A method and device for roaming authentication-free of a campus network

By setting up roaming groups and virtual ONU devices in the access cloud gateway, the frequent authentication problem of user terminals in the campus network when switching network environments is solved, and seamless network connection of terminals during roaming is achieved.

CN119946626BActive Publication Date: 2025-10-10WUHAN GREENET INFORMATION SERVICE
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411977959.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2025-10-10
Estimated Expiration
2044-12-31

AI Technical Summary

Technical Problem

In campus network scenarios, user terminals need to frequently perform portal authentication when switching network environments, causing inconvenience in network use.

Method used

By setting up roaming groups in the access cloud gateway, each roaming group corresponds to a virtual ONU device, and using the relevant information of the virtual ONU device to generate WAN side information, the terminal does not need to be repeatedly authenticated during the roaming process.

Benefits of technology

Campus network roaming is now free of authentication, and terminals maintain network connection during roaming, avoiding frequent portal authentication processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119946626B_ABST
    Figure CN119946626B_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of campus network, and provides a method and device for roaming authentication exemption of campus network, which comprises the following steps: setting a roaming group for a terminal in an access cloud gateway in advance, each roaming group corresponding to a virtual ONU device; when receiving a first uplink message from a first terminal, judging whether the first terminal is an authenticated terminal in a roaming area of a first ONU device; if the first terminal is an authenticated terminal in the roaming area, encapsulating the second uplink message into a third uplink message recognizable by a wide area network according to the virtual ONU device related information in the roaming group to which the first ONU device belongs, and transmitting the third uplink message to the network. The present application sets a roaming group and a virtual ONU device, and generates WAN side information using the virtual ONU device related information, so that the whole roaming group appears to be only one ONU device to the outside, and further, repeated authentication is not needed, thus realizing roaming authentication exemption of campus network.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of campus network, in particular to a campus network roaming authentication-free method and device. BACKGROUND

[0002] In the past campus network scenario, a user terminal needs to access the Internet, and must first log in to the edge portal server for verification to find a user link for accessing the Internet. Once the user terminal switches the network environment, such as switching to another dormitory or teaching building, the access ONU (Optical Network Unit, referred to as ONU for short) device changes, and therefore the portal authentication must be re-performed, the binding rules of the last login authentication are deleted, and the new link is bound, so that the network can be used again. This results in that the user needs to frequently perform portal authentication when the user is active in the campus, which brings trouble to the user's network use.

[0003] In view of this, overcoming the defects of the prior art is a problem to be solved in the technical field. SUMMARY

[0004] The technical problem to be solved by the present application is to provide a campus network roaming authentication-free method and device to realize campus network roaming authentication-free.

[0005] The present application adopts the following technical solutions:

[0006] In a first aspect, the present application provides a campus network roaming authentication-free method, comprising:

[0007] Pre-set a roaming group for a terminal in an access cloud gateway, each roaming group corresponding to a virtual ONU device; wherein the roaming group includes mac information of the terminal, related information of each actual ONU device in a roaming area required by the terminal, and related information of a virtual ONU device unique to the roaming group;

[0008] When a first ONU device receives a first uplink packet from a first terminal, the first ONU device adds related information of the first ONU device to the first uplink packet to generate a second uplink packet, and sends the second uplink packet to the access cloud gateway; wherein the first uplink packet also carries a mac address of the first terminal;

[0009] The access cloud gateway judges whether the first terminal is an authenticated terminal in the roaming area of the first ONU device according to the mac address of the first terminal, the related information of the first ONU device, and each roaming group carried in the second uplink packet;

[0010] If it is judged that the first terminal is an authenticated terminal in a roaming area of the first ONU device, the second uplink message is encapsulated into a third uplink message recognizable by a wide area network according to virtual ONU device related information in a roaming group to which the first ONU device belongs, and the third uplink message is transmitted to the network.

[0011] Preferably, the related information of the actual ONU device includes a VNI identifier of the actual ONU device and QinQ information of the actual ONU device; and the virtual ONU device related information includes a virtual VNI identifier and virtual QinQ information.

[0012] The access cloud gateway includes a virtual switch and a virtual client device, and the roaming group is set for the terminal in the access cloud gateway in advance, and specifically includes:

[0013] The roaming group information table item, the ONU device information table item and the terminal roaming information table item are stored in the virtual client device;

[0014] The ID number of each roaming group and the virtual VNI identifier and the virtual QinQ information corresponding to each roaming group are stored in the roaming group information table item;

[0015] The VNI identifier of each actual ONU device, the QinQ information of each actual ONU device and the ID number of the roaming group to which each actual ONU device belongs are stored in the ONU device information table item;

[0016] The mac address of the terminal and the ID number of the roaming group to which the terminal is bound in advance are stored in the terminal roaming information table item.

[0017] Preferably, the access cloud gateway judges whether the first terminal is an authenticated terminal in a roaming area of the first ONU device according to the mac address of the first terminal carried in the second uplink message, the related information of the first ONU device and each roaming group, and specifically includes:

[0018] The virtual switch receives the second uplink message and forwards the second uplink message to the virtual client device;

[0019] The virtual client device finds the first roaming group to which the first terminal is bound from the terminal roaming information table item according to the mac address of the first terminal carried in the second uplink message;

[0020] The second roaming group to which the first ONU device belongs is obtained from the ONU device information table item according to the VNI identifier of the first ONU device and the QinQ information of the first ONU device carried in the second uplink message;

[0021] determining whether the first roaming group and the second roaming group are consistent, and if they are consistent, searching for historical login information of the first terminal in the second roaming group;

[0022] If the historical login information exists, it is determined that the first terminal is an authenticated terminal in the second roaming group.

