A method and device for roaming authentication-free of multiple terminals in a campus network
By setting up roaming groups and virtual ONU devices in the campus network, the problem of repeated authentication during multi-terminal switching is solved, multi-terminal authentication is achieved, and the convenience of using the campus network is improved.
Patent Information
- Application Number
- CN202411977963.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-31
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2044-12-31
AI Technical Summary
In campus network scenarios, user terminals need to frequently perform portal authentication when switching network environments. In particular, repeated authentication is required when multiple terminals switch, causing inconvenience in network use.
By reserving a binding page entry on the portal page, users can enter the MAC addresses and roaming sub-areas of multiple terminals, set up roaming groups, and use the relevant information of the virtual ONU device to generate WAN side information, so that multiple terminals can avoid repeated authentication in the same roaming area.
This eliminates the need for repeated authentication for multiple terminals in the same roaming area, improves the convenience of campus network use, and reduces the frequency of user authentication.
Smart Images

Figure CN119967410B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of campus networks, and in particular to a method and device for multi-terminal roaming authentication-free on a campus network. Background Art
[0002] In the past, in campus network scenarios, if a user terminal wanted to access the internet, it had to first log in and authenticate with a portal server at the edge to find the user link to access the internet. Once the user terminal switched to another network environment, such as to another dormitory or teaching building, the optical network unit (ONU) connected to the terminal changed, so portal authentication had to be re-performed. The binding rules of the previous login authentication had to be deleted and the new link had to be bound before the network could be used again. This resulted in users having to frequently perform portal authentication when on campus, causing trouble for their network use.
[0003] Moreover, in actual use, there is often a situation where a campus network user has multiple terminals, such as a laptop computer, a mobile phone terminal and a tablet terminal. In the existing technology, every time the user switches the terminal to use the campus network, re-authentication is required.
[0004] In view of this, overcoming the defects of the prior art is an urgent problem to be solved in this technical field. Summary of the Invention
[0005] The technical problem to be solved by the present invention is to provide a method and device for multi-terminal roaming authentication-free on a campus network, so that multiple terminals do not need to perform repeated authentication when using the campus network in the same roaming area.
[0006] The present invention adopts the following technical solutions:
[0007] In a first aspect, the present invention provides a method for multi-terminal roaming authentication-free on a campus network, comprising:
[0008] A binding page entrance is reserved in the portal page so that after the user successfully authenticates and logs in using the corresponding terminal, the user can enter the binding page from the binding page entrance, enter the MAC addresses of multiple terminals owned by the user on the binding page, and select one or more roaming sub-areas;
[0009] According to the MAC addresses of the multiple terminals and the selected roaming sub-areas, setting a roaming group for the multiple terminals in the access cloud gateway; wherein the roaming group includes the MAC addresses of the multiple terminals, relevant information of the selected multiple roaming sub-areas, relevant information of each actual ONU device in the selected multiple roaming sub-areas, and relevant information of a unique virtual ONU device in the roaming group;
[0010] When the first ONU device receives the first uplink message from the first terminal, it adds relevant information of the first ONU device to the first uplink message, generates a second uplink message, and sends the second uplink message to the access cloud gateway; wherein the first uplink message also carries the MAC address of the first terminal;
[0011] The access cloud gateway determines, based on the MAC address of the first terminal carried in the second uplink message, the relevant information of the first ONU device, and each roaming group, whether the first user is an authenticated user in the roaming area where the first ONU device is located; wherein the first user is the user to which the first terminal belongs;
[0012] If it is determined that the first user is an authenticated user in the roaming area where the first ONU device is located, the second uplink message is encapsulated into a third uplink message recognizable by the wide area network based on the relevant information of the virtual ONU device in the roaming group to which the first ONU device belongs, and the third uplink message is transmitted to the network.
[0013] Preferably, the relevant information of the actual ONU device includes the VNI identifier of the actual ONU device and the QinQ information of the actual ONU device; the relevant information of the virtual ONU device includes the virtual VNI identifier and the virtual QinQ information;
[0014] The access cloud gateway includes a virtual switch and a virtual client device, and setting a roaming group for the multiple terminals in the access cloud gateway according to the MAC addresses of the multiple terminals and the selected roaming sub-areas specifically includes:
[0015] Storing a roaming group information table item, an ONU device information table item, and an account roaming information table item in the virtual client device;
[0016] The roaming group information table entry stores the ID number of each roaming group, the ID number of each roaming sub-area, and the virtual VNI identifier and virtual QinQ information corresponding to each roaming group;
[0017] The ONU device information table item stores the VNI identification of each actual ONU device, the QinQ information of each actual ONU device, and the ID number of the roaming sub-area to which each actual ONU device belongs;
[0018] The account roaming information table entry stores the MAC addresses of the terminals bound to the user, the user's account information, and the ID number of the bound roaming group.
[0019] Preferably, the access cloud gateway determines whether the first user is an authenticated user in the roaming area where the first ONU device is located according to the MAC address of the first terminal carried in the second uplink message, the relevant information of the first ONU device, and each roaming group, specifically including:
[0020] The virtual switch receives the second uplink message, and forwards the second uplink message to the virtual client device;
[0021] The virtual client device finds the first roaming group bound to the first terminal from the account roaming information entry according to the MAC address of the first terminal carried in the second uplink message, and finds the first account information of the user to which the first terminal belongs;
[0022] Acquire, from the ONU device information table entry, a first roaming sub-area to which the first ONU device belongs, according to the VNI identifier of the first ONU device and the QinQ information of the first ONU device carried in the second uplink message;
[0023] searching, according to the roaming group information entry, whether the first roaming group includes the first roaming sub-area; and if it is found that the first roaming group includes the first roaming sub-area, searching whether there is historical login information of the first account information in the first roaming group;
[0024] If the historical login information exists, it is determined that the first user is an authenticated user in the roaming area where the first ONU device is located.
