Campus network roaming authentication-free method and device

By setting up roaming groups and virtual ONU devices on the campus network, the problem of frequent authentication of users in the campus network is solved, and campus network roaming is not certified and the user experience is improved.

CN119946626AActive Publication Date: 2025-05-06WUHAN GREENET INFORMATION SERVICE
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411977959.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2025-05-06
Estimated Expiration
2044-12-31

AI Technical Summary

Technical Problem

In the campus network scenario, user terminals need to frequently perform portal authentication when switching network environments, resulting in trouble using the user's network.

Method used

By pre-setting a roaming group in the access cloud gateway, each roaming group corresponds to a virtual ONU device. The terminal does not need to repeat authentication in the roaming area, and uses the virtual ONU device-related information to generate WAN side information, so that the entire roaming group appears to have only one ONU device externally.

Benefits of technology

It has realized the certification of campus online roaming, which has reduced the frequency of authentication for users when they are on campus and improved the user's network experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119946626A_ABST
    Figure CN119946626A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of campus networks, and provides a campus network roaming authentication-free method and device. The method comprises the following steps: setting roaming groups for a terminal in an access cloud gateway in advance, wherein each roaming group corresponds to one virtual ONU device; when a first uplink message from the first terminal is received, judging whether the first terminal is an authenticated terminal in a roaming area where the first ONU equipment is located; and if it is judged that the first terminal is the authenticated terminal in the roaming area, packaging the second uplink message into a third uplink message which can be identified by the wide area network according to related information of virtual ONU equipment in a roaming group to which the first ONU equipment belongs, and transmitting the third uplink message to the network. According to the method, the roaming group and the virtual ONU equipment are arranged, and the WAN side information is generated by using the related information of the virtual ONU equipment, so that the whole roaming group is represented as only one ONU equipment for the outside, repeated authentication is not needed, and authentication-free roaming of the campus network is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of campus network, and in particular to a method and device for campus network roaming without authentication. Background Art

[0002] In the past campus network scenario, if a user terminal wanted to access the Internet, it had to first log in and verify at the edge portal server to find the user link to access the Internet; once the user terminal switched the network environment, such as switching to another dormitory or teaching building, the optical network unit (ONU) device connected to it changed, so it was necessary to re-perform portal authentication, delete the binding rules of the last login authentication, and bind to the new link before it could use the network again. This resulted in users having to frequently perform portal authentication when they were on campus, which brought trouble to their network use.

[0003] In view of this, overcoming the defects of the prior art is an urgent problem to be solved in the field of this technology. Summary of the invention

[0004] The technical problem to be solved by the present invention is to provide a method and device for campus network roaming without authentication, so as to realize campus network roaming without authentication.

[0005] The present invention adopts the following technical solution:

[0006] In a first aspect, the present invention provides a campus network roaming authentication-free method, comprising:

[0007] A roaming group is pre-set for the terminal in the access cloud gateway, and each roaming group corresponds to a virtual ONU device; wherein the roaming group includes the mac information of the terminal, the relevant information of each actual ONU device in the roaming area required by the terminal, and the relevant information of the unique virtual ONU device of the roaming group;

[0008] When the first ONU device receives the first uplink message from the first terminal, it adds relevant information of the first ONU device to the first uplink message, generates a second uplink message, and sends the second uplink message to the access cloud gateway; wherein the first uplink message also carries the mac address of the first terminal;

[0009] The access cloud gateway determines, according to the MAC address of the first terminal carried in the second uplink message, the relevant information of the first ONU device, and each roaming group, whether the first terminal is an authenticated terminal in the roaming area to which the first ONU device belongs;

[0010] If it is determined that the first terminal is an authenticated terminal in the roaming area where the first ONU device is located, the second uplink message is encapsulated into a third uplink message recognizable by the wide area network according to the relevant information of the virtual ONU device in the roaming group to which the first ONU device belongs, and the third uplink message is transmitted to the network.

[0011] Preferably, the relevant information of the actual ONU device includes the VNI identifier of the actual ONU device and the QinQ information of the actual ONU device; the relevant information of the virtual ONU device includes the virtual VNI identifier and the virtual QinQ information;

[0012] The access cloud gateway includes a virtual switch and a virtual client device, and the roaming group is pre-set for the terminal in the access cloud gateway, specifically including:

[0013] Storing roaming group information items, ONU device information items, and terminal roaming information items in the virtual client device;

[0014] The roaming group information table entry stores the ID number of each roaming group and the virtual VNI identifier and virtual QinQ information corresponding to each roaming group;

[0015] The ONU device information table item stores the VNI identification of each actual ONU device, the QinQ information of each actual ONU device, and the ID number of the roaming group to which each actual ONU device belongs;

[0016] The terminal roaming information table entry stores the MAC address of the terminal and the ID number of the roaming group to which the terminal is pre-bound.

[0017] Preferably, the access cloud gateway determines whether the first terminal is an authenticated terminal in the roaming area to which the first ONU device belongs according to the mac address of the first terminal carried in the second uplink message, the relevant information of the first ONU device, and each roaming group, specifically including:

[0018] The virtual switch receives the second uplink message, and forwards the second uplink message to the virtual client device;

[0019] The virtual client device finds the first roaming group bound to the first terminal from the terminal roaming information entry according to the MAC address of the first terminal carried in the second uplink message;

[0020] According to the VNI identifier of the first ONU device and the QinQ information of the first ONU device carried in the second uplink message, acquiring the second roaming group to which the first ONU device belongs from the ONU device information table item;

[0021] Determine whether the first roaming group is consistent with the second roaming group, and if they are consistent, search whether there is historical login information of the first terminal in the second roaming group;

[0022] If the historical login information exists, it is determined that the first terminal is an authenticated terminal in the second roaming group.