[0023] Preferably, the historical login information is recorded when the first terminal performs historical authentication and login in the roaming area where the second roaming group is located, and specifically includes:

[0024] When the virtual client device determines that the first terminal is not an authenticated terminal in the roaming area where the currently accessed ONU device is located, redirecting the second uplink message to the portal server so that the portal server feeds back a portal authentication page to the first terminal;

[0025] After the first terminal successfully logs in and authenticates on the portal authentication page, the portal server returns an authentication success message to the virtual client device; wherein the authentication success message carries the MAC address of the first terminal, the VNI identifier of the ONU device currently accessed by the first terminal, and the QinQ information of the ONU device currently accessed by the first terminal;

[0026] The virtual client finds the corresponding roaming group from the ONU device information table according to the VNI identifier of the ONU device currently accessed by the first terminal and the QinQ information of the ONU device currently accessed by the first terminal;

[0027] The ID number of the roaming group and the MAC address of the first terminal are recorded as historical login information in an authentication table; wherein, for a MAC address, only the latest historical login information is recorded in the authentication table.

[0028] Preferably, encapsulating the second uplink message into a third uplink message identifiable by the wide area network according to the relevant information of the virtual ONU device in the roaming group to which the first ONU device belongs specifically includes:

[0029] Find the corresponding WAN side VNI identifier and WAN side QinQ information according to the virtual ONU device related information in the roaming group to which the first ONU device belongs;

[0030] The virtual ONU device related information in the second uplink message is replaced by the WAN side VNI identifier and the WAN side QinQ information to generate the third uplink message.

[0031] Preferably, the method further comprises:

[0032] After determining that the first terminal is an authenticated terminal in the roaming area where the first ONU device is located, the access cloud gateway also reports the log of the first terminal to the log audit platform on the operator side, so that the log audit platform can determine the ONU device accessed by the first terminal based on the log, thereby performing a log audit;

[0033] Among them, the log includes the login account of the first terminal, the MAC address of the first terminal, the LAN side tunnel ID of the second uplink message, the LAN side PVLAN identifier of the second uplink message, the LAN side CVLAN identifier of the second uplink message, the WAN side tunnel ID of the third uplink message, the WAN side PVLAN identifier of the third uplink message and the WAN side CVLAN identifier of the third uplink message.

[0034] Preferably, the method further comprises: setting the same SSID for all ONU devices located in a roaming area.

[0035] Preferably, the method further comprises:

[0036] Set the option82_sensitive value of the roaming area in the access cloud gateway to 0 so that when the option82 field in the message sent by different ONU devices changes, redialing is not performed.

[0037] In a second aspect, the present invention further provides a campus network roaming authentication-free device, which is used to implement the campus network roaming authentication-free method described in the first aspect, and the device includes:

[0038] At least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the processor to execute the method for campus network roaming without authentication as described in the first aspect.

[0039] In a third aspect, the present invention further provides a non-volatile computer storage medium, wherein the computer storage medium stores computer-executable instructions, and the computer-executable instructions are executed by one or more processors to complete the method described in the first aspect.

[0040] In a fourth aspect, a chip is provided, comprising: a processor and an interface, for calling and running a computer program stored in a memory to execute the method of the first aspect.

[0041] In a fifth aspect, a computer program product comprising instructions is provided, which, when executed on a computer or a processor, causes the computer or the processor to execute the method of the first aspect.

[0042] The present application sets a roaming group and a virtual ONU device, and after verifying that the first terminal is an authenticated terminal, generates WAN side information using the virtual ONU device related information, so that the whole roaming group appears to the outside as only one ONU device (i.e. the virtual ONU device), and further does not need to perform repeated authentication, but uses the original link to perform network communication, and realizes the campus network roaming authentication exemption. BRIEF DESCRIPTION OF DRAWINGS

[0043] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed to be used in the embodiments of the present application will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application, and other drawings can also be obtained according to these drawings without creative labor for those skilled in the art.

[0044] Figure 1 is a flowchart of a first campus network roaming authentication exemption method provided by the embodiments of the present application;

[0045] Figure 2 is a roaming group information table item of a campus network roaming authentication exemption method provided by the embodiments of the present application;

[0046] Figure 3 is an ONU device information table item of a campus network roaming authentication exemption method provided by the embodiments of the present application;

[0047] Figure 4 is a terminal roaming information table item of a campus network roaming authentication exemption method provided by the embodiments of the present application;

[0048] Figure 5 is a flowchart of a second campus network roaming authentication exemption method provided by the embodiments of the present application;

[0049] Figure 6 is a flowchart of a third campus network roaming authentication exemption method provided by the embodiments of the present application;

[0050] Figure 7 is a flowchart of a fourth campus network roaming authentication exemption method provided by the embodiments of the present application;

[0051] Figure 8 is a campus network roaming authentication exemption method provided by the embodiments of the present application;

[0052] Figure 9 is a campus network roaming authentication exemption method provided by the embodiments of the present application;

[0053] Figure 10is a schematic diagram of a QinQ conversion table in a campus network roaming free authentication method provided by an embodiment of the present application;

[0054] Figure 11 is a schematic diagram of a campus network roaming free authentication method provided by an embodiment of the present application;

[0055] Figure 12 is a schematic diagram of a campus network roaming free authentication method provided by an embodiment of the present application;

[0056] Figure 13 is a schematic diagram of a campus network roaming free authentication device provided by an embodiment of the present application. DETAILED DESCRIPTION

[0057] In order to make the objects, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and do not limit the present application.