[0025] Preferably, the historical login information is recorded when the terminal bound to the user performs historical authentication and login in the roaming sub-area included in the first roaming group, and specifically includes:
[0026] When the virtual client device determines that the first user is not an authenticated user in the roaming area where the first ONU device is located, redirecting the second uplink message to the portal server so that the portal server feeds back a portal authentication page to the first terminal;
[0027] After the first terminal successfully logs in and authenticates on the portal authentication page, the portal server returns an authentication success message to the virtual client device; wherein the authentication success message carries the account information used for authentication, the VNI identifier of the ONU device currently accessed by the first terminal, and the QinQ information of the ONU device currently accessed by the first terminal;
[0028] The virtual client finds the corresponding roaming sub-area from the ONU device information table according to the VNI identifier of the ONU device currently accessed by the first terminal and the QinQ information of the ONU device currently accessed by the first terminal; and searches the roaming group including the roaming sub-area from the roaming group information table according to the roaming sub-area;
[0029] The ID number of the roaming group and the account information are recorded as historical login information in the authentication table; wherein, for one account information, only the latest historical login information is recorded in the authentication table.
[0030] Preferably, encapsulating the second uplink message into a third uplink message identifiable by the wide area network according to the virtual ONU device related information in the roaming group to which the first ONU device belongs specifically includes:
[0031] Find the corresponding WAN side VNI identifier and WAN side QinQ information according to the virtual ONU device related information in the roaming group to which the first ONU device belongs;
[0032] The virtual ONU device related information in the second uplink message is replaced by the WAN side VNI identifier and the WAN side QinQ information to generate the third uplink message.
[0033] Preferably, the method further comprises:
[0034] IOMP sets an address pool for each roaming group. The addresses in each address pool extend to the B segment.
[0035] According to the MAC address of the first terminal and the related information of the first ONU device carried in the second uplink message, a corresponding address is taken from the address pool of the corresponding roaming group and allocated to the first terminal.
[0036] Preferably, the method further comprises: setting the same SSID for all ONU devices located in a roaming area.
[0037] Preferably, the method further comprises:
[0038] Set the option82_sensitive value of the roaming area in the access cloud gateway to 0 so that when the option82 field in the message sent by different ONU devices changes, redialing is not performed.
[0039] In a second aspect, the present invention further provides a device for campus network multi-terminal roaming authentication-free, for implementing the campus network multi-terminal roaming authentication-free method described in the first aspect, the device comprising:
[0040] At least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the processor to execute the method for multi-terminal roaming in a campus network without authentication as described in the first aspect.
[0041] In a third aspect, the present invention further provides a non-volatile computer storage medium, wherein the computer storage medium stores computer-executable instructions, and the computer-executable instructions are executed by one or more processors to complete the method described in the first aspect.
[0042] In a fourth aspect, a chip is provided, comprising: a processor and an interface, for calling and running a computer program stored in a memory from a memory, and executing any method of the first aspect.
[0043] In a fifth aspect, a computer program product comprising instructions is provided, which, when executed on a computer or a processor, causes the computer or the processor to execute any of the methods of the first aspect.
[0044] The present invention sets up a roaming group and a virtual ONU device, and after verifying that the first user is an authenticated user, uses the virtual ONU device related information to generate WAN side information, so that the entire roaming group appears to the outside as having only one ONU device (i.e., the virtual ONU device). There is no need for repeated authentication, but the original link is used for network communication, thereby realizing authentication-free roaming in the campus network. In addition, the roaming group allows binding of multiple terminals of the user, so that multiple terminals do not need to be repeatedly authenticated when using the campus network in the same roaming area, further improving the convenience of using the campus network. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments of the present invention. Obviously, the drawings described below are only some embodiments of the present invention. Those skilled in the art can also derive other drawings based on these drawings without inventive effort.
[0046] Figure 1 This is a flowchart of a first campus network multi-terminal roaming authentication-free method provided by an embodiment of the present invention;
[0047] Figure 2 This is a schematic diagram of a portal authentication page in a campus network multi-terminal roaming authentication-free method provided by an embodiment of the present invention;
[0048] Figure 3This is a schematic diagram of a portal authentication page in a campus network multi-terminal roaming authentication-free method provided by an embodiment of the present invention;
[0049] Figure 4 This is a schematic diagram of a binding page in a campus network multi-terminal roaming authentication-free method provided by an embodiment of the present invention;
[0050] Figure 5 This is a schematic diagram of a roaming group information table entry in a campus network multi-terminal roaming authentication-free method provided by an embodiment of the present invention;
[0051] Figure 6 This is a flow chart of a second campus network multi-terminal roaming authentication-free method provided by an embodiment of the present invention;
[0052] Figure 7 This is a schematic diagram of an account roaming information table entry in a campus network multi-terminal roaming authentication-free method provided by an embodiment of the present invention;
[0053] Figure 8 This is a flow chart of a third campus network multi-terminal roaming authentication-free method provided by an embodiment of the present invention;
[0054] Figure 9 This is a flowchart of a fourth campus network multi-terminal roaming authentication-free method provided by an embodiment of the present invention;
[0055] Figure 10 This is a flowchart of a fifth campus network multi-terminal roaming authentication-free method provided by an embodiment of the present invention;
[0056] Figure 11 This is a schematic diagram of a campus network multi-terminal roaming authentication-free method provided by an embodiment of the present invention;
[0057] Figure 12 This is a schematic diagram of a campus network multi-terminal roaming authentication-free method provided by an embodiment of the present invention;
[0058] Figure 13 This is a schematic diagram of the architecture of a device for multi-terminal roaming without authentication in a campus network provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0059] In order to make the purpose, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0060] Unless the context requires otherwise, throughout the specification and claims, the term "including" is to be interpreted as meaning open inclusion, that is, "including, but not limited to". In the description of the specification, the terms "one embodiment", "some embodiments", "exemplary embodiments", "example", "specific example" or "some examples" and the like are intended to indicate that the specific features, structures, materials or characteristics associated with the embodiment or example are included in at least one embodiment or example of the present disclosure. The schematic representation of the above terms does not necessarily refer to the same embodiment or example. In addition, the specific features, structures, materials or characteristics may be included in any one or more embodiments or examples in any appropriate manner, that is, although they may be carried in the embodiments or examples of the above terms due to reasons such as the order and position of appearance, it is not limited to that they can be carried in combination by one embodiment or example.
