User authentication method and device and related equipment

By caching user authorization information in the admission authentication device, the problem of confusing permission management during VXLAN or VLAN network escape is solved, and rapid service recovery is achieved when the authentication server is unavailable.

CN119945754APending Publication Date: 2025-05-06NEW H3C TECH CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510034564.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-08
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

In VXLAN or VLAN network escape scenarios, the lack of correct permissions provided by the AAA server leads to confusing permission management and the inability to quickly restore business.

Method used

The authorization information of the certified user is cached in the admission authentication device. When the authentication server is unavailable, the local cached authorization information is used for user authentication and permission granting.

Benefits of technology

When the authentication server is unavailable, ensure that certified users can go online quickly, avoiding the problem of unchanged permissions or exactly the same during escape, and improving the flexibility and security of business recovery.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945754A_ABST
    Figure CN119945754A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network communication, in particular to a user authentication method and device and related equipment. The method is applied to an access authentication device. The method comprises the following steps: receiving an online request of a target user; judging whether an authentication server is online or not, and judging whether authorization information corresponding to the target user is locally cached or not if judging that the authentication server is not online; and if it is judged that the authorization information corresponding to the target user is cached locally, sending the authorization information to the target user, so that the target user is online based on the authorization information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network communication technology, and in particular to a user authentication method, device and related equipment. Background Art

[0002] Currently, in VXLAN or VLAN networking escape scenarios, since there is no AAA server to provide correct permission authorization, when an escape occurs, either the entire network is exempted from authentication (the entire network has security risks and any user can access it), or the escape permissions of the entire network are consistent (the user permissions of the entire network are completely consistent, resulting in chaos in intranet management), or the entire network is denied access (bringing inconvenience to the business direction).

[0003] However, customers at some special locations (such as financial locations) hope that the equipment (access equipment) supports authenticated users to go online without authentication by using the cached information in the equipment when the authentication server is unavailable, rather than going through the escape process, so that related services can be quickly restored without interruption. Summary of the invention

[0004] The present application provides a user authentication method, apparatus and related equipment.

[0005] In a first aspect, the present application provides a user authentication method, which is applied to an access authentication device, and the method includes:

[0006] Receive the target user's online request;

[0007] Determine whether the authentication server is online. If it is determined that the authentication server is not online, determine whether the authorization information corresponding to the target user is cached locally;

[0008] If it is determined that the authorization information corresponding to the target user is cached locally, the authorization information is sent to the target user, so that the target user goes online based on the authorization information.

[0009] Optionally, the method further comprises:

[0010] If it is determined that the authentication server is online, it is determined whether the target user is online for the first time. If it is determined that the target user is online for the first time, after the authentication server passes the user authentication based on the user online request, the authorization information corresponding to the target user sent by the authentication server is cached locally.

[0011] Optionally, the method further comprises:

[0012] If it is determined that this is not the first time that the target user is online, after the authentication server passes the user authentication based on the user online request, the first authorization information corresponding to the target user sent by the authentication server is compared with the second authorization information corresponding to the target user cached locally to determine whether the authorization information has changed; if it is determined that the authorization information has changed, the second authorization information cached locally is updated to the first authorization information.

[0013] Optionally, a cache table is established on the access authentication device using the user MAC as an index, and the cache table maintains a mapping relationship between the MAC of an authenticated user and authorization information.

[0014] Optionally, a cache entry corresponding to a user includes the user's MAC, authorized VSI, authorized Vlanid, UUID, authentication mode, user name, and timeout period.

[0015] In a second aspect, the present application provides a user authentication device, which is applied to an access authentication device, and the device includes:

[0016] A receiving unit, used for receiving a target user's online request;

[0017] A determination unit, configured to determine whether the authentication server is online, and if it is determined that the authentication server is not online, to determine whether authorization information corresponding to the target user is cached locally;

[0018] The sending unit is used for sending the authorization information to the target user if the judging unit determines that the authorization information corresponding to the target user is cached locally, so that the target user goes online based on the authorization information.