[0058] Unless otherwise required by context, the term "comprises" in the specification and claims is to be construed as open-ended, i.e. as "comprises but not limited to". In the description of the specification, the terms "one embodiment", "some embodiments", "exemplary embodiment", "example", "specific example" or "some examples" are intended to mean that a particular feature, structure, material or characteristic included in at least one embodiment or example of the present disclosure. The illustrative representation of the above terms does not necessarily mean the same embodiment or example. In addition, the specific features, structures, materials or characteristics described can be included in any one or more embodiments or examples in any appropriate manner, i.e. although they are carried in the embodiments or examples of the above terms due to the order of appearance and location, they are not limited to the combination of one embodiment or example.

[0059] In the description of the present application, the terms "first", "second" are only used for description purposes, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of indicated technical features. Therefore, the features limited by "first", "second" can be explicitly or implicitly included in one or more features. In the description of the embodiments of the present disclosure, unless otherwise specified, the meaning of "multiple" is two or more. In addition, for example, in the description, the same type of nouns can also be described as two independent individuals by adding "A", "B" at the end, in which case the features limited by "A", "B" are only used for the purpose of distinguishing the same type of individual description, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of indicated technical features.

[0060] In the description of the present invention, the expression "A and / or B" (where A and B are used to formally represent specific characteristic contents) will be involved, and the corresponding expressions include the following three combinations: only A, only B, and a combination of A and B.

[0061] As used herein, "about," "substantially," or "approximately" includes the stated value and an average value that is within an acceptable range of deviation from the particular value as determined by one of ordinary skill in the art taking into account the measurements in question and the errors associated with the measurement of the particular quantity (i.e., the limitations of the measurement system).

[0062] In addition, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.

[0063] Embodiment 1:

[0064] Embodiment 1 of the present invention provides a campus network roaming authentication-free method, such as Figure 1 Shown, including:

[0065] In step 201, a roaming group is pre-set for the terminal in the access cloud gateway, and each roaming group corresponds to a virtual ONU device; wherein the roaming group includes the MAC information of the terminal, the relevant information of each actual ONU device in the roaming area required by the terminal, and the relevant information of the virtual ONU device unique to the roaming group; the relevant information can be understood as identification information for identifying the corresponding device, and the virtual ONU device can be understood as not being a device actually existing in the network, but a virtual device used to represent all actual ONU devices in the corresponding area, and the virtual device has the same type of relevant information as the actual ONU device, such as the identification information of the actual ONU device includes the VNI identifier (full name: VXLAN Network Identity). Identifier, Chinese meaning is: identifier in VXLAN network) and QinQ information, then the virtual ONU device also has VNI identification and QinQ information (that is, the virtual ONU device related information), and is different from other virtual ONU devices and actual ONU devices. The VNI identification and QinQ information of the virtual ONU device are allocated when the roaming group is established. The pre-setting of a roaming group for the terminal in the access cloud gateway can be obtained by technical personnel in this field based on the demand analysis of personnel flow in the campus network. For example, for the student group, the student dormitory, cafeteria and teaching building are regarded as a roaming area, and the corresponding roaming group is set; for the teacher group, the teaching building, cafeteria and staff dormitory are regarded as a roaming area, and the corresponding roaming group is set.

[0066] In step 202, upon receiving a first uplink message from a first terminal, the first ONU device adds relevant information about the first ONU device to the first uplink message, generates a second uplink message, and sends the second uplink message to the access cloud gateway; wherein the first uplink message also carries the MAC address of the first terminal; the first ONU device is the ONU device accessed by the first terminal. In actual use, a roaming group also corresponds to a tunnel group, which includes tunnels used by each ONU device bound to the roaming group to transmit messages. The tunnel is used to isolate messages from different roaming groups, that is, to isolate messages. For example, the IP and QinQ information of messages in different tunnels can be repeated. If there is no tunnel isolation, the repeated IP and QinQ information of the messages will cause confusion in traffic identification. The ID of the tunnel group is also added to the second uplink message.

[0067] In step 203, the access cloud gateway determines whether the first terminal is an authenticated terminal in the roaming area to which the first ONU device belongs based on the MAC address of the first terminal carried in the second uplink message, the relevant information of the first ONU device, and each roaming group; that is, whether the user has performed portal authentication in the roaming area and the authentication information is still valid.

[0068] In step 204, if it is determined that the first terminal is an authenticated terminal within the roaming area where the first ONU device is located, the second uplink message is encapsulated into a third uplink message recognizable by the wide area network based on the relevant information of the virtual ONU devices in the roaming group to which the first ONU device belongs, and the third uplink message is transmitted to the network. If it is determined that the first terminal is not an authenticated terminal within the roaming area where the first ONU device is located, the user is redirected to the portal authentication page for authentication.