[0061] In the description of the present invention, the terms "first" and "second" are used for descriptive purposes only, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of technical features indicated. Thus, the features defined as "first" and "second" may explicitly or implicitly include one or more of the features. In the description of the embodiments of the present disclosure, unless otherwise specified, "multiple" means two or more. In addition, for example, the description may also use the method of adding "A" and "B" at the end to describe the same type of nouns as two independent individuals. In this case, the corresponding features defined as "A" and "B" are only used to distinguish the description purposes of the same type of individuals, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of technical features indicated.
[0062] In the description of the present invention, the expression "A and / or B" (where A and B are used to formally represent specific characteristic contents) will be involved, and the corresponding expressions include the following three combinations: only A, only B, and a combination of A and B.
[0063] As used herein, "about," "substantially," or "approximately" includes the stated value and an average value that is within an acceptable range of deviation from the particular value as determined by one of ordinary skill in the art taking into account the measurements in question and the errors associated with the measurement of the particular quantity (i.e., the limitations of the measurement system).
[0064] In addition, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.
[0065] Embodiment 1:
[0066] Embodiment 1 of the present invention provides a campus network multi-terminal roaming authentication-free method, such as Figure 1 Shown, including:
[0067] In step 201, a binding page entrance is reserved in the portal page so that after the user successfully authenticates and logs in using the corresponding terminal, the user can enter the binding page from the binding page entrance, enter the MAC addresses of multiple terminals owned by the user on the binding page, and select one or more roaming sub-areas; wherein the binding page entrance is displayed after the user is successfully authenticated, such as Figure 2 This is the portal page when the user has not logged in for authentication. Figure 3 Click on the portal page after the user successfully logs in and authenticates. Figure 3 In "Roaming Management" (i.e. binding page entrance), enter Figure 4 The binding page shown allows users to enter multiple devices and select multiple roaming sub-areas to form a roaming group. Each roaming sub-area is pre-defined by those skilled in the art based on campus buildings, for example, one building can be divided into one roaming sub-area.
[0068] In step 202, a roaming group is set up for the multiple terminals in the access cloud gateway based on the MAC addresses of the multiple terminals and the selected roaming sub-areas. The roaming group includes the MAC addresses of the multiple terminals, relevant information of the selected multiple roaming sub-areas, relevant information of each actual ONU device in the selected multiple roaming sub-areas, and relevant information of a virtual ONU device unique to the roaming group. The relevant information can be understood as identification information used to identify the corresponding device. The virtual ONU device can be understood as not being a device actually existing in the network, but rather a virtual device used to represent all actual ONU devices in the corresponding area. The virtual device has the same type of relevant information as the actual ONU device. For example, if the identification information of the actual ONU device includes a VNI identifier (full name: VXLAN Network Identifier, which means an identifier in a VXLAN network) and QinQ information, the virtual ONU device also has the VNI identifier and QinQ information (i.e., the virtual ONU device related information) and is different from other virtual ONU devices and actual ONU devices. The VNI identifier and QinQ information of the virtual ONU device are allocated when the roaming group is established.
[0069] In step 203, upon receiving the first uplink message from the first terminal, the first ONU device adds relevant information about the first ONU device to the first uplink message, generates a second uplink message, and sends the second uplink message to the access cloud gateway. The first uplink message also carries the MAC address of the first terminal. The first ONU device is the ONU device accessed by the first terminal. In actual use, a roaming group also corresponds to a tunnel group (also called an EVPN instance group). The tunnel group includes the tunnels (also called EVPN instances) used by each ONU device bound to the roaming group to transmit messages. The tunnel is used to isolate messages from different roaming groups, thus providing message isolation. For example, the IP and QinQ information of messages in different tunnels can be duplicated. Without tunnel isolation, duplicated IP and QinQ information can cause traffic identification confusion. The tunnel group ID (also called LAN_EVPN_Group) is also added to the second uplink message.
[0070] In step 204, the access cloud gateway determines whether the first user is an authenticated user in the roaming area where the first ONU device is located based on the MAC address of the first terminal, the relevant information of the first ONU device, and the roaming groups carried in the second uplink message; wherein, the first user is the user to which the first terminal belongs; that is, whether the first user has performed portal authentication in the roaming area and the authentication information is still valid.
[0071] In step 205, if it is determined that the first user is an authenticated user within the roaming area where the first ONU device is located, the second uplink message is encapsulated into a third uplink message recognizable by the wide area network based on the relevant information of the virtual ONU device in the roaming group to which the first ONU device belongs, and the third uplink message is transmitted to the network. If it is determined that the first user is not an authenticated user within the roaming area where the first ONU device is located, the user is redirected to a portal authentication page for user authentication.
[0072] Among them, according to the relevant information of the virtual ONU device in the roaming group to which the first ONU device belongs, the second uplink message is encapsulated into a third uplink message identifiable by the wide area network, specifically including: finding the corresponding wide area network (abbreviated as: WAN) side VNI identifier and WAN side QinQ information according to the relevant information of the virtual ONU device in the roaming group to which the first ONU device belongs; using the WAN side VNI identifier and WAN side QinQ information to replace the virtual ONU device related information in the second uplink message to generate the third uplink message.
[0073] The access cloud gateway includes a virtual switch and a virtual client device, and the process of generating the third uplink message is mainly completed by the virtual client device. In the virtual client device, each virtual ONU device corresponds to a unique local area network (LAN) side VNI identifier and LAN side QinQ information, and a WAN side VNI identifier and WAN side QinQ information.
[0074] This embodiment sets up a roaming group and a virtual ONU device, and after verifying that the first user is an authenticated user, uses the virtual ONU device related information to generate WAN side information, so that the entire roaming group appears to the outside as having only one ONU device (i.e., the virtual ONU device), and there is no need for repeated authentication. Instead, the original link is used for network communication, thereby realizing authentication-free roaming in the campus network. In addition, the roaming group allows binding of multiple terminals of the user, so that multiple terminals do not need to be repeatedly authenticated when using the campus network in the same roaming area, further improving the convenience of using the campus network.
[0075] In actual use, different ONU devices have different service set identifiers (SSIDs), which may also trigger the first terminal to re-dial authentication. Therefore, the method further includes: setting the same SSID for all ONU devices in a roaming area.
