noted that, in this document, the relationship terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply that there is any such actual relationship or order between these entities or operations. Moreover, the terms "include", "contain" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or device. Without more limitations, the element defined by the statement "including a" does not exclude the presence of other identical elements in the process, method, article or device including the element.

[0503] The various embodiments in the specification are described in a related manner, and the same or similar parts between the various embodiments can be referred to each other. Each embodiment focuses on the difference from other embodiments. In particular, for the device embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the part of the method embodiments.

[0504] The above description is merely the preferred embodiment of the present application, and is not intended to limit the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. A terminal authentication method, characterized in that, The method is applied to an access device, and the method includes: Send a first message to each of the multiple authentication servers. The first message is used to request the authentication server to perform access authentication for the terminal. If a second message is received from any authentication server and the second message is the first second message sent by the multiple authentication servers after receiving the first message, then a third message is sent to the terminal. Both the second message and the third message are used to indicate that the terminal has successfully accessed authentication. After sending the first message to multiple authentication servers, the method further includes: If a fourth message is received from any authentication server and the fourth message is the first fourth message sent by the multiple authentication servers after receiving the first message, then a fifth message is sent to the terminal. The fifth message includes authentication parameters, which are carried by the EAP message included in the fourth message. The terminal sends a sixth message, which includes user identity information and is encrypted using the authentication parameters. A seventh message is sent to each of the authentication servers, the seventh message including the sixth message and the EAP message, so that the authentication server verifies the user identity information based on the authentication parameters, and updates the locally stored authentication parameters to the authentication parameters when the authentication parameters stored locally are different from the authentication parameters. The seventh message includes EAP message attributes, which are used to carry the EAP message.

2. The method according to claim 1, characterized in that, After sending the first message to multiple authentication servers, the method further includes: If, within a first preset time period, the same number of eighth messages as those received by the multiple authentication servers are received, and each eighth message carries an authentication result indicating that the terminal access authentication has failed, then the authentication result of each server for the terminal is recorded as access authentication failure. A ninth message is sent to the terminal, which indicates that the terminal's access authentication has failed.

3. The method according to claim 1, characterized in that, After sending the first message to multiple authentication servers, the method further includes: If no message is received from any authentication server after the first preset time period, the authentication result of each server for the terminal is recorded as authentication server unreachable. A ninth message is sent to the terminal, which indicates that the terminal's access authentication has failed.

4. The method according to claim 1, characterized in that, After sending the first message to multiple authentication servers, the method further includes: If, within a first preset time period, an eighth message is received from a first number of authentication servers, and each eighth message carries an authentication result indicating that the terminal access authentication has failed, then the authentication result of the first number of authentication servers for the terminal is recorded as access authentication failure. If no message is received from the second number of authentication servers among the multiple servers after the first preset time period has elapsed, then the authentication results of the second number of authentication servers for the terminal are recorded as authentication server unreachable. A ninth message is sent to the terminal, or, if an escape strategy has been configured, a tenth message is sent to the terminal. The ninth message indicates that the terminal access authentication has failed, and the tenth message indicates that the terminal access authentication has succeeded. The sum of the first number and the second number is the same as the number of the multiple authentication servers.

5. The method according to claim 1, characterized in that, After sending the first message to multiple authentication servers, the method further includes: If, within the second preset time period, the same number of eighth messages as those received by the multiple authentication servers are received, and each eighth message carries an authentication result indicating that the terminal access authentication has failed, then the authentication result of each server for the terminal is recorded as access authentication failure. A ninth message is sent to the terminal, which indicates that the terminal's access authentication has failed.

6. The method according to claim 1, characterized in that, After sending the first message to multiple authentication servers, the method further includes: If no message is received from any authentication server after the second preset time period, the authentication result of each server for the terminal is recorded as authentication server unreachable. A ninth message is sent to the terminal, which indicates that the terminal's access authentication has failed.