[0023] Preferably, the historical login information is recorded when the first terminal performs historical authentication and login in the roaming area where the second roaming group is located, and specifically includes:

[0024] When the virtual client device determines that the first terminal is not an authenticated terminal in the roaming area where the currently accessed ONU device is located, redirecting the second uplink message to the portal server so that the portal server feeds back a portal authentication page to the first terminal;

[0025] After the first terminal successfully logs in and authenticates on the portal authentication page, the portal server returns an authentication success message to the virtual client device; wherein the authentication success message carries the mac address of the first terminal, the VNI identifier of the ONU device currently accessed by the first terminal, and the QinQ information of the ONU device currently accessed by the first terminal;

[0026] The virtual client finds the corresponding roaming group from the ONU device information table item according to the VNI identifier of the ONU device currently accessed by the first terminal and the QinQ information of the ONU device currently accessed by the first terminal;

[0027] The ID number of the roaming group and the MAC address of the first terminal are recorded as historical login information in the authentication table; wherein, for a MAC address, only the latest historical login information is recorded in the authentication table.

[0028] Preferably, encapsulating the second uplink message into a third uplink message identifiable by the wide area network according to the relevant information of the virtual ONU device in the roaming group to which the first ONU device belongs specifically includes:

[0029] Find the corresponding WAN side VNI identifier and WAN side QinQ information according to the virtual ONU device related information in the roaming group to which the first ONU device belongs;

[0030] The WAN side VNI identifier and the WAN side QinQ information are used to replace the virtual ONU device related information in the second uplink message to generate the third uplink message.

[0031] Preferably, the method further comprises:

[0032] After determining that the first terminal is an authenticated terminal in the roaming area where the first ONU device is located, the access cloud gateway also reports the log of the first terminal to the log audit platform on the operator side, so that the log audit platform can determine the ONU device accessed by the first terminal according to the log, thereby performing log audit;

[0033] Among them, the log includes the login account of the first terminal, the mac address of the first terminal, the LAN side tunnel ID of the second uplink message, the LAN side PVLAN identifier of the second uplink message, the LAN side CVLAN identifier of the second uplink message, the WAN side tunnel ID of the third uplink message, the WAN side PVLAN identifier of the third uplink message and the WAN side CVLAN identifier of the third uplink message.

[0034] Preferably, the method further comprises: setting the same SSID for all ONU devices located in a roaming area.

[0035] Preferably, the method further comprises:

[0036] Set the option82_sensitive value of the roaming area in the access cloud gateway to 0 so that when the option82 field in the message sent by different ONU devices changes, the dial-up is not re-performed.

[0037] In a second aspect, the present invention further provides a campus network roaming authentication-free device, which is used to implement the campus network roaming authentication-free method described in the first aspect, and the device includes:

[0038] At least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the processor to execute the method for campus network roaming without authentication as described in the first aspect.

[0039] In a third aspect, the present invention further provides a non-volatile computer storage medium, wherein the computer storage medium stores computer executable instructions, and the computer executable instructions are executed by one or more processors to complete the method described in the first aspect.

[0040] In a fourth aspect, a chip is provided, comprising: a processor and an interface, for calling and running a computer program stored in the memory from a memory to execute the method of the first aspect.

[0041] In a fifth aspect, a computer program product comprising instructions is provided, which, when executed on a computer or a processor, causes the computer or the processor to execute the method of the first aspect.

[0042] The present invention sets a roaming group and a virtual ONU device, and after verifying that the first terminal is an authenticated terminal, uses the virtual ONU device related information to generate WAN side information, so that the entire roaming group appears to the outside as having only one ONU device (i.e., the virtual ONU device), and thus there is no need for repeated authentication, but the original link is used for network communication, thereby realizing authentication-free roaming in the campus network. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments of the present invention. Obviously, the drawings described below are only some embodiments of the present invention, and for ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0044] Figure 1 It is a flowchart of a first campus network roaming authentication-free method provided by an embodiment of the present invention;

[0045] Figure 2 It is a schematic diagram of a roaming group information table item in a campus network roaming authentication-free method provided by an embodiment of the present invention;

[0046] Figure 3 It is a schematic diagram of an ONU device information table item in a campus network roaming authentication-free method provided by an embodiment of the present invention;

[0047] Figure 4 It is a schematic diagram of a terminal roaming information table item in a campus network roaming authentication-free method provided by an embodiment of the present invention;

[0048] Figure 5 It is a flow chart of a second campus network roaming authentication-free method provided by an embodiment of the present invention;

[0049] Figure 6 It is a flow chart of a third campus network roaming authentication-free method provided by an embodiment of the present invention;

[0050] Figure 7 It is a flowchart of a fourth campus network roaming authentication-free method provided by an embodiment of the present invention;

[0051] Figure 8 It is a schematic diagram of a campus network roaming authentication-free method provided by an embodiment of the present invention;

[0052] Fig. 9 It is a schematic diagram of a campus network roaming authentication-free method provided by an embodiment of the present invention;

[0053] Fig.10It is a schematic diagram of a QinQ conversion table in a campus network roaming authentication-free method provided by an embodiment of the present invention;