[0076] Furthermore, when a terminal roams between authentication-free ONUs, the Option 82 reported by the Optical Line Terminal (OLT) device will report different information depending on the physical location of the ONU connected to the OLT device. In the prior art, when the cloud gateway detects that the Option 82 for the same account is different, it will initiate a redial. This results in the terminal still needing to dial frequently when roaming between authentication-free ONUs. To solve this problem, the method also includes: setting the option82_sensitive value of the roaming area in the access cloud gateway to 0, so that when the Option 82 field in the message sent by different ONU devices changes, the dialing is not performed again. Option82_sensitive can be understood as a field used to identify whether the dialing action is sensitive to the Option 82 field. That is, when the value of option82_sensitive is 1, the dialing action is sensitive to the Option 82 field and a redial is performed when a change in the Option 82 field is detected; when the value of option82_sensitive is 0, the dialing action is not sensitive to the Option 82 field and a redial is performed when a change in the Option 82 field is detected.
[0077] In addition, if the operator has performed precise binding on the Authentication, Authorization, and Accounting (AAA) server, the physical scope of the roaming area needs to be limited according to the precise binding conditions. For example, if AAA has performed precise binding on the OLT device, Passive Optical Network (PON) board, and PON port, then the ONUs in a roaming area need to be on the same PON board of the same OLT and on the same PON port.
[0078] In actual application scenarios, the relevant information of the actual ONU device includes the VNI identifier of the actual ONU device and the QinQ information of the actual ONU device; the relevant information of the virtual ONU device includes the virtual VNI identifier and the virtual QinQ information. It should be noted that the VNI identifier of the actual ONU device and the QinQ information of the actual ONU device, as well as the virtual VNI identifier and the virtual QinQ information, all refer to the LAN-side VNI identifier and the LAN-side QinQ information. In actual use, the QinQ information is also manifested as Network Address Translation (NAT) plus QinQ.
[0079] The access cloud gateway includes a virtual switch and a virtual client device, the virtual switch is also called a vSwitch, and the virtual client device is also called a vCPE. The roaming group is set for the multiple terminals in the access cloud gateway according to the MAC addresses of the multiple terminals and the selected roaming sub-area, specifically including: storing roaming group information table items, ONU device information table items and account roaming information table items in the virtual client device.
[0080] The roaming group information table entry stores the ID number of each roaming group, the ID number of each roaming sub-area, and the virtual VNI identifier and virtual QinQ information corresponding to each roaming group, such as Figure 5 As shown, the roaming group ID is a unique index.
[0081] The VNI identification of each actual ONU device and the QinQ information of each actual ONU device and the ID number of the roaming sub-area to which each actual ONU device belongs are stored in the described ONU device information table item, such as Figure 6 wherein, the VNI identifier of the actual ONU device and the QinQ information of each actual ONU device are used as a unique index, and each actual ONU device corresponds to a unique roaming sub-area (expressed as the ID number of the roaming sub-area).
[0082] The account roaming information table entry stores the MAC address of each terminal bound to the user, the user's account information, and the ID number of the bound roaming group, such as Figure 7 As shown. The mac address is a unique index, corresponding to a roaming group. In actual use, when the user selects one or more corresponding roaming sub-areas, first determine whether the selected roaming sub-area corresponds to an existing roaming group. If there is a corresponding existing roaming group, directly add the mac addresses of the terminals bound to the user, the user's account information, and the ID number of the existing roaming group to the account roaming information table item; if there is no corresponding existing roaming group, generate a new roaming group, add the ID number of the new roaming group, the ID number of each roaming sub-area in the new roaming group, and the virtual VNI identifier and virtual QinQ information corresponding to the new roaming group to the roaming group information table item, and add the mac addresses of the terminals bound to the user, the user's account information, and the ID number of the new roaming group to the account roaming information table.
[0083] The access cloud gateway determines whether the first user is an authenticated user in the roaming area where the first ONU device is located based on the MAC address of the first terminal, the relevant information of the first ONU device, and each roaming group carried in the second uplink message, such as Figure 8 As shown, specifically including:
[0084] In step 301, the virtual switch receives the second uplink message and forwards the second uplink message to the virtual client device.
[0085] In step 302, the virtual client device finds the first roaming group bound to the first terminal from the account roaming information entry according to the MAC address of the first terminal carried in the second uplink message, and finds the first account information of the user to which the first terminal belongs.
[0086] In step 303, according to the VNI identifier of the first ONU device and the QinQ information of the first ONU device carried in the second uplink message, the first roaming sub-area to which the first ONU device belongs is obtained from the ONU device information table.
[0087] In step 304, based on the roaming group information table entry, a query is performed to determine whether the first roaming group includes the first roaming sub-area. If the query shows that the first roaming group includes the first roaming sub-area, it can be considered that the current access location is located in the first roaming group bound to the first terminal. Then, a query is performed to determine whether there is historical login information of the first account information in the first roaming group.
[0088] In step 305, if the historical login information exists, it is determined that the first user is an authenticated user in the roaming area where the first ONU device is located. If the first roaming group does not include the first roaming sub-area, or the historical login information does not exist, the user is redirected to the portal authentication page for re-authentication.
[0089] The historical login information is recorded when the terminal bound to the user performs historical authentication and login in the roaming sub-area included in the first roaming group, such as Figure 9 As shown, specifically including:
[0090] In step 401, when the virtual client device determines that the first user is not an authenticated user in the roaming area where the first ONU device is located, the second uplink message is redirected to the portal server so that the portal server feeds back a portal authentication page to the first terminal.
[0091] In step 402, after the first terminal successfully logs in and authenticates on the portal authentication page, the portal server returns an authentication success message to the virtual client device; wherein, the authentication success message carries the account information used for authentication, the VNI identifier of the ONU device currently accessed by the first terminal, and the QinQ information of the ONU device currently accessed by the first terminal.
[0092] In step 403, the virtual client finds the corresponding roaming sub-area from the ONU device information table item based on the VNI identifier of the ONU device currently accessed by the first terminal and the QinQ information of the ONU device currently accessed by the first terminal; and searches for the roaming group including the roaming sub-area from the roaming group information table item based on the roaming sub-area.