[0069] Among them, the process of encapsulating the second uplink message into a third uplink message identifiable by the wide area network based on the virtual ONU device related information in the roaming group to which the first ONU device belongs specifically includes: finding the corresponding WAN side VNI identifier and WAN side QinQ information based on the virtual ONU device related information in the roaming group to which the first ONU device belongs; using the wide area network (abbreviated as: WAN) side VNI identifier and WAN side QinQ information to replace the virtual ONU device related information in the second uplink message to generate the third uplink message. The access cloud gateway includes a virtual switch and a virtual client device, and the process of generating the third uplink message is mainly completed by the virtual client device. In the virtual client device, one virtual ONU device corresponds to a unique local area network (abbreviated as: LAN) side VNI identifier and LAN side QinQ information, and a WAN side VNI identifier and WAN side QinQ information.

[0070] This embodiment sets up a roaming group and a virtual ONU device, and after verifying that the first terminal is an authenticated terminal, uses the virtual ONU device-related information to generate WAN side information, so that the entire roaming group appears to the outside as having only one ONU device (i.e., the virtual ONU device). There is no need for repeated authentication, but the original link is used for network communication, thereby realizing authentication-free roaming on the campus network.

[0071] In actual use, different ONU devices have different service set identifiers (SSIDs), which may also trigger the first terminal to re-dial authentication. Therefore, the method also includes: setting the same SSID for all ONU devices located in a roaming area, so that the first terminal side does not perceive changes in the ONU device.

[0072] Furthermore, when a terminal roams between authentication-free ONUs, the Option 82 reported by the Optical Line Terminal (OLT) device will report different information depending on the physical location of the ONU connected to the OLT device. In the prior art, when the cloud gateway detects that the Option 82 for the same account is different, it will initiate a redial. This results in the terminal still needing to dial frequently when roaming between authentication-free ONUs. To solve this problem, the method also includes: setting the option82_sensitive value of the roaming area in the access cloud gateway to 0, so that when the Option 82 field in the message sent by different ONU devices changes, the dialing is not performed again. Option82_sensitive can be understood as a field used to identify whether the dialing action is sensitive to the Option 82 field. That is, when the value of option82_sensitive is 1, the dialing action is sensitive to the Option 82 field and a redial is performed when a change in the Option 82 field is detected; when the value of option82_sensitive is 0, the dialing action is not sensitive to the Option 82 field and a redial is performed when a change in the Option 82 field is detected.

[0073] And, if the operator side performs precision binding on an Authentication, Authorization, Accounting (AAA) server, the physical range of the roaming area needs to be limited according to the precision binding condition, such as the AAA performing precision binding on an OLT device, a Passive Optical Network (PON) board, and a PON port, then the ONUs in the roaming area need to be on the same PON board of the same OLT and on the same PON port.

[0074] In an actual application scenario, the related information of the actual ONU device includes a VNI identifier of the actual ONU device and QinQ information of the actual ONU device; the related information of the virtual ONU device includes a virtual VNI identifier and virtual QinQ information; it is to be noted that the VNI identifier of the actual ONU device and the QinQ information of the actual ONU device, the virtual VNI identifier and the virtual QinQ information all refer to LAN-side VNI identifiers and LAN-side QinQ information. In actual use, the QinQ information also appears as Network Address Translation (NAT) plus QinQ.

[0075] The access cloud gateway includes a virtual switch (vSwitch) and a virtual customer-premises equipment (vCPE), and the roaming groups are set for the terminals in the access cloud gateway in advance, specifically including: storing a roaming group information table item, an ONU device information table item, and a terminal roaming information table item in the vCPE.

[0076] The roaming group information table item stores the ID numbers of the roaming groups and the virtual VNI identifiers and virtual QinQ information corresponding to the roaming groups, as shown in FIG. 4. Figure 2 The roaming group ID is a unique index.

[0077] The ONU device information table item stores the VNI identifiers of the actual ONU devices and the QinQ information of the actual ONU devices and the ID numbers of the roaming groups to which the actual ONU devices belong, as shown in FIG. 5. Figure 3 The VNI identifiers of the actual ONU devices and the QinQ information of the actual ONU devices are used as unique indexes, and can correspond to multiple roaming groups.

[0078] The terminal roaming information table item stores the mac addresses of the terminals and the ID numbers of the roaming groups to which the terminals are bound in advance, as shown in FIG. 6. Figure 4 The mac address is a unique index, and can correspond to multiple roaming groups.

[0079] The access cloud gateway determines whether the first terminal is an authenticated terminal in the roaming area to which the first ONU device belongs based on the MAC address of the first terminal carried in the second uplink message, the relevant information of the first ONU device, and each roaming group. Figure 5 As shown, specifically including:

[0080] In step 301, the virtual switch receives the second uplink message and forwards the second uplink message to the virtual client device.

[0081] In step 302, the virtual client device finds the first roaming group bound to the first terminal from the terminal roaming information entry according to the MAC address of the first terminal carried in the second uplink message.

[0082] In step 303, according to the VNI identifier of the first ONU device and the QinQ information of the first ONU device carried in the second uplink message, the second roaming group to which the first ONU device belongs is obtained from the ONU device information table.

[0083] In step 304, a determination is made as to whether the first roaming group and the second roaming group are consistent. If so, it is determined that the current access location is within the roaming group of the first terminal. A search is then performed to determine whether there is historical login information of the first terminal within the second roaming group. In actual use, there may be multiple first roaming groups or multiple second roaming groups. In this case, determining whether the first roaming group and the second roaming group are consistent specifically means that there exists a first roaming group that is consistent with a second roaming group.