[0054] Fig.11 It is a schematic diagram of a campus network roaming authentication-free method provided by an embodiment of the present invention;

[0055] Fig.12 It is a schematic diagram of a campus network roaming authentication-free method provided by an embodiment of the present invention;

[0056] Fig.13 The present invention is a schematic diagram of the architecture of a campus network roaming authentication-free device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0057] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0058] Unless the context requires otherwise, throughout the specification and claims, the term "including" is to be interpreted as open inclusion, that is, "including, but not limited to". In the description of the specification, the terms "one embodiment", "some embodiments", "exemplary embodiments", "examples", "specific examples" or "some examples" and the like are intended to indicate that specific features, structures, materials or characteristics associated with the embodiment or example are included in at least one embodiment or example of the present disclosure. The schematic representation of the above terms does not necessarily refer to the same embodiment or example. In addition, the specific features, structures, materials or characteristics may be included in any one or more embodiments or examples in any appropriate manner, that is, although they may be carried in the embodiments or examples of the above terms due to reasons such as the order and position of appearance, it is not limited to that they can be carried in combination by one embodiment or example.

[0059] In the description of the present invention, the terms "first" and "second" are used only for descriptive purposes, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of indicated technical features. Thus, the features defined as "first" and "second" may explicitly or implicitly include one or more of the features. In the description of the embodiments of the present disclosure, unless otherwise specified, the meaning of "multiple" is two or more. In addition, for example, the same type of nouns may be described as two independent individuals by adding "A" and "B" at the end. In this case, the corresponding features defined as "A" and "B" are only used to distinguish the same type of individuals for description purposes, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of indicated technical features.

[0060] In the description of the present invention, the expression "A and / or B" (where A and B are used to formally represent specific characteristic contents) will be involved, and the corresponding expressions include the following three combinations: only A, only B, and a combination of A and B.

[0061] As used herein, "about," "substantially," or "approximately" includes the stated value and an average value that is within an acceptable range of deviation from the particular value as determined by one of ordinary skill in the art taking into account the measurements in question and the errors associated with the measurement of the particular quantity (i.e., the limitations of the measurement system).

[0062] In addition, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.

[0063] Embodiment 1:

[0064] Embodiment 1 of the present invention provides a campus network roaming authentication-free method, such as Figure 1 As shown, including:

[0065] In step 201, a roaming group is pre-set for the terminal in the access cloud gateway, and each roaming group corresponds to a virtual ONU device; wherein the roaming group includes the mac information of the terminal, the relevant information of each actual ONU device in the roaming area required by the terminal, and the relevant information of the unique virtual ONU device in the roaming group; the relevant information can be understood as identification information for identifying the corresponding device, and the virtual ONU device can be understood as a virtual device that is not a device actually existing in the network, but is used to represent all actual ONU devices in the corresponding area. The virtual device has the same type of relevant information as the actual ONU device, such as the identification information of the actual ONU device includes the VNI identifier (full name: VXLAN Network Identifier, Chinese meaning is: identifier in VXLAN network) and QinQ information, then the virtual ONU device also has VNI identification and QinQ information (that is, the virtual ONU device related information), and is different from other virtual ONU devices and actual ONU devices. The VNI identification and QinQ information of the virtual ONU device are allocated when the roaming group is established. The roaming group set for the terminal in the access cloud gateway in advance can be obtained by technical personnel in this field based on the demand analysis of personnel flow in the campus network. For example, for the student group, the student dormitory, canteen and teaching building are regarded as a roaming area as a whole, and the corresponding roaming group is set; for the teacher group, the teaching building, canteen and staff dormitory are regarded as a roaming area, and the corresponding roaming group is set.

[0066] In step 202, when the first ONU device receives the first uplink message from the first terminal, it adds the relevant information of the first ONU device to the first uplink message, generates a second uplink message, and sends the second uplink message to the access cloud gateway; wherein the first uplink message also carries the mac address of the first terminal; the first ONU device is the ONU device accessed by the first terminal. In actual use, a roaming group also corresponds to a tunnel group, which includes the tunnels used by each ONU device bound to the roaming group to transmit messages. The tunnel is used to isolate the messages of different roaming groups, that is, to isolate the messages. For example, the IP and QinQ information of the messages in different tunnels can be repeated. If there is no tunnel isolation, the IP and QinQ information of the messages will be repeated, which will cause confusion in the identification of the traffic. The ID of the tunnel group is also added to the second uplink message.

[0067] In step 203, the access cloud gateway determines whether the first terminal is an authenticated terminal in the roaming area to which the first ONU device belongs based on the MAC address of the first terminal carried in the second uplink message, the relevant information of the first ONU device, and each roaming group; that is, whether the user has performed portal authentication in the roaming area and the authentication information is still valid.

[0068] In step 204, if it is determined that the first terminal is an authenticated terminal in the roaming area where the first ONU device is located, the second uplink message is encapsulated as a third uplink message recognizable by the wide area network according to the virtual ONU device related information in the roaming group to which the first ONU device belongs, and the third uplink message is transmitted to the network. If it is determined that the first terminal is not an authenticated terminal in the roaming area where the first ONU device is located, redirect to the portal authentication page so that the user can perform authentication.