[0093] In step 404, the ID number of the roaming group and the account information are recorded as historical login information in an authentication table; wherein, for one account information, only the latest historical login information is recorded in the authentication table.
[0094] In the prior art, the address pool is often implemented using the C segment, that is, the first three segments of the IP address are fixed, and the fourth segment is used for address allocation. The number of IP addresses that can be allocated by an address pool is 265, such as from 192.168.2.0 to 192.168.2.255. In a specific application scenario, since a roaming group corresponds to information related to a virtual ONU device, and in a campus network scenario, there are often many users, that is, many terminals. When there are many terminals bound to a roaming group, the IP addresses in the address pool may be exhausted, resulting in the inability to allocate valid addresses to the terminals. To solve this problem, the method further includes:
[0095] The Integrated Operation Management Platform (IOMP) sets up an address pool for each roaming group. Each address pool extends to segment B, meaning the first two segments of the IP address are fixed, and the third and fourth segments are used for address allocation. Therefore, a single address pool can allocate 65,535 IP addresses, such as 192.168.0.0 to 192.168.255.255. Based on the MAC address of the first terminal and related information about the first ONU device carried in the second uplink message, an address is retrieved from the address pool of the corresponding roaming group and allocated to the first terminal.
[0096] In actual use, the method also includes: the access cloud gateway also records the ONU device accessed by each terminal when authenticating and logging in based on the authentication success message, and when it is monitored that the number of times the first terminal accesses the second ONU device is greater than the preset number, a reminder message is sent to the first terminal through the portal server; wherein, the second ONU device is an ONU device outside the roaming group of the first terminal, and the reminder message is used to prompt the user whether to add the current area to the roaming group; if the user chooses to add the current area to the roaming group according to the reminder message, the second ONU device is added to the roaming group of the first terminal.
[0097] Taking into account the actual application scenario, the area where students use the campus network for entertainment is mainly concentrated in the dormitory building. Generally speaking, in order to prevent the students' entertainment network from affecting the study and office network, a cloud gateway is often used to limit the network bandwidth of each dormitory, and a dormitory is used as a roaming sub-area to facilitate traffic isolation between dormitories. However, in this case, when a user in a dormitory needs to download a file, the file download task may affect the network speed of other users in the dormitory. In order to solve this problem, this embodiment provides an optimal campus network multi-terminal roaming authentication-free method, such as Figure 10 As shown, specifically including:
[0098] In step 501, the access cloud gateway monitors the downlink messages of each dormitory and determines whether each downlink message is a file download type message; wherein, the file download type is a message used to transmit files downloaded by users from the network, and the downlink message refers to a message on the LAN side after the message received from the wide area network is converted accordingly by NAT. The monitoring of the downlink messages of each dormitory specifically includes: pre-storing the corresponding relationship between each dormitory and the ONU device of each dormitory in the access cloud gateway. In actual use, the corresponding relationship is expressed as an ONU device information table item, and the ONU device information table item also includes a dormitory identifier (which can be understood as a dormitory number). When the corresponding roaming sub-area carries a dormitory identifier, the roaming sub-area can be regarded as a dormitory, and the specific dormitory can be identified based on the dormitory identifier.
[0099] When a downlink message is received, the ONU device to which the downlink message needs to be sent is identified based on the QinQ information carried in the downlink message, and the dormitory to which the downlink message belongs is found from the corresponding relationship based on the ONU device.
[0100] The determination of whether each downlink message is of the file download type may be performed by pre-analyzing downlink messages of commonly used types in the network to obtain identification words in each type of downlink message, and then using the identification words to match the downlink messages received in actual use.
[0101] In step 502, when a file download type message is detected in the first dormitory, the destination terminal to which the file download type message is intended is found, and a search is performed to determine whether a second dormitory other than the first dormitory exists in the historically bound dormitories of the first user to whom the destination terminal belongs. The historically bound dormitories refer to dormitories in the roaming group to which the first user has historically bound, and all roaming sub-areas previously added by the first user to the roaming group are recorded in the access cloud gateway. For example, if the first user added dormitories A and B to the bound roaming group a month ago, and deleted dormitories B and added dormitories C two weeks ago, and dormitories A is the first user's current dormitories, i.e., the first dormitory, then dormitories B and C can both be considered second dormitories. In actual use, the second dormitory can be understood as a dormitory with which the first user has close contact. The destination terminal can be understood as the first user's terminal.
[0102] In step 503, if it is found that there is a second dormitory, the bandwidth occupancy of the downlink message in the second dormitory is calculated. If the bandwidth occupancy of the downlink message in the second dormitory is less than the preset bandwidth, the file download type message received subsequently from the first dormitory is divided into the first message and the second message according to the preset quantity ratio; wherein, the access cloud gateway does not include the second message in the statistics of the first dormitory traffic; the preset bandwidth and the preset quantity ratio are obtained by technical personnel in this field based on empirical analysis. When the bandwidth occupancy of the downlink message in the second dormitory is less than the preset bandwidth, it can be considered that the current bandwidth demand of each user in the second dormitory is relatively small and there is more idle bandwidth. The setting standard of the preset quantity ratio is: while using the bandwidth of the second dormitory to assist in file downloading, it does not affect the network demand of each user in the second dormitory.
[0103] In step 504, the first message is sent to the destination terminal along the original path, and the forwarding identifier, the IP address of the second message, and the relevant information of the ONU device of the second dormitory are added to the second message to generate a third message; wherein, the second message carries the IP address, MAC address and relevant information of the destination terminal; wherein, the destination ONU device is the ONU device currently accessed by the destination terminal.
[0104] In step 505, the third message is sent to the ONU device of the second dormitory. The ONU device of the second dormitory identifies the third message according to the forwarding identifier, and forwards the third message to the destination ONU device through the local area network according to the IP address, MAC address and relevant information of the destination terminal in the third message, so that the destination ONU device restores the third message to the first message and transmits it to the destination terminal.
[0105] Among them, when the access cloud gateway limits the bandwidth of the dormitory, it mainly limits the external network traffic, that is, it limits the bandwidth of the traffic that needs to be transmitted to the wide area network. The usual implementation method is to discard the part of the received downlink message that exceeds the bandwidth according to the time interval, thereby reducing the rate at which the destination terminal sends a response message (such as the packet confirmation ACK message in the TCP protocol) to the message sender, so that the message sender reduces the rate at which it sends downlink messages to the target terminal when synchronizing the message sending rate.