7. The method according to claim 1, characterized in that, After sending the first message to multiple authentication servers, the method further includes: If, within the second preset time period, an eighth message is received from a third number of authentication servers, and each eighth message carries an authentication result indicating that the terminal access authentication has failed, then the authentication result of the third number of authentication servers for the terminal is recorded as access authentication failure. If no message is received from the fourth number of authentication servers among the multiple servers after the second preset time period has elapsed, the authentication result of the fourth number of authentication servers for the terminal is recorded as access authentication failure. A ninth message is sent to the terminal, or, if an escape strategy has been configured, a tenth message is sent to the terminal. The ninth message indicates that the terminal access authentication has failed, and the tenth message indicates that the terminal access authentication has succeeded. The sum of the third and fourth quantities is the same as the number of the multiple authentication servers.

8. The method according to claim 1, characterized in that, The length of the EAP message attributes is a preset length; If the length of the EAP message is greater than the preset length, the seventh message includes multiple EAP message attributes, and the EAP message is carried in fragments within the multiple EAP message attributes.

9. The method according to claim 1, characterized in that, The access device is connected to multiple authentication servers; Send a first message to the plurality of authentication servers, including: Select one group of authentication servers from the multiple groups of authentication servers in a load-sharing manner, and send the first message to the selected group of authentication servers; or, A preset number of authentication servers are selected from each of the multiple authentication servers in a load-sharing manner, and the first message is sent to the selected authentication servers.

10. A terminal authentication device, characterized in that, The device is used in an access device, and the device includes: The sending module is used to send a first message to each of the multiple authentication servers, wherein the first message is used to request the authentication server to perform access authentication for the terminal. The receiving module is configured to trigger the sending module to send a third message to the terminal if it receives a second message sent by any authentication server and the second message is the first second message sent by the multiple authentication servers after receiving the first message. Both the second message and the third message are used to indicate that the terminal has successfully accessed authentication. The receiving module is further configured to, if it receives a fourth message sent by any authentication server and the fourth message is the first fourth message sent by the multiple authentication servers after receiving the first message, trigger the sending module to send a fifth message to the terminal. The fifth message includes authentication parameters, which are carried by the EAP message included in the fourth message. The receiving module is further configured to receive a sixth message sent by the terminal, the sixth message including user identity information, the user identity information being encrypted using the authentication parameters; The sending module is further configured to send a seventh message to each authentication server, the seventh message including the sixth message and the EAP message, so that the authentication server verifies the user identity information based on the authentication parameters, and updates the locally stored authentication parameters to the authentication parameters when the authentication parameters stored locally are different from the authentication parameters. The seventh message includes EAP message attributes, which are used to carry the EAP message.

11. The apparatus according to claim 10, characterized in that, The device also includes a recording module: The receiving module is further configured to, if within a first preset time period, it receives the same number of eighth messages as the plurality of authentication servers, and each eighth message carries an authentication result indicating that the terminal access authentication has failed, then trigger the recording module to record the authentication result of each server for the terminal as access authentication failure. The sending module is further configured to send a ninth message to the terminal, the ninth message being used to indicate that the terminal access authentication failed.

12. The apparatus according to claim 11, characterized in that, The recording module is also used to record the authentication result of each server for the terminal as unreachable if no message is received from any authentication server after the first preset time period has elapsed. The sending module is further configured to send a ninth message to the terminal, the ninth message being used to indicate that the terminal access authentication failed.

13. The apparatus according to claim 11, characterized in that, The receiving module is further configured to, if within a first preset time period, it receives an eighth message sent by a first number of authentication servers, and each eighth message carries an authentication result indicating that the terminal access authentication has failed, trigger the recording module to record that the authentication result of the first number of authentication servers for the terminal is an access authentication failure. The recording module is further configured to, after the first preset time period has elapsed, if no message is received from the second number of authentication servers among the multiple servers, record the authentication result of the second number of authentication servers for the terminal as authentication server unreachable. The sending module is further configured to send a ninth message to the terminal, or, when an escape strategy has been configured, to send a tenth message to the terminal. The ninth message indicates that the terminal access authentication has failed, and the tenth message indicates that the terminal access authentication has succeeded. The sum of the first quantity and the second quantity is the same as the number of the multiple authentication servers.