[0019] Optionally, the device further includes a cache unit:

[0020] If the judgment unit determines that the authentication server is online, the judgment unit is also used to judge whether the target user is online for the first time. If it is determined that the target user is online for the first time, the cache unit is used to cache the authorization information corresponding to the target user sent by the authentication server locally after the authentication server passes the user authentication based on the user online request.

[0021] Optionally, the device further comprises an updating unit:

[0022] If the judgment unit determines that the target user is not online for the first time, the cache unit is also used to, after the authentication server passes the user authentication based on the user online request, compare the first authorization information corresponding to the target user sent by the authentication server with the second authorization information corresponding to the target user cached locally to determine whether the authorization information has changed; if it is determined that the authorization information has changed, the update unit is used to update the second authorization information cached locally to the first authorization information.

[0023] Optionally, a cache table is established on the access authentication device using the user MAC as an index, and the cache table maintains a mapping relationship between the MAC of an authenticated user and authorization information.

[0024] Optionally, a cache entry corresponding to a user includes the user's MAC, authorized VSI, authorized Vlanid, UUID, authentication mode, user name, and timeout period.

[0025] In a third aspect, an embodiment of the present application provides a user authentication device, the user authentication device comprising:

[0026] A memory for storing program instructions;

[0027] The processor is used to call the program instructions stored in the memory, and execute the steps of the method as described in any one of the first aspects above according to the obtained program instructions.

[0028] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are used to enable the computer to execute the steps of the method described in any one of the first aspects above.

[0029] In summary, the user authentication method provided in the embodiment of the present application is applied to an access authentication device, and the method includes: receiving a request for a target user to go online; determining whether the authentication server is online, and if it is determined that the authentication server is not online, determining whether the authorization information corresponding to the target user is cached locally; if it is determined that the authorization information corresponding to the target user is cached locally, sending the authorization information to the target user, so that the target user goes online based on the authorization information.

[0030] By adopting the user authentication method provided in the embodiment of the present application, the authorization key information of the online user is cached on the access authentication device. When the user goes online again and the authentication server is unavailable, the access authentication device can grant corresponding permissions to different users based on the authorization key information of each user cached locally, thereby solving the problem of the escaped user's permissions remaining unchanged before and after the escape, and avoiding the problem of the escaped user's permissions being exactly the same after the escape. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments of the present application or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this application. For ordinary technicians in this field, other drawings can also be obtained based on these drawings of the embodiments of the present application.

[0032] Figure 1 A detailed flow chart of a user authentication method provided in an embodiment of the present application;

[0033] Figure 2 A schematic diagram of the structure of a user authentication device provided in an embodiment of the present application;

[0034] Figure 3 A schematic diagram of the hardware architecture of a user authentication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0035] The terms used in the embodiments of the present application are only for the purpose of describing specific embodiments, rather than limiting the present application. The singular forms of "a", "said" and "the" used in the present application and claims are also intended to include plural forms, unless the context clearly indicates other meanings. It should also be understood that the term "and / or" used herein refers to any or all possible combinations of one or more associated listed items.

[0036] It should be understood that, although the terms first, second, third, etc. may be used to describe various information in the embodiments of the present application, these information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of the present application, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, in addition, the word "if" used may be interpreted as "at..." or "when..." or "in response to determination".

[0037] For example, see Figure 1 As shown, it is a detailed flow chart of a user authentication method provided in an embodiment of the present application. The method is applied to an access authentication device, and the method includes the following steps:

[0038] Step 100: Receive a target user's online request.

[0039] In an embodiment of the present application, a keep-alive detection mechanism is set between the access authentication device and the authentication server (such as an AAA server). The access authentication device can sense the working status of the authentication server (online / offline). When the authentication server is online, it can perform online authentication on the access user. When the authentication server is offline, it cannot perform online authentication on the access user.

[0040] When a user goes online on the network, he / she accesses the network through the access authentication device. When the user determines that he / she needs to go online, he / she sends a user online request to the access authentication device.