[0106] This embodiment, on the other hand, diverts file download type messages so that they reach the destination ONU device and the ONU device of the second dormitory respectively. The ONU device of the second dormitory then transmits the messages to the destination ONU device through the local area network (through the switch, not through the access cloud gateway), and finally reaches the destination terminal, so that the destination terminal can immediately return a response message to the message sender. While retaining the bandwidth limit for the first dormitory, the idle bandwidth of the second dormitory is utilized to increase the speed of the first user's file download and prevent the first user's file download from affecting the network usage of other users in the first dormitory.
[0107] Example 2:
[0108] The present invention is based on the method described in Example 1, combined with specific application scenarios, and uses technical descriptions in related scenarios to illustrate the implementation process of the present invention in characteristic scenarios.
[0109] This embodiment uses Figure 11 Taking the campus network application scenario shown as an example, the campus network is connected in the form of a new metropolitan area network. The campus network multi-terminal roaming authentication-free method described in this embodiment specifically includes:
[0110] First, to adapt to FTTR (Fiber to the Room) networking, PPPOE+ information was introduced. To enable account terminals to seamlessly switch links between optical modems, multiple ONUs use the same SSID. Under normal circumstances, mobile terminal devices use wireless networks to access the Internet. For network security, virtual MACs are used. Therefore, when switching wireless networks, terminals generally switch to different MACs to access the Internet. When the SSID name of the wireless network is the same, the same terminal device, although switching between different ONUs, will not perceive the change in the wireless network and will therefore use the same MAC to access the Internet. In other words, setting all optical modems on campus to the same SSID ensures that the terminal MAC remains unchanged when traveling under different links.
[0111] However, in actual use, the ONUID carried in the option 82 information of the Dynamic Host Configuration Protocol (DHCP) changes frequently, so the PPPOE+ information of the account dial-up changes synchronously. After sensing the change in PPPOE+ information, the IOMP platform will send an account redial interface, that is, the user terminal switches ONU frequently, PPPOE+ often changes, triggering frequent redialing, network instability, and high equipment pressure. To solve this problem, option82_sensitive is marked as 0 under the campus or QINQ, indicating that it is insensitive to the option 82 field, and 1 indicates that it is sensitive, that is, when the user terminal switches ONU, the cloud gateway receives a change in the option 82 field in the DHCP message. Since the QINQ link is marked as insensitive, there is no need to re-dial PPPOE, so as to ensure that the user terminal switches ONU, the PPPOE+ information remains unchanged, and there is no frequent redialing.
[0112] In the existing technology, the LAN address pool only supports one C segment, that is, 250 terminals at most. This results in excessive resource limitations and makes operation and maintenance very difficult. In other words, a QINQ address pool only supports one C segment, which is insufficient. To solve this problem, this embodiment expands the QINQ address pool to the B segment. Specifically:
[0113] IOMP configures the address pool of a LAN network as a B segment; the access virtual wireless terminal access device (Virtual Customer Premise Equipment, referred to as: vCPE) divides the configured B segment IP into multiple C segments for IP allocation (the mask is fixed to 24 bits, and each C segment corresponds to a gateway IP); the virtual private network (VPN) with a large address pool needs to be configured on the service vSwitch. Network, referred to as: VPN) sets an identifier for the maximum number of NAT resources (NATIP+port_range) allowed to be used by QinQ; the uplink message comes through LANVNI+QINQ+MAC (LANVNI+QINQ here refers to the VNI identifier of the actual ONU device and the QinQ information of the actual ONU device) to apply for the address pool IP. When the number of terminals is greater than 250, the cloud gateway will automatically divide the next C segment network, so as to ensure that every terminal in the school can get the IP under the same QINQ. When the SSID remains unchanged, users can achieve authentication-free operation; the service vSwitch allocates NATIP+port_range to users according to the QINQ under VPN. When there are too many user terminals, the number of NATIP+port_range can be dynamically adjusted.
[0114] After completing the above settings, Figure 12 As shown, it is assumed that accountA has dormitory building 1, teaching building 1, teaching building 2, library, gymnasium and teachers' building as the main activity venues in the school. The user of accountA selects these activity venues on the binding page (each activity venue corresponds to a roaming sub-area), generates and binds the corresponding roaming group, and accountB has dormitory building 2, teachers' building, gymnasium, library, teaching building 2 and teaching building 3 as the main activity venues in the school. Similarly, the user of accountB selects these activity venues on the binding page, generates and binds the corresponding roaming group; then the links can be divided into two groups according to the attributes of the students (i.e., the roaming groups in Example 1), forming an account+VNIQINQ relationship table (i.e., the roaming group information table item and the account roaming information table item are combined); one account supports three terminal devices, forming an account+mac relationship table (i.e., the account roaming information table item in Example 1).
[0115] After accountA's terminal mac1 passes portal authentication for the first time in dormitory building 1, it can register other devices mac2 and mac3 on the portal page; the portal server notifies the management platform to send pre-authentication policies for accountA and terminal devices mac2 and mac3 to the cloud gateway in advance.