[0069] Among them, according to the virtual ONU device related information in the roaming group to which the first ONU device belongs, the second uplink message is encapsulated into a third uplink message identifiable by the wide area network, specifically including: finding the corresponding WAN side VNI identifier and WAN side QinQ information according to the virtual ONU device related information in the roaming group to which the first ONU device belongs; using the wide area network (abbreviated as: WAN) side VNI identifier and WAN side QinQ information to replace the virtual ONU device related information in the second uplink message, and generating the third uplink message. The access cloud gateway includes a virtual switch and a virtual client device, and the process of generating the third uplink message is mainly completed by the virtual client device. In the virtual client device, a virtual ONU device corresponds to a unique local area network (abbreviated as: LAN) side VNI identifier and LAN side QinQ information, WAN side VNI identifier and WAN side QinQ information.

[0070] This embodiment sets up a roaming group and a virtual ONU device, and after verifying that the first terminal is an authenticated terminal, uses the virtual ONU device-related information to generate WAN side information, so that the entire roaming group appears to the outside as having only one ONU device (i.e., the virtual ONU device), and thus there is no need for repeated authentication. Instead, the original link is used for network communication, thereby realizing authentication-free roaming in the campus network.

[0071] In actual use, different ONU devices have different service set identifiers (SSIDs), which may also trigger the first terminal to re-dial authentication. Therefore, the method also includes: setting the same SSID for all ONU devices in a roaming area, so that the first terminal side does not perceive changes in the ONU device.

[0072] Moreover, when the terminal roams between authentication-free ONUs, the option82 reported by the optical line terminal (OLT) device will report different information according to the physical location of the ONU connected to the OLT device. In the prior art, when the cloud gateway detects that the option82 of the same account is different, it will initiate a redial, which causes the terminal to still need to dial frequently when roaming between authentication-free ONUs. In order to solve this problem, the method also includes: setting the value of option82_sensitive in the roaming area of ​​the access cloud gateway to 0, so that when the option82 field in the message sent by different ONU devices changes, the dialing is not re-dialed. Among them, option82_sensitive can be understood as a field used to identify whether the dialing action is sensitive to the option82 field, that is, when the value of option82_sensitive is 1, it is sensitive to the option82 field, and the dialing is re-dial when the option82 field is detected to change; when the value of option82_sensitive is 0, it is not sensitive to the option82 field, and the dialing is not re-dial when the option82 field is detected to change.

[0073] In addition, if the operator has performed precise binding on the Authentication, Authorization, Accounting (AAA) server, the physical scope of the roaming area needs to be limited according to the precise binding conditions. For example, if AAA has performed precise binding on the OLT device, the Passive Optical Network (PON) board, and the PON port, then these ONUs in a roaming area need to be on the same PON board of the same OLT and on the same PON port.

[0074] In the actual application scenario, the relevant information of the actual ONU device includes the VNI identifier of the actual ONU device and the QinQ information of the actual ONU device; the relevant information of the virtual ONU device includes the virtual VNI identifier and the virtual QinQ information; it should be noted that the VNI identifier of the actual ONU device and the QinQ information of the actual ONU device, the virtual VNI identifier and the virtual QinQ information all refer to the LAN side VNI identifier and the LAN side QinQ information. In actual use, the QinQ information is also manifested as Network Address Translation (NAT) plus QinQ.

[0075] The access cloud gateway includes a virtual switch and a virtual client device, the virtual switch is also called a vSwitch, and the virtual client device is also called a vCPE. The roaming group is pre-set for the terminal in the access cloud gateway, specifically including: storing roaming group information items, ONU device information items and terminal roaming information items in the virtual client device.

[0076] The roaming group information table entry stores the ID number of each roaming group and the virtual VNI identifier and virtual QinQ information corresponding to each roaming group, such as Figure 2 As shown in the figure, the roaming group ID is a unique index.

[0077] The VNI identification of each actual ONU device and the QinQ information of each actual ONU device and the ID number of the roaming group to which each actual ONU device belongs are stored in the ONU device information table item. Figure 3 Among them, the VNI identifier of the actual ONU device and the QinQ information of each actual ONU device are used as unique indexes, which can correspond to multiple roaming groups.

[0078] The terminal roaming information table entry stores the MAC address of the terminal and the ID number of the roaming group pre-bound to the terminal, such as Figure 4 The mac address is a unique index and may correspond to multiple roaming groups.

[0079] The access cloud gateway determines whether the first terminal is an authenticated terminal in the roaming area to which the first ONU device belongs according to the MAC address of the first terminal carried in the second uplink message, the relevant information of the first ONU device, and each roaming group, such as Figure 5 As shown, specifically including:

[0080] In step 301, the virtual switch receives the second uplink message, and forwards the second uplink message to the virtual client device.

[0081] In step 302, the virtual client device finds the first roaming group bound to the first terminal from the terminal roaming information entry according to the MAC address of the first terminal carried in the second uplink message.

[0082] In step 303, according to the VNI identifier of the first ONU device and the QinQ information of the first ONU device carried in the second uplink message, the second roaming group to which the first ONU device belongs is obtained from the ONU device information table item.

[0083] In step 304, it is determined whether the first roaming group is consistent with the second roaming group. If they are consistent, it can be considered that the current access location is in the roaming group where the first terminal is located, and then it is searched whether there is historical login information of the first terminal in the second roaming group. In actual use, there may be multiple first roaming groups or multiple second roaming groups. In this case, the determination of whether the first roaming group is consistent with the second roaming group is specifically: there is a first roaming group that is the same as a second roaming group.