[0041] Step 110: Determine whether the authentication server is online. If it is determined that the authentication server is not online, determine whether the authorization information corresponding to the target user is cached locally.

[0042] In an embodiment of the present application, if the access authentication device determines that the authentication server is online, it determines whether the target user is online for the first time. If it is determined that the target user is online for the first time, after the authentication server passes the user authentication based on the user online request, the authorization information corresponding to the target user sent by the authentication server is cached locally.

[0043] For example, user 1 initiates the online process, and the access authentication device forwards the user online request sent by user 1 to the authentication server. The authentication server performs online authentication on user 1, and after confirming that the authentication is successful, it sends the authorization information 1 corresponding to user 1 to the access authentication device, and the access authentication device caches the authorization information 1 locally.

[0044] In an embodiment of the present application, when the access authentication device receives a target user online request sent by the target user, it determines whether the authentication server is online (i.e., whether it is reachable). If it is determined that the authentication server is not online, at this time, the target user's online authentication cannot be performed based on the authentication server.

[0045] At this time, the access authentication device queries whether the authorization information corresponding to the target user is cached locally.

[0046] In actual applications, if the target user is not online for the first time, that is, has been online before, the access authentication device may cache the authorization information corresponding to the target user, which is preset based on the type of the target user / authorization scope of the pre-device.

[0047] Step 120: If it is determined that the authorization information corresponding to the target user is cached locally, the authorization information is sent to the target user, so that the target user goes online based on the authorization information.

[0048] In the embodiment of the present application, if the access authentication device determines that the authorization information corresponding to the target user is cached locally, the online / network access of the target user can be controlled based on the authorization information.

[0049] In an embodiment of the present application, the above method may further include the following steps: if it is determined that the target user is not online for the first time, after the authentication server passes the user authentication based on the user online request, the first authorization information corresponding to the target user sent by the authentication server is compared with the second authorization information corresponding to the target user cached locally to determine whether the authorization information has changed; if it is determined that the authorization information has changed, the second authorization information cached locally is updated to the first authorization information.

[0050] Specifically, when the authentication server is online and the target user is not online for the first time, the authentication server authenticates the target user based on the online request, and compares the first authorization information corresponding to the target user sent after the authentication is passed with the second authorization information sent by the authentication server when the user was last online and cached locally to determine whether the authorization information of the target user has changed. If it is determined that the authorization information has changed, that is, the network access rights of the target user have changed, then the latest authorization information shall prevail. The original authorization information cached locally shall be updated to the latest authorization information.

[0051] It should be noted that a cache table is established on the access authentication device with the user MAC (physical address) as an index, and the cache table maintains a mapping relationship between the MAC of an authenticated user and the authorization information.

[0052] For example, a cache entry corresponding to a user includes the user's MAC, authorized VSI (Virtual Switch Interface), authorized VLAN id, UUID (Universally Unique Identifier), authentication method, user name, and timeout period.

[0053] In actual applications, the access device will cache the cache entries of each user within the timeout period. If the cache entries are not updated within a certain period of time, the corresponding cache entries will be deleted.

[0054] Then, when the authentication server is online and this is not the first time that the target user is online, the authentication server will perform authentication based on the target user's online request, and compare the first authorization information corresponding to the target user sent after the authentication is passed with the second authorization information sent by the authentication server when the target user was last online and cached locally to determine whether the authorization information of the target user has changed. If it is determined that there is no change, the timeout time in the cache entry corresponding to the target user can be updated at this time.

[0055] The following is an illustrative description of the networking scenarios to which the user authentication method provided in the embodiments of the present application is applicable in conjunction with specific application scenarios.

[0056] In actual applications, in 802.1x / mac authentication scenarios, after the user goes online normally, the access authentication device uses the access mode + user name + Mac as the key to record the key authorization information (such as Vsi / Vlan, etc.) of the authentication server in the cache. When the user encounters a server failure to respond when going online next time, the access device can use the cached information to authorize the user so that the user can go online normally. If a new online user (first time online / no local cache of the user's corresponding authorization information) cannot find the cache entry, he can enter the critical Vsi / Vlan according to the original escape process.