[0116] In actual use, the following situations may occur:
[0117] (1) When user accountA uses mac2 to access the Internet in the dormitory, the cloud gateway vSwitch receives a message of LANVNI+QINQ4+LAN_EVPN_Group, queries the rulein (i.e., the evpn transfer rule in the cloud gateway), and forwards the message to the vCPE. The vCPE queries the authentication table and finds that the mac has been authenticated and directly releases it. The LANVNI+QINQ4+LAN_EVPN_Group of the message (i.e., the second upstream message) is replaced with WANVNI+QINQ4+WAN_EVPN_Group (after the replacement, the third upstream message is obtained) and sent from the wan port. Among them, the VNI identifier and QinQ information of the actual ONU device (i.e., LANVNI+QINQ4+LAN_EVPN_Group) are first replaced with the WANVNI+QINQ4+WAN_EVPN_Group. Q4) is converted into the virtual VNI identifier and virtual QinQ information of the corresponding roaming group virtual ONU device, and then the virtual VNI identifier and virtual QinQ information are used to find the corresponding WAN side VNI identifier and WAN side QinQ information (i.e., WANVNI+QINQ4). After receiving the message, the vSwitch queries the ruleout (i.e., the outbound rule in the access cloud gateway) table and sends the message to the network side, so that the network can be accessed directly without repeated authentication; among them, LAN_EVPN_Group is the link from the terminal to the cloud gateway (also called a tunnel or EPVN instance), and WAN_EVPN_Group represents the link from the cloud gateway to Bras, which is used to establish an SRv6 tunnel to transmit data packets from the terminal to the cloud gateway and from the cloud gateway to Bras. That is, according to the binding relationship between Qinq and Evpn_Group, a rulein / ruleout forwarding table will be formed inside the cloud gateway. After the uplink message reaches the cloud gateway from the terminal, it queries the rulein on the LAN side and forwards it to vcpe. After vcpe processes it, it forwards it to vsw for encapsulation in the srv6 tunnel header. It queries the ruleout on the wan side and forwards it to bras. After the downlink message reaches the cloud gateway, it also queries the rulein of the wan side tunnel and forwards it to vcpe. After vcpe processes it, it forwards it to vsw for encapsulation in the srv6 tunnel header. It queries the ruleout on the lan side and forwards it to the terminal.
[0118] (2) User accountA uses mac2 to move to the library to surf the Internet, and the cloud gateway vSwitch receives the message of LAN VNI + QINQ6 + LAN_EVPN_Group, queries the rulein forwarding table, forwards the message to the vCPE, the vCPE queries the authentication table to find that the mac has been authenticated, the account is accountA, and the account + VNI QINQ table is queried to find the user group 1. The current terminal tunnel is moved from the dormitory to the library, the physical link is switched, but is still in group 1, and there is no need to re-authenticate. The LAN VNI + QINQ6 + LAN_EVPN_Group of the message is directly replaced by WAN VNI + QINQ6 + WAN_EVPN_Group and sent from the wan port. The vSwitch receives the message and queries the ruleout table to send the message to the network side.
[0119] (3) When user accountA uses terminal device mac2 to move to teaching building 3 to surf the Internet, the cloud gateway vSwitch receives the message of LAN VNI + QINQ3 + LAN_EVPN_Group, queries the rulein forwarding table, forwards the message to the vCPE, the vCPE queries the authentication table to find that the mac has been authenticated, the account is accountA, and the account + VNI QINQ table is queried to find that the link VNI + QINQ3 is not in group 1. The cloud gateway will redirect the traffic to the portal page, the terminal will pop up a window to ask whether to trust the network, click trust, the portal server notifies the management platform to incrementally issue accountA + VNI QINQ3 to group 1 to the cloud gateway (that is, add the teaching building 3 sub-region to the roaming group bound by user accountA), and the subsequent process is based on the same concept as step (2) to re-judge whether accountA has been authenticated in the roaming group, and then perform subsequent processing.
[0120] (4) When user accountA uses terminal device mac2 to move to a network outside the school district range but with the same SSID as the school, the cloud gateway vSwitch receives the message of LAN VNIx + QINQx + LAN_EVPN_Group. According to the QinQ query, it is found that the currently accessed ONU device is not within the school district range, and it is determined that user acconutA is located outside the school district range, and is redirected to the interception page. The terminal will pop up a window to prompt "suspicious network, prohibit surfing the Internet!".
[0121] (5) When user accountA uses mac4 to access the Internet in the dormitory, the cloud gateway vSwitch receives a message with LANVNI+QINQ4+LAN_EVPN_Group, queries the rulein forwarding table, and forwards the message to the vCPE. The vCPE queries the authentication table and finds that the mac is not authenticated. It redirects the message to the portal server, allowing the unknown mac to find an account for authentication. If the number of macs under user accountA is less than 3, it is directly authenticated to access the Internet; if it is equal to 3, it is necessary to manually remove a terminal and add the new terminal to the authentication table.
[0122] Example 3:
[0123] like Figure 13 FIG is a schematic diagram of the architecture of a campus network multi-terminal roaming authentication-free device according to an embodiment of the present invention. The campus network multi-terminal roaming authentication-free device according to this embodiment includes one or more processors 21 and a memory 22. Figure 13 A processor 21 is taken as an example.
[0124] The processor 21 and the memory 22 may be connected via a bus or other means. Figure 13 The bus connection is taken as an example.
[0125] The memory 22, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs and non-volatile computer executable programs, such as the campus network multi-terminal roaming authentication-free method in Example 1. The processor 21 executes the campus network multi-terminal roaming authentication-free method by running the non-volatile software programs and instructions stored in the memory 22.
[0126] The memory 22 may include high-speed random access memory and non-volatile memory, such as at least one disk storage device, flash memory device, or other non-volatile solid-state memory device. In some embodiments, the memory 22 may optionally include a memory remotely located relative to the processor 21, and such remote memory may be connected to the processor 21 via a network. Examples of such networks include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0127] The program instructions / modules are stored in the memory 22 and, when executed by the one or more processors 21 , execute the campus network multi-terminal roaming authentication-free method in the above-mentioned embodiment 1.
[0128] It is worth noting that the information interaction, execution process, etc. between the modules and units within the above-mentioned devices and systems are based on the same concept as the processing method embodiment of the present invention. The specific content can be found in the description of the method embodiment of the present invention and will not be repeated here.
[0129] Those skilled in the art will understand that all or part of the steps in the various methods of the embodiments can be completed by instructing related hardware through a program, and the program can be stored in a computer-readable storage medium, which may include: read-only memory (ROM), random access memory (RAM), a disk or an optical disk, etc.