[0084] In step 305, if the historical login information exists, it is determined that the first terminal is an authenticated terminal in the second roaming group. If the first roaming group is inconsistent with the second roaming group, or the historical login information does not exist, redirect to the portal authentication page for re-authentication.

[0085] The historical login information is recorded when the first terminal performs authentication login in the roaming area where the second roaming group is located. Figure 6 As shown, specifically including:

[0086] In step 401, when the virtual client device determines that the first terminal is not an authenticated terminal in the roaming area where the currently accessed ONU device is located, the second uplink message is redirected to the portal server so that the portal server can feedback the portal authentication page to the first terminal; the currently accessed ONU device is the ONU device accessed by the first terminal during historical login.

[0087] In step 402, after the first terminal successfully logs in and authenticates on the portal authentication page, the portal server returns an authentication success message to the virtual client device; wherein the authentication success message carries the mac address of the first terminal, the VNI identifier of the ONU device currently accessed by the first terminal, and the QinQ information of the ONU device currently accessed by the first terminal.

[0088] In step 403, the virtual client finds a corresponding roaming group from the ONU device information table item according to the VNI identifier of the ONU device currently accessed by the first terminal and the QinQ information of the ONU device currently accessed by the first terminal.

[0089] In step 404, the ID number of the roaming group and the mac address of the first terminal are recorded as historical login information in the authentication table; wherein, for a mac address, only the latest historical login information is recorded in the authentication table, that is, the latest login information is always recorded, and the authentication table has the same format as the terminal roaming information table item, the difference is: the authentication table records the relevant information of the terminal that has logged in, and the terminal roaming information table records the relevant information of the roaming group to which the terminal belongs.

[0090] In some embodiments, the campus network also needs to perform traffic auditing for billing. However, after the introduction of the virtual ONU device, the wide area network cannot identify the ONU device actually connected to the terminal, which makes auditing difficult. That is, because the terminal frequently changes access points, this brings problems to the audit. In order to solve this problem, the cloud gateway solves the audit problem by reporting the terminal location on the LAN side and the information on the WAN side together. That is, the method also includes:

[0091] After the access cloud gateway determines that the first terminal is an authenticated terminal in the roaming area where the first ONU device is located, the access cloud gateway also reports the log of the first terminal to the log audit platform on the operator side, so that the log audit platform can determine the ONU device accessed by the first terminal based on the log, thereby performing a log audit.

[0092] The log includes the login account of the first terminal, the mac address of the first terminal, the LAN side tunnel ID of the second uplink message, the LAN side private VLAN (Private VLAN, referred to as: PVLAN) identifier of the second uplink message, the LAN side user VLAN (Custom VLAN, referred to as: CVLAN) identifier of the second uplink message, the WAN side tunnel ID of the third uplink message, the WAN side PVLAN identifier of the third uplink message and the WAN side CVLAN identifier of the third uplink message.

[0093] In actual use, the method also includes: the access cloud gateway also records the ONU device accessed when each terminal authenticates and logs in according to the authentication success message, and when it is monitored that the number of times the first terminal accesses the second ONU device is greater than the preset number of times, a reminder message is sent to the first terminal through the portal server; wherein, the second ONU device is an ONU device outside the roaming group of the first terminal, and the reminder message is used to prompt the user whether to add the current area to the roaming group; if the user chooses to add the current area to the roaming group according to the reminder message, the second ONU device is added to the roaming group of the first terminal.

[0094] Considering the actual application scenario, the area where students use the campus network for entertainment is mainly concentrated in the dormitory building. Generally speaking, in order to prevent the students' entertainment network from affecting their study and office network, a cloud gateway is often used to limit the network bandwidth of each dormitory. However, in this case, when a user in a dormitory needs to download a file, the network speed of other users in the dormitory may be affected by the file download task. In order to solve this problem, this embodiment provides an optimal campus network multi-terminal roaming authentication-free method, such as Figure 7 As shown, specifically including:

[0095] In step 501, the access cloud gateway monitors the downlink messages of each dormitory and determines whether each downlink message is a file download type message; wherein the file download type is a message used to transmit files downloaded by users from the network, and the downlink message refers to a message on the LAN side after the received message from the wide area network is converted by NAT. The monitoring of the downlink messages of each dormitory specifically includes: pre-storing the corresponding relationship between each dormitory and the ONU device of each dormitory in the access cloud gateway, and when receiving the downlink message, identifying the ONU device that the downlink message needs to reach according to the QinQ information carried in the downlink message, and finding the dormitory to which the downlink message belongs from the corresponding relationship according to the ONU device.

[0096] The determination of whether each downlink message is of the file download type may be performed by pre-analyzing the commonly used types of downlink messages in the network to obtain identification words in each type of downlink message, and then using the identification words to match the downlink messages received in actual use.

[0097] In step 502, when it is detected that there is a file download type message in the first dormitory, the destination terminal that the file download type message needs to reach is found, and whether there is a second dormitory other than the first dormitory in the historically bound dormitory of the first user to which the destination terminal belongs; wherein the historically bound dormitory refers to the dormitory in the roaming group bound by the first user in history (actually, the ONU device of the dormitory is bound to the roaming group), and the ONU devices added to the roaming group by the first user in history are all recorded in the access cloud gateway; for example, if the first user added dormitory A and dormitory B to the bound roaming group one month ago, deleted dormitory B and added dormitory C two weeks ago, dormitory A is the dormitory where the first user is currently located, that is, the first dormitory, then dormitory B and dormitory C can both be considered as the second dormitory; the second dormitory can be understood as a dormitory with close contacts with the first user in actual use. The destination terminal can be understood as the terminal of the first user.