[0057] The user authentication method provided in the embodiment of the present application is combined with the AD-Campus solution. The Vxlan model has all standard networking. At this time, the authentication point is at Leaf, and the cache information mentioned in the embodiment of the present application is also cached on the Leaf role (authentication point). When the terminal triggers the authentication online on Leaf, the Leaf device with the authentication cache function turned on will create a cache table entry on the device with Mac as the index. The table entry contains Mac, authorized Vsi, authorized Vlan id, UUID (index ID used for name-address binding, which can be used to solve the terminal's need to obtain a specified IP in the name-address binding scenario), authentication method, user name, timeout, etc.

[0058] For example, see Figure 2 , which is a schematic diagram of the structure of a ... device provided in an embodiment of the present application, the device comprises:

[0059] A receiving unit, used for receiving a target user's online request;

[0060] A determination unit, configured to determine whether the authentication server is online, and if it is determined that the authentication server is not online, to determine whether authorization information corresponding to the target user is cached locally;

[0061] The sending unit is used for sending the authorization information to the target user if the judging unit determines that the authorization information corresponding to the target user is cached locally, so that the target user goes online based on the authorization information.

[0062] Optionally, the device further includes a cache unit:

[0063] If the judgment unit determines that the authentication server is online, the judgment unit is also used to judge whether the target user is online for the first time. If it is determined that the target user is online for the first time, the cache unit is used to cache the authorization information corresponding to the target user sent by the authentication server locally after the authentication server passes the user authentication based on the user online request.

[0064] Optionally, the device further comprises an updating unit:

[0065] If the judgment unit determines that the target user is not online for the first time, the cache unit is also used to, after the authentication server passes the user authentication based on the user online request, compare the first authorization information corresponding to the target user sent by the authentication server with the second authorization information corresponding to the target user cached locally to determine whether the authorization information has changed; if it is determined that the authorization information has changed, the update unit is used to update the second authorization information cached locally to the first authorization information.

[0066] Optionally, a cache table is established on the access authentication device using the user MAC as an index, and the cache table maintains a mapping relationship between the MAC of an authenticated user and authorization information.

[0067] Optionally, a cache entry corresponding to a user includes the user's MAC, authorized VSI, authorized Vlanid, UUID, authentication mode, user name, and timeout period.

[0068] The above units may be one or more integrated circuits configured to implement the above methods, such as one or more application specific integrated circuits (ASIC), or one or more digital signal processors (DSP), or one or more field programmable gate arrays (FPGA). For another example, when a certain unit is implemented in the form of a processing element scheduling program code, the processing element may be a general-purpose processor, such as a central processing unit (CPU) or other processor that can call program code. For another example, these units may be integrated together and implemented in the form of a system-on-a-chip (SOC).

[0069] Furthermore, the user authentication device provided in the embodiment of the present application, from the hardware level, the hardware architecture diagram of the user authentication device can be seen in Figure 3As shown, the user authentication device may include: a memory 30 and a processor 31,

[0070] The memory 30 is used to store program instructions; the processor 31 calls the program instructions stored in the memory 30 and executes the above method embodiment according to the obtained program instructions. The specific implementation method and technical effect are similar and will not be repeated here.

[0071] Optionally, the present application also provides an access authentication device, comprising at least one processing element (or chip) for executing the above method embodiment.

[0072] Optionally, the present application also provides a program product, such as a computer-readable storage medium, which stores computer-executable instructions, and the computer-executable instructions are used to enable the computer to execute the above method embodiments.

[0073] Here, the machine-readable storage medium may be any electronic, magnetic, optical or other physical storage device that may contain or store information, such as executable instructions, data, etc. For example, the machine-readable storage medium may be: RAM (RadomAccess Memory), volatile memory, non-volatile memory, flash memory, storage drive (such as hard disk drive), solid state drive, any type of storage disk (such as CD, DVD, etc.), or similar storage medium, or a combination thereof.