[0084] In step 305, if the historical login information exists, it is determined that the first terminal is an authenticated terminal in the second roaming group. If the first roaming group is inconsistent with the second roaming group, or the historical login information does not exist, the user is redirected to the portal authentication page for re-authentication.

[0085] The historical login information is recorded when the first terminal performs authentication and login in the roaming area where the second roaming group is located. Figure 6 As shown, specifically including:

[0086] In step 401, when the virtual client device determines that the first terminal is not an authenticated terminal in the roaming area where the currently accessed ONU device is located, the second uplink message is redirected to the portal server so that the portal server can feedback the portal authentication page to the first terminal; the currently accessed ONU device is the ONU device that the first terminal accessed during the historical login.

[0087] In step 402, after the first terminal successfully logs in and authenticates on the portal authentication page, the portal server returns an authentication success message to the virtual client device; wherein, the authentication success message carries the MAC address of the first terminal, the VNI identifier of the ONU device currently accessed by the first terminal, and the QinQ information of the ONU device currently accessed by the first terminal.

[0088] In step 403, the virtual client finds a corresponding roaming group from the ONU device information table according to the VNI identifier of the ONU device currently accessed by the first terminal and the QinQ information of the ONU device currently accessed by the first terminal.

[0089] In step 404, the ID number of the roaming group and the MAC address of the first terminal are recorded as historical login information in the authentication table; wherein, for a MAC address, only the latest historical login information is recorded in the authentication table, that is, the latest login information is always recorded. The authentication table has the same format as the terminal roaming information table item, the difference being that the authentication table records the relevant information of the terminal that has logged in, and the terminal roaming information table records the relevant information of the roaming group to which the terminal belongs.

[0090] In some embodiments, the campus network also needs to perform traffic auditing for billing purposes. However, after the introduction of virtual ONU devices, the wide area network cannot identify the ONU devices to which the terminal is actually connected, resulting in auditing difficulties. That is, because the terminal frequently changes access points, this poses a problem for the audit. To solve this problem, the cloud gateway solves the audit problem by reporting the terminal location on the LAN side and the information on the WAN side together. That is, the method further includes:

[0091] After the access cloud gateway determines that the first terminal is an authenticated terminal in the roaming area where the first ONU device is located, it also reports the log of the first terminal to the log audit platform on the operator side, so that the log audit platform can determine the ONU device accessed by the first terminal based on the log, and thus perform log audit.

[0092] The log includes the login account of the first terminal, the MAC address of the first terminal, the LAN side tunnel ID of the second uplink message, the LAN side private VLAN (Private VLAN, abbreviated as: PVLAN) identifier of the second uplink message, the LAN side user-side VLAN (Custom VLAN, abbreviated as: CVLAN) identifier of the second uplink message, the WAN side tunnel ID of the third uplink message, the WAN side PVLAN identifier of the third uplink message, and the WAN side CVLAN identifier of the third uplink message.

[0093] In actual use, the method also includes: the access cloud gateway also records the ONU device accessed by each terminal when authenticating and logging in based on the authentication success message, and when it is monitored that the number of times the first terminal accesses the second ONU device is greater than the preset number, a reminder message is sent to the first terminal through the portal server; wherein, the second ONU device is an ONU device outside the roaming group of the first terminal, and the reminder message is used to prompt the user whether to add the current area to the roaming group; if the user chooses to add the current area to the roaming group according to the reminder message, the second ONU device is added to the roaming group of the first terminal.

[0094] Taking into account the actual application scenario, the area where students use the campus network for entertainment is mainly concentrated in the dormitory building. Generally speaking, in order to prevent students' entertainment network from affecting their study and office network, a cloud gateway is often used to limit the network bandwidth of each dormitory. However, in this case, when a user in a dormitory needs to download a file, the file download task may affect the network speed of other users in the dormitory. In order to solve this problem, this embodiment provides an optimal campus network multi-terminal roaming authentication-free method, such as Figure 7 As shown, specifically including:

[0095] In step 501, the access cloud gateway monitors the downlink messages of each dormitory and determines whether each downlink message is a file download type message; wherein, the file download type is a message used to transmit files downloaded by users from the network, and the downlink message refers to a message on the LAN side after performing corresponding NAT conversion on the message received from the wide area network. The monitoring of the downlink messages of each dormitory specifically includes: pre-storing the corresponding relationship between each dormitory and the ONU device of each dormitory in the access cloud gateway, and when receiving the downlink message, identifying the ONU device that the downlink message needs to reach based on the QinQ information carried in the downlink message, and finding the dormitory to which the downlink message belongs from the corresponding relationship based on the ONU device.

[0096] The determination of whether each downlink message is of the file download type may be performed by pre-analyzing downlink messages of commonly used types in the network to obtain identification words in each type of downlink message, and then using the identification words to match the downlink messages received in actual use.

[0097] In step 502, when a file download type message is detected in the first dormitory, the destination terminal to which the file download type message is to be sent is found, and a search is performed to determine whether there is a second dormitory other than the first dormitory in the historically bound dormitories of the first user to which the destination terminal belongs. The historically bound dormitory refers to a dormitory in a roaming group to which the first user has historically bound (actually, the ONU devices in the dormitory are bound to the roaming group). All ONU devices added to the roaming group by the first user are recorded in the access cloud gateway. For example, if the first user added dormitory A and dormitory B to the bound roaming group a month ago, and deleted dormitory B and added dormitory C two weeks ago, dormitory A is the first user's current dormitory, i.e., the first dormitory. Then, dormitory B and dormitory C can both be considered as the second dormitory. In actual use, the second dormitory can be understood as a dormitory with which the first user has close contact. The destination terminal can be understood as the first user's terminal.