14. The apparatus according to claim 11, characterized in that, The receiving module is further configured to, if within a second preset time period, it receives the same number of eighth messages as the plurality of authentication servers, and each eighth message carries an authentication result indicating that the terminal access authentication has failed, then trigger the recording module to record the authentication result of each server for the terminal as access authentication failure. The sending module is further configured to send a ninth message to the terminal, the ninth message being used to indicate that the terminal access authentication failed.

15. The apparatus according to claim 11, characterized in that, The recording module is also used to record the authentication result of each server for the terminal as "authentication server unreachable" if no message is received from any authentication server after the second preset time period has elapsed. The sending module is further configured to send a ninth message to the terminal, the ninth message being used to indicate that the terminal access authentication failed.

16. The apparatus according to claim 11, characterized in that, The receiving module is further configured to, if within a second preset time period, it receives an eighth message sent by a third number of authentication servers, and each eighth message carries an authentication result indicating that the terminal access authentication has failed, then trigger the recording module to record the authentication result of the third number of authentication servers for the terminal as access authentication failure. The recording module is further configured to, after the second preset time period has elapsed, if no message is received from the fourth number of authentication servers among the multiple servers, record the authentication result of the fourth number of authentication servers for the terminal as authentication server unreachable. The sending module is further configured to send a ninth message to the terminal, or, when an escape strategy has been configured, to send a tenth message to the terminal. The ninth message indicates that the terminal access authentication has failed, and the tenth message indicates that the terminal access authentication has succeeded. The sum of the third quantity and the fourth quantity is the same as the number of the multiple authentication servers.

17. The apparatus according to claim 10, characterized in that, The length of the EAP message attributes is a preset length; If the length of the EAP message is greater than the preset length, the seventh message includes multiple EAP message attributes, and the EAP message is carried in fragments within the multiple EAP message attributes.

18. The apparatus according to claim 10, characterized in that, The access device is connected to multiple groups of authentication servers; the sending module is further configured to select one group of authentication servers from the multiple groups of authentication servers in a load-sharing manner, and send the first message to the selected group of authentication servers; or... A preset number of authentication servers are selected from each of the multiple authentication servers in a load-sharing manner, and the first message is sent to the selected authentication servers.

19. An access device, characterized in that, The access device includes: processor; transceiver; A machine-readable storage medium storing machine-executable instructions that can be executed by the processor; the machine-executable instructions cause the processor to perform the following steps: The transceiver sends a first message to each of the multiple authentication servers, the first message being used to request the authentication server to perform access authentication for the terminal. If the transceiver receives a second message from any authentication server and the second message is the first second message sent by the multiple authentication servers after receiving the first message, then the transceiver sends a third message to the terminal. Both the second message and the third message are used to indicate that the terminal has successfully accessed authentication. The machine-executable instructions also cause the processor to perform the following steps: If the transceiver receives a fourth message from any authentication server, and the fourth message is the first fourth message sent by the multiple authentication servers after receiving the first message, then the transceiver sends a fifth message to the terminal. The fifth message includes authentication parameters, which are carried by the EAP message included in the fourth message. The transceiver receives a sixth message sent by the terminal, the sixth message including user identity information, which is encrypted using the authentication parameters. The transceiver sends a seventh message to each authentication server, the seventh message including the sixth message and the EAP message, so that the authentication server verifies the user's identity information based on the authentication parameters, and updates the locally stored authentication parameters to the authentication parameters when the authentication parameters stored locally are different from the authentication parameters. The seventh message includes EAP message attributes, which are used to carry the EAP message.

20. The access device according to claim 19, characterized in that, The machine-executable instructions also cause the processor to perform the following steps: If, within a first preset time period, the transceiver receives the same number of eighth messages as the multiple authentication servers, and each eighth message carries an authentication result indicating that the terminal access authentication has failed, then the authentication result of each server for the terminal is recorded as access authentication failure. The transceiver sends a ninth message to the terminal, which indicates that the terminal's access authentication has failed.