[0074] The systems, devices, modules or units described in the above embodiments may be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer, which may be in the form of a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email transceiver, a game console, a tablet computer, a wearable device or a combination of any of these devices.

[0075] For the convenience of description, the above device is described in various units according to their functions. Of course, when implementing the present application, the functions of each unit can be implemented in the same or multiple software and / or hardware.

[0076] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the embodiments of the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0077] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0078] Moreover, these computer program instructions can also be stored in a computer-readable memory that can guide a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0079] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable device to implement the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0080] The above description is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application shall be included in the scope of protection of the present application.

Claims

1. A user authentication method, characterized in that: Applied to access authentication equipment, the method comprises: Receive the target user's online request; Determine whether the authentication server is online. If it is determined that the authentication server is not online, determine whether the authorization information corresponding to the target user is cached locally; If it is determined that the authorization information corresponding to the target user is cached locally, the authorization information is sent to the target user, so that the target user goes online based on the authorization information.

2. The method according to claim 1, characterized in that The method further comprises: If it is determined that the authentication server is online, it is determined whether the target user is online for the first time. If it is determined that the target user is online for the first time, after the authentication server passes the user authentication based on the user online request, the authorization information corresponding to the target user sent by the authentication server is cached locally.

3. The method according to claim 2, characterized in that The method further comprises: If it is determined that this is not the first time that the target user is online, after the authentication server passes the user authentication based on the user online request, the first authorization information corresponding to the target user sent by the authentication server is compared with the second authorization information corresponding to the target user cached locally to determine whether the authorization information has changed; if it is determined that the authorization information has changed, the second authorization information cached locally is updated to the first authorization information.

4. The method according to any one of claims 1 to 3, characterized in that: The access authentication device establishes a cache table with the user MAC as an index, and the cache table maintains a mapping relationship between the MAC of the authenticated user and the authorization information.

5. The method according to claim 4, characterized in that The cache entry corresponding to a user includes the user's MAC, authorized VSI, authorized VLAN ID, UUID, authentication method, user name, and timeout period.

6. A user authentication device, characterized in that: Applied to access authentication equipment, the device comprises: A receiving unit, used for receiving a target user's online request; A determination unit, configured to determine whether the authentication server is online, and if it is determined that the authentication server is not online, to determine whether authorization information corresponding to the target user is cached locally; The sending unit is used for sending the authorization information to the target user if the judging unit determines that the authorization information corresponding to the target user is cached locally, so that the target user goes online based on the authorization information.

7. The device according to claim 6, characterized in that The device also includes a cache unit: If the judgment unit determines that the authentication server is online, the judgment unit is also used to judge whether the target user is online for the first time. If it is determined that the target user is online for the first time, the cache unit is used to cache the authorization information corresponding to the target user sent by the authentication server locally after the authentication server passes the user authentication based on the user online request.

8. The device according to claim 7, characterized in that The device also includes an updating unit: If the judgment unit determines that the target user is not online for the first time, the cache unit is also used to, after the authentication server passes the user authentication based on the user online request, compare the first authorization information corresponding to the target user sent by the authentication server with the second authorization information corresponding to the target user cached locally to determine whether the authorization information has changed; if it is determined that the authorization information has changed, the update unit is used to update the second authorization information cached locally to the first authorization information.

9. A user authentication device, characterized in that: The user authentication device comprises: A memory for storing program instructions; A processor is used to call the program instructions stored in the memory, and execute the steps of the method according to any one of claims 1 to 5 according to the obtained program instructions.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are used to enable the computer to execute the steps of the method according to any one of claims 1 to 5.

Citation Information

Cited By

  • Network access method and device, electronic equipment and storage medium

    CN121367618A

  • Application offline access method and device of zero-trust server

    CN121441580A