[0098] In step 503, if it is found that there is a second dormitory, the bandwidth occupancy of the downlink message in the second dormitory is calculated. If the bandwidth occupancy of the downlink message in the second dormitory is less than the preset bandwidth, the file download type message received subsequently from the first dormitory is divided into the first message and the second message according to the preset quantity ratio; wherein, the access cloud gateway does not include the second message in the statistics of the first dormitory traffic; the preset bandwidth and the preset quantity ratio are obtained by technical personnel in this field based on empirical analysis. When the bandwidth occupancy of the downlink message in the second dormitory is less than the preset bandwidth, it can be considered that the current bandwidth demand of each user in the second dormitory is relatively small and there is more idle bandwidth. The setting standard of the preset quantity ratio is: while using the bandwidth of the second dormitory to assist in file downloading, it does not affect the network demand of each user in the second dormitory.

[0099] In step 504, the first message is sent to the destination terminal along the original path, and the forwarding identifier, the IP address of the second message, and the relevant information of the ONU device of the second dormitory are added to the second message to generate a third message; wherein, the second message carries the IP address, MAC address and relevant information of the destination terminal; wherein, the destination ONU device is the ONU device currently accessed by the destination terminal.

[0100] In step 505, the third message is sent to the ONU device of the second dormitory. The ONU device of the second dormitory identifies the third message according to the forwarding identifier, and forwards the third message to the destination ONU device through the local area network according to the IP address, MAC address and relevant information of the destination terminal in the third message, so that the destination ONU device restores the third message to the first message and transmits it to the destination terminal.

[0101] The access cloud gateway mainly limits the external network flow when limiting the bandwidth of the dormitory, that is, limits the flow to be transmitted to the wide area network, and the common implementation manner is to discard the part exceeding the bandwidth in the received downlink message according to the time interval, so as to reduce the rate of the target terminal to the message sending end for sending a response message (such as an ack message in the tcp protocol), so that the message sending end reduces the rate of sending the downlink message to the target terminal when synchronizing the message sending rate.

[0102] The embodiment divides the file download type message into two parts, one part reaches the target ONU device and the second ONU device of the second dormitory, and the other part reaches the target ONU device through the local area network (through the switch and not through the access cloud gateway) by the second ONU device of the second dormitory, and finally reaches the target terminal, so that the target terminal can return the response message to the message sending end in time, and then the speed of the file download of the first user is improved by using the idle bandwidth of the second dormitory while the bandwidth limitation of the first dormitory is retained, and the influence of the file download of the first user on the network use of other users in the first dormitory is avoided.

[0103] Embodiment 2:

[0104] The embodiment is based on the method described in embodiment 1, combined with specific application scenarios, and the implementation process in the specific scenario of the application is described by the technical description in the related scenario.

[0105] The embodiment takes the campus network application scenario shown in Figure 8 as an example, the campus network is connected and implemented in the mode of a new metropolitan area network, and the campus network roaming authentication-free method described in the embodiment specifically includes:

[0106] The operation and maintenance personnel pre-set the Qinq of the ONU device that needs to roam and authenticate-free into a binding group (that is, the roaming group in embodiment 1), as shown in Figure 9 so that the terminal only needs to be authenticated once when roaming between these ONUs.

[0107] Among them, for the ONU devices in a roaming group, the SSIDs of these ONUs need to be set to be the same; the CVLANs of these ONUs can be set to be different (if the CVLANs are the same, there is a limit on the number of binding group terminals: a maximum of 5000 terminals); these ONUs need to be in the same tunnel group of the same virtual switch (abbreviated as: vSwitch); these ONUs need to be in the same school district; if the operator side has done fine binding on the AAA server, the physical range of the ONU needs to be limited according to the fine binding condition, such as the OLT, PON board and PON port of the AAA, which need to be in the same OLT, the same PON board and the same PON port.

[0108] When a terminal roams between authentication-free ONUs, the Option 82 information reported by the OLT will vary depending on the physical location of the ONU within the OLT. Currently, if the cloud gateway detects different Option 82 values ​​for the same account, it will initiate a redial. This can cause terminals to dial frequently after roaming between authentication-free ONUs. To address this issue, this embodiment sets Option 82 to non-sensitive information. This prevents the cloud gateway from re-initiating PPPoE dialing even if the Option 82 value reported for an account changes.

[0109] In actual use, the management platform will set up binding groups for ONUs that need to roam without authentication according to VNI+QinQ. There can be multiple binding groups on a vSwitch.

[0110] When the terminal traffic arrives at the access vSwitch, if the VNI+QinQ of this traffic is in the binding group and the terminal MAC is not in the QinQ conversion table (that is, the virtual VNI identifier and virtual QinQ information have not been assigned to the roaming group), the access vSwitch selects a QinQ from the QinQ of the binding group in a balanced manner for the terminal; no matter which ONU the terminal roams to in the binding group, the selected QinQ will not change, and LAN / WAN will use this QinQ; when the LAN-side messages of the terminal in the binding group enter and exit the access vSwitch, QinQ conversion is implemented according to the QinQ conversion table, such as Figure 11 As shown, Figure 11 The QinQ conversion table used is as follows Figure 10 As shown, it includes the terminal's MAC address, the virtual QinQ information (NAT and QinQ) on the LAN side, the ID of the tunnel group corresponding to the roaming group, the VNI identifier on the WAN side, and the QinQ information on the WAN side; among them, the QinQ conversion table can be queried through the command line on the cloud gateway.