[0130] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions and improvements made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A campus network multi-terminal roaming authentication-free method, characterized in that: include: A binding page entrance is reserved in the portal page so that after the user successfully authenticates and logs in using the corresponding terminal, the user can enter the binding page from the binding page entrance, enter the MAC addresses of multiple terminals owned by the user on the binding page, and select one or more roaming sub-areas; According to the MAC addresses of the multiple terminals and the selected roaming sub-areas, setting a roaming group for the multiple terminals in the access cloud gateway; wherein the roaming group includes the MAC addresses of the multiple terminals, relevant information of the selected multiple roaming sub-areas, relevant information of each actual ONU device in the selected multiple roaming sub-areas, and relevant information of a unique virtual ONU device in the roaming group; When the first ONU device receives the first uplink message from the first terminal, it adds relevant information of the first ONU device to the first uplink message, generates a second uplink message, and sends the second uplink message to the access cloud gateway; wherein the first uplink message also carries the MAC address of the first terminal; The access cloud gateway determines, based on the MAC address of the first terminal carried in the second uplink message, the relevant information of the first ONU device, and each roaming group, whether the first user is an authenticated user in the roaming area where the first ONU device is located; wherein the first user is the user to which the first terminal belongs; If it is determined that the first user is an authenticated user in the roaming area where the first ONU device is located, the second uplink message is encapsulated into a third uplink message recognizable by the wide area network based on the relevant information of the virtual ONU device in the roaming group to which the first ONU device belongs, and the third uplink message is transmitted to the network.
2. The campus network multi-terminal roaming authentication-free method according to claim 1, characterized in that: The relevant information of the actual ONU device includes the VNI identifier of the actual ONU device and the QinQ information of the actual ONU device; the relevant information of the virtual ONU device includes the virtual VNI identifier and the virtual QinQ information; The access cloud gateway includes a virtual switch and a virtual client device, and setting a roaming group for the multiple terminals in the access cloud gateway according to the MAC addresses of the multiple terminals and the selected roaming sub-areas specifically includes: Storing a roaming group information table item, an ONU device information table item, and an account roaming information table item in the virtual client device; The roaming group information table entry stores the ID number of each roaming group, the ID number of each roaming sub-area, and the virtual VNI identifier and virtual QinQ information corresponding to each roaming group; The ONU device information table item stores the VNI identification of each actual ONU device, the QinQ information of each actual ONU device, and the ID number of the roaming sub-area to which each actual ONU device belongs; The account roaming information table entry stores the MAC addresses of the terminals bound to the user, the user's account information, and the ID number of the bound roaming group.
3. The campus network multi-terminal roaming authentication-free method according to claim 2, characterized in that: The access cloud gateway determines, based on the MAC address of the first terminal carried in the second uplink message, relevant information of the first ONU device, and each roaming group, whether the first user is an authenticated user in the roaming area where the first ONU device is located, specifically including: The virtual switch receives the second uplink message, and forwards the second uplink message to the virtual client device; The virtual client device finds the first roaming group bound to the first terminal from the account roaming information entry according to the MAC address of the first terminal carried in the second uplink message, and finds the first account information of the user to which the first terminal belongs; Acquire, from the ONU device information table entry, a first roaming sub-area to which the first ONU device belongs, according to the VNI identifier of the first ONU device and the QinQ information of the first ONU device carried in the second uplink message; searching, according to the roaming group information entry, whether the first roaming group includes the first roaming sub-area; and if it is found that the first roaming group includes the first roaming sub-area, searching whether there is historical login information of the first account information in the first roaming group; If the historical login information exists, it is determined that the first user is an authenticated user in the roaming area where the first ONU device is located.
4. The campus network multi-terminal roaming authentication-free method according to claim 3, characterized in that: The historical login information is recorded when the terminal bound to the user performs historical authentication and login in the roaming sub-area included in the first roaming group, and specifically includes: When the virtual client device determines that the first user is not an authenticated user in the roaming area where the first ONU device is located, redirecting the second uplink message to the portal server so that the portal server feeds back a portal authentication page to the first terminal; After the first terminal successfully logs in and authenticates on the portal authentication page, the portal server returns an authentication success message to the virtual client device; wherein the authentication success message carries the account information used for authentication, the VNI identifier of the ONU device currently accessed by the first terminal, and the QinQ information of the ONU device currently accessed by the first terminal; The virtual client finds the corresponding roaming sub-area from the ONU device information table according to the VNI identifier of the ONU device currently accessed by the first terminal and the QinQ information of the ONU device currently accessed by the first terminal; and searches the roaming group including the roaming sub-area from the roaming group information table according to the roaming sub-area; The ID number of the roaming group and the account information are recorded as historical login information in the authentication table; wherein, for one account information, only the latest historical login information is recorded in the authentication table.
5. The campus network multi-terminal roaming authentication-free method according to claim 2, characterized in that: The step of encapsulating the second uplink message into a third uplink message identifiable by the wide area network according to the relevant information of the virtual ONU device in the roaming group to which the first ONU device belongs, specifically includes: Find the corresponding WAN side VNI identifier and WAN side QinQ information according to the virtual ONU device related information in the roaming group to which the first ONU device belongs; The virtual ONU device related information in the second uplink message is replaced by the WAN side VNI identifier and the WAN side QinQ information to generate the third uplink message.
6. The campus network multi-terminal roaming authentication-free method according to claim 1, characterized in that: The method also includes: IOMP sets an address pool for each roaming group. The addresses in each address pool extend to the B segment. According to the MAC address of the first terminal and the related information of the first ONU device carried in the second uplink message, a corresponding address is taken from the address pool of the corresponding roaming group and allocated to the first terminal.
7. The campus network multi-terminal roaming authentication-free method according to claim 1, characterized in that: The method further includes: setting the same SSID for all ONU devices located in a roaming area.
8. The campus network multi-terminal roaming authentication-free method according to claim 1, characterized in that: The method also includes: Set the option82_sensitive value of the roaming area in the access cloud gateway to 0 so that when the option82 field in the message sent by different ONU devices changes, redialing is not performed.
9. A non-volatile computer storage medium, characterized in that The computer storage medium stores computer-executable instructions, which are executed by one or more processors to complete the campus network multi-terminal roaming authentication-free method described in any one of claims 1-8.
10. A device for multi-terminal roaming authentication-free on a campus network, characterized in that: include: at least one processor; And, a memory communicatively connected to the at least one processor; wherein the memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the processor to execute the method for multi-terminal roaming in a campus network without authentication as described in any one of claims 1-8.
Citation Information
Patent Citations
Method and device for preventing re-authentication of roaming user
CN102075904A
Network access control method and system
CN102984173A