[0098] In step 503, if it is found that there is a second dormitory, the bandwidth occupancy of the downlink message in the second dormitory is calculated. If the bandwidth occupancy of the downlink message in the second dormitory is less than the preset bandwidth, the file download type message received subsequently from the first dormitory is divided into a first message and a second message according to a preset quantity ratio; wherein the access cloud gateway does not include the second message in the statistics of the first dormitory traffic; the preset bandwidth and the preset quantity ratio are obtained by technical personnel in this field based on empirical analysis. When the bandwidth occupancy of the downlink message in the second dormitory is less than the preset bandwidth, it can be considered that the current bandwidth demand of each user in the second dormitory is relatively small and there is more idle bandwidth. The setting standard of the preset quantity ratio is: while using the bandwidth of the second dormitory to assist in file downloading, it does not affect the network demand of each user in the second dormitory.

[0099] In step 504, the first message is sent to the destination terminal along the original path, and the forwarding identifier, the IP address of the second message and the relevant information of the ONU device of the second dormitory are added to the second message to generate a third message; wherein the second message carries the IP address, MAC address and relevant information of the destination terminal; wherein the destination ONU device is the ONU device currently connected to the destination terminal.

[0100] In step 505, the third message is sent to the ONU device of the second dormitory. The ONU device of the second dormitory identifies the third message according to the forwarding identifier, and forwards the third message to the destination ONU device through the local area network according to the IP address, MAC address of the destination terminal and the relevant information of the destination ONU device in the third message, so that the destination ONU device restores the third message to the first message and transmits it to the destination terminal.

[0101] Among them, when the access cloud gateway limits the bandwidth of the dormitory, it mainly limits the external network traffic, that is, it limits the bandwidth of the traffic that needs to be transmitted to the wide area network. The usual implementation method is to discard the part of the received downlink message that exceeds the bandwidth according to the time interval, thereby reducing the rate at which the destination terminal sends a response message (such as the packet confirmation ACK message in the TCP protocol) to the message sender, so that the message sender reduces the rate of sending downlink messages to the target terminal when synchronizing the message sending rate.

[0102] The present embodiment, however, diverts the file download type messages so that they reach the destination ONU device and the ONU device of the second dormitory respectively, and then are transmitted from the ONU device of the second dormitory to the destination ONU device through the local area network (through the switch, not through the access cloud gateway), and finally reach the destination terminal, so that the destination terminal can immediately return a response message to the message sender, thereby maintaining the bandwidth limit for the first dormitory and utilizing the idle bandwidth of the second dormitory to increase the speed of file downloading for the first user and prevent the file downloading of the first user from affecting the network usage of other users in the first dormitory.

[0103] Embodiment 2:

[0104] The present invention is based on the method described in Example 1, combined with specific application scenarios, and uses technical descriptions in related scenarios to illustrate the implementation process of the present invention in characteristic scenarios.

[0105] This embodiment uses Figure 8 Taking the campus network application scenario shown as an example, the campus network is connected in the form of a new metropolitan area network. The campus network roaming authentication-free method described in this embodiment specifically includes:

[0106] The operation and maintenance personnel pre-set the QinQ of the ONU device that needs to roam without authentication to a binding group (i.e. the roaming group of Example 1), such as Fig. 9 As shown, when the terminal roams between these ONUs, it only needs to be authenticated once.

[0107] Among them, for the ONU devices in a roaming group, the SSID of these ONUs needs to be set to the same; the CVLAN of these ONUs can be set to different (if the CVLAN is the same, there is a limit on the number of terminals in the binding group: a maximum of 5000 terminals); these ONUs need to be in the same tunnel group of the same virtual switch (abbreviated as: vSwitch); these ONUs need to be in the same campus; if the operator side has performed precise binding on the AAA server, the physical range of the ONU needs to be limited according to the precise binding conditions. For example, if AAA has performed precise binding on the OLT, PON board, and PON port, then these ONUs need to be on the same PON board of the same OLT and on the same PON port.

[0108] When the terminal roams between authentication-free ONUs, the option 82 reported by the OLT device will report different information according to the physical location of the ONU connected to the OLT. At present, when the cloud gateway detects that the option 82 of the same account is different, it will initiate a redial, which causes the terminal to dial frequently after roaming between authentication-free ONUs. In order to solve this problem, this embodiment also sets option 82 as insensitive information, so that even if the option 82 reported by an account changes, the cloud gateway will not re-initiate PPPoE dialing.

[0109] In actual use, the management platform will set up binding groups for ONUs that need to roam without authentication according to VNI+QinQ. There can be multiple binding groups on a vSwitch.

[0110] When the terminal traffic arrives at the access vSwitch, if the VNI+QinQ of this traffic is in the binding group, and the terminal mac is not in the QinQ conversion table (that is, the virtual VNI identifier and virtual QinQ information have not been assigned to the roaming group), the access vSwitch selects a QinQ from the QinQ of the binding group in a balanced manner for the terminal; no matter which ONU the terminal roams to in the binding group, the selected QinQ will not change, and LAN / WAN will use this QinQ; when the terminal LAN side message in the binding group enters and exits the access vSwitch, QinQ conversion is implemented according to the QinQ conversion table, such as Fig.11 As shown, Fig.11 The QinQ conversion table used is as follows Fig.10 As shown, it includes the mac address of the terminal, the virtual QinQ information (nat and QinQ) on the lan side, the ID of the tunnel group corresponding to the roaming group, the VNI identifier on the wan side and the QinQ information on the wan side; among them, the QinQ conversion table can be queried on the cloud gateway through the command line.