[0111] In specific application scenarios, the management platform can configure campus-level roaming authentication-free. This authentication-free campus is required to be on a vSwitch and in a tunnel group; the management platform sets the new city VNI+QinQ (i.e., virtual VNI identifier and virtual QinQ information) of this campus to this binding group, and sends the binding group information to the cloud gateway; if an ONU in the campus is no longer used, the VNI+QinQ corresponding to this ONU can be deleted from the binding group; if the terminal has no traffic for more than a certain period, the management platform will initiate the offline kicking of this terminal; when the terminal roams to an ONU outside the binding group and goes online, the management platform will initiate the offline PPPoE of this terminal and the account where this terminal is located in the binding group, and at the same time, the terminal will be kicked offline on the portal web.

[0112] The method described in this embodiment enables a single terminal to roam between multiple bound ONUs. After passing authentication on one ONU, the terminal can roam to other bound ONUs without further portal authentication. The virtual customer premises equipment (vCPE) also eliminates the need for PPPoE dialing during roaming. These bound ONUs can be deployed on a single floor of a teaching building, across an entire building, across multiple buildings, or even across multiple buildings on different campuses within the same school.

[0113] In actual application scenarios, because terminals frequently change access points, this brings problems to auditing. In order to solve the auditing problem, Figure 12 As shown, the cloud gateway reports the LAN side terminal location and the WAN side information together, and the information reported in the log includes the LAN side information and the WAN side information.

[0114] LAN side information includes: MAC, tunnel ID, PVLAN, CVLAN and account.

[0115] WAN side information includes: account, tunnel ID, PVLAN and CVLAN.

[0116] Among them, the MAC, PVLAN and CVLAN in the LAN side information are extracted from the message from the terminal, the tunnel ID is obtained according to the tunnel used by the message, and the account in the LAN side information is found from the access cloud gateway based on the tunnel ID, PVLAN and CVLAN. The access cloud gateway is configured with account binding information, that is, the corresponding binding relationship between the account and the tunnel ID, PVLAN and CVLAN.

[0117] The PVLAN and CVLAN in the WAN-side information are also extracted from the message. The tunnel ID is obtained based on the tunnel used by the message. The account is found from the access cloud gateway based on the tunnel ID.

[0118] The tunnel ID on the LAN side is different from the tunnel ID on the WAN side; the PVLAN and CVLAN on the LAN side may also be different from the PVLAN and CVLAN on the WAN side.

[0119] In an optional implementation, the reporting log includes account number, mac, lan_tunnel id, lan_pvlan, lan_cvlan, wan_tunnel id, wan_pvlan and lan_cvlan.

[0120] Example 3:

[0121] like Figure 13FIG. 1 is a schematic diagram of the architecture of a campus network roaming authentication-free device according to an embodiment of the present invention. The campus network roaming authentication-free device according to this embodiment includes one or more processors 21 and a memory 22. Figure 13 A processor 21 is taken as an example.

[0122] The processor 21 and the memory 22 may be connected via a bus or other means. Figure 13 The bus connection is taken as an example.

[0123] The memory 22, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs and non-volatile computer executable programs, such as the campus network roaming authentication-free method in Example 1. The processor 21 executes the campus network roaming authentication-free method by running the non-volatile software programs and instructions stored in the memory 22.

[0124] The memory 22 may include high-speed random access memory and non-volatile memory, such as at least one disk storage device, flash memory device, or other non-volatile solid-state memory device. In some embodiments, the memory 22 may optionally include a memory remotely located relative to the processor 21, and such remote memory may be connected to the processor 21 via a network. Examples of such networks include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0125] The program instructions / modules are stored in the memory 22 and, when executed by the one or more processors 21 , execute the campus network roaming authentication-free method in the above-mentioned embodiment 1.

[0126] It is worth noting that the information interaction, execution process, etc. between the modules and units within the above-mentioned devices and systems are based on the same concept as the processing method embodiment of the present invention. The specific content can be found in the description of the method embodiment of the present invention and will not be repeated here.

[0127] Those skilled in the art will understand that all or part of the steps in the various methods of the embodiments can be completed by instructing related hardware through a program, and the program can be stored in a computer-readable storage medium, which may include: read-only memory (ROM), random access memory (RAM), a disk or an optical disk, etc.

[0128] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions and improvements made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A campus network roaming authentication-free method, characterized in that: include: A roaming group is pre-set for the terminal in the access cloud gateway, and each roaming group corresponds to a virtual ONU device; wherein the relevant information of the roaming group includes the MAC information of the terminal, the relevant information of each actual ONU device in the roaming area required by the terminal, and the relevant information of the unique virtual ONU device of the roaming group; When the first ONU device receives the first uplink message from the first terminal, it adds relevant information of the first ONU device to the first uplink message, generates a second uplink message, and sends the second uplink message to the access cloud gateway; wherein the first uplink message also carries the MAC address of the first terminal; The access cloud gateway determines, based on the MAC address of the first terminal carried in the second uplink message, the relevant information of the first ONU device, and each roaming group, whether the first terminal is an authenticated terminal in the roaming area to which the first ONU device belongs; If it is determined that the first terminal is an authenticated terminal in the roaming area to which the first ONU device belongs, the second uplink message is encapsulated into a third uplink message recognizable by the wide area network according to the relevant information of the virtual ONU device in the roaming group to which the first ONU device belongs, and the third uplink message is transmitted to the network.