21. The access device according to claim 19, characterized in that, The machine-executable instructions also cause the processor to perform the following steps: If no message is received from any authentication server after the first preset time period, the authentication result of each server for the terminal is recorded as authentication server unreachable. The transceiver sends a ninth message to the terminal, which indicates that the terminal's access authentication has failed.

22. The access device according to claim 19, characterized in that, The machine-executable instructions also cause the processor to perform the following steps: If, within a first preset time period, the transceiver receives an eighth message sent by a first number of authentication servers, and each eighth message carries an authentication result indicating that the terminal access authentication has failed, then the authentication result of the first number of authentication servers for the terminal is recorded as access authentication failure. If no message is received from the second number of authentication servers among the multiple servers after the first preset time period has elapsed, then the authentication results of the second number of authentication servers for the terminal are recorded as authentication server unreachable. The transceiver sends a ninth message to the terminal, or, if an escape strategy is configured, sends a tenth message to the terminal. The ninth message indicates that the terminal access authentication failed, and the tenth message indicates that the terminal access authentication succeeded. The sum of the first number and the second number is the same as the number of the multiple authentication servers.

23. The access device according to claim 19, characterized in that, The machine-executable instructions also cause the processor to perform the following steps: If, within a second preset time period, the transceiver receives the same number of eighth messages as the multiple authentication servers, and each eighth message carries an authentication result indicating that the terminal access authentication has failed, then the authentication result of each server for the terminal is recorded as access authentication failure. The transceiver sends a ninth message to the terminal, which indicates that the terminal's access authentication has failed.

24. The access device according to claim 19, characterized in that, The machine-executable instructions also cause the processor to perform the following steps: If no message is received from any authentication server after the second preset time period, the authentication result of each server for the terminal is recorded as authentication server unreachable. The transceiver sends a ninth message to the terminal, which indicates that the terminal's access authentication has failed.

25. The access device according to claim 19, characterized in that, The machine-executable instructions also cause the processor to perform the following steps: If, within a second preset time period, the transceiver receives an eighth message sent by a third number of authentication servers, and each eighth message carries an authentication result indicating that the terminal access authentication has failed, then the authentication result of the third number of authentication servers for the terminal is recorded as access authentication failure. If no message is received from the fourth number of authentication servers among the multiple servers after the second preset time period has elapsed, then the authentication result of the fourth number of authentication servers for the terminal is recorded as authentication server unreachable. The transceiver sends a ninth message to the terminal, or, if an escape strategy has been configured, sends a tenth message to the terminal. The ninth message indicates that the terminal access authentication failed, and the tenth message indicates that the terminal access authentication succeeded. The sum of the third and fourth quantities is the same as the number of the multiple authentication servers.

26. The access device according to claim 19, characterized in that, The length of the EAP message attributes is a preset length; If the length of the EAP message is greater than the preset length, the seventh message includes multiple EAP message attributes, and the EAP message is carried in fragments within the multiple EAP message attributes.

27. The access device according to claim 19, characterized in that, The access device is connected to multiple authentication servers; the machine-executable instructions cause the processor to perform the following steps: Select one group of authentication servers from the plurality of groups of authentication servers in a load-sharing manner, and send the first message to the selected group of authentication servers through the transceiver; or... A preset number of authentication servers are selected from each of the multiple authentication servers in a load-sharing manner, and the first message is sent to the selected authentication servers through the transceiver.

28. A machine-readable storage medium, characterized in that, The device stores machine-executable instructions that, when invoked and executed by a processor, cause the processor to: implement the method of any one of claims 1-9.

29. A computer program product, characterized in that, The computer program product causes the processor to implement the method of any one of claims 1-9.

Citation Information

Patent Citations

  • Authentication system based on WAPI and authentication method

    CN101610515A

  • Method and device for controlling terminal to be online

    CN106506495A