[0111] In specific application scenarios, the management platform can configure campus-level roaming authentication-free. This authentication-free campus is required to be on a vSwitch and in a tunnel group. The management platform sets the new city VNI+QinQ (i.e., virtual VNI identifier and virtual QinQ information) of this campus to this binding group, and sends the binding group information to the cloud gateway. If an ONU in the campus is no longer in use, the VNI+QinQ corresponding to this ONU can be deleted from the binding group. If the terminal has no traffic for more than a certain period, the management platform will initiate the process of kicking the terminal offline. When the terminal roams to an ONU outside the binding group and goes online, the management platform will initiate the process of taking the terminal and the account where the terminal is located in the binding group offline through PPPoE, and at the same time, kick the terminal offline on the portal web.

[0112] Through the method described in this embodiment, the same terminal can roam between multiple bound ONUs. After one of the ONUs passes authentication, the terminal device roams to other bound ONUs without portal authentication. The virtual wireless terminal access device (Virtual Customer Premise Equipment, referred to as: vCPE) no longer initiates PPPoE dialing when the terminal roams. These bound ONUs can be deployed on: a certain floor of a teaching building, the entire teaching building, multiple teaching buildings, and multiple teaching buildings in different campuses of the same school.

[0113] In actual application scenarios, because terminals frequently change access points, this brings problems to auditing. In order to solve auditing problems, such as Fig.12 As shown, the cloud gateway reports the terminal location on the LAN side and the information on the WAN side together, and the information reported in the log includes the LAN side information and the WAN side information.

[0114] LAN side information includes: mac, tunnel id, pvlan, cvlan and account.

[0115] The WAN side information includes: account, tunnel ID, pvlan and cvlan.

[0116] Among them, the MAC, PVLAN and CVLAN in the LAN side information are extracted from the message from the terminal, the tunnel ID is obtained according to the tunnel used by the message, and the account in the LAN side information is found from the access cloud gateway according to the tunnel ID, PVLAN and CVLAN. The access cloud gateway is configured with account binding information, that is, the corresponding binding relationship between the account and the tunnel ID, PVLAN and CVLAN.

[0117] The pvlan and cvlan in the wan side information are also extracted from the message. The tunnel id is obtained according to the tunnel used by the message. The account is found from the access cloud gateway based on the tunnel id.

[0118] The tunnel ID on the LAN side is different from the tunnel ID on the WAN side; the PVLAN and CVLAN on the LAN side may also be different from the PVLAN and CVLAN on the WAN side.

[0119] In an optional implementation, the reporting log includes account, mac, lan_tunnel id, lan_pvlan, lan_cvlan, wan_tunnel id, wan_pvlan and lan_cvlan.

[0120] Embodiment 3:

[0121] like Fig.13, which is a schematic diagram of the architecture of a campus network roaming authentication-free device according to an embodiment of the present invention. The campus network roaming authentication-free device according to this embodiment includes one or more processors 21 and a memory 22. Fig.13 A processor 21 is taken as an example.

[0122] The processor 21 and the memory 22 may be connected via a bus or other means. Fig.13 The example of connecting through bus is taken in the following.

[0123] The memory 22 is a non-volatile computer-readable storage medium that can be used to store non-volatile software programs and non-volatile computer executable programs, such as the campus network roaming authentication-free method in Example 1. The processor 21 executes the campus network roaming authentication-free method by running the non-volatile software programs and instructions stored in the memory 22.

[0124] The memory 22 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other non-volatile solid-state storage devices. In some embodiments, the memory 22 may optionally include a memory remotely arranged relative to the processor 21, and these remote memories may be connected to the processor 21 via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0125] The program instructions / modules are stored in the memory 22, and when executed by the one or more processors 21, the campus network roaming authentication-free method in the above-mentioned embodiment 1 is executed.

[0126] It is worth noting that the information interaction, execution process, etc. between the modules and units within the above-mentioned devices and systems are based on the same concept as the processing method embodiment of the present invention. The specific contents can be found in the description of the method embodiment of the present invention and will not be repeated here.

[0127] A person skilled in the art may understand that all or part of the steps in the various methods of the embodiments may be completed by instructing related hardware through a program, and the program may be stored in a computer-readable storage medium, and the storage medium may include: a read-only memory (ROM), a random access memory (RAM), a disk or an optical disk, etc.

[0128] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions and improvements made within the spirit and principles of the present invention should be included in the protection scope of the present invention.

Claims

1. A campus network roaming authentication-free method, characterized in that: include: A roaming group is pre-set for the terminal in the access cloud gateway, and each roaming group corresponds to a virtual ONU device; wherein the roaming group includes the mac information of the terminal, the relevant information of each actual ONU device in the roaming area required by the terminal, and the relevant information of the unique virtual ONU device of the roaming group; When the first ONU device receives the first uplink message from the first terminal, it adds relevant information of the first ONU device to the first uplink message, generates a second uplink message, and sends the second uplink message to the access cloud gateway; wherein the first uplink message also carries the mac address of the first terminal; The access cloud gateway determines, according to the MAC address of the first terminal carried in the second uplink message, the relevant information of the first ONU device, and each roaming group, whether the first terminal is an authenticated terminal in the roaming area to which the first ONU device belongs; If it is determined that the first terminal is an authenticated terminal in the roaming area where the first ONU device is located, the second uplink message is encapsulated into a third uplink message recognizable by the wide area network according to the relevant information of the virtual ONU device in the roaming group to which the first ONU device belongs, and the third uplink message is transmitted to the network.