2. The campus network roaming authentication-free method according to claim 1, characterized in that: The relevant information of the actual ONU device includes the VNI identifier of the actual ONU device and the QinQ information of the actual ONU device; the relevant information of the virtual ONU device includes the virtual VNI identifier and the virtual QinQ information; The access cloud gateway includes a virtual switch and a virtual client device, and the step of pre-setting a roaming group for the terminal in the access cloud gateway specifically includes: Storing roaming group information items, ONU device information items, and terminal roaming information items in the virtual client device; The roaming group information table entry stores the ID number of each roaming group and the virtual VNI identifier and virtual QinQ information corresponding to each roaming group; The ONU device information table item stores the VNI identification of each actual ONU device, the QinQ information of each actual ONU device, and the ID number of the roaming group to which each actual ONU device belongs; The terminal roaming information table entry stores the MAC address of the terminal and the ID number of the roaming group to which the terminal is pre-bound.

3. The campus network roaming authentication-free method according to claim 2, characterized in that: The access cloud gateway determines, based on the MAC address of the first terminal carried in the second uplink message, relevant information of the first ONU device, and each roaming group, whether the first terminal is an authenticated terminal in the roaming area to which the first ONU device belongs, specifically including: The virtual switch receives the second uplink message, and forwards the second uplink message to the virtual client device; The virtual client device finds the first roaming group bound to the first terminal from the terminal roaming information entry according to the MAC address of the first terminal carried in the second uplink message; Acquire, from the ONU device information table entry, the second roaming group to which the first ONU device belongs, according to the VNI identifier of the first ONU device and the QinQ information of the first ONU device carried in the second uplink message; determining whether the first roaming group and the second roaming group are consistent, and if they are consistent, searching for historical login information of the first terminal in the second roaming group; If the historical login information exists, it is determined that the first terminal is an authenticated terminal in the second roaming group.

4. The campus network roaming authentication-free method according to claim 3, characterized in that: The historical login information is recorded when the first terminal performs authentication and login in the roaming area to which the second roaming group belongs, and specifically includes: When the virtual client device determines that the first terminal is not an authenticated terminal in the roaming area to which the currently accessed ONU device belongs, redirecting the second uplink message to the portal server so that the portal server feeds back a portal authentication page to the first terminal; After the first terminal successfully logs in and authenticates on the portal authentication page, the portal server returns an authentication success message to the virtual client device; wherein the authentication success message carries the MAC address of the first terminal, the VNI identifier of the ONU device currently accessed by the first terminal, and the QinQ information of the ONU device currently accessed by the first terminal; The virtual client finds the corresponding roaming group from the ONU device information table according to the VNI identifier of the ONU device currently accessed by the first terminal and the QinQ information of the ONU device currently accessed by the first terminal; The ID number of the roaming group and the MAC address of the first terminal are recorded as historical login information in an authentication table; wherein, for a MAC address, only the latest historical login information is recorded in the authentication table.

5. The campus network roaming authentication-free method according to claim 2, characterized in that: The step of encapsulating the second uplink message into a third uplink message identifiable by the wide area network according to the relevant information of the virtual ONU device in the roaming group to which the first ONU device belongs, specifically includes: Find the corresponding WAN side VNI identifier and WAN side QinQ information according to the virtual ONU device related information in the roaming group to which the first ONU device belongs; The virtual ONU device related information in the second uplink message is replaced by the WAN side VNI identifier and the WAN side QinQ information to generate the third uplink message.

6. The campus network roaming authentication-free method according to claim 1, characterized in that: The method also includes: After determining that the first terminal is an authenticated terminal in the roaming area to which the first ONU device belongs, the access cloud gateway also reports the log of the first terminal to the log audit platform on the operator side, so that the log audit platform can determine the ONU device accessed by the first terminal based on the log, thereby performing a log audit; Among them, the log includes the login account of the first terminal, the MAC address of the first terminal, the LAN side tunnel ID of the second uplink message, the LAN side PVLAN identifier of the second uplink message, the LAN side CVLAN identifier of the second uplink message, the WAN side tunnel ID of the third uplink message, the WAN side PVLAN identifier of the third uplink message and the WAN side CVLAN identifier of the third uplink message.

7. The campus network roaming authentication-free method according to claim 1, characterized in that: The method further includes: setting the same SSID for all ONU devices located in a roaming area.

8. The campus network roaming authentication-free method according to claim 1, characterized in that: The method also includes: Set the option82_sensitive value of the roaming area in the access cloud gateway to 0 so that when the option82 field in the message sent by different ONU devices changes, redialing is not performed.

9. A non-volatile computer storage medium, characterized in that The computer storage medium stores computer-executable instructions, which are executed by one or more processors to complete the campus network roaming authentication-free method described in any one of claims 1-8.

10. A campus network roaming authentication-free device, characterized in that: include: at least one processor; And, a memory communicatively connected to the at least one processor; wherein the memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the processor to execute the method for campus network roaming without authentication as described in any one of claims 1-8.

Citation Information

Patent Citations

  • Authentication-free roaming method and device

    CN117528495A

  • Campus network login method and device based on cloud gateway

    CN118713937A