2. The campus network roaming authentication-free method according to claim 1, characterized in that: The relevant information of the actual ONU device includes the VNI identification of the actual ONU device and the QinQ information of the actual ONU device; the relevant information of the virtual ONU device includes the virtual VNI identification and the virtual QinQ information; The access cloud gateway includes a virtual switch and a virtual client device, and the step of pre-setting a roaming group for the terminal in the access cloud gateway specifically includes: Storing roaming group information items, ONU device information items, and terminal roaming information items in the virtual client device; The roaming group information table entry stores the ID number of each roaming group and the virtual VNI identifier and virtual QinQ information corresponding to each roaming group; The ONU device information table item stores the VNI identification of each actual ONU device, the QinQ information of each actual ONU device, and the ID number of the roaming group to which each actual ONU device belongs; The terminal roaming information table entry stores the MAC address of the terminal and the ID number of the roaming group to which the terminal is pre-bound.

3. The campus network roaming authentication-free method according to claim 2, characterized in that: The access cloud gateway determines, according to the MAC address of the first terminal carried in the second uplink message, the relevant information of the first ONU device, and each roaming group, whether the first terminal is an authenticated terminal in the roaming area to which the first ONU device belongs, specifically including: The virtual switch receives the second uplink message, and forwards the second uplink message to the virtual client device; The virtual client device finds the first roaming group bound to the first terminal from the terminal roaming information entry according to the MAC address of the first terminal carried in the second uplink message; According to the VNI identifier of the first ONU device and the QinQ information of the first ONU device carried in the second uplink message, acquiring the second roaming group to which the first ONU device belongs from the ONU device information table item; Determine whether the first roaming group is consistent with the second roaming group, and if they are consistent, search whether there is historical login information of the first terminal in the second roaming group; If the historical login information exists, it is determined that the first terminal is an authenticated terminal in the second roaming group.

4. The campus network roaming authentication-free method according to claim 3, characterized in that: The historical login information is recorded when the first terminal performs authentication and login in the roaming area where the second roaming group is located, and specifically includes: When the virtual client device determines that the first terminal is not an authenticated terminal in the roaming area where the currently accessed ONU device is located, redirecting the second uplink message to the portal server so that the portal server feeds back a portal authentication page to the first terminal; After the first terminal successfully logs in and authenticates on the portal authentication page, the portal server returns an authentication success message to the virtual client device; wherein the authentication success message carries the mac address of the first terminal, the VNI identifier of the ONU device currently accessed by the first terminal, and the QinQ information of the ONU device currently accessed by the first terminal; The virtual client finds the corresponding roaming group from the ONU device information table item according to the VNI identifier of the ONU device currently accessed by the first terminal and the QinQ information of the ONU device currently accessed by the first terminal; The ID number of the roaming group and the MAC address of the first terminal are recorded as historical login information in the authentication table; wherein, for a MAC address, only the latest historical login information is recorded in the authentication table.

5. The campus network roaming authentication-free method according to claim 2, characterized in that: The encapsulating the second uplink message into a third uplink message identifiable by the wide area network according to the virtual ONU device related information in the roaming group to which the first ONU device belongs specifically includes: Find the corresponding WAN side VNI identifier and WAN side QinQ information according to the virtual ONU device related information in the roaming group to which the first ONU device belongs; The WAN side VNI identifier and the WAN side QinQ information are used to replace the virtual ONU device related information in the second uplink message to generate the third uplink message.

6. The campus network roaming authentication-free method according to claim 1, characterized in that: The method also includes: After determining that the first terminal is an authenticated terminal in the roaming area where the first ONU device is located, the access cloud gateway also reports the log of the first terminal to the log audit platform on the operator side, so that the log audit platform can determine the ONU device accessed by the first terminal according to the log, thereby performing log audit; Among them, the log includes the login account of the first terminal, the mac address of the first terminal, the LAN side tunnel ID of the second uplink message, the LAN side PVLAN identifier of the second uplink message, the LAN side CVLAN identifier of the second uplink message, the WAN side tunnel ID of the third uplink message, the WAN side PVLAN identifier of the third uplink message and the WAN side CVLAN identifier of the third uplink message.

7. The campus network roaming authentication-free method according to claim 1, characterized in that: The method also includes: setting the same SSID for all ONU devices located in a roaming area.

8. The campus network roaming authentication-free method according to claim 1, characterized in that: The method also includes: Set the option82_sensitive value of the roaming area in the access cloud gateway to 0 so that when the option82 field in the message sent by different ONU devices changes, the dial-up is not re-performed.

9. A non-volatile computer storage medium, characterized in that: The computer storage medium stores computer executable instructions, which are executed by one or more processors to complete the campus network roaming authentication-free method described in any one of claims 1-8.

10. A campus network roaming authentication-free device, characterized in that: include: at least one processor; And, a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the processor to execute the method for campus network roaming without authentication as described in any one of claims 1-8.

Citation Information

Patent Citations

  • Authentication-free roaming method and device

    CN117528495A

  • Campus network login method and device based on cloud gateway

    CN118713937A

  • Electronic device, and wifi-based roaming method on electronic device

    WO2022164179A1